[automatic] Publish 14 advisories for 5 packages #153
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This action searched
recent NVD/EUVD changes/publications
, checking 471 (+11) advisories from NVD and 5000 (+239) from EUVD for advisories that pertain here. It identified 14 advisories as being related to the Julia package(s): Exiv2_jll, Perl_jll, ImageMagick_jll, XML2_jll, and GnuTLS_jll.12 advisories apply to all registered versions of a package
These advisories had no obvious failures but computed a range without bounds.
["*"]
. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}exiv2:exiv2
at<= 0.27.4
includes all versions["*"]
. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}exiv2:exiv2
at<= 0.27.4
includes all versions["*"]
. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}exiv2:exiv2
at<= 0.27.4
includes all versions["*"]
. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}exiv2:exiv2
at<= 0.27.4
includes all versions["*"]
. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}exiv2:exiv2
at<= 0.27.4
includes all versions["*"]
. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}exiv2:exiv2
at<= 0.27.4
includes all versions["*"]
. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}exiv2:exiv2
at< 0.27.5
includes all versions["*"]
. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}exiv2:exiv2
at<= 0.27.4
includes all versions["*"]
. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}exiv2:exiv2
at<= 0.27.4
includes all versions["*"]
. Its latest version (0.27.4+0) has components: {exiv2 = "0.27.4"}exiv2:exiv2
at<= 0.27.4
includes all versions["*"]
. Its latest version (5.34.1+0) has components: {"perl:xml-namespacesupport" = "1.12", "perl:file-which" = "1.27", "perl:getopt-tabular" = "0.3", "perl:regexp-common" = "2017060201", "perl:json" = "4.03", "perl:xml-sax" = ["1.02", "Base-1.09"], "perl:term-readline-gnu" = "1.42", "perl:xml-writer" = "0.900", "perl:exporter-lite" = "0.08", perl = "5.34.1", "perl:term-readkey" = "2.38"}perl:perl
at>= 5.30.0, <= 5.38.0
includes all versions["*"]
. Its latest version (3.8.4+0) has components: {gnutls = "3.8.4"}gnu:gnutls
at< 3.8.10
includes all versions1 advisories apply to the latest version of a package and do not have a patch
[">= 6.9.12+0, < 6.9.12+4", ">= 7.1.0+0"]
. Its latest version (7.1.2005+0) has components: {imagemagick = "*"}imagemagick:imagemagick
at>= 6.9.12-0, < 6.9.12-22
mapped to[>= 6.9.12+0, < 6.9.12+4, >= 7.1.0+0], includes the latest version
imagemagick:imagemagick
at>= 7.1.0-0, < 7.1.0-7
mapped to[>= 7.1.0+0], includes the latest version
1 advisories found concrete vulnerable ranges
["< 2.12.0+0"]
. Its latest version (2.14.4+0) has components: {libxml2 = "2.14.4"}