Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Release cockpit-image-builder-94.3-1.el10_2 ALSA-2026:24331

未关闭
#2,715 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
25/100
Issue 类型
缺陷
描述清晰度
需要澄清
活跃度
冷清
领域
release, security

调研方向

Issue 中未标识源文件、测试或入口点。首先检查 cockpit-image-builder 软件包和列出的 lodash CVE;受影响软件包的发布版本完成更新以解决安全问题,即视为完成。

由索引模型根据 Issue 内容生成。

描述

cockpit-image-builder security update
Severity: Important
Description
The image-builder-frontend generates custom images suitable for deploying systems or uploading to the cloud. It integrates into Cockpit as a frontend for osbuild.

Security Fix(es):

  • lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)
  • lodash: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected packages:
cockpit-image-builder-94.3-1.el10_2.noarch
cockpit-image-builder-94.3-1.el10_2.noarch
cockpit-image-builder-94.3-1.el10_2.noarch
cockpit-image-builder-94.3-1.el10_2.noarch
cockpit-image-builder-94.3-1.el10_2.noarch

主要语言
没有语言数据
星标
2
派生
0
PR 合并指标
30 天内没有已合并 PR

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

AlmaLinux/updates 的其他 Issue

查看 AlmaLinux/updates 的全部 Issue

相似的 Issue

更多 Release Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。