[automatic] Publish 5 advisories for 4 packages #165
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This action searched
recent NVD/EUVD changes/publications, checking 408 (+0) advisories from NVD and 527 (+264) from EUVD for advisories that pertain here. It identified 5 advisories as being related to the Julia package(s): Poppler_jll, XML2_jll, GnuPG_jll, and HTTP.3 advisories apply to all registered versions of a package
These advisories had no obvious failures but computed a range without bounds.
["*"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}freedesktop:popplerat<= 24.12.0includes all versions["*"]. Its latest version (2.4.7+0) has components: {gnupg = "2.4.7"}gnupg:gnupgat< 2.5.5includes all versions["*"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}freedesktop:popplerat< 25.06.0includes all versions2 advisories found concrete vulnerable ranges
["< 2.12.7+0"]. Its latest version (2.14.4+0) has components: {libxml2 = "2.14.4"}["< 1.10.19"].