caddy-fips
github.com/slackhq/nebula
2.11.1-r0
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
2.11.1-r0Status
Impact
nebula v1.10.3 fixes GHSA-69x3-g4r3-p962 but introduces breaking API changes that cause compilation failures via a transitive dependency. caddy depends on github.com/smallstep/certificates@v0.29.0, whose nebula provisioner (authority/provisioner/nebula.go) uses types removed in v1.10.3: nebula.NebulaCAPool, nebula.NebulaCertificate, nebula.NewCAPoolFromBytes, nebula.UnmarshalNebulaCertificate. The fix requires smallstep/certificates upstream to update their nebula provisioner for the v1.10.3 API changes.
Upstream advisory: https://github.com/advisories/GHSA-69x3-g4r3-p962 Blocking: https://github.com/smallstep/certificates/blob/v0.29.0/authority/provisioner/nebula.go
Status