[automatic] Publish and update 8 advisories for 7 packages #248
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This action searched
recent NVD/EUVD changes/publications, checking 460 (+2) advisories from NVD and 657 (+283) from EUVD for advisories that pertain here. It identified 8 advisories as being related to the Julia package(s): Libgcrypt_jll, GnuTLS_jll, wolfSSL_jll, MbedTLS_jll, XML2_jll, Kerberos_krb5_jll, and systemd_jll.2 advisories apply to all registered versions of a package
These advisories had no obvious failures but computed a range without bounds.
["*"]. Its latest version (256.7.0+0) has components: {systemd = "256.7"}systemd_project:systemdat>= 256, < 256.14mapped to[>= 256.7.0+0], includes the latest version`["*"]. Its latest version (5.7.2+0) has components: {wolfssl = "5.7.2-stable"}wolfssl:wolfsslat>= 3.15.0, <= 5.8.0includes all versions6 advisories found concrete vulnerable ranges
["< 2.9.10+0"]. Its latest version (2.15.1+0) has components: {libxml2 = "2.15.1"}["< 1.21.3+0"]. Its latest version (1.21.3+0) has components: {krb5 = "1.21.3"}["< 2.16.8+0"]. Its latest version (2.28.1010+0) has components: {mbedtls = "2.28.10"}[">= 2.9.10+0, < 2.9.12+0"]. Its latest version (2.15.1+0) has components: {libxml2 = "2.15.1"}["< 3.7.1+0"]. Its latest version (3.8.4+0) has components: {gnutls = "3.8.4"}["< 1.8.11+0"]. Its latest version (1.11.1+0) has components: {libgcrypt = "1.11.0"}