pkgsrc-Changes archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
CVS commit: [pkgsrc-2025Q1] pkgsrc/lang
Module Name: pkgsrc
Committed By: maya
Date: Wed Apr 2 02:19:08 UTC 2025
Modified Files:
pkgsrc/lang/go [pkgsrc-2025Q1]: version.mk
pkgsrc/lang/go123 [pkgsrc-2025Q1]: PLIST distinfo
pkgsrc/lang/go124 [pkgsrc-2025Q1]: PLIST distinfo
Log Message:
Pullup ticket #6952 - requested by bsiegert
lang/go123: Security fix
lang/go124: Security fix
Revisions pulled up:
- lang/go/version.mk 1.229
- lang/go123/PLIST 1.8
- lang/go123/distinfo 1.10
- lang/go124/PLIST 1.3
- lang/go124/distinfo 1.3
---
Module Name: pkgsrc
Committed By: bsiegert
Date: Tue Apr 1 17:44:25 UTC 2025
Modified Files:
pkgsrc/lang/go: version.mk
pkgsrc/lang/go123: PLIST distinfo
pkgsrc/lang/go124: PLIST distinfo
Log Message:
Update go123 to 1.23.8 and go124 to 1.24.2
These minor releases include 1 security fixes following the security policy=
:
- net/http: request smuggling through invalid chunked data
The net/http package accepted data in the chunked transfer encoding
containing an invalid chunk-size line terminated by a bare LF.
When used in conjunction with a server or proxy which incorrectly
interprets a bare LF in a chunk extension as part of the extension,
this could permit request smuggling.
The net/http package now rejects chunk-size lines containing a bare LF.
Thanks to Jeppe Bonde Weikop for reporting this issue.
This is CVE-2025-22871 and Go issue https://go.dev/issue/71988.
View the release notes for more information.
To generate a diff of this commit:
cvs rdiff -u -r1.228 -r1.228.2.1 pkgsrc/lang/go/version.mk
cvs rdiff -u -r1.7 -r1.7.2.1 pkgsrc/lang/go123/PLIST
cvs rdiff -u -r1.9 -r1.9.2.1 pkgsrc/lang/go123/distinfo
cvs rdiff -u -r1.2 -r1.2.2.1 pkgsrc/lang/go124/PLIST \
pkgsrc/lang/go124/distinfo
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Modified files:
Index: pkgsrc/lang/go/version.mk
diff -u pkgsrc/lang/go/version.mk:1.228 pkgsrc/lang/go/version.mk:1.228.2.1
--- pkgsrc/lang/go/version.mk:1.228 Fri Mar 7 20:41:31 2025
+++ pkgsrc/lang/go/version.mk Wed Apr 2 02:19:08 2025
@@ -1,4 +1,4 @@
-# $NetBSD: version.mk,v 1.228 2025/03/07 20:41:31 bsiegert Exp $
+# $NetBSD: version.mk,v 1.228.2.1 2025/04/02 02:19:08 maya Exp $
#
# If bsd.prefs.mk is included before go-package.mk in a package, then this
@@ -6,8 +6,8 @@
#
.include "go-vars.mk"
-GO124_VERSION= 1.24.1
-GO123_VERSION= 1.23.7
+GO124_VERSION= 1.24.2
+GO123_VERSION= 1.23.8
GO122_VERSION= 1.22.12
GO121_VERSION= 1.21.13
GO120_VERSION= 1.20.14
Index: pkgsrc/lang/go123/PLIST
diff -u pkgsrc/lang/go123/PLIST:1.7 pkgsrc/lang/go123/PLIST:1.7.2.1
--- pkgsrc/lang/go123/PLIST:1.7 Fri Mar 7 20:41:31 2025
+++ pkgsrc/lang/go123/PLIST Wed Apr 2 02:19:08 2025
@@ -1,4 +1,4 @@
-@comment $NetBSD: PLIST,v 1.7 2025/03/07 20:41:31 bsiegert Exp $
+@comment $NetBSD: PLIST,v 1.7.2.1 2025/04/02 02:19:08 maya Exp $
bin/go${GOVERSSUFFIX}
bin/gofmt${GOVERSSUFFIX}
go123/CONTRIBUTING.md
@@ -9000,6 +9000,7 @@ go123/src/runtime/testdata/testprogcgo/b
go123/src/runtime/testdata/testprogcgo/bindm.c
go123/src/runtime/testdata/testprogcgo/bindm.go
go123/src/runtime/testdata/testprogcgo/callback.go
+go123/src/runtime/testdata/testprogcgo/callback_pprof.go
go123/src/runtime/testdata/testprogcgo/catchpanic.go
go123/src/runtime/testdata/testprogcgo/cgo.go
go123/src/runtime/testdata/testprogcgo/cgonocallback.c
Index: pkgsrc/lang/go123/distinfo
diff -u pkgsrc/lang/go123/distinfo:1.9 pkgsrc/lang/go123/distinfo:1.9.2.1
--- pkgsrc/lang/go123/distinfo:1.9 Fri Mar 7 20:41:31 2025
+++ pkgsrc/lang/go123/distinfo Wed Apr 2 02:19:08 2025
@@ -1,11 +1,11 @@
-$NetBSD: distinfo,v 1.9 2025/03/07 20:41:31 bsiegert Exp $
+$NetBSD: distinfo,v 1.9.2.1 2025/04/02 02:19:08 maya Exp $
BLAKE2s (80344887818a2321296ce7fa71cca8ca2520611d.diff) = 80c77c55780bbd3b61f54698a5790169566a5c1c142ea9cf6b3de4ff261375f6
SHA512 (80344887818a2321296ce7fa71cca8ca2520611d.diff) = a72fe9c2bba6191df1fb796fe55cc0fea2eb1809f7a4f148230a8be798e3b6820405e48a92a57da59d8fbe23d7d624b49cef9761852a62b4e81ba9dcaa7deaa6
Size (80344887818a2321296ce7fa71cca8ca2520611d.diff) = 3273 bytes
-BLAKE2s (go1.23.7.src.tar.gz) = fda562713c406d6f38739ee994d79f345315dbf4bd1042b1dfb463f18a562d55
-SHA512 (go1.23.7.src.tar.gz) = 79192b760ab6fcc9512fd879a9484a3566fdeec5eace36c54b728cd9cb033e7ac68065a42fc657b351a106d684b79fdbefbf682cf63209c0191e7e7c8c0a0147
-Size (go1.23.7.src.tar.gz) = 28181215 bytes
+BLAKE2s (go1.23.8.src.tar.gz) = 2cef7c1512b3878d657a9316990a39cfd6ce1922bde0e656dbb12e007ccf56ed
+SHA512 (go1.23.8.src.tar.gz) = 8e352a01484c168894026080ee4501180e327d734fb3d892ab17daac193964fcd5fd90033c9cf86d6ffe8b7e4da64bda83ba4501a6c05919bcefbe9e2467c771
+Size (go1.23.8.src.tar.gz) = 28182772 bytes
SHA1 (patch-misc_ios_clangwrap.sh) = 28ea4426336155d6720f7e16b43f0207b47a6dd8
SHA1 (patch-src_cmd_dist_build.go) = cbb9576f832806b0cbef121ea38ba6a54db95bc3
SHA1 (patch-src_crypto_x509_root__bsd.go) = 0b5dead901450967109303f873a2696c65ccac35
Index: pkgsrc/lang/go124/PLIST
diff -u pkgsrc/lang/go124/PLIST:1.2 pkgsrc/lang/go124/PLIST:1.2.2.1
--- pkgsrc/lang/go124/PLIST:1.2 Fri Mar 7 16:30:08 2025
+++ pkgsrc/lang/go124/PLIST Wed Apr 2 02:19:08 2025
@@ -1,4 +1,4 @@
-@comment $NetBSD: PLIST,v 1.2 2025/03/07 16:30:08 bsiegert Exp $
+@comment $NetBSD: PLIST,v 1.2.2.1 2025/04/02 02:19:08 maya Exp $
bin/go${GOVERSSUFFIX}
bin/gofmt${GOVERSSUFFIX}
go124/CONTRIBUTING.md
@@ -9853,6 +9853,7 @@ go124/src/runtime/testdata/testprogcgo/b
go124/src/runtime/testdata/testprogcgo/bindm.c
go124/src/runtime/testdata/testprogcgo/bindm.go
go124/src/runtime/testdata/testprogcgo/callback.go
+go124/src/runtime/testdata/testprogcgo/callback_pprof.go
go124/src/runtime/testdata/testprogcgo/catchpanic.go
go124/src/runtime/testdata/testprogcgo/cgo.go
go124/src/runtime/testdata/testprogcgo/cgonocallback.c
@@ -13228,6 +13229,8 @@ go124/test/fixedbugs/issue71680.go
go124/test/fixedbugs/issue71852.go
go124/test/fixedbugs/issue71857.go
go124/test/fixedbugs/issue71932.go
+go124/test/fixedbugs/issue72063.go
+go124/test/fixedbugs/issue72090.go
go124/test/fixedbugs/issue7214.go
go124/test/fixedbugs/issue7223.go
go124/test/fixedbugs/issue7272.go
Index: pkgsrc/lang/go124/distinfo
diff -u pkgsrc/lang/go124/distinfo:1.2 pkgsrc/lang/go124/distinfo:1.2.2.1
--- pkgsrc/lang/go124/distinfo:1.2 Fri Mar 7 16:30:08 2025
+++ pkgsrc/lang/go124/distinfo Wed Apr 2 02:19:08 2025
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.2 2025/03/07 16:30:08 bsiegert Exp $
+$NetBSD: distinfo,v 1.2.2.1 2025/04/02 02:19:08 maya Exp $
-BLAKE2s (go1.24.1.src.tar.gz) = 1c7804d3f49c0aaa82dfb463201b4bf3611daa85049e7b8ffee89bf835aa1246
-SHA512 (go1.24.1.src.tar.gz) = a924d6bdc7e7101917e6d063bc7b471390525394e79224c152997564657c4362b5600e0c8bf6ee857d345129ccf7368bdf4ed2251ab740446ea2abda144e6353
-Size (go1.24.1.src.tar.gz) = 30777528 bytes
+BLAKE2s (go1.24.2.src.tar.gz) = 40e468465c036116332e888fed7943ca92b5893a5b6835e32cbd87cbb3435b9f
+SHA512 (go1.24.2.src.tar.gz) = 6366a32f6678e7908b138f62dafeed96f7144b3b93505e75fba374b33727da8b1d087c1f979f493382b319758ebfcbeb30e9d7dadcb2923b628c8abe7db41c6f
+Size (go1.24.2.src.tar.gz) = 30787666 bytes
SHA1 (patch-misc_ios_clangwrap.sh) = 28ea4426336155d6720f7e16b43f0207b47a6dd8
SHA1 (patch-src_cmd_dist_build.go) = cbb9576f832806b0cbef121ea38ba6a54db95bc3
SHA1 (patch-src_crypto_x509_root__bsd.go) = 0b5dead901450967109303f873a2696c65ccac35
Home |
Main Index |
Thread Index |
Old Index