schema-version: 2.0.2

package:
  name: aws-flb-kinesis

advisories:
  - id: CGA-358h-xcv7-58w2
    aliases:
      - CVE-2024-24791
      - GHSA-hw49-2p59-3mhj
    events:
      - timestamp: 2024-07-05T07:03:42Z
        type: fixed
        data:
          fixed-version: 1.10.2-r13

  - id: CGA-58mw-7g4v-3x4x
    aliases:
      - CVE-2024-24789
      - GHSA-236w-p7wf-5ph8
    events:
      - timestamp: 2024-06-07T14:10:21Z
        type: fixed
        data:
          fixed-version: 1.10.2-r12

  - id: CGA-5993-6v22-v763
    aliases:
      - CVE-2024-34156
      - GHSA-crqm-pwhx-j97f
    events:
      - timestamp: 2024-09-10T07:06:57Z
        type: detection
        data:
          type: scan/v1
          data:
            subpackageName: aws-flb-kinesis
            componentID: 4018305453cf5e59
            componentName: stdlib
            componentVersion: go1.22.5
            componentType: go-module
            componentLocation: /usr/bin/kinesis.so
            scanner: grype
      - timestamp: 2024-09-12T19:00:54Z
        type: fixed
        data:
          fixed-version: 1.10.2-r14

  - id: CGA-6f3f-ffw9-cc7w
    aliases:
      - CVE-2024-34155
      - GHSA-8xfx-rj4p-23jm
    events:
      - timestamp: 2024-09-10T07:06:54Z
        type: detection
        data:
          type: scan/v1
          data:
            subpackageName: aws-flb-kinesis
            componentID: 4018305453cf5e59
            componentName: stdlib
            componentVersion: go1.22.5
            componentType: go-module
            componentLocation: /usr/bin/kinesis.so
            scanner: grype
      - timestamp: 2024-09-12T19:00:55Z
        type: fixed
        data:
          fixed-version: 1.10.2-r14

  - id: CGA-8hxf-qq3r-3vx3
    aliases:
      - CVE-2023-45285
      - GHSA-5f94-vhjq-rpg8
    events:
      - timestamp: 2023-12-18T15:44:05Z
        type: fixed
        data:
          fixed-version: 1.10.2-r6

  - id: CGA-8vj9-jgr8-r7jh
    aliases:
      - CVE-2024-24783
      - GHSA-3q2c-pvp5-3cqp
    events:
      - timestamp: 2024-03-13T07:13:58Z
        type: fixed
        data:
          fixed-version: 1.10.2-r7

  - id: CGA-8xm4-w2qq-292f
    aliases:
      - CVE-2023-39326
      - GHSA-9f76-wg39-x86h
    events:
      - timestamp: 2023-12-18T15:44:16Z
        type: fixed
        data:
          fixed-version: 1.10.2-r6

  - id: CGA-94w5-mq8h-q3c7
    aliases:
      - CVE-2023-45288
      - GHSA-4v7x-pqxf-cx7m
    events:
      - timestamp: 2024-04-13T07:10:49Z
        type: fixed
        data:
          fixed-version: 1.10.2-r9

  - id: CGA-c292-32wg-4xpm
    aliases:
      - CVE-2024-24790
      - GHSA-49gw-vxvf-fc2g
    events:
      - timestamp: 2024-06-07T14:10:18Z
        type: fixed
        data:
          fixed-version: 1.10.2-r12

  - id: CGA-h2jm-jr73-c58p
    aliases:
      - CVE-2024-24784
      - GHSA-fgq5-q76c-gx78
    events:
      - timestamp: 2024-03-13T07:13:58Z
        type: fixed
        data:
          fixed-version: 1.10.2-r7

  - id: CGA-h98c-j3wg-f3pw
    aliases:
      - CVE-2023-45283
      - GHSA-vvjp-q62m-2vph
    events:
      - timestamp: 2023-11-07T19:23:30Z
        type: false-positive-determination
        data:
          type: vulnerable-code-not-included-in-package
          note: Only affects Windows

  - id: CGA-hccw-3rp5-6c56
    aliases:
      - CVE-2023-45289
      - GHSA-32ch-6x54-q4h9
    events:
      - timestamp: 2024-03-13T07:13:56Z
        type: fixed
        data:
          fixed-version: 1.10.2-r7

  - id: CGA-hmxp-2jrg-8fj2
    aliases:
      - CVE-2023-45284
      - GHSA-rq3x-83w4-p28c
    events:
      - timestamp: 2023-11-07T19:23:31Z
        type: false-positive-determination
        data:
          type: vulnerable-code-not-included-in-package
          note: Only affects Windows

  - id: CGA-hw25-f668-5687
    aliases:
      - CVE-2024-24785
      - GHSA-j6m3-gc37-6r6q
    events:
      - timestamp: 2024-03-13T07:13:59Z
        type: fixed
        data:
          fixed-version: 1.10.2-r7

  - id: CGA-j3mf-q486-pf83
    aliases:
      - CVE-2024-34158
      - GHSA-j7vj-rw65-4v26
    events:
      - timestamp: 2024-09-10T07:07:01Z
        type: detection
        data:
          type: scan/v1
          data:
            subpackageName: aws-flb-kinesis
            componentID: 4018305453cf5e59
            componentName: stdlib
            componentVersion: go1.22.5
            componentType: go-module
            componentLocation: /usr/bin/kinesis.so
            scanner: grype
      - timestamp: 2024-09-12T19:00:55Z
        type: fixed
        data:
          fixed-version: 1.10.2-r14

  - id: CGA-p2w2-8f2q-4m7w
    aliases:
      - CVE-2023-45290
      - GHSA-rr6r-cfgf-gc6h
    events:
      - timestamp: 2024-03-13T07:13:57Z
        type: fixed
        data:
          fixed-version: 1.10.2-r7

  - id: CGA-p76g-3ghq-6xq2
    aliases:
      - CVE-2024-24786
      - GHSA-8r3f-844c-mc37
    events:
      - timestamp: 2024-03-14T08:19:59Z
        type: detection
        data:
          type: scan/v1
          data:
            subpackageName: aws-flb-kinesis
            componentID: 41a4c3783e1fde3f
            componentName: google.golang.org/protobuf
            componentVersion: v1.30.0
            componentType: go-module
            componentLocation: /usr/bin/kinesis.so
            scanner: grype
      - timestamp: 2024-03-17T14:17:56Z
        type: fixed
        data:
          fixed-version: 1.10.2-r8

  - id: CGA-qp48-w797-6m85
    aliases:
      - CVE-2025-22866
      - GHSA-3whm-j4xm-rv8x
    events:
      - timestamp: 2025-02-08T07:09:30Z
        type: detection
        data:
          type: scan/v1
          data:
            subpackageName: aws-flb-kinesis
            componentID: b177cca67b1fbc31
            componentName: stdlib
            componentVersion: go1.23.5
            componentType: go-module
            componentLocation: /usr/bin/kinesis.so
            scanner: grype
      - timestamp: 2025-02-08T17:35:59Z
        type: fixed
        data:
          fixed-version: 1.10.2-r16

  - id: CGA-rpwg-6q7m-pcmf
    aliases:
      - CVE-2024-45341
      - GHSA-3f6r-qh9c-x6mm
    events:
      - timestamp: 2025-01-31T07:37:20Z
        type: fixed
        data:
          fixed-version: 1.10.2-r15

  - id: CGA-rrpc-2wgh-php5
    aliases:
      - CVE-2024-45336
      - GHSA-7wrw-r4p8-38rx
    events:
      - timestamp: 2025-01-31T07:37:15Z
        type: fixed
        data:
          fixed-version: 1.10.2-r15