Skip to content

Conversation

@jlsec-bot
Copy link
Contributor

@jlsec-bot jlsec-bot commented Nov 1, 2025

This action searched recent NVD/EUVD changes/publications, checking 400 (+1) advisories from NVD and 553 (+287) from EUVD for advisories that pertain here. It identified 2 advisories as being related to the Julia package(s): nghttp2_jll, libnode_jll , and MbedTLS_jll.

1 advisories apply to the latest version of a package and do not have a patch

  • CVE-2023-44487 for packages: nghttp2_jll, and libnode_jll
    • nghttp2_jll computed ["< 1.58.0+0"]. Its latest version (1.68.0+1) has components: {nghttp2 = "1.68.0", nghttp2-libs = "*"}
    • libnode_jll computed [">= 18.12.1+0"]. Its latest version (18.12.1+0) has components: {node-v = "18.12.1", nodejs = "18.12.1"}
      • nodejs:node.js at >= 18.0.0, < 18.18.2 mapped to [>= 18.12.1+0], includes the latest version`

@mbauman
Copy link
Member

mbauman commented Nov 3, 2025

Let's defer mbedtls to #125.

@mbauman mbauman changed the title [automatic] Publish 2 advisories for nghttp2_jll, libnode_jll and MbedTLS_jll [automatic] Publish 1 advisories for nghttp2_jll and libnode_jll Nov 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants