This bug was fixed in the package jq - 1.8.2-1ubuntu1

---------------
jq (1.8.2-1ubuntu1) stonking; urgency=medium

  * Merge with Debian unstable (LP: #2153197). Remaining changes:
    - d/control: don't build-depend on python3-jsonschema on i386, since that
      package is uninstallable on Ubuntu i386. This works for now because
      python3-jsonschema is only used in a script during tests if the manual.yml
      file is patched by the packaging. (LP #2104170)

jq (1.8.2-1) unstable; urgency=medium

  * New upstream version 1.8.2.
  * d/patches: Remove unnecessary upstream patches.
  * d/gbp.conf: Update debian-branch.

jq (1.8.1-8) unstable; urgency=high

  * Cherry-pick upstream fix for the following:
    * GHSA-ggc9-rpv2-xgpm
    * GHSA-gvwx-xj9r-3frq
    * CVE-2026-49839

jq (1.8.1-7) unstable; urgency=high

  * Cherry-pick upstream fix for CVE-2026-47770.
  * d/patches: Add no-forwarded for all upstream fixes.

jq (1.8.1-6) unstable; urgency=high

  * Cherry-pick upstream fix for the following CVE (Closes: #1136445):
    * CVE-2026-40612
    * CVE-2026-41256
    * CVE-2026-41257
    * CVE-2026-43894
    * CVE-2026-43895
    * CVE-2026-43896
    * CVE-2026-44777

jq (1.8.1-5) unstable; urgency=medium

  * d/control: Bump Standards-Version to 4.7.4:
    * Remove unnecessary Priority, Rules-Required-Root.
  * Cherry-pick upstream fix for the following CVE (Closes: #1133921):
    * CVE-2026-32316
    * CVE-2026-33947
    * CVE-2026-33948
    * CVE-2026-39956
    * CVE-2026-39979
    * CVE-2026-40164

 -- Jonas Jelten <[email protected]>  Sat, 01 Aug 2026 05:30:29 +0200

** Changed in: jq (Ubuntu)
       Status: Fix Committed => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2026-32316

** CVE added: https://cve.org/CVERecord?id=CVE-2026-33947

** CVE added: https://cve.org/CVERecord?id=CVE-2026-33948

** CVE added: https://cve.org/CVERecord?id=CVE-2026-39956

** CVE added: https://cve.org/CVERecord?id=CVE-2026-39979

** CVE added: https://cve.org/CVERecord?id=CVE-2026-40164

** CVE added: https://cve.org/CVERecord?id=CVE-2026-40612

** CVE added: https://cve.org/CVERecord?id=CVE-2026-41256

** CVE added: https://cve.org/CVERecord?id=CVE-2026-41257

** CVE added: https://cve.org/CVERecord?id=CVE-2026-43894

** CVE added: https://cve.org/CVERecord?id=CVE-2026-43895

** CVE added: https://cve.org/CVERecord?id=CVE-2026-43896

** CVE added: https://cve.org/CVERecord?id=CVE-2026-44777

** CVE added: https://cve.org/CVERecord?id=CVE-2026-47770

** CVE added: https://cve.org/CVERecord?id=CVE-2026-49839

** CVE added: https://github.com/advisories/GHSA-ggc9-rpv2-xgpm

** CVE added: https://github.com/advisories/GHSA-gvwx-xj9r-3frq

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2153197

Title:
  Merge jq from Debian for stonking cycle

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/jq/+bug/2153197/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to