|
|
Log in / Subscribe / Register

SUSE alert openSUSE-SU-2026:0244-1 (gosec)

From:  maintenance@opensuse.org
To:  security-announce@lists.opensuse.org
Subject:  openSUSE-SU-2026:0244-1: important: Security update for gosec
Date:  Wed, 15 Jul 2026 00:05:05 +0200
Message-ID:  <20260714220505.57841FCD7@maintenance.suse.de>
Archive-link:  Article

openSUSE Security Update: Security update for gosec ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0244-1 Rating: important References: #1265919 #1266209 #1266793 #1267195 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for gosec fixes the following issues: - Fixing multiple vulnerabilities in the following embedded dependencies: golang.org/x/crypto/ssh (bsc#1266209), golang.org/x/net/html (bsc#1267195), golang.org/x/net/idna (bsc#1266793), golang.org/x/net/http2 (bsc#1265919). - Update to version 2.27.1: * Downgrade google lib to avoid min Go version bump (#1687) * Downgrade the jsonschema dep to v0.13.0 due to incompatibility with anthropick-sdk-go (#1686) * Update all dependencies (#1685) * Downgrade the github.com/invopop/jsonschema v0.13.0 to solve incopatibility with anthropic-sdk (#1683) * Update all dependencies (#1682) * Update vulnerabilities alerts for indirect dependencies * Pin dependencies (#1681) * Skip pining for my repos * Update renovate configuration * Fix typo * Update branch config in renovate config * Migrate config renovate.json (#1678) * Update renovate to refresh the branch creation * Update the renovate branch prefix * Update renovate config to pin the actions dependencies by digests (#1676) * Migrate the html remport to react v19. (#1675) * Manually update version to fix renovate (#1674) * feat: integrate Atlas Cloud provider (#1672) * Refactor error position parsing to support path with colon. (#1673) * Add two options to require rule ID and justificaiton for inline annotations (#1671) * Fix false positive in G118 when cancel is stored in a slice/map (#1670) * chore(go): update supported Go versions to 1.25.10 and 1.26.3 (#1669) * Harden the github workflows and action (#1665) * Fix justification delimiter in annotation format doc (#1661) * Update all dependencies (#1664) * Update action to use gosec version v2.26.1 (#1660) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-244=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): gosec-2.27.1-bp157.2.9.1 References: https://bugzilla.suse.com/1265919 https://bugzilla.suse.com/1266209 https://bugzilla.suse.com/1266793 https://bugzilla.suse.com/1267195


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds