Описание
Security update for trivy
This update for trivy fixes the following issues:
Changes in trivy:
- update go-git to 5.18.0 (bsc#1264873, CVE-2026-41506)
Список пакетов
openSUSE Leap 16.0
trivy-0.70.0-bp160.2.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1264873
- SUSE CVE CVE-2026-41506 page
Описание
go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2.
Затронутые продукты
openSUSE Leap 16.0:trivy-0.70.0-bp160.2.1
Ссылки
- CVE-2026-41506
- SUSE Bug 1264854