chore(deps): update module github.com/containers/image/v5 to v5.30.1 [security] (#1743)

This PR contains the following updates:



Package
Change
Age
Adoption
Passing
Confidence




github.com/containers/image/v5
v5.30.0 -> v5.30.1








WarningSome dependencies could not be looked up. Check the warning logs for more information.

GitHub Vulnerability Alerts
CVE-2024-3727
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Release Notes

containers/image (github.com/containers/image/v5)
v5.30.1
Compare Source
This fixes CVE-2024-3727 .
Digest values used throughout this library were not always validated. That allowed attackers to trigger, when pulling untrusted images, unexpected authenticated registry accesses on behalf of a victim user.
In less common uses of this library (using other transports or not using the containers/image/v5/copy.Image API), an attacker could also trigger local path traversals or crashes.


Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
â™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.


 If you want to rebase/retry this PR, check this box


This PR was generated by Mend Renovate. View the repository job log.
2 files changed
tree: eb9c36c37bf269bf87f8a0bdd8fef059f83c3c71
  1. .github/
  2. atmosphere/
  3. build/
  4. charts/
  5. cmd/
  6. doc/
  7. hack/
  8. images/
  9. internal/
  10. meta/
  11. molecule/
  12. playbooks/
  13. plugins/
  14. roles/
  15. tests/
  16. tools/
  17. zuul.d/
  18. .ansible-lint
  19. .charts.yml
  20. .envrc
  21. .flake8
  22. .gitignore
  23. .pre-commit-config.yaml
  24. .python-version
  25. .stestr.conf
  26. CHANGELOG.md
  27. Dockerfile
  28. Earthfile
  29. flake.lock
  30. flake.nix
  31. galaxy.yml
  32. go.mod
  33. go.sum
  34. README.md
  35. requirements.txt
  36. setup.cfg
  37. setup.py
  38. tox.ini
README.md

Atmosphere

Community

If you have any questions and discussions about Atmosphere, you can join the community:

Contributing

You'll need to make sure that you have pre-commit setup and installed in your environment by running these commands::

pre-commit install --hook-type commit-msg