Skip to content

Commit 3e61580

Browse files
fix(sonarqube): Remediate GHSA-m9gh-789g-q5pv (#76769)
Cherry pick c6894b30d37bcfb0d093a3bffb8a31744ca2b489 to bump Elasticsearch to 8.19.8 and reemdiate GHSA-m9gh-789g-q5pv Signed-off-by: Ankush Pathak <ankush.pathak@chainguard.dev> <!--ci-cve-scan:must-fix: GHSA-m9gh-789g-q5pv--> Signed-off-by: Ankush Pathak <ankush.pathak@chainguard.dev>
1 parent 715474d commit 3e61580

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

sonarqube.yaml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
package:
22
name: sonarqube
33
version: "25.12.0.117093"
4-
epoch: 0
4+
epoch: 1 # GHSA-m9gh-789g-q5pv
55
description: SonarQube is an open source platform for continuous inspection of code quality (Community Build)
66
copyright:
77
- license: LGPL-3.0-or-later
@@ -41,6 +41,8 @@ pipeline:
4141
repository: https://github.com/SonarSource/sonarqube
4242
tag: ${{package.version}}
4343
expected-commit: bd7a1254715e0df950e61d05c9a07cb1ba42552b
44+
cherry-picks: |
45+
master/c6894b30d37bcfb0d093a3bffb8a31744ca2b489: GHSA-m9gh-789g-q5pv
4446
4547
- name: build
4648
runs: |

0 commit comments

Comments
 (0)