os icon indicating copy to clipboard operation
os copied to clipboard

pax-utils/1.3.8 package update

Open octo-sts[bot] opened this issue 1 year ago • 2 comments

octo-sts[bot] avatar Sep 23 '24 14:09 octo-sts[bot]

Open AI suggestions to solve the build error:

The error message is: "ERROR: failed to build package. the build environment has been preserved:
INFO   workspace dir: /temp/melange-workspace-1189690670
INFO   guest dir: /temp/melange-guest-371689043
ERRO failed to build package: unable to run package pax-utils pipeline: unable to run pipeline: unable to run pipeline: exit status 1
make[1]: *** [Makefile:111: packages/aarch64/pax-utils-1.3.8-r0.apk] Error 1
make[1]: Leaving directory '/github/home'
make: *** [Makefile:101: package/pax-utils] Error 2
##[error]Process completed with exit code 2."

1. Verify dependencies for pax-utils are installed.
2. Check the Makefile for correct paths and targets.
3. Ensure the build environment is correctly set up.
4. Run `make clean` to clear previous builds.
5. Re-run the build command with increased verbosity for more details.
6. Check for any specific logs in `/temp/melange-workspace-1189690670` and `/temp/melange-guest-371689043`.

octo-sts[bot] avatar Sep 23 '24 14:09 octo-sts[bot]

Open AI suggestions to solve the build error:

The error message is: "WARN porting.h:14:10: fatal error: config.h: No such file or directory"

1. Verify that `config.h` exists in the project directory.
2. Ensure the include path is correctly set in your build configuration (e.g., Makefile, CMakeLists.txt).
3. If `config.h` is generated, confirm the generation step is executed before compilation.
4. Check for any conditional compilation that might exclude `config.h`.
5. Rebuild the project to ensure all dependencies are correctly resolved.

octo-sts[bot] avatar Sep 24 '24 23:09 octo-sts[bot]

  • pax-utils builds scanelf package
  • pax-utils is trying to use meson build system
  • packages used to build meson call strip pipeline
  • strip pipeline uses scanelf to find packages
  • thus a cycle is created, to build scanelf (from pax-utils package) one needs scanelf
  • becausing stripping things is optional, we can create a bootstrap scanelf, which is simply /bin/true
  • it means initial set of packages will be unstripped until one gets to scanelf

cc @jonjohnsonjr @smoser the solution is to create pax-utils-bootstrap.yaml which provide pax-utils and scanelf at lower priority than real pax-utils. This allows to use "strip" pipeline in bootstrap, whilst one doesn't yet have a real scanelf. It does mean that initial set of packages potentially will be under-stripped. Which for bootstrap purposes is fine.

See https://github.com/wolfi-dev/os/pull/29169/commits/994941353b2437eedd7026771c49cc348c8618c9

xnox avatar Oct 14 '24 15:10 xnox

Package py3.10-pyelftools: Click to expand/collapse

Package py3.10-pyelftools: Modified: /usr/lib/python3.10/site-packages/elftools/elf/pycache/structs.cpython-310.pyc

Package py3.13-pyelftools-bin: Click to expand/collapse

Package py3.13-pyelftools-bin: Unchanged

Package py3-supported-pyelftools: Click to expand/collapse

Package py3-supported-pyelftools: Unchanged

Package py3-pyelftools: Click to expand/collapse

Package py3-pyelftools: Unchanged

Package py3-wheels-pyelftools: Click to expand/collapse

Package py3-wheels-pyelftools: Unchanged

Package py3.12-pyelftools-bin: Click to expand/collapse

Package py3.12-pyelftools-bin: Unchanged

Package pax-utils: Click to expand/collapse

Package pax-utils: Added: /usr/bin/lddtree Modified: /usr/bin/dumpelf Modified: /usr/bin/pspax Modified: /usr/bin/scanmacho Deleted: /usr/share/doc/pax-utils/BUGS Deleted: /usr/share/doc/pax-utils/README.md Deleted: /usr/share/doc/pax-utils/TODO

Package py3.11-pyelftools: Click to expand/collapse

Package py3.11-pyelftools: Unchanged

Package py3.12-pyelftools: Click to expand/collapse

Package py3.12-pyelftools: Modified: /usr/lib/python3.12/site-packages/elftools/pycache/init.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/common/pycache/init.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/common/pycache/construct_utils.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/common/pycache/exceptions.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/common/pycache/utils.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/construct/pycache/init.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/construct/pycache/adapters.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/construct/pycache/core.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/construct/pycache/debug.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/construct/pycache/macros.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/construct/lib/pycache/init.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/construct/lib/pycache/binary.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/construct/lib/pycache/bitstream.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/construct/lib/pycache/container.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/construct/lib/pycache/hex.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/construct/lib/pycache/py3compat.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/init.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/abbrevtable.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/aranges.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/callframe.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/compileunit.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/constants.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/datatype_cpp.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/descriptions.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/die.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/dwarf_expr.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/dwarf_util.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/dwarfinfo.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/enums.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/lineprogram.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/locationlists.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/namelut.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/ranges.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/dwarf/pycache/structs.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/ehabi/pycache/init.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/ehabi/pycache/constants.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/ehabi/pycache/decoder.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/ehabi/pycache/ehabiinfo.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/ehabi/pycache/structs.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/init.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/constants.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/descriptions.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/dynamic.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/elffile.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/enums.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/gnuversions.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/hash.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/notes.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/relocation.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/sections.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/segments.cpython-312.pyc Modified: /usr/lib/python3.12/site-packages/elftools/elf/pycache/structs.cpython-312.pyc

Package py3.11-pyelftools-bin: Click to expand/collapse

Package py3.11-pyelftools-bin: Unchanged

Package pax-utils-bootstrap: Click to expand/collapse

Package pax-utils-bootstrap: Added: /.PKGINFO

Package py3.13-pyelftools: Click to expand/collapse

Package py3.13-pyelftools: Modified: /usr/lib/python3.13/site-packages/elftools/construct/pycache/adapters.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/construct/pycache/core.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/construct/pycache/debug.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/construct/lib/pycache/bitstream.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/construct/lib/pycache/container.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/abbrevtable.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/aranges.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/callframe.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/compileunit.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/datatype_cpp.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/descriptions.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/die.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/dwarfinfo.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/lineprogram.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/locationlists.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/namelut.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/ranges.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/dwarf/pycache/structs.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/ehabi/pycache/decoder.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/ehabi/pycache/ehabiinfo.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/ehabi/pycache/structs.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/elf/pycache/dynamic.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/elf/pycache/elffile.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/elf/pycache/gnuversions.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/elf/pycache/hash.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/elf/pycache/relocation.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/elf/pycache/sections.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/elf/pycache/segments.cpython-313.pyc Modified: /usr/lib/python3.13/site-packages/elftools/elf/pycache/structs.cpython-313.pyc

Package py3.10-pyelftools-bin: Click to expand/collapse

Package py3.10-pyelftools-bin: Unchanged

Package scanelf: Click to expand/collapse

Package scanelf: Modified: /usr/bin/scanelf

malcontent found differences: Click to expand/collapse

Deleted: py3.10-pyelftools/var/lib/db/sbom/py3.10-pyelftools-0.31-r1.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/fdad7aed24f39259167eb7e4cfa3

Deleted: py3-pyelftools/var/lib/db/sbom/py3-pyelftools-0.31-r1.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/ae4ff6bdcbcca6eb3feb66adb14a

Deleted: py3.11-pyelftools-bin/var/lib/db/sbom/py3.11-pyelftools-bin-0.31-r1.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/98afe98e4786704a5898f15aee2a

Deleted: py3.12-pyelftools-bin/var/lib/db/sbom/py3.12-pyelftools-bin-0.31-r1.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/5b0297d381b9eba33d3100e7fa0b

Deleted: py3.13-pyelftools/var/lib/db/sbom/py3.13-pyelftools-0.31-r1.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/b39e95e496fee594b9670ec5baf3

Deleted: py3.11-pyelftools/var/lib/db/sbom/py3.11-pyelftools-0.31-r1.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/f653973780ec30d80e8625043361

Deleted: py3-supported-pyelftools/var/lib/db/sbom/py3-supported-pyelftools-0.31-r1.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/50da51c3fc1a8f139e8c53bb7239

Deleted: py3.10-pyelftools-bin/var/lib/db/sbom/py3.10-pyelftools-bin-0.31-r1.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/3daf0e173db191fded249e5e7fd3

Deleted: py3.13-pyelftools-bin/var/lib/db/sbom/py3.13-pyelftools-bin-0.31-r1.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/34a563c77dfb729fef1d2c3d63c8

Deleted: py3-wheels-pyelftools/var/lib/db/sbom/py3-wheels-pyelftools-0.31-r1.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/7575f1d9ddba4c887b1436f07a84

Deleted: pax-utils/var/lib/db/sbom/pax-utils-1.3.7-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/84fd5d4f2424719685f90fa165f4

Deleted: py3.12-pyelftools/var/lib/db/sbom/py3.12-pyelftools-0.31-r1.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/db965a5512432b472089825200ac

Added: pax-utils/var/lib/db/sbom/pax-utils-1.3.8-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/5fc9f41596717e76305d9248db76

Added: py3.10-pyelftools-bin/var/lib/db/sbom/py3.10-pyelftools-bin-0.31-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/f5d91b976e36b2f466e2176df32b

Added: py3.11-pyelftools-bin/var/lib/db/sbom/py3.11-pyelftools-bin-0.31-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/a834e26c6ad88b47d7bf9d68c17f

Added: py3-wheels-pyelftools/var/lib/db/sbom/py3-wheels-pyelftools-0.31-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/fa8851b34e43b9e662bea1e1e92e

Added: py3.13-pyelftools-bin/var/lib/db/sbom/py3.13-pyelftools-bin-0.31-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/1c841f51a66bc87441a59387847a

Added: pax-utils-bootstrap/var/lib/db/sbom/pax-utils-bootstrap-1.3.8-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/25e8fe28046f172a1163da17b193

Added: py3.13-pyelftools/var/lib/db/sbom/py3.13-pyelftools-0.31-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/1415e4fb65734abfbd72891984d1

Added: py3-pyelftools/var/lib/db/sbom/py3-pyelftools-0.31-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/c272c77437146a645cb3a15bb84d

Added: py3.11-pyelftools/var/lib/db/sbom/py3.11-pyelftools-0.31-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/db3f484f1270fd97fc5ff377547b

Added: py3-supported-pyelftools/var/lib/db/sbom/py3-supported-pyelftools-0.31-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/09c47f4c287d15c8410ed3487156

Added: py3.12-pyelftools-bin/var/lib/db/sbom/py3.12-pyelftools-bin-0.31-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/10b8119406ae54230896f4f577a7

Added: py3.10-pyelftools/var/lib/db/sbom/py3.10-pyelftools-0.31-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/5525f2e6b8842f2925c7958e5c31

Added: pax-utils/usr/bin/lddtree [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM combo/recon/system_network invasive recon val lspci
+MEDIUM fs/file/read opens a binary file for read open(interp, "rb")
open(path, "rb")
open(target, "rb")
+MEDIUM fs/permission/modify modifies file permissions chmod
+MEDIUM net/fetch Invokes curl curl will dlopen
+MEDIUM ref/path/root path reference within /root /root/bin/bash.
/root/bin/sh
+MEDIUM ref/words/exclamation gets very excited circular loop !!!
+MEDIUM shell/exec executes shell /bin/bash $PWD
/bin/bash and then resolve
/bin/bash rather than a plain
/bin/sh into $PWD
+LOW env/LD_LIBRARY_PATH ld library path LD_LIBRARY_PATH
+LOW fs/directory/create creates directories os.makedirs
+LOW fs/directory/list Uses /bin/ls list a directory /bin/ls
+LOW fs/file/delete deletes files unlink
+LOW fs/file/open opens files open(
+LOW fs/link/read read value of a symbolic link readlink
+LOW fs/symlink/resolve resolves symbolic links realpath
+LOW ref/path/etc path reference within /etc /etc/ld.so.conf.
+LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env
/usr/bin/lsof.
+LOW ref/path/usr/sbin path reference within /usr/sbin /usr/sbin/lspci

Added: py3.12-pyelftools/var/lib/db/sbom/py3.12-pyelftools-0.31-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/2b334ad1bca07b2d99deef094a47

Changed: /tmp/wolfictl-apk-2375186532/py3.12-pyelftools/usr/lib/python3.12/site-packages/elftools/elf/enums.py

Changed: /tmp/wolfictl-apk-2375186532/py3.13-pyelftools/usr/lib/python3.13/site-packages/elftools/elf/enums.py

Changed: /tmp/wolfictl-apk-2375186532/py3.11-pyelftools/usr/lib/python3.11/site-packages/elftools/dwarf/constants.py

Changed: /tmp/wolfictl-apk-2375186532/py3.12-pyelftools/usr/lib/python3.12/site-packages/elftools/dwarf/enums.py

Changed: /tmp/wolfictl-apk-2375186532/py3.12-pyelftools/usr/lib/python3.12/site-packages/elftools/ehabi/decoder.py

Changed: /tmp/wolfictl-apk-2375186532/py3.13-pyelftools/usr/lib/python3.13/site-packages/elftools/ehabi/decoder.py

Changed: /tmp/wolfictl-apk-2375186532/py3.13-pyelftools/usr/lib/python3.13/site-packages/elftools/dwarf/dwarf_expr.py

Changed: /tmp/wolfictl-apk-2375186532/py3.11-pyelftools/usr/lib/python3.11/site-packages/elftools/dwarf/enums.py

Changed: /tmp/wolfictl-apk-2375186532/py3.13-pyelftools/usr/lib/python3.13/site-packages/elftools/elf/constants.py

Changed: /tmp/wolfictl-apk-2375186532/py3.12-pyelftools/usr/lib/python3.12/site-packages/elftools/elf/constants.py

Changed: /tmp/wolfictl-apk-2375186532/py3.10-pyelftools/usr/lib/python3.10/site-packages/elftools/elf/enums.py

Changed: /tmp/wolfictl-apk-2375186532/py3.10-pyelftools/usr/lib/python3.10/site-packages/elftools/dwarf/enums.py

Changed: /tmp/wolfictl-apk-2375186532/py3.13-pyelftools/usr/lib/python3.13/site-packages/elftools/dwarf/constants.py

Changed: /tmp/wolfictl-apk-2375186532/py3.13-pyelftools/usr/lib/python3.13/site-packages/elftools/dwarf/enums.py

Changed: /tmp/wolfictl-apk-2375186532/py3.10-pyelftools/usr/lib/python3.10/site-packages/elftools/dwarf/constants.py

Changed: /tmp/wolfictl-apk-2375186532/py3.11-pyelftools/usr/lib/python3.11/site-packages/elftools/elf/constants.py

Changed: /tmp/wolfictl-apk-2375186532/py3.11-pyelftools/usr/lib/python3.11/site-packages/elftools/elf/enums.py

Changed: /tmp/wolfictl-apk-2375186532/py3.12-pyelftools/usr/lib/python3.12/site-packages/elftools/dwarf/constants.py

Changed: /tmp/wolfictl-apk-2375186532/py3.10-pyelftools/usr/lib/python3.10/site-packages/elftools/elf/constants.py

Changed: /tmp/wolfictl-apk-2375186532/py3.10-pyelftools/usr/lib/python3.10/site-packages/elftools/ehabi/decoder.py

Changed: /tmp/wolfictl-apk-2375186532/py3.11-pyelftools/usr/lib/python3.11/site-packages/elftools/ehabi/decoder.py

Changed: /tmp/wolfictl-apk-2375186532/py3.11-pyelftools/usr/lib/python3.11/site-packages/elftools/dwarf/dwarf_expr.py

Changed: /tmp/wolfictl-apk-2375186532/py3.12-pyelftools/usr/lib/python3.12/site-packages/elftools/dwarf/dwarf_expr.py

Changed: /tmp/wolfictl-apk-2375186532/py3.10-pyelftools/usr/lib/python3.10/site-packages/elftools/dwarf/dwarf_expr.py

Moved: scanelf/var/lib/db/sbom/scanelf-1.3.7-r2.spdx.json -> /tmp/wolfictl-apk-2375186532/scanelf/var/lib/db/sbom/scanelf-1.3.8-r0.spdx.json (similarity: 0.98)

github-actions[bot] avatar Oct 14 '24 16:10 github-actions[bot]

Package pax-utils-bootstrap: Click to expand/collapse

Package pax-utils-bootstrap: Added: /.PKGINFO

Package pax-utils: Click to expand/collapse

Package pax-utils: Added: /usr/bin/lddtree Modified: /usr/bin/dumpelf Modified: /usr/bin/pspax Modified: /usr/bin/scanmacho Deleted: /usr/share/doc/pax-utils/BUGS Deleted: /usr/share/doc/pax-utils/README.md Deleted: /usr/share/doc/pax-utils/TODO

Package scanelf: Click to expand/collapse

Package scanelf: Modified: /usr/bin/scanelf

malcontent found differences: Click to expand/collapse

Deleted: scanelf/var/lib/db/sbom/scanelf-1.3.7-r2.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/adbceed2d512997e00a15d48a3ed

Added: pax-utils-bootstrap/var/lib/db/sbom/pax-utils-bootstrap-1.3.8-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/25e8fe28046f172a1163da17b193

Added: pax-utils/usr/bin/lddtree [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM combo/recon/system_network invasive recon val lspci
+MEDIUM fs/file/read opens a binary file for read open(interp, "rb")
open(path, "rb")
open(target, "rb")
+MEDIUM fs/permission/modify modifies file permissions chmod
+MEDIUM net/fetch Invokes curl curl will dlopen
+MEDIUM ref/path/root path reference within /root /root/bin/bash.
/root/bin/sh
+MEDIUM ref/words/exclamation gets very excited circular loop !!!
+MEDIUM shell/exec executes shell /bin/bash $PWD
/bin/bash and then resolve
/bin/bash rather than a plain
/bin/sh into $PWD
+LOW env/LD_LIBRARY_PATH ld library path LD_LIBRARY_PATH
+LOW fs/directory/create creates directories os.makedirs
+LOW fs/directory/list Uses /bin/ls list a directory /bin/ls
+LOW fs/file/delete deletes files unlink
+LOW fs/file/open opens files open(
+LOW fs/link/read read value of a symbolic link readlink
+LOW fs/symlink/resolve resolves symbolic links realpath
+LOW ref/path/etc path reference within /etc /etc/ld.so.conf.
+LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env
/usr/bin/lsof.
+LOW ref/path/usr/sbin path reference within /usr/sbin /usr/sbin/lspci

Added: scanelf/var/lib/db/sbom/scanelf-1.3.8-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/2f50a91e05a549a613668b4c0d23

Moved: pax-utils/var/lib/db/sbom/pax-utils-1.3.7-r2.spdx.json -> /tmp/wolfictl-apk-1199200401/pax-utils/var/lib/db/sbom/pax-utils-1.3.8-r0.spdx.json (similarity: 0.98)

github-actions[bot] avatar Oct 14 '24 16:10 github-actions[bot]