openSUSE-SU-2026:21557-1: moderate: Security update for gleam
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE security update: security update for gleam
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21557-1
Rating: moderate
References:
* bsc#1272992
Cross-References:
* CVE-2026-59247
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for gleam fixes the following issues:
Changes in gleam:
- Update to 1.18.1:
* CVE-2026-59247: insufficient verification of data authenticity
allows a MITM adversary to substitute forged Hex package
contents during dependency resolution (bsc#1272992)
* Set minimum required Erlang version to 26
* All features and bug fixes are extensively highlighted with
examples in upstream's blog post at
https://gleam.run/news/a-field-day-for-gleams-language-server/
and changelog at
https://github.com/gleam-lang/gleam/blob/v1.18.1/CHANGELOG.md .
Some of the highlights include:
- A lot of new features for the LSP
- Faster JavaScript using singletons
- Deprecation of ambiguous pipe syntax
- Path support in Git dependencies
- Up to 13% faster compilation
- Fixed various bugs in Erlang and JavaScript code
generation.
- Fixed several bugs in the float handling for the JavaScript
target.
- Fixed a bug in the generation of Erlang .app files.
- Fixed a bug where the formatter would produce invalid code.
- Fixed a bug in the TypeScript type definition generation.
- Fixed a bug where the compiler would evaluate the numerator
and denominator of a division in the wrong order.
- Fixed a bug where gleam docs would not be generated.
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-packagehub-471=1
Package List:
- openSUSE Leap 16.0:
gleam-1.18.1-bp160.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-59247.html