Skip to content

Update freetype to 2.14.3 - #284

Merged
bryan-minimal merged 1 commit into
mainfrom
update-freetype-2.14.3
Jun 22, 2026
Merged

Update freetype to 2.14.3#284
bryan-minimal merged 1 commit into
mainfrom
update-freetype-2.14.3

Conversation

@gominimal-pkgmgr-mgr

Copy link
Copy Markdown
Contributor

Update freetype 2.14.12.14.3

Source: override:freetype
Released: unknown (non-GitHub source or tag-only fallback)

Pkgscan: clean — diff against the prior version surfaced no newly-introduced suspicious patterns.

Vulnerability impact

Partition analysis at 2.14.3 (uses each advisory's fixed-version, vulnerable-range, affected-ranges, and fix-commit ancestry to decide):

  • 1 cleared — the new version is outside the advisory's affected range, OR the tag's lineage includes a known fix-commit. These will drop off the next scan.

Vulnerabilities fixed (1)

This update clears 1 vulnerabilities affecting 2.14.1:

CVE / GHSA Severity Fixed in
CVE-2026-23865 MEDIUM via range: >= 2.13.2, <= 2.13.3; >= 2.14.0, <= 2.14.1
Advisory summaries

Components changed

CycloneDX component delta (declared materials — the package's own version, not a dependency-tree diff)
Component Old New
~ freetype 2.14.1 2.14.3

Changes

Old New
Version 2.14.1 2.14.3
SHA256 32427e8c471ac095... 36bc4f1cc4133353...
Size 2.7 MB 2.7 MB
Source gs://minimal-staging-archives/freetype-2.14.1.tar.xz gs://minimal-staging-archives/freetype-2.14.3.tar.xz

Quality suggestions

  • Missing tests block. This package has no standalone tests, so the buildbot will only verify compilation — not functional correctness. Consider adding a minimal smoke test (e.g., a --version or small round-trip invocation) as part of this PR so future bumps catch regressions. See packages/python/build.ncl for a simple example.

Created by pkgmgr

@bryan-minimal
bryan-minimal added this pull request to the merge queue Jun 22, 2026
Merged via the queue into main with commit 2b78827 Jun 22, 2026
3 checks passed
@bryan-minimal
bryan-minimal deleted the update-freetype-2.14.3 branch June 22, 2026 17:06
bryan-minimal added a commit that referenced this pull request Jul 16, 2026
…x#284)

Resolves the #284 gcloud verify item: the bundle's own LICENSE declares
Apache-2.0 for the CLI and its source; the ToS language in it governs use of
GCP services, not redistribution of the CLI - so public-cache redistribution
is fine. Tom's suggestion: guard that conclusion at build time - if Google
ever ships the bundle under different terms, the build fails loudly and the
redistribution question gets re-audited rather than silently shipping.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
(cherry picked from commit 720de05)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants