Package
melange
Component
chainguard.dev/melange
Latest update
4.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
Not vulnerable. GHSA-7rp8-r62p-q6wc / CVE-2026-29049 affects chainguard.dev/melange <= 0.40.5 only; upstream records no fixed version because later releases are not affected. This package ships melange 0.54.0, above the affected range. The detection originates from the Go vulnerability database record (GO-2026-4588) omitting the last_affected 0.40.5 bound carried by the GHSA/OSV data, causing the scanner to over-match.
Status