[automatic] Publish and update 6 advisories for 6 packages #247
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This action searched
recent NVD/EUVD changes/publications, checking 529 (+0) advisories from NVD and 470 (+235) from EUVD for advisories that pertain here. It identified 6 advisories as being related to the Julia package(s): OpenSSL_jll, XML2_jll, Openresty_jll, Cares_jll, MbedTLS_jll, and GnuTLS_jll.1 advisories apply to all registered versions of a package
These advisories had no obvious failures but computed a range without bounds.
["*"]. Its latest version (2.28.1010+0) has components: {mbedtls = "2.28.10"}arm:mbed_tlsat<= 3.0.0includes all versions5 advisories found concrete vulnerable ranges
["< 2.9.12+0"]. Its latest version (2.15.1+0) has components: {libxml2 = "2.15.1"}["< 3.7.8+0"]. Its latest version (3.8.4+0) has components: {gnutls = "3.8.4"}["< 1.32.2+0"]. Its latest version (1.33.1+0) has components: {c-ares = "1.33.1"}[">= 3.0.8+0, < 3.0.12+0"]. Its latest version (3.5.4+0) has components: {openssl = "3.5.4"}openssl:openssl. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}["< 3.0.13+0"]. Its latest version (3.5.4+0) has components: {openssl = "3.5.4"}["< 1.27.1+0"]. Its latest version (1.27.1+0) has components: {openresty = "1.27.1.1", openssl = "3.0.15", pcre = "8.45", zlib = "1.3.1"}