github.com/openshift-pipelines/pipelines-as-code
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/openshift-pipelines/pipelines-as-codepage 1 of 1
- CVE-2026-54167HIGHCVSS 8.2EG 8.2✓ Fixed in 0.48.02026-08-20
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing…
- CVE-2026-54168MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.48.02026-08-20
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the re…
Check whether github.com/openshift-pipelines/pipelines-as-code is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/openshift-pipelines/pipelines-as-code CVEs against the assets you own.
Start Free Scan →