[automatic] Publish 4 advisories for 5 packages #239
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This action searched
recent NVD/EUVD changes/publications, checking 853 (+0) advisories from NVD and 1092 (+595) from EUVD for advisories that pertain here. It identified 4 advisories as being related to the Julia package(s): Python_jll, Expat_jll, XML2_jll, SDL2_jll, and Ghostscript_jll.1 advisories apply to all registered versions of a package
These advisories had no obvious failures but computed a range without bounds.
["*"]. Its latest version (2.32.10+0) has components: {sdl2 = "*", sdl3 = "2.32.10"}libsdl:simple_directmedia_layerat>= 2.0.4, < 2.26.0includes all versionslibsdl:simple_directmedia_layermight mean a different project; it could be one ofsdl3orsdl23 advisories found concrete vulnerable ranges
["< 3.10.7+0"]. Its latest version (3.11.12+0) has components: {"python:idle" = "3.11.12", python = "3.11.12"}["< 2.4.4+0"]. Its latest version (2.7.3+0) has components: {expat = "2.7.3"}libjpeg-turbo:libjpeg-turbo. Its latest version (3.1.3+0) has components: {libjpeg-turbo = "3.1.2"}["< 9.55.0+0"]. Its latest version (9.55.1+0) has components: {ghostscript = "9.55.0"}[">= 2.11.5+0, < 2.13.3+0"]. Its latest version (2.15.1+0) has components: {libxml2 = "2.15.1"}