Skip to content

tez/0.10.4-r7: fix GHSA-mfj5-cf8g-g2fv

780895f
Select commit
Loading
Failed to load commit list.
Closed

tez/0.10.4-r7: cve remediation #52974

tez/0.10.4-r7: fix GHSA-mfj5-cf8g-g2fv
780895f
Select commit
Loading
Failed to load commit list.
Octo STS / ci-diff-report succeeded May 9, 2025 in 0s

Package diff

Package diff

Details

Package Diffs

aarch64/tez-0.10.4-r7.apk -> aarch64/tez-0.10.4-r8.apk

📦 Package diff:

  &apk.Package{
  	Name:        "tez",
- 	Version:     "0.10.4-r7",
+ 	Version:     "0.10.4-r8",
  	Arch:        "aarch64",
  	Description: "Apache Tez",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0x26, 0xae, 0x69, 0x3e, 0x35, 0x72, 0xf9, 0xbe, 0x2f, 0xe1, 0x76, 0x03, 0xed, 0x27, 0x66, 0xe2, // -|&.i>5r../.v..'f.|
- 		0xb5, 0x30, 0xbd, 0x73,                                                                         // -|.0.s|
+ 		0xc3, 0x7d, 0x9f, 0x77, 0x78, 0xb3, 0x56, 0x25, 0x39, 0x32, 0x48, 0xf3, 0xd8, 0x6b, 0xe4, 0x70, // +|.}.wx.V%92H..k.p|
+ 		0x1b, 0x28, 0x06, 0xbd,                                                                         // +|.(..|
  	},
  	Dependencies:     {"openjdk-8-default-jvm"},
  	Provides:         nil,
  	InstallIf:        nil,
- 	Size:             76395107,
+ 	Size:             76394648,
- 	InstalledSize:    81956349,
+ 	InstalledSize:    81956346,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-05-09 08:24:15 +0000 UTC",
+ 	BuildTime:        s"2025-05-09 21:17:48 +0000 UTC",
- 	BuildDate:        1746779055,
+ 	BuildDate:        1746825468,
  	RepoCommit: strings.Join({
- 		"6b03f7f82c075a794f3a04c8651d8c56b1b14d84",
+ 		"bb5be00f8515afc331b549ffcf33d3a2eb349e58",
  	}, ""),
  	Replaces: nil,
  	DataHash: "",
  }

➕ Added:

  • var/lib/db/sbom/tez-0.10.4-r8.spdx.json

➖ Removed:

  • var/lib/db/sbom/tez-0.10.4-r7.spdx.json

🔺 Changed:

.PKGINFO
- -rw-r--r-- 348 2025-05-09 08:24:15 .PKGINFO
+ -rw-r--r-- 348 2025-05-09 21:17:48 .PKGINFO
.melange.yaml
- -rw-r--r-- 12120 2025-05-09 08:24:15 .melange.yaml
+ -rw-r--r-- 12166 2025-05-09 21:17:48 .melange.yaml
usr/share/java/tez/LICENSE
- -rw-r--r-- 17263 2025-05-09 08:24:15 LICENSE
+ -rw-r--r-- 17263 2025-05-09 21:17:48 LICENSE
usr/share/java/tez/LICENSE-BSD-3clause
- -rw-r--r-- 1465 2025-05-09 08:24:15 LICENSE-BSD-3clause
+ -rw-r--r-- 1465 2025-05-09 21:17:48 LICENSE-BSD-3clause
usr/share/java/tez/LICENSE-CDDLv1.0
- -rw-r--r-- 16792 2025-05-09 08:24:15 LICENSE-CDDLv1.0
+ -rw-r--r-- 16792 2025-05-09 21:17:48 LICENSE-CDDLv1.0
usr/share/java/tez/LICENSE-CDDLv1.1-GPLv2_withCPE
- -rw-r--r-- 36261 2025-05-09 08:24:15 LICENSE-CDDLv1.1-GPLv2_withCPE
+ -rw-r--r-- 36261 2025-05-09 21:17:48 LICENSE-CDDLv1.1-GPLv2_withCPE
usr/share/java/tez/LICENSE-MIT
- -rw-r--r-- 1045 2025-05-09 08:24:15 LICENSE-MIT
+ -rw-r--r-- 1045 2025-05-09 21:17:48 LICENSE-MIT
usr/share/java/tez/LICENSE-SIL_OpenFontLicense-v1.1
- -rw-r--r-- 4128 2025-05-09 08:24:15 LICENSE-SIL_OpenFontLicense-v1.1
+ -rw-r--r-- 4128 2025-05-09 21:17:48 LICENSE-SIL_OpenFontLicense-v1.1
usr/share/java/tez/NOTICE
- -rw-r--r-- 1510 2025-05-09 08:24:15 NOTICE
+ -rw-r--r-- 1510 2025-05-09 21:17:48 NOTICE
usr/share/java/tez/hadoop-shim-0.10.4.jar
- -rw-r--r-- 15904 2025-05-09 08:24:15 hadoop-shim-0.10.4.jar
-   APK-TOOLS.checksum.SHA1: "f1648a99100d1f8aec72a8708e15bf4a2c73de12"
+ -rw-r--r-- 15904 2025-05-09 21:17:48 hadoop-shim-0.10.4.jar
+   APK-TOOLS.checksum.SHA1: "384d5fe157028c7987034e108f8cfb0bea23b4f0"
  - ... and 185 more

x86_64/tez-0.10.4-r7.apk -> x86_64/tez-0.10.4-r8.apk

📦 Package diff:

  &apk.Package{
  	Name:        "tez",
- 	Version:     "0.10.4-r7",
+ 	Version:     "0.10.4-r8",
  	Arch:        "x86_64",
  	Description: "Apache Tez",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0x44, 0xfd, 0x41, 0x18, 0x28, 0x00, 0x80, 0x2f, 0x98, 0xfc, 0x7a, 0xe0, 0x94, 0x64, 0x79, 0x89, // -|D.A.(../..z..dy.|
- 		0xc0, 0xd7, 0x52, 0xee,                                                                         // -|..R.|
+ 		0x0f, 0x09, 0xdb, 0x7c, 0x53, 0xee, 0x40, 0x71, 0xcf, 0xc2, 0xe0, 0x05, 0xa1, 0xda, 0xce, 0x27, // +|...|S.@q.......'|
+ 		0xcd, 0xcd, 0xb7, 0x50,                                                                         // +|...P|
  	},
  	Dependencies:     {"openjdk-8-default-jvm"},
  	Provides:         nil,
  	InstallIf:        nil,
- 	Size:             76120471,
+ 	Size:             76120580,
- 	InstalledSize:    81645400,
+ 	InstalledSize:    81645397,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-05-09 08:24:15 +0000 UTC",
+ 	BuildTime:        s"2025-05-09 21:17:48 +0000 UTC",
- 	BuildDate:        1746779055,
+ 	BuildDate:        1746825468,
  	RepoCommit: strings.Join({
- 		"6b03f7f82c075a794f3a04c8651d8c56b1b14d84",
+ 		"bb5be00f8515afc331b549ffcf33d3a2eb349e58",
  	}, ""),
  	Replaces: nil,
  	DataHash: "",
  }

➕ Added:

  • var/lib/db/sbom/tez-0.10.4-r8.spdx.json

➖ Removed:

  • var/lib/db/sbom/tez-0.10.4-r7.spdx.json

🔺 Changed:

.PKGINFO
- -rw-r--r-- 347 2025-05-09 08:24:15 .PKGINFO
+ -rw-r--r-- 347 2025-05-09 21:17:48 .PKGINFO
.melange.yaml
- -rw-r--r-- 12084 2025-05-09 08:24:15 .melange.yaml
+ -rw-r--r-- 12130 2025-05-09 21:17:48 .melange.yaml
usr/share/java/tez/LICENSE
- -rw-r--r-- 17263 2025-05-09 08:24:15 LICENSE
+ -rw-r--r-- 17263 2025-05-09 21:17:48 LICENSE
usr/share/java/tez/LICENSE-BSD-3clause
- -rw-r--r-- 1465 2025-05-09 08:24:15 LICENSE-BSD-3clause
+ -rw-r--r-- 1465 2025-05-09 21:17:48 LICENSE-BSD-3clause
usr/share/java/tez/LICENSE-CDDLv1.0
- -rw-r--r-- 16792 2025-05-09 08:24:15 LICENSE-CDDLv1.0
+ -rw-r--r-- 16792 2025-05-09 21:17:48 LICENSE-CDDLv1.0
usr/share/java/tez/LICENSE-CDDLv1.1-GPLv2_withCPE
- -rw-r--r-- 36261 2025-05-09 08:24:15 LICENSE-CDDLv1.1-GPLv2_withCPE
+ -rw-r--r-- 36261 2025-05-09 21:17:48 LICENSE-CDDLv1.1-GPLv2_withCPE
usr/share/java/tez/LICENSE-MIT
- -rw-r--r-- 1045 2025-05-09 08:24:15 LICENSE-MIT
+ -rw-r--r-- 1045 2025-05-09 21:17:48 LICENSE-MIT
usr/share/java/tez/LICENSE-SIL_OpenFontLicense-v1.1
- -rw-r--r-- 4128 2025-05-09 08:24:15 LICENSE-SIL_OpenFontLicense-v1.1
+ -rw-r--r-- 4128 2025-05-09 21:17:48 LICENSE-SIL_OpenFontLicense-v1.1
usr/share/java/tez/NOTICE
- -rw-r--r-- 1510 2025-05-09 08:24:15 NOTICE
+ -rw-r--r-- 1510 2025-05-09 21:17:48 NOTICE
usr/share/java/tez/hadoop-shim-0.10.4.jar
- -rw-r--r-- 15904 2025-05-09 08:24:15 hadoop-shim-0.10.4.jar
-   APK-TOOLS.checksum.SHA1: "db4b3b5c73e122438d8eb7397025d03209d9ee12"
+ -rw-r--r-- 15904 2025-05-09 21:17:48 hadoop-shim-0.10.4.jar
+   APK-TOOLS.checksum.SHA1: "384d5fe157028c7987034e108f8cfb0bea23b4f0"
  - ... and 185 more