pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/lang



Module Name:    pkgsrc
Committed By:   bsiegert
Date:           Sat Jul 15 10:40:37 UTC 2023

Modified Files:
        pkgsrc/lang/go: version.mk
        pkgsrc/lang/go120: PLIST distinfo

Log Message:
go120: update to 1.20.6 (security)

This minor release includes 1 security fix following the security policy:

net/http: insufficient sanitization of Host header

The HTTP/1 client did not fully validate the contents of the Host header. A
maliciously crafted Host header could inject additional headers or entire
requests. The HTTP/1 client now refuses to send requests containing an invalid
Request.Host or Request.URL.Host value.

Thanks to Bartek Nowotarski for reporting this issue.

Includes security fixes for CVE-2023-29406 and Go issue
https://go.dev/issue/60374


To generate a diff of this commit:
cvs rdiff -u -r1.182 -r1.183 pkgsrc/lang/go/version.mk
cvs rdiff -u -r1.6 -r1.7 pkgsrc/lang/go120/PLIST pkgsrc/lang/go120/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/lang/go/version.mk
diff -u pkgsrc/lang/go/version.mk:1.182 pkgsrc/lang/go/version.mk:1.183
--- pkgsrc/lang/go/version.mk:1.182     Sat Jul 15 10:35:14 2023
+++ pkgsrc/lang/go/version.mk   Sat Jul 15 10:40:37 2023
@@ -1,4 +1,4 @@
-# $NetBSD: version.mk,v 1.182 2023/07/15 10:35:14 bsiegert Exp $
+# $NetBSD: version.mk,v 1.183 2023/07/15 10:40:37 bsiegert Exp $
 
 #
 # If bsd.prefs.mk is included before go-package.mk in a package, then this
@@ -6,7 +6,7 @@
 #
 .include "go-vars.mk"
 
-GO120_VERSION= 1.20.5
+GO120_VERSION= 1.20.6
 GO119_VERSION= 1.19.11
 GO118_VERSION= 1.18.10
 GO14_VERSION=  1.4.3

Index: pkgsrc/lang/go120/PLIST
diff -u pkgsrc/lang/go120/PLIST:1.6 pkgsrc/lang/go120/PLIST:1.7
--- pkgsrc/lang/go120/PLIST:1.6 Sat Jun 10 11:41:31 2023
+++ pkgsrc/lang/go120/PLIST     Sat Jul 15 10:40:37 2023
@@ -1,4 +1,4 @@
-@comment $NetBSD: PLIST,v 1.6 2023/06/10 11:41:31 bsiegert Exp $
+@comment $NetBSD: PLIST,v 1.7 2023/07/15 10:40:37 bsiegert Exp $
 bin/go${GOVERSSUFFIX}
 bin/gofmt${GOVERSSUFFIX}
 go120/CONTRIBUTING.md
@@ -2081,6 +2081,7 @@ go120/src/cmd/go/testdata/script/list_co
 go120/src/cmd/go/testdata/script/list_compiler_output.txt
 go120/src/cmd/go/testdata/script/list_constraints.txt
 go120/src/cmd/go/testdata/script/list_dedup_packages.txt
+go120/src/cmd/go/testdata/script/list_empty_import.txt
 go120/src/cmd/go/testdata/script/list_err_cycle.txt
 go120/src/cmd/go/testdata/script/list_err_stack.txt
 go120/src/cmd/go/testdata/script/list_export_e.txt
@@ -2391,6 +2392,7 @@ go120/src/cmd/go/testdata/script/mod_tid
 go120/src/cmd/go/testdata/script/mod_tidy_duplicates.txt
 go120/src/cmd/go/testdata/script/mod_tidy_error.txt
 go120/src/cmd/go/testdata/script/mod_tidy_indirect.txt
+go120/src/cmd/go/testdata/script/mod_tidy_issue60313.txt
 go120/src/cmd/go/testdata/script/mod_tidy_lazy_self.txt
 go120/src/cmd/go/testdata/script/mod_tidy_newroot.txt
 go120/src/cmd/go/testdata/script/mod_tidy_old.txt
@@ -8015,6 +8017,8 @@ go120/src/runtime/testdata/testwinlibsig
 go120/src/runtime/testdata/testwinlibthrow/main.go
 go120/src/runtime/testdata/testwinlibthrow/veh.c
 go120/src/runtime/testdata/testwinsignal/main.go
+go120/src/runtime/testdata/testwintls/main.c
+go120/src/runtime/testdata/testwintls/main.go
 go120/src/runtime/textflag.h
 go120/src/runtime/time.go
 go120/src/runtime/time_fake.go
@@ -11035,6 +11039,7 @@ go120/test/fixedbugs/issue5963.go
 go120/test/fixedbugs/issue6004.go
 go120/test/fixedbugs/issue6036.go
 go120/test/fixedbugs/issue6055.go
+go120/test/fixedbugs/issue60601.go
 go120/test/fixedbugs/issue6131.go
 go120/test/fixedbugs/issue6140.go
 go120/test/fixedbugs/issue6247.go
Index: pkgsrc/lang/go120/distinfo
diff -u pkgsrc/lang/go120/distinfo:1.6 pkgsrc/lang/go120/distinfo:1.7
--- pkgsrc/lang/go120/distinfo:1.6      Sat Jun 10 11:41:31 2023
+++ pkgsrc/lang/go120/distinfo  Sat Jul 15 10:40:37 2023
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.6 2023/06/10 11:41:31 bsiegert Exp $
+$NetBSD: distinfo,v 1.7 2023/07/15 10:40:37 bsiegert Exp $
 
-BLAKE2s (go1.20.5.src.tar.gz) = a739ed4608461945d17e7198d148bfb9ebee68c72debb61fda6059b5d45e3a46
-SHA512 (go1.20.5.src.tar.gz) = 94cecb366cd9d9722b53e52ea3b0a5715a9e9dc21da0273dd3db9354557f71b9501b018125ef073dacc2e59125335f436cea1151cd8df0d60e2ad513f841905c
-Size (go1.20.5.src.tar.gz) = 26192951 bytes
+BLAKE2s (go1.20.6.src.tar.gz) = ec2db20ad86617288f47694668a7ccd79e07acabf0f8a1c35f57b1b9d1580fb5
+SHA512 (go1.20.6.src.tar.gz) = 509ade7c2a76bd46b26dda4522692ceef5023aae21461b866006341f98544e7ea755aee230a9fea789ed7afb1c49a693c34c8337892e308dfb051aef2b08c975
+Size (go1.20.6.src.tar.gz) = 26194491 bytes
 SHA1 (patch-misc_ios_clangwrap.sh) = 0a06403609cb7bce2e6f65444fd322f486761afe
 SHA1 (patch-src_cmd_dist_util.go) = 2d9c2f59e27672d56f5f1a0e3f9d5101a05546a7
 SHA1 (patch-src_crypto_x509_root__bsd.go) = 0b5dead901450967109303f873a2696c65ccac35



Home | Main Index | Thread Index | Old Index