pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/lang



Module Name:    pkgsrc
Committed By:   bsiegert
Date:           Sat Sep  6 12:54:33 UTC 2025

Modified Files:
        pkgsrc/lang/go: version.mk
        pkgsrc/lang/go124: distinfo
        pkgsrc/lang/go125: distinfo

Log Message:
go: update to 1.24.7 and 1.25.1 (security)

These minor releases include 1 security fixes following the security policy:

-   net/http: CrossOriginProtection bypass patterns are over-broad

    When passing patterns to CrossOriginProtection.AddInsecureBypassPattern,
    requests that would have redirected to those patterns (e.g. without
    a trailing slash) were also exempted, which might be unexpected.

    Thanks to Marco Gazerro for reporting this issue.

    This is CVE-2025-47910 and Go issue https://go.dev/issue/75054.


To generate a diff of this commit:
cvs rdiff -u -r1.236 -r1.237 pkgsrc/lang/go/version.mk
cvs rdiff -u -r1.7 -r1.8 pkgsrc/lang/go124/distinfo
cvs rdiff -u -r1.1 -r1.2 pkgsrc/lang/go125/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/lang/go/version.mk
diff -u pkgsrc/lang/go/version.mk:1.236 pkgsrc/lang/go/version.mk:1.237
--- pkgsrc/lang/go/version.mk:1.236     Sun Aug 31 09:47:42 2025
+++ pkgsrc/lang/go/version.mk   Sat Sep  6 12:54:33 2025
@@ -1,4 +1,4 @@
-# $NetBSD: version.mk,v 1.236 2025/08/31 09:47:42 bsiegert Exp $
+# $NetBSD: version.mk,v 1.237 2025/09/06 12:54:33 bsiegert Exp $
 
 #
 # If bsd.prefs.mk is included before go-package.mk in a package, then this
@@ -6,8 +6,8 @@
 #
 .include "go-vars.mk"
 
-GO125_VERSION= 1.25.0
-GO124_VERSION= 1.24.6
+GO125_VERSION= 1.25.1
+GO124_VERSION= 1.24.7
 GO123_VERSION= 1.23.12
 GO122_VERSION= 1.22.12
 GO120_VERSION= 1.20.14

Index: pkgsrc/lang/go124/distinfo
diff -u pkgsrc/lang/go124/distinfo:1.7 pkgsrc/lang/go124/distinfo:1.8
--- pkgsrc/lang/go124/distinfo:1.7      Fri Aug 15 12:46:30 2025
+++ pkgsrc/lang/go124/distinfo  Sat Sep  6 12:54:33 2025
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.7 2025/08/15 12:46:30 bsiegert Exp $
+$NetBSD: distinfo,v 1.8 2025/09/06 12:54:33 bsiegert Exp $
 
-BLAKE2s (go1.24.6.src.tar.gz) = 58cbdca8e7c9de658a6213de8d2003dc140bfee43316d27a478e4b5045374b14
-SHA512 (go1.24.6.src.tar.gz) = 65f535c722f4a0f6111c9ed829677621e456a5bc969ccb99009da1ade096b2b1a648a44ccfa913543677c220baeaf1afe634ba8ba165d9474ac9433ac249c914
-Size (go1.24.6.src.tar.gz) = 30794139 bytes
+BLAKE2s (go1.24.7.src.tar.gz) = ce05bb8d4f1c68ad3f35466dd43aacb176c71cab03a355d15b1d3ae9c225851f
+SHA512 (go1.24.7.src.tar.gz) = 656bb879244ba888af18b6e609fb2c4bc067b919827b9026c3ee44b3e2d0c7bffde262945de989880066196846b669c215da2e8c5d9adfb8491bb5d52af0d49a
+Size (go1.24.7.src.tar.gz) = 30794506 bytes
 SHA1 (patch-misc_ios_clangwrap.sh) = 28ea4426336155d6720f7e16b43f0207b47a6dd8
 SHA1 (patch-src_cmd_dist_build.go) = cbb9576f832806b0cbef121ea38ba6a54db95bc3
 SHA1 (patch-src_crypto_x509_root__bsd.go) = 0b5dead901450967109303f873a2696c65ccac35

Index: pkgsrc/lang/go125/distinfo
diff -u pkgsrc/lang/go125/distinfo:1.1 pkgsrc/lang/go125/distinfo:1.2
--- pkgsrc/lang/go125/distinfo:1.1      Sat Aug 16 15:52:04 2025
+++ pkgsrc/lang/go125/distinfo  Sat Sep  6 12:54:33 2025
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.1 2025/08/16 15:52:04 bsiegert Exp $
+$NetBSD: distinfo,v 1.2 2025/09/06 12:54:33 bsiegert Exp $
 
-BLAKE2s (go1.25.0.src.tar.gz) = 02cdf6b4fb0c6a6095636544daf42ff50cc816efa30306624ea03e4f89b0e143
-SHA512 (go1.25.0.src.tar.gz) = 45030cd02ab0ed4feb74e12ad9dde544bf2255c4d1a48655fca5b643bbe690c75ea3dfac74a0e3e3c707c5af5e9171ae383a7a322e70fe824f9a47b6ffd42201
-Size (go1.25.0.src.tar.gz) = 31974753 bytes
+BLAKE2s (go1.25.1.src.tar.gz) = 72f1278bbe406337a11fef85da52063ce1fed9c9ae456ddaaf28f908980794ab
+SHA512 (go1.25.1.src.tar.gz) = e77ae799a0dcd4ded40a196c3645da5b7e808e417831d2c5441387b0fd0ed5f946b678305294c52fda0a258889225c24c6073bb0973c3531ba4aa107b6afe849
+Size (go1.25.1.src.tar.gz) = 31974863 bytes
 SHA1 (patch-misc_ios_clangwrap.sh) = 28ea4426336155d6720f7e16b43f0207b47a6dd8
 SHA1 (patch-src_cmd_dist_build.go) = cbb9576f832806b0cbef121ea38ba6a54db95bc3
 SHA1 (patch-src_crypto_x509_root__bsd.go) = 0b5dead901450967109303f873a2696c65ccac35



Home | Main Index | Thread Index | Old Index