Keeper of mazes.
- Seattle
- https://ariadne.space
- @ariadneconill
Block or Report
Block or report kaniini
Report abuse
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abusePinned
3,431 contributions in the last year
Less
More
Contribution activity
March 2023
Created 199 commits in 7 repositories
Created a pull request in chainguard-dev/melange that received 5 comments
container: bubblewrap runner: use --new-session to mitigate CVE-2017-5226
Without it, it is possible to escape the sandbox via TIOCSTI ioctls on the session PTY. Related: containers/bubblewrap#555 Related: containers/bubb…
+2
−1
•
5
comments
Opened 45 other pull requests in 4 repositories
wolfi-dev/os
1
open
20
merged
1
closed
- makefile: switch to using --cache-source instead of --cache-dir
- openssl: add mitigation for CVE-2023-0465
- workflows: push-production: fix location of comments to avoid breaking shell command
- workflows: drop gcloud SDK version pinning
- execline: rebuild to fix execline-dev dependencies
- dotnet-7: depend on icu instead of icu-dev for the runtime host
- powershell: new package
- rebuild libunwind, userspace-rcu and lttng-ust
- Add dotnet-7
- apko: upgrade to 0.7.2
- openssl: add mitigation for CVE-2023-0464
- skalibs: rebuild to fix dependency relationship
- glibc: reintroduce ld-linux package with explicit dependency on wolfi-baselayout
- glibc: split ld-linux interpreter into its own package
- llvm-libunwind: fix build on ARM
- Makefile: add compatibility with Darwin hosts
- push packages to wolfi-production-registry-destination directly
- glibc: rebuild 2.37-r3 to remove final dependency cycle
- glibc: disable gettext for C.UTF-8 locale and ensure stdio locking is consistent across threads
- withdrawn-packages: withdraw python 3.12.0_alpha5-r{0,1}
- Fix/python3 rebuild
- python-{3.10,3.11}: rebuild python3 again for sqlite
chainguard-dev/melange
1
open
12
merged
- docs: fix baseurl for melange reference in generated docs
- Refactor --cache-dir and separate preloading concerns into --cache-source
- Add --debug flag for logging
- Use cond package to do variable substitution
- cond: parser: use newer fork of goparsify
- pipelines: git-checkout: mark clone directory as a safe directory for git
- Bootstrap fixes
- update apko to latest git
- pipeline: only run mkdir -p if absolutely needed
- upgrade to apko 0.7.2 (git mainline)
- autoconf: always define the GNU host and build triplets in configure step
- package: only use base soname when generating runtime dependencies across symlinks
- remove self-provided dependencies from the runtime dependency set
chainguard-dev/apko
6
merged
- build: accounts: go back to using 0o755 permissions for the homedir
- update NEWS for apko 0.7.2 release
- apk: gracefully handle non-existent local repository
- sign-image: drop -f option
- fix signing the image with cosign
- apk: version: filterPackages: fall back to comparing provided versions when the package version itself is mismatched
Reviewed 119 pull requests in 7 repositories
wolfi-dev/os
25 pull requests
- ca-certificates/20230106 package update
- fix: copy objects to the correct location in GCS
- Bump some deps in the mysqld exporter to mitigate GHSAs
- Clean up YAML files to prepare for linting
- move package update mapping data to melange configs
- traefik: upgrade to v2.9.9
- Bump execline to rebuild the package.
- don't cache APKINDEX objects in GCS
- Update coreutils advisory as now affected
- use .tar.gz extension as .tar.bz2 are not generate in future versions
- Add rqlite package.
- Mark a bunch of CVEs as fixed in Jenkins.
- Add mc package.
- Add minio package.
- clamav: new package
- grep/3.10 package update
-
add
vars-transformsfor openjdk packages to fix apk version resolution - new pkg: bird, ipvsadm, ldns
- Add mercurial (and py3-wheel, which is required).
- DON'T MERGE: Minimize jre sub-packages
- tzdata/2023a package update
- bump openjdk versions
- deno/1.32.0 package update
- openssl: add mitigation for CVE-2023-0464
- haproxy: use libslz instead of zlib for compression implementation
- Some pull request reviews not shown.
chainguard-dev/apko
23 pull requests
- Add codeowners
- create homedir 0700, but parents 0755
- record when writing symlinks to case-sensitive
- generate list of links for busybox
- build(deps): bump google.golang.org/protobuf from 1.29.0 to 1.29.1
- build(deps): bump github/codeql-action from 2.2.6 to 2.2.7
- build(deps): bump github.com/go-git/go-git/v5 from 5.6.0 to 5.6.1
- build(deps): bump actions/setup-go from 3.5.0 to 4.0.0
- build(deps): bump actions/checkout from 3.3.0 to 3.4.0
- build(deps): bump github.com/google/go-containerregistry from 0.13.1-0.20230203223142-b3c23b4c3f28 to 0.14.0
- Permissions fixes
- handle symlink dir correctly for installed db
- build(deps): bump github/codeql-action from 2.2.5 to 2.2.6
- get entire mode when opening, not just permission bits
- update docs that indicate apko calls apk-tools
- add tree to busybox
- fix mutateaccounts
- build(deps): bump sigstore/cosign-installer from 2.8.1 to 3.0.1
- add newlines to arch and world
- build(deps): bump github.com/go-git/go-git/v5 from 5.5.2 to 5.6.0
- build(deps): bump github.com/stretchr/testify from 1.8.1 to 1.8.2
- build(deps): bump github/codeql-action from 2.2.4 to 2.2.5
- add support for pinned repos
chainguard-images/images
16 pull requests
- Add telegraf image.
- Login with cosign instead to prevent scope error
- Login with crane instead to prevent scope error
- Fix actions missing shell
- Pass generic credentials into apko publish
- Add minio and minio-client images.
- Ability to mark certains tests with tags (e.g. k8s etc)
- add dotnet-sdk image (experimental)
- Image: add nginx dev variant
- Add ruby dev variants
- Publish SBOM attestations, add policy 03-has-sbom-attestation.yaml
- Fix for image summary and tagging
- Bad ending in for loop (fi vs done oof)
- Fix image summary to add subvariant suffix, respect excludes
- Shared config for dev image variants
- Fix policy-check to use latest apko
chainguard-dev/melange
15 pull requests
- add query and package-version commands
- Hookup user and accounts in the environment.
- build(deps): bump google.golang.org/api from 0.113.0 to 0.114.0
- build(deps): bump actions/checkout from 3.3.0 to 3.5.0
- build(deps): bump actions/setup-go from 3.5.0 to 4.0.0
- add codeowners
- add Update struct for identifying how a melange package can be updated
-
add
var-transformsfor manipulation of variables using regular expr… - Try to fix a strange index generation bug.
- build(deps): bump google.golang.org/api from 0.111.0 to 0.113.0
- build(deps): bump cloud.google.com/go/storage from 1.29.0 to 1.30.0
- build(deps): bump github.com/go-git/go-git/v5 from 5.6.0 to 5.6.1
- add convert subcommand
- build(deps): bump google.golang.org/api from 0.111.0 to 0.112.0
- change --out-dir to not depend on cwd
chainguard-images/actions
4 pull requests
wolfi-dev/wolfictl
3 pull requests
chainguard-dev/actions
1 pull request
Created an issue in chainguard-images/images that received 4 comments
redis: user id should be 999
Which image/versions are related to this issue/feature request? When switching to chainguard's redis image, I had to chown my volume to 65532:65532…
4
comments
Opened 6 other issues in 2 repositories
chainguard-dev/apko
2
open
3
closed
chainguard-dev/melange
1
closed
11
contributions
in private repositories
Mar 6 – Mar 28






