Received: by mail.netbsd.org (Postfix, from userid 605) id E255E84E84; Fri, 12 Aug 2022 16:15:05 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 27BBB84E67 for ; Fri, 12 Aug 2022 16:15:05 +0000 (UTC) X-Virus-Scanned: amavisd-new at netbsd.org Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.netbsd.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id 54Bgvjf0aKj4 for ; Fri, 12 Aug 2022 16:15:04 +0000 (UTC) Received: from cvs.NetBSD.org (ivanova.netbsd.org [199.233.217.197]) by mail.netbsd.org (Postfix) with ESMTP id 77E3384C71 for ; Fri, 12 Aug 2022 16:15:04 +0000 (UTC) Received: by cvs.NetBSD.org (Postfix, from userid 500) id 70DCBFB1A; Fri, 12 Aug 2022 16:15:04 +0000 (UTC) Content-Transfer-Encoding: 7bit Content-Type: multipart/mixed; boundary="_----------=_1660320904229440" MIME-Version: 1.0 Date: Fri, 12 Aug 2022 16:15:04 +0000 From: "Benny Siegert" Subject: CVS commit: pkgsrc/lang To: pkgsrc-changes@NetBSD.org Reply-To: bsiegert@netbsd.org X-Mailer: log_accum Message-Id: <20220812161504.70DCBFB1A@cvs.NetBSD.org> Sender: pkgsrc-changes-owner@NetBSD.org List-Id: Precedence: bulk List-Unsubscribe: This is a multi-part message in MIME format. --_----------=_1660320904229440 Content-Disposition: inline Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset="US-ASCII" Module Name: pkgsrc Committed By: bsiegert Date: Fri Aug 12 16:15:04 UTC 2022 Modified Files: pkgsrc/lang/go: version.mk pkgsrc/lang/go118: PLIST distinfo Log Message: go118: update to 1.18.5 (security) 1 security fix following the security policy: encoding/gob & math/big: decoding big.Float and big.Rat can panic Decoding big.Float and big.Rat types can panic if the encoded message is too short. This is CVE-2022-32189 and Go issue https://go.dev/issue/53871. To generate a diff of this commit: cvs rdiff -u -r1.154 -r1.155 pkgsrc/lang/go/version.mk cvs rdiff -u -r1.5 -r1.6 pkgsrc/lang/go118/PLIST pkgsrc/lang/go118/distinfo Please note that diffs are not public domain; they are subject to the copyright notices on the relevant files. --_----------=_1660320904229440 Content-Disposition: inline Content-Length: 3612 Content-Transfer-Encoding: binary Content-Type: text/x-diff; charset=us-ascii Modified files: Index: pkgsrc/lang/go/version.mk diff -u pkgsrc/lang/go/version.mk:1.154 pkgsrc/lang/go/version.mk:1.155 --- pkgsrc/lang/go/version.mk:1.154 Fri Aug 12 15:48:35 2022 +++ pkgsrc/lang/go/version.mk Fri Aug 12 16:15:04 2022 @@ -1,4 +1,4 @@ -# $NetBSD: version.mk,v 1.154 2022/08/12 15:48:35 bsiegert Exp $ +# $NetBSD: version.mk,v 1.155 2022/08/12 16:15:04 bsiegert Exp $ # # If bsd.prefs.mk is included before go-package.mk in a package, then this @@ -6,7 +6,7 @@ # .include "go-vars.mk" -GO118_VERSION= 1.18.4 +GO118_VERSION= 1.18.5 GO117_VERSION= 1.17.13 GO116_VERSION= 1.16.15 GO110_VERSION= 1.10.8 Index: pkgsrc/lang/go118/PLIST diff -u pkgsrc/lang/go118/PLIST:1.5 pkgsrc/lang/go118/PLIST:1.6 --- pkgsrc/lang/go118/PLIST:1.5 Wed Jul 13 15:02:02 2022 +++ pkgsrc/lang/go118/PLIST Fri Aug 12 16:15:04 2022 @@ -1,4 +1,4 @@ -@comment $NetBSD: PLIST,v 1.5 2022/07/13 15:02:02 bsiegert Exp $ +@comment $NetBSD: PLIST,v 1.6 2022/08/12 16:15:04 bsiegert Exp $ bin/go${GOVERSSUFFIX} bin/gofmt${GOVERSSUFFIX} go118/AUTHORS @@ -3063,6 +3063,7 @@ go118/src/cmd/go/testdata/script/work.tx go118/src/cmd/go/testdata/script/work_build_no_modules.txt go118/src/cmd/go/testdata/script/work_edit.txt go118/src/cmd/go/testdata/script/work_env.txt +go118/src/cmd/go/testdata/script/work_goproxy_off.txt go118/src/cmd/go/testdata/script/work_gowork.txt go118/src/cmd/go/testdata/script/work_init_gowork.txt go118/src/cmd/go/testdata/script/work_init_path.txt @@ -10789,6 +10790,7 @@ go118/test/fixedbugs/issue52612.go go118/test/fixedbugs/issue5291.dir/pkg1.go go118/test/fixedbugs/issue5291.dir/prog.go go118/test/fixedbugs/issue5291.go +go118/test/fixedbugs/issue52953.go go118/test/fixedbugs/issue53137.dir/main.go go118/test/fixedbugs/issue53137.go go118/test/fixedbugs/issue53454.go @@ -11634,14 +11636,12 @@ go118/test/typeparam/issue51836.dir/a.go go118/test/typeparam/issue51836.dir/aa.go go118/test/typeparam/issue51836.dir/p.go go118/test/typeparam/issue51836.go -go118/test/typeparam/issue51840.go go118/test/typeparam/issue52026.go go118/test/typeparam/issue52117.dir/a.go go118/test/typeparam/issue52117.dir/b.go go118/test/typeparam/issue52117.go go118/test/typeparam/issue52228.go go118/test/typeparam/issue52241.go -go118/test/typeparam/issue53309.go go118/test/typeparam/issue53419.go go118/test/typeparam/issue53477.go go118/test/typeparam/list.go Index: pkgsrc/lang/go118/distinfo diff -u pkgsrc/lang/go118/distinfo:1.5 pkgsrc/lang/go118/distinfo:1.6 --- pkgsrc/lang/go118/distinfo:1.5 Wed Jul 13 15:02:02 2022 +++ pkgsrc/lang/go118/distinfo Fri Aug 12 16:15:04 2022 @@ -1,8 +1,8 @@ -$NetBSD: distinfo,v 1.5 2022/07/13 15:02:02 bsiegert Exp $ +$NetBSD: distinfo,v 1.6 2022/08/12 16:15:04 bsiegert Exp $ -BLAKE2s (go1.18.4.src.tar.gz) = dd125a9933268dec6298dd40e64ac08906a2bbebdd827bf75a0b8884c3734fa1 -SHA512 (go1.18.4.src.tar.gz) = 4872956e31fa5d681021db12e876bc60a1815cf45203e75db83d6c54e9b7138766ae44bf1659db5333eba0b6097aea1990519795fffd2f124e7a78b78df1339b -Size (go1.18.4.src.tar.gz) = 22845866 bytes +BLAKE2s (go1.18.5.src.tar.gz) = 7c859789d63ca8a99845582df0ff049ab368d3f1c188699b3060391f2bdae527 +SHA512 (go1.18.5.src.tar.gz) = 4ba69ad49b5c17963fdc39ae7f5360fa38950db39ec1fb9b52744d6a209abf177dab6bd587e7457c83a4fd265589907ec241d8b09d0eac76cf984243a14500ef +Size (go1.18.5.src.tar.gz) = 22847094 bytes SHA1 (patch-misc_ios_clangwrap.sh) = 0a06403609cb7bce2e6f65444fd322f486761afe SHA1 (patch-src_cmd_dist_util.go) = 2d9c2f59e27672d56f5f1a0e3f9d5101a05546a7 SHA1 (patch-src_crypto_x509_root__bsd.go) = 0b5dead901450967109303f873a2696c65ccac35 --_----------=_1660320904229440--