This bug was fixed in the package jq - 1.8.2-1ubuntu1
---------------
jq (1.8.2-1ubuntu1) stonking; urgency=medium
* Merge with Debian unstable (LP: #2153197). Remaining changes:
- d/control: don't build-depend on python3-jsonschema on i386, since that
package is uninstallable on Ubuntu i386. This works for now because
python3-jsonschema is only used in a script during tests if the manual.yml
file is patched by the packaging. (LP #2104170)
jq (1.8.2-1) unstable; urgency=medium
* New upstream version 1.8.2.
* d/patches: Remove unnecessary upstream patches.
* d/gbp.conf: Update debian-branch.
jq (1.8.1-8) unstable; urgency=high
* Cherry-pick upstream fix for the following:
* GHSA-ggc9-rpv2-xgpm
* GHSA-gvwx-xj9r-3frq
* CVE-2026-49839
jq (1.8.1-7) unstable; urgency=high
* Cherry-pick upstream fix for CVE-2026-47770.
* d/patches: Add no-forwarded for all upstream fixes.
jq (1.8.1-6) unstable; urgency=high
* Cherry-pick upstream fix for the following CVE (Closes: #1136445):
* CVE-2026-40612
* CVE-2026-41256
* CVE-2026-41257
* CVE-2026-43894
* CVE-2026-43895
* CVE-2026-43896
* CVE-2026-44777
jq (1.8.1-5) unstable; urgency=medium
* d/control: Bump Standards-Version to 4.7.4:
* Remove unnecessary Priority, Rules-Required-Root.
* Cherry-pick upstream fix for the following CVE (Closes: #1133921):
* CVE-2026-32316
* CVE-2026-33947
* CVE-2026-33948
* CVE-2026-39956
* CVE-2026-39979
* CVE-2026-40164
-- Jonas Jelten <[email protected]> Sat, 01 Aug 2026 05:30:29 +0200
** Changed in: jq (Ubuntu)
Status: Fix Committed => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-32316
** CVE added: https://cve.org/CVERecord?id=CVE-2026-33947
** CVE added: https://cve.org/CVERecord?id=CVE-2026-33948
** CVE added: https://cve.org/CVERecord?id=CVE-2026-39956
** CVE added: https://cve.org/CVERecord?id=CVE-2026-39979
** CVE added: https://cve.org/CVERecord?id=CVE-2026-40164
** CVE added: https://cve.org/CVERecord?id=CVE-2026-40612
** CVE added: https://cve.org/CVERecord?id=CVE-2026-41256
** CVE added: https://cve.org/CVERecord?id=CVE-2026-41257
** CVE added: https://cve.org/CVERecord?id=CVE-2026-43894
** CVE added: https://cve.org/CVERecord?id=CVE-2026-43895
** CVE added: https://cve.org/CVERecord?id=CVE-2026-43896
** CVE added: https://cve.org/CVERecord?id=CVE-2026-44777
** CVE added: https://cve.org/CVERecord?id=CVE-2026-47770
** CVE added: https://cve.org/CVERecord?id=CVE-2026-49839
** CVE added: https://github.com/advisories/GHSA-ggc9-rpv2-xgpm
** CVE added: https://github.com/advisories/GHSA-gvwx-xj9r-3frq
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2153197
Title:
Merge jq from Debian for stonking cycle
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/jq/+bug/2153197/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs