[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2024:0460-1 -- SLES rekor

ID: oval:org.secpod.oval:def:89051455Date: (C)2024-04-26   (M)2024-05-06
Class: PATCHFamily: unix




This update for rekor fixes the following issues: update to 1.3.5 : * Additional unique index correction * Remove timestamp from checkpoint * Drop conditional when verifying entry checkpoint * Fix panic for DSSE canonicalization * Change Redis value for locking mechanism * give log timestamps nanosecond precision * output trace in slog and override correlation header name * bumped embedded golang.org/x/crypto/ssh to fix the Terrapin attack CVE-2023-48795 Updated to 1.3.4: * add mysql indexstorage backend * add s3 storage for attestations * fix: Do not check for pubsub.topics.get on initialization * fix optional field in cose schema * Update ranges.go * update indexstorage interface to reduce roundtrips * use a single validator library in rekor-cli * Remove go-playground/validator dependency from pkg/pki Updated to rekor 1.3.3 : * Update signer flag description * update trillian to 1.5.3 * adds redis_auth * Add method to get artifact hash for an entry * make e2e tests more usable with docker-compose * install go at correct version for codeql Updated to rekor 1.3.2 : Updated to rekor 1.3.1 : New Features: * enable GCP cloud profiling on rekor-server * move index storage into interface * add info to readme to denote additional documentation sources * Add type of ed25519 key for TUF * Allow parsing base64-encoded TUF metadata and root content Quality Enhancements: * disable quota in trillian in test harness Bug Fixes: * Update contact for code of conduct * Fix panic when parsing SSH SK pubkeys * Correct index creation * docs: fixzes a small typo on the readme * chore: fix backfill-redis Makefile target Updated to rekor 1.3.0 : * Update openapi.yaml * pass transient errors through retrieveLogEntry * return full entryID on HTTP 409 responses * feat: Support publishing new log entries to Pub/Sub topics * Change values of Identity.Raw, add fingerprints * Extract all subjects from SANs for x509 verifier * Fix type comment for Identity struct * Refactor Identities API * Refactor Verifiers to return multiple keys * Update checkpoint link * Use correct log index in inclusion proof * remove instrumentation library Updated to rekor 1.2.2 : * pass down error with message instead of nil * swap killswitch for "docker-compose restart" * CVE-2023-48795: Fixed Terrapin attack in embedded golang.org/x/crypto/ssh .

Platform:
SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise Server 15 SP5
Product:
rekor
Reference:
SUSE-SU-2024:0460-1
CVE-2023-48795
CVE    1
CVE-2023-48795

© SecPod Technologies