{"id":"openSUSE-SU-2026:21663-1","summary":"Security update for gh","details":"This update for gh fixes the following issues:\n\nChanges in gh:\n\n- Update to version 2.98.0:\n  * chore: fix extra whitespace\n  * Default Codespaces port forwarding to loopback\n  * Bump gh-aw-actions to v0.87.1 and recompile workflows\n  * Fix issue triage action compatibility\n  * chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0\n  * chore: bump go to 1.26.7 (#14205)\n  * chore(deps): bump the codeql-actions group across 1 directory with 3 updates\n  * chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.1\n  * Revert \"ci: add temporary step to verify Linux repo signing keys\"\n  * ci: add temporary step to verify Linux repo signing keys\n  * Accept pre-release tags in deployment validation (#14193)\n  * chore: sign APT repositories with both keys\n  * chore(deps): bump charm.land/lipgloss/v2 from 2.0.5 to 2.0.6\n  * chore(deps): bump the aw-actions group with 2 updates\n  * chore(deps): bump github.com/klauspost/compress from 1.19.1 to 1.19.2\n  * Bump Go to 1.26.6\n  * Upgrade gh-aw workflows to v0.85.4\n  * chore(deps): bump github.com/google/go-containerregistry\n  * chore(deps): bump google.golang.org/protobuf from 1.36.11 to 1.36.12\n  * Address review: drop cleanup markers, document search-type in skill\n  * Reconcile feature detection cleanup comment rules in AGENTS.md\n  * Update AGENTS.md with cleanup comment guidance\n  * Address review feedback\n  * Add --search-type flag for semantic and hybrid issue search\n  * Rename config mock constructors to match repo convention\n  * Document when to use the config mock or the isolated config\n  * Accept config content in NewIsolatedTestConfig\n  * Clear auth environment variables in isolated test config\n  * Isolate git config in tests that shell out to git\n  * Rename config stub file to test.go\n  * chore(deps): bump the aw-actions group with 2 updates\n  * Add aw-actions group to dependabot configuration\n  * Rename cli-code-reviewer skill to code-review (#14116)\n  * chore(deps): bump github/gh-aw-actions/setup-cli from 0.83.4 to 0.85.4\n  * Reduce item-add test diff\n  * Isolate item-add test mocks\n  * Test item-add output through command path\n  * Run lint workflow when the lint workflow changes\n  * Bump golangci-lint in CI to v2.12.2\n  * Clarify PR testing section expectations\n  * chore(deps): bump the codeql-actions group across 1 directory with 3 updates\n  * chore(deps): bump azure/login from 3.0.0 to 3.0.1\n  * chore(deps): bump actions/attest from 4.2.1 to 4.2.2\n  * Use reflect.Pointer instead of deprecated reflect.Ptr\n  * Add a scheduled tech debt burndown skill (#14095)\n  * Restore automatic spam issue closure (#14088)\n  * Give Dependabot triage a real reachability check (#14087)\n  * Route release deletions through api.Client (#14077)\n  * chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.0\n  * chore(deps): bump github.com/google/go-containerregistry\n  * Grant the gate the scopes its CI read needs\n  * Keep pre-flight dedup out of the integrity proxy\n  * Key direct/indirect off the // indirect comment\n  * Gate triager confidence on required evidence\n  * Gate Dependabot triage on deterministic pre-flight check\n  * Set GH_EXTENSION=1 when gh invokes an extension\n  * Tell agents to use the PR template in AGENTS.md\n  * Merge pull request #14062 from cli/williammartin-wp-08-release-create\n  * Route extension requests through api.Client (#14059)\n  * Route autolink requests through api.Client (#14013)\n  * chore(deps): bump the codeql-actions group across 1 directory with 3 updates\n  * fix(release create): trim spaces when parsing X-Oauth-Scopes\n  * Match worktree rev-parse stub against absolute path on Windows\n  * fix(pr/checkout): pass -- before worktree path so dash paths work\n  * docs(pr/checkout): add worktree usage example to help text\n  * docs(skills): mention pr checkout worktree support\n  * chore(pr checkout): polish worktree related tests\n  * Route gpg key requests through api.Client (#13997)\n  * Use generated key in ssh-key acceptance test\n  * Route ssh key requests through api.Client\n  * Fix item-add output for non-TTY\n  * test(pr/checkout): add acceptance tests for worktree checkout\n  * chore(deps): bump actions/attest from 4.2.0 to 4.2.1\n  * chore(deps): bump github.com/sigstore/sigstore-go from 1.2.2 to 1.3.0\n  * Generate unique acceptance SSH keys\n  * Route deploy key requests through api.Client\n  * Collapse spam triage into the agentic issue-triage workflow (#14027)\n  * Run Dependabot triage hourly\n  * chore(deps): bump github.com/yuin/goldmark from 1.8.4 to 1.8.5\n  * Require explicit PR review ownership (#14028)\n  * Slim down dependabot triage comments (#14019)\n  * Wrap RESTWithNext errors as api.HTTPError\n  * Bail out early on unusable --worktree paths\n  * Clarify current-worktree rejection message\n  * Return ok bool from revParseFacts to satisfy nilerr\n  * Drop docs on self-explanatory worktree helpers\n  * Trim redundant comments and clarify worktree field names\n  * Resolve worktree target once instead of re-querying git\n  * Fix worktree toplevel stub to match Windows absolute paths\n  * Detect worktrees via git rev-parse and reject the current worktree\n  * Address review: restore TODO, flatten detachCmds, guard worktree symlink\n  * Cover detach-reuse, worktree fetch dir, and symlink path resolution\n  * Harden worktree submodule prefixing and cover cmd.Dir stripping\n  * Create branch when reusing a worktree with a new --branch name\n  * Extract authenticatedCommand helper to dedupe -C handling\n  * Preserve no-force safety when reusing a worktree for fork PRs\n  * Simplify submodule worktree prefix to inline conditional\n  * Run submodule commands inside the worktree for pr checkout\n  * tidying..\n  * Refine PR checkout worktree flag help\n  * Add --worktree flag to gh pr checkout\n\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only\n  Punycode-encoded labels allows for validation bypass and privilege\n  escalation (bsc#1266618).\n\n- Update to version 2.97.0, fixing four security issues (CVE-2026-64654, bsc#1276662,\n  CVE-2026-64653, bsc#1276664, CVE-2026-64652, bsc#1276663, CVE-2026-64655, bsc#1276661):\n  * CVE-2026-64654: terminal escape sequence injection in gist view, api,\n    pr diff, release download --output -, codespace logs, skills preview\n    and agent-task view/create\n  * CVE-2026-64653: unescaped variable path components in request URLs\n    could redirect gh to a different resource than intended\n  * CVE-2026-64652: gh auth status could print part of the auth token in\n    plaintext for token types with an underscore after the prefix\n  * CVE-2026-64655: gh attestation verify built its --signer-repo/\n    --signer-workflow matcher without escaping regex metacharacters,\n    allowing a lookalike signer to pass verification\n  * Add named field columns to gh project item-list and item-edit\n","modified":"2026-08-27T17:30:03.684853288Z","published":"2026-08-26T16:15:07Z","related":["CVE-2026-39821","CVE-2026-64652","CVE-2026-64653","CVE-2026-64654","CVE-2026-64655"],"upstream":["CVE-2026-39821","CVE-2026-64652","CVE-2026-64653","CVE-2026-64654","CVE-2026-64655"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266618"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276661"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276662"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276663"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276664"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64652"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64653"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64654"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64655"}],"affected":[{"package":{"name":"gh","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/gh&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.98.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"gh":"2.98.0-bp160.1.1","gh-bash-completion":"2.98.0-bp160.1.1","gh-fish-completion":"2.98.0-bp160.1.1","gh-zsh-completion":"2.98.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21663-1.json"}}],"schema_version":"1.9.0"}