openSUSE-SU-2026:0244-1: important: Security update for gosec

[email protected] Wed, 15 Jul 2026 00:05:05 +0200 (CEST)
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for gosec
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0244-1
Rating:             important
References:         #1265919 #1266209 #1266793 #1267195 
Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that contains security fixes can now be installed.

Description:

   This update for gosec fixes the following issues:

   - Fixing multiple vulnerabilities in the following embedded dependencies:
     golang.org/x/crypto/ssh (bsc#1266209), golang.org/x/net/html
     (bsc#1267195), golang.org/x/net/idna (bsc#1266793),
     golang.org/x/net/http2 (bsc#1265919).

   - Update to version 2.27.1:
     * Downgrade google lib to avoid min Go version bump (#1687)
     * Downgrade the jsonschema dep to v0.13.0 due to incompatibility with
       anthropick-sdk-go (#1686)
     * Update all dependencies (#1685)
     * Downgrade the github.com/invopop/jsonschema v0.13.0 to solve
       incopatibility with anthropic-sdk (#1683)
     * Update all dependencies (#1682)
     * Update vulnerabilities alerts for indirect dependencies
     * Pin dependencies (#1681)
     * Skip pining for my repos
     * Update renovate configuration
     * Fix typo
     * Update branch config in renovate config
     * Migrate config renovate.json (#1678)
     * Update renovate to refresh the branch creation
     * Update the renovate branch prefix
     * Update renovate config to pin the actions dependencies by digests
       (#1676)
     * Migrate the html remport to react v19. (#1675)
     * Manually update version to fix renovate (#1674)
     * feat: integrate Atlas Cloud provider (#1672)
     * Refactor error position parsing to support path with colon. (#1673)
     * Add two options to require rule ID and justificaiton for inline
       annotations (#1671)
     * Fix false positive in G118 when cancel is stored in a slice/map (#1670)
     * chore(go): update supported Go versions to 1.25.10 and 1.26.3 (#1669)
     * Harden the github workflows and action (#1665)
     * Fix justification delimiter in annotation format doc (#1661)
     * Update all dependencies (#1664)
     * Update action to use gosec version v2.26.1 (#1660)


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-244=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

      gosec-2.27.1-bp157.2.9.1


References:

   https://bugzilla.suse.com/1265919
   https://bugzilla.suse.com/1266209
   https://bugzilla.suse.com/1266793
   https://bugzilla.suse.com/1267195