mirror of
https://github.com/freedomofpress/dangerzone.git
synced 2025-04-28 18:02:38 +02:00

Some checks failed
Tests / macOS (x86_64) (push) Has been cancelled
Build dev environments / Build dev-env (debian-bookworm) (push) Has been cancelled
Build dev environments / Build dev-env (debian-bullseye) (push) Has been cancelled
Build dev environments / Build dev-env (debian-trixie) (push) Has been cancelled
Build dev environments / Build dev-env (fedora-40) (push) Has been cancelled
Build dev environments / Build dev-env (fedora-41) (push) Has been cancelled
Build dev environments / Build dev-env (ubuntu-20.04) (push) Has been cancelled
Build dev environments / Build dev-env (ubuntu-22.04) (push) Has been cancelled
Build dev environments / Build dev-env (ubuntu-24.04) (push) Has been cancelled
Build dev environments / Build dev-env (ubuntu-24.10) (push) Has been cancelled
Build dev environments / build-container-image (push) Has been cancelled
Tests / run-lint (push) Has been cancelled
Tests / build-container-image (push) Has been cancelled
Tests / Download and cache Tesseract data (push) Has been cancelled
Tests / check-reproducibility (push) Has been cancelled
Scan latest app and container / security-scan-container (push) Has been cancelled
Scan latest app and container / security-scan-app (push) Has been cancelled
Tests / windows (push) Has been cancelled
Tests / macOS (arch64) (push) Has been cancelled
Tests / build-deb (debian bookworm) (push) Has been cancelled
Tests / build-deb (debian bullseye) (push) Has been cancelled
Tests / build-deb (debian trixie) (push) Has been cancelled
Tests / build-deb (ubuntu 20.04) (push) Has been cancelled
Tests / build-deb (ubuntu 22.04) (push) Has been cancelled
Tests / build-deb (ubuntu 24.04) (push) Has been cancelled
Tests / build-deb (ubuntu 24.10) (push) Has been cancelled
Tests / install-deb (debian bookworm) (push) Has been cancelled
Tests / install-deb (debian bullseye) (push) Has been cancelled
Tests / install-deb (debian trixie) (push) Has been cancelled
Tests / install-deb (ubuntu 20.04) (push) Has been cancelled
Tests / install-deb (ubuntu 22.04) (push) Has been cancelled
Tests / install-deb (ubuntu 24.04) (push) Has been cancelled
Tests / install-deb (ubuntu 24.10) (push) Has been cancelled
Tests / build-install-rpm (fedora 40) (push) Has been cancelled
Tests / build-install-rpm (fedora 41) (push) Has been cancelled
Tests / run tests (debian bookworm) (push) Has been cancelled
Tests / run tests (debian bullseye) (push) Has been cancelled
Tests / run tests (debian trixie) (push) Has been cancelled
Tests / run tests (fedora 40) (push) Has been cancelled
Tests / run tests (fedora 41) (push) Has been cancelled
Tests / run tests (ubuntu 20.04) (push) Has been cancelled
Tests / run tests (ubuntu 22.04) (push) Has been cancelled
Tests / run tests (ubuntu 24.04) (push) Has been cancelled
Tests / run tests (ubuntu 24.10) (push) Has been cancelled
Ignore the CVE-2025-0665 vulnerability, since it's a libcurl one, and the Dangerzone container does not make network calls. Also, it seems that Debian Bookworm is not affected.
48 lines
2.1 KiB
YAML
48 lines
2.1 KiB
YAML
# This configuration file will be used to track CVEs that we can ignore for the
|
|
# latest release of Dangerzone, and offer our analysis.
|
|
|
|
ignore:
|
|
# CVE-2023-45853
|
|
# ==============
|
|
#
|
|
# Debian tracker: https://security-tracker.debian.org/tracker/CVE-2023-45853
|
|
# Verdict: Dangerzone is not affected because the zlib library in Debian is
|
|
# built in a way that is not vulnerable.
|
|
- vulnerability: CVE-2023-45853
|
|
# CVE-2024-38428
|
|
# ==============
|
|
#
|
|
# Debian tracker: https://security-tracker.debian.org/tracker/CVE-2024-38428
|
|
# Verdict: Dangerzone is not affected because it doesn't use wget in the
|
|
# container image (which also has no network connectivity).
|
|
- vulnerability: CVE-2024-38428
|
|
# CVE-2024-57823
|
|
# ==============
|
|
#
|
|
# Debian tracker: https://security-tracker.debian.org/tracker/CVE-2024-57823
|
|
# Verdict: Dangerzone is not affected. First things first, LibreOffice is
|
|
# using this library for parsing RDF metadata in a document [1], and has
|
|
# issued a fix for the vendored raptor2 package they have for other distros
|
|
# [2].
|
|
#
|
|
# On the other hand, the Debian security team has stated that this is a minor
|
|
# issue [3], and there's no fix from the developers yet. It seems that the
|
|
# Debian package is not affected somehow by this CVE, probably due to the way
|
|
# it's packaged.
|
|
#
|
|
# [1] https://wiki.documentfoundation.org/Documentation/DevGuide/Office_Development#RDF_metadata
|
|
# [2] https://cgit.freedesktop.org/libreoffice/core/commit/?id=2b50dc0e4482ac0ad27d69147b4175e05af4fba4
|
|
# [2] From https://security-tracker.debian.org/tracker/CVE-2024-57823:
|
|
#
|
|
# [bookworm] - raptor2 <postponed> (Minor issue, revisit when fixed upstream)
|
|
#
|
|
- vulnerability: CVE-2024-57823
|
|
# CVE-2025-0665
|
|
# ==============
|
|
#
|
|
# Debian tracker: https://security-tracker.debian.org/tracker/CVE-2025-0665
|
|
# Verdict: Dangerzone is not affected because the vulnerable code is not
|
|
# present in Debian Bookworm. Also, libcurl is an HTTP client, and the
|
|
# Dangerzone container does not make any network calls.
|
|
- vulnerability: CVE-2025-0665
|
|
|