[ELSA-2023-2283] skopeo security and bug fix update

Severity Moderate
Affected Packages 2
CVEs 2

- update to the latest content of https://github.com/containers/skopeo/tree/release-1.11
- Related: #2124478

- update to https://github.com/containers/skopeo/releases/tag/v1.11.1
- Related: #2124478

- update to 1.11.0 release
- Related: #2124478

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2124478

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2124478

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2124478

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2124478

- update to https://github.com/containers/skopeo/releases/tag/v1.10.0
- Related: #2124478

- update to https://github.com/containers/skopeo/releases/tag/v1.9.3
- Related: #2124478

- update to https://github.com/containers/skopeo/releases/tag/v1.9.2
- Related: #2061316

- update to https://github.com/containers/skopeo/releases/tag/v1.9.1
- Related: #2061316

- update to https://github.com/containers/skopeo/releases/tag/v1.9.0
- Related: #2061316

- Re-enable debuginfo
- Related: #2061316

- BuildRequires: /usr/bin/go-md2man
- Related: #2061316

- enable LTO
- Related: #1988128

- update to https://github.com/containers/skopeo/releases/tag/v1.8.0
- Related: #2061316

- update to https://github.com/containers/skopeo/releases/tag/v1.7.0
- Related: #2061316

- add tags: classic (Ed Santiago)
- Related: #2061316

- remove BATS from required packages (Ed Santiago)
- Related: #2061316

- be sure to install BATS before gating tests are executed
(thanks to Ed Santiago)
- Related: #2061316

- update to https://github.com/containers/skopeo/releases/tag/v1.6.1
- Related: #2000051

- update to https://github.com/containers/skopeo/releases/tag/v1.6.0
- Related: #2000051

- update to https://github.com/containers/skopeo/releases/tag/v1.5.2
- Related: #2000051

- update to https://github.com/containers/skopeo/releases/tag/v1.5.1
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- bump Epoch to preserve upgrade patch from RHEL8
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- add skopeo tests from Fedora
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- add gating.yaml
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- update to the latest content of https://github.com/containers/skopeo/tree/main
- Related: #2000051

- rebuild with containers-common dep fixed
- Related: #2000051

- Rebuilt for IMA sigs, glibc 2.34, aarch64 flags
Related: rhbz#1991688

- be sure short-name-mode is permissive in RHEL8
- Related: #1970747

- don't define short-name-mode in RHEL8
- Related: #1970747

- put both RHEL8 and RHEL9 conditional configurations into update.sh
- Related: #1970747

- update vendored components
- always require runc on RHEL8 or lesser
- Related: #1970747

- update to the latest content of https://github.com/containers/skopeo/tree/release-1.4
- Related: #1970747

- update to 1.4.0 release and switch to the release-1.4 maint branch
- Related: #1970747

- update vendored components
- ship /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release only on non-RHEL and
CentOS distros
- Related: #1970747

- switch to the main branch of skopeo
- Related: #1970747

- Add support for signed RHEL images, enabled by default
- Related: #1970747

- update seccomp.json from Fedora to allow clone3 to pass
- Related: #1970747

- update shortnames from Pyxis
- put RHEL9/UBI9 images into overrides
- Related: #1970747

- correct name of the option is 'short-name-mode' not 'short-names-mode'
- Related: #1970747

- handle CentOS Stream while updating vendored components
- Related: #1970747

- update to the latest content of https://github.com/containers/skopeo/tree/release-1.3
- Related: #1970747

- update registries.conf to be consistent with upstream
- Related: #1970747

- consume content from the release-1.3 upstream branch
- Related: #1970747

- update to https://github.com/containers/skopeo/releases/tag/v1.3.1
- Related: #1970747

- Rebuilt for RHEL 9 BETA for openssl 3.0
Related: rhbz#1971065

- set short-names-mode = 'enforcing' in registries.conf
- Resolves: #1971752

- configure for RHEL9
- Related: #1970747

- add missing containers-mounts.conf.5.md file to git
- don't list/install the same doc twice
- Related: #1970747

- update to new versions of vendored components
- fail is there is an issue in communication with Pyxis API
- understand devel branch in update.sh script, use pkg wrapper
- sync with Pyxis
- use containers-mounts.conf.5.md from containers/common
- Related: #1970747

- Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937

- disable LTO again

- use rhel-shortnames only from trusted registries
- sync with config files from current versions of vendored projects

(16 months ago)
(16 months ago)
Copyright 2023 Oracle, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/skopeo?distro=oraclelinux-9 oraclelinux skopeo < 1.11.2-0.1.el9 oraclelinux-9
Affected pkg:rpm/oraclelinux/skopeo-tests?distro=oraclelinux-9 oraclelinux skopeo-tests < 1.11.2-0.1.el9 oraclelinux-9
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date