gpp_maybe Security update for yq
SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3327


This update for yq fixes the following issues: Update to v4.53.3. - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1267199). - CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1271994). Changes for yq: - v4.53.3: * Add --ini-preserve-quotes flag for INI round-trip quote preservation. * Fix: reset INI decoder state on init. * Fix: decode properties array bracket paths. * Fix: preserve floats with trailing zero when encoding YAML to JSON. * Fix: JSON to TOML root scope and null handling. * Fix: reset TOML decoder finished flag on Init for multi-doc evaluation. * Fix: reset TOML decoder between files when evaluating all at once. * Fix: preserve TOML inline table array scope. * Fix: preserve empty TOML arrays in tables * Fix: TOML encoder uses inline tables for YAML FlowStyle mappings. * Fix nested inline YAML merge explode. * Fix repeatString overflow test on 32-bit platforms.


cloud_download Downloads

SUSE Package Hub 15.7 x86_64
  • Packages
    yq
    A portable command-line YAML processor
    4.53.3-150500.3.12.1 lock rpm lock src
SUSE Package Hub 15.7 s390x
  • Packages
    yq
    A portable command-line YAML processor
    4.53.3-150500.3.12.1 lock rpm lock src
SUSE Package Hub 15.7 aarch64
  • Packages
    yq
    A portable command-line YAML processor
    4.53.3-150500.3.12.1 lock rpm lock src
SUSE Package Hub 15.7 ppc64le
  • Packages
    yq
    A portable command-line YAML processor
    4.53.3-150500.3.12.1 lock rpm lock src