Skip to content

Which public CVEs are addressed in what versions? #25571

Answered by Luap99
Venefilyn asked this question in Q&A
Discussion options

You must be logged in to vote

podman-remote and podman are build from the same sources so they use the same dependencies.

How do you install podman-remote generally the distro trackers keep track of which CVE was fixed in what versions.
For upstream we patch the deps if we are aware of the CVEs of course. But most releases don't actively list all the CVE's unless they are directly for podman.

Looking in 5.4 branch the go-jose CVE's are fixed in 5.4.1, and CVE-2025-22866 is a golang CVE so it depends on the version you build with and not our upstream dependencies.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by Venefilyn
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants