Skip to content

chore(deps): refresh rpm lockfiles [SECURITY]#3184

Merged
red-hat-konflux[bot] merged 1 commit intorelease-3.24from
konflux/mintmaker/release-3.24/lock-file-maintenance-vulnerability
Apr 15, 2026
Merged

chore(deps): refresh rpm lockfiles [SECURITY]#3184
red-hat-konflux[bot] merged 1 commit intorelease-3.24from
konflux/mintmaker/release-3.24/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux
Copy link
Copy Markdown
Contributor

@red-hat-konflux red-hat-konflux bot commented Apr 2, 2026

This PR contains the following updates:

File rpms.in.yaml:

Package Change
kpartx 0.8.4-42.el8_10 -> 0.8.4-43.el8_10
libnghttp2 1.33.0-6.el8_10.1 -> 1.33.0-6.el8_10.2
sed 4.5-5.el8 -> 4.5-5.el8_10

nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination

CVE-2026-27135

More information

Details

A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 frame, leading to an assertion failure and a denial of service (DoS).

Severity

Important

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" in timezone Etc/UTC, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux red-hat-konflux bot enabled auto-merge (squash) April 2, 2026 17:58
@red-hat-konflux red-hat-konflux bot requested review from a team and rhacs-bot as code owners April 2, 2026 17:58
Copy link
Copy Markdown
Contributor

@rhacs-bot rhacs-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

Copy link
Copy Markdown
Contributor

@rhacs-bot rhacs-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by automation.

@codecov-commenter
Copy link
Copy Markdown

codecov-commenter commented Apr 2, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 27.38%. Comparing base (77c6480) to head (d50e94c).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@              Coverage Diff              @@
##           release-3.24    #3184   +/-   ##
=============================================
  Coverage         27.38%   27.38%           
=============================================
  Files                95       95           
  Lines              5427     5427           
  Branches           2548     2548           
=============================================
  Hits               1486     1486           
  Misses             3214     3214           
  Partials            727      727           
Flag Coverage Δ
collector-unit-tests 27.38% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/release-3.24/lock-file-maintenance-vulnerability branch from 6d1645f to 8fd8155 Compare April 13, 2026 14:34
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/release-3.24/lock-file-maintenance-vulnerability branch from 8fd8155 to d50e94c Compare April 15, 2026 10:13
@github-actions
Copy link
Copy Markdown

/retest collector-on-push

2 similar comments
@github-actions
Copy link
Copy Markdown

/retest collector-on-push

@github-actions
Copy link
Copy Markdown

/retest collector-on-push

@red-hat-konflux red-hat-konflux bot merged commit 8b6254f into release-3.24 Apr 15, 2026
69 of 75 checks passed
@red-hat-konflux red-hat-konflux bot deleted the konflux/mintmaker/release-3.24/lock-file-maintenance-vulnerability branch April 15, 2026 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants