[automatic] Publish 4 advisories for nghttp2_jll and libnode_jll #203
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This action searched
--project=nghttp2, checking 7 (+0) advisories from NVD and 3 (+1) from EUVD for advisories that pertain here. It identified 4 advisories as being related to the Julia package(s): nghttp2_jll, and libnode_jll.1 advisories apply to the latest version of a package and do not have a patch
["< 1.58.0+0"]. Its latest version (1.67.1+0) has components: {nghttp2 = "1.67.1", nghttp2-libs = "*"}[">= 18.12.1+0"]. Its latest version (18.12.1+0) has components: {node-v = "18.12.1", nodejs = "18.12.1"}nodejs:node.jsat>= 18.0.0, < 18.18.2mapped to[>= 18.12.1+0], includes the latest version`3 advisories found concrete vulnerable ranges
["< 1.41.0+0"]. Its latest version (1.67.1+0) has components: {nghttp2 = "1.67.1", nghttp2-libs = "*"}nodejs:node.js. Its latest version (18.12.1+0) has components: {node-v = "18.12.1", nodejs = "18.12.1"}["< 1.58.0+0"]. Its latest version (1.67.1+0) has components: {nghttp2 = "1.67.1", nghttp2-libs = "*"}["< 1.61.0+0"]. Its latest version (1.67.1+0) has components: {nghttp2 = "1.67.1", nghttp2-libs = "*"}