Skip to content

Conversation

mbauman
Copy link
Member

@mbauman mbauman commented Oct 6, 2025

No description provided.

mbauman and others added 10 commits October 6, 2025 21:10
* [create-pull-request] automated change

* Update advisories/published/2025/JLSEC-0000-mnro0hbsb-1apl96y.md

---------

Co-authored-by: mbauman <[email protected]>
Co-authored-by: Matt Bauman <[email protected]>
* [create-pull-request] automated change

* Use < range instead of <=

---------

Co-authored-by: mbauman <[email protected]>
* [create-pull-request] automated change

* Update advisories/published/2025/JLSEC-0000-mnro3zbxq-1uffgci.md

---------

Co-authored-by: mbauman <[email protected]>
Co-authored-by: Matt Bauman <[email protected]>
* [create-pull-request] automated change

* Update advisories/published/2025/JLSEC-0000-mnroszxl4-154kqvj.md

---------

Co-authored-by: mbauman <[email protected]>
Co-authored-by: Matt Bauman <[email protected]>
[Julia@6850940b8115ec6ee0ba9a7cd20185196620b097](JuliaLang/julia@6850940) was the one that upgraded OpenBLAS on master (v1.9-DEV). It was [back-ported to 1.8](JuliaLang/julia@1d93878). Julia v1.7 is vulnerable (https://github.com/JuliaLang/julia/blob/release-1.7/stdlib/OpenBLAS_jll/Project.toml).

[[email protected]+1](https://github.com/JuliaBinaryWrappers/libjulia_jll.jl/tree/libjulia-v1.8.0%2B1) was built with Julia@515a24240fcebc246d2bddbebd91c3800fc1fb3a, which is the first release of libjulia_jll to have the bumped openblas (https://github.com/JuliaLang/julia/blob/515a24240fcebc246d2bddbebd91c3800fc1fb3a/deps/openblas.version)
[automatic] Publish 1 advisory for 9 packages
@mbauman mbauman merged commit 5606786 into main Oct 8, 2025
2 checks passed
@mbauman mbauman deleted the mb/release branch October 8, 2025 17:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants