[automatic] Publish 5 advisories for 7 packages #207
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This action searched
--project=zlib, checking 13 (+0) advisories from NVD and 0 (+3) from EUVD for advisories that pertain here. It identified 5 advisories as being related to the Julia package(s): Zlib_jll, Openresty_jll, GCCBootstrap_jll, CURL_jll, LibCURL_jll, boost_jll, and Python_jll.3 advisories apply to all registered versions of a package
These advisories had no obvious failures but computed a range without bounds.
["< 3.10.7+0"]. Its latest version (3.11.12+0) has components: {"python:idle" = "3.11.12", python = "3.11.12"}["< 1.2.12+3"]. Its latest version (1.3.1+2) has components: {zlib = "1.3.1"}mariadb:mariadb. Its latest version (3.3.9+0) has components: {mariadb-connector-c = "3.3.9"}["< 1.21.4+0"]. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}["*"]. Its latest version (9.4.0+0) has components: {mingw-w64-headers = "9.0.0", gettext = "0.21", crosstool-ng = "1.25.0_rc1", isl = "0.24", gmp = "6.2.1", gnumpc = "1.2.1", zlib = "1.2.11", libiconv = "1.16", mpfr = "4.1.0", musl = "1.2.2"}zlib:zlibat>= 1.2.2.2, < 1.2.12includes all versions["< 1.2.13+0"]. Its latest version (1.3.1+2) has components: {zlib = "1.3.1"}["< 1.27.1+0"]. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}["*"]. Its latest version (9.4.0+0) has components: {mingw-w64-headers = "9.0.0", gettext = "0.21", crosstool-ng = "1.25.0_rc1", isl = "0.24", gmp = "6.2.1", gnumpc = "1.2.1", zlib = "1.2.11", libiconv = "1.16", mpfr = "4.1.0", musl = "1.2.2"}zlib:zlibat<= 1.2.12includes all versions["< 1.3.1+0"]. Its latest version (1.3.1+2) has components: {zlib = "1.3.1"}["< 1.27.1+0"]. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}["*"]. Its latest version (9.4.0+0) has components: {mingw-w64-headers = "9.0.0", gettext = "0.21", crosstool-ng = "1.25.0_rc1", isl = "0.24", gmp = "6.2.1", gnumpc = "1.2.1", zlib = "1.2.11", libiconv = "1.16", mpfr = "4.1.0", musl = "1.2.2"}zlib:zlibat< 1.3.1includes all versions2 advisories found concrete vulnerable ranges
zlib:zlib. Its latest version (9.4.0+0) has components: {mingw-w64-headers = "9.0.0", gettext = "0.21", crosstool-ng = "1.25.0_rc1", isl = "0.24", gmp = "6.2.1", gnumpc = "1.2.1", zlib = "1.2.11", libiconv = "1.16", mpfr = "4.1.0", musl = "1.2.2"}nodejs:node.js. Its latest version (18.12.1+0) has components: {node-v = "18.12.1", nodejs = "18.12.1"}zlib:zlib. Its latest version (1.3.1+2) has components: {zlib = "1.3.1"}zlib:zlib. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}["< 1.79.0+0"]. Its latest version (1.87.0+0) has components: {boost = "1.87.0"}["< 8.13.0+0"]. Its latest version (8.16.0+0) has components: {curl = "8.16.0"}["< 8.12.0+0"]. Its latest version (8.16.0+0) has components: {curl = "8.16.0"}