Skip to content

Update lots of components #15

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Apr 21, 2025
Merged

Update lots of components #15

merged 1 commit into from
Apr 21, 2025

Conversation

nmburgan
Copy link
Member

@nmburgan nmburgan force-pushed the component_updates branch from 4a9f0a4 to 1987cfb Compare April 18, 2025 18:33
bastelfreak
bastelfreak previously approved these changes Apr 18, 2025
silug
silug previously approved these changes Apr 18, 2025
@nmburgan nmburgan force-pushed the component_updates branch 4 times, most recently from 108cd7f to cd1bdc8 Compare April 19, 2025 03:39
- curl 8.13.0
- dmidecode 3.6
- git 2.49.0 - Addresses CVE-2024-50349, CVE-2024-52006 (Note, this is only used in PDK, not the agent)
- libffi 3.4.8 - Addresses CVE-2024-56171, CVE-2025-24928, CVE-2025-32414, CVE-2025-32415
- libxslt 1.1.43 - Addresses CVE-2024-55549, CVE-2025-24855
- OpenSSL 3.0.16 - Addresses CVE-2024-13176, CVE-2024-9143
- Ruby 3.2.8 - Addresses CVE-2025-27219, CVE-2025-27220, CVE-2025-27221
- eruby 1.13.1
- ffi 1.17.2 - Fixes an issue compiling on MacOS
- hiera-eyaml 4.2.0
- mini_portile2 2.8.8
- nokogiri 1.18.7 - Only used on MacOS, this update fixes a ton of different CVEs that were present in vendored versions of libxml2. CVE-2023-29469, CVE-2023-28484, CVE-2024-25062, CVE-2024-25062, CVE-2024-34459, CVE-2024-40896, CVE-2025-24928, CVE-2025-24855
- optimist 3.2.1
- prime 0.1.3
- sys-filesystem 1.4.5
- yaml-cpp 0.8.0
- boost 1.82
@nmburgan nmburgan force-pushed the component_updates branch from cd1bdc8 to 0333560 Compare April 19, 2025 03:39
@nmburgan nmburgan merged commit 0372aea into main Apr 21, 2025
2 checks passed
@nmburgan nmburgan deleted the component_updates branch April 21, 2025 21:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants