fix(forgejo): update to 16.0.4 for two security fixes #760
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/forgejo-16.0.4"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Forgejo 16.0.2 → 16.0.4 on the cluster. 16.0.4 is a security release: an RCE
through template expansion (a malicious template repo creating a
.gitfolderduring variable expansion, reading arbitrary data and running processes on the
host) and an authorization bypass letting a repo-scoped API token edit pull
requests past its restrictions.
Same shape as
e430e004(16.0.2), plus the two pins that did not exist then:forgejo-app/deployment.yaml— five tag pins move together.binjovi/integration-bootstrap.yaml— the digest-pinned publisher moves to the16.0.4-rootless index digest
sha256:a263a129…, and because a Job templateis immutable the generation moves v32 → v33 in all four places.
tests/binjovi.sh— count, retired-generation refute (now v32) and the templatefingerprint (
2484060452 18830) re-pinned under the new name.tests/upstream-inventory.txt— the record moves; count stays 6.Rollout is the migration:
Recreate, one replica,gitea migratein theconfigure-giteainit container — expect a short outage ofcode.sean.farm.Verified:
tests/upstream-inventory.shok,tests/binjovi.shok, fulltests/check.shexit 0.First step of putting all three tiers of the off-cluster mirror chain on the
same Forgejo release; the FreeBSD and OmniOS tiers follow from source.
https://claude.ai/code/session_01XdBRc9CHgFhAxCyHbdVtt6