Skip to content

Commit 9c985d5

Browse files
authored
expat: add v2.7.2 (fixes CVE-2025-59375) and v2.7.3 (spack#1517)
1 parent f5e9658 commit 9c985d5

File tree

1 file changed

+14
-2
lines changed

1 file changed

+14
-2
lines changed

repos/spack_repo/builtin/packages/expat/package.py

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,8 +18,20 @@ class Expat(AutotoolsPackage, CMakePackage):
1818
url = "https://github.com/libexpat/libexpat/releases/download/R_2_2_9/expat-2.2.9.tar.bz2"
1919

2020
license("MIT")
21-
version("2.7.1", sha256="45c98ae1e9b5127325d25186cf8c511fa814078e9efeae7987a574b482b79b3d")
22-
version("2.7.0", sha256="10f3e94896cd7f44de566cafa2e0e1f35e8df06d119b38d117c0e72d74a4b4b7")
21+
version("2.7.3", sha256="59c31441fec9a66205307749eccfee551055f2d792f329f18d97099e919a3b2f")
22+
version("2.7.2", sha256="976f6c2d358953c22398d64cd93790ba5abc62e02a1bbc204a3a264adea149b8")
23+
# deprecate all releases before 2.7.2 because of security issues,
24+
# the latest being https://nvd.nist.gov/vuln/detail/CVE-2025-59375
25+
version(
26+
"2.7.1",
27+
sha256="45c98ae1e9b5127325d25186cf8c511fa814078e9efeae7987a574b482b79b3d",
28+
deprecated=True,
29+
)
30+
version(
31+
"2.7.0",
32+
sha256="10f3e94896cd7f44de566cafa2e0e1f35e8df06d119b38d117c0e72d74a4b4b7",
33+
deprecated=True,
34+
)
2335

2436
build_system("autotools", "cmake", default="autotools")
2537

0 commit comments

Comments
 (0)