Skip to content

yara-x/1.10.0-r0: fix GHSA-9c48-w39g-hm26

fe6bc78
Select commit
Loading
Failed to load commit list.
Merged

yara-x/1.10.0-r0: cve remediation #77388

yara-x/1.10.0-r0: fix GHSA-9c48-w39g-hm26
fe6bc78
Select commit
Loading
Failed to load commit list.
Octo STS / ci-diff-report succeeded Jan 7, 2026 in 0s

Package diff

Package diff

Details

Package Diffs

aarch64/yara-x-1.10.0-r0.apk -> aarch64/yara-x-1.10.0-r1.apk

📦 Package diff:

  &apk.Package{
  	Name:        "yara-x",
- 	Version:     "1.10.0-r0",
+ 	Version:     "1.10.0-r1",
  	Arch:        "aarch64",
  	Description: "A rewrite of YARA in Rust.",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0x7a, 0xfe, 0xde, 0x60, 0x15, 0x1f, 0xd1, 0x1b, 0xf4, 0x2a, 0x39, 0x61, 0x32, 0x45, 0x00, 0x0d, // -|z..`.....*9a2E..|
- 		0x3f, 0x97, 0x60, 0xb1,                                                                         // -|?.`.|
+ 		0x1c, 0xce, 0x10, 0xa5, 0xd0, 0xd9, 0xb5, 0x87, 0x60, 0x5c, 0x33, 0x1e, 0x34, 0x7a, 0x9b, 0xdc, // +|........`\3.4z..|
+ 		0x4f, 0x3f, 0xeb, 0xd6,                                                                         // +|O?..|
  	},
  	Dependencies: {"so:ld-linux-aarch64.so.1", "so:libc.so.6", "so:libgcc_s.so.1", "so:libm.so.6"},
  	Provides: []string{
- 		"cmd:yr=1.10.0-r0",
+ 		"cmd:yr=1.10.0-r1",
- 		"pc:yara_x_capi=1.10.0-r0",
+ 		"pc:yara_x_capi=1.10.0-r1",
  		strings.Join({
  			"so-ver:libyara_x_capi.so.1=1.10.0-r",
- 			"0",
+ 			"1",
  		}, ""),
  		"so:libyara_x_capi.so.1=1",
  	},
  	InstallIf:        nil,
- 	Size:             46324671,
+ 	Size:             45607789,
- 	InstalledSize:    182711818,
+ 	InstalledSize:    178651466,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-11-20 14:05:06 +0000 UTC",
+ 	BuildTime:        s"2026-01-07 11:22:07 +0000 UTC",
- 	BuildDate:        1763647506,
+ 	BuildDate:        1767784927,
  	RepoCommit: strings.Join({
- 		"3ffec28d0e151de0a4f1a7bbe51a97097d1042",
+ 		"4192b1ca2a831048bbb56dc92ea03c8ad6c560",
  		"30",
  	}, ""),
  	Replaces: nil,
  	DataHash: "",
  }

➕ Added:

  • var/lib/db/sbom/yara-x-1.10.0-r1.spdx.json (644)

➖ Removed:

  • var/lib/db/sbom/yara-x-1.10.0-r0.spdx.json (644)

🔺 Changed:

.melange.yaml
- -rw-r--r-- 14418 2025-11-20 14:05:06 .melange.yaml
+ -rw-r--r-- 14944 2026-01-07 11:22:07 .melange.yaml
usr/bin/yr
- -rwxr-xr-x 34820400 2025-11-20 14:05:06 yr
-   APK-TOOLS.checksum.SHA1: "da53866ec52bfb8e17ea0a82f328ca93539eac08"
+ -rwxr-xr-x 34111800 2026-01-07 11:22:07 yr
+   APK-TOOLS.checksum.SHA1: "bb92beab5730e99918c94ec815c952f9c192d003"
usr/lib/libyara_x_capi.a
- -rw-r--r-- 118211878 2025-11-20 14:05:06 libyara_x_capi.a
-   APK-TOOLS.checksum.SHA1: "7cd8951d98da5a3c4ef21dbf5c8129e9946df19d"
+ -rw-r--r-- 114680824 2026-01-07 11:22:07 libyara_x_capi.a
+   APK-TOOLS.checksum.SHA1: "1d16883b4d22aa8f7259b0e1a17e1445ca8a2bc3"
usr/lib/libyara_x_capi.so.1.10.0
- -rwxr-xr-x 29596120 2025-11-20 14:05:06 libyara_x_capi.so.1.10.0
-   APK-TOOLS.checksum.SHA1: "b0232745233242620faca9f616863e735bb79b92"
+ -rwxr-xr-x 28952728 2026-01-07 11:22:07 libyara_x_capi.so.1.10.0
+   APK-TOOLS.checksum.SHA1: "c022b4823d7b198d3ff9dd8478f3470bbb5bcb3e"

x86_64/yara-x-1.10.0-r0.apk -> x86_64/yara-x-1.10.0-r1.apk

📦 Package diff:

  &apk.Package{
  	Name:        "yara-x",
- 	Version:     "1.10.0-r0",
+ 	Version:     "1.10.0-r1",
  	Arch:        "x86_64",
  	Description: "A rewrite of YARA in Rust.",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0xe3, 0xd1, 0xa8, 0xe2, 0x9f, 0x46, 0xe7, 0x62, 0x7d, 0xef, 0xd9, 0x46, 0x38, 0xa0, 0x34, 0x04, // -|.....F.b}..F8.4.|
- 		0x6e, 0xd9, 0x4e, 0x67,                                                                         // -|n.Ng|
+ 		0x86, 0x03, 0x7e, 0x08, 0xcd, 0x00, 0xf5, 0x1f, 0x77, 0x6c, 0xf6, 0x2c, 0xd0, 0x05, 0xca, 0xff, // +|..~.....wl.,....|
+ 		0xa7, 0x4b, 0xac, 0xdb,                                                                         // +|.K..|
  	},
  	Dependencies: {"so:ld-linux-x86-64.so.2", "so:libc.so.6", "so:libgcc_s.so.1", "so:libm.so.6"},
  	Provides: []string{
- 		"cmd:yr=1.10.0-r0",
+ 		"cmd:yr=1.10.0-r1",
- 		"pc:yara_x_capi=1.10.0-r0",
+ 		"pc:yara_x_capi=1.10.0-r1",
  		strings.Join({
  			"so-ver:libyara_x_capi.so.1=1.10.0-r",
- 			"0",
+ 			"1",
  		}, ""),
  		"so:libyara_x_capi.so.1=1",
  	},
  	InstallIf:        nil,
- 	Size:             48800178,
+ 	Size:             47965148,
- 	InstalledSize:    193448267,
+ 	InstalledSize:    189677552,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-11-20 14:05:06 +0000 UTC",
+ 	BuildTime:        s"2026-01-07 11:22:07 +0000 UTC",
- 	BuildDate:        1763647506,
+ 	BuildDate:        1767784927,
  	RepoCommit: strings.Join({
- 		"3ffec28d0e151de0a4f1a7bbe51a97097d1042",
+ 		"4192b1ca2a831048bbb56dc92ea03c8ad6c560",
  		"30",
  	}, ""),
  	Replaces: nil,
  	DataHash: "",
  }

➕ Added:

  • var/lib/db/sbom/yara-x-1.10.0-r1.spdx.json (644)

➖ Removed:

  • var/lib/db/sbom/yara-x-1.10.0-r0.spdx.json (644)

🔺 Changed:

.melange.yaml
- -rw-r--r-- 14382 2025-11-20 14:05:06 .melange.yaml
+ -rw-r--r-- 14908 2026-01-07 11:22:07 .melange.yaml
usr/bin/yr
- -rwxr-xr-x 37370648 2025-11-20 14:05:06 yr
-   APK-TOOLS.checksum.SHA1: "64c26895820406c2355494a05340157d498dd822"
+ -rwxr-xr-x 36595768 2026-01-07 11:22:07 yr
+   APK-TOOLS.checksum.SHA1: "b23cb824d7b8665ab1bf538a514a191f616439bd"
usr/lib/libyara_x_capi.a
- -rw-r--r-- 123966896 2025-11-20 14:05:06 libyara_x_capi.a
-   APK-TOOLS.checksum.SHA1: "adf161e8d9c12be99fea4aad2217f1a673d8d37a"
+ -rw-r--r-- 120831792 2026-01-07 11:22:07 libyara_x_capi.a
+   APK-TOOLS.checksum.SHA1: "68cd8c2aa4ee87d7375ad90f629e203ced558870"
usr/lib/libyara_x_capi.so.1.10.0
- -rwxr-xr-x 32027304 2025-11-20 14:05:06 libyara_x_capi.so.1.10.0
-   APK-TOOLS.checksum.SHA1: "7f3bcae7a5ac696afc101e47fed851d6ac901942"
+ -rwxr-xr-x 31343880 2026-01-07 11:22:07 libyara_x_capi.so.1.10.0
+   APK-TOOLS.checksum.SHA1: "08056af40aba99992ebfd4f14661fa4f854a3c02"