Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

protobuf/3.27.3 package update #25350

Merged
merged 1 commit into from
Jul 31, 2024

Conversation

octo-sts[bot]
Copy link
Contributor

@octo-sts octo-sts bot commented Jul 31, 2024

@octo-sts octo-sts bot added request-version-update request for a newer version of a package automated pr labels Jul 31, 2024
Copy link
Contributor

Package protobuf: Click to expand/collapse

Package protobuf:
Added: /usr/bin/protoc-gen-upb-27.3.0
Added: /usr/bin/protoc-gen-upb_minitable-27.3.0
Added: /usr/bin/protoc-gen-upbdefs-27.3.0
Deleted: /usr/bin/protoc-gen-upb-27.2.0
Deleted: /usr/bin/protoc-gen-upb_minitable-27.2.0
Deleted: /usr/bin/protoc-gen-upbdefs-27.2.0

Package protobuf-dev: Click to expand/collapse

Package protobuf-dev:
Modified: /usr/include/google/protobuf/any.pb.h
Modified: /usr/include/google/protobuf/api.pb.h
Modified: /usr/include/google/protobuf/compiler/java/java_features.pb.h
Modified: /usr/include/google/protobuf/compiler/plugin.pb.h
Modified: /usr/include/google/protobuf/compiler/versions.h
Modified: /usr/include/google/protobuf/cpp_features.pb.h
Modified: /usr/include/google/protobuf/descriptor.pb.h
Modified: /usr/include/google/protobuf/duration.pb.h
Modified: /usr/include/google/protobuf/empty.pb.h
Modified: /usr/include/google/protobuf/field_mask.pb.h
Modified: /usr/include/google/protobuf/port.h
Modified: /usr/include/google/protobuf/runtime_version.h
Modified: /usr/include/google/protobuf/source_context.pb.h
Modified: /usr/include/google/protobuf/struct.pb.h
Modified: /usr/include/google/protobuf/stubs/common.h
Modified: /usr/include/google/protobuf/timestamp.pb.h
Modified: /usr/include/google/protobuf/type.pb.h
Modified: /usr/include/google/protobuf/wrappers.pb.h
Modified: /usr/lib/cmake/protobuf/protobuf-config-version.cmake
Modified: /usr/lib/cmake/protobuf/protobuf-module.cmake
Modified: /usr/lib/cmake/protobuf/protobuf-targets-release.cmake
Modified: /usr/lib/libupb.a
Modified: /usr/lib/libutf8_range.a
Modified: /usr/lib/libutf8_validity.a
Modified: /usr/lib/pkgconfig/protobuf-lite.pc
Modified: /usr/lib/pkgconfig/protobuf.pc

Package protoc: Click to expand/collapse

Package protoc:
Added: /usr/bin/protoc-27.3.0
Deleted: /usr/bin/protoc-27.2.0

Package libprotoc: Click to expand/collapse

Package libprotoc:
Added: /usr/lib/libprotoc.so.27.3.0
Deleted: /usr/lib/libprotoc.so.27.2.0

Package libprotobuf: Click to expand/collapse

Package libprotobuf:
Added: /usr/lib/libprotobuf.so.27.3.0
Deleted: /usr/lib/libprotobuf.so.27.2.0

Package libprotobuf-lite: Click to expand/collapse

Package libprotobuf-lite:
Added: /usr/lib/libprotobuf-lite.so.27.3.0
Deleted: /usr/lib/libprotobuf-lite.so.27.2.0

bincapz found differences: Click to expand/collapse

Changed: /tmp/wolfictl-apk-3238268210/protoc/usr/bin/protoc-27.3.0 [✅ LOW → ✅ ]

1 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-LOW ref/words/plugin references a 'plugin' plugin

Changed: /tmp/wolfictl-apk-3238268210/protobuf/usr/bin/protoc-gen-upb-27.3.0

Moved: libprotobuf-lite/var/lib/db/sbom/libprotobuf-lite-3.27.2-r0.spdx.json -> /tmp/wolfictl-apk-3238268210/libprotobuf-lite/var/lib/db/sbom/libprotobuf-lite-3.27.3-r0.spdx.json (similarity: 0.99)

Changed: /tmp/wolfictl-apk-3238268210/libprotobuf/var/lib/db/sbom/libprotobuf-3.27.3-r0.spdx.json [✅ → ⚠️ MEDIUM]

2 new behaviors

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/96102ca1ace869f7951cb01318ef

Moved: protobuf/usr/bin/protoc-gen-upb_minitable-27.2.0 -> /tmp/wolfictl-apk-3238268210/protobuf/usr/bin/protoc-gen-upb_minitable-27.3.0 (similarity: 0.99)

Changed: /tmp/wolfictl-apk-3238268210/protobuf/usr/bin/protoc-gen-upbdefs-27.3.0 [⚠️ MEDIUM → ✅ LOW]

1 new behaviors

RISK KEY DESCRIPTION EVIDENCE
+LOW ref/words/plugin references a 'plugin' plugin

2 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/3692785ae4fe2eed98aa5fd3a87e

Changed: /tmp/wolfictl-apk-3238268210/libprotobuf-lite/usr/lib/libprotobuf-lite.so.27.3.0 [⚠️ MEDIUM → ✅ LOW]

1 new behaviors

RISK KEY DESCRIPTION EVIDENCE
+LOW process/thread_local_storage Uses glibc thread local storage __tls_get_addr

2 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/3692785ae4fe2eed98aa5fd3a87e

Moved: protobuf-dev/var/lib/db/sbom/protobuf-dev-3.27.2-r0.spdx.json -> /tmp/wolfictl-apk-3238268210/protobuf-dev/var/lib/db/sbom/protobuf-dev-3.27.3-r0.spdx.json (similarity: 0.99)

Changed: /tmp/wolfictl-apk-3238268210/protoc/var/lib/db/sbom/protoc-3.27.3-r0.spdx.json

Changed: /tmp/wolfictl-apk-3238268210/protobuf/var/lib/db/sbom/protobuf-3.27.3-r0.spdx.json [✅ LOW → ⚠️ MEDIUM]

2 new behaviors

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/7b6245b5d30c484c3493b3f9abb1

1 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-LOW ref/words/plugin references a 'plugin' plugin

Changed: /tmp/wolfictl-apk-3238268210/libprotoc/usr/lib/libprotoc.so.27.3.0

10 new behaviors

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM exec/program executes external programs execvp
+MEDIUM procfs/self/exe gets executable associated to this process /proc/self/exe
+LOW encoding/base64 Supports base64 encoded strings base64
+LOW env/USER Looks up the USER name of the current user USER
getenv
+LOW exec/program/background wait for process to exit waitpid
+LOW fs/directory/create creates directories mkdir
+LOW fs/directory/remove Uses libc functions to remove directories rmdir
+LOW fs/link/read read value of a symbolic link readlink
+LOW process/thread_local_storage Uses glibc thread local storage __tls_get_addr
+LOW ref/words/plugin references a 'plugin' First file chunk returned by plugin did not
PluginProtosZ
This compiler does not support plugins
in which case the given plugin name
pluginpb
sent unparseable request to plugin
users should use the Java Lite plugin instead

1 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation

Changed: /tmp/wolfictl-apk-3238268210/libprotobuf/usr/lib/libprotobuf.so.27.3.0 [⚠️ MEDIUM → ✅ LOW]

3 new behaviors

RISK KEY DESCRIPTION EVIDENCE
+LOW compression/gzip works with gzip files gzip
+LOW encoding/base64 Supports base64 encoded strings base64
+LOW process/thread_local_storage Uses glibc thread local storage __tls_get_addr

1 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation

Changed: /tmp/wolfictl-apk-3238268210/libprotoc/var/lib/db/sbom/libprotoc-3.27.3-r0.spdx.json

@octo-sts octo-sts bot merged commit 60ada6a into main Jul 31, 2024
8 checks passed
@octo-sts octo-sts bot deleted the wolfictl-4b9fbdb4-b087-44d6-8b16-20f3244cd95d branch July 31, 2024 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant