Skip to content

gh: switch remediation bump to package pulling dep in recursively

1c6776b
Select commit
Loading
Failed to load commit list.
Merged

gh/2.83.1-r2: cve remediation #75109

gh: switch remediation bump to package pulling dep in recursively
1c6776b
Select commit
Loading
Failed to load commit list.
Octo STS / ci-diff-report succeeded Dec 11, 2025 in 0s

Package diff

Package diff

Details

Package Diffs

aarch64/gh-2.83.1-r2.apk -> aarch64/gh-2.83.1-r3.apk

📦 Package diff:

  &apk.Package{
  	Name:        "gh",
- 	Version:     "2.83.1-r2",
+ 	Version:     "2.83.1-r3",
  	Arch:        "aarch64",
  	Description: "GitHub's official command line tool",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0xc0, 0xbb, 0xac, 0x34, 0xc4, 0xa8, 0x8d, 0x16, 0x3c, 0x4d, 0x99, 0x71, 0xee, 0xc3, 0x62, 0x6e, // -|...4....<M.q..bn|
- 		0x8a, 0x67, 0x3a, 0x95,                                                                         // -|.g:.|
+ 		0xa0, 0x83, 0x8c, 0xf3, 0x7d, 0x20, 0xc9, 0xd0, 0x94, 0x63, 0xce, 0xc6, 0x40, 0x9c, 0x3c, 0xf7, // +|....} ...c..@.<.|
+ 		0x76, 0xad, 0x69, 0x73,                                                                         // +|v.is|
  	},
  	Dependencies:     nil,
- 	Provides:         []string{"cmd:gh=2.83.1-r2"},
+ 	Provides:         []string{"cmd:gh=2.83.1-r3"},
  	InstallIf:        nil,
- 	Size:             18215441,
+ 	Size:             13538198,
- 	InstalledSize:    60237263,
+ 	InstalledSize:    39243202,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-12-04 11:58:15 +0000 UTC",
+ 	BuildTime:        s"2025-12-11 21:02:25 +0000 UTC",
- 	BuildDate:        1764849495,
+ 	BuildDate:        1765486945,
- 	RepoCommit:       "unknown",
+ 	RepoCommit:       "97c060e33155d5d222059eb4dddd86eaecd18c83",
  	Replaces:         nil,
  	DataHash:         "",
  }

➕ Added:

  • var/lib/db/sbom/gh-2.83.1-r3.spdx.json (644)

➖ Removed:

  • var/lib/db/sbom/gh-2.83.1-r2.spdx.json (644)

🔺 Changed:

.PKGINFO
- -rw-r--r-- 328 2025-12-04 11:58:15 .PKGINFO
+ -rw-r--r-- 361 2025-12-11 21:02:25 .PKGINFO
.melange.yaml
- -rw-r--r-- 15631 2025-12-04 11:58:15 .melange.yaml
+ -rw-r--r-- 16329 2025-12-11 21:02:25 .melange.yaml
usr/bin/gh
- -rwxr-xr-x 60143848 2025-12-04 11:58:15 gh
-   APK-TOOLS.checksum.SHA1: "7184d01b6af69af047228f9a5c1d9391aaa6771d"
+ -rwxr-xr-x 39149680 2025-12-11 21:02:25 gh
+   APK-TOOLS.checksum.SHA1: "88c2e6d2caf5376462c0df1c6d4d1415e95cf72c"

aarch64/gh-doc-2.83.1-r2.apk -> aarch64/gh-doc-2.83.1-r3.apk

📦 Package diff:

  &apk.Package{
  	Name:        "gh-doc",
- 	Version:     "2.83.1-r2",
+ 	Version:     "2.83.1-r3",
  	Arch:        "aarch64",
  	Description: "gh docs",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0x6b, 0x90, 0xdd, 0x34, 0xa8, 0x80, 0xf0, 0xa6, 0x37, 0x63, 0x9b, 0x3a, 0x42, 0xb6, 0x87, 0x6e, // -|k..4....7c.:B..n|
- 		0xb0, 0xdb, 0x84, 0x11,                                                                         // -|....|
+ 		0x28, 0x3b, 0xc4, 0x69, 0x7a, 0x40, 0xf4, 0xf7, 0x21, 0xd2, 0x5b, 0xf8, 0x0b, 0x5f, 0xf2, 0x5e, // +|(;.iz@..!.[.._.^|
+ 		0x67, 0x6d, 0xe7, 0xe6,                                                                         // +|gm..|
  	},
  	Dependencies:     {"man-db"},
  	Provides:         nil,
  	InstallIf:        nil,
- 	Size:             84215,
+ 	Size:             84449,
- 	InstalledSize:    361929,
+ 	InstalledSize:    362036,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-12-04 11:58:15 +0000 UTC",
+ 	BuildTime:        s"2025-12-11 21:02:25 +0000 UTC",
- 	BuildDate:        1764849495,
+ 	BuildDate:        1765486945,
- 	RepoCommit:       "unknown",
+ 	RepoCommit:       "97c060e33155d5d222059eb4dddd86eaecd18c83",
  	Replaces:         nil,
  	DataHash:         "",
  }

➕ Added:

  • var/lib/db/sbom/gh-doc-2.83.1-r3.spdx.json (644)

➖ Removed:

  • var/lib/db/sbom/gh-doc-2.83.1-r2.spdx.json (644)

🔺 Changed:

