Skip to content

Conversation

@CBL-Mariner-Bot
Copy link
Collaborator

[AUTOPATCHER-CORE] Upgrade libpng to 1.6.54 for CVE-2026-22695, CVE-2026-22801
Upgrade pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1025371&view=results

buddy build -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1025377&view=results

@CBL-Mariner-Bot CBL-Mariner-Bot requested a review from a team as a code owner January 13, 2026 09:05
@Kanishk-Bansal Kanishk-Bansal self-assigned this Jan 13, 2026
@Kanishk-Bansal Kanishk-Bansal changed the title [AUTOPATCHER-CORE] Upgrade libpng to 1.6.54 for CVE-2026-22695, CVE-2026-22801 [AUTOPATCHER-CORE] Upgrade libpng to 1.6.54 for CVE-2026-22695, CVE-2026-22801 [Medium] Jan 13, 2026
@Kanishk-Bansal Kanishk-Bansal added security CVE-fixed-by-upgrade CVE fixed by package upgrade labels Jan 13, 2026
@mayankfz mayankfz added the ready-for-stable-review PR has passed initial review and is now ready for a second-level stable maintainer review label Jan 20, 2026
@Kanishk-Bansal
Copy link
Contributor

/azurepipelines run

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

Copy link
Contributor

@kgodara912 kgodara912 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor version upgrade libpng to address CVEs. Buddy build is successful. LGTM.

@kgodara912 kgodara912 merged commit c643f2b into 3.0-dev Jan 21, 2026
29 of 32 checks passed
@kgodara912 kgodara912 deleted the cblmargh/libpng-upgrade-to-1.6.54-3.0-dev branch January 21, 2026 05:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3.0-dev PRs Destined for AzureLinux 3.0 Automatic PR AutoUpgrade Core CVE-fixed-by-upgrade CVE fixed by package upgrade Packaging ready-for-stable-review PR has passed initial review and is now ready for a second-level stable maintainer review security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants