p11-kit still contains version 0.23.22-r0 and therefore vulnerabilities
When I run alpine v3.13.0 and install gnupg (apk update && apk upgrade && apk add --no-cache bash gnupg) p11-kit-0.23.22-r0 is still used.
$ apk info p11-kit
p11-kit-0.23.22-r0 description:
Library for loading and sharing PKCS#11 modules
p11-kit-0.23.22-r0 webpage:
https://p11-glue.freedesktop.org/
p11-kit-0.23.22-r0 installed size:
1200 KiB
This is also shown in the package details.
Anyway this version has 3 security vulnerabilities (CVE-2020-29361, CVE-2020-29362, CVE-2020-29363) and needs to be updated to p11-kit-0.23.22. Which should be already fixed, see the file p11-kit.
Why is still the old version used?