{"id":"openSUSE-SU-2026:21143-1","summary":"Security update for gleam","details":"This update for gleam fixes the following issues:\n\nChanges in gleam:\n\n- Update to 1.17.0:\n  * Fixed security vulnerabilities:\n    - Restrict custom documentation page `path` and `source` values so\n      `gleam docs build` cannot escape the docs output directory or project\n      root (bsc#1267396, CVE-2026-32685)\n    - Restrict publication tarball creation so they cannot contain files\n      from outside the project root (bsc#1267397, CVE-2026-42795)\n    - Stricter deserialisation rules for files internal the build directory\n      to reject corrupted data (bsc#1267398, CVE-2026-43965)\n  * All features and bug fixes are extensively highlighted with\n    examples in the upstream blog post at\n    https://gleam.run/news/single-file-gleam-beam-programs-with-escript/\n    and changelog at\n    https://github.com/gleam-lang/gleam/blob/v1.17.0/CHANGELOG.md some of\n    the highlights include:\n    - Various JavaScript code generation fixes and optimization\n    - Various compiler error handling improvements\n    - Ability to use the `todo` keyword in constants\n    - Improved handling of Git monorepos during package management\n    - Ability to create escripts from Gleam programs\n    - Various language server improvements like reference highlighting,\n      record hovering and code actions\n\n- Update to 1.16.0:\n  * Changelog v1.16.0: https://gleam.run/news/javascript-source-maps/\n\n- Update to 1.15.1:\n  * Changelog v1.12.0: https://gleam.run/news/no-more-dependency-management-headaches/\n  * Changelog v1.13.0: https://gleam.run/news/formalising-external-apis/\n  * Changelog v1.14.0: https://gleam.run/news/the-happy-holidays-2025-release/\n  * Changelog v1.15.0: https://gleam.run/news/upgrading-hex-security/\n\n- Replace deprecated \"disabled\" mode with \"manual\" in _service\n- Update to 1.11.0:\n  * The displaying of internal types in HTML documentation has been\n\timproved\n  * A warning is now emitted when the same module is imported\n\tmultiple times into the same module with different aliases\n  * Fixed a bug where a bit array segment matching on a floating\n\tpoint number would match with NaN or Infinity on the JavaScript\n\ttarget\n  * https://github.com/gleam-lang/gleam/blob/v1.11.1/CHANGELOG.md\n\n- Update to 1.10.0:\n  * Changelog: https://gleam.run/news/global-rename-and-find-references/\n\n- skip unit tests that requires networking upon build\n\n- Update to 1.9.0:\n  * Changelog: https://gleam.run/news/hello-echo-hello-git/\n\n- Update to 1.8.1:\n * Fixed a metadata caching bug where accessors for opaque types\n   could sometimes be used in other modules. (Louis Pilfold)\n * Changelog: https://gleam.run/news/gleam-gets-rename-variable/\n\n- Update to 1.7.0:\n * Changelog: https://gleam.run/news/improved-performance-and-publishing/\n\n- Update to 1.6.3:\n * Fixed a bug where Gleam would be unable to compile to BEAM\n   bytecode on older versions of Erlang/OTP. (yoshi)\n\n- Update to 1.6.2:\n * Fixed a bug where patterns in use expressions would not be checked\n   to ensure that they were exhaustive. (Surya Rose)\n\n- Update to 1.6.1:\n * fix update use_manifest logic (Jason Sipula)\n * 1.6.0 Changelog: https://gleam.run/news/context-aware-compilation/\n","modified":"2026-06-30T18:24:44.864495883Z","published":"2026-06-23T09:40:09Z","related":["CVE-2026-32685","CVE-2026-42795","CVE-2026-43965"],"upstream":["CVE-2026-32685","CVE-2026-42795","CVE-2026-43965"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267396"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267397"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267398"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32685"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42795"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43965"}],"affected":[{"package":{"name":"gleam","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/gleam&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.17.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"gleam":"1.17.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21143-1.json"}}],"schema_version":"1.7.5"}