--- - branch: MAIN date: Sat Dec 23 20:00:23 UTC 2023 files: - new: '1.24' old: '1.23' path: pkgsrc/textproc/glow/Makefile pathrev: pkgsrc/textproc/glow/Makefile@1.24 type: modified - new: '1.3' old: '1.2' path: pkgsrc/textproc/glow/distinfo pathrev: pkgsrc/textproc/glow/distinfo@1.3 type: modified - new: '1.2' old: '1.1' path: pkgsrc/textproc/glow/go-modules.mk pathrev: pkgsrc/textproc/glow/go-modules.mk@1.2 type: modified - new: '1.1' old: '0' path: pkgsrc/textproc/glow/patches/patch-go.mod pathrev: pkgsrc/textproc/glow/patches/patch-go.mod@1.1 type: added - new: '1.1' old: '0' path: pkgsrc/textproc/glow/patches/patch-go.sum pathrev: pkgsrc/textproc/glow/patches/patch-go.sum@1.1 type: added id: 20231223T200023Z.9de5cc8730b2d94e817119b68a8d322bb29b7065 log: | glow: update to 1.5.1 - bugfixes Also manually fix the following vulnerability: Vulnerability #1: GO-2023-2402 Man-in-the-middle attacker can compromise integrity of secure channel in golang.org/x/crypto More info: https://pkg.go.dev/vuln/GO-2023-2402 Module: golang.org/x/crypto Found in: golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e Fixed in: golang.org/x/crypto@v0.17.0 module: pkgsrc subject: 'CVS commit: pkgsrc/textproc/glow' unixtime: '1703361623' user: bsiegert