Skip to content

Update libpng to 1.6.58 - #87

Closed
bryan-minimal wants to merge 1 commit into
mainfrom
update-libpng-1.6.58
Closed

Update libpng to 1.6.58#87
bryan-minimal wants to merge 1 commit into
mainfrom
update-libpng-1.6.58

Conversation

@bryan-minimal

Copy link
Copy Markdown
Member

Update libpng 1.6.531.6.58

Source: github:pnggroup/libpng:tag (+sf-mirror)
Release: https://github.com/pnggroup/libpng/releases/tag/v1.6.58
Changelog: pnggroup/libpng@v1.6.53...v1.6.58

Vulnerabilities fixed (2)

This update clears 2 vulnerabilities affecting 1.6.53:

CVE / GHSA Severity Fixed in
GHSA-mmq5-27w3-rxpp MEDIUM 1.6.54
GHSA-vgjq-8cw5-ggw8 MEDIUM 1.6.54

Warning

4 known vulnerabilities still affect 1.6.58 after this update.

CVE / GHSA Severity Fixed in
GHSA-g8hp-mq4h-rqm3 HIGH ``
GHSA-m4pc-p4q3-4c7j HIGH 1.6.56, 1.8.0 (trunk)
GHSA-wjr5-c57x-95m2 HIGH 1.6.56, 1.8.0 (trunk)
GHSA-6fr7-g8h7-v645 MEDIUM 1.6.57, 1.8.0 (trunk)

Changes

Old New
Version 1.6.53 1.6.58
SHA256 1d3fb8ccc2932d04... 28eb403f51f0f740...
Size 1.1 MB
Source gs://minimal-staging-archives/libpng-1.6.53.tar.xz gs://minimal-staging-archives/libpng-1.6.58.tar.xz

Quality suggestions

  • Missing tests block. This package has no standalone tests, so the buildbot will only verify compilation — not functional correctness. Consider adding a minimal smoke test (e.g., a --version or small round-trip invocation) as part of this PR so future bumps catch regressions. See packages/python/build.ncl for a simple example.

Created by pkgmgr

@bryan-minimal

Copy link
Copy Markdown
Member Author

Closing to regenerate with corrected vuln classification. The pr body reported 2/6 cleared but all 6 libpng advisories actually clear on 1.6.58 — fix landed in pkgmgr-rs #21 via shared supply-chain helper. Re-running pkgmgr now.

@bryan-minimal
bryan-minimal deleted the update-libpng-1.6.58 branch April 20, 2026 20:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant