Skip to content

tez/0.10.4-r7: fix GHSA-rhrv-645h-fjfh

4185731
Select commit
Loading
Failed to load commit list.
Closed

tez/0.10.4-r7: cve remediation #52977

tez/0.10.4-r7: fix GHSA-rhrv-645h-fjfh
4185731
Select commit
Loading
Failed to load commit list.
Octo STS / ci-diff-report succeeded May 9, 2025 in 0s

Package diff

Package diff

Details

Package Diffs

aarch64/tez-0.10.4-r7.apk -> aarch64/tez-0.10.4-r8.apk

📦 Package diff:

  &apk.Package{
  	Name:        "tez",
- 	Version:     "0.10.4-r7",
+ 	Version:     "0.10.4-r8",
  	Arch:        "aarch64",
  	Description: "Apache Tez",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0x26, 0xae, 0x69, 0x3e, 0x35, 0x72, 0xf9, 0xbe, 0x2f, 0xe1, 0x76, 0x03, 0xed, 0x27, 0x66, 0xe2, // -|&.i>5r../.v..'f.|
- 		0xb5, 0x30, 0xbd, 0x73,                                                                         // -|.0.s|
+ 		0x46, 0xc6, 0x39, 0xf3, 0xcb, 0x7e, 0xa4, 0x16, 0x51, 0x35, 0xdb, 0x46, 0x88, 0xb7, 0x11, 0x8c, // +|F.9..~..Q5.F....|
+ 		0x59, 0x55, 0xb2, 0x77,                                                                         // +|YU.w|
  	},
  	Dependencies:     {"openjdk-8-default-jvm"},
  	Provides:         nil,
  	InstallIf:        nil,
- 	Size:             76395107,
+ 	Size:             76394267,
- 	InstalledSize:    81956349,
+ 	InstalledSize:    81956341,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-05-09 08:24:15 +0000 UTC",
+ 	BuildTime:        s"2025-05-09 21:25:51 +0000 UTC",
- 	BuildDate:        1746779055,
+ 	BuildDate:        1746825951,
  	RepoCommit: strings.Join({
- 		"6",
  		"b",
- 		"03f7f82c075a794f3a04c8651d8c56b1b14d84",
+ 		"cb49eaa237497f7380eab513dc4b391b117bdeb",
  	}, ""),
  	Replaces: nil,
  	DataHash: "",
  }

➕ Added:

  • var/lib/db/sbom/tez-0.10.4-r8.spdx.json

➖ Removed:

  • var/lib/db/sbom/tez-0.10.4-r7.spdx.json

🔺 Changed:

.PKGINFO
- -rw-r--r-- 348 2025-05-09 08:24:15 .PKGINFO
+ -rw-r--r-- 348 2025-05-09 21:25:51 .PKGINFO
.melange.yaml
- -rw-r--r-- 12120 2025-05-09 08:24:15 .melange.yaml
+ -rw-r--r-- 12166 2025-05-09 21:25:51 .melange.yaml
usr/share/java/tez/LICENSE
- -rw-r--r-- 17263 2025-05-09 08:24:15 LICENSE
+ -rw-r--r-- 17263 2025-05-09 21:25:51 LICENSE
usr/share/java/tez/LICENSE-BSD-3clause
- -rw-r--r-- 1465 2025-05-09 08:24:15 LICENSE-BSD-3clause
+ -rw-r--r-- 1465 2025-05-09 21:25:51 LICENSE-BSD-3clause
usr/share/java/tez/LICENSE-CDDLv1.0
- -rw-r--r-- 16792 2025-05-09 08:24:15 LICENSE-CDDLv1.0
+ -rw-r--r-- 16792 2025-05-09 21:25:51 LICENSE-CDDLv1.0
usr/share/java/tez/LICENSE-CDDLv1.1-GPLv2_withCPE
- -rw-r--r-- 36261 2025-05-09 08:24:15 LICENSE-CDDLv1.1-GPLv2_withCPE
+ -rw-r--r-- 36261 2025-05-09 21:25:51 LICENSE-CDDLv1.1-GPLv2_withCPE
usr/share/java/tez/LICENSE-MIT
- -rw-r--r-- 1045 2025-05-09 08:24:15 LICENSE-MIT
+ -rw-r--r-- 1045 2025-05-09 21:25:51 LICENSE-MIT
usr/share/java/tez/LICENSE-SIL_OpenFontLicense-v1.1
- -rw-r--r-- 4128 2025-05-09 08:24:15 LICENSE-SIL_OpenFontLicense-v1.1
+ -rw-r--r-- 4128 2025-05-09 21:25:51 LICENSE-SIL_OpenFontLicense-v1.1
usr/share/java/tez/NOTICE
- -rw-r--r-- 1510 2025-05-09 08:24:15 NOTICE
+ -rw-r--r-- 1510 2025-05-09 21:25:51 NOTICE
usr/share/java/tez/hadoop-shim-0.10.4.jar
- -rw-r--r-- 15904 2025-05-09 08:24:15 hadoop-shim-0.10.4.jar
-   APK-TOOLS.checksum.SHA1: "f1648a99100d1f8aec72a8708e15bf4a2c73de12"
+ -rw-r--r-- 15904 2025-05-09 21:25:51 hadoop-shim-0.10.4.jar
+   APK-TOOLS.checksum.SHA1: "c2066afdbd4a85249ce93f1abd2b031f61710e14"
  - ... and 185 more

x86_64/tez-0.10.4-r7.apk -> x86_64/tez-0.10.4-r8.apk

📦 Package diff:

  &apk.Package{
  	Name:        "tez",
- 	Version:     "0.10.4-r7",
+ 	Version:     "0.10.4-r8",
  	Arch:        "x86_64",
  	Description: "Apache Tez",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0x44, 0xfd, 0x41, 0x18, 0x28, 0x00, 0x80, 0x2f, 0x98, 0xfc, 0x7a, 0xe0, 0x94, 0x64, 0x79, 0x89, // -|D.A.(../..z..dy.|
- 		0xc0, 0xd7, 0x52, 0xee,                                                                         // -|..R.|
+ 		0xc1, 0x07, 0x77, 0x15, 0xa6, 0xb8, 0xad, 0x8f, 0x54, 0xfa, 0xc2, 0xf2, 0xd7, 0xe9, 0xfd, 0x86, // +|..w.....T.......|
+ 		0x43, 0x22, 0x64, 0xba,                                                                         // +|C"d.|
  	},
  	Dependencies:     {"openjdk-8-default-jvm"},
  	Provides:         nil,
  	InstallIf:        nil,
- 	Size:             76120471,
+ 	Size:             76120128,
- 	InstalledSize:    81645400,
+ 	InstalledSize:    81645393,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-05-09 08:24:15 +0000 UTC",
+ 	BuildTime:        s"2025-05-09 21:25:51 +0000 UTC",
- 	BuildDate:        1746779055,
+ 	BuildDate:        1746825951,
  	RepoCommit: strings.Join({
- 		"6",
  		"b",
- 		"03f7f82c075a794f3a04c8651d8c56b1b14d84",
+ 		"cb49eaa237497f7380eab513dc4b391b117bdeb",
  	}, ""),
  	Replaces: nil,
  	DataHash: "",
  }

➕ Added:

  • var/lib/db/sbom/tez-0.10.4-r8.spdx.json

➖ Removed:

  • var/lib/db/sbom/tez-0.10.4-r7.spdx.json

🔺 Changed:

.PKGINFO
- -rw-r--r-- 347 2025-05-09 08:24:15 .PKGINFO
+ -rw-r--r-- 347 2025-05-09 21:25:51 .PKGINFO
.melange.yaml
- -rw-r--r-- 12084 2025-05-09 08:24:15 .melange.yaml
+ -rw-r--r-- 12130 2025-05-09 21:25:51 .melange.yaml
usr/share/java/tez/LICENSE
- -rw-r--r-- 17263 2025-05-09 08:24:15 LICENSE
+ -rw-r--r-- 17263 2025-05-09 21:25:51 LICENSE
usr/share/java/tez/LICENSE-BSD-3clause
- -rw-r--r-- 1465 2025-05-09 08:24:15 LICENSE-BSD-3clause
+ -rw-r--r-- 1465 2025-05-09 21:25:51 LICENSE-BSD-3clause
usr/share/java/tez/LICENSE-CDDLv1.0
- -rw-r--r-- 16792 2025-05-09 08:24:15 LICENSE-CDDLv1.0
+ -rw-r--r-- 16792 2025-05-09 21:25:51 LICENSE-CDDLv1.0
usr/share/java/tez/LICENSE-CDDLv1.1-GPLv2_withCPE
- -rw-r--r-- 36261 2025-05-09 08:24:15 LICENSE-CDDLv1.1-GPLv2_withCPE
+ -rw-r--r-- 36261 2025-05-09 21:25:51 LICENSE-CDDLv1.1-GPLv2_withCPE
usr/share/java/tez/LICENSE-MIT
- -rw-r--r-- 1045 2025-05-09 08:24:15 LICENSE-MIT
+ -rw-r--r-- 1045 2025-05-09 21:25:51 LICENSE-MIT
usr/share/java/tez/LICENSE-SIL_OpenFontLicense-v1.1
- -rw-r--r-- 4128 2025-05-09 08:24:15 LICENSE-SIL_OpenFontLicense-v1.1
+ -rw-r--r-- 4128 2025-05-09 21:25:51 LICENSE-SIL_OpenFontLicense-v1.1
usr/share/java/tez/NOTICE
- -rw-r--r-- 1510 2025-05-09 08:24:15 NOTICE
+ -rw-r--r-- 1510 2025-05-09 21:25:51 NOTICE
usr/share/java/tez/hadoop-shim-0.10.4.jar
- -rw-r--r-- 15904 2025-05-09 08:24:15 hadoop-shim-0.10.4.jar
-   APK-TOOLS.checksum.SHA1: "db4b3b5c73e122438d8eb7397025d03209d9ee12"
+ -rw-r--r-- 15904 2025-05-09 21:25:51 hadoop-shim-0.10.4.jar
+   APK-TOOLS.checksum.SHA1: "dde97ab01db565ba9e44dbe7be78e606a2362e2c"
  - ... and 185 more