Skip to content

libxslt: Add version 1.1.43 (CVE-2025-24855, CVE-2024-55549) - libxml2: Add version 2.13.8 (CVE-2025-32414, CVE-2025-32415) #27370

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

gsantner
Copy link
Contributor

@gsantner gsantner commented May 6, 2025

Summary

  • Changes to recipe: libxml2: Add version 2.13.8
  • Changes to recipe: libxslt: Add version 1.1.43

Motivation

New upstream releases, known security vulnerabilities

Details

Version bumps


@jcar87
Copy link
Contributor

jcar87 commented May 6, 2025

Thanks @gsantner - please split them into separate PRs, thanks!

@gsantner
Copy link
Contributor Author

gsantner commented May 6, 2025

Is there no bot that could automate (trying) version bump commits and open such PRs automated?

A core library like libxml and openssl shouldn't went unnoticed/outdated for months after release and require manual comparison between conan and upstream version control.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants