[automatic] Publish and update 80 advisories for 40 packages #223
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This action searched
recent NVD/EUVD changes/publications, checking 2713 (+1) advisories from NVD and 295 (+2377) from EUVD for advisories that pertain here. It identified 80 advisories as being related to the Julia package(s): OpenSSH_jll, OpenSSL_jll, Openresty_jll, Expat_jll, Xorg_libX11_jll, nghttp2_jll, libnode_jll, Git_jll, Vim_jll, libLAS_jll, XML2_jll, CURL_jll, LibCURL_jll, GStreamer_jll, JasPer_jll, systemd_jll, FFMPEG_jll, FFplay_jll, Qt5Base_jll, Qt_jll, ruby_jll, BlueZ_jll, Poppler_jll, GnuTLS_jll, Rusticl_jll, MbedTLS_jll, TinyXML_jll, LibPQ_jll, libxls_jll, Tar_jll, LibSSH2_jll, ImageMagick_jll, Glib_jll, GlibNetworking_jll, util_linux_jll, Libuuid_jll, Libmount_jll, OpenEXR_jll, Ncurses_jll, and Graphviz_jll.1 advisories failed to parse the source version range
These advisories seem to apply to a Julia package but had trouble identifying exactly how and at which versions.
["*"]. Its latest version (10.2.1+0) has components: {openssh = "10.2p1"}openbsd:opensshat `` failed to parse31 advisories apply to all registered versions of a package
These advisories had no obvious failures but computed a range without bounds.
["*"]. Its latest version (2.7.1+0) has components: {ruby = "2.7.1"}ruby-lang:rubyat>= 2.7.0, < 2.7.7includes all versions["*"]. Its latest version (5.54.0+1) has components: {bluez-sixaxis = "5.54", bluez = "5.54"}bluez:bluezat< 5.61includes all versions["*"]. Its latest version (2.6.2+0) has components: {tinyxml = "2.6.2"}tinyxml_project:tinyxmlat>= 2.3.2, <= 2.6.2includes all versions["*"]. Its latest version (5.54.0+1) has components: {bluez-sixaxis = "5.54", bluez = "5.54"}bluez:bluezat< 5.63includes all versions["*"]. Its latest version (2.7.1+0) has components: {ruby = "2.7.1"}ruby-lang:rubyat>= 2.7.0, < 2.7.6includes all versions["*"]. Its latest version (5.54.0+1) has components: {bluez-sixaxis = "5.54", bluez = "5.54"}bluez:bluezat< 5.59includes all versions["*"]. Its latest version (5.54.0+1) has components: {bluez-sixaxis = "5.54", bluez = "5.54"}bluez:bluezat< 5.59includes all versions["*"]. Its latest version (2.7.1+0) has components: {ruby = "2.7.1"}ruby-lang:rubyat<= 2.7.7includes all versions["*"]. Its latest version (2.6.2+0) has components: {tinyxml = "2.6.2"}tinyxml_project:tinyxmlat<= 2.6.2includes all versions["*"]. Its latest version (1.20.3+0) has components: {gstreamer = "1.20.3"}gstreamer_project:gstreamerat< 1.20.7includes all versions["*"]. Its latest version (1.20.3+0) has components: {gstreamer = "1.20.3"}gstreamer_project:gstreamerat< 1.20.7includes all versions["*"]. Its latest version (1.20.3+0) has components: {gstreamer = "1.20.3"}gstreamer_project:gstreamerat< 1.20.7includes all versions["*"]. Its latest version (1.20.3+0) has components: {gstreamer = "1.20.3"}gstreamer_project:gstreamerat< 1.22.6includes all versions["*"]. Its latest version (1.20.3+0) has components: {gstreamer = "1.20.3"}gstreamer_project:gstreamerat< 1.22.6includes all versions["*"]. Its latest version (1.20.3+0) has components: {gstreamer = "1.20.3"}gstreamer_project:gstreamerat< 1.22.7includes all versionsmesa3d:mesa. Its latest version (20.1.5+2) has components: {mesa-clc = "20.1.5", mesa = "20.1.5", mesa-zink = "20.1.5"}mesa3d:mesamight mean a different project; it could be one ofmesa-clcormesa["*"]. Its latest version (25.2.0+2) has components: {mesa-pvr-ddk119 = "", meson = "1.7.2", mesa = "", molten-vk = "1.4.0"}mesa3d:mesaat= 23.0.4includes all versionsmesa3d:mesamight mean a different project; it could be one ofmesa-clcormesamesa3d:mesa. Its latest version (20.1.5+2) has components: {mesa-clc = "20.1.5", mesa = "20.1.5", mesa-zink = "20.1.5"}mesa3d:mesamight mean a different project; it could be one ofmesa-clcormesa["*"]. Its latest version (25.2.0+2) has components: {mesa-pvr-ddk119 = "", meson = "1.7.2", mesa = "", molten-vk = "1.4.0"}mesa3d:mesaat= 23.0.4includes all versionsmesa3d:mesamight mean a different project; it could be one ofmesa-clcormesamesa3d:mesa. Its latest version (20.1.5+2) has components: {mesa-clc = "20.1.5", mesa = "20.1.5", mesa-zink = "20.1.5"}mesa3d:mesamight mean a different project; it could be one ofmesa-clcormesa["*"]. Its latest version (25.2.0+2) has components: {mesa-pvr-ddk119 = "", meson = "1.7.2", mesa = "", molten-vk = "1.4.0"}mesa3d:mesaat= 23.0.4includes all versionsmesa3d:mesamight mean a different project; it could be one ofmesa-clcormesamesa3d:mesa. Its latest version (20.1.5+2) has components: {mesa-clc = "20.1.5", mesa = "20.1.5", mesa-zink = "20.1.5"}mesa3d:mesamight mean a different project; it could be one ofmesa-clcormesa["*"]. Its latest version (25.2.0+2) has components: {mesa-pvr-ddk119 = "", meson = "1.7.2", mesa = "", molten-vk = "1.4.0"}mesa3d:mesaat= 23.0.4includes all versionsmesa3d:mesamight mean a different project; it could be one ofmesa-clcormesa["*"]. Its latest version (2.50.0+1) has components: {graphviz = "2.50.0"}graphviz:graphvizat>= 2.36.0, < 10.0.0includes all versions["*"]. Its latest version (2.0.33+0) has components: {jasper = "*"}jasper_project:jasperat<= 4.1.1includes all versions["*"]. Its latest version (16.8.0+0) has components: {postgresql = "*"}postgresql:postgresqlat>= 11.0, < 11.22mapped to[>= 16.0.0+0], includes the latest version`postgresql:postgresqlat>= 12.0, < 12.17mapped to[< 14.1.0+0, >= 16.0.0+0], includes the latest version`postgresql:postgresqlat>= 13.0, < 13.13mapped to[>= 16.0.0+0], includes the latest version`postgresql:postgresqlat>= 14.0, < 14.10mapped to[>= 14.1.0+0], includes the latest version`postgresql:postgresqlat>= 15.0, < 15.5mapped to[>= 16.0.0+0], includes the latest version`postgresql:postgresqlat= 16.0mapped to[>= 16.0.0+0], includes the latest version`["*"]. Its latest version (5.15.3+2) has components: {qt = "5.15.3", qt5base = "5.15.3", qtbase = "5.15.3"}qt:qtat>= 5.12.0, < 5.15.17includes all versions["*"]. Its latest version (5.15.2+3) has components: {qt = "5.15.2"}qt:qtat>= 5.12.0, < 5.15.17includes all versions["*"]. Its latest version (0.1.0+0) has components: {liblas = "*"}liblas:liblasat= 1.8.1includes all versions["< 2.80.2+0"]. Its latest version (2.86.0+0) has components: {mingw-w64-headers = "10.0.0", glib = "2.86.0"}gnome:glibmight mean a different project; it could be one ofgliborglib-networking["*"]. Its latest version (2.74.0+0) has components: {glib-networking = "2.74.0"}gnome:glibat< 2.78.5includes all versionsgnome:glibmight mean a different project; it could be one ofgliborglib-networking["*"]. Its latest version (5.15.3+2) has components: {qt = "5.15.3", qt5base = "5.15.3", qtbase = "5.15.3"}qt:qtat< 5.15.17includes all versions["*"]. Its latest version (5.15.2+3) has components: {qt = "5.15.2"}qt:qtat< 5.15.17includes all versions["*"]. Its latest version (9.1.0+0) has components: {vim = "9.1.0"}vim:vimat< 9.1.0647includes all versions["*"]. Its latest version (3.8.4+0) has components: {gnutls = "3.8.4"}gnu:gnutlsat< 3.8.10includes all versions["*"]. Its latest version (256.7.0+0) has components: {systemd = "256.7"}systemd_project:systemdat>= 256, < 256.14mapped to[>= 256.7.0+0], includes the latest version`["*"]. Its latest version (9.1.0+0) has components: {vim = "9.1.0"}vim:vimat< 9.1.1552includes all versions["*"]. Its latest version (9.1.0+0) has components: {vim = "9.1.0"}vim:vimat< 9.1.1551includes all versions7 advisories apply to the latest version of a package and do not have a patch
[">= 16.14.0+0"]. Its latest version (18.12.1+0) has components: {node-v = "18.12.1", nodejs = "18.12.1"}nodejs:node.jsat>= 18.0.0, < 18.16.1mapped to[>= 18.12.1+0], includes the latest version`[">= 16.14.0+0"]. Its latest version (18.12.1+0) has components: {node-v = "18.12.1", nodejs = "18.12.1"}nodejs:node.jsat>= 18.0.0, < 18.16.1mapped to[>= 18.12.1+0], includes the latest version`[">= 16.14.0+0"]. Its latest version (18.12.1+0) has components: {node-v = "18.12.1", nodejs = "18.12.1"}nodejs:node.jsat>= 18.0.0, <= 18.17.0mapped to[>= 18.12.1+0], includes the latest version`[">= 1.6.2+0"]. Its latest version (1.6.2+0) has components: {libxls = "1.6.2"}libxls_project:libxlsat= 1.6.2mapped to[>= 1.6.2+0], includes the latest version`["< 1.58.0+0"]. Its latest version (1.68.0+1) has components: {nghttp2 = "1.68.0", nghttp2-libs = "*"}[">= 18.12.1+0"]. Its latest version (18.12.1+0) has components: {node-v = "18.12.1", nodejs = "18.12.1"}nodejs:node.jsat>= 18.0.0, < 18.18.2mapped to[>= 18.12.1+0], includes the latest version`[">= 18.12.1+0"]. Its latest version (18.12.1+0) has components: {node-v = "18.12.1", nodejs = "18.12.1"}nodejs:node.jsat>= 18.0.0, < 18.19.1mapped to[>= 18.12.1+0], includes the latest version`[">= 18.12.1+0"]. Its latest version (18.12.1+0) has components: {node-v = "18.12.1", nodejs = "18.12.1"}nodejs:node.jsat>= 18.0, < 18.20.6mapped to[>= 18.12.1+0], includes the latest version`41 advisories found concrete vulnerable ranges
["< 2.9.12+0"]. Its latest version (2.15.1+0) has components: {libxml2 = "2.15.1"}["< 2.26.1+0"]. Its latest version (2.51.3+0) has components: {git-for-windows = "2.51.2.windows.1", git = "2.51.2"}["< 1.1.20+0"]. Its latest version (3.5.4+0) has components: {openssl = "3.5.4"}["< 1.27.1+0"]. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}["< 1.1.20+0"]. Its latest version (3.5.4+0) has components: {openssl = "3.5.4"}[">= 1.19.9+0, < 1.27.1+0"]. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}[">= 6.9.12+0, < 6.9.12+4"]. Its latest version (7.1.2005+0) has components: {imagemagick = "7.1.2-3"}["< 1.1.20+0"]. Its latest version (3.5.4+0) has components: {openssl = "3.5.4"}["< 1.27.1+0"]. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}["< 1.1.20+0"]. Its latest version (3.5.4+0) has components: {openssl = "3.5.4"}["< 1.27.1+0"]. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}["< 2.42.0+0"]. Its latest version (2.51.3+0) has components: {git-for-windows = "2.51.2.windows.1", git = "2.51.2"}["< 2.42.0+0"]. Its latest version (2.51.3+0) has components: {git-for-windows = "2.51.2.windows.1", git = "2.51.2"}["< 6.4.0+0"]. Its latest version (6.5.1+0) has components: {ncurses = "6.5"}["< 23.12.0+0"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}["< 8.5.0+0"]. Its latest version (8.16.0+0) has components: {curl = "8.16.0"}["< 8.4.0+0"]. Its latest version (8.16.0+0) has components: {curl = "8.16.0"}["< 1.35.0+0"]. Its latest version (1.35.0+0) has components: {tar = "1.35"}["< 1.8.12+0"]. Its latest version (1.8.12+0) has components: {libx11 = "1.8.12"}["< 1.8.12+0"]. Its latest version (1.8.12+0) has components: {libx11 = "1.8.12"}["< 1.8.12+0"]. Its latest version (1.8.12+0) has components: {libx11 = "1.8.12"}["< 1.11.3+0"]. Its latest version (1.11.3+1) has components: {libssh2 = "1.11.1"}libssh:libssh. Its latest version (0.11.3+0) has components: {libssh = "0.11.3"}["< 9.9.1+0"]. Its latest version (10.2.1+0) has components: {openssh = "10.2p1"}[">= 6.1.1+0, < 7.1.0+0"]. Its latest version (8.0.0+0) has components: {ffmpeg = "8.0"}ffmpeg:ffmpeg. Its latest version (7.1.1+0) has components: {ffmpeg = "7.1.1"}["< 9.9.1+0"]. Its latest version (10.2.1+0) has components: {openssh = "10.2p1"}["< 2.6.2+0"]. Its latest version (2.7.3+0) has components: {expat = "2.7.3"}["< 2.6.2+0"]. Its latest version (2.7.3+0) has components: {expat = "2.7.3"}["< 3.2.4+0"]. Its latest version (3.2.4+0) has components: {openexr = "3.2.4"}["< 2.28.10+0"]. Its latest version (2.28.10+0) has components: {mbedtls = "2.28.10"}["< 2.28.10+0"]. Its latest version (2.28.10+0) has components: {mbedtls = "2.28.10"}["< 2.40.1+0"]. Its latest version (2.41.2+0) has components: {util-linux = "2.41.2"}["< 2.40.0+0"]. Its latest version (2.41.2+0) has components: {util-linux = "2.41.2"}["< 2.40.0+0"]. Its latest version (2.41.2+0) has components: {util-linux = "2.41.2"}["< 1.61.0+0"]. Its latest version (1.68.0+1) has components: {nghttp2 = "1.68.0", nghttp2-libs = "*"}["< 2.6.2+0"]. Its latest version (2.7.3+0) has components: {expat = "2.7.3"}["< 2.28.10+0"]. Its latest version (2.28.10+0) has components: {mbedtls = "2.28.10"}["< 7.1.0+0"]. Its latest version (8.0.0+0) has components: {ffmpeg = "8.0"}["< 7.1.0+0"]. Its latest version (7.1.1+0) has components: {ffmpeg = "7.1.1"}[">= 6.1.1+0, < 7.1.0+0"]. Its latest version (8.0.0+0) has components: {ffmpeg = "8.0"}ffmpeg:ffmpeg. Its latest version (7.1.1+0) has components: {ffmpeg = "7.1.1"}["< 2.46.2+0"]. Its latest version (2.51.3+0) has components: {git-for-windows = "2.51.2.windows.1", git = "2.51.2"}["< 2.12.7+0"]. Its latest version (2.15.1+0) has components: {libxml2 = "2.15.1"}["< 2.6.4+0"]. Its latest version (2.7.3+0) has components: {expat = "2.7.3"}["< 2.6.4+0"]. Its latest version (2.7.3+0) has components: {expat = "2.7.3"}["< 2.6.4+0"]. Its latest version (2.7.3+0) has components: {expat = "2.7.3"}["< 3.0.14+0"]. Its latest version (3.5.4+0) has components: {openssl = "3.5.4"}[">= 1.19.9+0, < 1.27.1+0"]. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}["< 2.50.1+0"]. Its latest version (2.51.3+0) has components: {git-for-windows = "2.51.2.windows.1", git = "2.51.2"}["< 2.7.3+0"]. Its latest version (2.7.3+0) has components: {expat = "2.7.3"}["< 10.1.1+0"]. Its latest version (10.2.1+0) has components: {openssh = "10.2p1"}[">= 3.5.0+0, < 3.5.4+0"]. Its latest version (3.5.4+0) has components: {openssl = "3.5.4"}OpenSSL:OpenSSL. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}[">= 3.0.16+0, < 3.5.4+0"]. Its latest version (3.5.4+0) has components: {openssl = "3.5.4"}OpenSSL:OpenSSL. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}