golang-1.25 (1.25.8-1)
[PTS] [DDPO]
OK: VCS matches the version in the archive
- Git: https://salsa.debian.org/go-team/compiler/golang.git -b golang-1.25
-
- Branch: golang-1.25
- Path: debian/changelog
- Repo size: 10526720
- Browser: https://salsa.debian.org/go-team/compiler/golang/tree/golang-1.25
- Last scan: 2026-03-07 21:01:16+00
- Next scan: 2026-03-15 14:53:00+00
- Merge requests: 1
- Debian changelog in Git:
golang-1.25 (1.25.8-1) unstable; urgency=medium
* Update to 1.25.8 upstream release
https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk/m/41DopX_WAAAJ
- CVE-2026-27142: html/template: URLs in meta content attribute actions
are not escaped
- CVE-2026-25679: net/url: reject IPv6 literal not at start of host
- CVE-2026-27139: os: FileInfo can escape from a Root
(notably, CVE-2026-27137 and CVE-2026-27138 apply only to 1.26+)
* Drop 0004-Replace-localhostCert-and-localhostKey.patch (obsolete via
https://github.com/golang/go/commit/0c56fa28180c1281bb4934bb6779a72a3fb43f52)
-- Tianon Gravi <tianon@debian.org> Sat, 07 Mar 2026 09:12:47 -0800
- This branch is even with tag debian/1.25.8-1