apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| chainguard.dev/apko(Go) | 0 | 0.14.5 | N/A |
CVSS Metrics