.PKGINFO
- -rw-r--r-- 290 2025-12-04 11:58:15 .PKGINFO
+ -rw-r--r-- 323 2025-12-11 21:02:25 .PKGINFO
.melange.yaml
- -rw-r--r-- 15631 2025-12-04 11:58:15 .melange.yaml
+ -rw-r--r-- 16329 2025-12-11 21:02:25 .melange.yaml

x86_64/gh-2.83.1-r2.apk -> x86_64/gh-2.83.1-r3.apk

📦 Package diff:

  &apk.Package{
  	Name:        "gh",
- 	Version:     "2.83.1-r2",
+ 	Version:     "2.83.1-r3",
  	Arch:        "x86_64",
  	Description: "GitHub's official command line tool",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0xc5, 0x29, 0xcf, 0x2e, 0xd3, 0x31, 0x55, 0x31, 0xe4, 0x90, 0x56, 0x1a, 0x50, 0xa8, 0x41, 0x26, // -|.)...1U1..V.P.A&|
- 		0x46, 0x1f, 0x26, 0xeb,                                                                         // -|F.&.|
+ 		0x9a, 0xd0, 0x42, 0x71, 0x25, 0x4c, 0xfd, 0xf2, 0x48, 0xf7, 0xd0, 0xd7, 0x03, 0x9b, 0xc9, 0x5e, // +|..Bq%L..H......^|
+ 		0x74, 0x4a, 0x34, 0x64,                                                                         // +|tJ4d|
  	},
  	Dependencies:     nil,
- 	Provides:         []string{"cmd:gh=2.83.1-r2"},
+ 	Provides:         []string{"cmd:gh=2.83.1-r3"},
  	InstallIf:        nil,
- 	Size:             20020519,
+ 	Size:             14818637,
- 	InstalledSize:    63504254,
+ 	InstalledSize:    41770553,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-12-04 11:58:15 +0000 UTC",
+ 	BuildTime:        s"2025-12-11 21:02:25 +0000 UTC",
- 	BuildDate:        1764849495,
+ 	BuildDate:        1765486945,
- 	RepoCommit:       "unknown",
+ 	RepoCommit:       "97c060e33155d5d222059eb4dddd86eaecd18c83",
  	Replaces:         nil,
  	DataHash:         "",
  }

➕ Added:

  • var/lib/db/sbom/gh-2.83.1-r3.spdx.json (644)

➖ Removed:

  • var/lib/db/sbom/gh-2.83.1-r2.spdx.json (644)

🔺 Changed:

.PKGINFO
- -rw-r--r-- 327 2025-12-04 11:58:15 .PKGINFO
+ -rw-r--r-- 360 2025-12-11 21:02:25 .PKGINFO
.melange.yaml
- -rw-r--r-- 15595 2025-12-04 11:58:15 .melange.yaml
+ -rw-r--r-- 16293 2025-12-11 21:02:25 .melange.yaml
usr/bin/gh
- -rwxr-xr-x 63410840 2025-12-04 11:58:15 gh
-   APK-TOOLS.checksum.SHA1: "a602ca7af6bb163672468e0d3726556c7754b84c"
+ -rwxr-xr-x 41677032 2025-12-11 21:02:25 gh
+   APK-TOOLS.checksum.SHA1: "a136260959081ba679516e671021a13e2de35e90"

x86_64/gh-doc-2.83.1-r2.apk -> x86_64/gh-doc-2.83.1-r3.apk

📦 Package diff:

  &apk.Package{
  	Name:        "gh-doc",
- 	Version:     "2.83.1-r2",
+ 	Version:     "2.83.1-r3",
  	Arch:        "x86_64",
  	Description: "gh docs",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0x75, 0x92, 0xef, 0x3b, 0xca, 0x46, 0xb9, 0xa0, 0xf4, 0xd7, 0x12, 0x4a, 0x3a, 0xfd, 0x3a, 0x38, // -|u..;.F.....J:.:8|
- 		0x7c, 0x1b, 0x88, 0xdd,                                                                         // -||...|
+ 		0x3d, 0xac, 0xad, 0x4c, 0xb0, 0xd2, 0x46, 0x32, 0x8c, 0x5f, 0x4b, 0xdc, 0x21, 0x0d, 0x3c, 0xb4, // +|=..L..F2._K.!.<.|
+ 		0x60, 0x03, 0xed, 0xef,                                                                         // +|`...|
  	},
  	Dependencies:     {"man-db"},
  	Provides:         nil,
  	InstallIf:        nil,
- 	Size:             84185,
+ 	Size:             84416,
- 	InstalledSize:    361928,
+ 	InstalledSize:    362035,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-12-04 11:58:15 +0000 UTC",
+ 	BuildTime:        s"2025-12-11 21:02:25 +0000 UTC",
- 	BuildDate:        1764849495,
+ 	BuildDate:        1765486945,
- 	RepoCommit:       "unknown",
+ 	RepoCommit:       "97c060e33155d5d222059eb4dddd86eaecd18c83",
  	Replaces:         nil,
  	DataHash:         "",
  }

➕ Added:

  • var/lib/db/sbom/gh-doc-2.83.1-r3.spdx.json (644)

➖ Removed:

  • var/lib/db/sbom/gh-doc-2.83.1-r2.spdx.json (644)

🔺 Changed:

.PKGINFO
- -rw-r--r-- 289 2025-12-04 11:58:15 .PKGINFO
+ -rw-r--r-- 322 2025-12-11 21:02:25 .PKGINFO
.melange.yaml
- -rw-r--r-- 15595 2025-12-04 11:58:15 .melange.yaml
+ -rw-r--r-- 16293 2025-12-11 21:02:25 .melange.yaml