[UPDATE] devel/github-cli 2.96.0 -> 2.97.0
David Uhden Collado <[email protected]>
| Newsgroups | gmane.os.openbsd.ports |
|---|---|
| Message-ID | <[email protected]> |
Hello, Please find attached a patch that updates the devel/github-cli port from version 2.96.0 to 2.97.0. The upstream release notes and full list of changes are available at: https://github.com/cli/cli/releases/tag/v2.97.0 https://github.com/cli/cli/compare/v2.96.0...v2.97.0 This is primarily a security update. Version 2.97.0 fixes four vulnerabilities affecting terminal escape sequence handling, URL path construction, authentication token output, and attestation verification. In particular, several commands could print externally controlled content without neutralizing terminal escape sequences. The release also fixes insufficient escaping of variable URL path components, a case where "gh auth status" could expose part of some authentication tokens, and a regular expression issue that could allow lookalike repository or workflow names to satisfy an attestation signer matcher. In addition to the security fixes, this release adds name-based resolution for fields and single-select options in "gh project item-edit", named field columns in "gh project item-list", additional agent support for "gh skill", and several smaller fixes and improvements. For the port, I updated the version to 2.97.0 and regenerated modules.inc and distinfo to match the new upstream Go dependency set. No package list or local patch changes were required. Thank you for your time and consideration. Best regards, David.
gh-2.97.0.patch
(text/x-patch, 141.9 KB) - not displayed