/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-gcgr-6v44-f2qw

Published

Last updated

https://images.chainguard.dev/security/CGA-gcgr-6v44-f2qw
Package

starship

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-31130
  • GHSA-2frx-2596-x5r6

Severity

6.8

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-31130

Updates

Status

Pending upstream fix

Impact

upstream maintainers have pinned gix to version 0.69.1 and will have to patch. There is a pending upstream fix https://github.com/starship/starship/pull/6670/files. Attempts to cherry-pick or patch this have resulted in build failures. This is also due to significant changes from version 0.69.1 to 0.71.0

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing