[AUTO-CHERRYPICK] [AUTOPATCHER-CORE] Upgrade zstd to 1.5.4 CVE-2022-4899 - branch main (#8315)

This commit is contained in:
CBL-Mariner-Bot 2024-03-13 14:21:04 -07:00 committed by GitHub
parent ead84f492a
commit 72631720c7
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
7 changed files with 26 additions and 22 deletions

View File

@ -1,5 +1,5 @@
{
"Signatures": {
"zstd-1.5.0.tar.gz": "5194fbfa781fcf45b98c5e849651aa7b3b0a008c6b72d4a0db760f3002291e94"
}
"Signatures": {
"zstd-1.5.4.tar.gz": "0f470992aedad543126d06efab344dc5f3e171893810455787d38347343a4424"
}
}

View File

@ -1,6 +1,6 @@
Summary: Tools for zstd compression and decompression
Name: zstd
Version: 1.5.0
Version: 1.5.4
Release: 1%{?dist}
License: BSD or GPLv2
Vendor: Microsoft Corporation
@ -73,6 +73,10 @@ find %{buildroot} -type f -name "*.a" -delete -print
%{_mandir}/man1/*
%changelog
* Fri Mar 08 2024 Archana Choudhary <archana1@microsoft.com> - 1.5.4-1
- Auto-upgrade to 1.5.4 - CVE-2022-4899
- License verified
* Tue Oct 12 2021 Thomas Crain <thcrain@microsoft.com> - 1.5.0-1
- Upgrade to latest upstream version
- Change license tag to properly reflect dual licensing situation

View File

@ -30940,8 +30940,8 @@
"type": "other",
"other": {
"name": "zstd",
"version": "1.5.0",
"downloadUrl": "https://github.com/facebook/zstd/releases/download/v1.5.0/zstd-1.5.0.tar.gz"
"version": "1.5.4",
"downloadUrl": "https://github.com/facebook/zstd/releases/download/v1.5.4/zstd-1.5.4.tar.gz"
}
}
},

View File

@ -74,9 +74,9 @@ xz-5.2.5-1.cm2.aarch64.rpm
xz-devel-5.2.5-1.cm2.aarch64.rpm
xz-lang-5.2.5-1.cm2.aarch64.rpm
xz-libs-5.2.5-1.cm2.aarch64.rpm
zstd-1.5.0-1.cm2.aarch64.rpm
zstd-devel-1.5.0-1.cm2.aarch64.rpm
zstd-libs-1.5.0-1.cm2.aarch64.rpm
zstd-1.5.4-1.cm2.aarch64.rpm
zstd-devel-1.5.4-1.cm2.aarch64.rpm
zstd-libs-1.5.4-1.cm2.aarch64.rpm
libtool-2.4.6-8.cm2.aarch64.rpm
flex-2.6.4-7.cm2.aarch64.rpm
flex-devel-2.6.4-7.cm2.aarch64.rpm

View File

@ -74,9 +74,9 @@ xz-5.2.5-1.cm2.x86_64.rpm
xz-devel-5.2.5-1.cm2.x86_64.rpm
xz-lang-5.2.5-1.cm2.x86_64.rpm
xz-libs-5.2.5-1.cm2.x86_64.rpm
zstd-1.5.0-1.cm2.x86_64.rpm
zstd-devel-1.5.0-1.cm2.x86_64.rpm
zstd-libs-1.5.0-1.cm2.x86_64.rpm
zstd-1.5.4-1.cm2.x86_64.rpm
zstd-devel-1.5.4-1.cm2.x86_64.rpm
zstd-libs-1.5.4-1.cm2.x86_64.rpm
libtool-2.4.6-8.cm2.x86_64.rpm
flex-2.6.4-7.cm2.x86_64.rpm
flex-devel-2.6.4-7.cm2.x86_64.rpm

View File

@ -589,8 +589,8 @@ zip-debuginfo-3.0-5.cm2.aarch64.rpm
zlib-1.2.13-2.cm2.aarch64.rpm
zlib-debuginfo-1.2.13-2.cm2.aarch64.rpm
zlib-devel-1.2.13-2.cm2.aarch64.rpm
zstd-1.5.0-1.cm2.aarch64.rpm
zstd-debuginfo-1.5.0-1.cm2.aarch64.rpm
zstd-devel-1.5.0-1.cm2.aarch64.rpm
zstd-doc-1.5.0-1.cm2.aarch64.rpm
zstd-libs-1.5.0-1.cm2.aarch64.rpm
zstd-1.5.4-1.cm2.aarch64.rpm
zstd-debuginfo-1.5.4-1.cm2.aarch64.rpm
zstd-devel-1.5.4-1.cm2.aarch64.rpm
zstd-doc-1.5.4-1.cm2.aarch64.rpm
zstd-libs-1.5.4-1.cm2.aarch64.rpm

View File

@ -595,8 +595,8 @@ zip-debuginfo-3.0-5.cm2.x86_64.rpm
zlib-1.2.13-2.cm2.x86_64.rpm
zlib-debuginfo-1.2.13-2.cm2.x86_64.rpm
zlib-devel-1.2.13-2.cm2.x86_64.rpm
zstd-1.5.0-1.cm2.x86_64.rpm
zstd-debuginfo-1.5.0-1.cm2.x86_64.rpm
zstd-devel-1.5.0-1.cm2.x86_64.rpm
zstd-doc-1.5.0-1.cm2.x86_64.rpm
zstd-libs-1.5.0-1.cm2.x86_64.rpm
zstd-1.5.4-1.cm2.x86_64.rpm
zstd-debuginfo-1.5.4-1.cm2.x86_64.rpm
zstd-devel-1.5.4-1.cm2.x86_64.rpm
zstd-doc-1.5.4-1.cm2.x86_64.rpm
zstd-libs-1.5.4-1.cm2.x86_64.rpm