Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

acme.sh/3.0.8 package update #28413

Merged
merged 1 commit into from
Sep 15, 2024

Conversation

octo-sts[bot]
Copy link
Contributor

@octo-sts octo-sts bot commented Sep 15, 2024

Signed-off-by: wolfi-bot <121097084+wolfi-bot@users.noreply.github.com>
@octo-sts octo-sts bot added request-version-update request for a newer version of a package automated pr labels Sep 15, 2024
Copy link
Contributor

Package acme.sh: Click to expand/collapse

Package acme.sh:

.PKGINFO metadata:

  (
  	"""
- 	# Generated by melange v0.15.5-4-g817ede6
+ 	# Generated by melange
  	pkgname = acme.sh
- 	pkgver = 3.0.7-r1
+ 	pkgver = 3.0.8-r0
  	arch = x86_64
- 	size = 1487069
+ 	size = 1363614
  	origin = acme.sh
  	pkgdesc = ACME Shell script, an acme client alternative to certbot
  	url = 
- 	commit = dd07be6d1c4c8beb10935f6d9557b41a1db07e84
- 	builddate = 1710422077
+ 	commit = b723417d2a08d0c61f82ecd93122ed9b61a6d2ce
  	license = GPL-3.0-only
  	depend = curl
  	depend = openssl
  	depend = socat
- 	datahash = 5a205bac1aed0e38782dc2e742f8d4797e50bb0dc23c3ef2adf78adeab61ad09
+ 	datahash = b493215ce504bc3c394b231623689923cc0132e0fdae8d3c03d8a5711afab8af
  	"""
  )

Added: /usr/share/acme.sh/deploy/ali_cdn.sh
Added: /usr/share/acme.sh/dnsapi/dns_alviy.sh
Added: /usr/share/acme.sh/dnsapi/dns_ionos_cloud.sh
Added: /usr/share/acme.sh/dnsapi/dns_limacity.sh
Added: /usr/share/acme.sh/dnsapi/dns_timeweb.sh
Added: /usr/share/acme.sh/dnsapi/dns_west_cn.sh
Added: /usr/share/acme.sh/dnsapi/dns_yandex360.sh
Added: /usr/share/acme.sh/notify/mattermost.sh
Added: /usr/share/acme.sh/notify/ntfy.sh
Modified: /usr/share/acme.sh/acme.sh
Modified: /usr/share/acme.sh/deploy/haproxy.sh
Modified: /usr/share/acme.sh/deploy/panos.sh
Modified: /usr/share/acme.sh/deploy/proxmoxve.sh
Modified: /usr/share/acme.sh/deploy/routeros.sh
Modified: /usr/share/acme.sh/deploy/synology_dsm.sh
Modified: /usr/share/acme.sh/deploy/vault.sh
Modified: /usr/share/acme.sh/dnsapi/dns_1984hosting.sh
Modified: /usr/share/acme.sh/dnsapi/dns_acmedns.sh
Modified: /usr/share/acme.sh/dnsapi/dns_acmeproxy.sh
Modified: /usr/share/acme.sh/dnsapi/dns_active24.sh
Modified: /usr/share/acme.sh/dnsapi/dns_ad.sh
Modified: /usr/share/acme.sh/dnsapi/dns_ali.sh
Modified: /usr/share/acme.sh/dnsapi/dns_anx.sh
Modified: /usr/share/acme.sh/dnsapi/dns_artfiles.sh
Modified: /usr/share/acme.sh/dnsapi/dns_arvan.sh
Modified: /usr/share/acme.sh/dnsapi/dns_aurora.sh
Modified: /usr/share/acme.sh/dnsapi/dns_autodns.sh
Modified: /usr/share/acme.sh/dnsapi/dns_aws.sh
Modified: /usr/share/acme.sh/dnsapi/dns_azion.sh
Modified: /usr/share/acme.sh/dnsapi/dns_azure.sh
Modified: /usr/share/acme.sh/dnsapi/dns_bookmyname.sh
Modified: /usr/share/acme.sh/dnsapi/dns_bunny.sh
Modified: /usr/share/acme.sh/dnsapi/dns_cf.sh
Modified: /usr/share/acme.sh/dnsapi/dns_clouddns.sh
Modified: /usr/share/acme.sh/dnsapi/dns_cloudns.sh
Modified: /usr/share/acme.sh/dnsapi/dns_cn.sh
Modified: /usr/share/acme.sh/dnsapi/dns_conoha.sh
Modified: /usr/share/acme.sh/dnsapi/dns_constellix.sh
Modified: /usr/share/acme.sh/dnsapi/dns_cpanel.sh
Modified: /usr/share/acme.sh/dnsapi/dns_curanet.sh
Modified: /usr/share/acme.sh/dnsapi/dns_cyon.sh
Modified: /usr/share/acme.sh/dnsapi/dns_da.sh
Modified: /usr/share/acme.sh/dnsapi/dns_ddnss.sh
Modified: /usr/share/acme.sh/dnsapi/dns_desec.sh
Modified: /usr/share/acme.sh/dnsapi/dns_df.sh
Modified: /usr/share/acme.sh/dnsapi/dns_dgon.sh
Modified: /usr/share/acme.sh/dnsapi/dns_dnsexit.sh
Modified: /usr/share/acme.sh/dnsapi/dns_dnshome.sh
Modified: /usr/share/acme.sh/dnsapi/dns_dnsimple.sh
Modified: /usr/share/acme.sh/dnsapi/dns_dnsservices.sh
Modified: /usr/share/acme.sh/dnsapi/dns_doapi.sh
Modified: /usr/share/acme.sh/dnsapi/dns_domeneshop.sh
Modified: /usr/share/acme.sh/dnsapi/dns_dp.sh
Modified: /usr/share/acme.sh/dnsapi/dns_dpi.sh
Modified: /usr/share/acme.sh/dnsapi/dns_dreamhost.sh
Modified: /usr/share/acme.sh/dnsapi/dns_duckdns.sh
Modified: /usr/share/acme.sh/dnsapi/dns_durabledns.sh
Modified: /usr/share/acme.sh/dnsapi/dns_dyn.sh
Modified: /usr/share/acme.sh/dnsapi/dns_dynu.sh
Modified: /usr/share/acme.sh/dnsapi/dns_dynv6.sh
Modified: /usr/share/acme.sh/dnsapi/dns_easydns.sh
Modified: /usr/share/acme.sh/dnsapi/dns_edgedns.sh
Modified: /usr/share/acme.sh/dnsapi/dns_euserv.sh
Modified: /usr/share/acme.sh/dnsapi/dns_exoscale.sh
Modified: /usr/share/acme.sh/dnsapi/dns_fornex.sh
Modified: /usr/share/acme.sh/dnsapi/dns_freedns.sh
Modified: /usr/share/acme.sh/dnsapi/dns_gandi_livedns.sh
Modified: /usr/share/acme.sh/dnsapi/dns_gcloud.sh
Modified: /usr/share/acme.sh/dnsapi/dns_gcore.sh
Modified: /usr/share/acme.sh/dnsapi/dns_gd.sh
Modified: /usr/share/acme.sh/dnsapi/dns_geoscaling.sh
Modified: /usr/share/acme.sh/dnsapi/dns_googledomains.sh
Modified: /usr/share/acme.sh/dnsapi/dns_he.sh
Modified: /usr/share/acme.sh/dnsapi/dns_hetzner.sh
Modified: /usr/share/acme.sh/dnsapi/dns_hexonet.sh
Modified: /usr/share/acme.sh/dnsapi/dns_hostingde.sh
Modified: /usr/share/acme.sh/dnsapi/dns_huaweicloud.sh
Modified: /usr/share/acme.sh/dnsapi/dns_infoblox.sh
Modified: /usr/share/acme.sh/dnsapi/dns_infomaniak.sh
Modified: /usr/share/acme.sh/dnsapi/dns_internetbs.sh
Modified: /usr/share/acme.sh/dnsapi/dns_inwx.sh
Modified: /usr/share/acme.sh/dnsapi/dns_ionos.sh
Modified: /usr/share/acme.sh/dnsapi/dns_ipv64.sh
Modified: /usr/share/acme.sh/dnsapi/dns_ispconfig.sh
Modified: /usr/share/acme.sh/dnsapi/dns_jd.sh
Modified: /usr/share/acme.sh/dnsapi/dns_joker.sh
Modified: /usr/share/acme.sh/dnsapi/dns_kappernet.sh
Modified: /usr/share/acme.sh/dnsapi/dns_kas.sh
Modified: /usr/share/acme.sh/dnsapi/dns_kinghost.sh
Modified: /usr/share/acme.sh/dnsapi/dns_knot.sh
Modified: /usr/share/acme.sh/dnsapi/dns_la.sh
Modified: /usr/share/acme.sh/dnsapi/dns_leaseweb.sh
Modified: /usr/share/acme.sh/dnsapi/dns_lexicon.sh
Modified: /usr/share/acme.sh/dnsapi/dns_linode.sh
Modified: /usr/share/acme.sh/dnsapi/dns_linode_v4.sh
Modified: /usr/share/acme.sh/dnsapi/dns_loopia.sh
Modified: /usr/share/acme.sh/dnsapi/dns_lua.sh
Modified: /usr/share/acme.sh/dnsapi/dns_maradns.sh
Modified: /usr/share/acme.sh/dnsapi/dns_me.sh
Modified: /usr/share/acme.sh/dnsapi/dns_miab.sh
Modified: /usr/share/acme.sh/dnsapi/dns_misaka.sh
Modified: /usr/share/acme.sh/dnsapi/dns_myapi.sh
Modified: /usr/share/acme.sh/dnsapi/dns_mydevil.sh
Modified: /usr/share/acme.sh/dnsapi/dns_mydnsjp.sh
Modified: /usr/share/acme.sh/dnsapi/dns_mythic_beasts.sh
Modified: /usr/share/acme.sh/dnsapi/dns_namecheap.sh
Modified: /usr/share/acme.sh/dnsapi/dns_namecom.sh
Modified: /usr/share/acme.sh/dnsapi/dns_namesilo.sh
Modified: /usr/share/acme.sh/dnsapi/dns_nanelo.sh
Modified: /usr/share/acme.sh/dnsapi/dns_nederhost.sh
Modified: /usr/share/acme.sh/dnsapi/dns_neodigit.sh
Modified: /usr/share/acme.sh/dnsapi/dns_netcup.sh
Modified: /usr/share/acme.sh/dnsapi/dns_netlify.sh
Modified: /usr/share/acme.sh/dnsapi/dns_nic.sh
Modified: /usr/share/acme.sh/dnsapi/dns_njalla.sh
Modified: /usr/share/acme.sh/dnsapi/dns_nm.sh
Modified: /usr/share/acme.sh/dnsapi/dns_nsd.sh
Modified: /usr/share/acme.sh/dnsapi/dns_nsone.sh
Modified: /usr/share/acme.sh/dnsapi/dns_nsupdate.sh
Modified: /usr/share/acme.sh/dnsapi/dns_nw.sh
Modified: /usr/share/acme.sh/dnsapi/dns_oci.sh
Modified: /usr/share/acme.sh/dnsapi/dns_one.sh
Modified: /usr/share/acme.sh/dnsapi/dns_online.sh
Modified: /usr/share/acme.sh/dnsapi/dns_openprovider.sh
Modified: /usr/share/acme.sh/dnsapi/dns_openstack.sh
Modified: /usr/share/acme.sh/dnsapi/dns_opnsense.sh
Modified: /usr/share/acme.sh/dnsapi/dns_ovh.sh
Modified: /usr/share/acme.sh/dnsapi/dns_pdns.sh
Modified: /usr/share/acme.sh/dnsapi/dns_pleskxml.sh
Modified: /usr/share/acme.sh/dnsapi/dns_pointhq.sh
Modified: /usr/share/acme.sh/dnsapi/dns_porkbun.sh
Modified: /usr/share/acme.sh/dnsapi/dns_rackcorp.sh
Modified: /usr/share/acme.sh/dnsapi/dns_rackspace.sh
Modified: /usr/share/acme.sh/dnsapi/dns_rage4.sh
Modified: /usr/share/acme.sh/dnsapi/dns_rcode0.sh
Modified: /usr/share/acme.sh/dnsapi/dns_regru.sh
Modified: /usr/share/acme.sh/dnsapi/dns_scaleway.sh
Modified: /usr/share/acme.sh/dnsapi/dns_schlundtech.sh
Modified: /usr/share/acme.sh/dnsapi/dns_selectel.sh
Modified: /usr/share/acme.sh/dnsapi/dns_selfhost.sh
Modified: /usr/share/acme.sh/dnsapi/dns_servercow.sh
Modified: /usr/share/acme.sh/dnsapi/dns_simply.sh
Modified: /usr/share/acme.sh/dnsapi/dns_tele3.sh
Modified: /usr/share/acme.sh/dnsapi/dns_tencent.sh
Modified: /usr/share/acme.sh/dnsapi/dns_transip.sh
Modified: /usr/share/acme.sh/dnsapi/dns_udr.sh
Modified: /usr/share/acme.sh/dnsapi/dns_ultra.sh
Modified: /usr/share/acme.sh/dnsapi/dns_unoeuro.sh
Modified: /usr/share/acme.sh/dnsapi/dns_variomedia.sh
Modified: /usr/share/acme.sh/dnsapi/dns_veesp.sh
Modified: /usr/share/acme.sh/dnsapi/dns_vercel.sh
Modified: /usr/share/acme.sh/dnsapi/dns_vscale.sh
Modified: /usr/share/acme.sh/dnsapi/dns_vultr.sh
Modified: /usr/share/acme.sh/dnsapi/dns_websupport.sh
Modified: /usr/share/acme.sh/dnsapi/dns_world4you.sh
Modified: /usr/share/acme.sh/dnsapi/dns_yc.sh
Modified: /usr/share/acme.sh/dnsapi/dns_zilore.sh
Modified: /usr/share/acme.sh/dnsapi/dns_zone.sh
Modified: /usr/share/acme.sh/dnsapi/dns_zonomi.sh
Modified: /usr/share/acme.sh/notify/teams.sh
Deleted: /usr/share/acme.sh/dnsapi/dns_do.sh
Deleted: /usr/share/acme.sh/dnsapi/dns_yandex.sh

bincapz found differences: Click to expand/collapse

Deleted: acme.sh/usr/share/acme.sh/dnsapi/dns_yandex.sh [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM ref/site/download http dropper url https://github.com/non7top/acme.sh
-LOW net/dns/txt Uses DNS TXT (text) records TXT
dns
-LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env
-LOW ref/site/url contains embedded HTTPS URLs https://github.com/non7top/acme.sh
https://pddimp.yandex.ru/api2/admin/dns/add
https://pddimp.yandex.ru/api2/admin/dns/del
https://pddimp.yandex.ru/api2/admin/dns/list?domain=
https://pddimp.yandex.ru/api2/admin/get_token.

Deleted: acme.sh/usr/share/acme.sh/dnsapi/dns_do.sh [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/http/cookies access HTTP resources using cookies Cookie
HTTP
-MEDIUM ref/site/download http dropper url https://github.com/seidler2547/acme.sh
-LOW net/dns/txt Uses DNS TXT (text) records TXT
dns
-LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env
-LOW ref/site/url contains embedded HTTPS URLs https://github.com/seidler2547/acme.sh/issues
https://soap.resellerinterface.de/
-LOW ref/words/password references a 'password' customer ID and password

Added: acme.sh/usr/share/acme.sh/deploy/ali_cdn.sh [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/http/post submit content to websites POST
http
+MEDIUM net/upload uploads files upload
+MEDIUM net/url/encode encodes URL, likely to pass GET variables urlencode
+MEDIUM ref/path/dev path reference within /dev /dev/urandom
+LOW encoding/base64 Supports base64 encoded strings base64
+LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env
+LOW ref/site/url contains embedded HTTPS URLs https://cdn.aliyuncs.com/

Added: acme.sh/usr/share/acme.sh/dnsapi/dns_west_cn.sh [🔥 HIGH]

RISK KEY DESCRIPTION EVIDENCE
+HIGH exfil/sysinfo_http sends host information via HTTP GET variables &hostname=
+MEDIUM net/http/post submit content to websites POST
http
+LOW net/dns/txt Uses DNS TXT (text) records TXT
dns
+LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env
+LOW ref/site/url contains embedded HTTPS URLs https://api.west.cn/API/v2
https://www.west.cn/manager/API/APIconfig.asp

Added: acme.sh/usr/share/acme.sh/dnsapi/dns_timeweb.sh [✅ LOW]

RISK KEY DESCRIPTION EVIDENCE
+LOW net/dns/txt Uses DNS TXT (text) records TXT
dns
+LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env
+LOW ref/site/url contains embedded HTTPS URLs https://api.timeweb.cloud/api/v1
https://github.com/nikolaypronchev.
https://timeweb.cloud/my/api-keys

Added: acme.sh/usr/share/acme.sh/notify/mattermost.sh [✅ LOW]

RISK KEY DESCRIPTION EVIDENCE
+LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env

Added: acme.sh/usr/share/acme.sh/dnsapi/dns_ionos_cloud.sh [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/http/post submit content to websites HTTP
POST
http
+LOW net/dns/txt Uses DNS TXT (text) records TXT
dns
+LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env
+LOW ref/site/url contains embedded HTTPS URLs https://api.ionos.com/docs/authentication/v1/
https://dns.de-fra.ionos.com

Added: acme.sh/usr/share/acme.sh/dnsapi/dns_alviy.sh [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/http/post submit content to websites HTTP
POST
http
+LOW net/dns/txt Uses DNS TXT (text) records TXT
dns
+LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env
+LOW ref/site/url contains embedded HTTPS URLs https://cloud.alviy.com/api/v1
https://cloud.alviy.com/token

Added: acme.sh/usr/share/acme.sh/notify/ntfy.sh [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/http/post submit content to websites POST
http
+LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env

Added: acme.sh/usr/share/acme.sh/dnsapi/dns_limacity.sh [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/http/post submit content to websites POST
http
+LOW encoding/base64 Supports base64 encoded strings base64
+LOW net/dns/txt Uses DNS TXT (text) records TXT
dns
+LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env
+LOW ref/site/url contains embedded HTTPS URLs https://www.lima-city.de/usercp

Added: acme.sh/usr/share/acme.sh/dnsapi/dns_yandex360.sh [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/http/post submit content to websites POST
http
+LOW kernel/platform system identification uname
+LOW net/dns/txt Uses DNS TXT (text) records TXT
dns
+LOW ref/path/usr/bin path reference within /usr/bin /usr/bin/env
+LOW ref/site/url contains embedded HTTPS URLs https://360.yandex.com/
https://api360.yandex.net/directory/v1
acmesh-official/acme.sh#5213
https://github.com/acmesh-official/acme.sh/wiki/dnsapi2
https://oauth.yandex.ru

Changed: /tmp/wolfictl-apk-3824017707/acme.sh/usr/share/acme.sh/dnsapi/dns_df.sh

1 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM ref/site/download http dropper url https://github.com/ThiloGa/acme.sh

Changed: /tmp/wolfictl-apk-3824017707/acme.sh/usr/share/acme.sh/dnsapi/dns_namecheap.sh

Changed: /tmp/wolfictl-apk-3824017707/acme.sh/usr/share/acme.sh/acme.sh

Changed: /tmp/wolfictl-apk-3824017707/acme.sh/usr/share/acme.sh/dnsapi/dns_nm.sh

1 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM ref/site/download http dropper url https://github.com/ThiloGa/acme.sh

Moved: acme.sh/var/lib/db/sbom/acme.sh-3.0.7-r1.spdx.json -> /tmp/wolfictl-apk-3824017707/acme.sh/var/lib/db/sbom/acme.sh-3.0.8-r0.spdx.json (similarity: 0.98)

2 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM ref/site/dyndns dynamic dns user duckdns
-MEDIUM secrets/keychain May access the macOS keychain keychain

@mamccorm mamccorm merged commit fa739fa into main Sep 15, 2024
11 checks passed
@mamccorm mamccorm deleted the wolfictl-7d4d499a-d597-40e4-b83d-8a69fd8dce30 branch September 15, 2024 21:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants