openSUSE Security Update: Addressing Vulnerability in gh Affected by CVE-2024-6104
Description
This update for gh fixes the following issues: Update to version 2.53.0: * CVE-2024-6104: gh: hashicorp/go-retryablehttp: url might write sensitive information to log file (boo#1227035) * Disable `TestGetTrustedRoot/successfully_verifies_TUF_root` test due to https://github.com/cli/cli/issues/8928 * Rename package directory and files * Rename package name to `update_branch` * Rename `gh pr update` to `gh pr update-branch` * Add test case for merge conflict error * Handle merge conflict error * Return error if PR is not mergeable * Replace literals with consts for `Mergeable` field values * Add separate type for `PullRequest.Mergeable` field * Remove unused flag * Print message on stdout instead of stderr * Raise error if editor is used in non-tty mode * Add tests for JSON field support on issue and pr view commands * docs: Update documentation for `gh repo create` to clarify owner * Ensure PR does not panic when stateRe...
Read the Full Advisory
Patch
Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-227=1
Package List
- openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): gh-2.53.0-bp155.2.12.1 - openSUSE Backports SLE-15-SP5 (noarch): gh-bash-completion-2.53.0-bp155.2.12.1 gh-fish-completion-2.53.0-bp155.2.12.1 gh-zsh-completion-2.53.0-bp155.2.12.1
References
https://www.suse.com/security/cve/CVE-2024-6104.html https://bugzilla.suse.com/1227035