From ec0f0435fa4d3dd8756c4f362e92eb42ee14f2c6 Mon Sep 17 00:00:00 2001 From: Dongsu Park Date: Fri, 5 Jan 2024 12:17:30 +0100 Subject: [PATCH] overlay profiles: accept keywords of app-misc/jq 1.7.1 We need to accept keywords for both arches to address CVE-2023-50246, CVE-2023-50268. --- .../profiles/coreos/base/package.accept_keywords | 3 +++ 1 file changed, 3 insertions(+) diff --git a/sdk_container/src/third_party/coreos-overlay/profiles/coreos/base/package.accept_keywords b/sdk_container/src/third_party/coreos-overlay/profiles/coreos/base/package.accept_keywords index 51ab420c0b..046c4ec86c 100644 --- a/sdk_container/src/third_party/coreos-overlay/profiles/coreos/base/package.accept_keywords +++ b/sdk_container/src/third_party/coreos-overlay/profiles/coreos/base/package.accept_keywords @@ -31,6 +31,9 @@ # Keep versions on both arches in sync. =app-misc/pax-utils-1.3.7 ~amd64 +# Needed for addressing CVE-2023-50246, CVE-2023-50268 +=app-misc/jq-1.7.1 ~amd64 ~arm64 + # Required for addressing CVE-2022-3715. =app-shells/bash-5.2_p15-r7 ~amd64 ~arm64