Skip to content

Conversation

@github-actions
Copy link
Contributor

Automated changes by create-pull-request GitHub action

Copy link
Collaborator

@daniel-noland daniel-noland left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@daniel-noland daniel-noland enabled auto-merge (rebase) October 19, 2025 19:17
@qmonnet qmonnet closed this Oct 19, 2025
auto-merge was automatically disabled October 19, 2025 20:01

Pull request was closed

@qmonnet qmonnet reopened this Oct 19, 2025
@qmonnet qmonnet enabled auto-merge (rebase) October 19, 2025 20:02
@github-actions
Copy link
Contributor Author

Outdated packages (gnu64):

priority nix_package version_local version_nixpkgs version_upstream
15 libunistring 1.3 1.3 1.4.1
13 glibc 2.40-66 2.40-66 2.42
12 gcc 14.3.0 14.3.0 15.2.0;15.2
12 libxml2 2.14.6 2.14.6 2.15.1
11 binutils 2.44 2.44 2.45
11 llvm 20.1.8 21.1.1 21.1.3
10 coreutils 9.7 9.7 9.8
5 perl 5.40.0 5.40.0 5.42.0;5.42
4 openssl 3.5.2 1.1.1w 3.6.0
4 openssl 3.5.2 3.5.2 3.6.0
4 numactl 2.0.18 2.0.18 2.0.19
4 expat 2.7.2 2.7.2 2.7.3
4 kmod 31 31 34.2

@github-actions
Copy link
Contributor Author

Vulnerable packages (gnu64):

vuln_id url package severity version_local version_nixpkgs version_upstream package_repology sortcol classify
CVE-2025-49796 https://nvd.nist.gov/vuln/detail/CVE-2025-49796 libxml2 9.1 2.14.6 2.14.6 2.15.1 libxml2 2025A0000049796 err_not_vulnerable_based_on_repology
CVE-2025-49795 https://nvd.nist.gov/vuln/detail/CVE-2025-49795 libxml2 7.5 2.14.6 2.14.6 2.15.1 libxml2 2025A0000049795 err_not_vulnerable_based_on_repology
CVE-2025-49794 https://nvd.nist.gov/vuln/detail/CVE-2025-49794 libxml2 9.1 2.14.6 2.14.6 2.15.1 libxml2 2025A0000049794 err_not_vulnerable_based_on_repology
CVE-2025-9232 https://nvd.nist.gov/vuln/detail/CVE-2025-9232 openssl 5.9 3.5.2 3.5.2 3.6.0 openssl 2025A0000009232 err_not_vulnerable_based_on_repology
CVE-2025-9231 https://nvd.nist.gov/vuln/detail/CVE-2025-9231 openssl 6.5 3.5.2 3.5.2 3.6.0 openssl 2025A0000009231 err_not_vulnerable_based_on_repology
CVE-2025-9230 https://nvd.nist.gov/vuln/detail/CVE-2025-9230 openssl 7.5 3.5.2 3.5.2 3.6.0 openssl 2025A0000009230 err_not_vulnerable_based_on_repology
CVE-2025-8225 https://nvd.nist.gov/vuln/detail/CVE-2025-8225 binutils 3.3 2.44 2.44 2.45 binutils 2025A0000008225 fix_update_to_version_upstream
CVE-2025-8224 https://nvd.nist.gov/vuln/detail/CVE-2025-8224 binutils 3.3 2.44 2.44 2.45 binutils 2025A0000008224 fix_update_to_version_upstream
CVE-2025-6170 https://nvd.nist.gov/vuln/detail/CVE-2025-6170 libxml2 2.5 2.14.6 2.14.6 2.15.1 libxml2 2025A0000006170 err_not_vulnerable_based_on_repology
CVE-2025-6021 https://nvd.nist.gov/vuln/detail/CVE-2025-6021 libxml2 7.5 2.14.6 2.14.6 2.15.1 libxml2 2025A0000006021 err_not_vulnerable_based_on_repology
CVE-2025-5702 https://nvd.nist.gov/vuln/detail/CVE-2025-5702 glibc 5.6 2.40-66 2.40-66 2.42 glibc 2025A0000005702 fix_update_to_version_upstream
CVE-2025-5245 https://nvd.nist.gov/vuln/detail/CVE-2025-5245 binutils 5.3 2.44 2.44 2.45 binutils 2025A0000005245 fix_update_to_version_upstream
CVE-2025-5244 https://nvd.nist.gov/vuln/detail/CVE-2025-5244 binutils 5.3 2.44 2.44 2.45 binutils 2025A0000005244 fix_update_to_version_upstream
CVE-2025-3198 https://nvd.nist.gov/vuln/detail/CVE-2025-3198 binutils 3.3 2.44 2.44 2.45 binutils 2025A0000003198 fix_update_to_version_upstream
CVE-2025-1153 https://nvd.nist.gov/vuln/detail/CVE-2025-1153 binutils 3.1 2.44 2.44 2.45 binutils 2025A0000001153 fix_update_to_version_upstream
CVE-2023-6992 https://nvd.nist.gov/vuln/detail/CVE-2023-6992 zlib 4.0 1.3.1 1.3.1 1.3.1 zlib 2023A0000006992 err_not_vulnerable_based_on_repology
CVE-2023-4039 https://nvd.nist.gov/vuln/detail/CVE-2023-4039 gcc 4.8 14.3.0 14.3.0 15.2.0 gcc 2023A0000004039 fix_not_available
CVE-2016-2781 https://nvd.nist.gov/vuln/detail/CVE-2016-2781 coreutils 6.5 9.7 9.7 9.8 coreutils 2016A0000002781 fix_not_available

@qmonnet qmonnet merged commit 5811549 into main Oct 19, 2025
7 checks passed
@qmonnet qmonnet deleted the bump/main branch October 19, 2025 20:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants