[automatic] Publish 6 advisories for 5 packages #174
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This action searched
recent NVD/EUVD changes/publications, checking 587 (+20) advisories from NVD and 373 (+263) from EUVD for advisories that pertain here. It identified 6 advisories as being related to the Julia package(s): Perl_jll, XML2_jll, libssh_jll, GnuPG_jll, and LibArchive_jll.1 advisories failed to parse the source version range
These advisories seem to apply to a Julia package but had trouble identifying exactly how and at which versions.
["*"]. Its latest version (0.11.1+0) has components: {libssh = "0.11.1"}libssh:libsshat `` failed to parse1 advisories apply to all registered versions of a package
These advisories had no obvious failures but computed a range without bounds.
["*"]. Its latest version (2.4.7+0) has components: {gnupg = "2.4.7"}gnupg:gnupgat< 2.4.8includes all versions1 advisories apply to the latest version of a package and do not have a patch
[">= 5.34.0+0"]. Its latest version (5.34.1+0) has components: {"perl:xml-namespacesupport" = "1.12", "perl:file-which" = "1.27", "perl:getopt-tabular" = "0.3", "perl:regexp-common" = "2017060201", "perl:json" = "4.03", "perl:xml-sax" = ["1.02", "Base-1.09"], "perl:term-readline-gnu" = "1.42", "perl:xml-writer" = "0.900", "perl:exporter-lite" = "0.08", perl = "5.34.1", "perl:term-readkey" = "2.38"}perl:perlat>= 5.33.1, < 5.38.4mapped to[>= 5.34.0+0], includes the latest version`3 advisories found concrete vulnerable ranges
["< 2.13.6+1"]. Its latest version (2.15.0+0) has components: {libxml2 = "2.15.0"}["< 2.13.6+1"]. Its latest version (2.15.0+0) has components: {libxml2 = "2.15.0"}["< 3.8.0+0"]. Its latest version (3.8.1+0) has components: {libarchive = "3.8.1"}