shipwright-io/build 软件分析报告

基础信息

项目名称:shipwright-io/build

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1744627644688736256/1755966354125860864

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
Tekton Pipelines 数据伪造问题漏洞 对数据真实性的验证不充分 MPS-8qbc-otvf CVE-2023-37264 中危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
github.com/tektoncd/pipeline v0.47.4 直接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
MIT 26
BSD-3-Clause 34
Apache-2.0 60
MPL-2.0 2
BSD-2-Clause 3
ISC 3
CC-BY-SA-4.0 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
github.com/go-task/slim-sprig v0.0.0-20230315185526-52ccab3ef572 间接依赖 go
golang.org/x/oauth2 v0.12.0 间接依赖 go
github.com/go-openapi/jsonpointer v0.19.6 间接依赖 go
github.com/cyphar/filepath-securejoin v0.2.4 间接依赖 go
github.com/prometheus/client_model v0.5.0 直接依赖 go
github.com/json-iterator/go v1.1.12 间接依赖 go
github.com/go-kit/log v0.2.1 间接依赖 go
github.com/go-logr/logr v1.4.1 直接依赖 go
go.opencensus.io v0.24.0 间接依赖 go
github.com/vbatts/tar-split v0.11.3 间接依赖 go
k8s.io/code-generator v0.26.9 直接依赖 go
k8s.io/apimachinery v0.26.9 直接依赖 go
github.com/census-instrumentation/opencensus-proto v0.4.1 间接依赖 go
sigs.k8s.io/controller-runtime v0.14.6 直接依赖 go
knative.dev/pkg v0.0.0-20230221145627-8efb3485adcf 直接依赖 go
github.com/prometheus/client_golang v1.18.0 直接依赖 go
github.com/google/go-containerregistry v0.19.0 直接依赖 go
k8s.io/client-go v0.26.9 直接依赖 go
github.com/hashicorp/errwrap v1.1.0 间接依赖 go
github.com/ProtonMail/go-crypto v0.0.0-20230828082145-3c4c8a2d2371 间接依赖 go
github.com/go-git/go-git/v5 v5.11.0 直接依赖 go
github.com/cespare/xxhash/v2 v2.2.0 间接依赖 go
github.com/gogo/protobuf v1.3.2 间接依赖 go
gopkg.in/warnings.v0 v0.1.2 间接依赖 go
github.com/opencontainers/image-spec v1.1.0-rc3 间接依赖 go
github.com/spf13/pflag v1.0.5 直接依赖 go
github.com/prometheus/statsd_exporter v0.22.5 间接依赖 go
k8s.io/klog/v2 v2.90.1 间接依赖 go
github.com/evanphx/json-patch v5.6.0+incompatible 间接依赖 go
github.com/grpc-ecosystem/grpc-gateway/v2 v2.11.3 间接依赖 go
github.com/kevinburke/ssh_config v1.2.0 间接依赖 go
google.golang.org/protobuf v1.31.0 间接依赖 go
sigs.k8s.io/structured-merge-diff/v4 v4.2.3 间接依赖 go
github.com/pkg/errors v0.9.1 间接依赖 go
github.com/tektoncd/pipeline v0.47.4 直接依赖 go
github.com/davecgh/go-spew v1.1.1 间接依赖 go
github.com/docker/docker v24.0.7+incompatible 间接依赖 go
github.com/google/gnostic v0.6.9 间接依赖 go
golang.org/x/crypto v0.17.0 间接依赖 go
go.uber.org/zap v1.26.0 直接依赖 go
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da 间接依赖 go
golang.org/x/sys v0.15.0 间接依赖 go
github.com/cloudflare/circl v1.3.7 间接依赖 go
google.golang.org/genproto v0.0.0-20230711160842-782d3b101e98 间接依赖 go
github.com/inconshreveable/mousetrap v1.1.0 间接依赖 go
github.com/mitchellh/go-homedir v1.1.0 间接依赖 go
k8s.io/utils v0.0.0-20230209194617-a36077c30491 直接依赖 go
github.com/docker/docker-credential-helpers v0.7.0 间接依赖 go
golang.org/x/time v0.3.0 间接依赖 go
google.golang.org/genproto/googleapis/rpc v0.0.0-20230711160842-782d3b101e98 间接依赖 go
golang.org/x/text v0.14.0 间接依赖 go
github.com/Microsoft/go-winio v0.6.1 间接依赖 go
golang.org/x/net v0.19.0 间接依赖 go
gopkg.in/inf.v0 v0.9.1 间接依赖 go
github.com/google/go-cmp v0.6.0 间接依赖 go
github.com/docker/cli v25.0.3+incompatible 直接依赖 go
github.com/google/pprof v0.0.0-20210720184732-4bb14d4b1be1 间接依赖 go
k8s.io/api v0.26.9 直接依赖 go
gopkg.in/yaml.v2 v2.4.0 间接依赖 go
github.com/beorn7/perks v1.0.1 间接依赖 go
github.com/containerd/stargz-snapshotter/estargz v0.14.3 间接依赖 go
github.com/google/uuid v1.3.0 间接依赖 go
k8s.io/kube-openapi v0.0.0-20230308215209-15aac26d736a 间接依赖 go
github.com/emirpasic/gods v1.18.1 间接依赖 go
github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 间接依赖 go
golang.org/x/sync v0.5.0 间接依赖 go
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd 间接依赖 go
github.com/pjbgf/sha1cd v0.3.0 间接依赖 go
golang.org/x/tools v0.16.1 间接依赖 go
github.com/xanzy/ssh-agent v0.3.3 间接依赖 go
github.com/prometheus/procfs v0.12.0 间接依赖 go
github.com/go-logfmt/logfmt v0.5.1 间接依赖 go
github.com/matttproud/golang_protobuf_extensions/v2 v2.0.0 间接依赖 go
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 直接依赖 go
github.com/blendle/zapdriver v1.3.1 间接依赖 go
k8s.io/gengo v0.0.0-20221011193443-fad74ee6edd9 间接依赖 go
github.com/evanphx/json-patch/v5 v5.6.0 间接依赖 go
k8s.io/component-base v0.26.9 间接依赖 go
github.com/go-git/go-billy/v5 v5.5.0 间接依赖 go
github.com/modern-go/reflect2 v1.0.2 间接依赖 go
sigs.k8s.io/yaml v1.3.0 直接依赖 go
github.com/docker/distribution v2.8.2+incompatible 间接依赖 go
golang.org/x/mod v0.14.0 间接依赖 go
github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 间接依赖 go
golang.org/x/term v0.15.0 间接依赖 go
github.com/sergi/go-diff v1.2.0 间接依赖 go
github.com/imdario/mergo v0.3.15 间接依赖 go
github.com/golang/protobuf v1.5.3 间接依赖 go
gopkg.in/yaml.v3 v3.0.1 间接依赖 go
github.com/josharian/intern v1.0.0 间接依赖 go
github.com/klauspost/compress v1.16.5 间接依赖 go
github.com/emicklei/go-restful/v3 v3.9.0 间接依赖 go
gomodules.xyz/jsonpatch/v2 v2.2.0 间接依赖 go
github.com/mailru/easyjson v0.7.7 间接依赖 go
google.golang.org/api v0.122.0 间接依赖 go
k8s.io/kubectl v0.26.9 直接依赖 go
github.com/hashicorp/go-multierror v1.1.1 间接依赖 go
github.com/golang-jwt/jwt/v4 v4.5.0 直接依赖 go
github.com/go-openapi/swag v0.22.3 间接依赖 go
github.com/google/gofuzz v1.2.0 间接依赖 go
k8s.io/apiextensions-apiserver v0.26.9 直接依赖 go
dario.cat/mergo v1.0.0 间接依赖 go
github.com/onsi/ginkgo/v2 v2.15.0 直接依赖 go
google.golang.org/grpc v1.58.3 间接依赖 go
google.golang.org/appengine v1.6.7 间接依赖 go
github.com/prometheus/common v0.45.0 间接依赖 go
github.com/go-openapi/jsonreference v0.20.1 间接依赖 go
golang.org/x/exp v0.0.0-20230307190834-24139beb5833 间接依赖 go
github.com/spf13/cobra v1.8.0 直接依赖 go
contrib.go.opencensus.io/exporter/prometheus v0.4.1 间接依赖 go
github.com/onsi/gomega v1.31.1 直接依赖 go
google.golang.org/genproto/googleapis/api v0.0.0-20230711160842-782d3b101e98 间接依赖 go
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd 间接依赖 go
github.com/opencontainers/go-digest v1.0.0 间接依赖 go
github.com/skeema/knownhosts v1.2.1 间接依赖 go
go.uber.org/multierr v1.10.0 间接依赖 go
github.com/go-logr/zapr v1.2.3 间接依赖 go
github.com/fsnotify/fsnotify v1.6.0 间接依赖 go
github.com/sirupsen/logrus v1.9.1 间接依赖 go
contrib.go.opencensus.io/exporter/ocagent v0.7.1-0.20200907061046-05415f1de66d 间接依赖 go
go.uber.org/atomic v1.10.0 间接依赖 go
(0)
上一篇 2024年2月9日
下一篇 2024年2月9日

相关推荐

  • yenoiwesa/homebridge-connexoon 软件分析报告

    基础信息 项目名称:yenoiwesa/homebridge-connexoon 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721660740104396800/1721660740146339840 此报告…

    软件分析 2023年11月7日
    0
  • dotnet-architecture/eShopOnContainers 软件分析报告

    基础信息 项目名称:dotnet-architecture/eShopOnContainers 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721142101994967040/1725783939106693…

    软件分析 2023年11月18日
    0
  • capnproto/capnproto 软件分析报告

    基础信息 项目名称:capnproto/capnproto 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716568888329420800/1716568888501387264 此报告由Murphysec提…

    软件分析 2023年10月24日
    0
  • ibireme/YYKit 软件分析报告

    基础信息 项目名称:ibireme/YYKit 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721271011696476160/1728325065596428288 此报告由Murphysec提供 漏洞列表…

    软件分析 2023年11月25日
    0
  • Jean-PhilippeDESCAMPS/AppleWatchSimulateur 软件分析报告

    基础信息 项目名称:Jean-PhilippeDESCAMPS/AppleWatchSimulateur 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1719045356188729344/17190453563…

    软件分析 2023年10月31日
    0