Skip to content

Update regex support - #31

Merged
DamianZaremba merged 1 commit into
mainfrom
feature/bugfix-compile
Jun 13, 2026
Merged

Update regex support#31
DamianZaremba merged 1 commit into
mainfrom
feature/bugfix-compile

Conversation

@DamianZaremba

Copy link
Copy Markdown
Member

No description provided.

@DamianZaremba
DamianZaremba force-pushed the feature/bugfix-compile branch 15 times, most recently from af43f84 to dd0ede7 Compare June 13, 2026 16:25
@DamianZaremba
DamianZaremba force-pushed the feature/bugfix-compile branch from dd0ede7 to e5ed18e Compare June 13, 2026 16:46
@DamianZaremba DamianZaremba changed the title Disable boost regex Update regex support Jun 13, 2026
@DamianZaremba
DamianZaremba merged commit bc4014e into main Jun 13, 2026
1 check passed
@DamianZaremba
DamianZaremba deleted the feature/bugfix-compile branch June 13, 2026 16:48
@github-actions

Copy link
Copy Markdown

Trivy Security Scan

ghcr.io/cluebotng/core:07a9bd317b4afa8cf71c1b352f3a16fb55d82697 (ubuntu 24.04)

Severity Package Installed Fixed CVE Title
🟠 HIGH libssl3t64 3.0.13-0ubuntu3.9 3.0.13-0ubuntu3.11 CVE-2026-45447 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
🟠 HIGH openssl 3.0.13-0ubuntu3.9 3.0.13-0ubuntu3.11 CVE-2026-45447 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()

cnb/lifecycle/launcher

Severity Package Installed Fixed CVE Title
🟠 HIGH stdlib v1.26.0 1.25.8, 1.26.1 CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url
🟠 HIGH stdlib v1.26.0 1.26.1 CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🟠 HIGH stdlib v1.26.0 1.25.9, 1.26.2 CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
🟠 HIGH stdlib v1.26.0 1.25.9, 1.26.2 CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🟠 HIGH stdlib v1.26.0 1.25.9, 1.26.2 CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
🟠 HIGH stdlib v1.26.0 1.26.2 CVE-2026-33810 crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-33814 When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39820 Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39823 CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39825 ReverseProxy can forward queries containing parameters not visible to ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39836 ELSA-2026-22112: go-toolset:ol8 security update (IMPORTANT)
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-42499 Pathological inputs could cause DoS through consumePhrase when parsing ...
🟠 HIGH stdlib v1.26.0 1.25.11, 1.26.4 CVE-2026-42504 Decoding a maliciously-crafted MIME header containing many invalid enc ...

layers/sbom/launch/buildpacksio_lifecycle/launcher/sbom.cdx.json

Severity Package Installed Fixed CVE Title
🟠 HIGH stdlib 1.26.0 1.25.8, 1.26.1 CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url
🟠 HIGH stdlib 1.26.0 1.26.1 CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
🟠 HIGH stdlib 1.26.0 1.26.2 CVE-2026-33810 crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-33814 When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39820 Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39823 CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39825 ReverseProxy can forward queries containing parameters not visible to ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39836 ELSA-2026-22112: go-toolset:ol8 security update (IMPORTANT)
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-42499 Pathological inputs could cause DoS through consumePhrase when parsing ...
🟠 HIGH stdlib 1.26.0 1.25.11, 1.26.4 CVE-2026-42504 Decoding a maliciously-crafted MIME header containing many invalid enc ...

layers/sbom/launch/buildpacksio_lifecycle/launcher/sbom.spdx.json

Severity Package Installed Fixed CVE Title
🟠 HIGH stdlib 1.26.0 1.25.8, 1.26.1 CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url
🟠 HIGH stdlib 1.26.0 1.26.1 CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
🟠 HIGH stdlib 1.26.0 1.26.2 CVE-2026-33810 crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-33814 When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39820 Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39823 CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39825 ReverseProxy can forward queries containing parameters not visible to ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39836 ELSA-2026-22112: go-toolset:ol8 security update (IMPORTANT)
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-42499 Pathological inputs could cause DoS through consumePhrase when parsing ...
🟠 HIGH stdlib 1.26.0 1.25.11, 1.26.4 CVE-2026-42504 Decoding a maliciously-crafted MIME header containing many invalid enc ...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant