leap-16.1 #9
Reference in New Issue
Block a user
Delete Branch "mcepl/git-bug:leap-16.1"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
- Revendor to include fixed version of depending libraries:
- GO-2025-4116 (CVE-2025-47913, bsc#1253506) upgrade
golang.org/x/crypto to v0.43.0
- GO-2025-3900 (GHSA-2464-8j7c-4cjm) upgrade
github.com/go-viper/mapstructure/v2 to v2.4.0
- GO-2025-3787 (GHSA-fv92-fjc5-jj9h) included in the previous
- GO-2025-3754 (GHSA-2x5j-vhc8-9cwm) upgrade
github.com/cloudflare/circl to v1.6.1
- GO-2025-4134 (CVE-2025-58181, bsc#1253930) upgrade
golang.org/x/crypto/ssh to v0.45.0
- GO-2025-4135 (CVE-2025-47914, bsc#1254084) upgrade
golang.org/x/crypto/ssh/agent to v0.45.0
Wed Oct 15 20:05:09 UTC 2025 - Matej Cepl mcepl@cepl.eu
possible DoS by various algorithms with quadratic complexity
when parsing HTML documents (bsc#1251463, CVE-2025-47911 and
bsc#1251664, CVE-2025-58190).
Mon May 19 08:38:03 UTC 2025 - Matej Cepl mcepl@cepl.eu
Tue May 06 10:21:55 UTC 2025 - mcepl@cepl.eu
Tue Mar 25 15:29:50 UTC 2025 - mcepl@cepl.eu
(apparently upstream still didn’t see the other one).
Thu Mar 13 17:02:33 UTC 2025 - mcepl@cepl.eu
golang.org/x/crypto/ssh to v0.35.0 (bsc#1239494,
CVE-2025-22869).
Wed Jan 22 16:32:25 UTC 2025 - Matej Cepl mcepl@cepl.eu
Wed Jan 8 09:00:10 UTC 2025 - Matej Cepl mcepl@cepl.eu
Tue Dec 17 13:53:28 UTC 2024 - Matej Cepl mcepl@cepl.eu
golang.org/x/crypto from v0.26.0 to v0.31.0 (fix for
CVE-2024-45337, bsc#1234565).
Review by packagehub-review represents a group of reviewers: bigironman, lkocman-factory, maxlin_factory, smithfarm .
Do not use standard review interface to review on behalf of the group.
To accept the review on behalf of the group, create the following comment:
@packagehub-review: approve.To request changes on behalf of the group, create the following comment:
@packagehub-review: declinefollowed with lines justifying the decision.Future edits of the comments are ignored, a new comment is required to change the review state.
Legal reviewed as acceptable_by_lawyer:
- GO-2025-4116 (CVE-2025-47913, bsc#1253506) upgrade golang.org/x/crypto to v0.43.0 - GO-2025-3900 (GHSA-2464-8j7c-4cjm) upgrade github.com/go-viper/mapstructure/v2 to v2.4.0 - GO-2025-3787 (GHSA-fv92-fjc5-jj9h) included in the previous - GO-2025-3754 (GHSA-2x5j-vhc8-9cwm) upgrade github.com/cloudflare/circl to v1.6.1 - GO-2025-4134 (CVE-2025-58181, bsc#1253930) upgrade golang.org/x/crypto/ssh to v0.45.0 - GO-2025-4135 (CVE-2025-47914, bsc#1254084) upgrade golang.org/x/crypto/ssh/agent to v0.45.0New commits pushed, approval review dismissed automatically according to repository settings
Review by packagehub-review represents a group of reviewers: bigironman, lkocman-factory, maxlin_factory, smithfarm .
Do not use standard review interface to review on behalf of the group.
To accept the review on behalf of the group, create the following comment:
@packagehub-review: approve.To request changes on behalf of the group, create the following comment:
@packagehub-review: declinefollowed with lines justifying the decision.Future edits of the comments are ignored, a new comment is required to change the review state.
Legal reviewed as acceptable_by_lawyer:
@packagehub-review: approve
maxlin_factory approved a review on behalf of packagehub-review
This PR is merged via the associated Project PR.