commit 98c951d374f765a2de3ca2ac7cb2d6058ceeef69 Author: Cauê Faleiros Date: Tue Sep 15 16:42:34 2026 -0300 first commit diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..3992834 --- /dev/null +++ b/.dockerignore @@ -0,0 +1,16 @@ +.git +.agents +.codex +.env +.venv +**/__pycache__ +node_modules +output +tmp +*.pdf +agente +backups +staging/staging.env +deploy/portainer.env +portal +kanban diff --git a/.env.example b/.env.example new file mode 100644 index 0000000..88e9981 --- /dev/null +++ b/.env.example @@ -0,0 +1,32 @@ +# LOCAL DEVELOPMENT ONLY. These are public disposable development values. +COMPOSE_PROJECT_NAME=dtf-cloud +SITE_PORT=8080 +KANBAN_PORT=8081 +API_PORT=8000 +POSTGRES_DB=dtf_local +POSTGRES_USER=dtf_local +POSTGRES_PASSWORD=local-database-only +APP_DB_USER=dtf_app +APP_DB_PASSWORD=local-app-database-only +MINIO_ROOT_USER=dtf_local +MINIO_ROOT_PASSWORD=local-storage-only +S3_APP_USER=dtf_app +S3_APP_PASSWORD=local-app-storage-only +S3_BUCKET=dtf-local-artwork +S3_PUBLIC_ENDPOINT=http://localhost:9000 +OPERATOR_USER=operator +OPERATOR_PASSWORD=local-operator-only +APP_ENV=local +PAYMENT_ADAPTER=fake +FREIGHT_ADAPTER=fake +TINY_ADAPTER=fake +WHATSAPP_ADAPTER=fake +STORAGE_ADAPTER=s3-local +MOCK_FREIGHT_CENTS=1500 +MAX_UPLOAD_BYTES=5368709120 +UPLOAD_PART_BYTES=8388608 +STORAGE_QUOTA_BYTES=53687091200 +OWNER_UPLOAD_QUOTA_BYTES=10737418240 +MAX_PENDING_UPLOADS=10 +# Files above 128 MiB remain blocked (ClamAV config must agree with this limit). +SCAN_MAX_BYTES=134217728 diff --git a/.env.exemplo b/.env.exemplo new file mode 100644 index 0000000..e246ae9 --- /dev/null +++ b/.env.exemplo @@ -0,0 +1,27 @@ +# HISTORICAL PROTOTYPE ONLY. Do not use for the local stack; use .env.example. +# ---- portal (nuvem) ---- +DATABASE_URL=postgresql+psycopg://dtf:senha@localhost/dtf +S3_ENDPOINT=https://.r2.cloudflarestorage.com +S3_BUCKET=dtf-artes +AWS_ACCESS_KEY_ID= +AWS_SECRET_ACCESS_KEY= +BASE_PORTAL=https://arte.dropstaratacado.com.br +BASE_KANBAN=http://servidor:8080 +WEBHOOK_TOKEN=troque-isto +AGENTE_TOKEN=troque-isto-tambem +AGENTE_WEBHOOK=http://ip-da-fabrica:8080/api/agente/acordar + +# ---- Tiny ---- +TINY_CLIENT_ID= +TINY_CLIENT_SECRET= +TINY_TOKEN_URL= +TINY_BASE=https://api.tiny.com.br/public-api/v3 + +# ---- WhatsApp ---- +WHATS_PROVEDOR=meta +WHATS_TOKEN= +WHATS_NUMERO_ID= + +# ---- fábrica ---- +PASTA_DTF=\\servidor\DTF +KANBAN_DB=C:\dtf\kanban.db diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml new file mode 100644 index 0000000..ec777fa --- /dev/null +++ b/.gitea/workflows/deploy.yml @@ -0,0 +1,109 @@ +name: Validate, publish and deploy + +on: + pull_request: + push: + branches: [main] + workflow_dispatch: + +jobs: + validate: + runs-on: ubuntu-latest + timeout-minutes: 15 + steps: + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 + - name: Validate source and deployment definitions + run: | + python3 -m py_compile local/*.py deploy/*.py + python3 -m unittest local.test_dependency_lock local.test_staging_readiness deploy.test_production_preflight local.test_pricing -v + sh -n local/lock_dependencies.sh + docker compose config --quiet + docker compose -f compose.staging.yaml config --quiet + set -a + . deploy/portainer.env.example + set +a + docker stack config --compose-file deploy/stack.yaml >/dev/null + + publish-and-deploy: + needs: validate + if: gitea.event_name == 'push' && gitea.ref == 'refs/heads/main' + runs-on: ubuntu-latest + timeout-minutes: 75 + env: + COMPOSE_PROJECT_NAME: dtf-release-${{ gitea.run_number }} + REGISTRY_HOST: ${{ vars.REGISTRY_HOST }} + REGISTRY_OWNER: ${{ vars.REGISTRY_OWNER }} + PYTHON_BASE_IMAGE: ${{ vars.PYTHON_BASE_IMAGE }} + NGINX_BASE_IMAGE: ${{ vars.NGINX_BASE_IMAGE }} + TRIVY_IMAGE: ${{ vars.TRIVY_IMAGE }} + steps: + - name: Checkout + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 + - name: Require production-capable application source + run: python3 deploy/production_preflight.py --source-only + - name: Validate immutable build inputs + run: | + for value in "$PYTHON_BASE_IMAGE" "$NGINX_BASE_IMAGE" "$TRIVY_IMAGE"; do + echo "$value" | grep -Eq '^[a-z0-9][a-z0-9._:/-]*@sha256:[0-9a-f]{64}$' + echo "$value" | grep -Ev '@sha256:0{64}$' >/dev/null + done + case "$REGISTRY_HOST/$REGISTRY_OWNER" in *[A-Z]*|*' '*|'/'*) exit 2;; esac + - name: Run complete isolated regression suite + run: | + docker compose up --build -d --wait + python3 -m local.security_test + python3 -m local.scanning_test + python3 -m local.smoke_test + python3 -m local.workflow_test + docker compose exec -T api python -m local.runtime_security_test + docker compose exec -T api python -m local.retention_test + node local/browser_test.mjs + python3 -m local.backup create-and-verify + - name: Build production images + run: | + api_sha="$REGISTRY_HOST/$REGISTRY_OWNER/dtf-api:${{ gitea.sha }}" + api_latest="$REGISTRY_HOST/$REGISTRY_OWNER/dtf-api:latest" + web_sha="$REGISTRY_HOST/$REGISTRY_OWNER/dtf-web:${{ gitea.sha }}" + web_latest="$REGISTRY_HOST/$REGISTRY_OWNER/dtf-web:latest" + docker build --pull --file deploy/Dockerfile.api \ + --build-arg PYTHON_BASE_IMAGE="$PYTHON_BASE_IMAGE" \ + --build-arg VCS_REF="${{ gitea.sha }}" \ + --tag "$api_sha" --tag "$api_latest" . + docker build --pull --file deploy/Dockerfile.web \ + --build-arg PYTHON_BASE_IMAGE="$PYTHON_BASE_IMAGE" \ + --build-arg NGINX_BASE_IMAGE="$NGINX_BASE_IMAGE" \ + --build-arg VCS_REF="${{ gitea.sha }}" \ + --tag "$web_sha" --tag "$web_latest" . + - name: Block secret, configuration and image findings + run: | + api="$REGISTRY_HOST/$REGISTRY_OWNER/dtf-api:${{ gitea.sha }}" + web="$REGISTRY_HOST/$REGISTRY_OWNER/dtf-web:${{ gitea.sha }}" + docker run --rm --volume "$PWD:/src:ro" --workdir /src "$TRIVY_IMAGE" \ + fs --scanners secret --exit-code 1 --severity HIGH,CRITICAL . + docker run --rm --volume "$PWD:/src:ro" --workdir /src "$TRIVY_IMAGE" \ + config --exit-code 1 --severity HIGH,CRITICAL deploy + docker run --rm --volume /var/run/docker.sock:/var/run/docker.sock:ro "$TRIVY_IMAGE" \ + image --exit-code 1 --scanners vuln --severity HIGH,CRITICAL "$api" + docker run --rm --volume /var/run/docker.sock:/var/run/docker.sock:ro "$TRIVY_IMAGE" \ + image --exit-code 1 --scanners vuln --severity HIGH,CRITICAL "$web" + - name: Publish latest and rollback tags + env: + REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }} + REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }} + run: | + trap 'docker logout "$REGISTRY_HOST" >/dev/null 2>&1 || true' EXIT + echo "$REGISTRY_TOKEN" | docker login "$REGISTRY_HOST" --username "$REGISTRY_USERNAME" --password-stdin + docker push "$REGISTRY_HOST/$REGISTRY_OWNER/dtf-api:${{ gitea.sha }}" + docker push "$REGISTRY_HOST/$REGISTRY_OWNER/dtf-api:latest" + docker push "$REGISTRY_HOST/$REGISTRY_OWNER/dtf-web:${{ gitea.sha }}" + docker push "$REGISTRY_HOST/$REGISTRY_OWNER/dtf-web:latest" + - name: Trigger the Portainer stack webhook + env: + PORTAINER_WEBHOOK: ${{ secrets.PORTAINER_WEBHOOK }} + run: | + test -n "$PORTAINER_WEBHOOK" + curl --fail --silent --show-error --max-time 30 --request POST "$PORTAINER_WEBHOOK" + - name: Stop isolated test stack + if: always() + run: docker compose down --volumes --remove-orphans diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..0243c32 --- /dev/null +++ b/.gitignore @@ -0,0 +1,10 @@ +.env +.venv/ +__pycache__/ +*.pyc +node_modules/ +test-results/ +playwright-report/ +backups/ +staging/staging.env +deploy/portainer.env diff --git a/API.md b/API.md new file mode 100644 index 0000000..80b0038 --- /dev/null +++ b/API.md @@ -0,0 +1,328 @@ +# API — contratos + +> Historical prototype contracts only. The active local API is documented at +> [localhost:8000/docs](http://localhost:8000/docs) and in [LOCAL_SETUP.md](LOCAL_SETUP.md). +> `CONTEXT.md` overrides the legacy endpoints and workflows below. + +> Todos os endpoints do módulo DTF, com requisição e resposta. +> Base: `portal/main.py` e `kanban/main.py`. + +--- + +## Autenticação + +| Quem chama | Como se autentica | +|---|---| +| Tiny (webhook) | header `x-token` com `WEBHOOK_TOKEN` | +| Cliente | token no path da URL — sem login | +| Agente | header `x-token` com `AGENTE_TOKEN` | +| Kanban (aba do PCP) | sessão do PCP — **rede interna, sem porta para fora** | + +--- + +# PORTAL · na nuvem + +## `POST /webhook/tiny` + +Chamado quando nasce um pedido de DTF. **É o gatilho de tudo.** + +```json +{ "numero": "48213", "cliente": "Estamparia Vitória", + "telefone": "5516999998888", "metros": 2.4, "cliente_novo": false } +``` + +**200** +```json +{ "ok": true, "link": "https://arte.dropstaratacado.com.br/arte/a7f3k9..." } +``` + +Cria o pedido, gera token de 7 dias e enfileira o WhatsApp com o link. +Se o número já existir, devolve `{"ok":true,"ja_existia":true}` sem duplicar. + +**Latência importa.** O link só sai depois que o pedido existe no Tiny — se a +integração VNDA → Tiny demorar, o cliente espera. Medir antes de subir. + +--- + +## `GET /arte/{token}` + +Página de upload. HTML. O token já sabe o pedido — **o cliente não digita nada.** + +## `GET /api/arte/{token}` + +```json +{ "pedido": "48213", "cliente": "Estamparia Vitória", "metros": 2.4, + "area_util_cm": 97, "largura_max_cm": 57, + "limite_arquivo_m": 20, "max_gb": 5, "max_arquivos": 10 } +``` + +**410** se o token expirou. + +## `POST /api/arte/{token}/url` + +```json +{ "nome": "estampa.png", "bytes": 84000000 } +``` +```json +{ "url": "https://r2.../48213/ab12_estampa.png?X-Amz-...", + "chave": "48213/ab12_estampa.png", "expira_em": 3600 } +``` + +**Upload direto para o storage.** Arquivo de 5 GB passando pelo VPS derrubaria +o processo. Em partes, para arquivos grandes. + +## `POST /api/arte/{token}/pronto` + +```json +{ "chave": "48213/ab12_estampa.png", "repeticoes": 20 } +``` +```json +{ "arte_id": 991, "status": "processando" } +``` + +Dispara o pré-flight em background. O cliente acompanha por polling em +`GET /api/arte/{token}/status`. + +## `GET /api/arte/{token}/status` + +**Aprovada:** +```json +{ "status": "aprovada", "dpi_efetivo": 300, "qualidade_pct": 100, + "metros_totais": 48.0, "minutos_maquina": 144, + "partes": [{"ordem":1,"metros":20,"nome":"48213_p1.png"}, + {"ordem":2,"metros":20,"nome":"48213_p2.png"}, + {"ordem":3,"metros":8,"nome":"48213_p3_carimbado.png"}], + "avisos": [], "previsao_saida": "2026-09-02T18:00:00-03:00" } +``` + +**Recusada:** +```json +{ "status": "recusada", + "motivo": "A resolução real da arte é de 72 DPI no tamanho que você comprou. Precisamos de pelo menos 150 DPI — o ideal é 300. Reenvie em maior resolução." } +``` + +**O relógio do prazo só começa quando `status = aprovada`.** Arquivo ruim +enviado às 17h não faz as horas correrem contra a casa. + +--- + +## `GET /api/artes` · o agente busca + +Header `x-token`. Devolve o que está aprovado, com vírus liberado e ainda não baixado. + +```json +[{ "arte_id": 991, "pedido": "48213", "cliente": "Estamparia Vitória", + "metros": 48.0, "minutos_maquina": 144, "conferir_manual": false, + "partes": [{"ordem":1,"metros":20,"nome":"48213_p1.png", + "url":"https://r2.../...","sha256":"a3f9..."}] }] +``` + +## `POST /api/artes/{id}/baixada` · confirma o download +## `POST /api/agente/heartbeat` · a cada 5 min + +**Sem sinal por 15 minutos, alertar o TI.** Serviço silencioso parado é pior que +erro barulhento: ninguém percebe até o cliente cobrar. + +--- + +## `GET /cliente/{token_cliente}` · minhas artes + +Link permanente do cliente, não do pedido. Lista as artes tratadas dos últimos +12 meses. + +## `POST /cliente/{token_cliente}/reimprimir` + +```json +{ "arte_id": 812, "metros": 20 } +``` + +Abre pedido novo no Tiny com a arte já pronta. **Recompra sem atrito.** + +--- + +# KANBAN · rede interna, aba do PCP + +## `GET /api/quadro` + +```json +{ "colunas": [{"id":"rec","nome":"Arte recebida"}, ...], + "cards": { + "fil": [{ "arte_id": 991, "pedido": "48213", "cliente": "Estamparia Vitória", + "metros": 48.0, "minutos_maquina": 144, "partes": 3, + "maquina": null, "desde": "2026-09-02T14:02:00", + "parado_seg": 4320, "conferir_manual": false }] + }, + "maquinas": [{ "n": 1, "ocupada": true, "pedido": "48190", + "metros": 9.0, "rodando_seg": 720 }, + { "n": 3, "ocupada": false }] } +``` + +`maquinas` é o que pinta o **círculo vermelho**. Com seis máquinas vendo o mesmo +quadro, é o que evita dois operadores no mesmo arquivo. + +--- + +## `POST /api/puxar` + +```json +{ "maquina": 4, "usuario": "alexandre" } +``` +```json +{ "maquina": "Maq 4", "pedido": "48197", "metros": 18.0, + "minutos": 60, "reserva_expira_em": 3 } +``` + +**Um pedido por vez** e **reserva de 3 minutos** — ajustes pedidos pela sala. +Pega sempre o mais antigo da fila. Se não entrar em `imp` em 3 min, volta. + +**409** se a máquina já estiver ocupada. **404** se a fila estiver vazia. + +## `POST /api/devolver` + +```json +{ "arte_id": 991, "usuario": "thales", "motivo": "travou no meio" } +``` + +Volta ao **topo** da fila, não ao fim — o pedido já esperou uma vez. + +## `POST /api/mover` + +```json +{ "arte_id": 991, "para": "fin", "usuario": "poliana", "maquina": 4 } +``` + +Grava o movimento **antes** de qualquer integração externa. Se o Tiny estiver +fora, o job fica na fila e tenta de novo em 1, 5 e 30 min — **mas a medição de +tempo já está salva.** + +Move o arquivo entre as pastas e enfileira marcador e WhatsApp quando a coluna +pedir. Ao ir para `apc`, pergunta o motivo da prova de cor. + +## `PATCH /api/card/{arte_id}` + +```json +{ "minutos_maquina": 90 } +``` + +Ajuste da estimativa. **O sistema sugere por `metros/20*60`; quem trata a arte +corrige só quando foge do normal.** É esse número que soma a fila contra a +capacidade do dia. + +## `GET /p/{pedido}` + +O QR do carimbo aponta para cá. Redireciona para o card. **A revisão bipa e cai +na tela do pedido** em vez de procurar na lista. + +--- + +## Retrabalho + +### `POST /api/retrabalho` + +```json +{ "pedido_origem": "48184", "metros": 2.0, "causa": "impressao", + "aberto_por": "mayana", "evidencia": "print-whatsapp.jpg" } +``` +```json +{ "id": 44, "alcada": "sala", "vez": 1, "conta_na_meta": true } +``` + +**A Mayana abre e classifica** — conhece o cliente e a reclamação. +**A causa fica travada.** Quem discorda contesta, não altera. + +### `POST /api/retrabalho/{id}/autorizar` + +```json +{ "usuario": "thales" } +``` + +**Thales ou Alexandre autorizam**, porque o retrabalho da casa entra na meta +deles. Eles confirmaram achar justo. + +**403** se a alçada exigir financeiro ou diretoria. + +### `POST /api/retrabalho/{id}/contestar` + +```json +{ "usuario": "alexandre", "texto": "não foi impressão, a arte veio em CMYK" } +``` + +Registra a discordância sem mudar a causa. Fica com quem pediu e quem decidiu. + +--- + +## Relatórios + +### `GET /api/relatorio/etapas?dias=7` + +```json +[{ "coluna": "tra", "nome": "Arte tratada", "movimentos": 84, + "media_min": 94, "pior_min": 380 }] +``` + +**Responde a pergunta que decide o terceiro turno:** quanto do tempo é fila e +quanto é trabalho. Se a arte demora 6h e a máquina imprime em 40 min, rodar 24h +só faz a fila esperar de madrugada. + +### `GET /api/relatorio/impressao?dias=7` + +```json +[{ "maquina": "Maq 1", "pedidos": 42, "media_min": 34, + "metros": 310.5, "m_por_hora": 20.4 }] +``` + +**`m_por_hora` valida ou derruba os 20 m/h.** Todo o cálculo de capacidade — +60.480 metros/mês, R$ 148 mil de ganho — depende desse número. Se for 14, a +conta muda inteira. + +### `GET /api/relatorio/aproveitamento?dias=30` + +```json +{ "metros_faturados": 11605, "metros_de_filme": 12693, + "aproveitamento_pct": 91.4, "valor_do_ponto_mes": 980, + "fonte": "transferências para o depósito Sala DTF no Tiny" } +``` + +**Não exige apontamento novo.** O consumo já é registrado quando o insumo é +transferido para o depósito de impressão — a Altus faz isso porque também +revende insumo. + +### `GET /api/relatorio/retrabalho?dias=30` + +```json +{ "por_causa": [{ "causa": "impressao", "descricao": "Falha de impressão", + "responsavel": "Thales e Alexandre", "pedidos": 9, + "metros": 24.5, "pct": 1.1, "meta": 0.4, "bate": false }], + "total_casa_pct": 2.9, "meta_casa_pct": 1.6 } +``` + +**⚠ A meta ainda não está decidida.** A proposta era 0,4% por causa; a sala +respondeu que "meta geral seria melhor". `META_POR_CAUSA` está isolado no código +para trocar sem mexer no resto. + +--- + +## Códigos de erro + +| Código | Quando | +|---|---| +| 400 | payload inválido, coluna inexistente, mais de 10 arquivos | +| 401 | token do webhook ou do agente errado | +| 403 | alçada insuficiente para autorizar retrabalho | +| 404 | token não existe, card não encontrado, fila vazia | +| 409 | máquina já ocupada, pedido já reservado | +| 410 | token do link expirou | +| 413 | arquivo acima de 5 GB | +| 429 | rate limit — 20 req/min por token | + +--- + +## O que testar antes de dar por pronto + +- [ ] Upload de arquivo de 5 GB sem derrubar o VPS +- [ ] Dois operadores clicando `puxar` ao mesmo tempo — só um pega +- [ ] Reserva expirando: puxar e não mover em 3 min devolve à fila +- [ ] Tiny fora do ar: o movimento grava e o job fica na fila +- [ ] Agente sem internet: para, e ao voltar baixa o acumulado +- [ ] Arquivo baixado pela metade não aparece no kanban +- [ ] Token expirado devolve 410 com mensagem clara ao cliente diff --git a/CONTEXT.md b/CONTEXT.md new file mode 100644 index 0000000..11031c5 --- /dev/null +++ b/CONTEXT.md @@ -0,0 +1,392 @@ +# DTF System - Project Context for AI Agents + +## Purpose of this document + +Read this document before changing code, documentation, architecture, or scope. +It is the current English source of truth for the project. It supersedes older +decisions in `README.md`, `ESPECIFICACAO.md`, `schema.sql`, and the existing +prototype code whenever they conflict. + +Update this file whenever the team makes a material product, process, or +architecture decision. + +## Project goal + +Build a DTF ordering and production-flow system for Dropstar/Altus. + +The current process is slow and manual: customers send artwork through +WhatsApp, staff forward files, designers discover problems late, and production +status is not visible outside the factory. The business has substantially more +machine capacity than it currently uses. The goal is to let customers place DTF +orders online, pay, send artwork, and follow production without making +WhatsApp, shared folders, or manual handoffs the bottleneck. + +The customer-facing value is speed and clarity. The operations value is a +traceable queue and fewer lost or manually handled orders. + +## Current MVP scope + +The MVP must be delivered in **at most three weeks**. The target is a working +online system, not factory-machine automation. + +### Included + +- Dedicated DTF site/subdomain. +- Existing Site DTF commercial rules and product experience. +- Direct, resumable multipart file upload to Cloudflare R2. +- Mercado Pago payment integration with signed and idempotent webhooks. +- Freight quotation and charging at checkout. +- Idempotent Tiny/Olist order integration and order traceability. +- Online Kanban for production status and secure file download. +- WhatsApp status notifications. +- Private object storage, 30-day file retention, backups, and basic security. +- Operator guidance for the factory team. + +### Explicitly outside the three-week delivery + +- Automatic pre-flight validation. It will be validated after delivery using + real customer files and real printed output, then refined as support work. +- Direct FlexiPRINT integration. +- Factory-side agent, hot folder, internal file server automation, VPN, and + heartbeat monitoring. +- Production-room dashboard, printer/machine telemetry, and advanced reports. +- Automated shipping-label purchase, shipping-label printing, and dispatch + automation. The MVP freight scope is quote selection and charging only. +- Personalized cart behaviour based on past orders, day, or time. + +After delivery, the team provides support and evaluates requested changes. Do +not turn post-delivery support into a new committed delivery phase without an +explicit decision. + +## Agreed production model + +```text +Customer browser + -> Site DTF / API on VPS + -> direct multipart upload to private Cloudflare R2 + -> Mercado Pago payment + freight selected at checkout + -> Tiny/Olist order record + -> online Kanban + -> factory operator downloads final file and imports it manually into FlexiPRINT +``` + +WhatsApp is a notification channel, not the artwork-upload channel. It is used +for payment confirmation, correction requests, production status, and order +completion. + +The operator works through the browser. The factory does not need an installed +agent or an internal server for the MVP. + +If the factory internet connection fails, only the factory team temporarily +loses access to the Kanban and secure downloads. The public portal, payments, +uploads, R2 objects, queue, and cloud services remain online. Factory work +resumes when local access returns. + +## Infrastructure and deployment + +- **VPS:** runs the website, API, worker, PostgreSQL, ClamAV, Kanban, and + third-party integrations. +- **Cloudflare R2:** private S3-compatible object storage for original uploads + and final files. It does not run the application, database, worker, or + antivirus. +- **Upload path:** the browser uploads directly to R2 using short-lived, + server-issued presigned multipart URLs. Large files must never be proxied + through the VPS. +- **Deployment:** one Portainer-owned `dtf-cloud` Docker Swarm stack. One Gitea + Actions workflow tests/scans, publishes `latest` plus commit-SHA application + images, and calls the Portainer webhook. Activation remains blocked pending + the production work listed below. +- **Recommended VPS baseline:** 4 vCPU, 16 GB RAM, and 200 GB NVMe. Existing + VPS capacity may be used if it safely meets or exceeds this baseline. +- **Backups:** PostgreSQL backups go to R2. Application secrets are never + committed to Git. + +## File retention + +The business does not want an unlimited artwork library. + +| Artifact | Retention | +|---|---:| +| Incomplete multipart upload | 1 day | +| Rejected or infected upload | 3 days | +| Customer original after approval | Up to 7 days | +| Final print artwork | Maximum 30 days from the first upload | +| Order history and metrics | Kept in the database without keeping the image | + +The 30-day retention decision overrides older references to 90 days or +12-month artwork reordering. + +## R2 planning cost reference + +R2 cost is driven primarily by the average number of gigabytes stored during a +month; read/write operations are expected to be a much smaller cost at the +project's scale. There is no egress charge in the current planning model. + +The client-facing roadmap uses the following planning examples, based on +standard R2 storage pricing, the included storage allowance, and an exchange +rate reference of USD 1 = BRL 5.13: + +| Average storage | Approx. R2/month | Approx. BRL/month | +|---|---:|---:| +| 100 GB | USD 1.35 | BRL 7 | +| 500 GB | USD 7.35 | BRL 38 | +| 1 TB | USD 14.85 | BRL 76 | +| 3 TB | USD 44.85 | BRL 230 | + +These are planning estimates only. Confirm Cloudflare pricing, exchange rates, +taxes, and payment-provider fees before presenting a commercial quote. + +## Commercial rules + +The existing rules in `dtf-site.html` are approved as the current source of +truth. Do **not** redesign, simplify, or change prices, discounts, minimums, +rounding, or product modes without explicit approval. + +The current site contains four product modes, quality-based price tiers, +artwork-ready discounts, separate assembly charges for loose artwork, a +one-metre minimum, and ten-centimetre billing rounding. + +The browser may display the calculation, but production payment creation must +recalculate and validate all price, quantity, freight, and discount values on +the server. Client-provided totals are never authoritative. + +## Freight + +The original visual freight flow in `dtf-site.html` was a stub with only pickup +functional. The localhost bridge now supports pickup and backend fake freight +quotes; there is still no real carrier quotation or production checkout. + +The customer already uses Correios and other shipping platforms. Before freight +can be completed, obtain: + +- The platform(s) that should be used as the source of truth. +- API credentials or delegated access for the selected platform. +- Origin postal code/address. +- Available services and carriers to offer. +- Packaging weight and dimensions by DTF length/package. +- Freight business policy: exact pass-through, subsidy, free-shipping rules, + pickup, or other exceptions. + +At checkout, the backend must quote freight from the selected source, store the +chosen service and quoted amount, include the amount in the Mercado Pago +payment, and persist it in the order. Do not create a payment before the freight +amount is final. + +## Integrations + +### Mercado Pago + +Required before production payment integration, not for the local mock milestone: + +- Production credentials. +- Webhook configuration/access. + +Webhook processing must verify authenticity and be idempotent. A duplicate or +late delivery must not create a duplicate payment, order, message, or queue +card. + +### Tiny/Olist + +Tiny/Olist is already available. The implementation must create/update orders +idempotently and use the order number for traceability. Confirm the actual API +endpoints, marker/tag behaviour, and rate limits before production use. + +### WhatsApp + +WhatsApp is already available, but the technical provider still needs to be +confirmed (official Meta Cloud API, Z-API, or another provider). + +Implement only the required customer events: + +1. Payment approved. +2. Artwork correction needed, with a secure link back to the site. +3. Order entered production. +4. Order ready for collection or shipping. + +Messages initiated by the business may require approved templates depending on +the provider and conversation state. Use an outbox/job mechanism with retries, +delivery status handling, and idempotency. Do not send artwork through +WhatsApp. + +## Factory responsibilities after delivery + +The client/factory team is responsible for: + +- Opening the Kanban, downloading final files, and importing them manually into + the current FlexiPRINT setup. +- Performing real print tests and reporting mismatches in the final file or + printed result. +- Maintaining PCs, printers, FlexiPRINT licences, printing profiles, internal + folders, and the local factory network. +- Informing the development team about changes to prices, freight, operational + rules, or external platforms that need system changes. + +The development team delivers the online system, provides usage guidance, and +supports subsequent corrections or scoped enhancements. + +## Three-week roadmap + +| Week | Delivery | Result | +|---|---|---| +| 1 | Infrastructure and upload | VPS, domain, database, R2, multipart upload, antivirus, and service foundation. | +| 2 | Payment, freight, and order | Mercado Pago, freight quotation, idempotent Tiny/Olist order creation, final file generation, and main Kanban states. | +| 3 | Kanban and handover | Online Kanban, secure download, WhatsApp status messages, 30-day retention, and operational handover. | + +## Known implementation status + +### Active localhost milestone (2026-09-15) + +The current implementation target is localhost before any production connection. +Use `compose.yaml`, `.env.example`, and `LOCAL_SETUP.md`. The runtime is in +`local/`; historical `portal/`, `kanban/`, `agente/`, and `schema.sql` are preserved +as references and are not imported or started by Compose. + +- One local `dtf-cloud` Compose project runs seven long-lived services: Site and + Kanban web gateways, FastAPI Portal/API, PostgreSQL, MinIO, ClamAV, and a + PostgreSQL outbox/scanning worker. Separate database and storage initialization + jobs provision restricted runtime identities, for nine Compose services total. +- MinIO implements the S3 storage boundary with direct multipart browser uploads, + resumable parts, private objects, and short-lived signed operator downloads. +- Payment, freight, Tiny/Olist, and WhatsApp use fake adapters only. No production + credentials or integrations are configured. The API and worker have no external + network route; only local web/storage gateways publish loopback ports. +- The original Site commercial calculation and appearance remain the source of + truth. Its existing browser artwork analysis is retained as prototype advice; + no new automatic pre-flight, server artwork analysis, or print-file generation + is implemented or invoked. +- Since client length and grade could be tampered with and automatic pre-flight + is deferred, a local operator manually confirms those commercial inputs before + checkout. This is a development trust-boundary decision, not a new production + promise. The backend calculates all tiers, discounts, assembly-inclusive rates, + one-metre minimum, ten-centimetre rounding, freight, and final totals. Immutable + approved quotes expire after 24 hours. A customer confirms the server total + on the Site to create one idempotent local paid order. +- Paid orders use `rec`, `tra`, `fil`, `imp`, `cor`, `fin`, with allowed transitions, + operator authentication, concurrency checks, and durable movement history. + Local mock integration receipts are visible in the Kanban. +- The customer portal at `/portal.html` supports local registration/login, + stronger scrypt password hashing with legacy-hash upgrade, revocable HttpOnly + sessions, owned order history/status, secure active + file downloads, and correction uploads. Registration/login can claim only the + current guest session's records, never orders found by email or CNPJ. Email + verification and password recovery are not implemented. +- Unfinished carts (including File blobs) recover from IndexedDB for 24 hours in + the same browser, scoped to the guest/account identity. Recovered items can be + removed/replaced or joined by new items; in-place reconstruction of the artwork + editor and cross-device cart synchronization are not implemented. Browser + storage capacity limits apply. Payment clears the saved cart. Logout revokes + the server session and clears local checkout metadata and saved File blobs + across open Site tabs. +- Operators manually upload and approve a complete final-file set, with one or + more files per order item. Queue entry requires active final files for every + item. Corrections invalidate the old set; customers submit corrections through + their portal, and operators reapprove final files. No artwork transformation, + automatic pre-flight, or machine control is performed. +- Every completed upload is quarantined pending a local ClamAV scan. Only `clean` + files can be quoted, commercially approved, paid, downloaded, attached as final + files, or admitted to the print queue. Rejected/error files remain blocked and + expire within three days. The isolated scanner uses signatures bundled in its + pinned image and has no external network route. The transport accepts files up + to 5 GiB, but the local scan/release limit is 128 MiB; larger files remain + blocked. This malware gate is not print pre-flight or artwork validation. +- A retention worker removes expired object bytes but keeps order/file metadata: + incomplete uploads after one day, originals within seven days of manual final + artwork approval, and attached final/correction files within 30 days of the + order's first upload. Storage lifecycle is also a 30-day backstop. +- Structured security events are written to logs and PostgreSQL. The local + `security_status` command summarizes authentication, rate-limit, scan, and + scanner/signature alerts without exposing secrets. Security regression tests, + exact-runtime Python dependency auditing, and Trivy image reports live under + `local/` and `output/security/`; open findings are documented in + `SECURITY_REPORT.md` and are not a production-readiness claim. +- All direct and transitive Python packages are pinned with artifact hashes in + `local/requirements.lock`; the API image build requires those hashes. The lock + is regenerated in a disposable Python 3.12 container by + `local/lock_dependencies.sh`. A fresh exact-runtime audit found no known Python + advisories on 2026-09-15; this does not cover OS/container findings. +- `compose.staging.yaml` is a separate, network-disabled readiness gate only. It + validates non-secret staging decisions and rejects placeholders, local endpoints, + fake providers, embedded secret settings, and unsafe secret sources. It does not + deploy the application, contain credentials, or contact any real provider. +- A separate production delivery package now exists under `deploy/`, with + non-root API/web image definitions, a single Portainer Docker Swarm stack, + external secret/volume contracts, health-monitored rolling updates, + commit-SHA rollback images, and one protected Gitea workflow under + `.gitea/workflows/`. The package never contains provider credentials and has + not been deployed. Its fail-closed preflight intentionally rejects the current + source until production adapters, Docker-secret file loading, approved inputs, + restore rehearsal, image scans, and human security approval are complete. +- `python3 -m local.backup create-and-verify` creates a private, Git-ignored bundle + containing a PostgreSQL dump plus every complete, unexpired object already marked + `clean`. SHA-256 manifests protect both parts. Verification restores the database + under a UUID name and the object bytes under a UUID MinIO prefix, hashes the + restored bytes, then removes only those temporary targets. Active data is never + overwritten; pending, rejected, errored, expired, and purged objects are excluded. + Run this local snapshot while uploads and retention are idle. Scheduling, offsite + copies, and production restore operations remain unfinished. +- Real providers, production authentication hardening, email verification/recovery, + automatic final-file generation, production backup operations, and production + activation remain incomplete. Deployment plumbing exists but cannot pass its + release gate yet. No factory automation or pre-flight is added. + +See `IMPLEMENTATION_REPORT.md` for verification, `PRODUCTION_INPUTS.md` for the +decisions and evidence required before staging or production connection, and +`PORTAINER.md` for the production delivery contract. +The client roadmap promises are unchanged, so its PDF source is not regenerated +for this local implementation checkpoint. + +### Existing assets + +- `dtf-site.html`: rich static front-end prototype. It includes the current + commercial rules, client-side artwork analysis, current-session cart, and + delivery UI. The localhost checkout bridge connects it to the new local API. +- `portal/`: early FastAPI prototype for the original Tiny-first, token-link + upload flow. +- `kanban/`: early FastAPI/SQLite Kanban prototype. +- `agente/`: factory-side agent prototype; out of current MVP scope. +- `tmp/pdfs/generate_dtf_report.py`: generator for the current client-facing + roadmap PDF. +- `output/pdf/dtf-plano-producao-e-roadmap.pdf`: current generated roadmap. +- `Reunião iniciada às 2026_09_09 09_39 GMT-03_00 - Anotações do Gemini.pdf`: + meeting notes that established the business direction. Treat it as context; + the latest decisions in this document define the active scope. + +### Important gaps and stale assumptions + +- The original Site had no backend payment, freight quote, order persistence, + authentication, purchase history, or real cart persistence. Local order + persistence, reviewed quotes, mock freight and fake payment now work through + `local/static/checkout.js`. The local customer portal now provides accounts and + order history; cart recovery is browser-local. Production account verification, + recovery, and cross-device cart editing are still absent. +- Without the local bridge, the original freight fallback remains a stub. + Real freight quotation remains unimplemented in all runtimes. +- The existing `portal/whats.py` and `kanban/whats.py` are duplicated and send + direct text messages. They are not production-ready notification modules. +- Older documentation and code describe a Tiny webhook creating an upload link, + a factory agent, local Kanban, FlexiPRINT automation, 90-day retention, and + 12-month artwork reuse. Those are not the current MVP model. + +## Documentation synchronization + +`context.md` is the compact operating context for agents. The current +client-facing narrative, diagrams, and formatting live in +`output/pdf/dtf-plano-producao-e-roadmap.pdf`, generated from +`tmp/pdfs/generate_dtf_report.py`. + +When a decision changes, update both the relevant implementation context here +and the roadmap source when it changes what the client-facing plan promises. + +## Change-control rules for agents + +- Preserve the current Site DTF commercial rules unless explicitly asked to + change them. +- Do not add factory-side automation, a local agent, hot folders, FlexiPRINT + control, machine dashboards, or a new post-MVP delivery commitment by + inference. +- Do not claim that R2 hosts or executes application services. +- Keep all customer-facing and internal documentation in English only when this + file is the requested artifact; otherwise follow the user's requested + language. +- When a requirement is unclear, distinguish between the MVP, a future + enhancement, and an existing prototype assumption before changing code. diff --git a/ESPECIFICACAO.md b/ESPECIFICACAO.md new file mode 100644 index 0000000..b17ff18 --- /dev/null +++ b/ESPECIFICACAO.md @@ -0,0 +1,307 @@ +# Módulo DTF no PCP — especificação de implementação + +> Para o Wagner. Consolida o desenho depois das reuniões com os designers e com +> a sala de impressão em 02/09/2026. +> Complementa o `README.md` (arquitetura) e o código em `portal/`, `agente/` e +> `kanban/`. + +--- + +## O que mudou depois das reuniões + +Sete decisões vieram da equipe e **já estão refletidas no código**. Se algo no +código parecer estranho, provavelmente é uma delas. + +| Item | Era | Ficou | Quem definiu | +|---|---|---|---| +| Reserva ao puxar | 15 min | **3 min** | sala | +| Puxar trabalho | até 30 min | **um pedido por vez** | sala | +| Marcadores de duração | seriam apagados | **viram campo `minutos_maquina`** | sala | +| Hot folder em rede | a confirmar | **aceita** | sala | +| Production Manager | a confirmar | **centraliza, mas o PC central precisa de mais capacidade** | sala | +| Licenças do Flexi | a confirmar | **por PC** | sala | +| Meta de retrabalho | 0,4% por causa | **rever: a sala prefere meta geral** | sala | + +--- + +## Números que a equipe deu e que entram no cálculo + +| Dado | Valor | De onde veio | +|---|---|---| +| Arquivos que chegam usáveis | **30%** | designers | +| Tempo para tratar arquivo bom | **3 minutos** | designers | +| Tempo para tratar arquivo ruim | **1h30** | designers | +| Formatos que mais chegam | **PNG e PDF** | designers | +| PDF que chega | **vetorial** | designers | +| SPOT | **sempre igual** | designers | +| Cores que sempre dão problema | azul, vermelho, castanho, laranja, verde — **secundárias** | sala | +| Prova de cor hoje | **não mandam para ninguém** | sala | +| Como o operador sabe o próximo | **notinha do pedido** | sala | +| Tempos de setup | **"não temos informação"** | sala | + +**O de 30% é o mais consequente.** Sete de cada dez arquivos passam pelo +designer. Se o pré-flight barrar metade dos ruins na entrada, são ~3,5 arquivos +em 10 que deixam de consumir tempo de arte. + +--- + +## Fases de implementação + +Cada fase entrega valor sozinha. **Não espere a fase 4 para colocar algo no ar.** + +### Fase 1 · Limpeza do Tiny — pode começar hoje + +Não depende de nada nem de ninguém. + +- [ ] Criar os marcadores `DTF-PRODUCAO`, `DTF-PRONTO` e `DTF-PROVA-COR` +- [ ] Tirar da **lista de sugestão** as variações digitadas à mão: `inicio 14:45`, + `inicio13:34`, `1hrs`, `3h`, `+30min de correcao` e as demais +- [ ] **Não apagar do histórico dos pedidos** — só da lista de opções +- [ ] **Preservar** `30 min`, `1 hora` e `3 horas`: são estimativa de máquina e + viram o campo `minutos_maquina` + +### Fase 2 · Portal e robô — recebe 24h sozinho + +Entrega valor sem o kanban existir. + +- [ ] Contratar VPS, storage S3 e o subdomínio (ver README) +- [ ] Webhook do Tiny → cria token → dispara link no WhatsApp +- [ ] Página de upload com campo de repetição e prévia da montagem +- [ ] URL pré-assinada · upload em partes até **5 GB** +- [ ] Pré-flight (`preflight.py` pronto) +- [ ] Normalização: vetor → PDF, raster → TIF, CMYK → RGB +- [ ] Montagem empilhada · fatiamento em 20 m · carimbo com QR de 20 mm +- [ ] ClamAV em segundo plano +- [ ] Retenção de 30 dias · artes para recompra, 12 meses + +### Fase 3 · Agente — o arquivo cai na pasta sozinho + +- [ ] Serviço no servidor da fábrica (NSSM ou systemd) +- [ ] Webhook + polling de 60 s +- [ ] Download com verificação de hash +- [ ] Heartbeat a cada 5 min · alerta se sumir por 15 + +### Fase 4 · Kanban como aba do PCP + +- [ ] Quadro com as 7 colunas e cronômetro por card +- [ ] Painel das 6 máquinas com **indicador vermelho de ocupada** +- [ ] `puxar próximo` — reserva de 3 min, um pedido por vez +- [ ] `devolver à fila` — volta ao topo +- [ ] Campo `minutos_maquina` no card, com sugestão automática +- [ ] Retrabalho: abertura, classificação de causa, autorização +- [ ] Painel com filtros de período +- [ ] Endpoints de relatório: etapas, impressão, aproveitamento, retrabalho + +### Fase 5 · Duas semanas medindo + +**Não pule.** É o que decide se vale o terceiro turno. + +O que sai depois de duas semanas rodando: +- tempo real de cada etapa +- metros/hora reais por máquina +- quanto do tempo do designer é retrabalho de arquivo ruim +- retrabalho medido contra o que a sala achava que era + +--- + +## Funcionalidades, uma a uma + +### Portal do cliente + +**Link com token.** Um por pedido, UUID v4, 7 dias de validade. O token já +carrega o número do pedido no Tiny — o cliente não digita nada. + +**Upload direto para o storage.** URL pré-assinada, em partes, até 5 GB. O +arquivo nunca passa pelo VPS. + +**Campo de repetição.** O cliente sobe uma arte e informa quantas vezes repetir. +O robô empilha. É o trabalho braçal que hoje o designer faz à mão. + +**Prévia da montagem.** Mostra como a folha ficou antes de fechar o pedido. +Montagem **empilhada**, sem encaixe lado a lado — decisão do Marcus. + +**Gabarito 57 × 97 cm** para download. Os 30 mm do rodapé são do carimbo. + +**Resposta na hora.** Aprovado ou recusado com o motivo em português. **O relógio +do prazo só começa quando a arte é aprovada.** + +### Robô de pré-flight + +Ordem: **normalizar → validar → repetir → fatiar → carimbar.** + +| Verificação | Limite | Ação | +|---|---|---| +| Canal de transparência | obrigatório | recusa | +| DPI efetivo na medida comprada | < 150 | recusa | +| Largura | > 57 cm | recusa | +| Formato | JPEG | recusa | +| DPI efetivo | 150 a 300 | aceita com aviso | +| Alfa parcial nas bordas | > 15% | aceita com aviso | +| CDR | — | **entra sem validar**, etiqueta "conferir" | + +**DPI efetivo = pixels ÷ (cm comprados ÷ 2,54).** O metadado do arquivo mente. + +**Normalização por natureza:** vetor sai PDF mantendo vetor, raster sai TIF com +alfa. CMYK vira RGB. **O original é sempre preservado** — pedido dos designers. + +### Kanban + +**Sete colunas:** arte recebida, arte tratada, aprovação de cor, fila, +imprimindo, correção, finalizado. **Não há coluna de aplicação** — a sala só +imprime o filme. + +**Fila por ordem de chegada, sempre.** + +**Puxar próximo.** Um botão por máquina. Reserva por 3 minutos; se não entrar em +Imprimindo nesse prazo, volta para a fila. **Um pedido por vez.** + +**Indicador de máquina ocupada.** Círculo vermelho e botão desabilitado. Com seis +máquinas vendo o mesmo quadro, é o que evita dois operadores no mesmo arquivo. + +**Devolver à fila.** Volta ao **topo**, não ao fim — o pedido já esperou uma vez. + +**Cronômetro por card.** Tempo parado na coluna atual, em tempo real. Verde até +1h, amarelo até 3h, vermelho acima. + +**Trilha por pedido.** Tempo em cada etapa e quanto do total foi só esperando. + +### Estimativa de máquina + +Campo `minutos_maquina` no card. **Herda os marcadores `30 min`, `1 hora` e +`3 horas` do Tiny**, que a sala confirmou serem estimativa. + +- O sistema sugere pelo tamanho: `metros ÷ 20 × 60` +- Quem trata a arte ajusta **só quando foge do normal** +- É esse número que soma a fila contra a capacidade do dia + +### Aprovação de cor + +A sala confirmou que **hoje não manda prova para ninguém**, e que as cores +problemáticas são as secundárias: azul, vermelho, castanho, laranja e verde. +São cores fora do gamut CMYK — o monitor do cliente mostra o que a máquina não +reproduz. + +Dispara sozinho em três casos: arquivo acima de 10 m, primeiro pedido do +cliente, ou cor detectada fora do gamut. + +**Custo:** ~30 cm de filme, R$ 1,50. Uma reposição de 20 m custa R$ 99. + +**Sugestão de implantação:** começar só com **cliente novo**. Os outros dois +gatilhos entram depois, senão metade dos pedidos vai esperar resposta e o prazo +morre. + +### Retrabalho + +SKU `CRRMP.TX.100CM`. **Mayana abre e classifica a causa; Thales ou Alexandre +autorizam** — eles confirmaram que acham justo, já que entra na meta deles. + +**A causa fica travada depois de aberta.** Com o indicador atrelado a bônus, +haveria incentivo para reclassificar falha de máquina como culpa do cliente. +Quem discorda contesta, e a contestação fica registrada. + +**⚠ A meta precisa ser redefinida.** A proposta era 0,4% por causa, somando 1,6%. +A sala respondeu que **"meta geral seria melhor"**. Antes de codificar, decidir +com o Marcus: meta única sobre o total da casa, ou por causa. O código tem +`META_POR_CAUSA` isolado justamente para isso. + +### Integração com o Tiny + +**Três marcadores, não sete.** O kanban é a fonte de verdade; o Tiny mostra o +estágio grosso para quem não abre o kanban. + +| Movimento | Marcador | +|---|---| +| Imprimindo | `DTF-PRODUCAO` | +| Correção | `CORRECAO DTF` | +| Finalizado | `DTF-PRONTO` | + +640 chamadas de API por dia em vez de 1.500. + +### Mensagens ao cliente + +| Quando | Mensagem | +|---|---| +| 1 hora sem arte | lembrete com o link · o pedido aparece como *faltando arquivo* | +| Arte recusada | motivo em português · o prazo não começou | +| Arte aprovada | qualidade em **% e DPI**, metragem, tempo estimado, horário previsto | +| Entrou em produção | aviso simples | +| Correção | motivo · **única que pede resposta** | +| Finalizado | pronto para retirada ou envio | + +--- + +## O que ainda não pode ser codificado + +### 1 · O SPOT automático + +**Hipótese, não fato.** Os designers disseram que o SPOT é sempre igual; a sala +disse que "é possível criar um perfil só para isso". A documentação do Flexi 22 +cita *transparency mask*, que gera o branco a partir da transparência de PNG e +TIF. + +**Mas ninguém configurou ainda**, e a edição MiniTX é OEM. + +O roteiro de teste está em `dtf-teste-branco-automatico.pdf`. Sete passos, uma +máquina, meia hora. + +- **Se funcionar:** o arquivo vai do portal direto para a hot folder e o PC + central atende só exceções. A madrugada roda sem ninguém. +- **Se não funcionar:** o SPOT segue manual e todo pedido passa pelo PC central. + **A conta das 24 horas muda.** + +### 2 · A capacidade do PC central + +A sala confirmou que o Production Manager centraliza várias impressoras, **mas +que o PC central precisa de mais capacidade**. E as licenças do Flexi são **por +PC** — então centralizar o RIP exige licença lá. + +Levantar antes de decidir: configuração atual do PC central, custo de uma +licença adicional, e quanto de memória o RIP consome num trabalho de 15 m. + +### 3 · As regras de choke + +Os designers **não responderam** os valores de choke nem a espessura mínima de +traço. Sem isso, a regra proposta — 2 px acima de 2 mm, 1 px de 1 a 2 mm, +nenhum abaixo de 1 mm — é chute informado. + +**Só entra em código depois de validada com um arquivo real.** + +### 4 · Metros/hora reais + +Todo o cálculo de capacidade assume **20 m/h por máquina**. A sala não respondeu +o valor real, e disse que não tem informação sobre tempos. + +Se o real for 14, a capacidade cai de 60.480 para 42.336 metros/mês e o plano +das 24 horas precisa ser refeito. + +--- + +## Ressalvas honestas sobre o código + +**`tiny.py` é chute informado.** Estrutura padrão de OAuth2 e endpoints v3, não +validado contra a documentação real. Está isolado de propósito: se o endpoint +for diferente, muda só ali. + +**`carimbar()` precisa de teste visual.** A lógica está certa, mas posicionamento +de texto com pyvips sempre pede ajuste olhando o resultado impresso. + +**O front do kanban usa dados fixos.** Precisa trocar por chamadas a +`/api/quadro` e `/api/mover`. O protótipo `dtf-kanban-treino.html` tem o layout e +o comportamento final. + +**Nada instalado nos PCs da sala.** Decisão do Marcus. O navegador não abre +arquivo no FlexiPRINT — o desenho é miniatura no card mais botão que copia o +caminho, e File System Access API para mover arquivo pelo navegador. + +--- + +## O que precisa de resposta antes da fase 4 + +1. Servidor da fábrica é Windows ou Linux? +2. A conta do Tiny já tem aplicação na API v3? +3. Confirmar na documentação do Tiny o endpoint de marcadores e o limite de + requisições por minuto +4. O número do WhatsApp migra para a API oficial da Meta? +5. Qual a latência da integração VNDA → Tiny? Define quando o link sai +6. Meta de retrabalho: geral ou por causa? +7. Configuração e licença do PC central, se for virar servidor de RIP diff --git a/IMPLEMENTATION_REPORT.md b/IMPLEMENTATION_REPORT.md new file mode 100644 index 0000000..a8cfb2f --- /dev/null +++ b/IMPLEMENTATION_REPORT.md @@ -0,0 +1,219 @@ +# Local milestone implementation report + +## Implemented + +- A single `dtf-cloud` Compose project: Site, Kanban, FastAPI Portal/API, + PostgreSQL 17, private MinIO S3 storage, isolated ClamAV, and a mock integration + outbox/scanning worker. Restricted database and MinIO runtime identities are + provisioned by separate one-shot initialization jobs. +- Existing Site product UI and commercial functions retained, with a separate + local checkout bridge. Server pricing mirrors the four price ladders, all + grade discounts, assembly-inclusive rates, minimum, and rounding. +- Direct multipart browser uploads, part resumption, owned upload completion, + size verification, private five-minute operator downloads, persistent volumes, + and 30-day object/one-day incomplete-upload lifecycle rules. +- Authenticated manual quote review supplies trusted commercial quantities and + grades without adding pre-flight. Immutable server quotes include mock freight; + the customer confirms the total and creates an idempotent local paid order. +- Shared PostgreSQL orders appear in Kanban. Validated transitions, correction + reasons, version checks and movement history persist. Tiny/WhatsApp events use + a transactional outbox, retry scheduling, unique event keys, and fake receipts. +- Loopback-only published ports; API/worker/database on an isolated network; + guards reject production mode, real adapters and nonlocal storage endpoints. + All long-running services have health checks. `.env.example` contains disposable local + defaults only. No new production credentials or provider endpoints. +- Local customer registration/login, scrypt password hashes, revocable database + sessions and attempt throttling. Customers see owned orders, timelines, final + files and correction requests, and can upload corrections through the portal. +- Browser-local unfinished-cart recovery for 24 hours, including file blobs, + with storage errors surfaced. Recovered rows can be removed/replaced and new + items added. Customer navigation now points to local pages instead of the old + external account/cart destinations. +- Manual final-file sets cover every order item, support multiple parts, and + are required before queue entry. Corrections invalidate old final approvals. + Customer and operator file views distinguish originals, corrections and finals. +- Worker retention cleanup: one-day unfinished uploads, seven-day originals + after final artwork approval, and final/correction files no later than 30 days + from the first upload. Combined database/clean-object backup plus isolated, + hash-checked restore verification. +- Upload extension/size/count quotas, exact signed multipart `Content-Length`, + Host/cross-origin rejection, CSP and security headers, escaped filenames, and + logout cleanup of browser cart blobs and checkout metadata. +- Expiring, revocable HttpOnly operator sessions replace browser-stored Basic + credentials. Customer passwords use stronger scrypt parameters, with legacy + verification and upgrade on login. +- Completed artwork is quarantined until local ClamAV marks it `clean`. Quote, + payment, download, final-file approval, queue, and printing gates fail closed. + Scanner errors/rejections remain blocked and expire within three days. This is + malware scanning only, not print pre-flight. +- Structured redacted security logging, a 30-day `security_events` table, live + scanner/signature alert summaries, security regressions, exact-runtime Python + auditing, and JSON image-scan reports under `output/security/`. +- Reproducible Python 3.12 dependency resolution: all 26 direct/transitive runtime + packages are pinned with artifact hashes, and image builds enforce those hashes. +- A separate network-disabled staging-readiness gate validates non-secret inputs; + it is deliberately not an application deployment or provider connection. +- A separate production delivery package defines non-root, hash-locked API/web + images, one external-secret Portainer Docker Swarm stack, health-monitored + rolling updates, commit-SHA rollback, and one Gitea test/scan/publish/webhook + workflow matching the established Graphs/ComporHUB operating model. Its + preflight deliberately blocks the current local-only source and placeholder + inputs; no registry push, Swarm deployment, or real provider call occurred. + +## URLs + +| Component | URL | +|---|---| +| Site | http://localhost:8080 | +| Customer portal | http://localhost:8080/portal.html | +| Kanban | http://localhost:8081 | +| API health | http://localhost:8000/health | +| Local object API and console | http://localhost:9000 · http://localhost:9001 | + +Kanban local login: `operator` / `local-operator-only`. +Setup and the complete browser test are in `LOCAL_SETUP.md`. +Interactive `/docs` and `/redoc` are disabled. + +## Verification completed + +- `docker compose up --build -d --wait`: all seven long-running services healthy; + both initialization jobs exited successfully and published ports are loopback-only. +- `python3 -m unittest local.test_pricing -v`: all tests passed, including + 4,444 comparisons with the actual Site JavaScript calculator. +- `python3 -m local.smoke_test`: passed multipart resume/incomplete completion, + download byte identity, private bucket and session ownership, input/tamper + rejection, four-mode pricing, reviewed corrections, mock freight, concurrent + payment idempotency, valid/invalid transitions, history and eight mock receipts. +- `node local/browser_test.mjs`: passed actual browser upload, manual review, + local payment, cart recovery, final-file approval, customer registration, + customer tracking, Kanban state changes and persisted board reload, with no + JavaScript exceptions. Screenshots inspected in `output/local/`. +- Local test orders are retained in **Finalizado** for inspection, including + the browser fixture at **R$21.89** and the four-mode smoke order at **R$537.25**. +- Restarts of all long-running containers preserved order snapshots, states, mock + receipts and original file bytes; all services returned to healthy. +- Explicit guard checks rejected production mode, every real integration adapter, + R2 selection and a nonlocal S3 endpoint without contacting external services. +- `python3 -m local.workflow_test`: passed account/session isolation, guest + migration, revoked-cookie rejection, customer corrections, final revision + invalidation, secure file downloads and final-file gating. +- `python3 -m local.backup create-and-verify`: the refreshed 2026-09-15 bundle + archived 61 clean MinIO objects (58,723,323 bytes) alongside the local database, + verified SHA-256 manifests, + restored and rehashed every object under an isolated MinIO prefix, restored the + database with 16 orders and 107 upload records, then removed all temporary restore + targets. The prior database-only backup also passed the legacy verifier. +- `docker compose exec -T api python -m local.retention_test`: verified expired + object deletion, preservation of unexpired bytes, and retention of upload + metadata. Only synthetic retention-test object bytes were cleaned up. +- `python3 -m local.security_test`: passed CSP/frame/Host/origin defenses, + rejection of Basic credentials, HttpOnly operator-session revocation, extension + and multipart-size signing, upload quotas, and login throttling. +- `python3 -m local.scanning_test`: a real harmless EICAR fixture was rejected by + ClamAV and could not be downloaded or quoted; a clean control was released. +- `docker compose exec -T api python -m local.runtime_security_test`: passed + database/MinIO least privilege, legacy/current password hashes, quarantine + states, live scanner commands, scan-size rejection, and fail-closed offline behavior. +- The hash-enforced rebuild completed successfully; `pip check`, four staging-gate + regressions, security, smoke, and runtime-security tests passed. A fresh + exact-runtime `pip-audit` found no known Python advisories on 2026-09-15. +- `node local/browser_test.mjs`: additionally passed filename XSS probes with CSP + bypassed, absence of stored operator credentials, and logout removal of File blobs. +- The final rebuilt stack has seven healthy long-running services; Site/API routing and a fresh + guest portal session were checked after the rebuild. +- Production-package validation passed Python/unit and shell syntax checks, Gitea + workflow YAML parsing, and `docker stack config` rendering. The API production + image built from an immutable Python base. The web production image built from + immutable Python/Nginx bases and ran as UID 101 with a read-only filesystem, + returning 200 for its configured Host and 400 for an unexpected Host. +- The pinned ClamAV validation image started as UID 100:101 with a read-only + filesystem, all capabilities dropped, and `no-new-privileges`, then returned + `PONG` through the production health command; those restrictions are encoded in + the Swarm stack. +- `python3 deploy/production_preflight.py --source-only` returned the expected + blocked result for local-only adapters/hosts/fake providers and missing Docker + secret-file loading. This is verified fail-closed behavior, not production + acceptance. + +The final closeout smoke test retained local order #14 in **Finalizado** with +eight durable fake receipts. The final workflow test again passed identity, +correction, download, invalidation, and final-file gates after the PostgreSQL 17 +image refresh. Existing database and MinIO named volumes were preserved. + +## Reuse and replacement decisions + +| Existing asset | Decision | +|---|---| +| `dtf-site.html` | Reused directly. Preserved layout, modes, pricing, client previews, minimums and rounding; added file references and hooks for local checkout/freight. | +| `portal/main.py` | Inspected and preserved. Reused FastAPI and direct signed S3 upload design; replaced runtime with `local/app.py` because the prototype starts from Tiny and invokes pre-flight/agent delivery. | +| `portal/preflight.py` | Inspected, untouched, never imported by local runtime. | +| `kanban/main.py` | Inspected and preserved. Reused workflow state names, movement-history concept and outbox approach; replaced SQLite/folder/machine runtime with PostgreSQL endpoints. | +| `kanban/static/kanban.html` | Inspected and preserved. Reused dark palette, cards, columns and drag/drop pattern in `local/static/kanban.html`. Legacy machine controls and conflicting local/server handlers are not loaded. | +| Duplicated Tiny/WhatsApp modules | Preserved but excluded from build/runtime. New explicit fake adapters cannot invoke them. | +| `agente/` | Inspected, untouched, excluded from build and Compose. Factory automation remains out of scope. | +| Root `schema.sql`, `requirements.txt`, `.env.exemplo` | Historical only; local runtime uses a separate `dtf_local` PostgreSQL schema, dependencies, and `.env.example`. No migration of prototype data. | +| README/API docs | Legacy content preserved under explicit notices pointing to active local instructions. | + +## Deferred and practical limits + +This is a working local development milestone, not the completed three-week production +MVP. Real payments/webhooks, freight providers, Tiny/Olist, WhatsApp, production +R2, production account verification/recovery/security, automatic final print-file +generation, scheduled/offsite backups and a production restore runbook, and production +activation remain undone. Deployment definitions and automation now exist, but +their gate correctly prevents use with the local-only application. No factory agent, hot folders, FlexiPRINT, VPN, +machine dashboards, label automation, or new automatic pre-flight were added. + +Browser artwork analysis already in the Site is retained as advisory prototype +behavior. The backend never adopts its prices, lengths or grades as approved. +The temporary manual quote step resolves that trust boundary locally; its role +in production needs an explicit product decision. Final files are manually +prepared and approved by operators; the test `.cdr` fixture is text, not printable +artwork. Cart recovery is browser-local, subject to quota, and does not reconstruct +the active artwork editor in place. Fake delivery receipts +mean only that the local adapter recorded an event, never that a person received +a message or an ERP order was created. + +The multipart transport supports up to 5 GiB, but this local scanner can release +only files up to 128 MiB. Larger uploads remain blocked. The scanner has no +external network route and uses signatures bundled in its pinned image; rebuild +or replace that image before signatures exceed the seven-day alert threshold. + +The 2026-09-15 exact-runtime Python audit reported no known dependency findings. +All 26 installed packages are transitively pinned with artifact hashes; scheduled +lock refresh and audit automation are still pending. +Trivy HIGH/CRITICAL image reports are retained in `output/security/`: API 46 +(44 Debian records without fixes plus two third-party-SBOM package records absent +from the runtime), Site 5, refreshed PostgreSQL 31, pinned MinIO 108, and pinned +ClamAV 0. Counts are scanner observations, not exploitability determinations. +MinIO was not upgraded over the preserved object volume; its old pinned release +is a material localhost-only limitation. See `SECURITY_REPORT.md`. + +The Site retains its pre-existing external fonts/logo/PDF.js 3.11.174 references. +The known eval advisory is mitigated by the existing `isEvalSupported:false` call; +the old CDN dependency still needs a planned upgrade or vendored/pinned +replacement. No new production service references were added. The `.git` directory is unavailable +as a working Git repository in this workspace, so changes are delivered as local +files without a commit or Git diff. + +## Exact next step + +The localhost security closeout is complete; continue local product work without +treating these controls as production approval. Before any staging or production +connection, complete `PRODUCTION_INPUTS.md` and pass the network-disabled readiness +gate, including the acceptance flow, +production authority for length/grade, and freight platform, origin, packaging and +policy. The verified local database/clean-object bundle addresses the local +recovery gap but is neither scheduled nor offsite and should be created while local +writes are idle. Remaining foundations include production backup/restore design, +container-image remediation/upgrade decisions, and account verification/recovery +design. The current `compose.staging.yaml` validates inputs only and cannot deploy +the application or contact providers. +Use the checked-in `deploy/` package as the target deployment contract rather +than creating another production stack. First add the actual separate staging application runtime, beginning with S3 +adapter contract tests for direct multipart upload, private downloads, CORS and +retention using injected staging credentials. Add real provider adapters only +after their contracts are confirmed; payment activation requires signed, +idempotent webhooks. Implement Docker-secret file loading, resolve or formally +accept image findings, rehearse production restore, and make the release preflight +pass without weakening it. The local runtime intentionally refuses production values. diff --git a/LOCAL_SETUP.md b/LOCAL_SETUP.md new file mode 100644 index 0000000..74e0142 --- /dev/null +++ b/LOCAL_SETUP.md @@ -0,0 +1,366 @@ +# DTF local development + +Read `CONTEXT.md` first. The current runtime lives in `local/`; older portal, +Kanban, agent, requirements, and SQL files are historical prototypes. + +## Start + +Install Docker Engine/Desktop with Compose v2 or later. Docker must be running +and your account must have permission to use it. The initial build downloads +public container images and Python packages; running integrations are local. + +From this repository directory: + +```bash +docker compose up --build +``` + +No `.env` is required: Compose has the same disposable defaults as `.env.example`. +To customize, copy `.env.example` to `.env` and edit it. Never use real credentials. +For a detached start with readiness verification: + +```bash +docker compose up --build -d --wait +docker compose ps +``` + +| Component | Local URL / port | Purpose | +|---|---|---| +| Site DTF | http://localhost:8080 | Existing Site with local checkout bridge | +| Customer portal | http://localhost:8080/portal.html | Local account, order history, corrections and files | +| Kanban | http://localhost:8081 | Quote review, orders, movement, original downloads | +| API health | http://localhost:8000/health | Checks PostgreSQL and MinIO | +| MinIO S3 | http://localhost:9000 | Direct signed multipart uploads and downloads | +| MinIO console | http://localhost:9001 | Inspect private local storage | +| PostgreSQL | `db:5432`, internal only | Shared persistent data | +| ClamAV | `scanner:3310`, internal only | Isolated malware scanner with bundled signatures | +| Worker | `worker:8002/health`, internal only | Mock outbox delivery, scanning and combined health | + +Use `localhost` consistently; mixing it with `127.0.0.1` creates a different +browser session. Published ports bind only to `127.0.0.1`. + +Kanban default login: `operator` / `local-operator-only`. +MinIO default login: `dtf_local` / `local-storage-only`. +These are public, disposable development values, not real credentials. +Interactive API documentation is disabled; `/docs` and `/redoc` are not local +operator interfaces. + +## Browser test order + +1. Open the Site. Choose **Arquivo por metro** and the manual/table-price path + (CDR/AI/PSD/TIFF). Select `local/fixtures/local-test.cdr`. This is deliberately + harmless text for upload testing, not a printable CDR file. +2. Enter **1.01 metres**. The original calculation bills **1.10 m × R$19.90 = + R$21.89**, with grade 0 and pickup. You can also use your own non-sensitive + artwork with the original product controls, repetitions, and mixed cart. +3. Use test CNPJ `11.222.333/0001-81`, phone `11999999999`, email + `local-test@example.test`, and pickup. For simulated freight, select delivery, + enter an eight-digit CEP, and click quote. The default mock price is R$15.00. +4. Click the Site checkout button. Files upload directly to MinIO, remain + quarantined until ClamAV returns `clean`, and then become eligible for a quote. + The local banner displays a quote ID awaiting commercial review. +5. Open Kanban and log in. In **Cotações**, download the original if needed, + confirm/correct total metres and grade, tick the manual confirmation, and + click **Aprovar cotação**. For the fixture keep 1.01 m and grade 0. +6. Return to the Site, click **Atualizar pedido local**, inspect the authoritative + server total, then click **Criar pedido pago local**. No real payment occurs. +7. Refresh Kanban. The paid order starts in **Arte recebida**. Move it using + the buttons or drag and drop to **Arte tratada**. Open **Arquivos de produção**, + select the manually prepared final files for every item, enter a review note, + tick the confirmation and click **Aprovar arquivos finais**. Use the harmless + fixture again only for this local test; no printable file is generated. + Continue through **Fila de impressão → + Imprimindo → Finalizado**. A move to **Correção** requires a reason; it can + return to **Arte recebida** or **Arte tratada**. Finalizado is terminal locally. +8. Inspect **Histórico** and **Eventos locais de integração**. Worker receipts + should say recorded locally. Download links expire after five minutes; + request another link from Kanban when needed. + +The manual quote step is necessary to enforce the backend trust boundary while +automatic pre-flight is deferred. Browser measurements and grade are proposals. +Only an authenticated operator can approve them; the server derives prices and +freight. Payment accepts a quote ID only. Approved quotes are immutable for +24 hours, and repeated/concurrent payment requests return the same order. +This local review step does not settle the future automated production checkout. +Malware scanning is a separate safety gate and does not inspect dimensions, +resolution, colors, printability, or any other pre-flight property. + +The existing client-side previews/analysis remain unchanged and advisory. No new +automatic print pre-flight or artwork validation runs on upload; malware scanning +is the separate gate described above. Original downloads and manually approved +final files are separately labeled. Never print the local text fixture. + +## Customer accounts, corrections, and cart recovery + +Open **Minha conta** on the Site, or `/portal.html`. Create a local account with +a test CNPJ, phone, email and password of at least 12 characters. Passwords use +the current stronger scrypt format; legacy local hashes are verified and upgraded +on successful login. Sessions are stored in PostgreSQL, expire after +seven days, and are revoked on logout. Login/registration attempts are limited. +No email service is used: email verification and password recovery remain absent. + +Registration associates only the current guest session's uploads, quotes and +orders with the new account. Signing in from another browser restores access to +that account's orders. Matching an email or CNPJ never grants access to an order. +Guests can still order and track within their current session. + +In the portal, **Ver detalhes e arquivos** displays status history, correction +reasons, files and expiry dates. When Kanban requests **Correção**, upload corrected +files against the relevant item and add a note. The order stays in correction +until the operator reviews it. The old final set is invalidated; the operator +must upload/approve another complete set before re-entering the queue. Concurrent +or repeated submissions with a stale order version are rejected. + +The browser saves unfinished cart items and their File blobs in IndexedDB for +24 hours. Reloading restores them as cart rows; remove/replace a row to alter its +artwork settings, or add more products. Existing calculations are preserved and +delivery must be requoted. Payment clears the saved cart. Cart recovery is local +to the browser, not a cross-device artwork library; very large files can exceed +browser storage capacity, which is reported visibly. Expired browser entries are +removed the next time the Site opens. Server retention does not erase downloaded +files or copies stored by the browser/operating system. +Logout also clears local checkout keys and IndexedDB File blobs across open Site +tabs. Operator authentication uses an expiring, revocable HttpOnly session; +browser storage never retains the operator password or a Basic-auth credential. + +## Automated checks + +Pricing parity requires Python 3.10+ and Node 22+ on the host, no package install: + +```bash +python3 -m unittest local.test_pricing -v +``` + +This executes the real pricing constants/functions extracted from `dtf-site.html` +and compares all four modes, 101 grades, and 11 lengths (4,444 cases) to backend +pricing, plus assembly and invalid-input checks. + +With the stack healthy, run the integration test (Python standard library only): + +```bash +python3 -m local.smoke_test +python3 -m local.workflow_test +``` + +It checks direct two-part upload/resume, missing parts, session isolation, +private downloads and byte identity, customer validation, tampered totals, +operator corrections, all four products, freight, immutable quotes, concurrent +payment retries, state rules, history, and durable fake integration receipts. +Each run leaves one clearly labeled test order and an approximately 8 MiB object. +The workflow test also checks guest-to-account migration, cross-session login, +revoked sessions, ownership isolation, correction submissions, final revision +invalidation, secure downloads, and mandatory final-file approval before queueing. + +Security and malware regressions are separate so an authorized harmless EICAR +test is unmistakable: + +```bash +python3 -m local.security_test +python3 -m local.scanning_test +docker compose exec -T api python -m local.runtime_security_test +docker compose exec -T api python -m local.retention_test +``` + +`local.scanning_test` stores an EICAR fixture as `SECURITY-EICAR.cdr`; ClamAV +must reject it, and quote/download gates must remain closed. The rejected fixture +is retained for at most three days, so it temporarily appears in alert summaries. + +For an automated real-browser walkthrough, install Chrome and use Node 22+: + +```bash +node local/browser_test.mjs +``` + +Set `CHROME_BIN` if Chrome is not at `/usr/bin/google-chrome-stable`. The test +uses a separate temporary browser profile, walks through the actual Site and +Kanban controls, and saves screenshots to `output/local/`. It leaves its local +test order for inspection. Both integration scripts read `.env` automatically. + +## Configuration and storage + +`.env.example` lists local ports, database/MinIO values, operator login, adapter +selection, mock freight amount, maximum file size (5 GiB), and multipart size +(8 MiB by default). The malware scanner releases only files up to 128 MiB by +default (`SCAN_MAX_BYTES`); larger uploads remain blocked even though the +multipart transport supports 5 GiB. `S3_ENDPOINT=http://storage:9000`, database +hostname `db`, +and the internal service ports are fixed Compose wiring. The public S3 endpoint +must resolve from the browser; keep `http://localhost:9000` for this stack. +Parts use 15-minute presigned URLs and uploads must finish within one day. + +Only fake integration adapters and `s3-local` storage are accepted. Startup fails +if a production adapter/environment or nonlocal S3 endpoint is selected. +The API, worker, and database run on an internal Docker network; web gateways +and MinIO also join a network that permits loopback port publishing. + +Objects are private, use UUID keys rather than filenames, and persist in a named +volume. MinIO lifecycle rules expire objects after 30 days and abandon incomplete +multipart uploads after one day; the API also blocks expired downloads. Order +history remains in PostgreSQL. Completed files start in `pending`; unknown, +scanner-error, over-limit, encrypted/unsafe, and malware results fail closed. +Only `clean` files can cross quote, payment, download, final-approval, and queue +gates. Rejected/error objects expire within three days. The worker deletes +original bytes within seven days of +manual final artwork approval, and final/correction bytes by 30 days from the +order's first upload. Expired files remain visible as metadata but cannot be +downloaded. Retention runs once a minute; MinIO lifecycle is a backstop. + +Upload retries resume completed parts. The saved cart retains files when browser +storage permits; otherwise reselect them. Saved quote IDs also survive reloads. +Clearing cookies loses a guest session, while registered customers can sign in +again. The operator can still inspect order records. + +## Local backup and restore check + +```bash +python3 -m local.backup create-and-verify +``` + +This writes a private four-file bundle in `backups/` (ignored by Git and Docker +builds): a PostgreSQL custom-format dump, a gzip object archive, a JSON manifest, +and the manifest's SHA-256 sidecar. The object archive includes only complete, +unexpired files that ClamAV has marked `clean`; pending, rejected, errored, expired, +and purged objects remain excluded. Run the command while uploads and retention are +idle so the database dump and subsequent object selection describe the same local +state. + +Verification restores the dump into a newly created UUID-named database and the +object bytes under a UUID-named `originals/restore-verification/` MinIO prefix. It +checks database counts, bundle hashes, every archived object's hash, and the bytes +downloaded after restore, then removes only the temporary database and objects. It +never restores over active data. Keep every bundle file private: it contains +customer data, password hashes, and customer artwork. To verify it again, run +`python3 -m local.backup verify` followed by the printed +`backups/...manifest.json` path. Legacy database-only `.dump` backups remain +verifiable. Scheduling, offsite copies, and a production restore runbook remain +unfinished. + +After building the current image, test retention with synthetic files: + +```bash +docker compose exec -T api python -m local.retention_test +``` + +This checks that expired bytes are removed while unexpired files survive. It +cleans up its own synthetic object bytes and retains their metadata. + +## Operations and troubleshooting + +```bash +docker compose logs --tail=100 api worker scanner +docker compose restart api worker +docker compose ps +docker compose down +``` + +`down` stops the stack and preserves named database/storage volumes. Restart +with `docker compose up -d --wait`. Do not add `--volumes` unless you intend to +permanently erase all local orders and artwork. No reset is required for tests. + +Seven long-running services have Docker health checks; the database and storage +initialization jobs must exit successfully. API health queries PostgreSQL and +MinIO; worker health fails if its database-processing loop, scanning thread, or +live ClamAV PING is unavailable. Both web gateways expose `/health`. MinIO +exposes `/minio/health/ready`. + +Run the redacted local alert summary inside the API network namespace: + +```bash +docker compose exec -T api python -m local.security_status +``` + +Exit status 1 means attention is required. Review blocked artwork, rate limits, +failed logins, scanner availability, and signature age. Immediately after the +security tests, expected synthetic login failures/rate limits and +`SECURITY-EICAR.cdr` rejections will trigger the alert; confirm names and test +timing before classifying them as expected. Unexpected failures, scanner errors, +stale signatures (more than seven days), or non-test rejected files require +investigation. Events are retained for 30 days. See `SECURITY_REPORT.md`. + +If a host port is occupied, change `SITE_PORT`, `KANBAN_PORT`, or `API_PORT` in +`.env` and recreate the stack. MinIO currently reserves 9000/9001. If Docker says +permission denied, fix Docker access or use your OS-approved Docker workflow. +If image/package download fails, check development internet access. A warning +about missing Buildx can fall back to Docker's classic builder; install your +platform's Buildx plugin for the supported modern build path. + +If API is unhealthy, inspect its logs and check local adapter settings. Database +and MinIO credentials initialize persistent volumes only once; changing values +later also requires updating the existing database/storage account deliberately. +If an upload fails, keep the session and click checkout again. If parts expired, +reselect the file to start another upload. For a stale Kanban move, refresh; +the backend rejects stale versions instead of overwriting another operator. + +The Site retains its existing remote visual assets (fonts/logo) and optional +PDF.js 3.11.174 CDN dependency. Its known eval-based advisory is mitigated in +the current call with `isEvalSupported:false`; the old CDN dependency is still +an upgrade/vendor-pinning limitation, not a claim that it is current. The local +API, manual fixture flow, storage, payment, +freight, Kanban, and mock integrations work without these external services. +Offline PDF previews may fall back to the prototype's manual/table-price path. + +## Dependency lock + +The API, worker, and database initializer install every Python dependency from +`local/requirements.lock` with `--require-hashes`. `local/requirements.txt` +remains the human-maintained direct dependency list. After deliberately changing +a direct pin, regenerate the lock in the same Python 3.12 environment and rebuild: + +```bash +./local/lock_dependencies.sh +docker compose up --build -d --wait +``` + +The generator downloads public package metadata in a disposable container and +does not modify the host Python environment. Review the resolved versions and run +the exact-runtime audit plus regression suite before accepting an updated lock. + +## Staging readiness gate + +`compose.staging.yaml` is intentionally not a staging deployment. It runs only a +network-disabled validator for non-secret decisions. After completing +`PRODUCTION_INPUTS.md`, copy `staging/staging.env.example` to the ignored +`staging/staging.env`, enter non-secret metadata, and run: + +```bash +docker compose -f compose.staging.yaml run --rm readiness +``` + +A pass does not authorize deployment or prove provider access. The real staging +composition and external secret injection still require approved provider +contracts and owners. See `staging/README.md`. + +## Next production connection step + +Keep this stack local. Before connecting real services, confirm the production +checkout trust workflow, complete `PRODUCTION_INPUTS.md`, and pass the isolated +staging-readiness gate. Then implement the actual staging composition using the adapter contracts in +`local/adapters.py`: start with private S3 staging storage, CORS, signed multipart +contract tests and scoped credentials injected outside Git. Add provider sandbox +adapters one at a time. Mercado Pago requires authenticated, signed, idempotent +webhook handling before real payment is allowed; Tiny/Olist and WhatsApp need +confirmed contracts and provider idempotency/delivery handling. Do not simply +change the local fake flags or point this Compose file at production. + +## Production delivery package + +The repository now includes a separate Docker Swarm and Gitea Actions delivery +package in `deploy/` and `.gitea/workflows/`. It is not used by this localhost +Compose stack and does not alter its volumes. Production images run as +unprivileged users and install the hash-locked Python runtime. Gitea publishes +`latest` for the normal Portainer webhook plus the full commit SHA for rollback. +The stack expects pre-provisioned external Swarm secrets and an external +PostgreSQL volume. Only Site and Kanban ports are published for the existing TLS +reverse proxy; API, database, worker, and scanner remain private. + +Run the source-only gate without credentials: + +```bash +python3 deploy/production_preflight.py --source-only +``` + +It must remain blocked while `local/` supports only local fake adapters and does +not load Docker secret `*_FILE` settings. Do not bypass or delete this check. +After approved production implementations and inputs exist, follow +`PORTAINER.md` and `deploy/PRODUCTION_CHECKLIST.md`; release and deployment +still require the Gitea scan/test gates and explicit approvals. diff --git a/PORTAINER.md b/PORTAINER.md new file mode 100644 index 0000000..69cc051 --- /dev/null +++ b/PORTAINER.md @@ -0,0 +1,121 @@ +# Portainer deployment + +DTF follows the same operating model as Graphs and ComporHUB: Gitea builds +prebuilt images, pushes them to the Gitea registry, and calls one Portainer +webhook. Portainer owns and redeploys one Docker Swarm stack named `dtf-cloud`. + +The production stack is `deploy/stack.yaml`. It contains Site, Kanban, API, +worker, PostgreSQL, ClamAV, and a one-time database initializer. Production uses +Cloudflare R2, so MinIO is not part of this stack. + +## 1. Gitea configuration + +The single workflow is `.gitea/workflows/deploy.yml`. Pull requests run static +validation. A push to `main` runs the full isolated test suite, builds and scans +the production images, publishes both `latest` and the full commit SHA, then +calls Portainer. + +Repository variables: + +- `REGISTRY_HOST` — normally `gitea.blyzer.com.br`. +- `REGISTRY_OWNER` — normally `blyzer`. +- `PYTHON_BASE_IMAGE`, `NGINX_BASE_IMAGE`, `TRIVY_IMAGE` — approved immutable + `@sha256:` image references. + +Repository secrets: + +- `REGISTRY_USERNAME` and `REGISTRY_TOKEN` — package write credentials. +- `PORTAINER_WEBHOOK` — webhook generated by the `dtf-cloud` Portainer stack. + +The webhook is called only after tests and HIGH/CRITICAL secret, +misconfiguration, and image gates pass. The current local-only application +fails the source preflight intentionally, so it cannot publish yet. + +## 2. One-time Portainer resources + +Use a Docker Swarm environment. Create a dedicated production PostgreSQL volume +and set its name as `POSTGRES_VOLUME`. Label its Swarm node +`dtf_database=true`. Do not reuse the localhost Compose volume. + +Create each application credential under **Secrets**. Use versioned names such +as `dtf_prod_database_url_v1`, then place only those names in the corresponding +`*_SECRET` stack variables. The stack expects distinct secrets for: + +- runtime and administrator database URLs; +- database administrator and application-role passwords; +- R2 access key and secret key; +- operator password; +- Mercado Pago token and webhook secret; +- Tiny/Olist token; +- WhatsApp token. + +Credential values must never be entered into Git, `portainer.env`, or Gitea +workflow variables. + +## 3. Create the stack once + +In Portainer select **Stacks → Add stack → Git repository**: + +- Name: `dtf-cloud` +- Repository: this Gitea repository +- Reference: `main` +- Compose path: `deploy/stack.yaml` +- Registry: the private `gitea.blyzer.com.br` registry +- Re-pull image: enabled +- Automatic update: webhook + +Load a completed copy of `deploy/portainer.env.example` as the stack's +non-secret environment variables. Do not load the example unchanged: `TBD` and +zero digests are deliberate blockers. Keep `IMAGE_TAG=latest` for normal +webhook deployments. + +Before entering those values in Portainer, validate the completed ignored file: + +```bash +set -a +. deploy/portainer.env +set +a +python3 deploy/production_preflight.py +``` + +The public reverse proxy should send the Site hostname to `SITE_PORT` and the +Kanban hostname to `KANBAN_PORT`. `/api/` and `/portal.html` are served through +the Site gateway. Preserve the original Host header. Do not expose PostgreSQL, +API, worker, or ClamAV. Restrict the +two published web ports at the host firewall so only the reverse proxy can use +them, and terminate HTTPS at the proxy. + +The `db-init` service completing and stopping is expected. The other six +services must be healthy. A failed `db-init` task or an unhealthy service blocks +acceptance. + +## 4. Normal deployment + +Push to `main`. Gitea validates, tests, scans, publishes these images, and calls +the webhook: + +```text +gitea.blyzer.com.br/blyzer/dtf-api:latest +gitea.blyzer.com.br/blyzer/dtf-api: +gitea.blyzer.com.br/blyzer/dtf-web:latest +gitea.blyzer.com.br/blyzer/dtf-web: +``` + +In Portainer, verify the new image digests, service health, `db-init` result, and +the public `/health` endpoints. Back up PostgreSQL and R2 before changes that +affect stored data or retention. + +## 5. Rollback + +In the Portainer stack variables, change `IMAGE_TAG` from `latest` to the full +SHA of the last known-good Gitea commit and redeploy. This rolls back Site, API, +Kanban, and worker code; it does not undo database migrations or restore data. +After recovery and a corrected release, return `IMAGE_TAG` to `latest`. + +## Current blocker + +This is the final deployment shape, but it is not authorized for production +today. Production adapters, Docker-secret file loading, provider sandbox tests, +current clean base images, approved inputs, and a production restore rehearsal +are still required. Do not bypass `deploy/production_preflight.py` or the Gitea +scan gates to make a deployment run. diff --git a/PRODUCTION_INPUTS.md b/PRODUCTION_INPUTS.md new file mode 100644 index 0000000..88975f8 --- /dev/null +++ b/PRODUCTION_INPUTS.md @@ -0,0 +1,62 @@ +# DTF staging and production input checklist + +Status: input worksheet only. Nothing in this document authorizes a real +integration, production deployment, or use of production credentials. + +Do not put passwords, tokens, webhook secrets, private keys, customer data, or +provider recovery codes in this repository. Record only the credential owner and +the approved secret-injection location. Test every provider in an isolated staging +or sandbox environment before production activation. + +## Decisions required before staging implementation + +| Area | Required decision or evidence | Owner | Status/date | +|---|---|---|---| +| Artwork acceptance | Decide whether customer-entered length and quality grade are accepted directly, manually approved, or verified by another defined process. Name the commercial authority and rejection/correction flow. | | | +| Checkout | Approve the exact transition from quote to payment, including quote expiry, customer confirmation, cancellation, refund, and correction rules. | | | +| Infrastructure | Confirm VPS capacity, operating system, domain/subdomain, DNS owner, TLS termination, Portainer access, Gitea Actions path, and deployment/rollback owner. | | | +| Cloudflare R2 | Provide a staging bucket and endpoint, CORS policy, retention/lifecycle rules, narrowly scoped credential owner, storage budget, and restore/rollback acceptance test. | | | +| PostgreSQL | Define the managed/self-hosted choice, encryption and access policy, backup destination, schedule, retention, restore objective, and named restore-test owner. | | | +| Malware signatures | Approve how ClamAV signatures are refreshed without unrestricted scanner egress, plus stale-signature and scanner-outage response. | | | +| Freight | Select the source-of-truth platform, staging access, origin address/postal code, services/carriers, packaging weight/dimensions by DTF length, pickup rules, and pass-through/subsidy/free-shipping policy. | | | +| Mercado Pago | Provide sandbox account ownership, webhook administration, approved event/status mapping, refund/cancellation policy, reconciliation owner, and secret-injection location. | | | +| Tiny/Olist | Confirm API version/endpoints, staging access, order/product/customer mappings, tag/marker behavior, idempotency key, rate limits, retry rules, and reconciliation owner. | | | +| WhatsApp | Select the provider, sending number owner, opt-in/legal basis, approved templates for the four agreed events, staging access, retry/delivery-failure policy, and support owner. | | | +| Customer accounts | Select email verification and password-recovery provider/flow, session policy, privacy/contact requirements, and customer-support ownership. | | | +| Operators | Define named operator provisioning/removal, roles, MFA expectation, emergency access, and periodic access review. Shared production credentials are not acceptable. | | | +| Monitoring | Name alert recipients and escalation windows for authentication abuse, malware detections, stale signatures, queue failures, provider failures, backup failures, capacity, and downtime. | | | +| Security findings | Record remediation or explicit risk acceptance for the current MinIO, PostgreSQL, Nginx, Debian, and PDF.js findings before a production-readiness review. | | | + +## Evidence required before production activation + +- A separate staging composition/deployment with no production secrets and no + route from local fake integrations to real provider accounts. +- Server-authoritative pricing regression results, including all four product + modes, discounts, assembly charges, minimum length, rounding, and freight. +- Direct multipart R2 tests for resume, exact part sizes, private access, CORS, + expiry, abort, malware quarantine, secure download, and retention. +- Signed and idempotent Mercado Pago webhook tests, including duplicate, delayed, + invalid, cancelled, and refunded events. No payment may be created before freight + is final. +- Idempotent Tiny/Olist and WhatsApp outbox tests covering retry, duplicate delivery, + rate limiting, permanent failure, and operator reconciliation. +- Account verification/recovery, operator access, TLS, cookie, Host/origin, audit, + alert, and incident-response checks in the target architecture. +- A scheduled, encrypted, offsite PostgreSQL/object backup and a documented restore + rehearsal. The verified localhost bundle is useful evidence, not this production + control. +- A recorded go/no-go review signed by the business owner, operations owner, and + technical owner, with rollback contacts and a support window. + +## Safe implementation order after inputs are approved + +1. Complete the non-secret metadata and pass the network-disabled readiness gate. +2. Create the actual separate staging composition and external secret-injection path. +3. Validate private R2 multipart storage, malware release gates, downloads, + retention, backup, and restore. +4. Add freight quotation because its final value is required before payment. +5. Add Mercado Pago sandbox checkout and authenticated idempotent webhooks. +6. Add Tiny/Olist through the existing outbox/idempotency boundary. +7. Add only the four agreed WhatsApp notification events. +8. Run the complete functional, security, dependency, image, recovery, and manual + acceptance suite in staging before any production activation. diff --git a/README.md b/README.md new file mode 100644 index 0000000..0c32fa4 --- /dev/null +++ b/README.md @@ -0,0 +1,662 @@ +# Sistema DTF 24h — Altus Group + +> **Active local milestone (2026-09-11):** Read [CONTEXT.md](CONTEXT.md) first. +> Start with `docker compose up --build`, then open the [Site](http://localhost:8080) +> and [Kanban](http://localhost:8081). Optional configuration: copy `.env.example` +> to `.env`. Follow [LOCAL_SETUP.md](LOCAL_SETUP.md) for the complete test flow, +> local login, health checks, and troubleshooting. See +> [IMPLEMENTATION_REPORT.md](IMPLEMENTATION_REPORT.md) for scope and reuse decisions. +> Production delivery uses one Portainer stack; see [PORTAINER.md](PORTAINER.md). +> Everything below is preserved historical prototype documentation, not the active +> setup or delivery specification. Do not run its production integrations or agent. + +> Documentação para o TI. Reúne o contexto do projeto, as decisões já tomadas, +> a arquitetura, o código e o que ainda depende de resposta. +> Base: conversas de 29 e 30/08/2026 com Marcus. + +--- + +## Por que este projeto existe + +A sala de DTF tem 6 máquinas a 20 m/h. Em dois turnos, das 5h às 20h, isso dá +**37.800 metros/mês de capacidade**. A produção real de maio a agosto de 2026 +ficou em **11.605 metros/mês** — 31% de ocupação. O pico foi junho, com 12.373 m. + +**Não falta máquina. Falta a porta ficar aberta.** + +O que limita a venda é o horário em que conseguimos receber e responder. O +pedido que chega às 17h30 espera até as 5h da manhã, porque não há ninguém para +receber o arquivo, tratar e mandar imprimir. O cliente de DTF compra por +rapidez, e a rapidez tem duas metades: receber e produzir. Hoje as duas param +juntas às 20h. + +### O que muda com o projeto + +| | Hoje · 18k m | Com 24h · 36k m | +|---|---|---| +| Custo por metro | R$ 9,43 | R$ 7,46 | +| Receita | R$ 268.200 | R$ 536.400 | +| **Resultado** | R$ 77.011 | **R$ 225.032** | +| Margem | 28,7% | 42,0% | + +**Ganho de R$ 148 mil/mês, R$ 1,78 milhão/ano**, com a folha subindo 20% +(R$ 6.333). Cada metro acima de 18 mil rende R$ 8,76 de margem de contribuição — +insumo e manutenção custam R$ 4,94 e não mudam; folha, fixo e administrativo já +estão pagos. + +Contra isso, a infraestrutura do projeto custa **R$ 160 a 450 por mês**. + +### Os quatro furos do fluxo atual + +1. **A arte entra por WhatsApp** — canal que não registra nada auditável +2. **O número do pedido é digitado à mão** no nome do arquivo; se errar, a arte + some no servidor e ninguém descobre até o cliente cobrar +3. **O status vive numa pasta de rede** — o Tiny sabe do pedido no começo e no + fim, no meio ninguém sabe +4. **Ninguém mede o tempo de espera** entre etapas + +O item 4 é o que mais importa. Sem ele, não dá para saber se o gargalo é máquina +ou designer — e essa resposta decide se vale montar o terceiro turno. + +--- + +Três componentes que fazem a sala de DTF receber arte 24 horas e medir o próprio tempo. + +> **Comece pelo `TAREFAS.md`** — ordem de execução com critério de aceite. +> Depois `ESPECIFICACAO.md` — ele traz as fases de implementação, as +> funcionalidades uma a uma, e o que mudou depois das reuniões com os designers e +> a sala em 02/09/2026. Este README cobre a arquitetura. + +``` +TAREFAS.md o que fazer, em ordem, com critério de aceite +ESPECIFICACAO.md as funcionalidades uma a uma e o que mudou nas reuniões +API.md contratos de todos os endpoints +schema.sql banco completo, nuvem e local +README.md arquitetura e decisões (este arquivo) + +portal/ FastAPI na nuvem · recebe a arte, valida, repete, fatia, carimba +agente/ script na fábrica · traz o arquivo aprovado para o servidor +kanban/ FastAPI local · a sala move o card, o Tiny recebe o marcador + static/kanban.html front já conectado à API +``` + +--- + +## O que cada um faz + +**portal** — aberto na internet, roda em VPS. O Tiny avisa por webhook que +nasceu um pedido; o portal cria um link com token e manda no WhatsApp. O cliente +sobe o arquivo direto para o storage, sem passar pelo servidor. O robô valida, +empilha as repetições, fatia em partes de no máximo 15 m e carimba a última. + +**agente** — roda como serviço no servidor da fábrica. Busca o que foi aprovado +e grava na pasta `00_ARTE_RECEBIDA`. Se a internet cair, ele para e o portal +continua recebendo; quando voltar, baixa o acumulado. + +**kanban** — tela da sala, só na rede interna. Mover o card grava o movimento, +move o arquivo entre as pastas e enfileira o marcador no Tiny e o WhatsApp. + +--- + +## Regras do processo, em código + +| Regra | Onde está | +|---|---| +| Área útil 57 × 97 cm (30 mm de rodapé) | `preflight.AREA_UTIL_CM` | +| DPI efetivo mínimo 150, ideal 300 | `preflight.validar()` | +| Largura máxima 57 cm | `preflight.validar()` | +| Repetição da arte | `preflight.empilhar()` | +| Montagem empilhada de vários arquivos | `preflight.montar_folha()` | +| Normalização por natureza do arquivo | `preflight.normalizar()` | +| CDR entra sem validar, etiqueta "conferir" | `preflight.FORMATOS_SEM_VALIDACAO` | +| Máximo 20 m por arquivo | `preflight.fatiar()` | +| Carimbo: QR 20 mm + texto, só preto | `preflight.carimbar()` | +| Um carimbo por pedido, na última parte | `preflight.processar()` | + +**A regra que mais pega arquivo ruim é o DPI efetivo.** O valor gravado no +cabeçalho mente com frequência — o cliente escala a imagem e o programa mantém +"300". O que vale é `pixels ÷ (centímetros comprados ÷ 2,54)`. + +--- + +## Decisões já tomadas + +Não precisam ser rediscutidas. Estão implementadas no código. + +| Assunto | Decisão | Por quê | +|---|---|---| +| Chave do pedido | **número do Tiny** | é o que a empresa inteira já usa | +| Gatilho do link | **webhook do Tiny**, não polling | o link sai no segundo em que o pedido nasce | +| Hospedagem do portal | **fora da fábrica** | se a internet cair às 3h, o cliente sobe do mesmo jeito | +| Hospedagem do kanban | **rede interna** | é tela de operação, funciona sem internet | +| Upload | **direto para o storage**, URL pré-assinada | 200 MB passando pelo VPS derrubaria o processo | +| Limite do site | VNDA não aceita 200 MB | por isso o portal é externo | +| Faixa do rodapé | **30 mm** → área útil 57 × 97 cm | cabe o QR de 20 mm com folga | +| QR | **20 mm**, leitura por **celular** | não haverá coletor; celular lê com folga | +| Conteúdo do QR | **URL do card no kanban** | a revisão bipa e cai na tela do pedido | +| Carimbo | **um por pedido**, na última parte | é ela que fecha o pedido | +| Cor do carimbo | **só canal preto** | sem branco de apoio: economiza a tinta mais cara | +| Repetição | **campo no portal**, robô empilha | tira do designer o trabalho mais braçal | +| Limite por arquivo | **20 metros** | 100 m viram 5 arquivos | +| Tamanho do upload | **5 GB** | é o que os PCs da sala aguentam abrir | +| Retenção | **30 dias** | depois apaga do storage | +| Montagem | **empilhada**, sem encaixe lado a lado | são artes de 1 m em sequência | +| CDR | entra com etiqueta **conferir** | a licença do Corel é de estação, não de servidor | +| Movimento | **no kanban**, pasta espelha | sem watchdog: uma peça a menos para manter | +| Qualidade na mensagem | **% e DPI** juntos | um para leigo, outro para quem é do ramo | +| Marcadores no Tiny | **3, não 7** | o kanban é a fonte de verdade | +| Avisos ao cliente | **3 + correção** | sete viraria spam e ele para de ler | +| Designer de madrugada | **não haverá** | a noite imprime o que já estava tratado | + +### O que o robô NÃO faz + +Tratar arte continua sendo trabalho do designer: remover fundo quando o cliente +não removeu, corrigir cor para o perfil da impressora, e julgar o que não presta +mesmo passando na validação técnica — degradê que vira mancha branca, traço fino +que some na aplicação. + +O robô filtra o que **nem deveria chegar** ao designer: DPI baixo, fundo não +removido, largura acima de 57 cm, arquivo corrompido. Isso volta ao cliente +automaticamente e não consome minuto de arte nenhum. + +**Isso gera o número que decide o terceiro turno:** quanto do tempo do designer é +retrabalho de arquivo ruim, e quanto é trabalho de verdade. O kanban mede isso na +primeira semana, olhando o tempo entre `Arte recebida` e `Arte tratada`. + +### Referência de mercado + +O **dtflexprint.com.br**, de Salvador, já opera este modelo: upload no próprio +produto, pré-flight automático, sem receber arquivo por WhatsApp. **Cobram +R$ 55,00 pela mesma unidade de 57 × 100 cm que vendemos a R$ 14,90.** + +A guerra de preço é local; o mercado não é. Depois de resolver a dinâmica de +horário, o passo seguinte é logística nacional. + +--- + +## Fase 1 — limpeza dos marcadores do Tiny + +Primeira entrega do projeto. Não depende de nada e pode começar hoje. + +### Regra que não pode ser violada + +**Limpar a lista de sugestão, não o histórico dos pedidos.** Apagar marcador de +pedido já fechado destrói o pouco de dado que existe sobre o passado. O que +atrapalha é a lista de opções aparecer poluída na hora de marcar um pedido novo. + +### O que sai da lista + +Todas as variações de horário e duração digitadas à mão. Existem dezenas, quase +todas com um ou dois pedidos: + +``` +inicio 14:45 inicio13:34 inicio 12:38hr inicio 930 INICIO 15:09 +11:10 15:30hr 1hrs 3h 3hr +2hrs 1h30min +20m +30min de correcao ++1hr (correcao) +``` + +Alguém na sala está tentando registrar tempo de máquina há meses, à mão, sem +padrão nenhum. **O kanban passa a fazer isso sozinho e melhor**, com carimbo +automático de entrada e saída em cada etapa. Esse trabalho manual deixa de +existir — e é bom dizer isso à sala, porque é esforço real que estava sendo +desperdiçado. + +### O que fica + +| Marcador | Pedidos | Para quê | +|---|---|---| +| `fila de impressao` | 2.004 | coluna do kanban | +| `CORRECAO DTF` | 116 | coluna do kanban | +| `Maq 1` … `Maq 6` | 3.406 | histórico de máquina | +| `multiempresa`, `VALE`, `Troca`, `BOLETO NEXSTAR SICCOB` | — | outra natureza, não mexer | + +### O que nasce + +`DTF-PRODUCAO` e `DTF-PRONTO`. Só dois — ver a seção de marcadores acima. + +### Atenção: os marcadores de duração NÃO são poluição + +``` +30 min → 2.430 pedidos +1 hora → 833 pedidos +3 horas → 40 pedidos +``` + +Estes são padronizados e parecem ser a **estimativa de minutos de máquina do +pedido** — exatamente o dado que o kanban precisa para calcular fila contra +capacidade. + +Hoje o código estima esse tempo pelos metros, a 20 m/h +(`kanban/main.py`, campo `minutos_maquina`). Mas arte complexa pode demorar mais +que arte simples do mesmo tamanho. + +**Confirmar com o Thales antes de apagar:** esses marcadores são estimativa de +tempo de máquina ou outra coisa? Se forem estimativa e refletirem algo que a +sala sabe e o metro não captura, viram **campo no card**, não marcador — e o +cálculo de capacidade fica mais preciso que a conta por metragem. + +--- + +## Como o arquivo chega na máquina + +**Desenho novo, decidido em 30/08/2026.** O PC central deixa de ser passagem +obrigatória e vira posto de validação e exceção. + +### Antes + +``` +PC central → abre o arquivo, aplica o SPOT à mão, salva de novo na pasta + ↓ +PC da máquina → alguém pega o arquivo e toca no software +``` + +Todos os arquivos passavam por uma máquina e uma pessoa. Se ela saía, a fila +parava. Às 3h da manhã, não havia ninguém. + +### Agora + +``` +portal → robô (valida · monta · SPOT · carimba) → fila única + ↓ + operador clica "puxar próximo" na máquina + ↓ + arquivo cai na hot folder 30_MAQ1 … 30_MAQ6 + ↓ + FlexiPRINT processa sozinho de lá +``` + +O operador abre no Flexi, roda, e arrasta o card para Finalizado. **Um clique no +começo, um arraste no fim.** Nunca escolhe pedido, nunca procura arquivo, nunca +decide ordem. + +### Por que puxada e não empurro + +Empurrar exigiria adivinhar qual máquina estará livre daqui a duas horas. Se uma +travar, a fila dela para enquanto outra fica ociosa, e alguém remaneja na mão. +**Por puxada nunca desbalanceia.** + +Três regras que sustentam isso: + +| Regra | Por quê | +|---|---| +| Reserva expira em **3 min** | ajustado pela sala: 15 era demais | +| Devolver põe no **topo**, não no fim | o pedido já esperou uma vez | +| **Um pedido por vez** | a sala preferiu assim a puxar lote de trabalho | + +Ver `/api/puxar` e `/api/devolver` em `kanban/main.py`. + +### O que sobra para o PC central + +Validação, exceções e o SPOT manual dos casos que a regra automática não cobre. +Deixa de estar no caminho crítico de todo pedido. + +--- + +## A validar com os designers e a sala — SPOT + +O canal branco passa a ser gerado pelo robô. A regra base é medível e cabe em +poucas linhas, mas existem variações que **precisam ser confirmadas antes de +codificar**. + +### O que já é regra, não julgamento + +**Choke** (contração do branco) evita que o branco apareça na borda quando o +registro sai levemente fora. O problema é que em traço fino ele come a linha: +um filete de 0,4 mm a 300 DPI tem ~5 px; tirando 2 de cada lado sobra 1, e o +branco quase some. + +Isso é medível. O robô mede a espessura de cada elemento e aplica choke +proporcional — **na mesma arte, texto grosso encolhe e filete fino não**: + +| Espessura do elemento | Choke | +|---|---| +| acima de 2 mm | 2 px | +| 1 a 2 mm | 1 px | +| abaixo de 1 mm | nenhum | + +### O que precisa ser validado + +| Ponto | Pergunta para a sala | +|---|---| +| **Valores do choke** | 2 px acima de 2 mm está certo, ou vocês usam outro número? | +| **Limite do traço fino** | abaixo de quanto vocês nunca aplicam contração? | +| **Branco em degradê** | onde a arte tem transparência parcial, o branco fica meio transparente. Vocês ajustam? Como? | +| **Densidade do branco** | arte escura pede mais branco que arte clara? Isso é ajustado hoje? | +| **Tipo de tecido** | o branco muda conforme o cliente vai aplicar em algodão ou poliéster? | +| **Casos que nunca dão certo no automático** | quais? | + +### Como conduzir a conversa + +Não perguntar "o que vocês fazem". Pedir **cinco arquivos**: + +- dois que sempre saem bem no automático +- dois que sempre precisam de ajuste +- um que já deu errado + +Com esses cinco dá para descobrir se a regra cabe em três linhas de código ou se +há julgamento de verdade envolvido. + +**Aposta:** 80% dos casos cabem na regra de espessura. Os 20% restantes viram +uma etiqueta `spot manual` no card e vão para o PC central como **exceção, não +como padrão**. + +**Isso decide a madrugada:** se o SPOT manual for exceção, o turno da noite roda +no automático e deixa as exceções para o dia. Não precisa de designer de plantão. + +--- + +## Insumos: tudo que passa pelo depósito já está medido + +O aproveitamento do filme sai das transferências para o depósito de impressão no +Tiny. O mesmo caminho serve para todo o resto: + +| Insumo | Consumo teórico por 100 m | O que o desvio revela | +|---|---|---| +| Filme | 100 m comprados → 90 úteis | acerto, prova de cor, refile, ponta | +| Tinta | 1,5 L | purga excessiva, vazamento, apontamento errado | +| Poliamida | 2,5 kg | idem | +| Peças de máquina | — | custo por metro, sem teórico | + +O sistema sabe quantos metros imprimiu, então calcula o teórico e compara com o +transferido. Tinta a 1,8 L por 100 m significa 20% de desvio — hoje ninguém +saberia. + +--- + +## FlexiPRINT · hot folder confirmado, arquitetura a definir + +A documentação oficial da SAi confirma: **o Flexi tem hot folder**, uma pasta +por dispositivo de saída, monitorada continuamente. Arquivo copiado ou movido +para dentro entra na fila automaticamente. Por padrão fica em +`C:\Program Files\[Software]\Jobs`. + +A versão 21 traz dois recursos relevantes: + +- **"RIP only" ao receber na hot folder** — processa o arquivo sem esperar a + máquina ficar livre +- **Opções melhoradas de branco para DTF** e ferramenta de fundo transparente + +### O problema de memória + +Relato da sala: **o PC que roda a máquina não aguenta preparar outro arquivo ao +mesmo tempo** — o RIP consome memória demais. É por isso que existe o PC +central hoje. + +Duas arquiteturas possíveis, e a escolha depende do que a licença de vocês +permite: + +**A · Production Manager centralizado.** Se o Flexi permitir gerenciar a fila de +várias impressoras a partir de um PC só, o **PC central vira servidor de RIP** e +os PCs das máquinas ficam leves — só transmitem dados para a impressora. +Resolve o problema sem trocar computador. + +**B · RIP distribuído.** Cada PC ripa o próprio trabalho. Aí o "RIP only" ajuda, +porque o arquivo é processado enquanto a máquina ainda roda o anterior — mas o +PC precisa aguentar as duas coisas. + +**Levantamento pendente com Thales e Alexandre** (ver `dtf-roteiro-reuniao.md`, +bloco E2): + +- edição e versão do Flexi **em cada máquina** — se forem diferentes, o + comportamento da hot folder varia entre elas +- a hot folder aceita pasta de rede ou só local? +- existe "RIP only" na versão instalada? +- o Production Manager centraliza várias impressoras? +- o Flexi gera o canal branco a partir da transparência? +- as licenças são por PC ou flutuantes? + +**Enquanto isso não fecha, não programe a fase 4.** O desenho da hot folder +depende de a pasta de rede funcionar. + +--- + +## Instalação + +### Portal (VPS Ubuntu) + +```bash +apt install -y python3.12-venv libvips-tools postgresql nginx certbot +python3 -m venv /opt/dtf/venv && source /opt/dtf/venv/bin/activate +pip install -r requirements.txt +cp .env.exemplo .env # preencher +cd portal && uvicorn main:app --host 0.0.0.0 --port 8000 +``` + +Nginx faz proxy para a 8000 e o certbot cuida do TLS em +`arte.dropstaratacado.com.br`. + +### Agente (servidor da fábrica) + +Windows, como serviço: + +``` +nssm install DtfAgente "C:\Python312\python.exe" "C:\dtf\agente.py" +nssm set DtfAgente AppEnvironmentExtra BASE_PORTAL=... AGENTE_TOKEN=... +nssm start DtfAgente +``` + +Linux: usar `agente/dtf-agente.service`. + +### Kanban (servidor da fábrica) + +```bash +cd kanban && uvicorn main:app --host 0.0.0.0 --port 8080 +``` + +O front é o protótipo `dtf-portal-kanban.html`, apontando para `/api/quadro` +e `/api/mover`. Colocar em `kanban/static/kanban.html`. + +--- + +## Estrutura de pastas no servidor + +``` +\\servidor\DTF\ + 00_ARTE_RECEBIDA 10_ARTE_TRATADA 20_FILA_IMPRESSAO + 30_IMPRIMINDO 40_CORRECAO 50_APLICACAO + 60_FINALIZADO _ERRO _log +``` + +O banco é a fonte de verdade e a pasta é espelho. Se divergirem, o banco ganha. + +--- + +## Tabelas + +| Tabela | Onde | Para quê | +|---|---|---| +| `pedido` | nuvem | número do Tiny, cliente, token e validade | +| `arte` | nuvem | arquivo, DPI, status, motivo da recusa | +| `parte` | nuvem + local | cada arquivo gerado pelo fatiamento | +| `card` | local | posição atual no kanban | +| **`movimento`** | local | **de onde saem todos os números** | +| `job` | local | fila de marcador e WhatsApp, com retentativa | + +### Normalização: o cliente manda o que quiser + +Não existe "formato certo" único — normalizar tudo para um só jogaria fora o +melhor de cada tipo. A regra é por **natureza do conteúdo**: + +| Chega como | Sai como | Por quê | +|---|---|---| +| PDF, AI, SVG, EPS | **PDF**, mantendo vetor | rasterizar aqui é perder qualidade | +| PNG, TIF, PSD, PSB | **TIF** com alfa, LZW | é o que a sala já usa | +| CDR | não converte | sem Corel no servidor | + +**O original é sempre preservado.** Pedido dos designers: se a conversão sair +ruim num caso, eles voltam ao arquivo do cliente. + +**Resolve o limite dos 5 metros.** Os designers relatam abrir PDF no Corel para +não rasterizar, exportar, abrir no Photoshop — e esbarrar em 5 metros. O limite +não é do Photoshop: é do formato **PSD**, que trava em 30.000 px por dimensão, +o que a 150 DPI dá 5,08 m. PSB vai a 300.000 px, ou 50 metros. Em PDF vetorial +não há esse limite. + +**Melhor ainda:** PDF vetorial pode ir do portal direto para a hot folder. O +FlexiPRINT rasteriza na resolução exata da máquina, na hora de imprimir — +qualidade melhor que qualquer caminho manual, e uma etapa a menos. + +**CMYK vira RGB na normalização.** Arquivo em CMYK é uma das causas de cor +errada no DTF: o cliente monta em CMYK, a máquina trabalha em RGB, e a cor muda. + +### Retrabalho: meta por causa, não meta única + +SKU `CRRMP.TX.100CM`. A Mayana abre e classifica a causa; Thales ou Alexandre +autorizam, porque o retrabalho da casa entra na meta e na remuneração deles. +**A causa fica travada depois de aberta** — com indicador atrelado a bônus, +haveria incentivo para reclassificar falha de máquina como culpa do cliente. +Quem discorda contesta, e a contestação fica registrada. + +| Causa | Responsável | Hoje | Meta | +|---|---|---|---| +| Falha de impressão | Thales e Alexandre | 1,8% | 0,4% | +| Perfil de cor | Thales e Alexandre | — | 0,4% | +| Erro de tratamento | designers | 1,1% | 0,4% | +| Erro de pedido | comercial | — | 0,4% | +| Arte do cliente | — | 0,9% | fora da meta | +| **Total da casa** | | **2,9%** | **1,6%** | + +**Perfil de cor virou causa própria.** Cor errada é o retrabalho mais comum de +DTF e quase nunca é defeito de máquina. Separando de "falha de impressão", dá +para saber quanto é arte em CMYK, quanto é monitor do cliente e quanto é perfil +da impressora desatualizado — só o último é da casa. + +**Coluna nova: aprovação de cor.** Antes de imprimir o pedido inteiro, sai uma +amostra, foto pelo WhatsApp e o cliente aprova. Dispara sozinho em arquivo acima +de 10 m, primeiro pedido do cliente, ou cor fora do gamut CMYK. Custa +centímetros de filme e evita metros de reposição. + +**Não existe coluna de aplicação.** A sala só imprime o filme — quem aplica na +peça é o cliente. + +Meta única de 1,5% penalizaria o designer por falha de máquina e exigiria +derrubar 64% do retrabalho de uma vez. Meta inatingível empurra para +reclassificar causa, não para reduzir defeito. Ver `META_POR_CAUSA` e +`/api/relatorio/retrabalho`. + +### Os marcadores de duração são estimativa de máquina + +Confirmado pela sala em 02/09/2026. `30 min` (2.430 pedidos), `1 hora` (833) e +`3 horas` (40) **não são lixo de cadastro** — são a estimativa de quanto tempo o +trabalho leva na máquina. + +**Não somem: viram o campo `minutos_maquina` no card.** É esse número que o +kanban usa para calcular fila contra capacidade do dia. Sem ele, a estimativa +sai dos metros a 20 m/h — mas arte complexa demora mais que arte simples do +mesmo tamanho, e a sala sabe qual é qual. + +**Quem preenche:** o sistema sugere pelo tamanho; quem trata a arte ajusta só +quando foge do normal. + +| Marcador | Destino | +|---|---| +| `inicio 14:45` e variações | **some** — o sistema carimba a hora do movimento real | +| `Maq 1` … `Maq 6` | vira etiqueta no card, sai do Tiny | +| `fila de impressao` | vira coluna do kanban | +| `CORRECAO DTF` | continua no Tiny — o comercial precisa ver | +| **`30 min` · `1 hora` · `3 horas`** | **vira campo `minutos_maquina`** | + +### Marcadores no Tiny: três, não sete + +O kanban é a fonte de verdade da operação. O Tiny recebe só o estágio grosso, +para quem não abre o kanban — comercial no telefone, expedição, celular: + +| Movimento no kanban | Marcador no Tiny | +|---|---| +| recebida · tratada · fila · aplicação | nenhum | +| entra em **Imprimindo** | `DTF-PRODUCAO` | +| vai para **Correção** | `CORRECAO DTF` | +| **Finalizado** | `DTF-PRONTO` | + +Três chamadas por pedido em vez de sete. A 213 pedidos/dia, 640 requisições +em vez de 1.500 — folga no limite da API e menos job para monitorar. +A máquina que imprimiu fica só no kanban. + +### Artes guardadas para recompra + +Prefixo separado no storage: `artes-cliente/{numero_cliente}/`, retenção de +**12 meses** — contra os 30 dias do arquivo de trabalho. Guarda-se só a **arte +tratada**, não o original: é menor e é a que vai para a máquina. + +O cliente acessa por um link permanente dele (token de cliente, não de pedido), +numa página "minhas artes", e pede reimpressão com um clique — que abre pedido +novo no Tiny. Resolve o caso de quem quer a mesma arte de dois meses atrás. + +### Abrir o arquivo pelo kanban · sem instalar nada + +**Decisão de 30/08/2026: nada instalado nos PCs da sala. Só a tela.** + +Navegador não lança programa externo — é bloqueio de segurança, sem contorno. +Então o desenho é: + +1. **Miniatura no card** — o operador confere a arte sem sair da tela +2. **Botão copia o caminho** — cola no FlexiPRINT +3. **File System Access API** — Chrome ou Edge pede permissão à pasta de rede + uma vez; a partir daí o kanban lê e move arquivo direto do navegador + +O item 3 tem uma consequência boa: **a movimentação de arquivo sai do backend.** +O `mover_arquivos()` em `kanban/main.py` vira opcional — quem move é a própria +tela. Menos código no servidor e menos chance de o estado divergir. + +O que continua manual: colar o caminho no Flexi. Uma tecla a mais que o ideal. +Handler local resolveria, mas exige instalação em cada máquina — descartado. + +### Aproveitamento do filme: sai do Tiny, sem apontamento novo + +A Altus transfere o insumo para um depósito de impressão antes de rodar, porque +também **revende insumo** — o depósito separa consumo interno de revenda. + +Isso significa que o consumo de filme **já é registrado hoje**. O painel só lê a +movimentação desse depósito e divide os metros faturados pelos metros +transferidos. Nenhum gesto novo para a sala. + +Ver `DEPOSITO_IMPRESSAO` e `tiny.transferido_para_deposito()`. + +`movimento` é a mais importante. Dela saem tempo por etapa, fila por máquina, +taxa de retrabalho e ocupação real — os números que hoje não existem em lugar +nenhum. Ver `/api/relatorio/etapas`. + +--- + +## Decisões que dependem de você, Wagner + +1. **Servidor da fábrica é Windows ou Linux?** Muda como o agente vira serviço. +2. **A conta do Tiny já tem aplicação na API v3?** Precisamos de client id e secret. +3. **Confirmar na documentação do Tiny** o endpoint de marcadores e o limite de + requisições por minuto. `tiny.py` isola isso — se mudar, muda só ali. +4. **O número do WhatsApp do DTF migra para a API oficial da Meta**, ou fica com + provedor tipo Z-API? A oficial exige template aprovado para mensagem iniciada + por nós, mas não corre risco de bloqueio. +5. **Latência da integração VNDA → Tiny.** É ela que define quanto tempo passa + entre a compra e o link chegar no cliente. Se for alta, o argumento de + rapidez do projeto perde força. +6. **Retenção dos arquivos: 90 dias.** Configurar regra de ciclo de vida no + bucket. A arte é propriedade do cliente. + +--- + +## Segurança + +- Token do link: UUID v4, 7 dias, um por pedido +- HTTPS obrigatório no portal, Let's Encrypt com renovação automática +- Kanban **sem porta aberta para fora** — se precisar de acesso remoto, VPN +- ClamAV no arquivo recebido antes de liberar para o agente +- Dump diário do Postgres para o storage +- Heartbeat do agente a cada 5 min; sem sinal por 15 min, alertar o TI + +Serviço silencioso parado é pior que erro barulhento — ninguém percebe até o +cliente cobrar. + +--- + +## Ordem de entrega + +| Fase | Entrega | Já dá valor sozinha? | +|---|---|---| +| 1 | Limpar marcadores — ver seção própria | **sim**: destrava o kanban e some com trabalho manual da sala | +| 2 | Portal + robô + storage no ar | **sim**: recebimento 24h e recusa automática | +| 3 | Agente rodando como serviço | **sim**: arquivo cai na pasta sozinho | +| 4 | Kanban + Tiny + WhatsApp | é o que transforma movimento em número | + +As fases 2 e 3 entregam sozinhas. A fase 4 é onde a medição começa. diff --git a/Reunião iniciada às 2026_09_09 09_39 GMT-03_00 - Anotações do Gemini.pdf b/Reunião iniciada às 2026_09_09 09_39 GMT-03_00 - Anotações do Gemini.pdf new file mode 100644 index 0000000..5e43ea6 Binary files /dev/null and b/Reunião iniciada às 2026_09_09 09_39 GMT-03_00 - Anotações do Gemini.pdf differ diff --git a/SECURITY_REPORT.md b/SECURITY_REPORT.md new file mode 100644 index 0000000..564c147 --- /dev/null +++ b/SECURITY_REPORT.md @@ -0,0 +1,175 @@ +# Local security closeout + +Date: 2026-09-15 + +## Scope and conclusion + +This report covers the localhost-only Site, Portal/API, Kanban, PostgreSQL, +MinIO, ClamAV, and fake integration worker. It does not approve production use +or real Mercado Pago, R2, Tiny/Olist, WhatsApp, freight, or other providers. +Malware scanning is a quarantine control; it is not artwork or print pre-flight. + +The local stack is healthy and its security regressions pass. Existing orders +and the named PostgreSQL/MinIO volumes were preserved. Open dependency and image +findings remain and are recorded below; there is no claim of zero vulnerabilities, +complete OWASP compliance, or production readiness. + +## Implemented controls + +- Loopback-only published ports, local-only adapter guards, internal API/worker/ + database/scanner network, Host checks, cross-origin write rejection, CSP, + frame denial, MIME sniffing protection, and no interactive API documentation. +- Escaped untrusted filenames and browser regression coverage with CSP bypassed. +- Expiring, revocable, hashed HttpOnly operator sessions. No Basic credentials or + operator password are retained in browser storage. +- Seven-day revocable customer sessions, stronger scrypt password hashes, legacy + verification and upgrade, comparable missing-account password work, and login + throttling. +- Upload extension/size/count quotas, storage quotas, private UUID object keys, + exact signed multipart `Content-Length`, completion/ownership checks, and + five-minute signed downloads. +- Files start `pending`. Only `clean` files may be quoted, approved, paid, + downloaded, attached as final files, or moved into queue/printing states. + Unknown, scanner error, unsafe/encrypted, over-limit, and malware outcomes fail + closed. Rejected/error files expire within three days. +- Restricted PostgreSQL and MinIO runtime identities provisioned separately from + administrator credentials. Containers use read-only filesystems/capability + drops where compatible. +- Structured redacted security logs plus a 30-day PostgreSQL event table. Worker + health includes outbox progress, scan-thread liveness, and a live ClamAV PING. + The alert summary also reports signature age. +- Logout revokes server sessions and clears checkout keys and IndexedDB File blobs + across open Site tabs. +- Production delivery definitions use unprivileged application/web users, + read-only filesystems, dropped capabilities, external Swarm secrets, private + service networking, immutable base images, commit-SHA rollback tags, + health-monitored rolling updates, and automatic application rollback. A + fail-closed source/configuration gate prevents the current local-only runtime + from being released as production. + +## Verified checks + +All results below were observed against the final application source. Smoke and +workflow were repeated after the refreshed PostgreSQL 17 image was activated. + +| Check | Result | +|---|---| +| Pricing parity against Site JavaScript | Pass: all 4,444 comparisons plus invalid inputs | +| Security regression | Pass: headers, Host/origin, sessions, quotas, multipart signing, throttling | +| Real ClamAV EICAR regression | Pass: rejected and blocked from download/quote; clean control released | +| Smoke workflow | Pass: multipart, ownership, all modes, pricing/freight, payment idempotency, states/history | +| Customer/final-file workflow | Pass: identity, revocation, corrections, secure downloads, invalidation and queue gate | +| Runtime security | Pass: PostgreSQL/MinIO least privilege, hashes, quarantine and scanner failure behavior | +| Retention | Pass: expired bytes removed, live bytes preserved, metadata retained | +| Browser workflow | Pass: end-to-end flow, filename XSS probe, no stored operator password, logout blob cleanup | +| Dependency lock | Pass: 26 exact packages, SHA-256 hashes on every entry, direct-pin parity, hash-enforced image build, `pip check` | +| Staging readiness gate | Pass with synthetic non-secret metadata in a network-disabled container; unsafe/incomplete regression cases rejected | +| Production delivery definitions | Pass: unit/syntax/YAML checks, Swarm render, immutable-base image builds, non-root read-only web runtime and Host rejection | +| Production source preflight | Expected block: local-only/fake adapters and Docker secret-file loading are not production implementations | +| Production ClamAV runtime | Pass: UID 100:101, read-only filesystem, no capabilities/no-new-privileges, live PONG | +| Repository secret scan | Pass: no HIGH/CRITICAL Trivy secret findings; release workflow enforces the same gate | + +## Malware-scanner operations + +The scanner image is digest-pinned and has no external network route. It uses +the signatures bundled into that image. On closeout it reported ClamAV +`1.5.4/28122/Sun Sep 13 06:26:25 2026`; the summary calculated 31.8 hours of age, +below the seven-day alert threshold. + +The multipart transport supports uploads up to 5 GiB, but `SCAN_MAX_BYTES` and +ClamAV stream limits release at most 128 MiB by default. Larger files remain +blocked. Supporting larger files requires a deliberate resource/timeout design, +not simply increasing the upload limit. + +Run: + +```bash +docker compose exec -T api python -m local.security_status +``` + +An exit status of 1 requires review. At closeout, attention was expected because +the regression suite produced two rate-limit alerts, 20 synthetic failed operator +logins, and two rejected `SECURITY-EICAR.cdr` fixtures. Both rejected fixtures +expire on 2026-09-17. ClamAV was available and its signatures were not stale. +Do not automatically dismiss later alerts: verify filename, timestamp, test run, +scanner availability, and signature age. Treat non-test rejected files, scanner +errors, unexplained authentication bursts, or stale signatures as incidents. + +## Dependency and image audit + +`pip-audit` inspected the exact packages installed in the hash-enforced rebuilt API +and found no known Python advisories on 2026-09-15. All 26 direct and transitive +runtime packages are pinned with artifact hashes in `local/requirements.lock`. +`local/lock_dependencies.sh` regenerates it in a disposable Python 3.12 container. +This is a point-in-time package-database result, not proof that the dependencies +or image are vulnerability-free. Scheduled lock refresh and audit automation remain +unfinished. + +Trivy JSON reports are in `output/security/`. HIGH/CRITICAL results after the +available custom-image package upgrades were: + +| Image | Findings | Qualification | +|---|---:|---| +| API | 46 HIGH | 44 Debian records had no fix; Trivy's two Python records named `msgpack` and `setuptools`, which `pip list` confirmed are absent from the runtime. Trivy warned that the third-party SBOM may be inaccurate. | +| Site | 5 HIGH | Nginx package records with fixes listed by Trivy, but the current official `nginx:1.28-alpine` image/repository did not supply them. | +| PostgreSQL 17 | 30 HIGH, 1 CRITICAL | Nine Alpine library records and 22 records in `/usr/local/bin/gosu`; presence is confirmed, reachability through this local stack is not. | +| MinIO | 102 HIGH, 6 CRITICAL | Findings span the MinIO and `mc` binaries and two OS packages. A verified local clean-object archive now exists, but the old pinned release was not changed without a tested version-migration and rollback plan. | +| ClamAV | 0 HIGH/CRITICAL | This scan result is not a guarantee that no vulnerability exists. | +| Production API validation image | 55 HIGH, 3 CRITICAL | 44 records had no fix. Fourteen listed fixes, but the `msgpack` and `setuptools` records came from a third-party SBOM and both packages were confirmed absent with `pip list`; the remaining fixed records are Debian packages. | +| Production web validation image | 52 HIGH, 2 CRITICAL | All 54 records listed fixed Alpine versions. A current approved Nginx base digest must replace the locally available validation base before release. | + +Scanner presence is evidence, while exploitability/reachability requires separate +analysis. MinIO and the remaining base-image findings block any production-readiness +claim even though ports are loopback-only here. The production validation reports +are `production-api-container-audit.json` and +`production-web-container-audit.json`; both make the release workflow's +HIGH/CRITICAL gate fail. Counts reflect the 2026-09-15 Trivy database and can +change when the advisory database or selected base digest changes. + +## Production delivery security boundary + +The files in `deploy/` and `.gitea/workflows/` are a guarded delivery mechanism, +not an approval to operate the current application on the public internet. The +single Gitea workflow requires a protected Docker runner, exact commit checkout, +digest-pinned base/scanner images, regressions, and HIGH/CRITICAL Trivy gates. +It publishes both `latest` and the full commit SHA, then calls the Portainer +webhook. Application/provider secrets are created directly as versioned external +Swarm secrets and never cross the workflow. Rollback selects the prior commit SHA +in Portainer and does not roll back the database. + +The gate currently identifies real blockers: production adapters and authenticated +payment webhooks are absent, the runtime intentionally rejects production/R2, +Docker secret-file configuration is not implemented, approvals are unset, and +the existing image findings are unresolved. These checks must be satisfied by +implementation and review, not by replacing the checks with permissive values. + +## PDF.js review + +The Site loads version 3.11.174 from a versioned CDN URL. That version is affected +by [GHSA-wgrm-67xf-hhpq](https://github.com/mozilla/pdf.js/security/advisories/GHSA-wgrm-67xf-hhpq), +whose documented workaround is `isEvalSupported:false`; the existing Site call +already sets that value, so the known eval path is mitigated and is not reported +as unmitigated. The newer +[GHSA-hq66-cqwq-w95j](https://github.com/mozilla/pdf.js/security/advisories/GHSA-hq66-cqwq-w95j) +affects versions from 5.6.83 up to the patched 6.2.108 and therefore does not +include 3.11.174. + +Version 3.11.174 is nevertheless old, remotely loaded, and not a satisfactory +long-term dependency posture. Plan a compatibility-tested upgrade and preferably +vendor or integrity-pin the asset. Keep script execution disabled and do not +weaken CSP merely to support a preview. + +## Before any staging or production work + +- Resolve or formally accept current MinIO, PostgreSQL, Nginx, and Debian image + findings. Use the verified local clean-object bundle to rehearse a MinIO + migration and rollback; it is not a scheduled, offsite, or production backup. +- Schedule controlled dependency-lock refreshes and exact-runtime audits; review + and test every resulting version change. +- Establish a signature update/rebuild process that works without giving the + scanner an unrestricted external network route. +- Replace disposable local secrets; add TLS, production session/cookie settings, + account verification/recovery, centralized monitoring, and complete backup/ + restore procedures. +- Re-run every security, malware, workflow, browser, retention, dependency, and + image check in the target staging architecture. diff --git a/TAREFAS.md b/TAREFAS.md new file mode 100644 index 0000000..a1f4ed0 --- /dev/null +++ b/TAREFAS.md @@ -0,0 +1,212 @@ +# Tarefas — em ordem de execução + +> Cada tarefa tem **critério de aceite**: o que precisa acontecer para ela ser +> considerada pronta. Sem isso, "terminei" vira discussão. +> +> A ordem importa: as três primeiras não dependem de decisão de ninguém. + +--- + +## Bloco A · Pode começar hoje + +Nada aqui depende de resposta pendente. + +### A1 · Limpar os marcadores do Tiny +**Aceite:** a lista de sugestão de marcadores só mostra os padrões. Os pedidos +antigos mantêm o histórico intacto. + +- Criar `DTF-PRODUCAO`, `DTF-PRONTO`, `DTF-PROVA-COR` +- Remover da lista de sugestão: `inicio 14:45`, `inicio13:34`, `1hrs`, `3h`, + `+30min de correcao` e as demais variações digitadas à mão +- **Não apagar do histórico dos pedidos** — só da lista de opções +- **Preservar** `30 min`, `1 hora`, `3 horas`: são estimativa de máquina + +### A2 · Contratar a infraestrutura +**Aceite:** `https://arte.dropstaratacado.com.br` responde com certificado +válido, e um arquivo de teste sobe e desce do storage. + +- VPS Linux 2 vCPU / 4 GB · Hetzner, Contabo ou Hostinger +- Storage S3 compatível · Cloudflare R2 ou Backblaze B2 +- Subdomínio + Let's Encrypt +- Bucket `dtf-artes` com ciclo de vida de 30 dias +- Prefixo `artes-cliente/` com 12 meses +- CORS liberado só para o domínio do portal + +### A3 · Criar o banco +**Aceite:** `schema.sql` roda sem erro no Postgres e no SQLite. + +- Postgres na nuvem · SQLite na fábrica +- Dump diário do Postgres para o storage + +### A4 · Provisionar acessos +**Aceite:** um token do Tiny obtido por código, e um WhatsApp de teste enviado. + +- Aplicação na API v3 do Tiny · client id e secret +- **Confirmar na documentação** o endpoint de marcadores e o limite de req/min +- WhatsApp: definir Meta oficial ou provedor + +--- + +## Bloco B · Portal — entrega sozinho + +Ao fim deste bloco a Altus **já recebe arte 24 horas**, mesmo sem kanban. + +### B1 · Webhook e link +**Aceite:** um pedido criado no Tiny gera link e chega no WhatsApp em menos de +1 minuto. + +- `POST /webhook/tiny` → cria pedido, token de 7 dias, dispara WhatsApp +- Idempotente: pedido repetido não duplica +- **Medir a latência VNDA → Tiny** e registrar + +### B2 · Página de upload +**Aceite:** um arquivo de 5 GB sobe sem derrubar o VPS. + +- URL pré-assinada, upload em partes +- Campo de repetição com prévia da conta +- Gabarito 57 × 97 cm para download +- Rate limit de 20 req/min por token + +### B3 · Pré-flight +**Aceite:** dos cinco arquivos que os designers separarem, o robô decide igual +ao que eles decidiriam. + +- `preflight.py` está pronto — integrar e testar +- Normalização: vetor → PDF, raster → TIF, CMYK → RGB, **original preservado** +- Repetição, fatiamento em 20 m, carimbo com QR de 20 mm +- CDR entra sem validar, etiqueta "conferir" +- **`carimbar()` precisa de teste visual impresso** antes de valer + +### B4 · Mensagens +**Aceite:** as seis mensagens chegam com o texto certo, e a de correção pede +resposta. + +- Lembrete de 1 hora sem arte +- Recusa com motivo em português +- Aprovação com **% e DPI**, metragem, tempo e horário previsto +- Em produção, correção, finalizado + +### B5 · Antivírus +**Aceite:** um EICAR de teste é barrado e não chega ao agente. + +- ClamAV em segundo plano, sem travar a fila + +--- + +## Bloco C · Agente + +### C1 · Serviço na fábrica +**Aceite:** derrubar a internet por 10 minutos e religar — o agente baixa o +acumulado sozinho, sem duplicar nada. + +- Windows via NSSM ou Linux via systemd +- Webhook + polling de 60 s +- Download em arquivo temporário, renomeia só quando completa +- Verificação de SHA-256 +- Idempotente pelo `arte_id` + +### C2 · Monitoramento +**Aceite:** matar o processo dispara alerta em até 15 minutos. + +- Heartbeat a cada 5 min +- Alerta ao TI se sumir + +--- + +## Bloco D · Kanban como aba do PCP + +### D1 · Quadro +**Aceite:** dois operadores clicando `puxar` ao mesmo tempo — só um pega. + +- 7 colunas · **sem coluna de aplicação** +- Cronômetro por card, em tempo real +- Front pronto em `kanban/static/kanban.html` +- `?maq=4` abre filtrado na máquina + +### D2 · Puxar e devolver +**Aceite:** puxar e não mover em 3 minutos devolve o pedido à fila sozinho. + +- Reserva de **3 min** · **um pedido por vez** +- Devolver volta ao **topo** +- Círculo vermelho na máquina ocupada, botão desabilitado + +### D3 · Movimento e integração +**Aceite:** desligar o Tiny, mover cards, religar — os marcadores entram sozinhos +e nenhum movimento se perde. + +- Gravar o movimento **antes** de qualquer chamada externa +- Fila de jobs com retentativa em 1, 5 e 30 min +- Três marcadores no Tiny, não sete +- Arquivo acompanha o card entre as pastas + +### D4 · Estimativa de máquina +**Aceite:** o card sugere os minutos e aceita ajuste manual. + +- Campo `minutos_maquina`, sugerido por `metros/20*60` +- Importar os marcadores `30 min`, `1 hora`, `3 horas` dos pedidos existentes + +### D5 · Retrabalho +**Aceite:** a causa não pode ser alterada depois de aberta, nem pelo autorizador. + +- Abertura com causa obrigatória e evidência +- Alçada automática · reincidência sobe nível +- Contestação registrada sem alterar a causa +- **Meta ainda não definida** — `META_POR_CAUSA` isolado + +### D6 · Painel e relatórios +**Aceite:** os quatro relatórios respondem com dados reais depois de uma semana. + +- Filtros de período +- `/api/relatorio/etapas`, `/impressao`, `/aproveitamento`, `/retrabalho` +- Aproveitamento lendo as transferências do depósito no Tiny + +--- + +## Bloco E · Só depois de medir + +**Duas semanas com o kanban rodando antes de tocar nisto.** + +### E1 · Decidir o terceiro turno +Depende de: metros/hora reais, tempo entre etapas, e quanto do tempo do designer +é retrabalho de arquivo ruim. + +### E2 · SPOT automático +Depende do teste em `dtf-teste-branco-automatico.pdf`. + +### E3 · PC central como servidor de RIP +Depende de: configuração atual, custo da licença (é **por PC**), e memória que o +RIP consome. + +--- + +## Bloqueios · o que trava qual tarefa + +| Tarefa | Espera por | De quem | +|---|---|---| +| B3 · pré-flight | os cinco arquivos de exemplo | designers | +| B3 · regras de choke | valor do choke e espessura mínima | designers | +| D5 · meta | meta geral ou por causa? | Marcus | +| E1 · terceiro turno | metros/hora reais | sala | +| E2 · SPOT | resultado do teste | sala | +| E3 · RIP central | config e licença do PC central | Wagner | + +**Nada no bloco A, B1, B2, C e D1 a D4 está bloqueado.** Dá para chegar até o +kanban funcionando sem nenhuma dessas respostas. + +--- + +## Ordem sugerida de trabalho + +``` +semana 1 A1 · A2 · A3 · A4 +semana 2 B1 · B2 +semana 3 B3 · B4 · B5 ← portal no ar, recebendo 24h +semana 4 C1 · C2 ← arquivo caindo na pasta sozinho +semana 5 D1 · D2 +semana 6 D3 · D4 +semana 7 D5 · D6 ← kanban completo +semana 8+ medir · depois E +``` + +**Ao fim da semana 3 a Altus já recebe arte de madrugada e recusa arquivo ruim +automaticamente**, sem nada ter mudado na sala. É o primeiro ganho real. diff --git a/agente/agente.py b/agente/agente.py new file mode 100644 index 0000000..1fb03bf --- /dev/null +++ b/agente/agente.py @@ -0,0 +1,141 @@ +""" +Agente da fábrica — traz a arte aprovada do portal para o servidor local. + +Roda como serviço: + Windows: nssm install DtfAgente "C:\\Python312\\python.exe" "C:\\dtf\\agente.py" + Linux: systemd (ver dtf-agente.service no repositório) + +Duas fontes de trabalho: + - webhook do portal (chega na hora) + - polling a cada 60 s (rede de segurança se o webhook falhar) + +Se a internet cair, o agente para e o portal continua recebendo. +Quando voltar, ele baixa o acumulado. Nada se perde. +""" + +from __future__ import annotations + +import hashlib +import logging +import os +import sqlite3 +import time +from datetime import datetime +from pathlib import Path + +import httpx + +PORTAL = os.environ["BASE_PORTAL"] +TOKEN = os.environ["AGENTE_TOKEN"] +RAIZ = Path(os.environ.get("PASTA_DTF", r"\\servidor\DTF")) +BANCO = Path(os.environ.get("KANBAN_DB", r"C:\dtf\kanban.db")) +INTERVALO = 60 +HEARTBEAT = 300 + +PASTA_ENTRADA = RAIZ / "00_ARTE_RECEBIDA" + +logging.basicConfig( + filename=RAIZ / "_log" / "agente.log", + level=logging.INFO, + format="%(asctime)s %(levelname)s %(message)s", +) +log = logging.getLogger("agente") + + +def sha256(caminho: Path) -> str: + h = hashlib.sha256() + with open(caminho, "rb") as f: + for bloco in iter(lambda: f.read(1 << 20), b""): + h.update(bloco) + return h.hexdigest() + + +def registrar_no_kanban(arte: dict, arquivos: list[Path]) -> None: + """Insere o card. Idempotente: a chave é o arte_id, não o nome do arquivo.""" + con = sqlite3.connect(BANCO) + try: + con.execute(""" + CREATE TABLE IF NOT EXISTS card( + arte_id INTEGER PRIMARY KEY, + pedido TEXT, cliente TEXT, metros REAL, + coluna TEXT DEFAULT 'rec', desde TEXT, + maquina TEXT, partes INTEGER + )""") + con.execute(""" + INSERT OR IGNORE INTO card(arte_id,pedido,cliente,metros,desde,partes) + VALUES (?,?,?,?,?,?)""", + (arte["arte_id"], arte["pedido"], arte["cliente"], + arte["metros"], datetime.now().isoformat(timespec="seconds"), + len(arquivos))) + con.commit() + finally: + con.close() + + +def baixar(cliente: httpx.Client, arte: dict) -> bool: + PASTA_ENTRADA.mkdir(parents=True, exist_ok=True) + salvos: list[Path] = [] + + for parte in arte["partes"]: + destino = PASTA_ENTRADA / f"{arte['pedido']}_{parte['nome']}" + if destino.exists(): + salvos.append(destino) + continue + tmp = destino.with_suffix(".parcial") + with cliente.stream("GET", parte["url"]) as r: + r.raise_for_status() + with open(tmp, "wb") as f: + for bloco in r.iter_bytes(1 << 20): + f.write(bloco) + tmp.rename(destino) # só aparece na pasta quando está completo + salvos.append(destino) + log.info("baixado %s (%s) sha=%s", destino.name, + f"{parte['metros']:.2f} m", sha256(destino)[:12]) + + registrar_no_kanban(arte, salvos) + cliente.post(f"{PORTAL}/api/artes/{arte['arte_id']}/baixada", + headers={"x-token": TOKEN}, timeout=15) + return True + + +def ciclo(cliente: httpx.Client) -> int: + r = cliente.get(f"{PORTAL}/api/artes", headers={"x-token": TOKEN}, timeout=30) + r.raise_for_status() + artes = r.json() + for arte in artes: + try: + baixar(cliente, arte) + except Exception as e: + log.error("falha na arte %s: %s", arte["arte_id"], e) + return len(artes) + + +def main() -> None: + log.info("agente iniciado · portal=%s · pasta=%s", PORTAL, RAIZ) + ultimo_hb = 0.0 + with httpx.Client(follow_redirects=True) as cliente: + while True: + try: + n = ciclo(cliente) + if n: + log.info("%d arte(s) processada(s)", n) + except httpx.HTTPError as e: + # internet caiu: não é erro fatal, o portal segue recebendo + log.warning("sem conexão com o portal: %s", e) + except Exception as e: + log.exception("erro inesperado: %s", e) + + agora = time.time() + if agora - ultimo_hb > HEARTBEAT: + try: + cliente.post(f"{PORTAL}/api/agente/heartbeat", + headers={"x-token": TOKEN}, timeout=10) + ultimo_hb = agora + except Exception: + pass # sem sinal por 15 min, o portal alerta o TI + + time.sleep(INTERVALO) + + +if __name__ == "__main__": + main() diff --git a/agente/dtf-agente.service b/agente/dtf-agente.service new file mode 100644 index 0000000..9dbd3ab --- /dev/null +++ b/agente/dtf-agente.service @@ -0,0 +1,14 @@ +[Unit] +Description=Agente DTF - baixa artes do portal +After=network-online.target + +[Service] +Type=simple +User=dtf +EnvironmentFile=/etc/dtf/.env +ExecStart=/usr/bin/python3 /opt/dtf/agente.py +Restart=always +RestartSec=15 + +[Install] +WantedBy=multi-user.target diff --git a/compose.staging.yaml b/compose.staging.yaml new file mode 100644 index 0000000..cf1ecc2 --- /dev/null +++ b/compose.staging.yaml @@ -0,0 +1,20 @@ +name: dtf-staging-readiness + +# This composition root is only a network-disabled readiness gate. It does not +# deploy the application or connect to R2, Mercado Pago, freight, Tiny/Olist, +# WhatsApp, a production database, or any other external service. +services: + readiness: + build: + context: . + dockerfile: local/Dockerfile + command: python -m local.staging_readiness /config/staging.env + volumes: + - ./staging/staging.env:/config/staging.env:ro + network_mode: none + read_only: true + tmpfs: [/tmp] + init: true + pids_limit: 64 + cap_drop: [ALL] + security_opt: [no-new-privileges:true] diff --git a/compose.yaml b/compose.yaml new file mode 100644 index 0000000..2ce84c6 --- /dev/null +++ b/compose.yaml @@ -0,0 +1,168 @@ +name: ${COMPOSE_PROJECT_NAME:-dtf-cloud} +x-app: &app + build: + context: . + dockerfile: local/Dockerfile + environment: &environment + APP_ENV: ${APP_ENV:-local} + DATABASE_URL: postgresql://${APP_DB_USER:-dtf_app}:${APP_DB_PASSWORD:-local-app-database-only}@db:5432/${POSTGRES_DB:-dtf_local} + S3_ENDPOINT: http://storage:9000 + S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-http://localhost:9000} + S3_BUCKET: ${S3_BUCKET:-dtf-local-artwork} + AWS_ACCESS_KEY_ID: ${S3_APP_USER:-dtf_app} + AWS_SECRET_ACCESS_KEY: ${S3_APP_PASSWORD:-local-app-storage-only} + AWS_DEFAULT_REGION: us-east-1 + OPERATOR_USER: ${OPERATOR_USER:-operator} + OPERATOR_PASSWORD: ${OPERATOR_PASSWORD:-local-operator-only} + PAYMENT_ADAPTER: ${PAYMENT_ADAPTER:-fake} + FREIGHT_ADAPTER: ${FREIGHT_ADAPTER:-fake} + TINY_ADAPTER: ${TINY_ADAPTER:-fake} + WHATSAPP_ADAPTER: ${WHATSAPP_ADAPTER:-fake} + STORAGE_ADAPTER: ${STORAGE_ADAPTER:-s3-local} + MOCK_FREIGHT_CENTS: ${MOCK_FREIGHT_CENTS:-1500} + MAX_UPLOAD_BYTES: ${MAX_UPLOAD_BYTES:-5368709120} + UPLOAD_PART_BYTES: ${UPLOAD_PART_BYTES:-8388608} + STORAGE_QUOTA_BYTES: ${STORAGE_QUOTA_BYTES:-53687091200} + OWNER_UPLOAD_QUOTA_BYTES: ${OWNER_UPLOAD_QUOTA_BYTES:-10737418240} + MAX_PENDING_UPLOADS: ${MAX_PENDING_UPLOADS:-10} + SCAN_MAX_BYTES: ${SCAN_MAX_BYTES:-134217728} + networks: [local] + init: true + security_opt: [no-new-privileges:true] + cap_drop: [ALL] + read_only: true + tmpfs: [/tmp] + pids_limit: 128 + logging: + driver: json-file + options: {max-size: "10m", max-file: "3"} +services: + scanner: + image: clamav/clamav@sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4 + entrypoint: [clamd, --foreground=true, --config-file=/etc/clamav/clamd.conf] + volumes: [./local/clamd.conf:/etc/clamav/clamd.conf:ro] + networks: [local] + mem_limit: 3g + pids_limit: 128 + security_opt: [no-new-privileges:true] + healthcheck: + test: [CMD, clamdscan, --config-file=/etc/clamav/clamd.conf, --ping, "3"] + start_period: 60s + interval: 10s + timeout: 5s + retries: 30 + db-init: + build: + context: . + dockerfile: local/Dockerfile + command: python -m local.bootstrap + environment: + DATABASE_ADMIN_URL: postgresql://${POSTGRES_USER:-dtf_local}:${POSTGRES_PASSWORD:-local-database-only}@db:5432/${POSTGRES_DB:-dtf_local} + APP_DB_USER: ${APP_DB_USER:-dtf_app} + APP_DB_PASSWORD: ${APP_DB_PASSWORD:-local-app-database-only} + networks: [local] + depends_on: + db: {condition: service_healthy} + storage-init: + image: minio/minio:RELEASE.2025-04-22T22-12-26Z + entrypoint: [/bin/sh, /init.sh] + environment: + MINIO_ROOT_USER: ${MINIO_ROOT_USER:-dtf_local} + MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-local-storage-only} + S3_APP_USER: ${S3_APP_USER:-dtf_app} + S3_APP_PASSWORD: ${S3_APP_PASSWORD:-local-app-storage-only} + S3_BUCKET: ${S3_BUCKET:-dtf-local-artwork} + volumes: + - ./local/storage-init.sh:/init.sh:ro + - ./local/storage-policy.json:/policy.json:ro + - ./local/storage-lifecycle.json:/lifecycle.json:ro + networks: [local] + depends_on: + storage: {condition: service_healthy} + db: + image: postgres:17-alpine + environment: + POSTGRES_DB: ${POSTGRES_DB:-dtf_local} + POSTGRES_USER: ${POSTGRES_USER:-dtf_local} + POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-local-database-only} + volumes: [postgres-data:/var/lib/postgresql/data] + networks: [local] + healthcheck: + test: [CMD-SHELL, 'pg_isready -U "$$POSTGRES_USER" -d "$$POSTGRES_DB"'] + interval: 5s + timeout: 3s + retries: 30 + storage: + image: minio/minio:RELEASE.2025-04-22T22-12-26Z + command: server /data --console-address :9001 + environment: + MINIO_ROOT_USER: ${MINIO_ROOT_USER:-dtf_local} + MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-local-storage-only} + ports: ["127.0.0.1:9000:9000", "127.0.0.1:9001:9001"] + volumes: [storage-data:/data] + networks: [local, edge] + healthcheck: + test: [CMD, curl, -f, http://localhost:9000/minio/health/ready] + interval: 5s + timeout: 3s + retries: 30 + api: + <<: *app + command: uvicorn local.app:app --host 0.0.0.0 --port 8000 --no-access-log + depends_on: + db-init: {condition: service_completed_successfully} + storage-init: {condition: service_completed_successfully} + healthcheck: + test: [CMD, python, -c, "import urllib.request; urllib.request.urlopen('http://localhost:8000/health')"] + interval: 5s + timeout: 3s + retries: 30 + worker: + <<: *app + command: python -m local.worker + depends_on: + api: {condition: service_healthy} + scanner: {condition: service_healthy} + healthcheck: + test: [CMD, python, -c, "import urllib.request; urllib.request.urlopen('http://localhost:8002/health')"] + interval: 5s + timeout: 3s + retries: 12 + site: + build: + context: . + dockerfile: local/Dockerfile.web + environment: + S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-http://localhost:9000} + ports: ["127.0.0.1:${SITE_PORT:-8080}:80", "127.0.0.1:${API_PORT:-8000}:81"] + networks: [local, edge] + depends_on: + api: {condition: service_healthy} + healthcheck: + test: [CMD, wget, -q, -O, /dev/null, http://127.0.0.1/health] + interval: 5s + timeout: 3s + retries: 12 + kanban: + build: + context: . + dockerfile: local/Dockerfile.web + environment: + WEB_INDEX: kanban.html + S3_PUBLIC_ENDPOINT: ${S3_PUBLIC_ENDPOINT:-http://localhost:9000} + ports: ["127.0.0.1:${KANBAN_PORT:-8081}:80"] + networks: [local, edge] + depends_on: + api: {condition: service_healthy} + healthcheck: + test: [CMD, wget, -q, -O, /dev/null, http://127.0.0.1/health] + interval: 5s + timeout: 3s + retries: 12 +volumes: + postgres-data: + storage-data: +networks: + local: + internal: true + edge: diff --git a/deploy/Dockerfile.api b/deploy/Dockerfile.api new file mode 100644 index 0000000..8978375 --- /dev/null +++ b/deploy/Dockerfile.api @@ -0,0 +1,18 @@ +# syntax=docker/dockerfile:1 +ARG PYTHON_BASE_IMAGE +FROM ${PYTHON_BASE_IMAGE} + +ARG VCS_REF=unknown +LABEL org.opencontainers.image.title="DTF Portal/API" \ + org.opencontainers.image.revision="$VCS_REF" \ + org.opencontainers.image.source="DTF System repository" + +WORKDIR /app +COPY local/requirements.txt local/requirements.lock /app/local/ +RUN python -m pip install --no-cache-dir --require-hashes -r local/requirements.lock +COPY local /app/local +RUN useradd --uid 10001 --create-home --shell /usr/sbin/nologin dtf +USER 10001:10001 +ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1 PYTHONPATH=/app +EXPOSE 8000 +CMD ["uvicorn", "local.app:app", "--host", "0.0.0.0", "--port", "8000", "--no-access-log"] diff --git a/deploy/Dockerfile.web b/deploy/Dockerfile.web new file mode 100644 index 0000000..f661d2b --- /dev/null +++ b/deploy/Dockerfile.web @@ -0,0 +1,22 @@ +# syntax=docker/dockerfile:1 +ARG PYTHON_BASE_IMAGE +ARG NGINX_BASE_IMAGE +FROM ${PYTHON_BASE_IMAGE} AS policy +WORKDIR /build +COPY dtf-site.html /build/dtf-site.html +COPY local /build/local +COPY deploy /build/deploy +ENV NGINX_TEMPLATE=/build/deploy/nginx.conf.template +RUN python local/compile_web.py + +FROM ${NGINX_BASE_IMAGE} +ARG VCS_REF=unknown +LABEL org.opencontainers.image.title="DTF Site and Kanban" \ + org.opencontainers.image.revision="$VCS_REF" \ + org.opencontainers.image.source="DTF System repository" +ENV WEB_INDEX=index.html PUBLIC_HOST=invalid.example S3_PUBLIC_ENDPOINT=https://invalid.example +COPY --from=policy /build/default.conf.template /etc/nginx/templates/default.conf.template +COPY dtf-site.html /usr/share/nginx/html/index.html +COPY local/static/ /usr/share/nginx/html/ +USER 101:101 +EXPOSE 8080 diff --git a/deploy/PRODUCTION_CHECKLIST.md b/deploy/PRODUCTION_CHECKLIST.md new file mode 100644 index 0000000..f2df6ee --- /dev/null +++ b/deploy/PRODUCTION_CHECKLIST.md @@ -0,0 +1,46 @@ +# Production release checklist + +Every item is required. A checked box records reviewed evidence; it is not a +substitute for `production_preflight.py`, CI, staging acceptance, or change approval. + +## Application and external contracts + +- [ ] `PRODUCTION_INPUTS.md` has owners, decisions, and evidence for every item. +- [ ] Production R2, freight, Mercado Pago, Tiny/Olist, and WhatsApp adapters have + sandbox contract tests and least-privilege credentials. +- [ ] Payment webhook authenticity, replay handling, and idempotency are tested. +- [ ] Docker secret `*_FILE` loading is implemented and tested without logging values. +- [ ] Production account verification/recovery and the length/grade authority flow + are approved. +- [ ] No factory automation or automatic print pre-flight was added by inference. + +## Platform and recovery + +- [ ] DNS/TLS proxy routes and firewall rules are approved; only Site and Kanban + have published web ports. +- [ ] External, versioned Swarm secrets exist and match the configured names. +- [ ] The PostgreSQL volume is encrypted/backed up and pinned to the labeled node. +- [ ] Scheduled offsite database/object backups and an isolated restore rehearsal pass. +- [ ] ClamAV signatures are current and have a controlled update/rebuild process. +- [ ] Central alerts, logs, clocks, capacity, and on-call ownership are verified. + +## Release and deploy + +- [ ] Protected Gitea runner, `main` branch, registry permissions, and variables are reviewed. +- [ ] Base, database, and scanner images use approved immutable digests; application + SHA tags remain pullable and the digest resolved by each deployment is recorded. +- [ ] Full regressions and production preflight pass on the exact release commit. +- [ ] HIGH/CRITICAL Trivy findings are fixed or formally risk-accepted with evidence. +- [ ] Staging acceptance passes with provider sandboxes and production-like topology. +- [ ] Four production approval variables equal `approved` only after their reviews. +- [ ] The generated `docker stack config` contains no secret values or placeholders. +- [ ] Health probes, monitoring, rollback, and a backup restore are observed in staging. +- [ ] The Portainer webhook redeploys the one `dtf-cloud` stack and post-deploy + HTTPS health probes pass. + +## Rollback + +- [ ] Previous application image digests remain pullable. +- [ ] Portainer rollback by full commit `IMAGE_TAG` has been rehearsed; it does + not roll back the database. +- [ ] Database migration forward/restore ownership and maintenance procedure are approved. diff --git a/deploy/README.md b/deploy/README.md new file mode 100644 index 0000000..d7c9f59 --- /dev/null +++ b/deploy/README.md @@ -0,0 +1,16 @@ +# Production deployment files + +The DTF application is one Portainer-owned Docker Swarm stack. Gitea builds, +tests, scans, and publishes the two application images, then calls the stack's +Portainer webhook. Start with the short operator guide in `../PORTAINER.md`. + +- `stack.yaml` — the single Portainer stack. +- `Dockerfile.api` and `Dockerfile.web` — prebuilt registry images. +- `portainer.env.example` — non-secret Portainer variables. +- `production_preflight.py` — fail-closed application/configuration validator. +- `PRODUCTION_CHECKLIST.md` — production evidence checklist. + +The current application remains deliberately blocked from production because +real adapters and Docker-secret file loading are absent and current validation +base images have unresolved HIGH/CRITICAL findings. No real provider or +production service has been configured or contacted. diff --git a/deploy/__init__.py b/deploy/__init__.py new file mode 100644 index 0000000..1c12ec4 --- /dev/null +++ b/deploy/__init__.py @@ -0,0 +1 @@ +"""Production deployment validation package.""" diff --git a/deploy/nginx.conf.template b/deploy/nginx.conf.template new file mode 100644 index 0000000..464cf1b --- /dev/null +++ b/deploy/nginx.conf.template @@ -0,0 +1,31 @@ +limit_req_zone $binary_remote_addr zone=api_limit:10m rate=20r/s; +server { + listen 8080; + server_name ${PUBLIC_HOST}; + if ($host != ${PUBLIC_HOST}) { return 400; } + root /usr/share/nginx/html; + index ${WEB_INDEX}; + + add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; + add_header X-Content-Type-Options nosniff always; + add_header Referrer-Policy no-referrer always; + add_header X-Frame-Options DENY always; + add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always; + add_header Content-Security-Policy "default-src 'self'; script-src 'self' @SCRIPT_HASHES@ https://cdnjs.cloudflare.com; script-src-attr 'none'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob: https://cdn.vnda.com.br; connect-src 'self' ${S3_PUBLIC_ENDPOINT} https://cdn.vnda.com.br https://cdnjs.cloudflare.com; worker-src 'self' blob: https://cdnjs.cloudflare.com; object-src 'none'; base-uri 'none'; frame-ancestors 'none'; form-action 'self'" always; + + location = /health { access_log off; return 200 'ok'; } + location /api/ { + limit_req zone=api_limit burst=100 nodelay; + limit_req_status 429; + proxy_pass http://api:8000; + proxy_http_version 1.1; + proxy_set_header Host $host; + proxy_set_header X-Forwarded-Host $host; + proxy_set_header X-Forwarded-Proto https; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_connect_timeout 5s; + proxy_read_timeout 30s; + client_max_body_size 2m; + } + location / { try_files $uri $uri/ =404; } +} diff --git a/deploy/portainer.env.example b/deploy/portainer.env.example new file mode 100644 index 0000000..ed9e542 --- /dev/null +++ b/deploy/portainer.env.example @@ -0,0 +1,51 @@ +# Non-secret Portainer stack variables. Never put credential values in this file. +PRODUCTION_DEPLOY_ENABLED=TBD +PRODUCTION_INPUTS_APPROVED=TBD +PRODUCTION_SECURITY_REVIEW_APPROVED=TBD +PRODUCTION_RESTORE_REHEARSED=TBD + +API_IMAGE=gitea.blyzer.com.br/blyzer/dtf-api +WEB_IMAGE=gitea.blyzer.com.br/blyzer/dtf-web +IMAGE_TAG=latest +POSTGRES_IMAGE=postgres@sha256:0000000000000000000000000000000000000000000000000000000000000000 +CLAMAV_IMAGE=clamav/clamav@sha256:0000000000000000000000000000000000000000000000000000000000000000 + +PUBLIC_ORIGIN=https://dtf.example.invalid +PUBLIC_HOST=dtf.example.invalid +KANBAN_HOST=kanban-dtf.example.invalid +SITE_PORT=8080 +KANBAN_PORT=8081 + +R2_ENDPOINT=TBD +R2_PUBLIC_ENDPOINT=TBD +R2_BUCKET=TBD + +POSTGRES_DB=dtf +POSTGRES_USER=dtf_admin +APP_DB_USER=dtf_app +POSTGRES_VOLUME=TBD +OPERATOR_USER=TBD + +PAYMENT_ADAPTER=TBD +FREIGHT_ADAPTER=TBD +TINY_ADAPTER=TBD +WHATSAPP_ADAPTER=TBD +STORAGE_QUOTA_BYTES=TBD +OWNER_UPLOAD_QUOTA_BYTES=TBD +MAX_PENDING_UPLOADS=10 +MAX_UPLOAD_BYTES=5368709120 +UPLOAD_PART_BYTES=8388608 +SCAN_MAX_BYTES=134217728 + +# Names of external Portainer/Docker Swarm secrets, never their values. +DATABASE_URL_SECRET=TBD +DATABASE_ADMIN_URL_SECRET=TBD +DB_ADMIN_PASSWORD_SECRET=TBD +APP_DB_PASSWORD_SECRET=TBD +R2_ACCESS_KEY_ID_SECRET=TBD +R2_SECRET_ACCESS_KEY_SECRET=TBD +OPERATOR_PASSWORD_SECRET=TBD +PAYMENT_TOKEN_SECRET=TBD +PAYMENT_WEBHOOK_SECRET=TBD +TINY_TOKEN_SECRET=TBD +WHATSAPP_TOKEN_SECRET=TBD diff --git a/deploy/production_preflight.py b/deploy/production_preflight.py new file mode 100644 index 0000000..8054e74 --- /dev/null +++ b/deploy/production_preflight.py @@ -0,0 +1,159 @@ +"""Fail closed until the application and non-secret production inputs are ready.""" +import os +from pathlib import Path +import re +import sys +from urllib.parse import urlparse + +ROOT = Path(__file__).resolve().parent.parent +APPROVALS = ( + 'PRODUCTION_DEPLOY_ENABLED', + 'PRODUCTION_INPUTS_APPROVED', + 'PRODUCTION_SECURITY_REVIEW_APPROVED', + 'PRODUCTION_RESTORE_REHEARSED', +) +REQUIRED = ( + 'API_IMAGE', 'WEB_IMAGE', 'POSTGRES_IMAGE', 'CLAMAV_IMAGE', + 'IMAGE_TAG', 'PUBLIC_ORIGIN', 'PUBLIC_HOST', 'KANBAN_HOST', + 'SITE_PORT', 'KANBAN_PORT', + 'R2_ENDPOINT', 'R2_PUBLIC_ENDPOINT', 'R2_BUCKET', + 'POSTGRES_DB', 'POSTGRES_USER', 'APP_DB_USER', 'POSTGRES_VOLUME', 'OPERATOR_USER', + 'STORAGE_QUOTA_BYTES', 'OWNER_UPLOAD_QUOTA_BYTES', 'MAX_UPLOAD_BYTES', + 'UPLOAD_PART_BYTES', 'MAX_PENDING_UPLOADS', 'SCAN_MAX_BYTES', + 'PAYMENT_ADAPTER', 'FREIGHT_ADAPTER', 'TINY_ADAPTER', 'WHATSAPP_ADAPTER', + 'DATABASE_URL_SECRET', 'DATABASE_ADMIN_URL_SECRET', + 'DB_ADMIN_PASSWORD_SECRET', 'APP_DB_PASSWORD_SECRET', + 'R2_ACCESS_KEY_ID_SECRET', 'R2_SECRET_ACCESS_KEY_SECRET', + 'OPERATOR_PASSWORD_SECRET', 'PAYMENT_TOKEN_SECRET', + 'PAYMENT_WEBHOOK_SECRET', 'TINY_TOKEN_SECRET', 'WHATSAPP_TOKEN_SECRET', +) +IMMUTABLE_IMAGE = re.compile(r'^[a-z0-9][a-z0-9._:/-]*@sha256:([0-9a-f]{64})$') +IMAGE_REPOSITORY = re.compile( + r'^[a-z0-9][a-z0-9.-]*(?::[0-9]{1,5})?(?:/[a-z0-9][a-z0-9._-]*)+$') +DNS = re.compile(r'^(?=.{1,253}$)(?:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?\.)+[a-z]{2,63}$') +NAME = re.compile(r'^[a-zA-Z0-9][a-zA-Z0-9_.-]{2,127}$') +SOURCE_BLOCKERS = { + 'local/adapters.py': ( + 'This runtime only supports APP_ENV=local', + 'Only local S3 storage is supported', + ), + 'local/app.py': ( + "allowed_hosts=['localhost', '127.0.0.1']", + "'environment': 'local'", + 'payment = FakePayment()', + ), + 'local/worker.py': ( + "adapters = {'tiny': FakeTiny(), 'whatsapp': FakeWhatsApp()}", + ), +} + + +def source_errors(root=ROOT): + errors = [] + for relative, markers in SOURCE_BLOCKERS.items(): + text = (root / relative).read_text() + for marker in markers: + if marker in text: + errors.append(f'{relative} remains local-only: {marker}') + secrets_module = root / 'local' / 'secrets.py' + if not secrets_module.exists() or 'DATABASE_URL_FILE' not in secrets_module.read_text(): + errors.append('local runtime does not load the production Docker secret *_FILE settings') + return errors + + +def config_errors(values): + errors = [] + for name in APPROVALS: + if values.get(name) != 'approved': + errors.append(f'{name} must equal approved') + for name in REQUIRED: + value = values.get(name, '') + if not value or value.lower() in {'tbd', 'todo', 'replace-me', 'unconfirmed'}: + errors.append(f'{name} is missing or unresolved') + for name in ('API_IMAGE', 'WEB_IMAGE'): + if not IMAGE_REPOSITORY.fullmatch(values.get(name, '')): + errors.append(f'{name} must be a lowercase registry repository without a tag') + for name in ('POSTGRES_IMAGE', 'CLAMAV_IMAGE'): + match = IMMUTABLE_IMAGE.fullmatch(values.get(name, '')) + if not match or match.group(1) == '0' * 64: + errors.append(f'{name} must be an immutable non-placeholder digest reference') + image_tag = values.get('IMAGE_TAG', '') + if image_tag != 'latest' and not re.fullmatch(r'(?:[0-9a-f]{40}|[0-9a-f]{64})', image_tag): + errors.append('IMAGE_TAG must be latest or a full commit SHA published by Gitea') + origin = urlparse(values.get('PUBLIC_ORIGIN', '')) + if (origin.scheme != 'https' or not origin.hostname or origin.path not in ('', '/') + or origin.params or origin.query or origin.fragment): + errors.append('PUBLIC_ORIGIN must be an HTTPS origin without a path') + for name in ('PUBLIC_HOST', 'KANBAN_HOST'): + if not DNS.fullmatch(values.get(name, '')): + errors.append(f'{name} must be a valid lowercase DNS hostname') + if origin.hostname and values.get('PUBLIC_HOST') != origin.hostname: + errors.append('PUBLIC_ORIGIN hostname must equal PUBLIC_HOST') + for name in ('R2_ENDPOINT', 'R2_PUBLIC_ENDPOINT'): + endpoint = urlparse(values.get(name, '')) + host = endpoint.hostname or '' + if (endpoint.scheme != 'https' or not host.endswith('.r2.cloudflarestorage.com') + or endpoint.path not in ('', '/') or endpoint.query or endpoint.fragment): + errors.append(f'{name} must be an HTTPS Cloudflare R2 S3 API endpoint') + bucket = values.get('R2_BUCKET', '') + if bucket and not re.fullmatch(r'[a-z0-9][a-z0-9.-]{1,61}[a-z0-9]', bucket): + errors.append('R2_BUCKET must be a valid S3 bucket name') + for name in ('PAYMENT_ADAPTER', 'FREIGHT_ADAPTER', 'TINY_ADAPTER', 'WHATSAPP_ADAPTER'): + if values.get(name, '').lower() in {'', 'fake', 'mock', 'local'}: + errors.append(f'{name} must select an approved non-fake implementation') + for name in REQUIRED: + if name.endswith('_SECRET') and values.get(name) and not NAME.fullmatch(values[name]): + errors.append(f'{name} must name a pre-provisioned external Swarm secret') + secret_names = [values.get(name, '') for name in REQUIRED if name.endswith('_SECRET')] + populated_secret_names = [name for name in secret_names if name] + if len(populated_secret_names) != len(set(populated_secret_names)): + errors.append('Every production secret setting must use a distinct external Swarm secret') + if values.get('POSTGRES_USER') == values.get('APP_DB_USER'): + errors.append('Database administrator and runtime user must differ') + if values.get('PUBLIC_HOST') == values.get('KANBAN_HOST'): + errors.append('Site and Kanban hosts must differ') + numeric = {} + for name in ( + 'STORAGE_QUOTA_BYTES', 'OWNER_UPLOAD_QUOTA_BYTES', 'MAX_UPLOAD_BYTES', + 'UPLOAD_PART_BYTES', 'MAX_PENDING_UPLOADS', 'SCAN_MAX_BYTES'): + try: + numeric[name] = int(values.get(name, '0')) + if numeric[name] <= 0: + raise ValueError + except ValueError: + errors.append(f'{name} must be a positive integer') + if numeric.get('OWNER_UPLOAD_QUOTA_BYTES', 0) > numeric.get('STORAGE_QUOTA_BYTES', 0): + errors.append('OWNER_UPLOAD_QUOTA_BYTES cannot exceed STORAGE_QUOTA_BYTES') + if numeric.get('SCAN_MAX_BYTES', 0) > numeric.get('MAX_UPLOAD_BYTES', 0): + errors.append('SCAN_MAX_BYTES cannot exceed MAX_UPLOAD_BYTES') + ports = {} + for name in ('SITE_PORT', 'KANBAN_PORT'): + try: + ports[name] = int(values.get(name, '0')) + if not 1024 <= ports[name] <= 65535: + raise ValueError + except ValueError: + errors.append(f'{name} must be an unprivileged TCP port from 1024 to 65535') + if ports.get('SITE_PORT') == ports.get('KANBAN_PORT'): + errors.append('SITE_PORT and KANBAN_PORT must differ') + return errors + + +def main(source_only=False): + errors = source_errors() + if not source_only: + errors.extend(config_errors(os.environ)) + if errors: + print('BLOCKED: production preflight failed:') + for error in errors: + print(f'- {error}') + return 2 + print('PASS: production source and non-secret deployment metadata passed preflight.') + print('This does not replace staging acceptance, image scanning, or human approval.') + return 0 + + +if __name__ == '__main__': + if len(sys.argv) > 2 or (len(sys.argv) == 2 and sys.argv[1] != '--source-only'): + raise SystemExit('usage: python deploy/production_preflight.py [--source-only]') + raise SystemExit(main(len(sys.argv) == 2)) diff --git a/deploy/stack.yaml b/deploy/stack.yaml new file mode 100644 index 0000000..0748867 --- /dev/null +++ b/deploy/stack.yaml @@ -0,0 +1,309 @@ +version: "3.8" + +x-app-environment: &app-environment + APP_ENV: production + DATABASE_URL_FILE: /run/secrets/database_url + S3_ENDPOINT: ${R2_ENDPOINT:?set R2_ENDPOINT} + S3_PUBLIC_ENDPOINT: ${R2_PUBLIC_ENDPOINT:?set R2_PUBLIC_ENDPOINT} + S3_BUCKET: ${R2_BUCKET:?set R2_BUCKET} + AWS_ACCESS_KEY_ID_FILE: /run/secrets/r2_access_key_id + AWS_SECRET_ACCESS_KEY_FILE: /run/secrets/r2_secret_access_key + AWS_DEFAULT_REGION: auto + OPERATOR_USER: ${OPERATOR_USER:?set OPERATOR_USER} + OPERATOR_PASSWORD_FILE: /run/secrets/operator_password + PAYMENT_ADAPTER: ${PAYMENT_ADAPTER:?set PAYMENT_ADAPTER} + FREIGHT_ADAPTER: ${FREIGHT_ADAPTER:?set FREIGHT_ADAPTER} + TINY_ADAPTER: ${TINY_ADAPTER:?set TINY_ADAPTER} + WHATSAPP_ADAPTER: ${WHATSAPP_ADAPTER:?set WHATSAPP_ADAPTER} + STORAGE_ADAPTER: s3-r2 + PAYMENT_TOKEN_FILE: /run/secrets/payment_token + PAYMENT_WEBHOOK_SECRET_FILE: /run/secrets/payment_webhook_secret + TINY_TOKEN_FILE: /run/secrets/tiny_token + WHATSAPP_TOKEN_FILE: /run/secrets/whatsapp_token + PUBLIC_ORIGIN: ${PUBLIC_ORIGIN:?set PUBLIC_ORIGIN} + PUBLIC_HOST: ${PUBLIC_HOST:?set PUBLIC_HOST} + ALLOWED_HOSTS: ${PUBLIC_HOST:?set PUBLIC_HOST},${KANBAN_HOST:?set KANBAN_HOST} + ALLOWED_ORIGINS: ${PUBLIC_ORIGIN:?set PUBLIC_ORIGIN},https://${KANBAN_HOST:?set KANBAN_HOST} + COOKIE_SECURE: "true" + MAX_UPLOAD_BYTES: ${MAX_UPLOAD_BYTES:-5368709120} + UPLOAD_PART_BYTES: ${UPLOAD_PART_BYTES:-8388608} + STORAGE_QUOTA_BYTES: ${STORAGE_QUOTA_BYTES:?set STORAGE_QUOTA_BYTES} + OWNER_UPLOAD_QUOTA_BYTES: ${OWNER_UPLOAD_QUOTA_BYTES:?set OWNER_UPLOAD_QUOTA_BYTES} + MAX_PENDING_UPLOADS: ${MAX_PENDING_UPLOADS:-10} + SCAN_MAX_BYTES: ${SCAN_MAX_BYTES:-134217728} + +x-app-secrets: &app-secrets + - database_url + - r2_access_key_id + - r2_secret_access_key + - operator_password + - payment_token + - payment_webhook_secret + - tiny_token + - whatsapp_token + +x-rolling: &rolling + update_config: + parallelism: 1 + delay: 10s + order: start-first + failure_action: rollback + monitor: 45s + rollback_config: + parallelism: 1 + delay: 5s + order: start-first + failure_action: pause + monitor: 45s + restart_policy: + condition: on-failure + delay: 5s + max_attempts: 5 + window: 60s + +services: + db: + image: ${POSTGRES_IMAGE:?set POSTGRES_IMAGE} + environment: + POSTGRES_DB: ${POSTGRES_DB:?set POSTGRES_DB} + POSTGRES_USER: ${POSTGRES_USER:?set POSTGRES_USER} + POSTGRES_PASSWORD_FILE: /run/secrets/db_admin_password + secrets: [db_admin_password] + volumes: + - postgres-data:/var/lib/postgresql/data + networks: [backend] + healthcheck: + test: [CMD-SHELL, 'pg_isready -U "$$POSTGRES_USER" -d "$$POSTGRES_DB"'] + interval: 10s + timeout: 5s + retries: 12 + start_period: 20s + stop_grace_period: 60s + deploy: + replicas: 1 + placement: + constraints: [node.labels.dtf_database == true] + update_config: + parallelism: 1 + order: stop-first + failure_action: rollback + monitor: 60s + rollback_config: + parallelism: 1 + order: stop-first + failure_action: pause + monitor: 60s + restart_policy: + condition: on-failure + delay: 10s + max_attempts: 5 + window: 120s + resources: + limits: {cpus: "2.0", memory: 4G} + reservations: {cpus: "0.5", memory: 1G} + + db-init: + image: ${API_IMAGE:?set API_IMAGE}:${IMAGE_TAG:-latest} + command: python -m local.bootstrap + environment: + APP_ENV: production + DATABASE_ADMIN_URL_FILE: /run/secrets/database_admin_url + APP_DB_USER: ${APP_DB_USER:?set APP_DB_USER} + APP_DB_PASSWORD_FILE: /run/secrets/app_db_password + secrets: [database_admin_url, app_db_password] + networks: [backend] + deploy: + replicas: 1 + restart_policy: {condition: none} + placement: + constraints: [node.platform.os == linux] + resources: + limits: {cpus: "0.5", memory: 512M} + + scanner: + image: ${CLAMAV_IMAGE:?set CLAMAV_IMAGE} + user: "100:101" + entrypoint: [clamd, --foreground=true, --config-file=/etc/clamav/clamd.conf] + configs: + - source: clamd_config + target: /etc/clamav/clamd.conf + mode: 0444 + networks: [backend] + read_only: true + cap_drop: [ALL] + security_opt: [no-new-privileges:true] + tmpfs: + - /tmp:uid=100,gid=101,mode=0750 + - /run/clamav:uid=100,gid=101,mode=0750 + - /var/log/clamav:uid=100,gid=101,mode=0750 + healthcheck: + test: [CMD, clamdscan, --config-file=/etc/clamav/clamd.conf, --ping, "3"] + interval: 15s + timeout: 5s + retries: 20 + start_period: 90s + deploy: + replicas: 1 + restart_policy: {condition: on-failure, delay: 10s} + resources: + limits: {cpus: "2.0", memory: 3G} + reservations: {cpus: "0.5", memory: 1G} + + api: + image: ${API_IMAGE:?set API_IMAGE}:${IMAGE_TAG:-latest} + environment: *app-environment + secrets: *app-secrets + networks: [backend, egress] + read_only: true + tmpfs: [/tmp] + init: true + cap_drop: [ALL] + security_opt: [no-new-privileges:true] + healthcheck: + test: + - CMD-SHELL + - >- + python -c "import os,urllib.request; r=urllib.request.Request('http://localhost:8000/health',headers={'Host':os.environ['PUBLIC_HOST']}); urllib.request.urlopen(r,timeout=3)" + interval: 10s + timeout: 5s + retries: 12 + start_period: 30s + stop_grace_period: 30s + deploy: + <<: *rolling + replicas: 2 + resources: + limits: {cpus: "1.0", memory: 1G} + reservations: {cpus: "0.25", memory: 256M} + + worker: + image: ${API_IMAGE:?set API_IMAGE}:${IMAGE_TAG:-latest} + command: python -m local.worker + environment: + <<: *app-environment + CLAMD_HOST: scanner + secrets: *app-secrets + networks: [backend, egress] + read_only: true + tmpfs: [/tmp] + init: true + cap_drop: [ALL] + security_opt: [no-new-privileges:true] + healthcheck: + test: [CMD, python, -c, "import urllib.request; urllib.request.urlopen('http://localhost:8002/health',timeout=3)"] + interval: 15s + timeout: 5s + retries: 12 + start_period: 90s + stop_grace_period: 60s + deploy: + <<: *rolling + replicas: 1 + update_config: + parallelism: 1 + order: stop-first + failure_action: rollback + monitor: 60s + rollback_config: + parallelism: 1 + order: stop-first + failure_action: pause + monitor: 60s + resources: + limits: {cpus: "1.5", memory: 2G} + reservations: {cpus: "0.25", memory: 512M} + + site: + image: ${WEB_IMAGE:?set WEB_IMAGE}:${IMAGE_TAG:-latest} + environment: + WEB_INDEX: index.html + PUBLIC_HOST: ${PUBLIC_HOST:?set PUBLIC_HOST} + S3_PUBLIC_ENDPOINT: ${R2_PUBLIC_ENDPOINT:?set R2_PUBLIC_ENDPOINT} + networks: [backend] + ports: + - target: 8080 + published: ${SITE_PORT:-8080} + protocol: tcp + mode: ingress + read_only: true + tmpfs: + - /tmp:uid=101,gid=101,mode=0750 + - /var/cache/nginx:uid=101,gid=101,mode=0750 + - /var/run:uid=101,gid=101,mode=0750 + - /etc/nginx/conf.d:uid=101,gid=101,mode=0750 + cap_drop: [ALL] + security_opt: [no-new-privileges:true] + healthcheck: + test: [CMD-SHELL, 'wget -q --header="Host: $$PUBLIC_HOST" -O /dev/null http://127.0.0.1:8080/health'] + interval: 10s + timeout: 5s + retries: 12 + start_period: 15s + deploy: + <<: *rolling + replicas: 2 + resources: + limits: {cpus: "0.5", memory: 256M} + reservations: {cpus: "0.1", memory: 64M} + + kanban: + image: ${WEB_IMAGE:?set WEB_IMAGE}:${IMAGE_TAG:-latest} + environment: + WEB_INDEX: kanban.html + PUBLIC_HOST: ${KANBAN_HOST:?set KANBAN_HOST} + S3_PUBLIC_ENDPOINT: ${R2_PUBLIC_ENDPOINT:?set R2_PUBLIC_ENDPOINT} + networks: [backend] + ports: + - target: 8080 + published: ${KANBAN_PORT:-8081} + protocol: tcp + mode: ingress + read_only: true + tmpfs: + - /tmp:uid=101,gid=101,mode=0750 + - /var/cache/nginx:uid=101,gid=101,mode=0750 + - /var/run:uid=101,gid=101,mode=0750 + - /etc/nginx/conf.d:uid=101,gid=101,mode=0750 + cap_drop: [ALL] + security_opt: [no-new-privileges:true] + healthcheck: + test: [CMD-SHELL, 'wget -q --header="Host: $$PUBLIC_HOST" -O /dev/null http://127.0.0.1:8080/health'] + interval: 10s + timeout: 5s + retries: 12 + start_period: 15s + deploy: + <<: *rolling + replicas: 1 + resources: + limits: {cpus: "0.5", memory: 256M} + reservations: {cpus: "0.1", memory: 64M} + +configs: + clamd_config: + file: ../local/clamd.conf + +secrets: + database_url: {external: true, name: "${DATABASE_URL_SECRET:?set DATABASE_URL_SECRET}"} + database_admin_url: {external: true, name: "${DATABASE_ADMIN_URL_SECRET:?set DATABASE_ADMIN_URL_SECRET}"} + db_admin_password: {external: true, name: "${DB_ADMIN_PASSWORD_SECRET:?set DB_ADMIN_PASSWORD_SECRET}"} + app_db_password: {external: true, name: "${APP_DB_PASSWORD_SECRET:?set APP_DB_PASSWORD_SECRET}"} + r2_access_key_id: {external: true, name: "${R2_ACCESS_KEY_ID_SECRET:?set R2_ACCESS_KEY_ID_SECRET}"} + r2_secret_access_key: {external: true, name: "${R2_SECRET_ACCESS_KEY_SECRET:?set R2_SECRET_ACCESS_KEY_SECRET}"} + operator_password: {external: true, name: "${OPERATOR_PASSWORD_SECRET:?set OPERATOR_PASSWORD_SECRET}"} + payment_token: {external: true, name: "${PAYMENT_TOKEN_SECRET:?set PAYMENT_TOKEN_SECRET}"} + payment_webhook_secret: {external: true, name: "${PAYMENT_WEBHOOK_SECRET:?set PAYMENT_WEBHOOK_SECRET}"} + tiny_token: {external: true, name: "${TINY_TOKEN_SECRET:?set TINY_TOKEN_SECRET}"} + whatsapp_token: {external: true, name: "${WHATSAPP_TOKEN_SECRET:?set WHATSAPP_TOKEN_SECRET}"} + +volumes: + postgres-data: + external: true + name: ${POSTGRES_VOLUME:?set POSTGRES_VOLUME} + +networks: + backend: + driver: overlay + internal: true + egress: + driver: overlay diff --git a/deploy/test_production_preflight.py b/deploy/test_production_preflight.py new file mode 100644 index 0000000..077b170 --- /dev/null +++ b/deploy/test_production_preflight.py @@ -0,0 +1,98 @@ +import unittest + +from .production_preflight import config_errors, source_errors + + +def valid_config(): + digest = '1' * 64 + values = { + 'PRODUCTION_DEPLOY_ENABLED': 'approved', + 'PRODUCTION_INPUTS_APPROVED': 'approved', + 'PRODUCTION_SECURITY_REVIEW_APPROVED': 'approved', + 'PRODUCTION_RESTORE_REHEARSED': 'approved', + 'API_IMAGE': 'registry.example.com/dropstar/dtf-api', + 'WEB_IMAGE': 'registry.example.com/dropstar/dtf-web', + 'IMAGE_TAG': 'latest', + 'POSTGRES_IMAGE': f'postgres@sha256:{digest}', + 'CLAMAV_IMAGE': f'clamav/clamav@sha256:{digest}', + 'PUBLIC_ORIGIN': 'https://dtf.example.com', + 'PUBLIC_HOST': 'dtf.example.com', + 'KANBAN_HOST': 'kanban-dtf.example.com', + 'SITE_PORT': '8080', + 'KANBAN_PORT': '8081', + 'R2_ENDPOINT': 'https://account.r2.cloudflarestorage.com', + 'R2_PUBLIC_ENDPOINT': 'https://account.r2.cloudflarestorage.com', + 'R2_BUCKET': 'dtf-production-artwork', + 'POSTGRES_DB': 'dtf', + 'POSTGRES_USER': 'dtf_admin', + 'APP_DB_USER': 'dtf_app', + 'POSTGRES_VOLUME': 'dtf-postgres-data', + 'OPERATOR_USER': 'dtf-operator', + 'STORAGE_QUOTA_BYTES': '53687091200', + 'OWNER_UPLOAD_QUOTA_BYTES': '10737418240', + 'MAX_UPLOAD_BYTES': '5368709120', + 'UPLOAD_PART_BYTES': '8388608', + 'MAX_PENDING_UPLOADS': '10', + 'SCAN_MAX_BYTES': '134217728', + 'PAYMENT_ADAPTER': 'mercado-pago', + 'FREIGHT_ADAPTER': 'approved-freight', + 'TINY_ADAPTER': 'tiny-olist', + 'WHATSAPP_ADAPTER': 'approved-whatsapp', + } + for name in ( + 'DATABASE_URL_SECRET', 'DATABASE_ADMIN_URL_SECRET', + 'DB_ADMIN_PASSWORD_SECRET', 'APP_DB_PASSWORD_SECRET', + 'R2_ACCESS_KEY_ID_SECRET', 'R2_SECRET_ACCESS_KEY_SECRET', + 'OPERATOR_PASSWORD_SECRET', 'PAYMENT_TOKEN_SECRET', + 'PAYMENT_WEBHOOK_SECRET', 'TINY_TOKEN_SECRET', 'WHATSAPP_TOKEN_SECRET', + ): + values[name] = 'dtf_prod_' + name.lower() + return values + + +class ProductionPreflightTests(unittest.TestCase): + def test_structurally_complete_metadata_passes(self): + self.assertEqual(config_errors(valid_config()), []) + + def test_mutable_images_and_fake_adapters_fail(self): + values = valid_config() + values['API_IMAGE'] = 'registry.example.com/dropstar/dtf-api:latest' + values['PAYMENT_ADAPTER'] = 'fake' + errors = config_errors(values) + self.assertTrue(any('API_IMAGE' in error for error in errors)) + self.assertTrue(any('PAYMENT_ADAPTER' in error for error in errors)) + + def test_image_tag_and_public_ports_are_validated(self): + values = valid_config() + values['IMAGE_TAG'] = 'main' + values['KANBAN_PORT'] = values['SITE_PORT'] + errors = config_errors(values) + self.assertTrue(any('IMAGE_TAG' in error for error in errors)) + self.assertTrue(any('must differ' in error for error in errors)) + + def test_approval_and_secret_name_are_enforced(self): + values = valid_config() + values['PRODUCTION_DEPLOY_ENABLED'] = 'yes' + values['DATABASE_URL_SECRET'] = '../unsafe' + errors = config_errors(values) + self.assertTrue(any('PRODUCTION_DEPLOY_ENABLED' in error for error in errors)) + self.assertTrue(any('DATABASE_URL_SECRET' in error for error in errors)) + + def test_current_application_is_explicitly_blocked(self): + errors = source_errors() + self.assertTrue(any('local/adapters.py remains local-only' in error for error in errors)) + self.assertTrue(any('local/app.py remains local-only' in error for error in errors)) + + def test_secret_reuse_and_incoherent_limits_are_rejected(self): + values = valid_config() + values['PAYMENT_TOKEN_SECRET'] = values['TINY_TOKEN_SECRET'] + values['OWNER_UPLOAD_QUOTA_BYTES'] = str(int(values['STORAGE_QUOTA_BYTES']) + 1) + values['SCAN_MAX_BYTES'] = str(int(values['MAX_UPLOAD_BYTES']) + 1) + errors = config_errors(values) + self.assertTrue(any('distinct external Swarm secret' in error for error in errors)) + self.assertIn('OWNER_UPLOAD_QUOTA_BYTES cannot exceed STORAGE_QUOTA_BYTES', errors) + self.assertIn('SCAN_MAX_BYTES cannot exceed MAX_UPLOAD_BYTES', errors) + + +if __name__ == '__main__': + unittest.main() diff --git a/dtf-organograma-sistema.pdf b/dtf-organograma-sistema.pdf new file mode 100644 index 0000000..7a28440 Binary files /dev/null and b/dtf-organograma-sistema.pdf differ diff --git a/dtf-organograma-ti.html b/dtf-organograma-ti.html new file mode 100644 index 0000000..da5b2c8 --- /dev/null +++ b/dtf-organograma-ti.html @@ -0,0 +1,205 @@ + + + + + +DTF — arquitetura para o TI + + + + + + +
+
+
+
Documento técnico · Wagner · agosto 2026
+

Arquitetura do DTF 24h
três zonas, oito componentes

+

Clique em qualquer caixa para ver o que ela faz, em que linguagem, o que acontece se cair e o que ainda depende de resposta. O código completo está em dtf-sistema.zip.

+
+ +
+ + + + + + Terceiros + + Nuvem · VPS + storage + + Fábrica · rede interna + + webhook + + + HTTPS + + + + marcador + WhatsApp + + + Tiny · Olistpedido nasce aqui + + WhatsApp API + + + Portal · FastAPItoken, link, pré-assinada + + Robô · pyvipsvalida, repete, fatia, carimba + + PostgreSQL + + Storage S3 + + + Agentebaixa e grava na pasta + + Pastas do servidor00 … 60 · espelho + + Kanban · FastAPISQLite · fonte de verdade + +
+ +
+

Setas do teclado navegam entre os componentes.

+
+ + + + diff --git a/dtf-site.html b/dtf-site.html new file mode 100644 index 0000000..0bea17d --- /dev/null +++ b/dtf-site.html @@ -0,0 +1,2819 @@ + + + + + +DTF Dropstar · mande sua arte e veja a qualidade + + + + + + + +
+ ENVIE SEU ARQUIVO DTF PELO SITE · DTF TÊXTIL COM O MENOR PREÇO DO METRO EM FRANCA-SP +
+ +
+ +
+ ⌕ + +
+ +
+ + + +
+ + +
+
+
+
+ Metro a partir de R$ 14,90 + Revisão inclusa + Franca · SP +
+

A gente encaixa sua folha
e você paga menos metro

+

Mande a arte, veja a nota em segundos e a folha montada antes de fechar. + Revisão e remanejamento por nossa conta.

+
+ Enviar minha arte + sem cadastro · resposta em segundos +
+
+ + +
+ +
+ ◆ Revisão de 5 pontos sem custo + ◆ Cobrança por proporção, a cada 10 cm + ◆ Filme de 57 cm, o dobro do padrão + ◆ Prévia da folha antes de pagar +
+
+
+ + + +
+
Quanto melhor sua arte,
menor o preço do metro
+ Têxtil de R$ 19,90 a R$ 14,90 · UV de R$ 99,90 a R$ 69,90. + A nota aparece na tela antes de você pagar.
+
Filme de 57 cm,
o dobro do padrão
+ Cabe o dobro de arte por metro. E reencaixamos sua folha sem cobrar.
+
Você paga só
o que usa
+ Cobrança a cada 10 cm. Folha de 2,75 m custa 2,80 — não 3.
+
Erro pego
antes de imprimir
+ 5 pontos conferidos e a nota na tela. Sem custo.
+
Envio em
até 24 horas
+ E avisamos por WhatsApp a cada etapa do pedido.
+
+ + +
+ + +
+
Comece por aqui
+

Qual é o seu caso?

+
+ + + + + + + +
+
+ + +
+ +
+
+
+

—

+ +

+
+
+
+
+ +
+ + +
+
+
↑
+ Arraste aqui + ou escolher no computador +
+ +
+ + +
+
+ +
+
+
+
+ +
+
+ + +
+
+

sua folha

+
+
—
+ qualidade
+
+
+
+
+

Ressalva de resolução

+
+ +
+
+ +
+ +
+ + + + + +
+ +
+

Seu pedido

+ +
+

Itens

+
+
+
Item que você está montando
+
+
+
+ +
+

Seus dados

+

A conta nasce aqui, no pagamento. O CNPJ é o mesmo da nota fiscal, + e é por ele que suas artes ficam guardadas para o próximo pedido.

+
+
+ +
+
+ +
+
+ +
+
+
+ +
+

Forma de entrega

+
+ + +
+ +
+ + +
+

+
+

+
+
+
+ + + +
+
+ + +
+
Como funciona
+

Tudo o que você precisa saber, em cinco cartões

+ +
+
+ +
+
+
Preço

Arte melhor,
metro mais barato

+
−25%no metro
+
+

Vale nos quatro produtos. Preço da folha que você monta:

+ + + + + + + +
notatêxtilUV
90–100R$ 14,90R$ 69,90
75–89R$ 16,20R$ 73,90
60–74R$ 17,50R$ 77,90
40–59R$ 18,70R$ 81,90
abaixo de 40R$ 19,90R$ 85,90
+
Se a montagem for nossa, some R$ 10,00 no têxtil e + R$ 14,00 no UV — mesma escada, em qualquer faixa
+
+ +
+
+
Largura

O dobro do
filme padrão

+
57cmde filme
+
+

A maioria trabalha com 28,5 cm. Na nossa largura cabe o dobro de arte + por metro corrido — e o metro sai mais barato por peça.

+
    +
  • Duas artes de 28 cm lado a lado
  • +
  • Menos emenda, menos corte
  • +
  • DTF UV também disponível, em 28,5 cm
  • +
+
+ +
+
+
Encaixe

Reencaixamos
sua folha de graça

+
grátisreencaixe
+
+

Se a sua montagem deixa espaço sobrando, refazemos o encaixe com o mesmo + motor que usamos nas nossas montagens.

+
    +
  • Artes que se tocam, separadas com 5 mm
  • +
  • Giramos as peças para aproveitar a largura
  • +
  • A folha encolhe e a sua conta diminui
  • +
+
Refazemos o encaixe antes de imprimir, sem cobrar nada
+
+ +
+
+
Cobrança

Você paga
o que usa

+
10cmde cada vez
+
+

Arredondamos a cada 10 cm. Uma folha de 2,75 m custa 2,80 m — quem cobra + metro cheio cobraria 3.

+
    +
  • Pedido mínimo de 1 metro
  • +
  • A identificação do pedido é por nossa conta
  • +
  • Sem taxa de arquivo, sem taxa de revisão
  • +
+
+ +
+
+
Sem burocracia

Conta só na
hora de pagar

+
0conta e senha
+
+

Sobe a arte e vê o preço sem conta nenhuma. A conta nasce no pagamento, junto com o CNPJ da nota — e o próximo pedido já vem com suas artes anteriores. A revisão de 5 pontos vem junto — + há quem cobre R$ 19,90 por pedido só por isso.

+
    +
  • Sem cadastro para subir e ver o preço
  • +
  • Envio em até 24 horas
  • +
  • WhatsApp a cada etapa do pedido
  • +
  • Arquivo guardado 90 dias · histórico 12 meses
  • +
+
+ +
+ +
+
+ + + + + + + + + + + diff --git a/kanban/main.py b/kanban/main.py new file mode 100644 index 0000000..a8da5e8 --- /dev/null +++ b/kanban/main.py @@ -0,0 +1,557 @@ +""" +Kanban da sala de DTF — roda no servidor da fábrica, rede interna. + +Princípio: o KANBAN é a única interface. O operador move o card aqui e as +pastas do servidor seguem sozinhas — ninguém abre o Explorer. +Decidido em 30/08/2026: não existe watchdog de pastas. Movimento feito fora do +kanban não é suportado. + +A fila é sempre por HORÁRIO DE CHEGADA: quem chegou primeiro fica em cima. +Mover o card grava o movimento, move o arquivo, enfileira o marcador no Tiny +e o WhatsApp ao cliente. Ninguém abre o Tiny para atualizar nada. + +O log de movimentos é gravado SEMPRE, mesmo se o Tiny estiver fora do ar. +A medição de tempo por etapa nunca depende de API de terceiro. + +Rodar: + uvicorn main:app --host 0.0.0.0 --port 8080 +""" + +from __future__ import annotations + +import json +import os +import shutil +import sqlite3 +import threading +import time +from datetime import datetime, timedelta +from pathlib import Path + +from fastapi import FastAPI, HTTPException +from fastapi.responses import FileResponse, RedirectResponse +from pydantic import BaseModel + +import tiny +import whats + +BANCO = Path(os.environ.get("KANBAN_DB", r"C:\dtf\kanban.db")) +RAIZ = Path(os.environ.get("PASTA_DTF", r"\\servidor\DTF")) + +# O KANBAN é a fonte de verdade da operação. O marcador no Tiny existe só para +# quem NÃO abre o kanban: comercial atendendo cliente no telefone, expedição +# conferindo se o DTF saiu, e o Marcus olhando pelo celular fora da fábrica. +# +# Por isso o Tiny recebe o estágio grosso, não o detalhe fino: +# está sendo feito · travou · ficou pronto +# +# Três chamadas por pedido em vez de sete. A 213 pedidos/dia, são 640 requisições +# em vez de 1.500 — folga no limite da API e menos job para o TI monitorar. +COLUNAS = [ + ("aut", "Aguardando autorização", "05_AUTORIZACAO", None, False), # só retrabalho + ("rec", "Arte recebida", "00_ARTE_RECEBIDA", None, False), + ("tra", "Arte tratada", "10_ARTE_TRATADA", None, False), + ("apc", "Aprovação de cor", "15_APROVACAO_COR", "DTF-PROVA-COR",False), + ("fil", "Fila de impressão", "20_FILA_IMPRESSAO", None, False), + ("imp", "Imprimindo", "30_IMPRIMINDO", "DTF-PRODUCAO", False), + ("cor", "Correção", "40_CORRECAO", "CORRECAO DTF", False), + ("fin", "Finalizado", "60_FINALIZADO", "DTF-PRONTO", False), +] +# A sala só IMPRIME o filme — quem aplica na peça é o cliente. +# Por isso não existe coluna de aplicação nem causa de retrabalho por aplicação. +IDS = [c[0] for c in COLUNAS] +INFO = {c[0]: c for c in COLUNAS} +AVISA_CLIENTE = {"apc": "prova_cor", "imp": "producao", + "cor": "correcao", "fin": "concluido"} + +app = FastAPI(title="Kanban DTF") + +# --------------------------------------------------------------------------- +# Distribuição entre as máquinas — POR PUXADA, não por empurro +# --------------------------------------------------------------------------- +# O sistema NÃO decide qual máquina roda qual pedido. A fila é única, por +# horário de chegada, e a máquina que termina puxa o próximo. +# +# Empurrar exigiria adivinhar qual máquina estará livre daqui a duas horas. Se +# uma travar, a fila dela para enquanto outra fica ociosa, e alguém remaneja na +# mão. Por puxada nunca desbalanceia. +# +# Para o operador: um botão "puxar próximo". O arquivo já vem com o spot pronto +# do robô — ele só abre no Flexi e roda. +# Ajustado em 02/09/2026 pelo Thales e Alexandre: +# "reserva de 15 min é demais, no máx 3 min" +# "pedido por vez" — não puxar lote de trabalho +RESERVA_MIN = 3 # sem entrar em Imprimindo nesse prazo, volta para a fila +PUXAR_ATE_MIN = 0 # 0 = um pedido por vez, como a sala pediu + + +class Puxar(BaseModel): + maquina: int + usuario: str + minutos: int = PUXAR_ATE_MIN + + +@app.post("/api/puxar") +def puxar(p: Puxar): + """ + A máquina puxa o próximo da fila. Reserva por 15 min e move o arquivo para + a hot folder daquela máquina — o FlexiPRINT processa sozinho de lá. + """ + agora = datetime.now() + limite = (agora - timedelta(minutes=RESERVA_MIN)).isoformat(timespec="seconds") + pegos, minutos = [], 0 + + with con() as c: + # solta reservas vencidas antes de distribuir + c.execute("UPDATE card SET reservado_por=NULL, reservado_em=NULL " + "WHERE reservado_em IS NOT NULL AND reservado_em < ?", (limite,)) + + fila = c.execute( + "SELECT * FROM card WHERE coluna='fil' AND reservado_por IS NULL " + "ORDER BY desde").fetchall() # sempre por horário de chegada + + for card in fila: + # estimativa de máquina: o campo do card manda; sem ele, calcula pelos metros + mm = card["minutos_maquina"] or round(card["metros"] / 20 * 60) + if pegos: # um pedido por vez + break + c.execute("UPDATE card SET reservado_por=?, reservado_em=?, maquina=? " + "WHERE arte_id=?", + (f"Maq {p.maquina}", agora.isoformat(timespec="seconds"), + f"Maq {p.maquina}", card["arte_id"])) + mover_arquivos(card["pedido"], "20_FILA_IMPRESSAO", f"30_MAQ{p.maquina}") + pegos.append({"pedido": card["pedido"], "metros": card["metros"], + "minutos": mm}) + minutos += mm + + return {"maquina": f"Maq {p.maquina}", "pedidos": pegos, + "minutos_total": minutos, + "reserva_expira_em": RESERVA_MIN} + + +@app.post("/api/devolver") +def devolver(arte_id: int, usuario: str): + """ + Máquina travou no meio. O pedido volta ao TOPO da fila, não ao fim — + ele já esperou uma vez. + """ + with con() as c: + card = c.execute("SELECT * FROM card WHERE arte_id=?", (arte_id,)).fetchone() + if not card: + raise HTTPException(404) + maq = (card["maquina"] or "Maq 1").replace("Maq ", "") + mover_arquivos(card["pedido"], f"30_MAQ{maq}", "20_FILA_IMPRESSAO") + # desde antigo = volta para o topo da ordem por horário de chegada + c.execute("UPDATE card SET coluna='fil', reservado_por=NULL, " + "reservado_em=NULL, maquina=NULL WHERE arte_id=?", (arte_id,)) + c.execute("""INSERT INTO movimento + (arte_id,pedido,de,para,entrou_em,saiu_em,segundos,usuario,maquina) + VALUES (?,?,?,?,?,?,?,?,?)""", + (arte_id, card["pedido"], "imp", "fil", card["desde"], + datetime.now().isoformat(timespec="seconds"), 0, usuario, card["maquina"])) + return {"ok": True, "voltou_ao_topo": True} + + +# --------------------------------------------------------------------------- +# Aprovação de cor — evita o retrabalho em vez de repor depois +# --------------------------------------------------------------------------- +# Imprime uma amostra pequena, fotografa e manda ao cliente. Ele aprova, e só +# então o pedido vai para a fila. Custa centímetros de filme e evita metros. +# +# Dispara sozinho em três situações: +PROVA_METROS = 10.0 # arquivo grande: erro de cor custa caro +PROVA_CLIENTE_NOVO = True # primeiro pedido do cliente +# cores fora do gamut CMYK, que quase nunca saem como o cliente vê na tela +PROVA_CORES_TENSAS = { + "vermelho_saturado", "laranja", "verde_vivo", "azul_royal", + "roxo", "tom_de_pele", "cinza_neutro", +} + + +def precisa_prova_cor(metros: float, cliente_novo: bool, + cores_detectadas: set[str]) -> tuple[bool, str]: + if metros >= PROVA_METROS: + return True, f"arquivo de {metros:.1f} m" + if cliente_novo and PROVA_CLIENTE_NOVO: + return True, "primeiro pedido do cliente" + tensas = cores_detectadas & PROVA_CORES_TENSAS + if tensas: + return True, "cor fora do gamut: " + ", ".join(sorted(tensas)) + return False, "" + +# --------------------------------------------------------------------------- +# Retrabalho — SKU CRRMP.TX.100CM +# --------------------------------------------------------------------------- +# A causa é obrigatória e define quem absorve o custo. Sem ela o card não anda. +CAUSAS = { + "arte_cliente": ("Arte ruim aprovada pelo cliente", "cliente"), + "tratamento": ("Erro de tratamento", "casa"), + "impressao": ("Falha de impressão", "casa"), + "perfil_cor": ("Perfil de cor", "casa"), + "pedido": ("Erro de pedido", "casa"), +} + +# Quem abre e quem autoriza são pessoas diferentes, de propósito. +# +# MAYANA abre e CLASSIFICA a causa. Ela conhece o cliente e sabe se a +# reclamação procede. A causa fica TRAVADA depois de aberta. +# +# THALES ou ALEXANDRE autorizam. O retrabalho da casa entra na meta e na +# remuneração deles — então têm incentivo real para questionar o que não +# procede. É controle natural, não burocracia. +# +# Por que a causa não pode ser mudada por quem autoriza: com o indicador +# atrelado a bônus, existiria incentivo para reclassificar falha de máquina +# como "arte do cliente". Quem discorda CONTESTA, e a contestação fica +# registrada com quem pediu e quem decidiu. +ABRE = "mayana" +AUTORIZA = ("thales", "alexandre") + +# Alçada por metragem. Cada metro custa R$ 4,94 de insumo mais tempo de máquina. +ALCADA = [(15.0, "sala"), (float("inf"), "financeiro")] +# Meta por causa, não meta única. Cada um responde pelo que controla. +# 0,4% em cada uma das quatro causas da casa = 1,6% no total. +# +# Perfil de cor é causa PRÓPRIA, separada de falha de impressão. Cor errada é o +# retrabalho mais comum de DTF e quase nunca é defeito de máquina: ou a arte +# veio em CMYK, ou o monitor do cliente não é calibrado, ou o perfil da +# impressora está desatualizado. Só o terceiro é da casa — e separando dá para +# saber quanto é cada coisa. +META_POR_CAUSA = { + "impressao": (0.4, "Thales e Alexandre"), + "perfil_cor": (0.4, "Thales e Alexandre"), + "tratamento": (0.4, "designers"), + "pedido": (0.4, "comercial"), + "arte_cliente": (None, None), # reposição comercial: fora da meta +} +# soma das metas da casa = 1,6% +TETO_MES_PCT = 6.0 # acima disso tudo sobe uma alçada +TETO_CLIENTE_PCT = 10.0 # cliente acima disso fica sinalizado no painel + + +def quem_autoriza(metros: float, vez: int, pct_mes: float) -> str: + """Reincidência e teto do mês sobem a alçada automaticamente.""" + if vez >= 3: + return "diretoria" + nivel = next(n for lim, n in ALCADA if metros <= lim) + if vez == 2: + nivel = {"sala": "financeiro"}.get(nivel, "diretoria") + if pct_mes > TETO_MES_PCT: + nivel = {"sala": "financeiro", "financeiro": "diretoria"}.get(nivel, "diretoria") + return nivel + + +def conta_na_meta(causa: str) -> bool: + """Só o retrabalho da casa entra na meta. O do cliente, não.""" + return CAUSAS[causa][1] == "casa" + + +@app.get("/api/relatorio/retrabalho") +def retrabalho(dias: int = 30): + """ + Retrabalho por causa, com responsável e meta. + Base para a bonificação: cada equipe é medida só pelo que controla. + """ + with con() as c: + total = c.execute( + "SELECT COUNT(*) n FROM card WHERE desde >= date('now', ?)", + (f"-{dias} days",)).fetchone()["n"] or 1 + linhas = c.execute(""" + SELECT causa, COUNT(*) n, SUM(metros) m + FROM retrabalho WHERE aberto_em >= date('now', ?) + GROUP BY causa""", (f"-{dias} days",)).fetchall() + + saida, casa = [], 0.0 + for r in linhas: + pct = r["n"] / total * 100 + meta, quem = META_POR_CAUSA.get(r["causa"], (None, None)) + if conta_na_meta(r["causa"]): + casa += pct + saida.append({ + "causa": r["causa"], "descricao": CAUSAS[r["causa"]][0], + "responsavel": quem, "pedidos": r["n"], "metros": r["m"], + "pct": round(pct, 2), "meta": meta, + "bate": None if meta is None else pct <= meta, + }) + return {"por_causa": saida, "total_casa_pct": round(casa, 2), + "meta_casa_pct": round(sum(m for m, _ in META_POR_CAUSA.values() + if m is not None), 2)} + +# -------------------------------------------------------------------------- +def con(): + c = sqlite3.connect(BANCO, timeout=10) + c.row_factory = sqlite3.Row + return c + + +def criar_tabelas() -> None: + with con() as c: + c.executescript(""" + CREATE TABLE IF NOT EXISTS card( + arte_id INTEGER PRIMARY KEY, pedido TEXT, cliente TEXT, metros REAL, + coluna TEXT DEFAULT 'rec', desde TEXT, maquina TEXT, partes INTEGER, + reservado_por TEXT, reservado_em TEXT, + minutos_maquina INTEGER); -- estimativa; herda os marcadores 30min/1h/3h + CREATE TABLE IF NOT EXISTS movimento( + id INTEGER PRIMARY KEY AUTOINCREMENT, + arte_id INTEGER, pedido TEXT, de TEXT, para TEXT, + entrou_em TEXT, saiu_em TEXT, segundos INTEGER, + usuario TEXT, maquina TEXT); + CREATE TABLE IF NOT EXISTS job( + id INTEGER PRIMARY KEY AUTOINCREMENT, + tipo TEXT, payload TEXT, tentativas INTEGER DEFAULT 0, + proxima_em REAL, erro TEXT, feito INTEGER DEFAULT 0); + CREATE INDEX IF NOT EXISTS ix_mov_arte ON movimento(arte_id); + CREATE INDEX IF NOT EXISTS ix_job_fila ON job(feito, proxima_em); + """) + + +criar_tabelas() + + +# -------------------------------------------------------------------------- +class Mover(BaseModel): + arte_id: int + para: str + usuario: str + maquina: str | None = None + + +@app.get("/api/quadro") +def quadro(): + agora = datetime.now() + with con() as c: + cards = c.execute("SELECT * FROM card ORDER BY desde").fetchall() + + saida = {i: [] for i in IDS} + for r in cards: + desde = datetime.fromisoformat(r["desde"]) + saida[r["coluna"]].append({ + "arte_id": r["arte_id"], "pedido": r["pedido"], "cliente": r["cliente"], + "metros": r["metros"], "maquina": r["maquina"], "partes": r["partes"], + "desde": r["desde"], + "parado_seg": int((agora - desde).total_seconds()), + "minutos_maquina": round(r["metros"] / 20 * 60), # 20 m/h por máquina + }) + return {"colunas": [{"id": c[0], "nome": c[1]} for c in COLUNAS], "cards": saida} + + +@app.post("/api/mover") +def mover(m: Mover): + if m.para not in IDS: + raise HTTPException(400, "coluna inválida") + + agora = datetime.now() + with con() as c: + card = c.execute("SELECT * FROM card WHERE arte_id=?", (m.arte_id,)).fetchone() + if not card: + raise HTTPException(404, "card não encontrado") + if card["coluna"] == m.para: + return {"ok": True, "sem_mudanca": True} + + de = card["coluna"] + desde = datetime.fromisoformat(card["desde"]) + + # 1. o movimento é gravado ANTES de qualquer integração externa + c.execute("""INSERT INTO movimento + (arte_id,pedido,de,para,entrou_em,saiu_em,segundos,usuario,maquina) + VALUES (?,?,?,?,?,?,?,?,?)""", + (m.arte_id, card["pedido"], de, m.para, card["desde"], + agora.isoformat(timespec="seconds"), + int((agora - desde).total_seconds()), m.usuario, + m.maquina or card["maquina"])) + + c.execute("UPDATE card SET coluna=?, desde=?, maquina=COALESCE(?,maquina) " + "WHERE arte_id=?", + (m.para, agora.isoformat(timespec="seconds"), m.maquina, m.arte_id)) + + # 2. arquivo acompanha o card + mover_arquivos(card["pedido"], INFO[de][2], INFO[m.para][2]) + + # 3. jobs: marcador no Tiny e WhatsApp + # a máquina fica só no kanban — no Tiny basta saber que entrou em produção + marcador = INFO[m.para][3] + if marcador: + enfileirar(c, "tiny_marcador", + {"pedido": card["pedido"], "marcador": marcador}) + if m.para in AVISA_CLIENTE: + enfileirar(c, "whats", + {"pedido": card["pedido"], "tipo": AVISA_CLIENTE[m.para]}) + + return {"ok": True, "de": de, "para": m.para} + + +def mover_arquivos(pedido: str, pasta_de: str, pasta_para: str) -> None: + origem, destino = RAIZ / pasta_de, RAIZ / pasta_para + destino.mkdir(parents=True, exist_ok=True) + for f in origem.glob(f"{pedido}_*"): + shutil.move(str(f), str(destino / f.name)) + + +# -------------------------------------------------------------------------- +# Fila de jobs — tabela simples, sem Redis nem Celery +# -------------------------------------------------------------------------- +def enfileirar(c, tipo: str, payload: dict) -> None: + c.execute("INSERT INTO job(tipo,payload,proxima_em) VALUES (?,?,?)", + (tipo, json.dumps(payload), time.time())) + + +ESPERA = [60, 300, 1800] # 1 min, 5 min, 30 min + + +def worker() -> None: + while True: + try: + with con() as c: + job = c.execute( + "SELECT * FROM job WHERE feito=0 AND proxima_em<=? " + "ORDER BY id LIMIT 1", (time.time(),)).fetchone() + if not job: + time.sleep(3) + continue + + p = json.loads(job["payload"]) + try: + if job["tipo"] == "tiny_marcador": + tiny.marcador(p["pedido"], p["marcador"]) + elif job["tipo"] == "whats": + whats.avisar(p["pedido"], p["tipo"]) + c.execute("UPDATE job SET feito=1 WHERE id=?", (job["id"],)) + except Exception as e: + n = job["tentativas"] + 1 + if n > len(ESPERA): + c.execute("UPDATE job SET feito=1, erro=? WHERE id=?", + (f"desistiu: {e}", job["id"])) + # TODO: alertar o TI + else: + c.execute( + "UPDATE job SET tentativas=?, proxima_em=?, erro=? WHERE id=?", + (n, time.time() + ESPERA[n - 1], str(e), job["id"])) + except Exception: + time.sleep(5) + + +threading.Thread(target=worker, daemon=True).start() + + +# -------------------------------------------------------------------------- +# QR do carimbo aponta para cá +# -------------------------------------------------------------------------- +@app.get("/p/{pedido}") +def abrir_card(pedido: str): + """A revisão bipa o QR do filme e cai direto no card.""" + with con() as c: + card = c.execute("SELECT arte_id FROM card WHERE pedido=?", (pedido,)).fetchone() + if not card: + raise HTTPException(404, "pedido não encontrado no kanban") + return RedirectResponse(f"/?card={card['arte_id']}") + + +@app.get("/api/pedido/{pedido}") +def trilha(pedido: str): + """Tempo em cada etapa e quanto do total foi só esperando.""" + PARADO = {"rec", "tra", "fil", "cor"} + with con() as c: + movs = c.execute( + "SELECT * FROM movimento WHERE pedido=? ORDER BY id", (pedido,)).fetchall() + card = c.execute("SELECT * FROM card WHERE pedido=?", (pedido,)).fetchone() + if not card: + raise HTTPException(404) + + agora = int((datetime.now() - datetime.fromisoformat(card["desde"])).total_seconds()) + etapas = [{"coluna": m["de"], "nome": INFO[m["de"]][1], "segundos": m["segundos"]} + for m in movs] + etapas.append({"coluna": card["coluna"], "nome": INFO[card["coluna"]][1], + "segundos": agora, "atual": True}) + + total = sum(e["segundos"] for e in etapas) + esperando = sum(e["segundos"] for e in etapas if e["coluna"] in PARADO) + return {"pedido": pedido, "cliente": card["cliente"], "metros": card["metros"], + "etapas": etapas, "total_seg": total, "esperando_seg": esperando} + + +PERIODOS = {"hoje": 1, "7": 7, "30": 30, "mes": 30, "ant": 60} + + +@app.get("/api/relatorio/impressao") +def tempo_impressao(dias: int = 7): + """ + Tempo médio de impressão e velocidade real por máquina. + Sai da coluna 'imp' da tabela movimento, cruzada com os metros do card. + É este número que diz se 20 m/h é a velocidade real ou só a de catálogo. + """ + with con() as c: + linhas = c.execute(""" + SELECT m.maquina, COUNT(*) n, + AVG(m.segundos) media_seg, + SUM(c.metros) metros, + SUM(m.segundos) total_seg + FROM movimento m JOIN card c ON c.arte_id = m.arte_id + WHERE m.de = 'imp' AND m.saiu_em >= date('now', ?) + GROUP BY m.maquina""", (f"-{dias} days",)).fetchall() + saida = [] + for r in linhas: + horas = (r["total_seg"] or 0) / 3600 + saida.append({ + "maquina": r["maquina"], "pedidos": r["n"], + "media_min": round((r["media_seg"] or 0) / 60), + "metros": round(r["metros"] or 0, 1), + "m_por_hora": round((r["metros"] or 0) / horas, 1) if horas else None, + }) + return saida + + +# Depósito do Tiny para onde o insumo é transferido antes de imprimir. +# A Altus também VENDE insumo, então esse depósito separa o que é consumo +# interno do que é revenda. Confirmar o nome exato no cadastro do Tiny. +DEPOSITO_IMPRESSAO = "Sala DTF" +SKU_FILME = "DTF.FILME.57" + + +@app.get("/api/relatorio/aproveitamento") +def aproveitamento(dias: int = 30): + """ + Quanto do filme transferido virou metro faturado. + + Compra-se rolo de 100 m e imprime-se cerca de 90, por acerto de máquina, + prova de cor, refile e sobra de ponta. Cada ponto percentual vale cerca de + R$ 980/mês no volume atual. + + NÃO exige apontamento novo na sala: o consumo já é registrado hoje, quando + o insumo é transferido para o depósito de impressão no Tiny. Este endpoint + só lê a movimentação desse depósito. + """ + fat = 0.0 + with con() as c: + fat = c.execute( + "SELECT SUM(metros) m FROM card WHERE coluna='fin' AND desde >= date('now', ?)", + (f"-{dias} days",)).fetchone()["m"] or 0 + + cons = tiny.transferido_para_deposito( + sku=SKU_FILME, deposito=DEPOSITO_IMPRESSAO, dias=dias) + + pct = fat / cons * 100 if cons else None + return {"metros_faturados": round(fat, 1), + "metros_de_filme": round(cons, 1), + "fonte": f"transferências para o depósito {DEPOSITO_IMPRESSAO} no Tiny", + "aproveitamento_pct": round(pct, 1) if pct else None, + "valor_do_ponto_mes": 980} + + +@app.get("/api/relatorio/etapas") +def relatorio(dias: int = 7): + """Tempo médio por etapa. É o número que hoje não existe em lugar nenhum.""" + with con() as c: + linhas = c.execute(""" + SELECT de, COUNT(*) n, AVG(segundos) media, MAX(segundos) pior + FROM movimento + WHERE saiu_em >= date('now', ?) + GROUP BY de""", (f"-{dias} days",)).fetchall() + return [{"coluna": r["de"], "nome": INFO[r["de"]][1], "movimentos": r["n"], + "media_min": round(r["media"] / 60), "pior_min": round(r["pior"] / 60)} + for r in linhas] + + +@app.get("/") +def index(): + return FileResponse("static/kanban.html") diff --git a/kanban/static/kanban.html b/kanban/static/kanban.html new file mode 100644 index 0000000..4b1a249 --- /dev/null +++ b/kanban/static/kanban.html @@ -0,0 +1,271 @@ + + + + + +DTF · sala de impressão + + + + + + + +
+

Kanban da sala de DTF

+ carregando… + — +
+ + + +
+
+
+ +
+ + +
+ + + + diff --git a/kanban/tiny.py b/kanban/tiny.py new file mode 100644 index 0000000..8e737d2 --- /dev/null +++ b/kanban/tiny.py @@ -0,0 +1,89 @@ +""" +Cliente da API do Tiny (Olist) — v3, OAuth2 client credentials. + +ATENÇÃO Wagner: confirmar na documentação oficial antes de subir: + - o endpoint exato de marcadores do pedido + - o limite de requisições por minuto (dimensiona o worker) + - se o refresh token expira e com que frequência +Este módulo isola a API: se o endpoint mudar, muda só aqui. +""" +from __future__ import annotations + +import os +import time + +import httpx + +BASE = os.environ.get("TINY_BASE", "https://api.tiny.com.br/public-api/v3") +CLIENT_ID = os.environ["TINY_CLIENT_ID"] +CLIENT_SECRET = os.environ["TINY_CLIENT_SECRET"] +TOKEN_URL = os.environ["TINY_TOKEN_URL"] + +_token: dict = {"valor": None, "expira": 0.0} + + +def _acesso() -> str: + if _token["valor"] and time.time() < _token["expira"] - 60: + return _token["valor"] + r = httpx.post(TOKEN_URL, data={ + "grant_type": "client_credentials", + "client_id": CLIENT_ID, + "client_secret": CLIENT_SECRET, + }, timeout=20) + r.raise_for_status() + d = r.json() + _token["valor"] = d["access_token"] + _token["expira"] = time.time() + d.get("expires_in", 3600) + return _token["valor"] + + +def _headers() -> dict: + return {"Authorization": f"Bearer {_acesso()}", "Content-Type": "application/json"} + + +def buscar_pedido(numero: str) -> dict: + r = httpx.get(f"{BASE}/pedidos", params={"numero": numero}, + headers=_headers(), timeout=20) + r.raise_for_status() + itens = r.json().get("itens") or [] + if not itens: + raise LookupError(f"pedido {numero} não encontrado no Tiny") + return itens[0] + + +def transferido_para_deposito(sku: str, deposito: str, dias: int) -> float: + """ + Soma o que foi transferido para o depósito de impressão no período. + + A Altus já faz essa transferência hoje, porque também revende insumo — o + depósito separa consumo interno de revenda. Por isso o aproveitamento sai + de graça: nenhum apontamento novo na sala. + + ATENÇÃO Wagner: confirmar o endpoint de movimentações de estoque por + depósito na API v3 e o nome exato do depósito no cadastro. + """ + r = httpx.get( + f"{BASE}/estoque/movimentacoes", + params={"codigo": sku, "deposito": deposito, "dias": dias, "tipo": "E"}, + headers=_headers(), timeout=30, + ) + r.raise_for_status() + return sum(float(m.get("quantidade", 0)) for m in r.json().get("itens", [])) + + +def marcador(numero: str, marcador: str) -> None: + """ + Troca o marcador do pedido. Substitui os marcadores de etapa do DTF, + preservando marcadores de outra natureza (multiempresa, VALE, Troca...). + """ + pedido = buscar_pedido(numero) + atuais = [m["descricao"] for m in pedido.get("marcadores", [])] + # só três marcadores de etapa vivem no Tiny; o resto do fluxo é do kanban + ETAPAS = {"DTF-RECEBIDA", "DTF-PRODUCAO", "CORRECAO DTF", "DTF-PRONTO"} + mantem = [m for m in atuais if m not in ETAPAS] + novos = mantem + [marcador] + + r = httpx.put(f"{BASE}/pedidos/{pedido['id']}/marcadores", + json={"marcadores": [{"descricao": m} for m in novos]}, + headers=_headers(), timeout=20) + r.raise_for_status() diff --git a/kanban/whats.py b/kanban/whats.py new file mode 100644 index 0000000..6b4e630 --- /dev/null +++ b/kanban/whats.py @@ -0,0 +1,68 @@ +""" +Envio de WhatsApp. Três avisos ao cliente, não sete: + aprovada · em produção · finalizada (+ correção, a única que pede resposta) + +Provedor definido por WHATS_PROVEDOR = meta | zapi +A API oficial da Meta exige template aprovado para mensagem iniciada por nós. +""" +from __future__ import annotations + +import os + +import httpx + +PROVEDOR = os.environ.get("WHATS_PROVEDOR", "meta") +TOKEN = os.environ.get("WHATS_TOKEN", "") +NUMERO_ID = os.environ.get("WHATS_NUMERO_ID", "") +ZAPI_URL = os.environ.get("ZAPI_URL", "") + +TEXTOS = { + "prova_cor": ("Antes de imprimir o pedido {pedido} inteiro, fizemos uma amostra " + "de cor. Confira a foto e responda APROVO para seguirmos. A cor no " + "filme pode variar em relação ao seu monitor."), + "producao": "Seu pedido {pedido} entrou em produção. Avisamos quando ficar pronto.", + "concluido": "Pedido {pedido} finalizado e pronto para retirada ou envio.", + "correcao": "Precisamos de um ajuste na arte do pedido {pedido}: {motivo}", +} + + +def _enviar(telefone: str, texto: str) -> None: + if PROVEDOR == "zapi": + httpx.post(ZAPI_URL, json={"phone": telefone, "message": texto}, timeout=20) + return + httpx.post( + f"https://graph.facebook.com/v20.0/{NUMERO_ID}/messages", + headers={"Authorization": f"Bearer {TOKEN}"}, + json={"messaging_product": "whatsapp", "to": telefone, + "type": "text", "text": {"body": texto}}, + timeout=20, + ).raise_for_status() + + +def enviar_link(telefone: str, pedido: str, link: str) -> None: + _enviar(telefone, + f"Pedido {pedido} confirmado. Envie sua arte por aqui: {link}\n" + "O link vale por 7 dias. Gabarito 57 × 97 cm, PNG 300 DPI com fundo " + "transparente.") + + +def enviar_aprovacao(pedido, r) -> None: + n = len(r.partes) + _enviar(pedido.telefone if hasattr(pedido, "telefone") else "", + f"Arte do pedido {pedido.numero_tiny} aprovada. " + f"{r.metros_totais:.2f} m em {n} arquivo{'s' if n > 1 else ''}. " + "Entrou na fila de impressão.".replace(".", ",", 1)) + + +def enviar_recusa(pedido, motivo: str) -> None: + _enviar(getattr(pedido, "telefone", ""), + f"A arte do pedido {pedido.numero_tiny} precisa de ajuste: {motivo}\n" + "O prazo só começa a contar depois que a arte for aprovada.") + + +def avisar(pedido: str, tipo: str, motivo: str = "") -> None: + # o telefone vem do cadastro do pedido no Tiny + import tiny + p = tiny.buscar_pedido(pedido) + telefone = (p.get("cliente") or {}).get("fone", "") + _enviar(telefone, TEXTOS[tipo].format(pedido=pedido, motivo=motivo)) diff --git a/local/Dockerfile b/local/Dockerfile new file mode 100644 index 0000000..4a738e3 --- /dev/null +++ b/local/Dockerfile @@ -0,0 +1,11 @@ +FROM python:3.12-slim +RUN apt-get update \ + && apt-get upgrade -y \ + && rm -rf /var/lib/apt/lists/* +WORKDIR /app +COPY local/requirements.txt local/requirements.lock /app/local/ +RUN pip install --no-cache-dir --require-hashes -r local/requirements.lock +COPY local /app/local +RUN useradd --uid 10001 --create-home dtf +USER dtf +ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1 diff --git a/local/Dockerfile.web b/local/Dockerfile.web new file mode 100644 index 0000000..83a4602 --- /dev/null +++ b/local/Dockerfile.web @@ -0,0 +1,13 @@ +FROM python:3.12-slim AS policy +WORKDIR /build +COPY dtf-site.html /build/dtf-site.html +COPY local /build/local +RUN python local/compile_web.py + +FROM nginx:1.28-alpine +RUN apk upgrade --no-cache +ENV WEB_INDEX=index.html +COPY --from=policy /build/default.conf.template /etc/nginx/templates/default.conf.template +ENV S3_PUBLIC_ENDPOINT=http://localhost:9000 +COPY dtf-site.html /usr/share/nginx/html/index.html +COPY local/static/ /usr/share/nginx/html/ diff --git a/local/__init__.py b/local/__init__.py new file mode 100644 index 0000000..8b13789 --- /dev/null +++ b/local/__init__.py @@ -0,0 +1 @@ + diff --git a/local/adapters.py b/local/adapters.py new file mode 100644 index 0000000..063e1c4 --- /dev/null +++ b/local/adapters.py @@ -0,0 +1,127 @@ +"""Local-only composition root. No production provider implementations/imports.""" +import os +from typing import Protocol +from urllib.parse import urlparse +import boto3 +from botocore.config import Config +from botocore.exceptions import ClientError + +def require_local(): + if os.environ.get('APP_ENV') != 'local': + raise RuntimeError('This runtime only supports APP_ENV=local') + for name in ('PAYMENT', 'FREIGHT', 'TINY', 'WHATSAPP'): + if os.environ.get(f'{name}_ADAPTER') != 'fake': + raise RuntimeError(f'{name} must use the fake adapter') + if os.environ.get('STORAGE_ADAPTER') != 's3-local': + raise RuntimeError('Only local S3 storage is supported') + for name in ('S3_ENDPOINT', 'S3_PUBLIC_ENDPOINT'): + endpoint = urlparse(os.environ[name]) + if endpoint.scheme != 'http' or endpoint.hostname not in ('storage', 'localhost', '127.0.0.1'): + raise RuntimeError(f'{name} must point to local MinIO') + +class PaymentAdapter(Protocol): + def pay(self, quote_id: str, total_cents: int) -> dict: ... + +class FakePayment: + def pay(self, quote_id: str, total_cents: int) -> dict: + return {'provider': 'fake', 'id': f'local-{quote_id}', + 'status': 'paid', 'total_cents': total_cents} + +class FreightAdapter(Protocol): + def quote(self, service: str, postal_code: str) -> dict: ... + +class FakeFreight: + def quote(self, service: str, postal_code: str) -> dict: + if service == 'pickup': + return {'provider': 'fake', 'service': 'pickup', 'total_cents': 0, 'postal_code': ''} + if service != 'mock-standard' or len(postal_code) != 8 or not postal_code.isascii() or not postal_code.isdigit(): + raise ValueError('Select pickup or a mock quote with an eight-digit CEP') + cents = int(os.environ.get('MOCK_FREIGHT_CENTS', '1500')) + if cents < 0: + raise ValueError('Invalid mock freight configuration') + return {'provider': 'fake', 'service': service, 'postal_code': postal_code, + 'total_cents': cents, 'description': 'Local simulated freight'} + +class EventAdapter(Protocol): + def deliver(self, event_key: str, payload: dict) -> dict: ... + +class FakeTiny: + def deliver(self, event_key: str, payload: dict) -> dict: + return {'provider': 'fake-tiny', 'reference': f"LOCAL-{payload['number']}", + 'event_key': event_key, 'status': 'recorded-locally'} + +class FakeWhatsApp: + def deliver(self, event_key: str, payload: dict) -> dict: + return {'provider': 'fake-whatsapp', 'event_key': event_key, + 'event': payload['event'], 'status': 'recorded-locally'} + +class ObjectStorage(Protocol): + def begin(self, key: str) -> str: ... + def parts(self, key: str, upload_id: str) -> list: ... + def part_url(self, key: str, upload_id: str, part: int, size: int) -> str: ... + def complete(self, key: str, upload_id: str, parts: list): ... + def size(self, key: str) -> int: ... + def download(self, key: str, name: str) -> str: ... + def health(self): ... + def discard(self, key: str, upload_id: str, complete: bool): ... + +class LocalS3Storage: + def __init__(self): + config = Config(signature_version='s3v4', s3={'addressing_style': 'path'}, + connect_timeout=3, read_timeout=10, retries={'max_attempts': 2}) + self.client = boto3.client('s3', endpoint_url=os.environ['S3_ENDPOINT'], config=config) + self.public = boto3.client('s3', endpoint_url=os.environ['S3_PUBLIC_ENDPOINT'], config=config) + self.bucket = os.environ['S3_BUCKET'] + + def initialize(self): + try: + self.client.head_bucket(Bucket=self.bucket) + except ClientError as exc: + if exc.response['ResponseMetadata']['HTTPStatusCode'] != 404: + raise + self.client.create_bucket(Bucket=self.bucket) + self.client.put_bucket_lifecycle_configuration(Bucket=self.bucket, LifecycleConfiguration={ + 'Rules': [{'ID': 'local-artwork-retention', 'Status': 'Enabled', 'Filter': {'Prefix': ''}, + 'Expiration': {'Days': 30}, 'AbortIncompleteMultipartUpload': {'DaysAfterInitiation': 1}}]}) + + def health(self): + self.client.head_bucket(Bucket=self.bucket) + + def begin(self, key): + return self.client.create_multipart_upload(Bucket=self.bucket, Key=key, + ContentType='application/octet-stream')['UploadId'] + + def parts(self, key, upload_id): + result = [] + for page in self.client.get_paginator('list_parts').paginate( + Bucket=self.bucket, Key=key, UploadId=upload_id): + result.extend(page.get('Parts', [])) + return result + + def part_url(self, key, upload_id, part, size): + return self.public.generate_presigned_url('upload_part', Params={ + 'Bucket': self.bucket, 'Key': key, 'UploadId': upload_id, 'PartNumber': part, + 'ContentLength': size}, ExpiresIn=900) + + def complete(self, key, upload_id, parts): + self.client.complete_multipart_upload(Bucket=self.bucket, Key=key, UploadId=upload_id, + MultipartUpload={'Parts': [{'PartNumber': p['PartNumber'], 'ETag': p['ETag']} for p in parts]}) + + def size(self, key): + return self.client.head_object(Bucket=self.bucket, Key=key)['ContentLength'] + + def download(self, key, name): + from urllib.parse import quote + return self.public.generate_presigned_url('get_object', Params={ + 'Bucket': self.bucket, 'Key': key, + 'ResponseContentDisposition': "attachment; filename*=UTF-8''" + quote(name, safe=''), + 'ResponseContentType': 'application/octet-stream'}, ExpiresIn=300) + + def discard(self, key, upload_id, complete): + if not complete: + try: + self.client.abort_multipart_upload(Bucket=self.bucket, Key=key, UploadId=upload_id) + except ClientError as exc: + if exc.response['ResponseMetadata']['HTTPStatusCode'] != 404: + raise + self.client.delete_object(Bucket=self.bucket, Key=key) diff --git a/local/app.py b/local/app.py new file mode 100644 index 0000000..a24c571 --- /dev/null +++ b/local/app.py @@ -0,0 +1,341 @@ +import hashlib +import json +import math +import os +import secrets +from contextlib import asynccontextmanager +from datetime import datetime, timedelta, timezone +from uuid import UUID, uuid4 + +from botocore.exceptions import ClientError +from fastapi import Depends, FastAPI, HTTPException, Request, Response +from fastapi.responses import JSONResponse +from starlette.middleware.trustedhost import TrustedHostMiddleware +from psycopg.types.json import Jsonb + +from . import db +from .adapters import FakeFreight, FakePayment, LocalS3Storage, require_local +from .models import Freight, Move, Pay, QuoteRequest, Review, UploadStart, OperatorLogin +from .pricing import price +from .auth import owner, session_row, new_session, operator, throttle, audit, rate_limit +from .scanning import require_clean + +require_local() +storage = LocalS3Storage() +payment = FakePayment() +freight = FakeFreight() +PART_BYTES = int(os.environ.get('UPLOAD_PART_BYTES', '8388608')) +if not 5242880 <= PART_BYTES <= 67108864: + raise RuntimeError('UPLOAD_PART_BYTES must be between 5 and 64 MiB') +STATES = {'rec': 'Arte recebida', 'tra': 'Arte tratada', 'fil': 'Fila de impressão', + 'imp': 'Imprimindo', 'cor': 'Correção', 'fin': 'Finalizado'} +TRANSITIONS = {'rec': ['tra','cor'], 'tra': ['fil','cor'], 'fil': ['imp','cor'], + 'imp': ['fin','cor'], 'cor': ['rec','tra'], 'fin': []} + +@asynccontextmanager +async def lifespan(app): + with db.connect() as c: + c.execute('SELECT 1 FROM dtf_local.operator_sessions LIMIT 1') + storage.health() + yield + +app = FastAPI(title='DTF Local Portal/API', lifespan=lifespan, docs_url=None, redoc_url=None) +app.add_middleware(TrustedHostMiddleware, allowed_hosts=['localhost', '127.0.0.1']) + +@app.post('/api/operator/login') +def operator_login(body: OperatorLogin, request: Request, response: Response): + throttle('operator:'+body.username, request) + valid_user = secrets.compare_digest(body.username.encode(), os.environ['OPERATOR_USER'].encode()) + valid_password = secrets.compare_digest(body.password.encode(), os.environ['OPERATOR_PASSWORD'].encode()) + if not (valid_user and valid_password): + audit('operator_login_failed') + raise HTTPException(401, 'Invalid local operator login') + token = secrets.token_urlsafe(32) + with db.connect() as c: + previous = hashlib.sha256(request.cookies.get('dtf_operator','').encode()).hexdigest() + c.execute('DELETE FROM dtf_local.operator_sessions WHERE token_hash=%s', (previous,)) + c.execute('INSERT INTO dtf_local.operator_sessions(token_hash,username) VALUES(%s,%s)', + (hashlib.sha256(token.encode()).hexdigest(), body.username)) + response.set_cookie('dtf_operator', token, httponly=True, samesite='strict', path='/api/operator', max_age=28800) + audit('operator_login_success', operator=body.username) + return {'ok': True} + +@app.post('/api/operator/logout') +def operator_logout(request: Request, response: Response): + with db.connect() as c: + digest = hashlib.sha256(request.cookies.get('dtf_operator','').encode()).hexdigest() + c.execute('DELETE FROM dtf_local.operator_sessions WHERE token_hash=%s', (digest,)) + response.delete_cookie('dtf_operator', path='/api/operator', httponly=True, samesite='strict') + audit('operator_logout') + return {'ok': True} + +@app.middleware('http') +async def safe_headers(request, call_next): + if request.method not in ('GET','HEAD','OPTIONS'): + origin = request.headers.get('origin') + if request.headers.get('sec-fetch-site') == 'cross-site' or (origin and origin != 'http://'+request.headers.get('host','')): + audit('cross_origin_rejected') + return JSONResponse({'detail':'Cross-origin request rejected'}, status_code=403) + response = await call_next(request) + if response.status_code in (401,403,429) or response.status_code>=500: + audit('http_security_event', method=request.method, status=response.status_code) + response.headers['Cache-Control'] = 'no-store' + response.headers['X-Content-Type-Options'] = 'nosniff' + response.headers['Referrer-Policy'] = 'no-referrer' + return response + +@app.get('/health') +@app.get('/api/health') +def health(): + try: + with db.connect() as c: + c.execute('SELECT 1') + storage.health() + except Exception: + raise HTTPException(503, 'Database or storage unavailable') + return {'status': 'ok', 'environment': 'local', 'storage': 'minio', 'integrations': 'fake'} + +@app.get('/api/session') +def session(request: Request, response: Response): + try: + session_id = owner(request) + except HTTPException: + rate_limit('guest-sessions', 'local-stack', 120, 900) + with db.connect() as c: + session_id = new_session(c, response) + return {'environment': 'local', 'cart_scope': str(session_id), 'part_bytes': PART_BYTES, + 'max_upload_bytes': int(os.environ.get('MAX_UPLOAD_BYTES', '5368709120'))} + +@app.post('/api/freight') +def quote_freight(body: Freight): + try: + return freight.quote(body.service, body.postal_code) + except ValueError as exc: + raise HTTPException(422, str(exc)) + +def upload_row(c, upload_id, session_id, lock=False): + row = c.execute('SELECT * FROM dtf_local.uploads WHERE id=%s AND owner=%s' + + (' FOR UPDATE' if lock else ''), (upload_id, session_id)).fetchone() + if not row: + raise HTTPException(404, 'Upload not found') + days = 30 if row['complete'] else 1 + if row['purged_at'] or row['expires_at'] <= datetime.now(timezone.utc) or row['created_at'] < datetime.now(timezone.utc) - timedelta(days=days): + raise HTTPException(410, 'Upload expired; select the file again') + return row + +@app.post('/api/uploads') +def begin_upload(body: UploadStart, session_id=Depends(owner)): + if body.size > int(os.environ.get('MAX_UPLOAD_BYTES', '5368709120')): + raise HTTPException(413, 'File exceeds the local upload limit') + uid = uuid4() + key = f'originals/{uid}' + rate_limit('upload-start', str(session_id), 60, 900) + with db.connect() as c: + # Serialize reservations across API processes, including changing guest IDs. + c.execute('SELECT pg_advisory_xact_lock(804208)') + usage = c.execute('''SELECT COALESCE(sum(size),0) AS total, + COALESCE(sum(size) FILTER(WHERE owner=%s),0) AS owned, + count(*) FILTER(WHERE owner=%s AND NOT complete) AS pending + FROM dtf_local.uploads WHERE purged_at IS NULL''', (session_id,session_id)).fetchone() + if (usage['total']+body.size > int(os.environ.get('STORAGE_QUOTA_BYTES','53687091200')) or + usage['owned']+body.size > int(os.environ.get('OWNER_UPLOAD_QUOTA_BYTES','10737418240')) or + usage['pending'] >= int(os.environ.get('MAX_PENDING_UPLOADS','10'))): + audit('upload_quota_rejected') + raise HTTPException(429, 'Local storage quota or pending upload limit reached') + multipart = storage.begin(key) + c.execute('INSERT INTO dtf_local.uploads(id,owner,name,size,object_key,multipart_id) VALUES(%s,%s,%s,%s,%s,%s)', + (uid, session_id, body.name, body.size, key, multipart)) + return {'id': uid, 'part_bytes': PART_BYTES} + +@app.get('/api/uploads/{uid}') +def upload_status(uid: UUID, session_id=Depends(owner)): + with db.connect() as c: + row = upload_row(c, uid, session_id) + parts = [] if row['complete'] else storage.parts(row['object_key'], row['multipart_id']) + return {'id': uid, 'complete': row['complete'], 'part_bytes': PART_BYTES, + 'scan_state':row['scan_state'], 'scan_reason':row['scan_reason'], + 'parts': [p['PartNumber'] for p in parts]} + +@app.post('/api/uploads/{uid}/parts/{part}') +def part_url(uid: UUID, part: int, session_id=Depends(owner)): + with db.connect() as c: + row = upload_row(c, uid, session_id) + if row['complete'] or not 1 <= part <= math.ceil(row['size'] / PART_BYTES): + raise HTTPException(409, 'Invalid part or completed upload') + size = min(PART_BYTES, row['size']-(part-1)*PART_BYTES) + return {'url': storage.part_url(row['object_key'], row['multipart_id'], part, size)} + +@app.post('/api/uploads/{uid}/complete') +def complete_upload(uid: UUID, session_id=Depends(owner)): + with db.connect() as c: + row = upload_row(c, uid, session_id, lock=True) + if row['complete']: + return {'id': uid, 'complete': True} + try: + existing_size = storage.size(row['object_key']) + except ClientError as exc: + if exc.response['ResponseMetadata']['HTTPStatusCode'] != 404: + raise + existing_size = None + if existing_size is None: + parts = storage.parts(row['object_key'], row['multipart_id']) + expected = math.ceil(row['size'] / PART_BYTES) + if [p['PartNumber'] for p in parts] != list(range(1, expected+1)) or any( + p['Size'] != min(PART_BYTES, row['size'] - i*PART_BYTES) for i,p in enumerate(parts)): + raise HTTPException(409, 'Parts are missing or their sizes do not match') + storage.complete(row['object_key'], row['multipart_id'], parts) + existing_size = storage.size(row['object_key']) + if existing_size != row['size']: + raise HTTPException(409, 'Stored size differs from declared size') + c.execute('UPDATE dtf_local.uploads SET complete=true WHERE id=%s', (uid,)) + return {'id': uid, 'complete': True} + +@app.post('/api/quotes') +def create_quote(body: QuoteRequest, session_id=Depends(owner)): + draft = body.model_dump(mode='json', exclude={'request_key'}) + digest = hashlib.sha256(json.dumps(draft, sort_keys=True).encode()).hexdigest() + try: + freight.quote(body.freight.service, body.freight.postal_code) + except ValueError as exc: + raise HTTPException(422, str(exc)) + with db.connect() as c: + for item in body.items: + for uid in item.uploads: + row = upload_row(c, uid, session_id) + if not row['complete']: + raise HTTPException(409, 'Complete every upload before requesting a quote') + require_clean(row) + uid = uuid4() + c.execute('INSERT INTO dtf_local.quotes(id,owner,request_key,request_hash,draft) VALUES(%s,%s,%s,%s,%s) ON CONFLICT(owner,request_key) DO NOTHING', + (uid, session_id, body.request_key, digest, Jsonb(draft))) + row = c.execute('SELECT * FROM dtf_local.quotes WHERE owner=%s AND request_key=%s', (session_id, body.request_key)).fetchone() + if row['request_hash'] != digest: + raise HTTPException(409, 'Request key already used for a different cart') + return {'id': row['id'], 'status': 'pending_review'} + +def quote_view(c, row): + order = c.execute('SELECT id,number,state FROM dtf_local.orders WHERE quote_id=%s', (row['id'],)).fetchone() + expired = row['approved_at'] and row['approved_at'] < datetime.now(timezone.utc)-timedelta(hours=24) + return {'id': row['id'], 'draft': row['draft'], 'approved': row['approved'], + 'status': 'paid' if order else 'expired' if expired else 'approved' if row['approved'] else 'pending_review', + 'order': order} + +@app.get('/api/quotes/{uid}') +def get_quote(uid: UUID, session_id=Depends(owner)): + with db.connect() as c: + row = c.execute('SELECT * FROM dtf_local.quotes WHERE id=%s AND owner=%s', (uid,session_id)).fetchone() + if not row: + raise HTTPException(404, 'Quote not found') + return quote_view(c, row) + +def enqueue(c, event_key, provider, payload): + c.execute('INSERT INTO dtf_local.outbox(event_key,provider,payload) VALUES(%s,%s,%s) ON CONFLICT(event_key) DO NOTHING', + (event_key, provider, Jsonb(payload))) + +@app.post('/api/orders/dev-paid') +def dev_paid(body: Pay, session_id=Depends(owner)): + with db.connect() as c: + row = c.execute('SELECT * FROM dtf_local.quotes WHERE id=%s AND owner=%s FOR UPDATE', (body.quote_id,session_id)).fetchone() + if not row: + raise HTTPException(404, 'Quote not found') + existing = c.execute('SELECT * FROM dtf_local.orders WHERE quote_id=%s', (body.quote_id,)).fetchone() + if existing: + return existing + if not row['approved']: + raise HTTPException(409, 'An operator must verify length and grade first') + if row['approved_at'] < datetime.now(timezone.utc)-timedelta(hours=24): + raise HTTPException(409, 'Quote expired; request a new quote') + approved = row['approved'] + for item in approved['items']: + for upload_id in item['uploads']: + require_clean(upload_row(c, UUID(upload_id), session_id)) + paid = payment.pay(str(body.quote_id), approved['total_cents']) + result = c.execute('INSERT INTO dtf_local.orders(id,quote_id,owner,snapshot,payment) VALUES(%s,%s,%s,%s,%s) RETURNING *', + (uuid4(),body.quote_id,session_id,Jsonb(approved),Jsonb(paid))).fetchone() + for provider in ('tiny','whatsapp'): + enqueue(c, f"{result['id']}:paid:{provider}", provider, + {'order_id': str(result['id']), 'number': result['number'], 'event': 'payment_approved', 'order': approved}) + return result + +@app.get('/api/operator/board') +def board(user=Depends(operator)): + with db.connect() as c: + orders = c.execute('SELECT * FROM dtf_local.orders ORDER BY created_at').fetchall() + quotes = c.execute('SELECT q.* FROM dtf_local.quotes q LEFT JOIN dtf_local.orders o ON o.quote_id=q.id WHERE o.id IS NULL ORDER BY q.created_at').fetchall() + return {'states': STATES, 'transitions': TRANSITIONS, 'orders': orders, + 'quotes': [quote_view(c, q) for q in quotes], + 'events': c.execute('SELECT * FROM dtf_local.outbox ORDER BY id DESC LIMIT 100').fetchall()} + +@app.post('/api/operator/quotes/{uid}/approve') +def approve(uid: UUID, body: Review, user=Depends(operator)): + with db.connect() as c: + row = c.execute('SELECT * FROM dtf_local.quotes WHERE id=%s FOR UPDATE', (uid,)).fetchone() + if not row: + raise HTTPException(404, 'Quote not found') + if row['approved']: + raise HTTPException(409, 'Approved quotes are immutable; request a new quote') + draft = row['draft'] + if len(body.items) != len(draft['items']): + raise HTTPException(422, 'Review must cover every item') + items = [] + for item, original in zip(body.items, draft['items']): + if item.mode != original['mode'] or list(map(str,item.uploads)) != original['uploads']: + raise HTTPException(422, 'Product mode and attached files cannot change during review') + for upload_id in item.uploads: + require_clean(upload_row(c, upload_id, row['owner'])) + items.append({**price(item.mode, str(item.metres), item.grade), 'uploads': original['uploads']}) + quoted_freight = freight.quote(**draft['freight']) + approved = {'customer': draft['customer'], 'items': items, 'freight': quoted_freight, + 'total_cents': sum(i['total_cents'] for i in items)+quoted_freight['total_cents']} + c.execute('UPDATE dtf_local.quotes SET approved=%s, reviewed_by=%s, approved_at=now() WHERE id=%s', (Jsonb(approved),user,uid)) + return approved + +@app.post('/api/operator/orders/{uid}/move') +def move(uid: UUID, body: Move, user=Depends(operator)): + with db.connect() as c: + row = c.execute('SELECT * FROM dtf_local.orders WHERE id=%s FOR UPDATE', (uid,)).fetchone() + if not row: + raise HTTPException(404, 'Order not found') + if body.version != row['version']: + raise HTTPException(409, 'Order changed; refresh the board') + if body.state == row['state']: + return row + if body.state not in TRANSITIONS[row['state']]: + raise HTTPException(409, 'Move is not allowed from this state') + if body.state == 'cor' and not body.reason.strip(): + raise HTTPException(422, 'Correction requires a reason') + if body.state in ('fil','imp'): + coverage = c.execute('SELECT DISTINCT f.item_index FROM dtf_local.order_files f JOIN dtf_local.uploads u ON u.id=f.upload_id WHERE f.order_id=%s AND f.kind=\'final\' AND f.active AND u.expires_at>now() AND u.purged_at IS NULL AND u.scan_state=\'clean\'', (uid,)).fetchall() + if {r['item_index'] for r in coverage} != set(range(len(row['snapshot']['items']))): + raise HTTPException(409, 'Approve a complete final-file set for every item before queueing') + if body.state == 'cor': + c.execute("UPDATE dtf_local.order_files SET active=false WHERE order_id=%s AND kind='final'", (uid,)) + c.execute('INSERT INTO dtf_local.movements(order_id,from_state,to_state,operator,reason) VALUES(%s,%s,%s,%s,%s)', + (uid,row['state'],body.state,user,body.reason)) + changed = c.execute('UPDATE dtf_local.orders SET state=%s, version=version+1, updated_at=now() WHERE id=%s RETURNING *', (body.state,uid)).fetchone() + events = {'imp':'production_started','cor':'correction_needed','fin':'ready'} + if body.state in events: + for provider in ('tiny','whatsapp'): + enqueue(c, f'{uid}:{changed["version"]}:{provider}', provider, + {'order_id':str(uid), 'number':row['number'], 'event':events[body.state], 'reason':body.reason, + 'customer_path': f'/portal.html?order={uid}'}) + return changed + +@app.get('/api/operator/orders/{uid}/history') +def history(uid: UUID, user=Depends(operator)): + with db.connect() as c: + return c.execute('SELECT * FROM dtf_local.movements WHERE order_id=%s ORDER BY id', (uid,)).fetchall() + +@app.get('/api/operator/uploads/{uid}/download') +def download(uid: UUID, user=Depends(operator)): + with db.connect() as c: + row = c.execute('SELECT * FROM dtf_local.uploads WHERE id=%s AND complete', (uid,)).fetchone() + if not row: + raise HTTPException(404, 'Completed upload not found') + if row['expires_at'] <= datetime.now(timezone.utc): + raise HTTPException(410, 'Artwork retention expired') + require_clean(row) + return {'name':row['name'], 'url':storage.download(row['object_key'],row['name']), 'expires_in':300} + +from .customer import install_routes +install_routes(app, operator, storage, begin_upload, upload_status, part_url, complete_upload, upload_row, STATES) diff --git a/local/auth.py b/local/auth.py new file mode 100644 index 0000000..3e65de7 --- /dev/null +++ b/local/auth.py @@ -0,0 +1,93 @@ +"""Local customer passwords and revocable database sessions. No email service.""" +import hashlib +import secrets +import logging +import json +from uuid import UUID, uuid4 +from fastapi import HTTPException, Request +from .db import connect + +def password_hash(password, salt=None): + salt = salt or secrets.token_hex(16) + digest = hashlib.scrypt(password.encode(), salt=bytes.fromhex(salt), n=16384, r=8, p=5).hex() + return f'scrypt-v2${salt}${digest}' + +def password_matches(password, stored): + try: + version, salt, digest = stored.split('$') + if version not in ('scrypt', 'scrypt-v2'): return False + actual = hashlib.scrypt(password.encode(), salt=bytes.fromhex(salt), n=16384, r=8, + p=1 if version == 'scrypt' else 5).hex() + return secrets.compare_digest(actual, digest) + except (ValueError, TypeError): + return False + +DUMMY_PASSWORD_HASH = password_hash('invalid-account-password', '00'*16) + +def session_row(request): + try: + sid = UUID(request.cookies.get('dtf_session', '')) + except ValueError: + raise HTTPException(401, 'Start a local session first') + with connect() as c: + row = c.execute('SELECT * FROM dtf_local.sessions WHERE id=%s AND expires_at>now()', (sid,)).fetchone() + if not row: + raise HTTPException(401, 'Session expired; sign in or start a new session') + return row + +def owner(request: Request): + return session_row(request)['owner'] + +def new_session(c, response, identity=None): + sid = uuid4() + identity = identity or uuid4() + c.execute('INSERT INTO dtf_local.sessions(id,owner) VALUES(%s,%s)', (sid,identity)) + response.set_cookie('dtf_session', str(sid), httponly=True, samesite='strict', max_age=86400*7) + return identity + +def transfer_guest(c, previous, identity): + # Successful authentication can claim only the current guest browser's records. + if c.execute('SELECT id FROM dtf_local.accounts WHERE id=%s', (previous['owner'],)).fetchone(): + return + for table in ('uploads','quotes','orders'): + c.execute(f'UPDATE dtf_local.{table} SET owner=%s WHERE owner=%s', (identity,previous['owner'])) + c.execute('DELETE FROM dtf_local.sessions WHERE owner=%s', (previous['owner'],)) + +def audit(event, **fields): + # Only explicit metadata: never cookies, passwords, signed URLs or request bodies. + logging.getLogger('dtf.security').warning(json.dumps({'event':event, **fields}, sort_keys=True)) + try: + from psycopg.types.json import Jsonb + with connect() as c: + c.execute('INSERT INTO dtf_local.security_events(event,details) VALUES(%s,%s)',(event,Jsonb(fields))) + except Exception: + # Logging must still work during a DB outage without recursively auditing itself. + logging.getLogger('dtf.security').error('Security event persistence unavailable') + +def rate_limit(scope, identity, limit, seconds=900): + key = hashlib.sha256((scope+'|'+identity).encode()).hexdigest() + with connect() as c: + row = c.execute("""INSERT INTO dtf_local.login_attempts(key,attempts) VALUES(%s,1) + ON CONFLICT(key) DO UPDATE SET + attempts=CASE WHEN dtf_local.login_attempts.started_at < now()-%s*interval '1 second' THEN 1 ELSE LEAST(dtf_local.login_attempts.attempts+1,1000000) END, + started_at=CASE WHEN dtf_local.login_attempts.started_at < now()-%s*interval '1 second' THEN now() ELSE dtf_local.login_attempts.started_at END + RETURNING attempts""", (key,seconds,seconds)).fetchone() + if row['attempts'] > limit: + audit('rate_limit', scope=scope) + raise HTTPException(429, 'Too many requests. Try again later.', headers={'Retry-After':str(seconds)}) + +def throttle(email, request): + # Independent account and source buckets prevent bypass by rotating emails. + rate_limit('auth-source', request.client.host if request.client else 'local', 60) + rate_limit('auth-account', email, 10) + +def operator(request: Request): + token = request.cookies.get('dtf_operator', '') + if not token or len(token)>128: + raise HTTPException(401, 'Sign in to the local Kanban') + digest = hashlib.sha256(token.encode()).hexdigest() + with connect() as c: + row = c.execute('SELECT username FROM dtf_local.operator_sessions WHERE token_hash=%s AND expires_at>now()', (digest,)).fetchone() + if not row: + raise HTTPException(401, 'Operator session expired') + return row['username'] diff --git a/local/backup.py b/local/backup.py new file mode 100644 index 0000000..81e30d2 --- /dev/null +++ b/local/backup.py @@ -0,0 +1,128 @@ +"""Local PostgreSQL and clean-object backup with isolated restore verification.""" +import argparse +from datetime import datetime, timezone +import hashlib +import json +from pathlib import Path +import subprocess +from uuid import uuid4 + +ROOT = Path(__file__).resolve().parent.parent +BACKUPS = ROOT / 'backups' + +def docker(script, *args, **kwargs): + return subprocess.run(['docker','compose','exec','-T','db','sh','-c',script,'sh',*args], + cwd=ROOT,check=True,**kwargs) + +def checksum(path): + digest=hashlib.sha256() + with path.open('rb') as stream: + for block in iter(lambda:stream.read(1048576),b''):digest.update(block) + return digest.hexdigest() + +def compose_exec(service, *command, **kwargs): + return subprocess.run(['docker','compose','exec','-T',service,*command], + cwd=ROOT,check=True,**kwargs) + +def create(): + BACKUPS.mkdir(mode=0o700,exist_ok=True) + prefix='dtf-'+datetime.now(timezone.utc).strftime('%Y%m%dT%H%M%SZ')+'-'+uuid4().hex[:8] + database=BACKUPS/(prefix+'.dump') + objects=BACKUPS/(prefix+'.objects.tar.gz') + manifest_path=BACKUPS/(prefix+'.manifest.json') + sidecar=BACKUPS/(prefix+'.manifest.sha256') + created=[] + try: + with database.open('xb') as stream: + created.append(database);database.chmod(0o600) + docker('pg_dump -U "$POSTGRES_USER" -d "$POSTGRES_DB" --format=custom',stdout=stream) + with objects.open('xb') as stream: + created.append(objects);objects.chmod(0o600) + result=compose_exec('api','python','-m','local.storage_backup','export', + stdout=stream,stderr=subprocess.PIPE) + summaries=[line.removeprefix('DTF_BACKUP_SUMMARY ') for line in + result.stderr.decode().splitlines() if line.startswith('DTF_BACKUP_SUMMARY ')] + if len(summaries)!=1: + raise RuntimeError('Object backup did not return a valid summary') + manifest={'format':'dtf-local-backup-v2', + 'created_at':datetime.now(timezone.utc).isoformat(), + 'database':{'file':database.name,'sha256':checksum(database)}, + 'objects':{'file':objects.name,'sha256':checksum(objects), + **json.loads(summaries[0])}} + manifest_path.write_text(json.dumps(manifest,indent=2,sort_keys=True)+'\n') + created.append(manifest_path);manifest_path.chmod(0o600) + sidecar.write_text(checksum(manifest_path)+'\n') + created.append(sidecar);sidecar.chmod(0o600) + except Exception: + for path in reversed(created):path.unlink(missing_ok=True) + raise + print(manifest_path.relative_to(ROOT)) + return manifest_path + +def verify_database(path): + if checksum(path)!=path.with_suffix('.sha256').read_text().strip(): + raise ValueError('Backup checksum mismatch') + database='dtf_verify_'+uuid4().hex + docker('createdb -U "$POSTGRES_USER" "$1"',database) + try: + with path.open('rb') as stream: + docker('pg_restore -U "$POSTGRES_USER" -d "$1" --exit-on-error --no-owner --no-privileges',database,stdin=stream) + result=docker('psql -U "$POSTGRES_USER" -d "$1" -At -v ON_ERROR_STOP=1 -c "SELECT json_build_object(\'orders\',(SELECT count(*) FROM dtf_local.orders),\'uploads\',(SELECT count(*) FROM dtf_local.uploads),\'accounts\',(SELECT count(*) FROM dtf_local.accounts),\'history\',(SELECT count(*) FROM dtf_local.movements));"',database,capture_output=True,text=True) + print('PASS: backup restored to isolated database; restored counts '+result.stdout.strip()) + finally: + # Only the freshly created UUID-named verification database is removed. + docker('dropdb -U "$POSTGRES_USER" "$1"',database) + print('Removed temporary verification database. Active database was untouched.') + +def bundle_file(manifest_path, name): + if not isinstance(name,str) or Path(name).name!=name: + raise ValueError('Backup manifest contains an invalid filename') + path=(manifest_path.parent/name).resolve() + if path.parent!=BACKUPS.resolve(): + raise ValueError('Backup manifest references a file outside backups/') + return path + +def verify(path): + path=path.resolve() + if path.parent!=BACKUPS.resolve(): + raise ValueError('Choose a backup generated in this repository backups/ directory') + if path.suffix=='.dump': + return verify_database(path) + if not path.name.endswith('.manifest.json'): + raise ValueError('Choose a v2 .manifest.json or legacy .dump backup') + sidecar=path.with_name(path.name.removesuffix('.json')+'.sha256') + if checksum(path)!=sidecar.read_text().strip(): + raise ValueError('Backup manifest checksum mismatch') + manifest=json.loads(path.read_text()) + if manifest.get('format')!='dtf-local-backup-v2': + raise ValueError('Unsupported backup format') + database=bundle_file(path,manifest.get('database',{}).get('file')) + objects=bundle_file(path,manifest.get('objects',{}).get('file')) + if checksum(database)!=manifest['database'].get('sha256') or checksum(objects)!=manifest['objects'].get('sha256'): + raise ValueError('Backup bundle checksum mismatch') + # Reuse the legacy database verifier with a temporary matching sidecar. + legacy_sidecar=database.with_suffix('.sha256') + had_legacy=legacy_sidecar.exists() + previous=legacy_sidecar.read_bytes() if had_legacy else None + legacy_sidecar.write_text(manifest['database']['sha256']+'\n');legacy_sidecar.chmod(0o600) + try: + verify_database(database) + finally: + if had_legacy:legacy_sidecar.write_bytes(previous) + else:legacy_sidecar.unlink(missing_ok=True) + with objects.open('rb') as stream: + compose_exec('api','python','-m','local.storage_backup','verify',stdin=stream) + print('PASS: combined database and clean-object backup verified. Active data was untouched.') + +if __name__=='__main__': + parser=argparse.ArgumentParser(description=__doc__) + parser.add_argument('command',choices=['create','verify','create-and-verify']) + parser.add_argument('path',nargs='?',type=Path, + help='v2 manifest printed by create, or a legacy .dump') + args=parser.parse_args() + if args.command=='verify': + if not args.path:parser.error('verify requires the path printed by create') + verify(args.path) + else: + path=create() + if args.command=='create-and-verify':verify(path) diff --git a/local/bootstrap.py b/local/bootstrap.py new file mode 100644 index 0000000..f62de26 --- /dev/null +++ b/local/bootstrap.py @@ -0,0 +1,25 @@ +"""One-shot schema/role setup. Only this job receives database admin credentials.""" +import os +from pathlib import Path +import psycopg +from psycopg import sql + +def main(): + role = os.environ['APP_DB_USER'] + with psycopg.connect(os.environ['DATABASE_ADMIN_URL']) as c: + admin, database = c.execute('SELECT current_user,current_database()').fetchone() + if role == admin: + raise RuntimeError('Application and database administrator must differ') + if not c.execute('SELECT 1 FROM pg_roles WHERE rolname=%s', (role,)).fetchone(): + c.execute(sql.SQL('CREATE ROLE {} LOGIN').format(sql.Identifier(role))) + c.execute(sql.SQL('ALTER ROLE {} NOSUPERUSER NOCREATEDB NOCREATEROLE NOREPLICATION NOBYPASSRLS PASSWORD {}').format( + sql.Identifier(role), sql.Literal(os.environ['APP_DB_PASSWORD']))) + c.execute(Path(__file__).with_name('schema.sql').read_text()) + c.execute(sql.SQL('REVOKE CREATE ON SCHEMA public FROM PUBLIC')) + c.execute(sql.SQL('GRANT CONNECT ON DATABASE {} TO {}').format(sql.Identifier(database),sql.Identifier(role))) + c.execute(sql.SQL('GRANT USAGE ON SCHEMA dtf_local TO {}').format(sql.Identifier(role))) + c.execute(sql.SQL('GRANT SELECT,INSERT,UPDATE,DELETE ON ALL TABLES IN SCHEMA dtf_local TO {}').format(sql.Identifier(role))) + c.execute(sql.SQL('GRANT USAGE,SELECT ON ALL SEQUENCES IN SCHEMA dtf_local TO {}').format(sql.Identifier(role))) + print('Local schema migrated; runtime role has DML only.') + +if __name__ == '__main__': main() diff --git a/local/browser_test.mjs b/local/browser_test.mjs new file mode 100644 index 0000000..0638166 --- /dev/null +++ b/local/browser_test.mjs @@ -0,0 +1,140 @@ +// Dependency-free Chrome DevTools smoke test. Node 22+ and Chrome required. +import {spawn} from 'node:child_process'; +import {mkdtemp,readFile,writeFile,mkdir} from 'node:fs/promises'; +import {tmpdir} from 'node:os'; +import {resolve} from 'node:path'; +import assert from 'node:assert/strict'; +try { + for(const line of (await readFile('.env','utf8')).split('\n')) { + if(!line.startsWith('#') && line.includes('=')) { + const i=line.indexOf('=');process.env[line.slice(0,i)]??=line.slice(i+1); + } + } +}catch(e){if(e.code!=='ENOENT')throw e;} +const profile=await mkdtemp(tmpdir()+'/dtf-browser-'); +const chrome=spawn(process.env.CHROME_BIN||'/usr/bin/google-chrome-stable',[ + '--headless=new','--disable-gpu','--no-first-run','--no-default-browser-check', + '--remote-debugging-port=0','--user-data-dir='+profile,'about:blank' +],{stdio:['ignore','ignore','pipe']}); +const pause=ms=>new Promise(r=>setTimeout(r,ms)); +let stderr='';chrome.stderr.on('data',data=>stderr+=data.toString()); +const clients=[]; +async function waitFor(fn,description,timeout=30000){const end=Date.now()+timeout;while(Date.now(){const d=JSON.parse(event.data);if(d.id){const p=this.pending.get(d.id);if(p){this.pending.delete(d.id);d.error?p.reject(d.error):p.resolve(d.result);}}else if(d.method==='Runtime.exceptionThrown')this.errors.push(d.params.exceptionDetails);}; + } + call(method,params={}){return new Promise((resolve,reject)=>{const id=++this.next;this.pending.set(id,{resolve,reject});this.ws.send(JSON.stringify({id,method,params}));});} + async eval(expression){const result=await this.call('Runtime.evaluate',{expression,awaitPromise:true,returnByValue:true});if(result.exceptionDetails)throw new Error(JSON.stringify(result.exceptionDetails));return result.result.value;} + async click(selector){await this.eval(`document.querySelector(${JSON.stringify(selector)}).click()`);} + async fill(selector,value,event='input'){await this.eval(`(()=>{const el=document.querySelector(${JSON.stringify(selector)});el.value=${JSON.stringify(value)};el.dispatchEvent(new Event(${JSON.stringify(event)},{bubbles:true}));})()`);} + async text(){return this.eval('document.body.innerText');} + async screenshot(path){const result=await this.call('Page.captureScreenshot',{format:'png',captureBeyondViewport:false});await writeFile(path,Buffer.from(result.data,'base64'));} +} +try{ + let port; + await waitFor(async()=>{try{port=Number((await readFile(profile+'/DevToolsActivePort','utf8')).split('\n')[0]);return true;}catch{return false;}},'Chrome startup'); + async function page(url){ + const tab=await (await fetch('http://localhost:'+port+'/json/new?'+encodeURIComponent(url),{method:'PUT'})).json(); + const ws=new WebSocket(tab.webSocketDebuggerUrl);await new Promise((r,j)=>{ws.onopen=r;ws.onerror=j;}); + const p=new Page(ws);clients.push(p);await p.call('Runtime.enable');await p.call('Page.enable'); + await p.call('Emulation.setDeviceMetricsOverride',{width:1440,height:1000,deviceScaleFactor:1,mobile:false}); + await waitFor(()=>p.eval('document.readyState === "complete"'),'page load');return p; + } + const site=await page('http://localhost:'+(process.env.SITE_PORT||8080)); + await waitFor(()=>site.eval('typeof window.dtfCheckout === "function"'),'checkout bridge'); + // Prove escaping itself, independently of the CSP's second line of defense. + await site.call('Page.setBypassCSP',{enabled:true}); + await site.eval(`(()=>{window.xssProbe=0;abrir('file');sel([new File(['test'],'.cdr')]);})()`); + await pause(500); + assert.equal(await site.eval('window.xssProbe'),0); + assert.equal(await site.eval('document.querySelectorAll("#lista img[onerror]").length'),0); + assert.ok((await site.text()).includes('.cdr')); + await site.eval(`(()=>{recusa([new File(['test'],'bad.')]);})()`); + await pause(200);assert.equal(await site.eval('window.xssProbe'),0); + await site.call('Page.setBypassCSP',{enabled:false}); + await site.call('Page.reload'); + await waitFor(()=>site.eval('typeof window.dtfCheckout === "function"'),'reload after security probe'); + await site.click('[data-modo="file"]'); + await site.click('[data-cam="tabela"]'); + const root=await site.call('DOM.getDocument'); + const input=await site.call('DOM.querySelector',{nodeId:root.root.nodeId,selector:'#inp'}); + await site.call('DOM.setFileInputFiles',{nodeId:input.nodeId,files:[resolve('local/fixtures/local-test.cdr')]}); + await waitFor(()=>site.eval('!!document.querySelector("[data-comp]")'),'manual length field'); + await site.fill('[data-comp]','1.01','change'); + await waitFor(()=>site.eval('!!itemAtual'),'cart calculation'); + assert.equal(await site.eval('itemAtual.total'),21.89); + await site.fill('#fCnpj','11222333000181'); + await site.fill('#fZap','11999999999'); + await site.fill('#fMail','local-browser@example.test'); + await pause(800); + await site.call('Page.reload'); + await waitFor(()=>site.eval('typeof pedido!=="undefined" && pedido.length===1'),'persistent cart recovery'); + assert.equal(await site.eval('pedido[0].localFiles[0].name'),'local-test.cdr'); + assert.equal(await site.eval('pedido[0].total'),21.89); + assert.equal(await site.eval('document.getElementById("bPagar").disabled'),false); + await site.click('#bPagar'); + await waitFor(async()=> (await site.text()).includes('Arquivos enviados.'),'browser upload and quote',45000); + const qid=await site.eval('localStorage.getItem("dtf-quote")'); + const kanban=await page('http://localhost:'+(process.env.KANBAN_PORT||8081)); + await kanban.fill('#user',process.env.OPERATOR_USER||'operator'); + await kanban.fill('#password',process.env.OPERATOR_PASSWORD||'local-operator-only'); + await kanban.eval('document.getElementById("login").requestSubmit()'); + await waitFor(async()=> (await kanban.text()).includes(qid.slice(0,8)),'quote on Kanban'); + assert.equal(await kanban.eval('sessionStorage.getItem("dtf-operator")'),null); + assert.equal(await kanban.eval('document.getElementById("password").value'),''); + await kanban.eval(`(()=>{const card=[...document.querySelectorAll('.review')].find(x=>x.textContent.includes(${JSON.stringify(qid.slice(0,8))}));card.querySelector('[type=checkbox]').click();card.querySelector('form').requestSubmit();})()`); + await waitFor(async()=> (await kanban.text()).includes('Aprovada:'),'quote approval'); + await site.eval('[...document.querySelectorAll("button")].find(x=>x.textContent==="Atualizar pedido local").click()'); + await waitFor(async()=> (await site.text()).includes('Total validado no servidor:'),'approved quote displayed'); + await site.eval('[...document.querySelectorAll("button")].find(x=>x.textContent==="Criar pedido pago local").click()'); + await waitFor(async()=> (await site.text()).includes('Nenhuma cobrança real.'),'local payment'); + await kanban.click('#refresh'); + await waitFor(()=>kanban.eval(`board.orders.some(o=>o.quote_id===${JSON.stringify(qid)})`),'paid card'); + const oid=await kanban.eval(`board.orders.find(o=>o.quote_id===${JSON.stringify(qid)}).id`); + // Click real transition buttons, including rerender after each move. + for(const [title,state] of [['Arte tratada','tra'],['Fila de impressão','fil'],['Imprimindo','imp'],['Finalizado','fin']]){ + if(state==='fil'){ + await kanban.eval(`(()=>{const card=document.querySelector('[data-order="${oid}"]');[...card.querySelectorAll('button')].find(x=>x.textContent==='Arquivos de produção').click();})()`); + await waitFor(()=>kanban.eval(`!!document.querySelector('[data-order="${oid}"] [data-final-item]')`),'final upload controls'); + const doc=await kanban.call('DOM.getDocument'); + const input=await kanban.call('DOM.querySelector',{nodeId:doc.root.nodeId,selector:`[data-order="${oid}"] [data-final-item]`}); + await kanban.call('DOM.setFileInputFiles',{nodeId:input.nodeId,files:[resolve('local/fixtures/local-test.cdr')]}); + await kanban.fill(`[data-order="${oid}"] input[placeholder="Nota da revisão"]`,'Browser test final file'); + await kanban.eval(`(()=>{const form=document.querySelector('[data-order="${oid}"] form');form.querySelector('[type=checkbox]').click();form.requestSubmit();})()`); + await waitFor(()=>kanban.eval(`board.orders.find(o=>o.id==='${oid}').version===2`),'final file approval'); + } + await kanban.eval(`(()=>{const card=document.querySelector('[data-order="${oid}"]');[...card.querySelectorAll('button')].find(x=>x.textContent===${JSON.stringify('→ '+title)}).click();})()`); + await waitFor(()=>kanban.eval(`board.orders.find(o=>o.id==='${oid}').state==='${state}'`),'transition '+state); + } + // Reload proves the board is persisted on the backend. + await kanban.call('Page.reload'); + await waitFor(()=>kanban.eval(`typeof board!=='undefined' && !!board && board.orders.some(o=>o.id==='${oid}'&&o.state==='fin')`),'persisted board'); + await mkdir('output/local',{recursive:true}); + await site.eval('window.scrollTo({top:0,behavior:"instant"})'); + await waitFor(()=>site.eval('window.scrollY===0'),'screenshot scroll position'); + await site.screenshot('output/local/site.png'); + await kanban.screenshot('output/local/kanban.png'); + const portal=await page('http://localhost:'+(process.env.SITE_PORT||8080)+'/portal.html?order='+oid); + await waitFor(async()=> (await portal.text()).includes('Finalizado'),'customer order tracking'); + await portal.fill('#cnpj','11222333000181');await portal.fill('#phone','11999999999'); + await portal.fill('#register-email','browser-'+Date.now()+'@example.test'); + await portal.fill('#register-password','local-browser-password-123'); + await portal.eval('document.getElementById("register").requestSubmit()'); + await waitFor(()=>portal.eval('document.getElementById("auth").hidden'),'customer registration'); + assert.ok((await portal.text()).includes('Finalizado')); + await portal.screenshot('output/local/portal.png'); + // A logout must clear draft file blobs and metadata, including other open Site tabs. + await portal.eval(`(async()=>{const db=await new Promise((resolve,reject)=>{const r=indexedDB.open('dtf-local-cart',1);r.onsuccess=()=>resolve(r.result);r.onerror=reject;});await new Promise((resolve,reject)=>{const tx=db.transaction('cart','readwrite');tx.objectStore('cart').put({items:[new File(['private'],'private.cdr')],expires:Date.now()+86400000},'security-fixture');tx.oncomplete=resolve;tx.onerror=reject;});db.close();})()`); + await portal.click('#logout'); + await waitFor(()=>portal.eval('document.getElementById("logout").hidden'),'customer logout'); + let stored; + await waitFor(async()=>{stored=await portal.eval(`(async()=>{try{const db=await new Promise((resolve,reject)=>{const r=indexedDB.open('dtf-local-cart',1);r.onupgradeneeded=()=>r.result.createObjectStore('cart');r.onsuccess=()=>resolve(r.result);r.onerror=()=>reject(r.error);});const n=await new Promise((resolve,reject)=>{const r=db.transaction('cart').objectStore('cart').count();r.onsuccess=()=>resolve(r.result);r.onerror=()=>reject(r.error);});db.close();return n;}catch{return -1;}})()`);return stored>=0;},'IndexedDB available after Clear-Site-Data'); + assert.equal(stored,0); + assert.deepEqual(portal.errors,[]); + assert.deepEqual(site.errors,[]);assert.deepEqual(kanban.errors,[]); + console.log('PASS: browser Site upload → operator quote → local paid order → all main Kanban states → reload persistence. Order '+oid); + console.log('Screenshots: output/local/site.png and output/local/kanban.png'); + console.log('PASS: filename XSS escaping with CSP bypassed, no stored operator password, logout clears browser file blobs.'); +}catch(error){console.error(error);if(stderr)console.error(stderr.slice(-1500));process.exitCode=1;} +finally{for(const p of clients)p.ws.close();chrome.kill();} diff --git a/local/clamd.conf b/local/clamd.conf new file mode 100644 index 0000000..55c0d00 --- /dev/null +++ b/local/clamd.conf @@ -0,0 +1,15 @@ +Foreground yes +LogTime yes +DatabaseDirectory /var/lib/clamav +TCPSocket 3310 +TCPAddr 0.0.0.0 +MaxThreads 2 +MaxQueue 8 +StreamMaxLength 128M +MaxFileSize 128M +MaxScanSize 256M +MaxScanTime 120000 +AlertExceedsMax yes +AlertEncrypted yes +ScanPDF yes +ScanArchive yes diff --git a/local/compile_web.py b/local/compile_web.py new file mode 100644 index 0000000..a0c9340 --- /dev/null +++ b/local/compile_web.py @@ -0,0 +1,15 @@ +"""Hash only trusted source inline scripts at image build time for strict CSP.""" +import base64 +import hashlib +import os +from pathlib import Path +import re + +root=Path('/build') +hashes=[] +for html in [root/'dtf-site.html',*(root/'local/static').glob('*.html')]: + for attributes,body in re.findall(r']*)>(.*?)',html.read_text(),re.S|re.I): + if not re.search(r'\bsrc\s*=',attributes,re.I): + hashes.append("'sha256-"+base64.b64encode(hashlib.sha256(body.encode()).digest()).decode()+"'") +template=Path(os.environ.get('NGINX_TEMPLATE', root/'local/nginx.conf.template')).read_text() +(root/'default.conf.template').write_text(template.replace('@SCRIPT_HASHES@',' '.join(hashes))) diff --git a/local/customer.py b/local/customer.py new file mode 100644 index 0000000..28de74d --- /dev/null +++ b/local/customer.py @@ -0,0 +1,191 @@ +"""Customer portal and manual artwork handoff, composed into the local API.""" +from datetime import datetime, timedelta, timezone +from uuid import UUID, uuid4, uuid5, NAMESPACE_URL +from fastapi import Depends, HTTPException, Request, Response +from psycopg.errors import UniqueViolation +from psycopg.types.json import Jsonb +from . import db +from .auth import owner, session_row, new_session, password_hash, password_matches, transfer_guest, throttle, DUMMY_PASSWORD_HASH, audit +from .models import Register, Login, UploadStart, ArtworkSubmission +from .scanning import require_clean + +def install_routes(app, operator, storage, begin, status, part, complete, upload_row, states): + def current(request): + try: return session_row(request) + except HTTPException: return None + + @app.post('/api/account/register') + def register(body: Register, request: Request, response: Response): + email = body.customer.mail.strip().lower() + throttle(email, request) + previous = current(request) + encoded = password_hash(body.password) + identity = uuid4() + profile = body.customer.model_dump() + profile['mail'] = email + try: + with db.connect() as c: + if previous and c.execute('SELECT id FROM dtf_local.accounts WHERE id=%s', (previous['owner'],)).fetchone(): + raise HTTPException(409, 'Sign out before registering another account') + c.execute('INSERT INTO dtf_local.accounts(id,email,password_hash,profile) VALUES(%s,%s,%s,%s)', (identity,email,encoded,Jsonb(profile))) + if previous: transfer_guest(c, previous, identity) + new_session(c, response, identity) + except UniqueViolation: + raise HTTPException(409, 'An account already exists; sign in') + audit('account_registered', account=str(identity)) + return {'customer': profile} + + @app.post('/api/account/login') + def login(body: Login, request: Request, response: Response): + email = body.email.strip().lower() + throttle(email, request) + with db.connect() as c: + account = c.execute('SELECT * FROM dtf_local.accounts WHERE email=%s', (email,)).fetchone() + # Comparable password work even when the email is absent. + stored = account['password_hash'] if account else DUMMY_PASSWORD_HASH + matches = password_matches(body.password, stored) + if not account or not matches: + audit('customer_login_failed') + raise HTTPException(401, 'Invalid email or password') + previous = current(request) + with db.connect() as c: + if not stored.startswith('scrypt-v2$'): + c.execute('UPDATE dtf_local.accounts SET password_hash=%s WHERE id=%s', (password_hash(body.password),account['id'])) + if previous: + transfer_guest(c, previous, account['id']) + c.execute('DELETE FROM dtf_local.sessions WHERE id=%s', (previous['id'],)) + new_session(c, response, account['id']) + audit('customer_login_success', account=str(account['id'])) + return {'customer': account['profile']} + + @app.post('/api/account/logout') + def logout(request: Request, response: Response): + previous = current(request) + if previous: + with db.connect() as c: + c.execute('DELETE FROM dtf_local.sessions WHERE id=%s', (previous['id'],)) + response.delete_cookie('dtf_session', httponly=True, samesite='strict') + response.headers['Clear-Site-Data'] = '"storage"' + audit('customer_logout') + return {'ok': True} + + @app.get('/api/account/me') + def me(identity=Depends(owner)): + with db.connect() as c: + row = c.execute('SELECT profile FROM dtf_local.accounts WHERE id=%s', (identity,)).fetchone() + return {'customer': row['profile'] if row else None} + + def owned_order(c, oid, identity, lock=False): + row = c.execute('SELECT * FROM dtf_local.orders WHERE id=%s AND owner=%s'+(' FOR UPDATE' if lock else ''), (oid,identity)).fetchone() + if not row: raise HTTPException(404, 'Order not found') + return row + + def file_rows(c, oid): + return c.execute('''SELECT f.id,f.upload_id,f.item_index,f.kind,f.active,f.note,f.created_at, + u.name,u.size,u.expires_at,(u.expires_at<=now()) AS expired + FROM dtf_local.order_files f JOIN dtf_local.uploads u ON u.id=f.upload_id + WHERE order_id=%s ORDER BY f.created_at''', (oid,)).fetchall() + + @app.get('/api/customer/orders') + def orders(identity=Depends(owner)): + with db.connect() as c: + rows = c.execute('SELECT id,number,state,version,snapshot,created_at,updated_at FROM dtf_local.orders WHERE owner=%s ORDER BY created_at DESC', (identity,)).fetchall() + quotes = c.execute('''SELECT q.id,q.approved,q.approved_at,q.created_at FROM dtf_local.quotes q + LEFT JOIN dtf_local.orders o ON o.quote_id=q.id WHERE q.owner=%s AND o.id IS NULL ORDER BY q.created_at DESC''', (identity,)).fetchall() + return {'orders': rows, 'quotes': quotes, 'states': states} + + @app.get('/api/customer/orders/{oid}') + def detail(oid: UUID, identity=Depends(owner)): + with db.connect() as c: + row = owned_order(c, oid, identity) + history = c.execute('SELECT from_state,to_state,reason,created_at FROM dtf_local.movements WHERE order_id=%s ORDER BY id', (oid,)).fetchall() + return {'id': row['id'], 'number': row['number'], 'state': row['state'], 'version': row['version'], + 'snapshot': row['snapshot'], 'history': history, 'files': file_rows(c,oid)} + + def submit_files(c, order, body, identity, kind, actor): + if order['version'] != body.version: + raise HTTPException(409, 'Order changed. Refresh before submitting files.') + if kind == 'final' and order['state'] not in ('rec','tra','cor'): + raise HTTPException(409, 'Final files can only change during artwork review') + if kind == 'correction' and order['state'] != 'cor': + raise HTTPException(409, 'This order is not awaiting artwork correction') + if len({f.upload_id for f in body.files}) != len(body.files): + raise HTTPException(422, 'Each uploaded file must appear once') + count = len(order['snapshot']['items']) + if any(f.item_index >= count for f in body.files): + raise HTTPException(422, 'Invalid order item') + if kind == 'final' and {f.item_index for f in body.files} != set(range(count)): + raise HTTPException(422, 'Final-file set must cover every order item') + original_ids = [UUID(uid) for item in order['snapshot']['items'] for uid in item['uploads']] + first = c.execute('SELECT min(created_at) AS first FROM dtf_local.uploads WHERE id=ANY(%s)', (original_ids,)).fetchone()['first'] + expiry = first + timedelta(days=30) + if expiry <= datetime.now(timezone.utc): + raise HTTPException(410, 'Order artwork retention has expired') + for ref in body.files: + upload = upload_row(c, ref.upload_id, identity, lock=True) + if not upload['complete']: + raise HTTPException(409, 'Complete all uploads first') + require_clean(upload) + if c.execute('SELECT id FROM dtf_local.order_files WHERE upload_id=%s', (ref.upload_id,)).fetchone(): + raise HTTPException(409, 'File is already attached. Upload a new revision.') + c.execute('UPDATE dtf_local.order_files SET active=false WHERE order_id=%s AND kind=%s', (order['id'],kind)) + for ref in body.files: + c.execute('INSERT INTO dtf_local.order_files(id,order_id,upload_id,item_index,kind,note,created_by) VALUES(%s,%s,%s,%s,%s,%s,%s)', + (uuid4(),order['id'],ref.upload_id,ref.item_index,kind,body.note,actor)) + c.execute('UPDATE dtf_local.uploads SET expires_at=LEAST(expires_at,%s) WHERE id=%s', (expiry,ref.upload_id)) + c.execute('UPDATE dtf_local.orders SET version=version+1,updated_at=now() WHERE id=%s', (order['id'],)) + if kind == 'final': + # Artwork approval, not commercial quote approval, starts original cleanup. + c.execute("UPDATE dtf_local.uploads SET expires_at=LEAST(expires_at,now()+interval '7 days') WHERE id=ANY(%s)", (original_ids,)) + return {'ok': True, 'version': order['version']+1, 'expires_at': expiry} + + @app.post('/api/customer/orders/{oid}/corrections') + def correction(oid: UUID, body: ArtworkSubmission, identity=Depends(owner)): + with db.connect() as c: + order = owned_order(c, oid, identity, lock=True) + return submit_files(c,order,body,identity,'correction','customer') + + @app.get('/api/customer/orders/{oid}/files/{fid}/download') + def customer_download(oid: UUID, fid: UUID, identity=Depends(owner)): + with db.connect() as c: + owned_order(c,oid,identity) + row = c.execute('SELECT u.* FROM dtf_local.order_files f JOIN dtf_local.uploads u ON u.id=f.upload_id WHERE f.id=%s AND f.order_id=%s AND f.active', (fid,oid)).fetchone() + if not row: raise HTTPException(404, 'Active file not found') + if row['expires_at'] <= datetime.now(timezone.utc): raise HTTPException(410, 'File expired') + require_clean(row) + return {'url':storage.download(row['object_key'],row['name']), 'name':row['name']} + + def operator_identity(user): + return uuid5(NAMESPACE_URL, 'dtf-local-operator:'+user) + + @app.post('/api/operator/orders/{oid}/uploads') + def begin_final(oid: UUID, body: UploadStart, user=Depends(operator)): + with db.connect() as c: + row = c.execute('SELECT state FROM dtf_local.orders WHERE id=%s', (oid,)).fetchone() + if not row: raise HTTPException(404, 'Order not found') + if row['state'] not in ('rec','tra','cor'): raise HTTPException(409, 'Order is not in artwork review') + return begin(body, session_id=operator_identity(user)) + + @app.get('/api/operator/uploads/{uid}') + def final_status(uid: UUID, user=Depends(operator)): + return status(uid,session_id=operator_identity(user)) + + @app.post('/api/operator/uploads/{uid}/parts/{number}') + def final_part(uid: UUID, number: int, user=Depends(operator)): + return part(uid,number,session_id=operator_identity(user)) + + @app.post('/api/operator/uploads/{uid}/complete') + def final_complete(uid: UUID, user=Depends(operator)): + return complete(uid,session_id=operator_identity(user)) + + @app.get('/api/operator/orders/{oid}/files') + def operator_files(oid: UUID, user=Depends(operator)): + with db.connect() as c: + return file_rows(c,oid) + + @app.post('/api/operator/orders/{oid}/final-files') + def final_files(oid: UUID, body: ArtworkSubmission, user=Depends(operator)): + with db.connect() as c: + order = c.execute('SELECT * FROM dtf_local.orders WHERE id=%s FOR UPDATE', (oid,)).fetchone() + if not order: raise HTTPException(404, 'Order not found') + return submit_files(c,order,body,operator_identity(user),'final',user) diff --git a/local/db.py b/local/db.py new file mode 100644 index 0000000..d16df74 --- /dev/null +++ b/local/db.py @@ -0,0 +1,12 @@ +import os +from pathlib import Path +import psycopg +from psycopg.rows import dict_row + +def connect(): + return psycopg.connect(os.environ['DATABASE_URL'], row_factory=dict_row) + +def initialize(): + with connect() as c: + c.execute(Path(__file__).with_name('schema.sql').read_text()) + diff --git a/local/dependency_audit.py b/local/dependency_audit.py new file mode 100644 index 0000000..aded9f8 --- /dev/null +++ b/local/dependency_audit.py @@ -0,0 +1,24 @@ +"""Audit exact installed API packages, not a host-dependent re-resolution. + +Install pip-audit in an isolated environment; pass its executable as argv[1]. +Only package names/versions are sent to the public vulnerability database. +""" +import json +from pathlib import Path +import subprocess +import sys + +if __name__=='__main__': + packages=json.loads(subprocess.check_output(['docker','compose','exec','-T','api','pip','list','--format=json'],text=True)) + requirements='\n'.join(p['name']+'=='+p['version'] for p in packages)+'\n' + destination=Path('output/security');destination.mkdir(parents=True,exist_ok=True) + (destination/'runtime-requirements.txt').write_text(requirements) + result=subprocess.run([sys.argv[1] if len(sys.argv)>1 else 'pip-audit','--no-deps','--disable-pip', + '--progress-spinner','off','-r',str(destination/'runtime-requirements.txt'), + '-f','json','-o',str(destination/'python-audit.json')]) + if (destination/'python-audit.json').exists(): + data=json.loads((destination/'python-audit.json').read_text()) + for package in data['dependencies']: + for vulnerability in package.get('vulns',[]): + print(package['name'],package['version'],vulnerability['id'],'fix:',','.join(vulnerability['fix_versions'])) + sys.exit(result.returncode) diff --git a/local/fixtures/local-test.cdr b/local/fixtures/local-test.cdr new file mode 100644 index 0000000..883c27d --- /dev/null +++ b/local/fixtures/local-test.cdr @@ -0,0 +1,4 @@ +DTF LOCAL UPLOAD TEST ONLY +This is a harmless text fixture with a .cdr extension, not printable artwork. +Use the manual-length path: 1.01 metres, grade 0, pickup = BRL 21.89. +It intentionally requires no artwork parsing or automatic pre-flight. diff --git a/local/lock_dependencies.sh b/local/lock_dependencies.sh new file mode 100755 index 0000000..8a397ce --- /dev/null +++ b/local/lock_dependencies.sh @@ -0,0 +1,13 @@ +#!/bin/sh +set -eu + +root=$(CDPATH= cd -- "$(dirname "$0")/.." && pwd) + +docker run --rm \ + --user "$(id -u):$(id -g)" \ + --env HOME=/tmp \ + --env CUSTOM_COMPILE_COMMAND=./local/lock_dependencies.sh \ + --volume "$root:/src" \ + --workdir /src \ + python:3.12-slim \ + sh -c 'python -m pip install --no-cache-dir --target /tmp/piptools pip==25.3 pip-tools==7.5.2 && PYTHONPATH=/tmp/piptools python -m piptools compile --generate-hashes --allow-unsafe --strip-extras --no-emit-index-url --output-file local/requirements.lock local/requirements.txt' diff --git a/local/models.py b/local/models.py new file mode 100644 index 0000000..70dbace --- /dev/null +++ b/local/models.py @@ -0,0 +1,101 @@ +import re +from decimal import Decimal +from typing import Literal +from uuid import UUID +from pydantic import BaseModel, ConfigDict, Field, field_validator + +class StrictModel(BaseModel): + model_config = ConfigDict(extra='forbid', allow_inf_nan=False) + +class Customer(StrictModel): + cnpj: str + zap: str + mail: str = Field(max_length=254) + + @field_validator('cnpj') + @classmethod + def cnpj_valid(cls, value): + digits = re.sub(r'\D', '', value) + if len(digits) != 14 or len(set(digits)) == 1 or not digits.isascii(): + raise ValueError('Invalid CNPJ') + def check(base, weights): + rem = sum(int(n) * w for n,w in zip(base, weights)) % 11 + return 0 if rem < 2 else 11-rem + if check(digits[:12], [5,4,3,2,9,8,7,6,5,4,3,2]) != int(digits[12]) or check(digits[:13], [6,5,4,3,2,9,8,7,6,5,4,3,2]) != int(digits[13]): + raise ValueError('Invalid CNPJ') + return digits + + @field_validator('zap') + @classmethod + def phone_valid(cls, value): + digits = re.sub(r'\D', '', value) + if len(digits) not in (10,11) or not digits.isascii(): + raise ValueError('Invalid phone') + return digits + + @field_validator('mail') + @classmethod + def email_valid(cls, value): + if not re.fullmatch(r'[^\s@]+@[^\s@]+\.[a-zA-Z]{2,}', value.strip()): + raise ValueError('Invalid email') + return value.strip() + +class Freight(StrictModel): + service: Literal['pickup','mock-standard'] = 'pickup' + postal_code: str = Field(default='', max_length=8) + +class UploadStart(StrictModel): + name: str = Field(min_length=1, max_length=200, pattern=r'^[^/\\\x00-\x1f]+$') + size: int = Field(gt=0, strict=True) + + @field_validator('name') + @classmethod + def artwork_extension(cls, value): + # Union of existing Site product formats; this is NOT malware/pre-flight validation. + if not re.search(r'\.(png|jpe?g|webp|tiff?|pdf|psd|psb|ai|cdr)$', value, re.I): + raise ValueError('Unsupported artwork file extension') + return value + +class Item(StrictModel): + mode: Literal['file','avulsa','uvfile','uv'] + metres: Decimal = Field(gt=0, le=12000) + grade: int = Field(ge=0, le=100, strict=True) + uploads: list[UUID] = Field(min_length=1, max_length=20) + +class QuoteRequest(StrictModel): + request_key: UUID + customer: Customer + items: list[Item] = Field(min_length=1, max_length=30) + freight: Freight + +class Review(StrictModel): + items: list[Item] = Field(min_length=1, max_length=30) + +class Pay(StrictModel): + quote_id: UUID + +class Move(StrictModel): + state: Literal['rec','tra','fil','imp','cor','fin'] + version: int = Field(ge=0) + reason: str = Field(default='', max_length=1000) + +class Register(StrictModel): + customer: Customer + password: str = Field(min_length=12, max_length=128) + +class Login(StrictModel): + email: str = Field(min_length=3, max_length=254) + password: str = Field(min_length=1, max_length=128) + +class OperatorLogin(StrictModel): + username: str = Field(min_length=1, max_length=100) + password: str = Field(min_length=1, max_length=128) + +class FileReference(StrictModel): + upload_id: UUID + item_index: int = Field(ge=0, strict=True) + +class ArtworkSubmission(StrictModel): + version: int = Field(ge=0, strict=True) + files: list[FileReference] = Field(min_length=1, max_length=60) + note: str = Field(min_length=1, max_length=1000) diff --git a/local/nginx.conf.template b/local/nginx.conf.template new file mode 100644 index 0000000..d97d99c --- /dev/null +++ b/local/nginx.conf.template @@ -0,0 +1,34 @@ +limit_req_zone $binary_remote_addr zone=api_limit:10m rate=20r/s; +server { + listen 80; + server_name localhost; + if ($host !~ ^(localhost|127\.0\.0\.1)$) { return 400; } + root /usr/share/nginx/html; + index ${WEB_INDEX}; + add_header X-Content-Type-Options nosniff always; + add_header Referrer-Policy no-referrer always; + add_header X-Frame-Options DENY always; + add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always; + add_header Content-Security-Policy "default-src 'self'; script-src 'self' @SCRIPT_HASHES@ https://cdnjs.cloudflare.com; script-src-attr 'none'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob: https://cdn.vnda.com.br; connect-src 'self' ${S3_PUBLIC_ENDPOINT} https://cdn.vnda.com.br https://cdnjs.cloudflare.com; worker-src 'self' blob: https://cdnjs.cloudflare.com; object-src 'none'; base-uri 'none'; frame-ancestors 'none'; form-action 'self'" always; + location = /health { access_log off; return 200 'ok'; } + location /api/ { + limit_req zone=api_limit burst=100 nodelay; + limit_req_status 429; + proxy_pass http://api:8000; + proxy_set_header Host $http_host; + client_max_body_size 2m; + } + location / { try_files $uri $uri/ =404; } +} +server { + listen 81; + server_name localhost; + if ($host !~ ^(localhost|127\.0\.0\.1)$) { return 400; } + client_max_body_size 2m; + location / { + limit_req zone=api_limit burst=100 nodelay; + limit_req_status 429; + proxy_pass http://api:8000; + proxy_set_header Host $http_host; + } +} diff --git a/local/pricing.py b/local/pricing.py new file mode 100644 index 0000000..e9e1d05 --- /dev/null +++ b/local/pricing.py @@ -0,0 +1,27 @@ +"""Exact approved Site DTF price ladders; integer BRL cents at the boundary. + +Quantity/grade must be supplied by an authenticated commercial reviewer. +This module does not inspect artwork or perform pre-flight. +""" +from decimal import Decimal, ROUND_CEILING + +TIERS = { + 'file': [(90,1490),(75,1620),(60,1750),(40,1870),(0,1990)], + 'avulsa': [(90,2490),(75,2620),(60,2750),(40,2870),(0,2990)], + 'uvfile': [(90,6990),(75,7390),(60,7790),(40,8190),(0,8590)], + 'uv': [(90,8390),(75,8790),(60,9190),(40,9590),(0,9990)], +} + +def price(mode: str, metres: str, grade: int) -> dict: + length = Decimal(str(metres)) + if mode not in TIERS or not length.is_finite() or not 0 < length <= 12000: + raise ValueError('Invalid product or length') + if isinstance(grade, bool) or not isinstance(grade, int) or not 0 <= grade <= 100: + raise ValueError('Grade must be an integer between 0 and 100') + billed = max(Decimal('1'), (length * 10).to_integral_value(rounding=ROUND_CEILING) / 10) + unit = next(cents for minimum, cents in TIERS[mode] if grade >= minimum) + return {'mode': mode, 'metres': str(length), 'grade': grade, + 'billed_metres': str(billed), 'unit_cents': unit, + 'total_cents': int(billed * unit), + 'discount_cents': int(billed * (TIERS[mode][-1][1] - unit))} + diff --git a/local/requirements.lock b/local/requirements.lock new file mode 100644 index 0000000..76007d0 --- /dev/null +++ b/local/requirements.lock @@ -0,0 +1,316 @@ +# +# This file is autogenerated by pip-compile with Python 3.12 +# by the following command: +# +# ./local/lock_dependencies.sh +# +annotated-doc==0.0.5 \ + --hash=sha256:117bac03a25ede5df5440e855b32d556049ca169ead221505badf432fed4b101 \ + --hash=sha256:c7e58ce09192557605d8bbd92836d7e1d520ac9580096042c0bfd197efacf1bb + # via fastapi +annotated-types==0.8.0 \ + --hash=sha256:13b2beaad985e05e2d6407ee4c4f35590b11f8d693a258a561055cac8f64cab7 \ + --hash=sha256:f072f4d804ea359e4eaf198b1af7a8b0943881a87f31bb764f8bf219bb9419e0 + # via pydantic +anyio==4.15.1 \ + --hash=sha256:6152fdbbf9a77fdec97731721bebf7c4c44f7c29b424b0065826173efc7ed101 \ + --hash=sha256:9f28306018cbd6d329e64a36d58256edff76dd996fe423bc957326e578b82a94 + # via + # httpx + # starlette +boto3==1.38.23 \ + --hash=sha256:70ab8364f1f6f0a7e0eaf97f62fbdacf9c1e4cc1de330faf1c146ef9ab01e7d0 \ + --hash=sha256:bcf73aca469add09e165b8793be18e7578db8d2604d82505ab13dc2495bad982 + # via -r local/requirements.txt +botocore==1.38.46 \ + --hash=sha256:8798e5a418c27cf93195b077153644aea44cb171fcd56edc1ecebaa1e49e226e \ + --hash=sha256:89ca782ffbf2e8769ca9c89234cfa5ca577f1987d07d913ee3c68c4776b1eb5b + # via + # boto3 + # s3transfer +certifi==2026.7.22 \ + --hash=sha256:62f22742b58a1a33014a2b6b706588a8d7e2a88ae7bd1a6ebe8c992928483775 \ + --hash=sha256:741e2c3b351ddf169a738da9f2c048608ff7f2c5cc02f1ebc6b118bb090d5d55 + # via + # httpcore + # httpx +click==8.5.0 \ + --hash=sha256:255bc9599cf7748b4b1a446ccc735421bd08a2ae529a8b88597d3de5664ee360 \ + --hash=sha256:ba0d2089de75ea0310e2dde03160e6ca10009947fb95a182f9b54021bb272e34 + # via uvicorn +fastapi==0.141.1 \ + --hash=sha256:bfb91aa2d334c61cb35ba9a116fc123b3d3df31640b801cf57a7a78ec3f603b3 \ + --hash=sha256:e8822fc40db1e1858054d7a949a888695bc9bdce70139178e33bd2871a453ca1 + # via -r local/requirements.txt +h11==0.16.0 \ + --hash=sha256:4e35b956cf45792e4caa5885e69fba00bdbc6ffafbfa020300e549b208ee5ff1 \ + --hash=sha256:63cf8bbe7522de3bf65932fda1d9c2772064ffb3dae62d55932da54b31cb6c86 + # via + # httpcore + # uvicorn +httpcore==1.0.9 \ + --hash=sha256:2d400746a40668fc9dec9810239072b40b4484b640a8c38fd654a024c7a1bf55 \ + --hash=sha256:6e34463af53fd2ab5d807f399a9b45ea31c3dfa2276f15a2c3f00afff6e176e8 + # via httpx +httpx==0.28.1 \ + --hash=sha256:75e98c5f16b0f35b567856f597f06ff2270a374470a5c2392242528e3e3e42fc \ + --hash=sha256:d909fcccc110f8c7faf814ca82a9a4d816bc5a6dbfea25d6591d6985b8ba59ad + # via -r local/requirements.txt +idna==3.19 \ + --hash=sha256:5e0811a4383b21dc5838069f801c4fb62113b7447663d2530d2bd6e77b49bf15 \ + --hash=sha256:815e7be7a7806d54abb586dc943addc79e8b2ee16915059658cbeff4b1b43bf4 + # via + # anyio + # httpx +jmespath==1.1.0 \ + --hash=sha256:472c87d80f36026ae83c6ddd0f1d05d4e510134ed462851fd5f754c8c3cbb88d \ + --hash=sha256:a5663118de4908c91729bea0acadca56526eb2698e83de10cd116ae0f4e97c64 + # via + # boto3 + # botocore +psycopg==3.2.9 \ + --hash=sha256:01a8dadccdaac2123c916208c96e06631641c0566b22005493f09663c7a8d3b6 \ + --hash=sha256:2fbb46fcd17bc81f993f28c47f1ebea38d66ae97cc2dbc3cad73b37cefbff700 + # via -r local/requirements.txt +psycopg-binary==3.2.9 \ + --hash=sha256:001e986656f7e06c273dd4104e27f4b4e0614092e544d950c7c938d822b1a894 \ + --hash=sha256:08bf9d5eabba160dd4f6ad247cf12f229cc19d2458511cab2eb9647f42fa6795 \ + --hash=sha256:093a0c079dd6228a7f3c3d82b906b41964eaa062a9a8c19f45ab4984bf4e872b \ + --hash=sha256:0e8aeefebe752f46e3c4b769e53f1d4ad71208fe1150975ef7662c22cca80fab \ + --hash=sha256:14f64d1ac6942ff089fc7e926440f7a5ced062e2ed0949d7d2d680dc5c00e2d4 \ + --hash=sha256:166acc57af5d2ff0c0c342aed02e69a0cd5ff216cae8820c1059a6f3b7cf5f78 \ + --hash=sha256:18ac08475c9b971237fcc395b0a6ee4e8580bb5cf6247bc9b8461644bef5d9f4 \ + --hash=sha256:1b2cf018168cad87580e67bdde38ff5e51511112f1ce6ce9a8336871f465c19a \ + --hash=sha256:1ed2bab85b505d13e66a914d0f8cdfa9475c16d3491cf81394e0748b77729af2 \ + --hash=sha256:1f1736d5b21f69feefeef8a75e8d3bf1f0a1e17c165a7488c3111af9d6936e91 \ + --hash=sha256:2290bc146a1b6a9730350f695e8b670e1d1feb8446597bed0bbe7c3c30e0abcb \ + --hash=sha256:24ddb03c1ccfe12d000d950c9aba93a7297993c4e3905d9f2c9795bb0764d523 \ + --hash=sha256:2504e9fd94eabe545d20cddcc2ff0da86ee55d76329e1ab92ecfcc6c0a8156c4 \ + --hash=sha256:25ab464bfba8c401f5536d5aa95f0ca1dd8257b5202eede04019b4415f491351 \ + --hash=sha256:354dea21137a316b6868ee41c2ae7cce001e104760cf4eab3ec85627aed9b6cd \ + --hash=sha256:387c87b51d72442708e7a853e7e7642717e704d59571da2f3b29e748be58c78a \ + --hash=sha256:39a127e0cf9b55bd4734a8008adf3e01d1fd1cb36339c6a9e2b2cbb6007c50ee \ + --hash=sha256:3db3ba3c470801e94836ad78bf11fd5fab22e71b0c77343a1ee95d693879937a \ + --hash=sha256:413f9e46259fe26d99461af8e1a2b4795a4e27cc8ac6f7919ec19bcee8945074 \ + --hash=sha256:418f52b77b715b42e8ec43ee61ca74abc6765a20db11e8576e7f6586488a266f \ + --hash=sha256:4bfec4a73e8447d8fe8854886ffa78df2b1c279a7592241c2eb393d4499a17e2 \ + --hash=sha256:4c1ab25e3134774f1e476d4bb9050cdec25f10802e63e92153906ae934578734 \ + --hash=sha256:4df22ec17390ec5ccb38d211fb251d138d37a43344492858cea24de8efa15003 \ + --hash=sha256:528239bbf55728ba0eacbd20632342867590273a9bacedac7538ebff890f1093 \ + --hash=sha256:52e239cd66c4158e412318fbe028cd94b0ef21b0707f56dcb4bdc250ee58fd40 \ + --hash=sha256:587a3f19954d687a14e0c8202628844db692dbf00bba0e6d006659bf1ca91cbe \ + --hash=sha256:5918c0fab50df764812f3ca287f0d716c5c10bedde93d4da2cefc9d40d03f3aa \ + --hash=sha256:5be8292d07a3ab828dc95b5ee6b69ca0a5b2e579a577b39671f4f5b47116dfd2 \ + --hash=sha256:5d2c9fe14fe42b3575a0b4e09b081713e83b762c8dc38a3771dd3265f8f110e7 \ + --hash=sha256:61d0a6ceed8f08c75a395bc28cb648a81cf8dee75ba4650093ad1a24a51c8724 \ + --hash=sha256:6a76b4722a529390683c0304501f238b365a46b1e5fb6b7249dbc0ad6fea51a0 \ + --hash=sha256:6afb3e62f2a3456f2180a4eef6b03177788df7ce938036ff7f09b696d418d186 \ + --hash=sha256:72691a1615ebb42da8b636c5ca9f2b71f266be9e172f66209a361c175b7842c5 \ + --hash=sha256:72fdbda5b4c2a6a72320857ef503a6589f56d46821592d4377c8c8604810342b \ + --hash=sha256:76eddaf7fef1d0994e3d536ad48aa75034663d3a07f6f7e3e601105ae73aeff6 \ + --hash=sha256:778588ca9897b6c6bab39b0d3034efff4c5438f5e3bd52fda3914175498202f9 \ + --hash=sha256:791759138380df21d356ff991265fde7fe5997b0c924a502847a9f9141e68786 \ + --hash=sha256:799fa1179ab8a58d1557a95df28b492874c8f4135101b55133ec9c55fc9ae9d7 \ + --hash=sha256:7a838852e5afb6b4126f93eb409516a8c02a49b788f4df8b6469a40c2157fa21 \ + --hash=sha256:7b617b81f08ad8def5edd110de44fd6d326f969240cc940c6f6b3ef21fe9c59f \ + --hash=sha256:7e4660fad2807612bb200de7262c88773c3483e85d981324b3c647176e41fdc8 \ + --hash=sha256:7fc2915949e5c1ea27a851f7a472a7da7d0a40d679f0a31e42f1022f3c562e87 \ + --hash=sha256:95315b8c8ddfa2fdcb7fe3ddea8a595c1364524f512160c604e3be368be9dd07 \ + --hash=sha256:96a551e4683f1c307cfc3d9a05fec62c00a7264f320c9962a67a543e3ce0d8ff \ + --hash=sha256:98bbe35b5ad24a782c7bf267596638d78aa0e87abc7837bdac5b2a2ab954179e \ + --hash=sha256:a1fa38a4687b14f517f049477178093c39c2a10fdcced21116f47c017516498f \ + --hash=sha256:a3e0f89fe35cb03ff1646ab663dabf496477bab2a072315192dbaa6928862891 \ + --hash=sha256:a4d76e28df27ce25dc19583407f5c6c6c2ba33b443329331ab29b6ef94c8736d \ + --hash=sha256:ac2c04b6345e215e65ca6aef5c05cc689a960b16674eaa1f90a8f86dfaee8c04 \ + --hash=sha256:ad280bbd409bf598683dda82232f5215cfc5f2b1bf0854e409b4d0c44a113b1d \ + --hash=sha256:b2d7a6646d41228e9049978be1f3f838b557a1bde500b919906d54c4390f5086 \ + --hash=sha256:b7e4e4dd177a8665c9ce86bc9caae2ab3aa9360b7ce7ec01827ea1baea9ff748 \ + --hash=sha256:bb37ac3955d19e4996c3534abfa4f23181333974963826db9e0f00731274b695 \ + --hash=sha256:bc75f63653ce4ec764c8f8c8b0ad9423e23021e1c34a84eb5f4ecac8538a4a4a \ + --hash=sha256:be7d650a434921a6b1ebe3fff324dbc2364393eb29d7672e638ce3e21076974e \ + --hash=sha256:cc19ed5c7afca3f6b298bfc35a6baa27adb2019670d15c32d0bb8f780f7d560d \ + --hash=sha256:cf789be42aea5752ee396d58de0538d5fcb76795c85fb03ab23620293fb81b6f \ + --hash=sha256:d9ac10a2ebe93a102a326415b330fff7512f01a9401406896e78a81d75d6eddc \ + --hash=sha256:e0f05b9dafa5670a7503abc715af081dbbb176a8e6770de77bccaeb9024206c5 \ + --hash=sha256:e4978c01ca4c208c9d6376bd585e2c0771986b76ff7ea518f6d2b51faece75e8 \ + --hash=sha256:eac3a6e926421e976c1c2653624e1294f162dc67ac55f9addbe8f7b8d08ce603 \ + --hash=sha256:f0d5b3af045a187aedbd7ed5fc513bd933a97aaff78e61c3745b330792c4345b \ + --hash=sha256:f34e88940833d46108f949fdc1fcfb74d6b5ae076550cd67ab59ef47555dba95 \ + --hash=sha256:fa5c80d8b4cbf23f338db88a7251cef8bb4b68e0f91cf8b6ddfa93884fdbb0c1 \ + --hash=sha256:fb7599e436b586e265bea956751453ad32eb98be6a6e694252f4691c31b16edb + # via psycopg +pydantic==2.13.5 \ + --hash=sha256:346a034f080da3755d8e9cb5e00e8b07de1d39e4f6e2c87d8ab7cafa0b269a73 \ + --hash=sha256:51a9c5f7b2f8e636f04c6cada605d9b6a3bf1348fdf945a3d8869b19bba0ee08 + # via fastapi +pydantic-core==2.46.5 \ + --hash=sha256:013d6f3483d81e02e7c328831808f336c8596ee33b4bd4026b9ffb1e960b8942 \ + --hash=sha256:03b9666e41e35d8909852ba191a0607520f81b74eaf12ccf8737005dbb313821 \ + --hash=sha256:045ab3b6d308439e32b81cc173bba5b9018bc6ed896afd0c65b3b009b1699af5 \ + --hash=sha256:0bddb4020d8f04175865ccd17eff3040874fc11fb593f424edb452653b4b947c \ + --hash=sha256:0cdbada856a1c69a7624a64d3d9aefe79300bd6ef827b43a4f265010b9b55184 \ + --hash=sha256:0fc5be0abd4a407e200d844b404e33639a554e7bd0d448e7b9ae181be4789ac2 \ + --hash=sha256:10416c15b8839ecc4ef4d0885da76da6fd0f67333a0eb8aff6d93c4b8f2910fc \ + --hash=sha256:15f4a94963c95accac15b7b657bb177d3ad82bb90b0d0526d9a9b85079925db5 \ + --hash=sha256:18a09e1e1011b462f2e32774f25859ef1223d5c2b0546a633cf56654710721e0 \ + --hash=sha256:193375f3548919d3f0b60936ca113ada3e38f264f91b9b8e0508efaad57be931 \ + --hash=sha256:1a353f84de772f423b5ffb11d7ae352fbbef0f446f3c0b0af0f8236d7233606e \ + --hash=sha256:1e449def1945a462c464331254e5a44fca7c3b4f9aedf59ec2f50f8066dd8e25 \ + --hash=sha256:1e5aad1220a1192c42341c8fd4a8686657e73ab2a920c970bdc4de334fe3193d \ + --hash=sha256:200aa3dc9f8d54f0754f43247c0bad0999fdcfbfd2488384dd44f37279271fe6 \ + --hash=sha256:2471fd51c61c610e1dcf7de44d7299283661654d11264ab4802b303368d69c47 \ + --hash=sha256:24922243639cbdac66c75fcb6fd6495a9cb52b213d62f9a0d16f0310b1ff8038 \ + --hash=sha256:28a6a556cd3b6066bea827857f9d9cce027c96f776e512f544a581f9e42161f8 \ + --hash=sha256:2bc9419666990c06d7397831f2126a1ecc3594aaa3ff7de5bf2d066802f4e07b \ + --hash=sha256:2cbd9a5eff05e51c447c34dfa4632145b26b09120cf04bd0c871e44c1a5e1c9a \ + --hash=sha256:2d330aaba8621b1edcec8ae2c4050f63b84ccf6d98723a8f212e9684713abf0e \ + --hash=sha256:2d5d76654becf5efd62c9e51c3756c67b49498b0c9a40884934c40807adbd074 \ + --hash=sha256:337639ba62a11acde6ef3aeb08c8ea755f8ef1fe5e513356c0f36a2b0d7568b0 \ + --hash=sha256:347ec774390c87326a2e4929d58d3f7e8763a104d5d35f4cd595a4c952366433 \ + --hash=sha256:356c8368cbc321050b169595683a2e1d63413b1e0e2868b330af9fc14c616d3f \ + --hash=sha256:37ae34309d7bd8c0d61ab839668058f2a7962ea1fc51d105d2db228fe0618034 \ + --hash=sha256:37ea7b83c935e5b0d68c9449b82651accf78a10828b2c02b2f2d9e9496446c21 \ + --hash=sha256:3a3e26b6a8274211bddee2d0e4d0d42778f17a34510f49d2ec44b58abfc41736 \ + --hash=sha256:3aa166e99c4f2985407fb8714aebede877ecb5455cf321b606adca926d30d5a0 \ + --hash=sha256:3d2652072b2d774947ba5cf78a9e59644ac62ee572daf6dd2e1dfe905e15b2b7 \ + --hash=sha256:40375c2d05acec10323e45dfe2077ac44bc74659008614af5069034e2cfc781c \ + --hash=sha256:413a717a410d0c817ef5b786a059415550b3794e1d0c2abffd9efb93a3d9f7b4 \ + --hash=sha256:46c25dda9d092a06c08db76ffe0a197107904d0dfac653f7d5306bbcd6d6119c \ + --hash=sha256:49776eab08766a08dfff7012f8b422dcd7e25e43b316eedf0477c24fcfa84b7c \ + --hash=sha256:4d44cf99ddebf875f9b68cc267aa684c99b7b44fe63ee1cac4ec163807290069 \ + --hash=sha256:4dedce55295becb61921e386b99d4f2706045306e7fa52249a33004c837379fb \ + --hash=sha256:4f8507560a9284e1370bb048ed4282012fbef4e8d109875b95e884d228552061 \ + --hash=sha256:4fdc8b93a41521988916eeaa271173fcca7fa0803d62f87675aac8dcec1c8e29 \ + --hash=sha256:5086029a57366b8cf81b130a43908738095c270c21a8d7f0e8bdfdb89718e2f3 \ + --hash=sha256:52e24eacdb536cade636aa90fb851835222becff8484b7001fdc78cb0290f2aa \ + --hash=sha256:53feb344243bb9510a9dec7bf3cf1b64d88a98af5dc7872a5160465f8b198c8e \ + --hash=sha256:545f26c504b27c3758439a5e6d9349931f0a04f855668d5fe323c89e82300a38 \ + --hash=sha256:54d510bac3ee52247af28ed4bb18a1e799f040ac60fd2bf5ccd4c92f1fbe786f \ + --hash=sha256:5cb482e9e84c851f4e623fe4acc1ced89168cf1fe18f7089db4548c8f5bbb65b \ + --hash=sha256:5e81740c09e310f5aa5cbd3e434a01c154d4bef93241c7877b39f211d2b78ba8 \ + --hash=sha256:5ee239d575f80b08eca11f6e20f90c4c695de7825c67eefe6091fbf20dda648e \ + --hash=sha256:5f194189415698233dd1114a093a9b56e61e2c57e11b469be3b0506f46f0771c \ + --hash=sha256:5f93c5fe914d75fbec9a49209b00da5f08e9e467d69da2b1510c81940cfd10be \ + --hash=sha256:657b40d6240c0a7b6a64b30f22d1e3aa631c7e846c621b0c0f6d1d75e2e15ea6 \ + --hash=sha256:6d30e1a4f138b8951063e9a394752a9179b51da288ffa507b1e659222f4c1793 \ + --hash=sha256:6f7b393a8b3da82f5c1fc0751e6d01ac6c55b93c18226a60bdfba4a724efafd1 \ + --hash=sha256:701b2e04b560eeb4bddf7a25ab8ca476176e34fdbd9a0e18196f0d12d4685f0b \ + --hash=sha256:771cf63ae0b1b50dd22e5f3e3549fab5f3f4ff1635d352a9e1a97fe01c7b2e64 \ + --hash=sha256:79bdfa52f843137045b2d081cc05c120ba6665d29b7559c2c47690906f39279f \ + --hash=sha256:7ac031912d54f3d83ef3b3eb98dfabc1608802e2202263d25957eeed40b94761 \ + --hash=sha256:7b0fc826b16c55e561e5d2a0c5c77b051ba1d92808118c4e4b5390f5e0cf191d \ + --hash=sha256:7c6be839a5a8312626b32029a415644a0846b420bc8b52b95b28cd92da162168 \ + --hash=sha256:816ff0a6550ffc06c098ccd2e0698600f9aa7da192a79eaa6f9af504a35db869 \ + --hash=sha256:82a36973cf8a2ef5406f4fe2edbf8ed0c99629535d959e0b100c76a32535a111 \ + --hash=sha256:837b396ca3d7b74091ca623f6cbd8351bd42d670a79c2683e79fb089f06a2de5 \ + --hash=sha256:850a08d167dde16db8702c274f320c7be9d7da6f6dff2b58b18f9e815bd94f5b \ + --hash=sha256:8816f3d218beb4b787de5c9759c259b8fa61f9dec42dc7811f320a33771778b7 \ + --hash=sha256:892a881d5f68c2b9ea304b7a6c2c60d9343df578a311b0f86b94bc8f1ffe8129 \ + --hash=sha256:895395f8918627b04efb1ad2a4cf605387143300ba03304cd1dfa6d03f5e095e \ + --hash=sha256:8b10e3e8fd7ddc2bd915848a2768e44c15b22936f1cc54c462ad1164deb02655 \ + --hash=sha256:8e24d8f05fa2d28513d94e877e9c75ad66175376209b3977f916e240e623193c \ + --hash=sha256:8feeac04b5794e513e710af2f9c87d49f31a6dc47967bb264a1fed61a8989bec \ + --hash=sha256:9432f3598db432cb51c5b37fdbf29a60fcccc79e30d37a05022776a6bc4ab689 \ + --hash=sha256:976e1128455aa595ea04c79ccfedff1aaeab96ee013fcc916bed120c4f0ad94f \ + --hash=sha256:978e7b97d4824b5be09c69fb70507cbde3b0323fc147332ca40a94d9a6a0ebbf \ + --hash=sha256:97bf8de4d541598c94a59344eeb988a94c08ff76b5723c41f6567ec18c7892ea \ + --hash=sha256:97cf3eb53a8cccacf9d46686a0926186c9bfb5574f2ed66d3639d5fe117cd3a9 \ + --hash=sha256:9b68938dd5b0c783d88ff8e2dcc69451b5eb936fe212d516b21b9d5567f6d464 \ + --hash=sha256:9c4b71f10dd532fb7a5cbc8f58707779e64f03a258c2bf8bfbaecfcd9970b519 \ + --hash=sha256:9f47b8a949e60f027f0aa0a6f6c7b7e9c55cbf4380d10b344e282fa4e7ab1e1b \ + --hash=sha256:a1dee1b804ff4d11c663636cf15d2ea47e9f79cd56c033fb1cbf08924842a48f \ + --hash=sha256:a2468d93d181667a7abd66e1b64bb9f76f361b0fef8faddf687456453576f5ee \ + --hash=sha256:a2a5e1d0ff29adddc9f6d6821a66302e4493f8ca898b715b6b1182c2c201ea0a \ + --hash=sha256:a39ac25a9a2fa4072efdb429833c4a4c8009a51ff9eea3eeae131713cd27991e \ + --hash=sha256:a445486499897b88a7d6c310c88ed64dd37b1b59bfd7ae9107490bbb362f47d6 \ + --hash=sha256:a91c17edf6eea2402cb5457b4c89e99bc5ed1004aa34c4adf1d4258c1a5c22c2 \ + --hash=sha256:ab4b66edffb32d9e951efb3814bd104b8367a7501b81b955cacb5726d897389f \ + --hash=sha256:aca6c767f552b21b10f774aeac128e828eafb796adfa1b666a18bf6321453c3a \ + --hash=sha256:acf8a67ba51f4ca9ddbd0e6b3000a65ac51ab734661778b3e7ba64d99a710f2f \ + --hash=sha256:b10ec717381bdbfafef34607824db4c91de69ff085e4fca3b2af91b4fa17e68a \ + --hash=sha256:b49924c73a235e969511bf2aabdff3beebf9820931f646c80274d5d780010c47 \ + --hash=sha256:b6acfb46a814762367fb7ba0828b0a17d441b92ce249a0e007474c9072662dda \ + --hash=sha256:b7ca9034437b6022f941f4857459562ee00a560b97e7cce8a0ec5a74fc6766e0 \ + --hash=sha256:b98134087d9de723658d17a42c7d0da8d6e2ef08015dee7dc93889047315f5e4 \ + --hash=sha256:b9fe6fb92520e3fd61f2e49000b6911b188824f089b75973ea06d6267f0b476d \ + --hash=sha256:bce57638e08ac148e5778cce7feb968307a727d66f8e2274a543d0cf0c9ad6a3 \ + --hash=sha256:c14ad3bdc85ee7f318742c457ca3968a92126d144b15721c759033bfb06296c2 \ + --hash=sha256:c1c43ad4339643d70ebb8124e1305a7dab423001eff58bb41a0f731adbc98355 \ + --hash=sha256:c3471e5c4a949c26ec00a77f01df59096aa9495877de76fd60a980f8ee6be461 \ + --hash=sha256:c583b927a8838dab890706a6fa7573fbb8b70e24000ef9f7238e2d6f6435a5ed \ + --hash=sha256:c76fe65e607be28c7fd4d56fc3c42b1583aa058ce3408b7ad0fd540171d31f9f \ + --hash=sha256:c7ea57fc63aa7da93a1bd2d644e6577befae10c52c4e36377635eea1056a74f5 \ + --hash=sha256:cd5214352ae68f3b5e9af7768bdc5253695ee069675db3480518420b3be881f2 \ + --hash=sha256:cdbb78909f52b981d3b2d56b97328d71eb0b974c36bd77c920123a7ebb192829 \ + --hash=sha256:cdc8b74ecc48c0cb1e9607a05ec4e9e88db60a19ffcc9a1d5f9088ede40c8dc0 \ + --hash=sha256:d0a24b40877af2de4950252be9d21eaf7fb07660f3c2cae1f56c6b599ada5266 \ + --hash=sha256:d22a945598fb91236b4dd793a6e42e4f3dd7740bb5aace5ebd7d4c08d13bb575 \ + --hash=sha256:d2f9fc07a8042a8f95925b35c4f04f469707c981fc33245b6ca187cf5d2dd290 \ + --hash=sha256:d625a186a65201c23a9e3b8ed9c47e90a026e03256608cc91851c6709096844f \ + --hash=sha256:d925f3d9afd05a8c0fb3a1031463a8d59ebe5e2afad297e29c78be19e13b4e62 \ + --hash=sha256:e64e88d5585bea9ce95861079de72006c7fa6d3df4e3a3b65ba31eb979c15c9f \ + --hash=sha256:e652ab17569c94bff5475520f907b7148b8c24036a8ebbe5cf7cf7493d28579a \ + --hash=sha256:e7b891faeedeafba41b2983e5001a81b6a915b69544c7e7570d1989ce1c36ac7 \ + --hash=sha256:e80675d75ae2cd14372cb65cad5400d9347a3d3f6c13000183f22dfd027283ed \ + --hash=sha256:e9c134bb666dd54b778b9fc0d2b50cbb7f979b9e3716f26a88c9ab3b6fc1dd0f \ + --hash=sha256:eb7d8d0e5886a89a55d2eef490e272fa965a9d57c6b29a5b5088a7997ec2cad1 \ + --hash=sha256:ecb42011e12ee19cafbc312887cbf3546959fe02fbad44f272d4be5baa997615 \ + --hash=sha256:ef3fbbf161dc9351a2fe0422e51b129f9e97e42385bd0320b309c15f7d287dd8 \ + --hash=sha256:efd62a42486f1bda5d24cb4f63d15a3c7768375fe83d36f9417b4ad7a2fb20b3 \ + --hash=sha256:f077d0b97ab11fa7dcc633fca53515f290bca8a8a633e966d5b6d1879d9ed01a \ + --hash=sha256:f332f0e72a5a0400141f830744e141bf9f97917878dbe968669e8a7fefea78ff \ + --hash=sha256:f7b0ec93a2893de856652154d73b7ba622f26fa97726487dcac373de5f4c6084 \ + --hash=sha256:fa10ef4112775900e7a0661068635eb67b2ab824fbde764de6e0e21982a93db0 \ + --hash=sha256:fc5d783bd4a2387e97b8a2d5ec781cfb92b3d893bf82370548e99db5915935d3 \ + --hash=sha256:fc8515076c11f3cfdf4fb142dcca0fe384b1230a3b5415458ac84f3e0903ec13 \ + --hash=sha256:ff218293c9c806138dca139765e3b067621be52bcd93cdc14c7711be7ddc90a9 + # via pydantic +python-dateutil==2.9.0.post0 \ + --hash=sha256:37dd54208da7e1cd875388217d5e00ebd4179249f90fb72437e91a35459a0ad3 \ + --hash=sha256:a8b2bc7bffae282281c8140a97d3aa9c14da0b136dfe83f850eea9a5f7470427 + # via botocore +s3transfer==0.13.1 \ + --hash=sha256:a981aa7429be23fe6dfc13e80e4020057cbab622b08c0315288758d67cabc724 \ + --hash=sha256:c3fdba22ba1bd367922f27ec8032d6a1cf5f10c934fb5d68cf60fd5a23d936cf + # via boto3 +six==1.17.0 \ + --hash=sha256:4721f391ed90541fddacab5acf947aa0d3dc7d27b2e1e8eda2be8970586c3274 \ + --hash=sha256:ff70335d468e7eb6ec65b95b99d3a2836546063f63acc5171de367e834932a81 + # via python-dateutil +starlette==1.6.0 \ + --hash=sha256:a86dd39d14bb45f85a3d18525215a9ef0cfd1f192ac793220e72598c90335f0c \ + --hash=sha256:d4e3ac5e546444960c710297a3c9fc3f7ebae1b7e963f3d36173b49da535be9b + # via + # -r local/requirements.txt + # fastapi +typing-extensions==4.16.0 \ + --hash=sha256:481caa481374e813c1b176ada14e97f1f67a4539ce9cfeb3f350d78d6370c2e8 \ + --hash=sha256:dc983d19a509c94dba722ee6abd33940f7c05a89e243c47e907eb4db6f1a43e5 + # via + # anyio + # fastapi + # psycopg + # pydantic + # pydantic-core + # starlette + # typing-inspection +typing-inspection==0.4.4 \ + --hash=sha256:547274fa6b0a561ccf549cc9524b999a578e737d015d8709d021f9d0d13bea47 \ + --hash=sha256:65b8397ba37ccbce054456aaccddfc91e6e3083c92824df348d96ca832f3f147 + # via + # fastapi + # pydantic +urllib3==2.7.0 \ + --hash=sha256:231e0ec3b63ceb14667c67be60f2f2c40a518cb38b03af60abc813da26505f4c \ + --hash=sha256:9fb4c81ebbb1ce9531cce37674bbc6f1360472bc18ca9a553ede278ef7276897 + # via botocore +uvicorn==0.34.2 \ + --hash=sha256:0e929828f6186353a80b58ea719861d2629d766293b6d19baf086ba31d4f3328 \ + --hash=sha256:deb49af569084536d269fe0a6d67e3754f104cf03aba7c11c40f01aadf33c403 + # via -r local/requirements.txt + +# The following packages are considered to be unsafe in a requirements file: +pip==26.2.1 \ + --hash=sha256:71138adf1f4ca900cdb7d289c21b7494329f2332b6d85f0e1c42108c0384ed3e \ + --hash=sha256:f6ad667e89a1fe78046c8f13232b247200f5258d7828f3f7883d660878e0813f + # via -r local/requirements.txt diff --git a/local/requirements.txt b/local/requirements.txt new file mode 100644 index 0000000..9cdac78 --- /dev/null +++ b/local/requirements.txt @@ -0,0 +1,7 @@ +fastapi==0.141.1 +starlette==1.6.0 +pip==26.2.1 +uvicorn==0.34.2 +psycopg[binary]==3.2.9 +boto3==1.38.23 +httpx==0.28.1 diff --git a/local/retention_test.py b/local/retention_test.py new file mode 100644 index 0000000..44ade2a --- /dev/null +++ b/local/retention_test.py @@ -0,0 +1,34 @@ +"""Run inside the API container. Creates only synthetic retention fixtures.""" +from datetime import datetime, timedelta, timezone +from uuid import uuid4 +from botocore.exceptions import ClientError +from .adapters import LocalS3Storage +from .db import connect +from .worker import cleanup + +def run(): + storage=LocalS3Storage() + ids=[] + for expired in (True,False): + uid=uuid4();ids.append(uid);key=f'originals/{uid}' + upload=storage.begin(key) + result=storage.client.upload_part(Bucket=storage.bucket,Key=key,UploadId=upload,PartNumber=1,Body=b'LOCAL RETENTION TEST') + storage.complete(key,upload,[{'PartNumber':1,'ETag':result['ETag']}]) + expiry=datetime.now(timezone.utc)+timedelta(days=-1 if expired else 1) + with connect() as c: + c.execute('INSERT INTO dtf_local.uploads(id,owner,name,size,object_key,multipart_id,complete,expires_at) VALUES(%s,%s,%s,%s,%s,%s,true,%s)', + (uid,uuid4(),'LOCAL-RETENTION-TEST.txt',len(b'LOCAL RETENTION TEST'),key,upload,expiry)) + cleanup() + with connect() as c: + assert c.execute('SELECT purged_at FROM dtf_local.uploads WHERE id=%s',(ids[0],)).fetchone()['purged_at'] + assert not c.execute('SELECT purged_at FROM dtf_local.uploads WHERE id=%s',(ids[1],)).fetchone()['purged_at'] + try:storage.size(f'originals/{ids[0]}');raise AssertionError('Expired bytes still exist') + except ClientError as exc:assert exc.response['ResponseMetadata']['HTTPStatusCode']==404 + assert storage.size(f'originals/{ids[1]}')==len(b'LOCAL RETENTION TEST') + # Clean only the other fixture just created above, leaving metadata intact. + with connect() as c: + c.execute("UPDATE dtf_local.uploads SET expires_at=now()-interval '1 second' WHERE id=%s",(ids[1],)) + cleanup() + print('PASS: expired bytes removed, unexpired bytes preserved, upload metadata retained. Synthetic fixture bytes cleaned up.') + +if __name__=='__main__':run() diff --git a/local/runtime_security_test.py b/local/runtime_security_test.py new file mode 100644 index 0000000..38dc44d --- /dev/null +++ b/local/runtime_security_test.py @@ -0,0 +1,42 @@ +"""Run inside API container: permissions, hashing and fail-closed scanner unit checks.""" +import hashlib +from unittest.mock import patch +from botocore.exceptions import ClientError +from .db import connect +from .adapters import LocalS3Storage +from .auth import password_hash, password_matches +from .scanning import ClamAV, require_clean +from fastapi import HTTPException + +def run(): + with connect() as c: + role=c.execute('SELECT rolsuper,rolcreatedb,rolcreaterole,rolbypassrls FROM pg_roles WHERE rolname=current_user').fetchone() + assert not any(role.values()),role + assert not c.execute("SELECT has_schema_privilege(current_user,'dtf_local','CREATE') AS allowed").fetchone()['allowed'] + storage=LocalS3Storage() + storage.health() + visible={bucket['Name'] for bucket in storage.client.list_buckets()['Buckets']} + assert visible=={storage.bucket},visible + for call in (lambda:storage.client.get_bucket_policy(Bucket=storage.bucket), + lambda:storage.client.get_object(Bucket=storage.bucket,Key='outside-runtime-prefix/test.cdr')): + try:call();raise AssertionError('Runtime storage credentials have excessive privilege') + except ClientError as error:assert error.response['ResponseMetadata']['HTTPStatusCode']==403 + password='test-password-for-hash' + salt='00'*16 + old='scrypt$'+salt+'$'+hashlib.scrypt(password.encode(),salt=bytes.fromhex(salt),n=16384,r=8,p=1).hex() + assert password_matches(password,old) + new=password_hash(password) + assert new.startswith('scrypt-v2$') and password_matches(password,new) + assert not password_matches('wrong',new) + for state in ('pending','error','rejected'): + try:require_clean({'complete':True,'scan_state':state});raise AssertionError('Unscanned file released') + except HTTPException as error:assert error.status_code==409 + require_clean({'complete':True,'scan_state':'clean'}) + assert ClamAV().ping() and ClamAV().version().startswith('ClamAV ') + assert ClamAV().scan(None,134217729)[0]=='rejected' + with patch('local.scanning.socket.create_connection',side_effect=OSError('offline')): + try:ClamAV().scan(None,1);raise AssertionError('Offline scanner returned success') + except OSError:pass + print('PASS: runtime DB/S3 least privilege, legacy/current password hashes, quarantine states and scanner size/offline behavior') + +if __name__=='__main__':run() diff --git a/local/scanning.py b/local/scanning.py new file mode 100644 index 0000000..f49d7de --- /dev/null +++ b/local/scanning.py @@ -0,0 +1,81 @@ +"""Local ClamAV boundary. Unknown/error/over-limit results NEVER release artwork.""" +import os +import socket +import struct +import time +from fastapi import HTTPException +from .auth import audit +from .db import connect + +def require_clean(row): + if not row['complete'] or row['scan_state'] != 'clean': + raise HTTPException(409, 'Artwork is quarantined until the malware scan succeeds') + +class ClamAV: + def command(self, command, timeout=2): + with socket.create_connection(('scanner',3310),timeout=timeout) as sock: + sock.settimeout(timeout) + sock.sendall(b'z'+command+b'\0') + reply=b'' + while b'\0' not in reply and len(reply)<4096: + block=sock.recv(4096) + if not block:break + reply+=block + return reply.rstrip(b'\0\n') + + def ping(self): + return self.command(b'PING') == b'PONG' + + def version(self): + return self.command(b'VERSION').decode('utf-8','replace') + + def scan(self, stream, size): + if size > min(134217728, int(os.environ.get('SCAN_MAX_BYTES','134217728'))): + return 'rejected', 'File exceeds the local malware scan limit' + with socket.create_connection(('scanner',3310),timeout=10) as sock: + sock.settimeout(150) + sock.sendall(b'zINSTREAM\0') + sent=0 + for chunk in stream.iter_chunks(chunk_size=65536): + sent+=len(chunk) + if sent>size: return 'rejected','Stored file size changed' + sock.sendall(struct.pack('!I',len(chunk))+chunk) + if sent!=size:return 'rejected','Stored file size changed' + sock.sendall(b'\0\0\0\0') + reply=b'' + while b'\0' not in reply and len(reply)<4096: + block=sock.recv(4096) + if not block:break + reply+=block + result=reply.rstrip(b'\0\n') + if result==b'stream: OK':return 'clean',None + if result.endswith(b' FOUND'):return 'rejected','Malware or unsafe scan condition detected' + return 'error','Scanner could not verify this file' + +def scan_one(storage, scanner=None): + scanner=scanner or ClamAV() + with connect() as c: + row=c.execute('''SELECT * FROM dtf_local.uploads WHERE complete AND purged_at IS NULL + AND expires_at>now() AND scan_state IN ('pending','error') AND scan_after<=now() + ORDER BY created_at FOR UPDATE SKIP LOCKED LIMIT 1''').fetchone() + if not row:return False + try: + stream=storage.client.get_object(Bucket=storage.bucket,Key=row['object_key'])['Body'] + try:state,reason=scanner.scan(stream,row['size']) + finally:stream.close() + except Exception: + state,reason='error','Local malware scanner unavailable; file remains blocked' + c.execute("""UPDATE dtf_local.uploads SET scan_state=%s,scan_reason=%s,scanned_at=now(), + scan_after=now()+interval '1 minute', + expires_at=CASE WHEN %s IN ('rejected','error') THEN LEAST(expires_at,now()+interval '3 days') ELSE expires_at END + WHERE id=%s""",(state,reason,state,row['id'])) + audit('artwork_scan', upload=str(row['id']), result=state) + return True + +def scan_loop(storage): + while True: + try: + if scan_one(storage):continue + except Exception: + audit('scanner_worker_error') + time.sleep(1) diff --git a/local/scanning_test.py b/local/scanning_test.py new file mode 100644 index 0000000..6ba2bec --- /dev/null +++ b/local/scanning_test.py @@ -0,0 +1,17 @@ +"""Harmless EICAR anti-malware test and blocked download/quote regressions.""" +from uuid import uuid4 +from .smoke_test import Client, upload_bytes + +def run(): + customer=Client();customer.call('/session') + # Standard antivirus test string, not executable malware. + marker=b'X5O!P%@AP[4\\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*' + uid=upload_bytes(customer,marker,name='SECURITY-EICAR.cdr',expected_scan='rejected') + customer.call('/operator/uploads/'+uid+'/download',operator=True,expected=409) + customer.call('/quotes',{'request_key':str(uuid4()),'customer':{'cnpj':'11222333000181','zap':'11999999999','mail':'security@example.test'}, + 'items':[{'mode':'file','metres':'1','grade':0,'uploads':[uid]}],'freight':{'service':'pickup'}},expected=409) + clean=upload_bytes(customer,b'Harmless local artwork fixture',name='SECURITY-CLEAN.cdr') + customer.call('/operator/uploads/'+clean+'/download',operator=True) + print('PASS: real ClamAV detects EICAR; rejected artwork cannot be downloaded or quoted; clean artwork is released.') + +if __name__=='__main__':run() diff --git a/local/schema.sql b/local/schema.sql new file mode 100644 index 0000000..74eedb1 --- /dev/null +++ b/local/schema.sql @@ -0,0 +1,81 @@ +-- Separate schema: never imports/migrates the historical schema.sql or SQLite. +CREATE SCHEMA IF NOT EXISTS dtf_local; +CREATE TABLE IF NOT EXISTS dtf_local.uploads ( + id uuid PRIMARY KEY, owner uuid NOT NULL, name text NOT NULL, + size bigint NOT NULL, object_key text UNIQUE NOT NULL, multipart_id text NOT NULL, + complete boolean NOT NULL DEFAULT false, + created_at timestamptz NOT NULL DEFAULT now() +); +CREATE TABLE IF NOT EXISTS dtf_local.quotes ( + id uuid PRIMARY KEY, owner uuid NOT NULL, request_key uuid NOT NULL, + request_hash text NOT NULL, draft jsonb NOT NULL, approved jsonb, + reviewed_by text, approved_at timestamptz, + created_at timestamptz NOT NULL DEFAULT now(), UNIQUE(owner, request_key) +); +CREATE TABLE IF NOT EXISTS dtf_local.orders ( + id uuid PRIMARY KEY, number bigint GENERATED ALWAYS AS IDENTITY UNIQUE, + quote_id uuid NOT NULL UNIQUE REFERENCES dtf_local.quotes(id), owner uuid NOT NULL, + snapshot jsonb NOT NULL, payment jsonb NOT NULL, state text NOT NULL DEFAULT 'rec', + version integer NOT NULL DEFAULT 0, created_at timestamptz NOT NULL DEFAULT now(), + updated_at timestamptz NOT NULL DEFAULT now() +); +CREATE TABLE IF NOT EXISTS dtf_local.movements ( + id bigint GENERATED ALWAYS AS IDENTITY PRIMARY KEY, + order_id uuid NOT NULL REFERENCES dtf_local.orders(id), + from_state text NOT NULL, to_state text NOT NULL, operator text NOT NULL, + reason text NOT NULL, created_at timestamptz NOT NULL DEFAULT now() +); +CREATE TABLE IF NOT EXISTS dtf_local.outbox ( + id bigint GENERATED ALWAYS AS IDENTITY PRIMARY KEY, event_key text NOT NULL UNIQUE, + provider text NOT NULL, payload jsonb NOT NULL, attempts integer NOT NULL DEFAULT 0, + available_at timestamptz NOT NULL DEFAULT now(), delivered_at timestamptz, + last_error text, receipt jsonb +); +CREATE TABLE IF NOT EXISTS dtf_local.accounts ( + id uuid PRIMARY KEY, email text UNIQUE NOT NULL, password_hash text NOT NULL, + profile jsonb NOT NULL, created_at timestamptz NOT NULL DEFAULT now() +); +CREATE TABLE IF NOT EXISTS dtf_local.sessions ( + id uuid PRIMARY KEY, owner uuid NOT NULL, + expires_at timestamptz NOT NULL DEFAULT now() + interval '7 days' +); +CREATE TABLE IF NOT EXISTS dtf_local.migrations (name text PRIMARY KEY); +-- Preserve pre-account guest sessions once, without resurrecting logged-out sessions. +DO $$ BEGIN + IF NOT EXISTS (SELECT 1 FROM dtf_local.migrations WHERE name='customer-sessions-v1') THEN + INSERT INTO dtf_local.sessions(id,owner) + SELECT owner,owner FROM ( + SELECT owner FROM dtf_local.orders UNION SELECT owner FROM dtf_local.quotes + UNION SELECT owner FROM dtf_local.uploads + ) legacy ON CONFLICT DO NOTHING; + INSERT INTO dtf_local.migrations VALUES('customer-sessions-v1'); + END IF; +END $$; +CREATE TABLE IF NOT EXISTS dtf_local.login_attempts ( + key text PRIMARY KEY, attempts integer NOT NULL DEFAULT 0, + started_at timestamptz NOT NULL DEFAULT now() +); +CREATE TABLE IF NOT EXISTS dtf_local.operator_sessions ( + token_hash text PRIMARY KEY, username text NOT NULL, + expires_at timestamptz NOT NULL DEFAULT now() + interval '8 hours' +); +CREATE TABLE IF NOT EXISTS dtf_local.security_events ( + id bigint GENERATED ALWAYS AS IDENTITY PRIMARY KEY, + event text NOT NULL, details jsonb NOT NULL, created_at timestamptz NOT NULL DEFAULT now() +); +CREATE INDEX IF NOT EXISTS uploads_owner ON dtf_local.uploads(owner); +ALTER TABLE dtf_local.uploads ADD COLUMN IF NOT EXISTS expires_at timestamptz; +ALTER TABLE dtf_local.uploads ADD COLUMN IF NOT EXISTS purged_at timestamptz; +ALTER TABLE dtf_local.uploads ADD COLUMN IF NOT EXISTS scan_state text NOT NULL DEFAULT 'pending'; +ALTER TABLE dtf_local.uploads ADD COLUMN IF NOT EXISTS scan_reason text; +ALTER TABLE dtf_local.uploads ADD COLUMN IF NOT EXISTS scanned_at timestamptz; +ALTER TABLE dtf_local.uploads ADD COLUMN IF NOT EXISTS scan_after timestamptz NOT NULL DEFAULT now(); +UPDATE dtf_local.uploads SET expires_at=created_at + interval '30 days' WHERE expires_at IS NULL; +ALTER TABLE dtf_local.uploads ALTER COLUMN expires_at SET DEFAULT now() + interval '30 days'; +CREATE TABLE IF NOT EXISTS dtf_local.order_files ( + id uuid PRIMARY KEY, order_id uuid NOT NULL REFERENCES dtf_local.orders(id), + upload_id uuid NOT NULL REFERENCES dtf_local.uploads(id), item_index integer NOT NULL, + kind text NOT NULL CHECK(kind IN ('final','correction')), active boolean NOT NULL DEFAULT true, + note text NOT NULL, created_by text NOT NULL, created_at timestamptz NOT NULL DEFAULT now(), + UNIQUE(order_id,upload_id,kind) +); diff --git a/local/security_status.py b/local/security_status.py new file mode 100644 index 0000000..1b521ab --- /dev/null +++ b/local/security_status.py @@ -0,0 +1,31 @@ +"""Local alert triage: prints redacted counts; exits 1 when attention is required.""" +import json +from datetime import datetime, timezone +from .db import connect +from .scanning import ClamAV + +def scanner_status(): + try: + version=ClamAV().version() + signature_text=version.split('/',2)[2] + signature_at=datetime.strptime(signature_text,'%a %b %d %H:%M:%S %Y').replace(tzinfo=timezone.utc) + age_hours=max(0,(datetime.now(timezone.utc)-signature_at).total_seconds()/3600) + return {'available':True,'version':version,'signature_age_hours':round(age_hours,1), + 'signatures_stale':age_hours>24*7} + except Exception: + return {'available':False,'version':None,'signature_age_hours':None,'signatures_stale':True} + +def status(): + with connect() as c: + rows=c.execute("""SELECT event,count(*) AS count FROM dtf_local.security_events + WHERE created_at>now()-interval '24 hours' GROUP BY event ORDER BY event""").fetchall() + blocked=c.execute("SELECT scan_state,count(*) AS count FROM dtf_local.uploads WHERE purged_at IS NULL AND scan_state IN ('error','rejected') GROUP BY scan_state").fetchall() + counts={r['event']:r['count'] for r in rows} + scanner=scanner_status() + attention=bool(blocked or not scanner['available'] or scanner['signatures_stale'] or + counts.get('rate_limit',0) or counts.get('scanner_worker_error',0) or + counts.get('operator_login_failed',0)+counts.get('customer_login_failed',0)>=10) + return {'attention_required':attention,'scanner':scanner,'last_24h':counts,'blocked_artwork':blocked} + +if __name__=='__main__': + result=status();print(json.dumps(result,indent=2));raise SystemExit(1 if result['attention_required'] else 0) diff --git a/local/security_test.py b/local/security_test.py new file mode 100644 index 0000000..fe7936d --- /dev/null +++ b/local/security_test.py @@ -0,0 +1,66 @@ +"""Non-destructive localhost security regressions. Leaves tiny test upload reservations.""" +import base64 +import os +from urllib.error import HTTPError +from urllib.request import Request, urlopen +from urllib.parse import urlparse, parse_qs +from uuid import uuid4 +from .smoke_test import Client, BASE + +def raw(path, expected, headers=None, body=None): + request=Request(BASE+path, data=body, headers=headers or {}) + try: + with urlopen(request,timeout=10) as response: + assert response.status==expected + return response.headers + except HTTPError as error: + assert error.code==expected,(path,error.code,expected) + return error.headers + +def run(): + headers=raw('/',200) + policy=headers['Content-Security-Policy'] + assert "script-src-attr 'none'" in policy and "frame-ancestors 'none'" in policy + assert "'sha256-" in policy and "object-src 'none'" in policy + raw('/api/health',400,{'Host':'attacker.invalid'}) + raw('/api/account/logout',403,{'Content-Type':'application/json','Origin':'https://attacker.invalid'},b'{}') + raw('/api/account/logout',403,{'Content-Type':'application/json','Origin':'http://localhost:9999'},b'{}') + print('PASS: CSP, frame protection, Host and cross-origin rejection') + + operator=Client() + credentials={'username':os.environ.get('OPERATOR_USER','operator'),'password':os.environ.get('OPERATOR_PASSWORD','local-operator-only')} + encoded=base64.b64encode((credentials['username']+':'+credentials['password']).encode()).decode() + raw('/api/operator/board',401,{'Authorization':'Basic '+encoded}) + operator.call('/operator/login',credentials) + token=next(c for c in operator.jar if c.name=='dtf_operator') + assert token.has_nonstandard_attr('HttpOnly') and token.get_nonstandard_attr('SameSite')=='strict' + assert token.path=='/api/operator' + operator.call('/operator/board') + replay=Client();replay.jar.set_cookie(token) + operator.call('/operator/logout',{}) + replay.call('/operator/board',expected=401) + print('PASS: Basic rejected; HttpOnly scoped operator session; server-side logout revocation') + + client=Client();client.call('/session') + client.call('/uploads',{'name':'payload.html','size':1},expected=422) + uid=client.call('/uploads',{'name':'SECURITY-PART.cdr','size':3})['id'] + url=client.call('/uploads/'+uid+'/parts/1',{})['url'] + assert 'content-length' in parse_qs(urlparse(url).query)['X-Amz-SignedHeaders'][0] + try: + urlopen(Request(url,data=b'toolong',method='PUT'),timeout=10) + raise AssertionError('Signed part accepted wrong length') + except HTTPError as error:assert error.code==403,error.code + with urlopen(Request(url,data=b'abc',method='PUT'),timeout=10) as response:assert response.status==200 + client.call('/uploads/'+uid+'/complete',{}) + count=int(os.environ.get('MAX_PENDING_UPLOADS','10')) + for i in range(count):client.call('/uploads',{'name':'SECURITY-PENDING.cdr','size':1}) + client.call('/uploads',{'name':'SECURITY-OVER-LIMIT.cdr','size':1},expected=429) + print('PASS: extension allowlist, exact multipart Content-Length signature, pending upload quota') + + # Unique identity avoids locking out the real local operator. + attacker=Client();username='test-'+uuid4().hex + for _ in range(10):attacker.call('/operator/login',{'username':username,'password':'invalid'},expected=401) + attacker.call('/operator/login',{'username':username,'password':'invalid'},expected=429) + print('PASS: operator login throttling (only synthetic account bucket exhausted)') + +if __name__=='__main__':run() diff --git a/local/smoke_test.py b/local/smoke_test.py new file mode 100644 index 0000000..d5a4e01 --- /dev/null +++ b/local/smoke_test.py @@ -0,0 +1,147 @@ +"""Local stack integration checks; creates and retains clearly named test orders. + +Run: python3 -m local.smoke_test. Standard library only. Honors .env/environment. +""" +from concurrent.futures import ThreadPoolExecutor +import hashlib +import http.cookiejar +import json +import os +from pathlib import Path +import time +from urllib.error import HTTPError +from urllib.request import build_opener, HTTPCookieProcessor, Request, urlopen +from uuid import uuid4 + +if Path('.env').exists(): + for line in Path('.env').read_text().splitlines(): + if line.strip() and not line.startswith('#') and '=' in line: + key,value=line.split('=',1) + os.environ.setdefault(key,value) +BASE='http://localhost:'+os.environ.get('SITE_PORT','8080') + +class Client: + def __init__(self): + self.jar=http.cookiejar.CookieJar() + self.opener=build_opener(HTTPCookieProcessor(self.jar)) + self.operator_client=None + def call(self,path,body=None,operator=False,expected=200): + headers={'Content-Type':'application/json'} + if operator: + if self.operator_client is None: + self.operator_client=Client() + self.operator_client.call('/operator/login',{'username':os.environ.get('OPERATOR_USER','operator'),'password':os.environ.get('OPERATOR_PASSWORD','local-operator-only')}) + return self.operator_client.call(path,body,expected=expected) + request=Request(BASE+'/api'+path,data=None if body is None else json.dumps(body).encode(),headers=headers) + try: + with self.opener.open(request,timeout=30) as response: + assert response.status==expected,(path,response.status,expected) + return json.load(response) + except HTTPError as exc: + if exc.code!=expected:raise AssertionError((path,exc.code,exc.read().decode())) from exc + return json.load(exc) + +def wait_scan(client, uid, operator=False, expected='clean'): + prefix='/operator/uploads' if operator else '/uploads' + deadline=time.monotonic()+150 + while time.monotonic() dict[str, str]: + values = {} + for number, raw in enumerate(path.read_text().splitlines(), 1): + line = raw.strip() + if not line or line.startswith('#'): + continue + if '=' not in line: + raise ValueError(f'{path}:{number}: expected NAME=value') + name, value = line.split('=', 1) + name = name.strip() + if not re.fullmatch(r'[A-Z][A-Z0-9_]*', name): + raise ValueError(f'{path}:{number}: invalid setting name') + if name in values: + raise ValueError(f'{path}:{number}: duplicate setting {name}') + if name != 'STAGING_SECRET_SOURCE' and FORBIDDEN_NAME.search(name): + raise ValueError(f'{path}:{number}: secrets must not be stored in this file ({name})') + values[name] = value.strip() + return values + + +def validate(values: dict[str, str]) -> list[str]: + errors = [] + for name in REQUIRED: + if values.get(name, '').lower() in PLACEHOLDERS: + errors.append(f'{name} is not decided') + if values.get('APP_ENV') != 'staging': + errors.append('APP_ENV must be staging') + for name in ('STAGING_PUBLIC_ORIGIN', 'STAGING_S3_ENDPOINT'): + endpoint = urlparse(values.get(name, '')) + if endpoint.scheme != 'https' or not endpoint.hostname: + errors.append(f'{name} must be an absolute HTTPS URL') + elif endpoint.hostname.lower() in LOCAL_HOSTS: + errors.append(f'{name} must not point to localhost or a Compose service') + if endpoint.path not in ('', '/') or endpoint.params or endpoint.query or endpoint.fragment: + errors.append(f'{name} must not include a path, query, or fragment') + storage_host = urlparse(values.get('STAGING_S3_ENDPOINT', '')).hostname or '' + if storage_host and not storage_host.endswith('.r2.cloudflarestorage.com'): + errors.append('STAGING_S3_ENDPOINT must be a Cloudflare R2 S3 API endpoint') + bucket = values.get('STAGING_S3_BUCKET', '') + if bucket and not re.fullmatch(r'[a-z0-9][a-z0-9.-]{1,61}[a-z0-9]', bucket): + errors.append('STAGING_S3_BUCKET is not a valid S3 bucket name') + for name in ('STAGING_FREIGHT_PROVIDER', 'STAGING_PAYMENT_PROVIDER', + 'STAGING_ERP_PROVIDER', 'STAGING_WHATSAPP_PROVIDER'): + if values.get(name, '').lower() in {'fake', 'local', 'mock'}: + errors.append(f'{name} cannot select a local fake provider') + if values.get('STAGING_DATABASE_MODE') not in {'managed', 'dedicated-container'}: + errors.append('STAGING_DATABASE_MODE must be managed or dedicated-container') + if values.get('STAGING_SECRET_SOURCE') in {'env-file', 'repository', '.env'}: + errors.append('STAGING_SECRET_SOURCE must be an external secret-injection mechanism') + return errors + + +def main(path: Path) -> int: + try: + errors = validate(read_config(path)) + except (OSError, ValueError) as exc: + print(f'BLOCKED: {exc}') + return 2 + if errors: + print('BLOCKED: staging inputs are incomplete or unsafe:') + for error in errors: + print(f'- {error}') + return 2 + print('PASS: non-secret staging inputs are complete and structurally safe.') + print('No provider was contacted. This check does not authorize deployment.') + return 0 + + +if __name__ == '__main__': + if len(sys.argv) != 2: + raise SystemExit('usage: python -m local.staging_readiness PATH') + raise SystemExit(main(Path(sys.argv[1]))) diff --git a/local/static/cart.js b/local/static/cart.js new file mode 100644 index 0000000..b20f629 --- /dev/null +++ b/local/static/cart.js @@ -0,0 +1,47 @@ +/* Browser-local cart recovery. Files are stored only for an unfinished cart, for 24h. */ +(() => { + let database,scope,timer,restoring=true; + let signedOut=false; + window.addEventListener('dtf-private-data-cleared',()=>{signedOut=true;clearTimeout(timer);pedido=[];itemAtual=null;folhas=[];artes=[];}); + const notice=document.createElement('p');notice.style.cssText='font:13px system-ui;color:#56616d;padding:8px 20px'; + document.getElementById('carr').prepend(notice); + function transaction(mode,fn){return new Promise((resolve,reject)=>{const tx=database.transaction('cart',mode);const request=fn(tx.objectStore('cart'));let result;request.onsuccess=()=>result=request.result;tx.oncomplete=()=>resolve(result);tx.onerror=()=>reject(tx.error);tx.onabort=()=>reject(tx.error);});} + async function save(){ + if(signedOut||restoring||!database||!scope)return; + const items=[...pedido,...(itemAtual?[itemAtual]:[])]; + try{ + if(!items.length){await transaction('readwrite',store=>store.delete(scope));return;} + await transaction('readwrite',store=>store.put({items,customer:{...cliente},delivery:{...entrega},expires:Date.now()+86400000},scope)); + notice.textContent='Carrinho salvo neste navegador por 24 horas. Você pode remover itens e adicionar outros após recarregar.'; + }catch(error){notice.textContent='Não foi possível salvar o carrinho neste navegador. Mantenha esta página aberta até enviar o pedido.';} + } + window.dtfClearCart=async()=>{clearTimeout(timer);if(database&&scope)await transaction('readwrite',store=>store.delete(scope));notice.textContent='';}; + window.addEventListener('dtf-cart-changed',()=>{clearTimeout(timer);timer=setTimeout(save,400);}); + window.addEventListener('pagehide',()=>{clearTimeout(timer);save();}); + setInterval(async()=>{ + if(!database||signedOut)return; + try{const keys=await transaction('readonly',s=>s.getAllKeys());for(const key of keys){const value=await transaction('readonly',s=>s.get(key));if(value&&value.expiress.delete(key));}}catch{/* Browser may close storage during navigation. */} + },60000); + (async()=>{ + try{ + scope=(await window.dtfSessionReady).cart_scope; + database=await new Promise((resolve,reject)=>{const req=indexedDB.open('dtf-local-cart',1);req.onupgradeneeded=()=>req.result.createObjectStore('cart');req.onsuccess=()=>resolve(req.result);req.onerror=()=>reject(req.error);}); + const records=await transaction('readonly',store=>store.getAllKeys()); + for(const key of records){const value=await transaction('readonly',store=>store.get(key));if(value.expiresstore.delete(key));} + const saved=await transaction('readonly',store=>store.get(scope)); + if(saved && !pedido.length && !itemAtual){ + pedido=saved.items;cliente=saved.customer;entrega=saved.delivery; + // Freight must be quoted again; restored browser values are never final. + if(entrega.tipo==='frete'){entrega.cotado=false;entrega.valor=0;} + for(const [id,key] of [['fCnpj','cnpj'],['fZap','zap'],['fMail','mail']])$(id).value=cliente[key]; + $('cepIn').value=entrega.cep; + $('atual').style.display='none';pintaEntrega(); + notice.textContent='Carrinho recuperado. Remova e adicione novamente um item se precisar alterar sua montagem.'; + }else{ + const account=await window.dtfApi('/account/me'); + if(account.customer && !cliente.mail){cliente={...account.customer};for(const [id,key] of [['fCnpj','cnpj'],['fZap','zap'],['fMail','mail']])$(id).value=cliente[key];pintaEntrega();} + } + }catch(error){notice.textContent='Recuperação de carrinho indisponível; o pedido ainda pode ser feito nesta sessão.';} + finally{restoring=false;} + })(); +})(); diff --git a/local/static/checkout.js b/local/static/checkout.js new file mode 100644 index 0000000..81e4907 --- /dev/null +++ b/local/static/checkout.js @@ -0,0 +1,126 @@ +/* Checkout bridge only: approved commercial functions in dtf-site.html stay intact. */ +(() => { + const box = document.createElement('section'); + box.style.cssText = 'position:relative;z-index:20;background:#152026;color:#e6f4f7;padding:12px 24px;font:14px system-ui;border-bottom:2px solid #00b8da'; + box.innerHTML = 'Ambiente local · pagamento simulado
'; + document.body.prepend(box); + const status = document.getElementById('local-status'); + const actions = document.getElementById('local-actions'); + let busy = false; + let draftId = localStorage.getItem('dtf-quote'); + let requestKey = localStorage.getItem('dtf-request-key'); + let requestBody = localStorage.getItem('dtf-request-body'); + const api = async (path, body) => { + const response = await fetch('/api'+path, { + credentials: 'same-origin', headers: {'Content-Type':'application/json'}, + ...(body === undefined ? {} : {method:'POST', body:JSON.stringify(body)}) + }); + const data = await response.json(); + if (!response.ok) { const error=new Error(typeof data.detail === 'string' ? data.detail : 'Confira os dados do pedido ('+response.status+').');error.status=response.status;throw error; } + return data; + }; + const ready = api('/session'); + window.dtfSessionReady=ready; + window.dtfApi=api; + ready.catch(error => { status.textContent = error.message; }); + function message(text) { status.textContent = ' · '+text; } + function button(label, handler) { + const el = document.createElement('button'); + el.textContent = label; + el.style.cssText = 'margin:8px 8px 0 0;padding:8px 14px;cursor:pointer'; + el.onclick = handler; + actions.append(el); + return el; + } + async function upload(file) { + const session=await ready; + return window.dtfUpload(file,{api,progress:message,scope:session.cart_scope}); + } + window.dtfFreight = async () => { + const cep = entrega.cep; + try { + const result = await api('/freight',{service:'mock-standard',postal_code:cep}); + if (entrega.cep !== cep || entrega.tipo !== 'frete') return; + entrega.valor = result.total_cents/100; + entrega.cotado = true; + $('cepMsg').textContent = 'Frete simulado local: '+rs(entrega.valor)+'. Nenhuma transportadora foi consultada.'; + pintaEntrega(); + } catch(error) { $('cepMsg').textContent = error.message; } + }; + window.dtfCheckout = async () => { + if (busy) return; + if (draftId) { await refresh(); box.scrollIntoView(); return; } + if (!clienteOk() || !entrega.cotado) return; + const cart = [...pedido,...(itemAtual?[itemAtual]:[])]; + if (!cart.length) return message('Adicione um item ao pedido.'); + busy = true; + $('bPagar').disabled = true; + try { + await ready; + if((await api('/session')).cart_scope !== (await ready).cart_scope) throw new Error('Sua conta ou sessão mudou. Recarregue a página antes de enviar o carrinho.'); + const items=[]; + for (const item of cart) { + if (!item.localFiles?.length) throw new Error('Selecione novamente os arquivos deste item.'); + const uploads=[]; + for (const file of item.localFiles) uploads.push(await upload(file)); + items.push({mode:item.modo, metres:String(item.metros), grade:item.nota, uploads}); + } + const content = {customer:{...cliente},items,freight:{service:entrega.tipo==='retira'?'pickup':'mock-standard',postal_code:entrega.tipo==='retira'?'':entrega.cep}}; + const serialized = JSON.stringify(content); + if (!requestKey || serialized !== requestBody) { + requestKey = crypto.randomUUID(); requestBody = serialized; + localStorage.setItem('dtf-request-key',requestKey); + localStorage.setItem('dtf-request-body',requestBody); + } + const quote = await api('/quotes',{request_key:requestKey,...content}); + draftId=quote.id; localStorage.setItem('dtf-quote',draftId); + await refresh(); + box.scrollIntoView({behavior:'smooth'}); + } catch(error) { message(error.message); } + finally { busy=false; pintaEntrega(); } + }; + async function refresh() { + if (!draftId) return; + try { + await ready; + const quote=await api('/quotes/'+draftId); + actions.replaceChildren(); + if (quote.status==='pending_review') { + message('Arquivos enviados. No Kanban, confira metragem e nota e aprove a cotação '+draftId.slice(0,8)+'.'); + } else if (quote.status==='approved') { + message('Total validado no servidor: '+rs(quote.approved.total_cents/100)+' · inclui frete. Cotação válida por 24 horas.'); + button('Criar pedido pago local',async event=>{ + event.target.disabled=true; + try { + const order=await api('/orders/dev-paid',{quote_id:draftId}); + pedido=[]; itemAtual=null; limpaPaineis(); + await window.dtfClearCart?.(); + message('Pedido local #'+order.number+' pago e disponível no Kanban.'); + await refresh(); + } catch(error) { message(error.message); event.target.disabled=false; } + }); + } else if (quote.status==='paid') { + message('Pedido local #'+quote.order.number+' pago · etapa: '+quote.order.state+'. Nenhuma cobrança real.'); + button('Novo pedido local',()=>{localStorage.removeItem('dtf-quote');localStorage.removeItem('dtf-request-key');localStorage.removeItem('dtf-request-body');location.reload();}); + } else { + message('Cotação expirada. Envie o carrinho para uma nova revisão.'); + button('Nova cotação',()=>{draftId=null;requestKey=null;localStorage.removeItem('dtf-quote');localStorage.removeItem('dtf-request-key');actions.replaceChildren();}); + } + } catch(error) { + message(error.message); + actions.replaceChildren(); + button('Limpar referência local e tentar de novo',()=>{draftId=null;requestKey=null;localStorage.removeItem('dtf-quote');localStorage.removeItem('dtf-request-key');actions.replaceChildren();}); + } + } + // Explicit refresh avoids replacing focused payment controls during interaction. + const refreshButton = document.createElement('button'); + refreshButton.textContent='Atualizar pedido local'; + refreshButton.style.cssText='margin-left:12px;padding:6px;cursor:pointer'; + refreshButton.onclick=refresh; + box.append(refreshButton); + const portalLink=document.createElement('a');portalLink.href='/portal.html';portalLink.textContent='Minha conta e pedidos'; + portalLink.style.cssText='color:#e6f4f7;margin-left:16px;text-decoration:underline';box.append(portalLink); + const quoteFromPortal=new URLSearchParams(location.search).get('quote'); + if(quoteFromPortal && /^[0-9a-f-]{36}$/.test(quoteFromPortal)){draftId=quoteFromPortal;localStorage.setItem('dtf-quote',draftId);} + refresh(); +})(); diff --git a/local/static/kanban.html b/local/static/kanban.html new file mode 100644 index 0000000..f7a11cf --- /dev/null +++ b/local/static/kanban.html @@ -0,0 +1,21 @@ + + +DTF · Kanban local + +

Kanban DTF

Desenvolvimento local
+
Pagamentos, Tiny/Olist, WhatsApp e frete são simulados. Confira a cotação manualmente. Em Arquivos de produção, envie e aprove os arquivos finais de todos os itens antes de colocar o pedido na fila. Não há validação automática de arte.
+
+

+
+
Eventos locais de integração
+ diff --git a/local/static/kanban.js b/local/static/kanban.js new file mode 100644 index 0000000..44a7ef4 --- /dev/null +++ b/local/static/kanban.js @@ -0,0 +1,107 @@ +/* Reuses the prototype palette, column names and drag/drop interaction; no machine controls. */ +const $ = id=>document.getElementById(id); +// Remove credentials saved by older local builds. Only HttpOnly sessions now. +sessionStorage.removeItem('dtf-operator'); +let board; +const money=cents=>(cents/100).toLocaleString('pt-BR',{style:'currency',currency:'BRL'}); +function node(tag,text,className){const e=document.createElement(tag);if(text!==undefined)e.textContent=text;if(className)e.className=className;return e;} +function action(text,fn){const b=node('button',text);b.onclick=async()=>{b.disabled=true;try{await fn();}catch(e){$('status').textContent=e.message;}finally{b.disabled=false;}};return b;} +async function api(path,body){ + const r=await fetch('/api/operator'+path,{headers:{'Content-Type':'application/json'},...(body===undefined?{}:{method:'POST',body:JSON.stringify(body)})}); + const d=await r.json();if(!r.ok){const error=new Error(typeof d.detail==='string'?d.detail:'Confira os campos ('+r.status+').');error.status=r.status;throw error;}return d; +} +function files(container,items){ + for(const uid of [...new Set(items.flatMap(i=>i.uploads))])container.append(action('Baixar original '+uid.slice(0,6),async()=>{ + const result=await api('/uploads/'+uid+'/download'); + const link=node('a');link.href=result.url;link.referrerPolicy='no-referrer';link.download=result.name;link.click(); + })); +} +async function load(){ + try{ + board=await api('/board');$('login').hidden=true; + $('status').textContent='Atualizado às '+new Date().toLocaleTimeString(); + render(); + }catch(e){$('status').textContent=e.message;$('login').hidden=false;} +} +function render(){ + $('reviews').replaceChildren(); + if(board.quotes.length)$('reviews').append(node('h2','Cotações · conferência comercial')); + for(const quote of board.quotes){ + const card=node('article',undefined,'review'); + card.append(node('b',quote.id.slice(0,8)+' · '+quote.draft.customer.mail)); + if(quote.status!=='pending_review'){ + card.append(node('p',quote.status==='expired'?'Cotação expirada. O cliente precisa solicitar outra.':'Aprovada: '+money(quote.approved.total_cents)+'. Volte ao Site, atualize o pedido e confirme o pagamento local.')); + }else{ + const form=node('form'); + const edits=quote.draft.items.map((item,index)=>{ + const row=node('div');row.append(node('strong',(index+1)+'. '+item.mode+' ')); + const metres=node('input');metres.type='number';metres.min='0.001';metres.max='12000';metres.step='any';metres.value=item.metres;metres.required=true; + const grade=node('input');grade.type='number';grade.min='0';grade.max='100';grade.step='1';grade.value=item.grade;grade.required=true; + const ml=node('label','Metros conferidos');ml.append(metres);const gl=node('label','Nota conferida');gl.append(grade);row.append(ml,gl);form.append(row); + return ()=>({...item,metres:metres.value,grade:Number(grade.value)}); + }); + const check=node('input');check.type='checkbox';check.required=true;const label=node('label','Conferi os arquivos, a metragem total (incluindo repetições/montagem) e a nota.');label.prepend(check);form.append(label); + const submit=node('button','Aprovar cotação');submit.type='submit';form.append(submit); + form.onsubmit=async e=>{e.preventDefault();submit.disabled=true;try{await api('/quotes/'+quote.id+'/approve',{items:edits.map(fn=>fn())});await load();}catch(error){$('status').textContent=error.message;submit.disabled=false;}}; + card.append(form); + } + const downloads=node('div',undefined,'actions');files(downloads,quote.draft.items);card.append(downloads);$('reviews').append(card); + } + $('kan').replaceChildren(); + const colors=['#00b8da','#e0357c','#efb700','#edebe6','#e0642a','#48b072']; + Object.entries(board.states).forEach(([state,title],index)=>{ + const column=node('section',undefined,'col');column.dataset.state=state;column.style.setProperty('--cc',colors[index]); + const orders=board.orders.filter(o=>o.state===state);column.append(node('h2',title+' · '+orders.length)); + for(const order of orders){ + const card=node('article',undefined,'cd');card.draggable=true;card.dataset.order=order.id; + card.append(node('b','#'+order.number+' · Pago local'),node('p',order.snapshot.customer.mail,'meta'),node('p',money(order.snapshot.total_cents))); + for(const item of order.snapshot.items)card.append(node('p',item.mode+' · '+item.billed_metres+' m · nota '+item.grade,'meta')); + const actions=node('div',undefined,'actions');files(actions,order.snapshot.items); + const artwork=node('div'); + actions.append(action('Arquivos de produção',()=>artworkPanel(order,artwork))); + actions.append(action('Histórico',async()=>{const rows=await api('/orders/'+order.id+'/history');alert(rows.map(r=>board.states[r.from_state]+' → '+board.states[r.to_state]+' · '+r.operator+(r.reason?' · '+r.reason:'')).join('\n')||'Pedido recebido.');})); + for(const next of board.transitions[state])actions.append(action('→ '+board.states[next],()=>move(order,next))); + card.append(actions,artwork);card.ondragstart=e=>e.dataTransfer.setData('text/plain',order.id);column.append(card); + } + column.ondragover=e=>{e.preventDefault();column.classList.add('alvo');};column.ondragleave=()=>column.classList.remove('alvo'); + column.ondrop=async e=>{e.preventDefault();column.classList.remove('alvo');const order=board.orders.find(o=>o.id===e.dataTransfer.getData('text/plain'));if(order)try{await move(order,state);}catch(error){$('status').textContent=error.message;}}; + $('kan').append(column); + }); + $('events').textContent=board.events.map(e=>e.provider+' · '+e.payload.event+' · pedido #'+e.payload.number+' · '+(e.delivered_at?'registrado localmente':'pendente')+' · tentativas '+e.attempts).join('\n')||'Nenhum evento.'; +} +async function move(order,state){ + let reason='';if(state==='cor'){reason=prompt('Motivo da correção:');if(!reason)return;} + await api('/orders/'+order.id+'/move',{state,version:order.version,reason});await load(); +} +$('login').onsubmit=async e=>{e.preventDefault();try{await api('/login',{username:$('user').value,password:$('password').value});await load();}catch(error){$('status').textContent=error.message;}finally{$('password').value='';}}; +$('logout').onclick=async()=>{await api('/logout',{});for(const key of Object.keys(localStorage))if(key.startsWith('dtf-'))localStorage.removeItem(key);location.reload();}; +$('refresh').onclick=load; +load(); + +async function artworkPanel(order,container){ + container.replaceChildren(); + const revisions=await api('/orders/'+order.id+'/files'); + for(const file of revisions){ + const row=node('p',(file.kind==='final'?'Final':'Correção do cliente')+' · item '+(file.item_index+1)+' · '+file.name+' · '+(file.expired?'expirado':file.active?'atual':'substituído'),'meta'); + row.append(node('p',file.note)); + if(!file.expired)row.append(action('Baixar '+file.name,async()=>{const result=await api('/uploads/'+file.upload_id+'/download');const link=node('a');link.href=result.url;link.download=result.name;link.referrerPolicy='no-referrer';link.click();})); + container.append(row); + } + if(!['rec','tra','cor'].includes(order.state))return; + const form=node('form'); + form.append(node('p','Enviar um conjunto final completo. Pode haver várias partes por item. Um novo conjunto substitui o anterior.')); + const inputs=order.snapshot.items.map((item,index)=>{const label=node('label','Item '+(index+1)+' · '+item.mode);label.style.display='block';const input=node('input');input.type='file';input.multiple=true;input.required=true;input.dataset.finalItem=index;input.style.width='100%';label.append(input);form.append(label);return input;}); + const note=node('input');note.placeholder='Nota da revisão';note.required=true;note.maxLength=1000;note.style.width='100%';form.append(note); + const check=node('input');check.type='checkbox';check.required=true;const label=node('label','Conferi estes arquivos finais para impressão manual.');label.prepend(check);form.append(label); + const submit=node('button','Aprovar arquivos finais');submit.type='submit';form.append(submit); + form.onsubmit=async event=>{event.preventDefault();submit.disabled=true;try{ + const refs=[]; + for(const [index,input] of inputs.entries())for(const file of input.files){ + const uid=await dtfUpload(file,{api,startPath:'/orders/'+order.id+'/uploads',scope:'operator:'+order.id+':'+order.version,progress:text=>$('status').textContent=text}); + refs.push({item_index:index,upload_id:uid}); + } + await api('/orders/'+order.id+'/final-files',{version:order.version,files:refs,note:note.value}); + await load(); + }catch(error){$('status').textContent=error.message;submit.disabled=false;}}; + container.append(form); +} diff --git a/local/static/portal.html b/local/static/portal.html new file mode 100644 index 0000000..03831ca --- /dev/null +++ b/local/static/portal.html @@ -0,0 +1,11 @@ +Dropstar · Meus pedidos DTF + +
DROPSTAREnviar arteMinha conta · DTF
+

Meus pedidos DTF

Ambiente de desenvolvimento local. Pagamentos e notificações são simulados. Use apenas dados de teste.

+
+

Entrar

+

Criar conta local

Pedidos desta sessão serão associados à sua conta. Não há envio de e-mail nem recuperação de senha nesta versão local.

+

Acompanhamento

+ diff --git a/local/static/portal.js b/local/static/portal.js new file mode 100644 index 0000000..f06fde7 --- /dev/null +++ b/local/static/portal.js @@ -0,0 +1,76 @@ +const $=id=>document.getElementById(id); +const node=(tag,text)=>{const el=document.createElement(tag);if(text!==undefined)el.textContent=text;return el;}; +const money=c=>(c/100).toLocaleString('pt-BR',{style:'currency',currency:'BRL'}); +let scope,states={}; +async function api(path,body){const r=await fetch('/api'+path,{headers:{'Content-Type':'application/json'},...(body===undefined?{}:{method:'POST',body:JSON.stringify(body)})});const d=await r.json();if(!r.ok){const error=new Error(typeof d.detail==='string'?d.detail:'Confira os campos informados.');error.status=r.status;throw error;}return d;} +function button(text,fn){const b=node('button',text);b.onclick=async()=>{b.disabled=true;try{await fn();}catch(e){$('message').textContent=e.message;}finally{b.disabled=false;}};return b;} +function forgetCheckout(){for(const k of ['dtf-quote','dtf-request-key','dtf-request-body'])localStorage.removeItem(k);} +async function load(){ + try{ + scope=(await api('/session')).cart_scope; + const account=await api('/account/me'); + $('auth').hidden=!!account.customer;$('logout').hidden=!account.customer; + $('account').textContent=account.customer?'Conta: '+account.customer.mail:''; + $('guest').textContent=account.customer?'':'Você está vendo apenas os pedidos desta sessão. Crie uma conta para acessar seus pedidos em outro navegador.'; + const data=await api('/customer/orders');states=data.states; + $('quotes').replaceChildren(); + for(const quote of data.quotes){ + const card=node('article');card.className='card';card.append(node('h3','Cotação '+quote.id.slice(0,8))); + card.append(node('p',quote.approved?'Total aprovado: '+money(quote.approved.total_cents):'Aguardando conferência de metragem e nota.')); + const link=node('a','Abrir cotação no Site');link.href='/?quote='+quote.id;card.append(link);$('quotes').append(card); + } + $('orders').replaceChildren(); + if(!data.orders.length)$('orders').append(node('p','Nenhum pedido pago nesta conta ou sessão.')); + for(const order of data.orders){ + const card=node('article');card.className='card';card.id='order-'+order.id; + card.append(node('h3','Pedido #'+order.number),node('p',states[order.state]+' · '+money(order.snapshot.total_cents)+' · pagamento local')); + card.append(node('p',new Date(order.created_at).toLocaleString('pt-BR'))); + const content=node('div'); + card.append(button('Ver detalhes e arquivos',()=>details(order.id,content)),content);$('orders').append(card); + if(new URLSearchParams(location.search).get('order')===order.id)await details(order.id,content); + } + }catch(error){$('message').textContent=error.message;} +} +async function details(id,container){ + const order=await api('/customer/orders/'+id);container.replaceChildren(); + for(const [i,item] of order.snapshot.items.entries())container.append(node('p',(i+1)+'. '+item.mode+' · '+item.billed_metres+' m · nota '+item.grade+' · '+money(item.total_cents))); + const history=node('ol'); + for(const h of order.history)history.append(node('li',new Date(h.created_at).toLocaleString('pt-BR')+' · '+states[h.to_state]+(h.reason?' — '+h.reason:''))); + container.append(history); + for(const file of order.files){ + const row=node('p',(file.kind==='final'?'Arquivo final':'Correção')+' · item '+(file.item_index+1)+' · '+file.name+' · '+(file.expired?'expirado':!file.active?'substituído':'disponível até '+new Date(file.expires_at).toLocaleDateString('pt-BR'))); + if(file.active&&!file.expired)row.append(button('Baixar',async()=>{const d=await api('/customer/orders/'+id+'/files/'+file.id+'/download');const link=node('a');link.href=d.url;link.download=d.name;link.referrerPolicy='no-referrer';link.click();})); + container.append(row); + } + if(order.state==='cor'){ + const form=node('form');form.append(node('h3','Enviar arte corrigida')); + const inputs=order.snapshot.items.map((item,index)=>{const label=node('label','Item '+(index+1)+' · '+item.mode);const input=node('input');input.type='file';input.multiple=true;input.dataset.item=index;label.append(input);form.append(label);return input;}); + const note=node('textarea');note.placeholder='Descreva a correção';note.required=true;note.maxLength=1000;form.append(note); + const submit=node('button','Enviar correção');submit.type='submit';form.append(submit); + form.onsubmit=async event=>{event.preventDefault();submit.disabled=true;try{ + const files=[];for(const [index,input] of inputs.entries())for(const file of input.files)files.push({item_index:index,upload_id:await dtfUpload(file,{api,scope:scope+':correction:'+id+':'+order.version,progress:text=>$('message').textContent=text})}); + if(!files.length)throw new Error('Selecione pelo menos um arquivo corrigido.'); + await api('/customer/orders/'+id+'/corrections',{version:order.version,files,note:note.value}); + $('message').textContent='Correção enviada. Aguarde a conferência da equipe.';await details(id,container); + }catch(error){$('message').textContent=error.message;}finally{submit.disabled=false;}}; + container.append(form); + } +} +async function migrateGuestCart(previous,next){ + if(previous===next)return; + const database=await new Promise((resolve,reject)=>{const r=indexedDB.open('dtf-local-cart',1);r.onupgradeneeded=()=>r.result.createObjectStore('cart');r.onsuccess=()=>resolve(r.result);r.onerror=()=>reject(r.error);}); + await new Promise((resolve,reject)=>{const tx=database.transaction('cart','readwrite'),store=tx.objectStore('cart'),req=store.get(previous);req.onsuccess=()=>{if(req.result){store.put(req.result,next);store.delete(previous);}};tx.oncomplete=resolve;tx.onerror=()=>reject(tx.error);}); + database.close(); +} +async function authenticate(path,body){ + const previous=scope,guest=!(await api('/account/me')).customer; + await api(path,body);forgetCheckout();$('message').textContent='Acesso confirmado.'; + const next=(await api('/session')).cart_scope; + if(guest)try{await migrateGuestCart(previous,next);}catch{$('message').textContent='Acesso confirmado. Não foi possível transferir o carrinho salvo neste navegador.';} + await load();$('password').value='';$('register-password').value=''; +} +$('login').onsubmit=async event=>{event.preventDefault();try{await authenticate('/account/login',{email:$('email').value,password:$('password').value});}catch(e){$('message').textContent=e.message;}}; +$('register').onsubmit=async event=>{event.preventDefault();try{await authenticate('/account/register',{customer:{cnpj:$('cnpj').value,zap:$('phone').value,mail:$('register-email').value},password:$('register-password').value});}catch(e){$('message').textContent=e.message;}}; +$('logout').onclick=async()=>{try{await window.dtfForgetPrivateData();await api('/account/logout',{});location.reload();}catch(error){$('message').textContent='Não foi possível concluir a limpeza local. Feche as abas do Site e limpe os dados deste site no navegador.';}}; +$('refresh').onclick=load; +load(); diff --git a/local/static/privacy.js b/local/static/privacy.js new file mode 100644 index 0000000..0718944 --- /dev/null +++ b/local/static/privacy.js @@ -0,0 +1,15 @@ +/* Clear draft files and metadata across Site tabs when signing out. */ +(() => { + const signal='dtf-privacy-reset'; + function notify(){window.dispatchEvent(new Event('dtf-private-data-cleared'));} + window.dtfForgetPrivateData=async()=>{ + notify(); + for(const key of Object.keys(localStorage))if(key.startsWith('dtf-'))localStorage.removeItem(key); + localStorage.setItem(signal,crypto.randomUUID()); + const db=await new Promise((resolve,reject)=>{const r=indexedDB.open('dtf-local-cart',1);r.onupgradeneeded=()=>r.result.createObjectStore('cart');r.onsuccess=()=>resolve(r.result);r.onerror=()=>reject(r.error);}); + try{await new Promise((resolve,reject)=>{const tx=db.transaction('cart','readwrite');tx.objectStore('cart').clear();tx.oncomplete=resolve;tx.onerror=()=>reject(tx.error);});}finally{db.close();} + }; + window.addEventListener('storage',event=>{ + if(event.key===signal && event.newValue){notify();location.reload();} + }); +})(); diff --git a/local/static/upload.js b/local/static/upload.js new file mode 100644 index 0000000..a3db838 --- /dev/null +++ b/local/static/upload.js @@ -0,0 +1,30 @@ +/* Shared direct multipart transport for customer originals/corrections and operator finals. */ +window.dtfUpload = async (file, {api, prefix='/uploads', startPath=prefix, progress=()=>{}, scope='guest', resume=true}) => { + const samples=new Blob([file.slice(0,65536),file.slice(Math.max(0,file.size-65536))]); + const hash=Array.from(new Uint8Array(await crypto.subtle.digest('SHA-256',await samples.arrayBuffer())),b=>b.toString(16).padStart(2,'0')).join(''); + const key='dtf-upload:'+JSON.stringify([scope,file.name,file.size,file.lastModified,hash]); + let id=resume?localStorage.getItem(key):null,state; + if(id){try{state=await api(prefix+'/'+id);}catch(error){if(![404,410].includes(error.status))throw error;id=null;}} + if(!id){state=await api(startPath,{name:file.name,size:file.size});id=state.id;if(resume)localStorage.setItem(key,id);} + async function waitForScan(){ + for(let attempt=0;attempt<150;attempt++){ + const checked=await api(prefix+'/'+id); + if(checked.scan_state==='clean')return id; + if(['rejected','error'].includes(checked.scan_state))throw new Error(checked.scan_reason||'Arquivo bloqueado pela verificação de segurança.'); + progress('Verificando segurança de '+file.name+'…'); + await new Promise(resolve=>setTimeout(resolve,1000)); + } + throw new Error('Verificação de segurança pendente. Tente novamente para consultar o resultado.'); + } + if(state.complete)return waitForScan(); + const done=new Set(state.parts||[]),size=state.part_bytes; + for(let offset=0,part=1;offset&2; exit 1;; esac +if [ "$MINIO_ROOT_USER" = "$S3_APP_USER" ]; then echo 'Runtime storage user must not be root' >&2; exit 1; fi +# Disposable local secrets are passed via environment, never traced/logged. +mc alias set local http://storage:9000 "$MINIO_ROOT_USER" "$MINIO_ROOT_PASSWORD" >/dev/null +mc mb --ignore-existing "local/$S3_BUCKET" >/dev/null +mc anonymous set none "local/$S3_BUCKET" >/dev/null +mc admin user add local "$S3_APP_USER" "$S3_APP_PASSWORD" >/dev/null +# Use shell builtins only: the minimal MinIO image does not ship sed/cat. +policy='' +while IFS= read -r line || [ -n "$line" ]; do + while [ "${line#*dtf-local-artwork}" != "$line" ]; do + policy="$policy${line%%dtf-local-artwork*}$S3_BUCKET" + line=${line#*dtf-local-artwork} + done + policy="$policy$line +" +done < /policy.json +printf '%s' "$policy" > /tmp/policy.json +mc admin policy create local dtf-artwork /tmp/policy.json >/dev/null +mc admin policy attach local dtf-artwork --user "$S3_APP_USER" >/dev/null +mc ilm import "local/$S3_BUCKET" < /lifecycle.json +echo 'Local storage runtime account provisioned.' diff --git a/local/storage-lifecycle.json b/local/storage-lifecycle.json new file mode 100644 index 0000000..18427cb --- /dev/null +++ b/local/storage-lifecycle.json @@ -0,0 +1 @@ +{"Rules":[{"ID":"local-artwork-retention","Status":"Enabled","Filter":{"Prefix":""},"Expiration":{"Days":30},"AbortIncompleteMultipartUpload":{"DaysAfterInitiation":1}}]} diff --git a/local/storage-policy.json b/local/storage-policy.json new file mode 100644 index 0000000..b590f96 --- /dev/null +++ b/local/storage-policy.json @@ -0,0 +1,7 @@ +{ + "Version": "2012-10-17", + "Statement": [ + {"Effect":"Allow","Action":["s3:ListBucket","s3:ListBucketMultipartUploads","s3:GetBucketLocation"],"Resource":["arn:aws:s3:::dtf-local-artwork"]}, + {"Effect":"Allow","Action":["s3:GetObject","s3:PutObject","s3:DeleteObject","s3:AbortMultipartUpload","s3:ListMultipartUploadParts"],"Resource":["arn:aws:s3:::dtf-local-artwork/originals/*"]} + ] +} diff --git a/local/storage_backup.py b/local/storage_backup.py new file mode 100644 index 0000000..151e5d6 --- /dev/null +++ b/local/storage_backup.py @@ -0,0 +1,192 @@ +"""Stream clean MinIO artwork to an archive and verify it via an isolated prefix.""" +import hashlib +import io +import json +import os +import sys +import tarfile +from datetime import datetime, timezone +from uuid import uuid4 + +from .adapters import LocalS3Storage, require_local +from .db import connect + +CHUNK = 8 * 1024 * 1024 +MAX_OBJECT = min(128 * 1024 * 1024, int(os.environ.get('SCAN_MAX_BYTES', '134217728'))) +MAX_TOTAL = int(os.environ.get('STORAGE_QUOTA_BYTES', '53687091200')) +MAX_OBJECTS = 100000 + + +class DigestReader: + def __init__(self, stream): + self.stream = stream + self.digest = hashlib.sha256() + self.size = 0 + + def read(self, size=-1): + block = self.stream.read(size) + if block: + self.digest.update(block) + self.size += len(block) + return block + + +def add_bytes(archive, name, content): + info = tarfile.TarInfo(name) + info.size = len(content) + info.mtime = int(datetime.now(timezone.utc).timestamp()) + info.mode = 0o600 + archive.addfile(info, io.BytesIO(content)) + + +def export_archive(): + require_local() + storage = LocalS3Storage() + with connect() as c: + rows = c.execute("""SELECT id,object_key,size,created_at,expires_at + FROM dtf_local.uploads WHERE complete AND purged_at IS NULL + AND expires_at>now() AND scan_state='clean' ORDER BY object_key""").fetchall() + if len(rows) > MAX_OBJECTS: + raise RuntimeError('Object count exceeds the backup safety limit') + expected_total = sum(row['size'] for row in rows) + if expected_total > MAX_TOTAL: + raise RuntimeError('Object bytes exceed the backup safety limit') + + objects = [] + with tarfile.open(fileobj=sys.stdout.buffer, mode='w|gz', compresslevel=6) as archive: + for index, row in enumerate(rows): + if row['size'] <= 0 or row['size'] > MAX_OBJECT: + raise RuntimeError('A clean object has an invalid backup size') + response = storage.client.get_object(Bucket=storage.bucket, Key=row['object_key']) + if response['ContentLength'] != row['size']: + response['Body'].close() + raise RuntimeError('Stored object size differs from database metadata') + reader = DigestReader(response['Body']) + name = f'objects/{index:08d}' + info = tarfile.TarInfo(name) + info.size = row['size'] + info.mtime = int(row['created_at'].timestamp()) + info.mode = 0o600 + try: + archive.addfile(info, reader) + finally: + response['Body'].close() + if reader.size != row['size']: + raise RuntimeError('Object changed while the backup was streaming') + objects.append({'archive_name': name, 'upload_id': str(row['id']), + 'object_key': row['object_key'], 'size': row['size'], + 'sha256': reader.digest.hexdigest(), + 'expires_at': row['expires_at'].isoformat()}) + manifest = {'format': 'dtf-object-backup-v1', + 'created_at': datetime.now(timezone.utc).isoformat(), + 'source_bucket': storage.bucket, 'objects': objects, + 'object_count': len(objects), 'total_bytes': expected_total} + add_bytes(archive, 'manifest.json', json.dumps(manifest, sort_keys=True).encode()) + print('DTF_BACKUP_SUMMARY '+json.dumps({'object_count': len(objects), + 'total_bytes': expected_total}), file=sys.stderr) + + +def upload_member(storage, source, size, key): + upload = storage.client.create_multipart_upload( + Bucket=storage.bucket, Key=key, ContentType='application/octet-stream')['UploadId'] + parts = [] + digest = hashlib.sha256() + remaining = size + try: + number = 1 + while remaining: + block = source.read(min(CHUNK, remaining)) + if not block: + raise ValueError('Archive object ended before its declared size') + digest.update(block) + result = storage.client.upload_part(Bucket=storage.bucket, Key=key, + UploadId=upload, PartNumber=number, Body=block, ContentLength=len(block)) + parts.append({'PartNumber': number, 'ETag': result['ETag']}) + remaining -= len(block) + number += 1 + storage.client.complete_multipart_upload(Bucket=storage.bucket, Key=key, + UploadId=upload, MultipartUpload={'Parts': parts}) + except Exception: + try: + storage.client.abort_multipart_upload( + Bucket=storage.bucket, Key=key, UploadId=upload) + except Exception: + # Preserve the original upload/read error; the verification-prefix + # cleanup below still removes any completed temporary object. + pass + raise + return digest.hexdigest() + + +def object_digest(storage, key): + response = storage.client.get_object(Bucket=storage.bucket, Key=key) + digest = hashlib.sha256() + size = 0 + try: + for block in response['Body'].iter_chunks(chunk_size=1024 * 1024): + digest.update(block) + size += len(block) + finally: + response['Body'].close() + return size, digest.hexdigest() + + +def verify_archive(): + require_local() + storage = LocalS3Storage() + verification = uuid4().hex + restored = [] + observed = [] + manifest = None + total = 0 + try: + with tarfile.open(fileobj=sys.stdin.buffer, mode='r|gz') as archive: + for member in archive: + if not member.isfile(): + raise ValueError('Backup archive contains a non-file member') + source = archive.extractfile(member) + if source is None: + raise ValueError('Backup archive member cannot be read') + if member.name == 'manifest.json': + if manifest is not None or member.size > 1024 * 1024: + raise ValueError('Invalid object-backup manifest') + manifest = json.loads(source.read().decode()) + continue + expected_name = f'objects/{len(observed):08d}' + if member.name != expected_name or len(observed) >= MAX_OBJECTS: + raise ValueError('Unexpected object-backup member') + if member.size <= 0 or member.size > MAX_OBJECT: + raise ValueError('Object-backup member exceeds safety limits') + total += member.size + if total > MAX_TOTAL: + raise ValueError('Object-backup total exceeds safety limits') + key = f'originals/restore-verification/{verification}/{len(observed):08d}' + digest = upload_member(storage, source, member.size, key) + restored.append(key) + observed.append({'archive_name': member.name, 'size': member.size, + 'sha256': digest}) + if not manifest or manifest.get('format') != 'dtf-object-backup-v1': + raise ValueError('Object-backup manifest is missing or unsupported') + expected = manifest.get('objects') + if manifest.get('object_count') != len(observed) or manifest.get('total_bytes') != total: + raise ValueError('Object-backup summary does not match archive contents') + if not isinstance(expected, list) or len(expected) != len(observed): + raise ValueError('Object-backup manifest count does not match') + for actual, recorded, key in zip(observed, expected, restored): + for field in ('archive_name', 'size', 'sha256'): + if actual[field] != recorded.get(field): + raise ValueError('Object-backup checksum manifest does not match') + restored_size, restored_hash = object_digest(storage, key) + if restored_size != actual['size'] or restored_hash != actual['sha256']: + raise ValueError('Restored verification object differs from archive') + print(f'PASS: {len(observed)} clean objects ({total} bytes) restored and hashed in an isolated prefix.') + finally: + for key in restored: + storage.client.delete_object(Bucket=storage.bucket, Key=key) + print('Removed temporary verification objects. Active artwork was untouched.') + + +if __name__ == '__main__': + if len(sys.argv) != 2 or sys.argv[1] not in ('export', 'verify'): + raise SystemExit('usage: python -m local.storage_backup export|verify') + export_archive() if sys.argv[1] == 'export' else verify_archive() diff --git a/local/test_dependency_lock.py b/local/test_dependency_lock.py new file mode 100644 index 0000000..cbaea83 --- /dev/null +++ b/local/test_dependency_lock.py @@ -0,0 +1,46 @@ +import re +import unittest +from pathlib import Path + +ROOT = Path(__file__).resolve().parent.parent +NAME_VERSION = re.compile(r'^([A-Za-z0-9_.-]+)==([^\s\\]+)', re.MULTILINE) + + +def normalized(name): + return re.sub(r'[-_.]+', '-', name).lower() + + +class DependencyLockTests(unittest.TestCase): + @classmethod + def setUpClass(cls): + cls.direct_text = (ROOT / 'local/requirements.txt').read_text() + cls.lock_text = (ROOT / 'local/requirements.lock').read_text() + + def test_every_direct_pin_matches_lock(self): + direct = {normalized(name): version for name, version in + NAME_VERSION.findall(self.direct_text)} + locked = {normalized(name): version for name, version in + NAME_VERSION.findall(self.lock_text)} + self.assertTrue(direct) + self.assertEqual({name: locked.get(name) for name in direct}, direct) + + def test_every_locked_package_has_sha256_hash(self): + matches = list(NAME_VERSION.finditer(self.lock_text)) + self.assertTrue(matches) + for index, match in enumerate(matches): + end = matches[index + 1].start() if index + 1 < len(matches) else len(self.lock_text) + block = self.lock_text[match.start():end] + hashes = re.findall(r'--hash=sha256:([0-9a-f]{64})(?:\s|\\)', block) + self.assertTrue(hashes, f'{match.group(1)} has no SHA-256 artifact hash') + + def test_image_build_requires_the_lock_and_hashes(self): + dockerfile = (ROOT / 'local/Dockerfile').read_text() + self.assertIn('requirements.lock', dockerfile) + self.assertIn('--require-hashes -r local/requirements.lock', dockerfile) + + def test_reproducible_generator_is_recorded(self): + self.assertIn('./local/lock_dependencies.sh', self.lock_text[:300]) + + +if __name__ == '__main__': + unittest.main() diff --git a/local/test_pricing.py b/local/test_pricing.py new file mode 100644 index 0000000..d01fe5e --- /dev/null +++ b/local/test_pricing.py @@ -0,0 +1,40 @@ +"""Run from repository root: python3 -m unittest local.test_pricing -v.""" +import json +from pathlib import Path +import subprocess +import unittest +from .pricing import price, TIERS + +class PricingTests(unittest.TestCase): + def test_every_grade_against_actual_site_javascript(self): + source = Path('dtf-site.html').read_text() + tiers = source.split('const FAIXAS=')[1].split('\n};',1)[0]+'\n}' + calculator = source.split('const cobrar=')[1].split(';',1)[0] + js = f'const FAIXAS={tiers};const MINIMO_M=1;const cobrar={calculator};' + js += '''const results=[];for(const mode of Object.keys(FAIXAS))for(let grade=0;grade<=100;grade++) + for(const metres of [0.01,0.99,1,1.01,1.1,2.75,2.8,2.8000000000000003,19.99,60,12000]){ + const unit=FAIXAS[mode].find(x=>grade>=x[0])[1]; + results.push([mode,String(metres),grade,cobrar(metres),Math.round(unit*100),Math.round(cobrar(metres)*unit*100)]); + }process.stdout.write(JSON.stringify(results));''' + cases = json.loads(subprocess.check_output(['node','-e',js],text=True)) + for mode,metres,grade,billed,unit,total in cases: + with self.subTest(mode=mode,metres=metres,grade=grade): + result=price(mode,metres,grade) + self.assertEqual(float(result['billed_metres']),billed) + self.assertEqual(result['unit_cents'],unit) + self.assertEqual(result['total_cents'],total) + + def test_assembly_is_included_at_every_tier(self): + for grade in range(101): + self.assertEqual(price('avulsa','1',grade)['total_cents']-price('file','1',grade)['total_cents'],1000) + self.assertEqual(price('uv','1',grade)['total_cents']-price('uvfile','1',grade)['total_cents'],1400) + + def test_invalid_inputs(self): + for value in ('0','-1','NaN','Infinity','12001'): + with self.assertRaises(ValueError):price('file',value,90) + for grade in (-1,101,True,89.5): + with self.assertRaises(ValueError):price('file','1',grade) + with self.assertRaises(ValueError):price('other','1',90) + +if __name__ == '__main__': + unittest.main() diff --git a/local/test_staging_readiness.py b/local/test_staging_readiness.py new file mode 100644 index 0000000..014a897 --- /dev/null +++ b/local/test_staging_readiness.py @@ -0,0 +1,56 @@ +import tempfile +import unittest +from pathlib import Path + +from .staging_readiness import read_config, validate + + +VALID = ''' +APP_ENV=staging +STAGING_APPROVED_BY=business-and-technical-owners +STAGING_PUBLIC_ORIGIN=https://staging.example.invalid +STAGING_S3_ENDPOINT=https://example.r2.cloudflarestorage.com +STAGING_S3_BUCKET=dtf-staging-artwork +STAGING_DATABASE_MODE=dedicated-container +STAGING_SECRET_SOURCE=portainer-secrets +STAGING_BACKUP_DESTINATION=separate-encrypted-r2-bucket +STAGING_FREIGHT_PROVIDER=provider-sandbox +STAGING_PAYMENT_PROVIDER=mercado-pago-sandbox +STAGING_ERP_PROVIDER=tiny-olist-sandbox +STAGING_WHATSAPP_PROVIDER=provider-sandbox +STAGING_ALERT_OWNER=operations-team +STAGING_ROLLBACK_OWNER=technical-team +''' + + +class StagingReadinessTests(unittest.TestCase): + def parse(self, text): + with tempfile.TemporaryDirectory() as directory: + path = Path(directory) / 'staging.env' + path.write_text(text) + return read_config(path) + + def test_complete_non_secret_metadata_passes(self): + self.assertEqual(validate(self.parse(VALID)), []) + + def test_local_endpoint_and_fake_provider_are_blocked(self): + values = self.parse(VALID.replace( + 'https://example.r2.cloudflarestorage.com', 'http://localhost:9000' + ).replace('provider-sandbox', 'fake', 1)) + errors = validate(values) + self.assertTrue(any('STAGING_S3_ENDPOINT' in error for error in errors)) + self.assertTrue(any('STAGING_FREIGHT_PROVIDER' in error for error in errors)) + + def test_secret_named_setting_is_rejected(self): + with self.assertRaisesRegex(ValueError, 'secrets must not be stored'): + self.parse(VALID + 'MERCADO_PAGO_ACCESS_TOKEN=do-not-store-this\n') + + def test_undecided_values_are_blocked(self): + errors = validate(self.parse(VALID.replace( + 'STAGING_APPROVED_BY=business-and-technical-owners', + 'STAGING_APPROVED_BY=TBD'))) + self.assertIn('STAGING_APPROVED_BY is not decided', errors) + + +if __name__ == '__main__': + unittest.main() diff --git a/local/worker.py b/local/worker.py new file mode 100644 index 0000000..e453df4 --- /dev/null +++ b/local/worker.py @@ -0,0 +1,77 @@ +"""Transactional outbox worker. Fake receipts persist; no messages leave the stack.""" +import json +import logging +import threading +import time +from http.server import BaseHTTPRequestHandler, HTTPServer +from psycopg.types.json import Jsonb +from .adapters import FakeTiny, FakeWhatsApp, LocalS3Storage, require_local +from .db import connect +from .scanning import ClamAV, scan_loop + +require_local() +adapters = {'tiny': FakeTiny(), 'whatsapp': FakeWhatsApp()} +last_tick = 0.0 +last_cleanup = 0.0 +storage = LocalS3Storage() +scan_thread = None + +def cleanup(): + """Delete only expired object bytes; retain order/file metadata and history.""" + with connect() as c: + rows = c.execute("""SELECT * FROM dtf_local.uploads WHERE purged_at IS NULL + AND (expires_at<=now() OR (NOT complete AND created_at 60: + cleanup() + last_cleanup = time.monotonic() + except Exception: + logging.exception('Local worker tick failed') + time.sleep(1) + +class Health(BaseHTTPRequestHandler): + def do_GET(self): + scanner = False + try: + scanner = bool(scan_thread and scan_thread.is_alive() and ClamAV().ping()) + except Exception: + pass + healthy = time.monotonic()-last_tick < 15 and scanner + self.send_response(200 if self.path == '/health' and healthy else 503) + self.end_headers() + self.wfile.write(json.dumps({'worker': 'ok' if healthy else 'unavailable', + 'scanner': 'ok' if scanner else 'unavailable'}).encode()) + def log_message(self, *args): + pass + +if __name__ == '__main__': + scan_thread = threading.Thread(target=scan_loop,args=(storage,),daemon=True) + scan_thread.start() + threading.Thread(target=loop, daemon=True).start() + HTTPServer(('0.0.0.0',8002),Health).serve_forever() diff --git a/local/workflow_test.py b/local/workflow_test.py new file mode 100644 index 0000000..6f5f36e --- /dev/null +++ b/local/workflow_test.py @@ -0,0 +1,73 @@ +"""Customer identity, correction and final-file trust boundaries against local stack.""" +from uuid import uuid4 +from urllib.request import urlopen +from .smoke_test import Client, upload_bytes + +def run(): + customer=Client();other=Client();customer.call('/session');other.call('/session') + uid=upload_bytes(customer,b'LOCAL ORIGINAL ONLY') + item={'mode':'file','metres':'1.01','grade':0,'uploads':[uid]} + profile={'cnpj':'11222333000181','zap':'11999999999','mail':'workflow-'+uuid4().hex[:8]+'@example.test'} + q=customer.call('/quotes',{'request_key':str(uuid4()),'customer':profile,'items':[item],'freight':{'service':'pickup'}}) + customer.call('/operator/quotes/'+q['id']+'/approve',{'items':[item]},operator=True) + order=customer.call('/orders/dev-paid',{'quote_id':q['id']});oid=order['id'] + before=list(customer.jar)[0].value + password='local-test-password-'+uuid4().hex + customer.call('/account/register',{'customer':profile,'password':password}) + assert customer.call('/account/me')['customer']['mail']==profile['mail'] + assert customer.call('/customer/orders')['orders'][0]['id']==oid + # Email/CNPJ do not grant ownership; only current guest session is migrated. + other.call('/customer/orders/'+oid,expected=404) + other.call('/account/login',{'email':profile['mail'],'password':'wrong-password'},expected=401) + revoked=Client() + import http.cookiejar + cookie=http.cookiejar.Cookie(0,'dtf_session',before,None,False,'localhost.local',False,False,'/',True,False,None,True,None,None,{},False) + revoked.jar.set_cookie(cookie) + revoked.call('/customer/orders',expected=401) + account_scope=customer.call('/session')['cart_scope'] + cookie.value=account_scope;revoked.jar.set_cookie(cookie) + revoked.call('/customer/orders',expected=401) + other.call('/account/login',{'email':profile['mail'],'password':password}) + assert other.call('/customer/orders/'+oid)['id']==oid + print('PASS: registration claims only current guest records, cross-session account login, revoked sessions, owner UUID is not a credential') + + def move(state,version): + return customer.call('/operator/orders/'+oid+'/move',{'state':state,'version':version,'reason':'Please replace the artwork' if state=='cor' else ''},operator=True)['version'] + version=move('tra',0) + customer.call('/operator/orders/'+oid+'/move',{'state':'fil','version':version},operator=True,expected=409) + final_id=upload_bytes(customer,b'LOCAL FINAL VERSION ONE',order_id=oid) + customer.call('/uploads/'+final_id,expected=404) + body={'version':version,'files':[{'item_index':0,'upload_id':final_id}],'note':'Manually checked final'} + customer.call('/operator/orders/'+oid+'/final-files',body,expected=401) + version=customer.call('/operator/orders/'+oid+'/final-files',body,operator=True)['version'] + detail=customer.call('/customer/orders/'+oid) + final=detail['files'][0] + link=customer.call('/customer/orders/'+oid+'/files/'+final['id']+'/download') + assert urlopen(link['url']).read()==b'LOCAL FINAL VERSION ONE' + guest=Client();guest.call('/session');guest.call('/customer/orders/'+oid+'/files/'+final['id']+'/download',expected=404) + version=move('fil',version);version=move('imp',version);version=move('cor',version) + customer.call('/customer/orders/'+oid+'/files/'+final['id']+'/download',expected=404) + correction_id=upload_bytes(customer,b'LOCAL CORRECTED ORIGINAL') + payload={'version':version,'files':[{'item_index':0,'upload_id':correction_id}],'note':'Replaced the artwork as requested'} + guest.call('/customer/orders/'+oid+'/corrections',payload,expected=404) + customer.call('/customer/orders/'+oid+'/corrections',{**payload,'version':0},expected=409) + version=customer.call('/customer/orders/'+oid+'/corrections',payload)['version'] + files=customer.call('/operator/orders/'+oid+'/files',operator=True) + assert any(f['kind']=='correction' and f['active'] and f['upload_id']==correction_id for f in files) + version=move('tra',version) + customer.call('/operator/orders/'+oid+'/move',{'state':'fil','version':version},operator=True,expected=409) + new_final=upload_bytes(customer,b'LOCAL FINAL VERSION TWO',order_id=oid) + version=customer.call('/operator/orders/'+oid+'/final-files',{'version':version,'files':[{'item_index':0,'upload_id':new_final}],'note':'Checked corrected final'},operator=True)['version'] + for state in ('fil','imp','fin'):version=move(state,version) + detail=other.call('/customer/orders/'+oid) + assert detail['state']=='fin' + assert sum(f['active'] and f['kind']=='final' for f in detail['files'])==1 + assert any(h['reason']=='Please replace the artwork' for h in detail['history']) + print('PASS: final-file gate, final revisions, secure customer downloads, correction history/uploads, old final invalidation and reapproval') + old_cookie=list(other.jar)[0].value + other.call('/account/logout',{}) + cookie.value=old_cookie;revoked.jar.set_cookie(cookie);revoked.call('/customer/orders',expected=401) + other.call('/session');assert other.call('/customer/orders')['orders']==[] + print('PASS: logout revokes server session and signed-out visitors cannot see account orders') + +if __name__=='__main__':run() diff --git a/output/local/kanban.png b/output/local/kanban.png new file mode 100644 index 0000000..f312630 Binary files /dev/null and b/output/local/kanban.png differ diff --git a/output/local/portal.png b/output/local/portal.png new file mode 100644 index 0000000..f5dad11 Binary files /dev/null and b/output/local/portal.png differ diff --git a/output/local/site.png b/output/local/site.png new file mode 100644 index 0000000..d7aeb7c Binary files /dev/null and b/output/local/site.png differ diff --git a/output/pdf/dtf-plano-producao-e-roadmap.pdf b/output/pdf/dtf-plano-producao-e-roadmap.pdf new file mode 100644 index 0000000..68cb104 Binary files /dev/null and b/output/pdf/dtf-plano-producao-e-roadmap.pdf differ diff --git a/output/security/api-container-audit.json b/output/security/api-container-audit.json new file mode 100644 index 0000000..c13502a --- /dev/null +++ b/output/security/api-container-audit.json @@ -0,0 +1,11040 @@ +{ + "SchemaVersion": 2, + "Trivy": { + "Version": "0.74.0" + }, + "ReportID": "01a0a028-caf1-741e-9c03-ebec072d0db6", + "CreatedAt": "2026-09-14T13:43:43.089272715Z", + "ArtifactID": "sha256:1069f039ad67fa535ff8d33e828708777a55920949fc7d785dbb849722f62c94", + "ArtifactName": "dtf-cloud-api:latest", + "ArtifactType": "container_image", + "Metadata": { + "Size": 235779072, + "OS": { + "Family": "debian", + "Name": "13.7" + }, + "ImageID": "sha256:ee688608fe056332577c1359b3c4897f2d34a06da16faa0c839e5eaea13eb75f", + "DiffIDs": [ + "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3", + "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca", + "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca", + "sha256:24257af4ce5bde01d3c7ebd6d366ec4a298ed27c794bbd6832ef5ce934a66170", + "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1", + "sha256:79f7610f0f2c10648886af3b8fc7e4750f9fe21ecb6eb32c51325ab63626b0ca", + "sha256:37878ab68fd91358d21bf3ea649ddece87bfdf35213d33665b3b7c6769515026", + "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb", + "sha256:9a8371d1b6d9e9c5988e44c8f0ecbf96be4d16ab9092fcb3b0b1b588c6bcc15b", + "sha256:b5364a9411a9ff28e312071b4c1fd72e5ac10ecb91ff708119cf0159a7664c3f" + ], + "RepoTags": [ + "dtf-cloud-api:latest", + "dtf-cloud-db-init:latest", + "dtf-cloud-worker:latest" + ], + "RepoDigests": [ + "dtf-cloud-api@sha256:ee688608fe056332577c1359b3c4897f2d34a06da16faa0c839e5eaea13eb75f", + "dtf-cloud-db-init@sha256:ee688608fe056332577c1359b3c4897f2d34a06da16faa0c839e5eaea13eb75f", + "dtf-cloud-worker@sha256:ee688608fe056332577c1359b3c4897f2d34a06da16faa0c839e5eaea13eb75f" + ], + "Reference": "dtf-cloud-api:latest", + "ImageConfig": { + "architecture": "amd64", + "created": "2026-09-14T10:41:32.889345494-03:00", + "history": [ + { + "created": "2026-08-24T00:00:00Z", + "created_by": "# debian.sh --arch 'amd64' out/ 'trixie' '@1787529600'", + "comment": "debuerreotype 0.17" + }, + { + "created": "2026-09-01T00:02:59.446345026Z", + "created_by": "ENV PATH=/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-01T00:02:59.446345026Z", + "created_by": "ENV LANG=C.UTF-8", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-01T00:02:59.446345026Z", + "created_by": "RUN /bin/sh -c set -eux; \tapt-get update; \tapt-get install -y --no-install-recommends \t\tca-certificates \t\tnetbase \t\ttzdata \t; \tapt-get dist-clean # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-01T00:02:59.446345026Z", + "created_by": "ENV GPG_KEY=7169605F62C751356D054A26A821E680E5FA6305", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-01T00:02:59.446345026Z", + "created_by": "ENV PYTHON_VERSION=3.12.14", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-01T00:02:59.446345026Z", + "created_by": "ENV PYTHON_SHA256=5c8462af5790baf43a321a1559dbe0db06d1be4300fb85fb53c40060668e548a", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-01T00:12:40.004923065Z", + "created_by": "RUN /bin/sh -c set -eux; \t\tsavedAptMark=\"$(apt-mark showmanual)\"; \tapt-get update; \tapt-get install -y --no-install-recommends \t\tdpkg-dev \t\tg++ \t\tgcc \t\tgnupg \t\tlibbluetooth-dev \t\tlibbz2-dev \t\tlibc6-dev \t\tlibdb-dev \t\tlibffi-dev \t\tlibgdbm-dev \t\tliblzma-dev \t\tlibncursesw5-dev \t\tlibreadline-dev \t\tlibsqlite3-dev \t\tlibssl-dev \t\tmake \t\ttk-dev \t\tuuid-dev \t\twget \t\txz-utils \t\tzlib1g-dev \t; \t\twget -O python.tar.xz \"https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz\"; \techo \"$PYTHON_SHA256 *python.tar.xz\" | sha256sum -c -; \twget -O python.tar.xz.asc \"https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz.asc\"; \tGNUPGHOME=\"$(mktemp -d)\"; export GNUPGHOME; \tgpg --batch --keyserver hkps://keys.openpgp.org --recv-keys \"$GPG_KEY\"; \tgpg --batch --verify python.tar.xz.asc python.tar.xz; \tgpgconf --kill all; \trm -rf \"$GNUPGHOME\" python.tar.xz.asc; \tmkdir -p /usr/src/python; \ttar --extract --directory /usr/src/python --strip-components=1 --file python.tar.xz; \trm python.tar.xz; \t\tcd /usr/src/python; \tgnuArch=\"$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)\"; \t./configure \t\t--build=\"$gnuArch\" \t\t--enable-loadable-sqlite-extensions \t\t--enable-optimizations \t\t--enable-option-checking=fatal \t\t--enable-shared \t\t$(test \"${gnuArch%%-*}\" != 'riscv64' \u0026\u0026 echo '--with-lto') \t\t--with-ensurepip \t; \tnproc=\"$(nproc)\"; \tEXTRA_CFLAGS=\"$(dpkg-buildflags --get CFLAGS)\"; \tLDFLAGS=\"$(dpkg-buildflags --get LDFLAGS)\"; \tLDFLAGS=\"${LDFLAGS:-} -Wl,--strip-all\"; \tarch=\"$(dpkg --print-architecture)\"; arch=\"${arch##*-}\"; \tcase \"$arch\" in \t\tamd64|arm64) \t\t\tEXTRA_CFLAGS=\"${EXTRA_CFLAGS:-} -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer\"; \t\t\t;; \t\ti386) \t\t\t;; \t\t*) \t\t\tEXTRA_CFLAGS=\"${EXTRA_CFLAGS:-} -fno-omit-frame-pointer\"; \t\t\t;; \tesac; \tmake -j \"$nproc\" \t\t\"EXTRA_CFLAGS=${EXTRA_CFLAGS:-}\" \t\t\"LDFLAGS=${LDFLAGS:-}\" \t; \trm python; \tmake -j \"$nproc\" \t\t\"EXTRA_CFLAGS=${EXTRA_CFLAGS:-}\" \t\t\"LDFLAGS=${LDFLAGS:-} -Wl,-rpath='\\$\\$ORIGIN/../lib'\" \t\tpython \t; \tmake install; \t\tcd /; \trm -rf /usr/src/python; \t\tfind /usr/local -depth \t\t\\( \t\t\t\\( -type d -a \\( -name test -o -name tests -o -name idle_test \\) \\) \t\t\t-o \\( -type f -a \\( -name '*.pyc' -o -name '*.pyo' -o -name 'libpython*.a' \\) \\) \t\t\\) -exec rm -rf '{}' + \t; \t\tldconfig; \t\tapt-mark auto '.*' \u003e /dev/null; \tapt-mark manual $savedAptMark; \tfind /usr/local -type f -executable -not \\( -name '*tkinter*' \\) -exec ldd '{}' ';' \t\t| awk '/=\u003e/ { so = $(NF-1); if (index(so, \"/usr/local/\") == 1) { next }; gsub(\"^/(usr/)?\", \"\", so); printf \"*%s\\n\", so }' \t\t| sort -u \t\t| xargs -rt dpkg-query --search \t\t| awk 'sub(\":$\", \"\", $1) { print $1 }' \t\t| sort -u \t\t| xargs -r apt-mark manual \t; \tapt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \tapt-get dist-clean; \t\texport PYTHONDONTWRITEBYTECODE=1; \tpython3 --version; \tpip3 --version # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-01T00:12:40.129211396Z", + "created_by": "RUN /bin/sh -c set -eux; \tfor src in idle3 pip3 pydoc3 python3 python3-config; do \t\tdst=\"$(echo \"$src\" | tr -d 3)\"; \t\t[ -s \"/usr/local/bin/$src\" ]; \t\t[ ! -e \"/usr/local/bin/$dst\" ]; \t\tln -svT \"$src\" \"/usr/local/bin/$dst\"; \tdone # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-01T00:12:40.129211396Z", + "created_by": "CMD [\"python3\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-14T10:39:50.056935607-03:00", + "created_by": "/bin/sh -c apt-get update \u0026\u0026 apt-get upgrade -y \u0026\u0026 rm -rf /var/lib/apt/lists/*" + }, + { + "created": "2026-09-14T10:39:59.718391151-03:00", + "created_by": "/bin/sh -c #(nop) WORKDIR /app" + }, + { + "created": "2026-09-14T13:40:01.972072003Z", + "created_by": "/bin/sh -c #(nop) COPY file:9562a016cf4a275d8f1ec4875162020ec70ab7f3c065bc6980bc124711dcaa48 in /app/local/requirements.txt " + }, + { + "created": "2026-09-14T10:40:45.155343181-03:00", + "created_by": "/bin/sh -c pip install --no-cache-dir -r local/requirements.txt" + }, + { + "created": "2026-09-14T13:41:02.217678703Z", + "created_by": "/bin/sh -c #(nop) COPY dir:b7070eda1a28cb84c31ee4185dc2c7e80284cfb4c722eafb21a04b3299823273 in /app/local " + }, + { + "created": "2026-09-14T10:41:06.68423126-03:00", + "created_by": "/bin/sh -c useradd --uid 10001 --create-home dtf" + }, + { + "created": "2026-09-14T10:41:16.490918944-03:00", + "created_by": "/bin/sh -c #(nop) USER dtf", + "empty_layer": true + }, + { + "created": "2026-09-14T10:41:29.106467105-03:00", + "created_by": "/bin/sh -c #(nop) ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1", + "empty_layer": true + }, + { + "created": "2026-09-14T10:41:32.889345494-03:00", + "created_by": "/bin/sh -c #(nop) LABEL com.docker.compose.image.builder=classic", + "empty_layer": true + } + ], + "os": "linux", + "rootfs": { + "type": "layers", + "diff_ids": [ + "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3", + "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca", + "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca", + "sha256:24257af4ce5bde01d3c7ebd6d366ec4a298ed27c794bbd6832ef5ce934a66170", + "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1", + "sha256:79f7610f0f2c10648886af3b8fc7e4750f9fe21ecb6eb32c51325ab63626b0ca", + "sha256:37878ab68fd91358d21bf3ea649ddece87bfdf35213d33665b3b7c6769515026", + "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb", + "sha256:9a8371d1b6d9e9c5988e44c8f0ecbf96be4d16ab9092fcb3b0b1b588c6bcc15b", + "sha256:b5364a9411a9ff28e312071b4c1fd72e5ac10ecb91ff708119cf0159a7664c3f" + ] + }, + "config": { + "Cmd": [ + "python3" + ], + "Env": [ + "PATH=/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", + "LANG=C.UTF-8", + "GPG_KEY=7169605F62C751356D054A26A821E680E5FA6305", + "PYTHON_VERSION=3.12.14", + "PYTHON_SHA256=5c8462af5790baf43a321a1559dbe0db06d1be4300fb85fb53c40060668e548a", + "PYTHONDONTWRITEBYTECODE=1", + "PYTHONUNBUFFERED=1" + ], + "Labels": { + "com.docker.compose.image.builder": "classic" + }, + "User": "dtf", + "WorkingDir": "/app" + } + }, + "Layers": [ + { + "Size": 81070080, + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + { + "Size": 12298752, + "Digest": "sha256:dbd0b7849e6c06b61e1fa6b7ffe053f246ce0075890620e3db64b47bb662433a", + "DiffID": "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca" + }, + { + "Size": 38131712, + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + { + "Size": 5120, + "Digest": "sha256:56235e4245636e401a28cf88944d543b29ee028ae3b6c27e03d6b43e7b4eac5f", + "DiffID": "sha256:24257af4ce5bde01d3c7ebd6d366ec4a298ed27c794bbd6832ef5ce934a66170" + }, + { + "Size": 31461888, + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + { + "Size": 1536, + "Digest": "sha256:c7eda8271838817e03d4989aaa9b74f5aac92634a27fc1455391836f90481cc9", + "DiffID": "sha256:79f7610f0f2c10648886af3b8fc7e4750f9fe21ecb6eb32c51325ab63626b0ca" + }, + { + "Size": 3072, + "Digest": "sha256:bccc356f9bf4b6146f54f21da5b32abcb5480582ad452b695193491bd6b34853", + "DiffID": "sha256:37878ab68fd91358d21bf3ea649ddece87bfdf35213d33665b3b7c6769515026" + }, + { + "Size": 72609280, + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + { + "Size": 176128, + "Digest": "sha256:88113a940fdc9d29e69fc2097af0a4a9ef2a221011091b9b4e6cf40318c2d087", + "DiffID": "sha256:9a8371d1b6d9e9c5988e44c8f0ecbf96be4d16ab9092fcb3b0b1b588c6bcc15b" + }, + { + "Size": 21504, + "Digest": "sha256:18cd363f4c732f8e867d12a02f2509bbb5e6992303613f16a1b0037ffd9ebf6b", + "DiffID": "sha256:b5364a9411a9ff28e312071b4c1fd72e5ac10ecb91ff708119cf0159a7664c3f" + } + ] + }, + "Results": [ + { + "Target": "dtf-cloud-api:latest (debian 13.7)", + "Class": "os-pkgs", + "Type": "debian", + "Packages": [ + { + "ID": "adduser@3.152", + "Name": "adduser", + "Identifier": { + "PURL": "pkg:deb/debian/adduser@3.152?arch=all\u0026distro=debian-13.7", + "UID": "17a3839c9950603e" + }, + "Version": "3.152", + "Arch": "all", + "SrcName": "adduser", + "SrcVersion": "3.152", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Debian Adduser Developers \u003cadduser@packages.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "passwd@1:4.17.4-2" + ], + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "InstalledFiles": [ + "/usr/sbin/adduser", + "/usr/sbin/deluser", + "/usr/share/doc/adduser/NEWS.Debian.gz", + "/usr/share/doc/adduser/README.gz", + "/usr/share/doc/adduser/TODO", + "/usr/share/doc/adduser/changelog.gz", + "/usr/share/doc/adduser/copyright", + "/usr/share/doc/adduser/examples/INSTALL", + "/usr/share/doc/adduser/examples/README", + "/usr/share/doc/adduser/examples/adduser.conf", + "/usr/share/doc/adduser/examples/adduser.local", + "/usr/share/doc/adduser/examples/adduser.local.conf", + "/usr/share/doc/adduser/examples/adduser.local.conf.examples/bash.bashrc", + "/usr/share/doc/adduser/examples/adduser.local.conf.examples/profile", + "/usr/share/doc/adduser/examples/adduser.local.conf.examples/skel.other/index.html", + "/usr/share/doc/adduser/examples/adduser.local.conf.examples/skel/dot.bash_logout", + "/usr/share/doc/adduser/examples/adduser.local.conf.examples/skel/dot.bash_profile", + "/usr/share/doc/adduser/examples/adduser.local.conf.examples/skel/dot.bashrc", + "/usr/share/doc/adduser/examples/deluser.conf", + "/usr/share/man/da/man5/deluser.conf.5.gz", + "/usr/share/man/de/man5/adduser.conf.5.gz", + "/usr/share/man/de/man5/deluser.conf.5.gz", + "/usr/share/man/de/man8/adduser.8.gz", + "/usr/share/man/de/man8/adduser.local.8.gz", + "/usr/share/man/de/man8/deluser.8.gz", + "/usr/share/man/es/man5/deluser.conf.5.gz", + "/usr/share/man/fr/man5/adduser.conf.5.gz", + "/usr/share/man/fr/man5/deluser.conf.5.gz", + "/usr/share/man/fr/man8/adduser.8.gz", + "/usr/share/man/fr/man8/deluser.8.gz", + "/usr/share/man/it/man5/deluser.conf.5.gz", + "/usr/share/man/man5/adduser.conf.5.gz", + "/usr/share/man/man5/deluser.conf.5.gz", + "/usr/share/man/man8/adduser.8.gz", + "/usr/share/man/man8/adduser.local.8.gz", + "/usr/share/man/man8/deluser.8.gz", + "/usr/share/man/nl/man5/adduser.conf.5.gz", + "/usr/share/man/nl/man5/deluser.conf.5.gz", + "/usr/share/man/nl/man8/adduser.8.gz", + "/usr/share/man/nl/man8/adduser.local.8.gz", + "/usr/share/man/nl/man8/deluser.8.gz", + "/usr/share/man/pl/man5/deluser.conf.5.gz", + "/usr/share/man/pt/man5/adduser.conf.5.gz", + "/usr/share/man/pt/man5/deluser.conf.5.gz", + "/usr/share/man/pt/man8/adduser.8.gz", + "/usr/share/man/pt/man8/adduser.local.8.gz", + "/usr/share/man/pt/man8/deluser.8.gz", + "/usr/share/man/ro/man5/adduser.conf.5.gz", + "/usr/share/man/ro/man5/deluser.conf.5.gz", + "/usr/share/man/ro/man8/adduser.8.gz", + "/usr/share/man/ro/man8/adduser.local.8.gz", + "/usr/share/man/ro/man8/deluser.8.gz", + "/usr/share/man/ru/man5/deluser.conf.5.gz", + "/usr/share/man/sv/man5/deluser.conf.5.gz", + "/usr/share/perl5/Debian/AdduserCommon.pm", + "/usr/share/perl5/Debian/AdduserLogging.pm", + "/usr/share/perl5/Debian/AdduserRetvalues.pm" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "apt@3.0.3", + "Name": "apt", + "Identifier": { + "PURL": "pkg:deb/debian/apt@3.0.3?arch=amd64\u0026distro=debian-13.7", + "UID": "55a02bb6f5876f39" + }, + "Version": "3.0.3", + "Arch": "amd64", + "SrcName": "apt", + "SrcVersion": "3.0.3", + "Licenses": [ + "GPL-2.0-or-later", + "curl", + "BSD-3-Clause", + "MIT", + "GPL-2.0-only" + ], + "Maintainer": "APT Development Team \u003cdeity@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "adduser@3.152", + "base-passwd@3.6.7", + "debian-archive-keyring@2025.1", + "libapt-pkg7.0@3.0.3", + "libc6@2.41-12+deb13u4", + "libgcc-s1@14.2.0-19", + "libseccomp2@2.6.0-2", + "libssl3t64@3.5.7-1~deb13u2", + "libstdc++6@14.2.0-19", + "libsystemd0@257.13-1~deb13u1", + "sqv@1.3.0-3+b2" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/apt", + "/usr/bin/apt-cache", + "/usr/bin/apt-cdrom", + "/usr/bin/apt-config", + "/usr/bin/apt-get", + "/usr/bin/apt-mark", + "/usr/lib/apt/apt-extracttemplates", + "/usr/lib/apt/apt-helper", + "/usr/lib/apt/apt.systemd.daily", + "/usr/lib/apt/methods/cdrom", + "/usr/lib/apt/methods/copy", + "/usr/lib/apt/methods/file", + "/usr/lib/apt/methods/gpgv", + "/usr/lib/apt/methods/http", + "/usr/lib/apt/methods/mirror", + "/usr/lib/apt/methods/rred", + "/usr/lib/apt/methods/sqv", + "/usr/lib/apt/methods/store", + "/usr/lib/apt/solvers/dump", + "/usr/lib/dpkg/methods/apt/desc.apt", + "/usr/lib/dpkg/methods/apt/install", + "/usr/lib/dpkg/methods/apt/names", + "/usr/lib/dpkg/methods/apt/setup", + "/usr/lib/dpkg/methods/apt/update", + "/usr/lib/systemd/system/apt-daily-upgrade.service", + "/usr/lib/systemd/system/apt-daily-upgrade.timer", + "/usr/lib/systemd/system/apt-daily.service", + "/usr/lib/systemd/system/apt-daily.timer", + "/usr/lib/x86_64-linux-gnu/libapt-private.so.0.0.0", + "/usr/share/apt/default-sequoia.config", + "/usr/share/bash-completion/completions/apt", + "/usr/share/bug/apt/script", + "/usr/share/doc/apt/NEWS.Debian.gz", + "/usr/share/doc/apt/README.md.gz", + "/usr/share/doc/apt/changelog.gz", + "/usr/share/doc/apt/copyright", + "/usr/share/doc/apt/examples/apt.conf", + "/usr/share/doc/apt/examples/configure-index", + "/usr/share/doc/apt/examples/debian.sources", + "/usr/share/doc/apt/examples/preferences", + "/usr/share/lintian/overrides/apt", + "/usr/share/locale/ar/LC_MESSAGES/apt.mo", + "/usr/share/locale/ast/LC_MESSAGES/apt.mo", + "/usr/share/locale/bg/LC_MESSAGES/apt.mo", + "/usr/share/locale/bs/LC_MESSAGES/apt.mo", + "/usr/share/locale/ca/LC_MESSAGES/apt.mo", + "/usr/share/locale/cs/LC_MESSAGES/apt.mo", + "/usr/share/locale/cy/LC_MESSAGES/apt.mo", + "/usr/share/locale/da/LC_MESSAGES/apt.mo", + "/usr/share/locale/de/LC_MESSAGES/apt.mo", + "/usr/share/locale/dz/LC_MESSAGES/apt.mo", + "/usr/share/locale/el/LC_MESSAGES/apt.mo", + "/usr/share/locale/es/LC_MESSAGES/apt.mo", + "/usr/share/locale/eu/LC_MESSAGES/apt.mo", + "/usr/share/locale/fi/LC_MESSAGES/apt.mo", + "/usr/share/locale/fr/LC_MESSAGES/apt.mo", + "/usr/share/locale/gl/LC_MESSAGES/apt.mo", + "/usr/share/locale/hu/LC_MESSAGES/apt.mo", + "/usr/share/locale/it/LC_MESSAGES/apt.mo", + "/usr/share/locale/ja/LC_MESSAGES/apt.mo", + "/usr/share/locale/km/LC_MESSAGES/apt.mo", + "/usr/share/locale/ko/LC_MESSAGES/apt.mo", + "/usr/share/locale/ku/LC_MESSAGES/apt.mo", + "/usr/share/locale/lt/LC_MESSAGES/apt.mo", + "/usr/share/locale/mr/LC_MESSAGES/apt.mo", + "/usr/share/locale/nb/LC_MESSAGES/apt.mo", + "/usr/share/locale/ne/LC_MESSAGES/apt.mo", + "/usr/share/locale/nl/LC_MESSAGES/apt.mo", + "/usr/share/locale/nn/LC_MESSAGES/apt.mo", + "/usr/share/locale/pl/LC_MESSAGES/apt.mo", + "/usr/share/locale/pt/LC_MESSAGES/apt.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/apt.mo", + "/usr/share/locale/ro/LC_MESSAGES/apt.mo", + "/usr/share/locale/ru/LC_MESSAGES/apt.mo", + "/usr/share/locale/sk/LC_MESSAGES/apt.mo", + "/usr/share/locale/sl/LC_MESSAGES/apt.mo", + "/usr/share/locale/sv/LC_MESSAGES/apt.mo", + "/usr/share/locale/th/LC_MESSAGES/apt.mo", + "/usr/share/locale/tl/LC_MESSAGES/apt.mo", + "/usr/share/locale/tr/LC_MESSAGES/apt.mo", + "/usr/share/locale/uk/LC_MESSAGES/apt.mo", + "/usr/share/locale/vi/LC_MESSAGES/apt.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/apt.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/apt.mo", + "/usr/share/man/de/man1/apt-transport-http.1.gz", + "/usr/share/man/de/man1/apt-transport-https.1.gz", + "/usr/share/man/de/man1/apt-transport-mirror.1.gz", + "/usr/share/man/de/man5/apt.conf.5.gz", + "/usr/share/man/de/man5/apt_auth.conf.5.gz", + "/usr/share/man/de/man5/apt_preferences.5.gz", + "/usr/share/man/de/man5/sources.list.5.gz", + "/usr/share/man/de/man7/apt-patterns.7.gz", + "/usr/share/man/de/man8/apt-cache.8.gz", + "/usr/share/man/de/man8/apt-cdrom.8.gz", + "/usr/share/man/de/man8/apt-config.8.gz", + "/usr/share/man/de/man8/apt-get.8.gz", + "/usr/share/man/de/man8/apt-mark.8.gz", + "/usr/share/man/de/man8/apt-secure.8.gz", + "/usr/share/man/de/man8/apt.8.gz", + "/usr/share/man/es/man5/apt_preferences.5.gz", + "/usr/share/man/es/man8/apt-cache.8.gz", + "/usr/share/man/es/man8/apt-cdrom.8.gz", + "/usr/share/man/es/man8/apt-config.8.gz", + "/usr/share/man/fr/man1/apt-transport-http.1.gz", + "/usr/share/man/fr/man1/apt-transport-https.1.gz", + "/usr/share/man/fr/man1/apt-transport-mirror.1.gz", + "/usr/share/man/fr/man5/apt.conf.5.gz", + "/usr/share/man/fr/man5/apt_auth.conf.5.gz", + "/usr/share/man/fr/man5/apt_preferences.5.gz", + "/usr/share/man/fr/man5/sources.list.5.gz", + "/usr/share/man/fr/man7/apt-patterns.7.gz", + "/usr/share/man/fr/man8/apt-cache.8.gz", + "/usr/share/man/fr/man8/apt-cdrom.8.gz", + "/usr/share/man/fr/man8/apt-config.8.gz", + "/usr/share/man/fr/man8/apt-get.8.gz", + "/usr/share/man/fr/man8/apt-mark.8.gz", + "/usr/share/man/fr/man8/apt-secure.8.gz", + "/usr/share/man/fr/man8/apt.8.gz", + "/usr/share/man/it/man5/apt.conf.5.gz", + "/usr/share/man/it/man5/apt_preferences.5.gz", + "/usr/share/man/it/man8/apt-cache.8.gz", + "/usr/share/man/it/man8/apt-cdrom.8.gz", + "/usr/share/man/it/man8/apt-config.8.gz", + "/usr/share/man/it/man8/apt-mark.8.gz", + "/usr/share/man/it/man8/apt.8.gz", + "/usr/share/man/ja/man5/apt.conf.5.gz", + "/usr/share/man/ja/man5/apt_preferences.5.gz", + "/usr/share/man/ja/man8/apt-cache.8.gz", + "/usr/share/man/ja/man8/apt-cdrom.8.gz", + "/usr/share/man/ja/man8/apt-config.8.gz", + "/usr/share/man/ja/man8/apt-mark.8.gz", + "/usr/share/man/ja/man8/apt.8.gz", + "/usr/share/man/man1/apt-transport-http.1.gz", + "/usr/share/man/man1/apt-transport-https.1.gz", + "/usr/share/man/man1/apt-transport-mirror.1.gz", + "/usr/share/man/man5/apt.conf.5.gz", + "/usr/share/man/man5/apt_auth.conf.5.gz", + "/usr/share/man/man5/apt_preferences.5.gz", + "/usr/share/man/man5/sources.list.5.gz", + "/usr/share/man/man7/apt-patterns.7.gz", + "/usr/share/man/man8/apt-cache.8.gz", + "/usr/share/man/man8/apt-cdrom.8.gz", + "/usr/share/man/man8/apt-config.8.gz", + "/usr/share/man/man8/apt-get.8.gz", + "/usr/share/man/man8/apt-mark.8.gz", + "/usr/share/man/man8/apt-secure.8.gz", + "/usr/share/man/man8/apt.8.gz", + "/usr/share/man/nl/man1/apt-transport-http.1.gz", + "/usr/share/man/nl/man1/apt-transport-https.1.gz", + "/usr/share/man/nl/man1/apt-transport-mirror.1.gz", + "/usr/share/man/nl/man5/apt.conf.5.gz", + "/usr/share/man/nl/man5/apt_auth.conf.5.gz", + "/usr/share/man/nl/man5/apt_preferences.5.gz", + "/usr/share/man/nl/man5/sources.list.5.gz", + "/usr/share/man/nl/man7/apt-patterns.7.gz", + "/usr/share/man/nl/man8/apt-cache.8.gz", + "/usr/share/man/nl/man8/apt-cdrom.8.gz", + "/usr/share/man/nl/man8/apt-config.8.gz", + "/usr/share/man/nl/man8/apt-get.8.gz", + "/usr/share/man/nl/man8/apt-mark.8.gz", + "/usr/share/man/nl/man8/apt-secure.8.gz", + "/usr/share/man/nl/man8/apt.8.gz", + "/usr/share/man/pl/man5/apt_preferences.5.gz", + "/usr/share/man/pl/man8/apt-cache.8.gz", + "/usr/share/man/pl/man8/apt-cdrom.8.gz", + "/usr/share/man/pl/man8/apt-config.8.gz", + "/usr/share/man/pt/man1/apt-transport-http.1.gz", + "/usr/share/man/pt/man1/apt-transport-https.1.gz", + "/usr/share/man/pt/man1/apt-transport-mirror.1.gz", + "/usr/share/man/pt/man5/apt.conf.5.gz", + "/usr/share/man/pt/man5/apt_auth.conf.5.gz", + "/usr/share/man/pt/man5/apt_preferences.5.gz", + "/usr/share/man/pt/man5/sources.list.5.gz", + "/usr/share/man/pt/man7/apt-patterns.7.gz", + "/usr/share/man/pt/man8/apt-cache.8.gz", + "/usr/share/man/pt/man8/apt-cdrom.8.gz", + "/usr/share/man/pt/man8/apt-config.8.gz", + "/usr/share/man/pt/man8/apt-get.8.gz", + "/usr/share/man/pt/man8/apt-mark.8.gz", + "/usr/share/man/pt/man8/apt-secure.8.gz", + "/usr/share/man/pt/man8/apt.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "base-files@13.8+deb13u7", + "Name": "base-files", + "Identifier": { + "PURL": "pkg:deb/debian/base-files@13.8%2Bdeb13u7?arch=amd64\u0026distro=debian-13.7", + "UID": "94433b6f299d4cc7" + }, + "Version": "13.8+deb13u7", + "Arch": "amd64", + "SrcName": "base-files", + "SrcVersion": "13.8+deb13u7", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "verbatim" + ], + "Maintainer": "Santiago Vila \u003csanvila@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "InstalledFiles": [ + "/usr/lib/os-release", + "/usr/share/base-files/dot.bashrc", + "/usr/share/base-files/dot.profile", + "/usr/share/base-files/dot.profile.md5sums", + "/usr/share/base-files/info.dir", + "/usr/share/base-files/motd", + "/usr/share/base-files/profile", + "/usr/share/base-files/profile.md5sums", + "/usr/share/base-files/staff-group-for-usr-local", + "/usr/share/common-licenses/AGPL-3.0", + "/usr/share/common-licenses/Apache-2.0", + "/usr/share/common-licenses/Artistic", + "/usr/share/common-licenses/Artistic-2.0", + "/usr/share/common-licenses/BSD", + "/usr/share/common-licenses/BSL-1.0", + "/usr/share/common-licenses/CC-BY-3.0", + "/usr/share/common-licenses/CC-BY-4.0", + "/usr/share/common-licenses/CC-BY-SA-3.0", + "/usr/share/common-licenses/CC-BY-SA-4.0", + "/usr/share/common-licenses/CC0-1.0", + "/usr/share/common-licenses/GFDL-1.1", + "/usr/share/common-licenses/GFDL-1.2", + "/usr/share/common-licenses/GFDL-1.3", + "/usr/share/common-licenses/GPL-1", + "/usr/share/common-licenses/GPL-2", + "/usr/share/common-licenses/GPL-3", + "/usr/share/common-licenses/LGPL-2", + "/usr/share/common-licenses/LGPL-2.1", + "/usr/share/common-licenses/LGPL-3", + "/usr/share/common-licenses/MPL-1.1", + "/usr/share/common-licenses/MPL-2.0", + "/usr/share/common-licenses/OFL-1.1", + "/usr/share/doc/base-files/NEWS.Debian.gz", + "/usr/share/doc/base-files/README", + "/usr/share/doc/base-files/README.FHS", + "/usr/share/doc/base-files/changelog.gz", + "/usr/share/doc/base-files/copyright", + "/usr/share/lintian/overrides/base-files" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "base-passwd@3.6.7", + "Name": "base-passwd", + "Identifier": { + "PURL": "pkg:deb/debian/base-passwd@3.6.7?arch=amd64\u0026distro=debian-13.7", + "UID": "1cd3add99b3d2533" + }, + "Version": "3.6.7", + "Arch": "amd64", + "SrcName": "base-passwd", + "SrcVersion": "3.6.7", + "Licenses": [ + "GPL-2.0-only", + "public-domain" + ], + "Maintainer": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libdebconfclient0@0.280", + "libselinux1@3.8.1-1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/sbin/update-passwd", + "/usr/share/base-passwd/group.master", + "/usr/share/base-passwd/passwd.master", + "/usr/share/doc-base/base-passwd.users-and-groups", + "/usr/share/doc/base-passwd/README", + "/usr/share/doc/base-passwd/changelog.gz", + "/usr/share/doc/base-passwd/copyright", + "/usr/share/doc/base-passwd/users-and-groups.html", + "/usr/share/doc/base-passwd/users-and-groups.txt.gz", + "/usr/share/lintian/overrides/base-passwd", + "/usr/share/man/de/man8/update-passwd.8.gz", + "/usr/share/man/es/man8/update-passwd.8.gz", + "/usr/share/man/fr/man8/update-passwd.8.gz", + "/usr/share/man/ja/man8/update-passwd.8.gz", + "/usr/share/man/man8/update-passwd.8.gz", + "/usr/share/man/pl/man8/update-passwd.8.gz", + "/usr/share/man/ro/man8/update-passwd.8.gz", + "/usr/share/man/ru/man8/update-passwd.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "bash@5.2.37-2+b10", + "Name": "bash", + "Identifier": { + "PURL": "pkg:deb/debian/bash@5.2.37-2%2Bb10?arch=amd64\u0026distro=debian-13.7", + "UID": "9ab189a103ef5617" + }, + "Version": "5.2.37", + "Release": "2+b10", + "Arch": "amd64", + "SrcName": "bash", + "SrcVersion": "5.2.37", + "SrcRelease": "2", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-3.0-only", + "GPL-3+ with Bison exception", + "GPL-2.0-or-later", + "GPL-2.0-only", + "GFDL-1.3-no-invariants-only", + "GFDL-1.3-only", + "Latex2e", + "BSD-4-Clause-UC", + "MIT", + "permissive" + ], + "Maintainer": "Matthias Klose \u003cdoko@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "base-files@13.8+deb13u7", + "debianutils@5.23.2" + ], + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "InstalledFiles": [ + "/usr/bin/bash", + "/usr/bin/bashbug", + "/usr/bin/clear_console", + "/usr/share/debianutils/shells.d/bash", + "/usr/share/doc/bash/CHANGES.gz", + "/usr/share/doc/bash/COMPAT.gz", + "/usr/share/doc/bash/INTRO.gz", + "/usr/share/doc/bash/NEWS.gz", + "/usr/share/doc/bash/POSIX.gz", + "/usr/share/doc/bash/RBASH", + "/usr/share/doc/bash/README.Debian.gz", + "/usr/share/doc/bash/README.abs-guide", + "/usr/share/doc/bash/README.commands.gz", + "/usr/share/doc/bash/README.gz", + "/usr/share/doc/bash/changelog.Debian.amd64.gz", + "/usr/share/doc/bash/changelog.Debian.gz", + "/usr/share/doc/bash/changelog.gz", + "/usr/share/doc/bash/copyright", + "/usr/share/doc/bash/inputrc.arrows", + "/usr/share/lintian/overrides/bash", + "/usr/share/locale/af/LC_MESSAGES/bash.mo", + "/usr/share/locale/bg/LC_MESSAGES/bash.mo", + "/usr/share/locale/ca/LC_MESSAGES/bash.mo", + "/usr/share/locale/cs/LC_MESSAGES/bash.mo", + "/usr/share/locale/da/LC_MESSAGES/bash.mo", + "/usr/share/locale/de/LC_MESSAGES/bash.mo", + "/usr/share/locale/el/LC_MESSAGES/bash.mo", + "/usr/share/locale/en@boldquot/LC_MESSAGES/bash.mo", + "/usr/share/locale/en@quot/LC_MESSAGES/bash.mo", + "/usr/share/locale/eo/LC_MESSAGES/bash.mo", + "/usr/share/locale/es/LC_MESSAGES/bash.mo", + "/usr/share/locale/et/LC_MESSAGES/bash.mo", + "/usr/share/locale/fi/LC_MESSAGES/bash.mo", + "/usr/share/locale/fr/LC_MESSAGES/bash.mo", + "/usr/share/locale/ga/LC_MESSAGES/bash.mo", + "/usr/share/locale/gl/LC_MESSAGES/bash.mo", + "/usr/share/locale/hr/LC_MESSAGES/bash.mo", + "/usr/share/locale/hu/LC_MESSAGES/bash.mo", + "/usr/share/locale/id/LC_MESSAGES/bash.mo", + "/usr/share/locale/it/LC_MESSAGES/bash.mo", + "/usr/share/locale/ja/LC_MESSAGES/bash.mo", + "/usr/share/locale/ko/LC_MESSAGES/bash.mo", + "/usr/share/locale/lt/LC_MESSAGES/bash.mo", + "/usr/share/locale/nb/LC_MESSAGES/bash.mo", + "/usr/share/locale/nl/LC_MESSAGES/bash.mo", + "/usr/share/locale/pl/LC_MESSAGES/bash.mo", + "/usr/share/locale/pt/LC_MESSAGES/bash.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/bash.mo", + "/usr/share/locale/ro/LC_MESSAGES/bash.mo", + "/usr/share/locale/ru/LC_MESSAGES/bash.mo", + "/usr/share/locale/sk/LC_MESSAGES/bash.mo", + "/usr/share/locale/sl/LC_MESSAGES/bash.mo", + "/usr/share/locale/sr/LC_MESSAGES/bash.mo", + "/usr/share/locale/sv/LC_MESSAGES/bash.mo", + "/usr/share/locale/tr/LC_MESSAGES/bash.mo", + "/usr/share/locale/uk/LC_MESSAGES/bash.mo", + "/usr/share/locale/vi/LC_MESSAGES/bash.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/bash.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/bash.mo", + "/usr/share/man/man1/bash.1.gz", + "/usr/share/man/man1/bashbug.1.gz", + "/usr/share/man/man1/clear_console.1.gz", + "/usr/share/man/man1/rbash.1.gz", + "/usr/share/man/man7/bash-builtins.7.gz", + "/usr/share/menu/bash" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "bsdutils@1:2.41.5-0+deb13u1", + "Name": "bsdutils", + "Identifier": { + "PURL": "pkg:deb/debian/bsdutils@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "a4b47561565a3535" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/logger", + "/usr/bin/renice", + "/usr/bin/script", + "/usr/bin/scriptlive", + "/usr/bin/scriptreplay", + "/usr/bin/wall", + "/usr/share/bash-completion/completions/logger", + "/usr/share/bash-completion/completions/renice", + "/usr/share/bash-completion/completions/script", + "/usr/share/bash-completion/completions/scriptlive", + "/usr/share/bash-completion/completions/scriptreplay", + "/usr/share/bash-completion/completions/wall", + "/usr/share/doc/bsdutils/NEWS.Debian.gz", + "/usr/share/doc/bsdutils/changelog.Debian.gz", + "/usr/share/doc/bsdutils/changelog.gz", + "/usr/share/doc/bsdutils/copyright", + "/usr/share/lintian/overrides/bsdutils", + "/usr/share/man/man1/logger.1.gz", + "/usr/share/man/man1/renice.1.gz", + "/usr/share/man/man1/script.1.gz", + "/usr/share/man/man1/scriptlive.1.gz", + "/usr/share/man/man1/scriptreplay.1.gz", + "/usr/share/man/man1/wall.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "ca-certificates@20250419", + "Name": "ca-certificates", + "Identifier": { + "PURL": "pkg:deb/debian/ca-certificates@20250419?arch=all\u0026distro=debian-13.7", + "UID": "7d49b711f66cb392" + }, + "Version": "20250419", + "Arch": "all", + "SrcName": "ca-certificates", + "SrcVersion": "20250419", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "MPL-2.0" + ], + "Maintainer": "Julien Cristau \u003cjcristau@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "debconf@1.5.91", + "openssl@3.5.7-1~deb13u2" + ], + "Layer": { + "Digest": "sha256:dbd0b7849e6c06b61e1fa6b7ffe053f246ce0075890620e3db64b47bb662433a", + "DiffID": "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca" + }, + "InstalledFiles": [ + "/usr/sbin/update-ca-certificates", + "/usr/share/ca-certificates/mozilla/ACCVRAIZ1.crt", + "/usr/share/ca-certificates/mozilla/AC_RAIZ_FNMT-RCM.crt", + "/usr/share/ca-certificates/mozilla/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.crt", + "/usr/share/ca-certificates/mozilla/ANF_Secure_Server_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/Actalis_Authentication_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/AffirmTrust_Commercial.crt", + "/usr/share/ca-certificates/mozilla/AffirmTrust_Networking.crt", + "/usr/share/ca-certificates/mozilla/AffirmTrust_Premium.crt", + "/usr/share/ca-certificates/mozilla/AffirmTrust_Premium_ECC.crt", + "/usr/share/ca-certificates/mozilla/Amazon_Root_CA_1.crt", + "/usr/share/ca-certificates/mozilla/Amazon_Root_CA_2.crt", + "/usr/share/ca-certificates/mozilla/Amazon_Root_CA_3.crt", + "/usr/share/ca-certificates/mozilla/Amazon_Root_CA_4.crt", + "/usr/share/ca-certificates/mozilla/Atos_TrustedRoot_2011.crt", + "/usr/share/ca-certificates/mozilla/Atos_TrustedRoot_Root_CA_ECC_TLS_2021.crt", + "/usr/share/ca-certificates/mozilla/Atos_TrustedRoot_Root_CA_RSA_TLS_2021.crt", + "/usr/share/ca-certificates/mozilla/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.crt", + "/usr/share/ca-certificates/mozilla/BJCA_Global_Root_CA1.crt", + "/usr/share/ca-certificates/mozilla/BJCA_Global_Root_CA2.crt", + "/usr/share/ca-certificates/mozilla/Baltimore_CyberTrust_Root.crt", + "/usr/share/ca-certificates/mozilla/Buypass_Class_2_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/Buypass_Class_3_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/CA_Disig_Root_R2.crt", + "/usr/share/ca-certificates/mozilla/CFCA_EV_ROOT.crt", + "/usr/share/ca-certificates/mozilla/COMODO_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/COMODO_ECC_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/COMODO_RSA_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/Certainly_Root_E1.crt", + "/usr/share/ca-certificates/mozilla/Certainly_Root_R1.crt", + "/usr/share/ca-certificates/mozilla/Certigna.crt", + "/usr/share/ca-certificates/mozilla/Certigna_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/Certum_EC-384_CA.crt", + "/usr/share/ca-certificates/mozilla/Certum_Trusted_Network_CA.crt", + "/usr/share/ca-certificates/mozilla/Certum_Trusted_Network_CA_2.crt", + "/usr/share/ca-certificates/mozilla/Certum_Trusted_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/CommScope_Public_Trust_ECC_Root-01.crt", + "/usr/share/ca-certificates/mozilla/CommScope_Public_Trust_ECC_Root-02.crt", + "/usr/share/ca-certificates/mozilla/CommScope_Public_Trust_RSA_Root-01.crt", + "/usr/share/ca-certificates/mozilla/CommScope_Public_Trust_RSA_Root-02.crt", + "/usr/share/ca-certificates/mozilla/Comodo_AAA_Services_root.crt", + "/usr/share/ca-certificates/mozilla/D-TRUST_BR_Root_CA_1_2020.crt", + "/usr/share/ca-certificates/mozilla/D-TRUST_BR_Root_CA_2_2023.crt", + "/usr/share/ca-certificates/mozilla/D-TRUST_EV_Root_CA_1_2020.crt", + "/usr/share/ca-certificates/mozilla/D-TRUST_EV_Root_CA_2_2023.crt", + "/usr/share/ca-certificates/mozilla/D-TRUST_Root_Class_3_CA_2_2009.crt", + "/usr/share/ca-certificates/mozilla/D-TRUST_Root_Class_3_CA_2_EV_2009.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_G2.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_G3.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Global_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Global_Root_G2.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Global_Root_G3.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_High_Assurance_EV_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_TLS_ECC_P384_Root_G5.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_TLS_RSA4096_Root_G5.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Trusted_Root_G4.crt", + "/usr/share/ca-certificates/mozilla/Entrust.net_Premium_2048_Secure_Server_CA.crt", + "/usr/share/ca-certificates/mozilla/Entrust_Root_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/Entrust_Root_Certification_Authority_-_EC1.crt", + "/usr/share/ca-certificates/mozilla/Entrust_Root_Certification_Authority_-_G2.crt", + "/usr/share/ca-certificates/mozilla/FIRMAPROFESIONAL_CA_ROOT-A_WEB.crt", + "/usr/share/ca-certificates/mozilla/GDCA_TrustAUTH_R5_ROOT.crt", + "/usr/share/ca-certificates/mozilla/GLOBALTRUST_2020.crt", + "/usr/share/ca-certificates/mozilla/GTS_Root_R1.crt", + "/usr/share/ca-certificates/mozilla/GTS_Root_R2.crt", + "/usr/share/ca-certificates/mozilla/GTS_Root_R3.crt", + "/usr/share/ca-certificates/mozilla/GTS_Root_R4.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_ECC_Root_CA_-_R4.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_ECC_Root_CA_-_R5.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_Root_CA_-_R3.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_Root_CA_-_R6.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_Root_E46.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_Root_R46.crt", + "/usr/share/ca-certificates/mozilla/Go_Daddy_Class_2_CA.crt", + "/usr/share/ca-certificates/mozilla/Go_Daddy_Root_Certificate_Authority_-_G2.crt", + "/usr/share/ca-certificates/mozilla/HARICA_TLS_ECC_Root_CA_2021.crt", + "/usr/share/ca-certificates/mozilla/HARICA_TLS_RSA_Root_CA_2021.crt", + "/usr/share/ca-certificates/mozilla/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.crt", + "/usr/share/ca-certificates/mozilla/Hellenic_Academic_and_Research_Institutions_RootCA_2015.crt", + "/usr/share/ca-certificates/mozilla/HiPKI_Root_CA_-_G1.crt", + "/usr/share/ca-certificates/mozilla/Hongkong_Post_Root_CA_3.crt", + "/usr/share/ca-certificates/mozilla/ISRG_Root_X1.crt", + "/usr/share/ca-certificates/mozilla/ISRG_Root_X2.crt", + "/usr/share/ca-certificates/mozilla/IdenTrust_Commercial_Root_CA_1.crt", + "/usr/share/ca-certificates/mozilla/IdenTrust_Public_Sector_Root_CA_1.crt", + "/usr/share/ca-certificates/mozilla/Izenpe.com.crt", + "/usr/share/ca-certificates/mozilla/Microsec_e-Szigno_Root_CA_2009.crt", + "/usr/share/ca-certificates/mozilla/Microsoft_ECC_Root_Certificate_Authority_2017.crt", + "/usr/share/ca-certificates/mozilla/Microsoft_RSA_Root_Certificate_Authority_2017.crt", + "/usr/share/ca-certificates/mozilla/NAVER_Global_Root_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/NetLock_Arany_=Class_Gold=_Főtanúsítvány.crt", + "/usr/share/ca-certificates/mozilla/OISTE_WISeKey_Global_Root_GB_CA.crt", + "/usr/share/ca-certificates/mozilla/OISTE_WISeKey_Global_Root_GC_CA.crt", + "/usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_1_G3.crt", + "/usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_2.crt", + "/usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_2_G3.crt", + "/usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_3.crt", + "/usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_3_G3.crt", + "/usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_ECC.crt", + "/usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_RSA_R2.crt", + "/usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_ECC.crt", + "/usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_RSA.crt", + "/usr/share/ca-certificates/mozilla/SSL.com_TLS_ECC_Root_CA_2022.crt", + "/usr/share/ca-certificates/mozilla/SSL.com_TLS_RSA_Root_CA_2022.crt", + "/usr/share/ca-certificates/mozilla/SZAFIR_ROOT_CA2.crt", + "/usr/share/ca-certificates/mozilla/Sectigo_Public_Server_Authentication_Root_E46.crt", + "/usr/share/ca-certificates/mozilla/Sectigo_Public_Server_Authentication_Root_R46.crt", + "/usr/share/ca-certificates/mozilla/SecureSign_Root_CA12.crt", + "/usr/share/ca-certificates/mozilla/SecureSign_Root_CA14.crt", + "/usr/share/ca-certificates/mozilla/SecureSign_Root_CA15.crt", + "/usr/share/ca-certificates/mozilla/SecureTrust_CA.crt", + "/usr/share/ca-certificates/mozilla/Secure_Global_CA.crt", + "/usr/share/ca-certificates/mozilla/Security_Communication_ECC_RootCA1.crt", + "/usr/share/ca-certificates/mozilla/Security_Communication_RootCA2.crt", + "/usr/share/ca-certificates/mozilla/Starfield_Class_2_CA.crt", + "/usr/share/ca-certificates/mozilla/Starfield_Root_Certificate_Authority_-_G2.crt", + "/usr/share/ca-certificates/mozilla/Starfield_Services_Root_Certificate_Authority_-_G2.crt", + "/usr/share/ca-certificates/mozilla/SwissSign_Gold_CA_-_G2.crt", + "/usr/share/ca-certificates/mozilla/T-TeleSec_GlobalRoot_Class_2.crt", + "/usr/share/ca-certificates/mozilla/T-TeleSec_GlobalRoot_Class_3.crt", + "/usr/share/ca-certificates/mozilla/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.crt", + "/usr/share/ca-certificates/mozilla/TWCA_CYBER_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/TWCA_Global_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/TWCA_Root_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/Telekom_Security_TLS_ECC_Root_2020.crt", + "/usr/share/ca-certificates/mozilla/Telekom_Security_TLS_RSA_Root_2023.crt", + "/usr/share/ca-certificates/mozilla/TeliaSonera_Root_CA_v1.crt", + "/usr/share/ca-certificates/mozilla/Telia_Root_CA_v2.crt", + "/usr/share/ca-certificates/mozilla/TrustAsia_Global_Root_CA_G3.crt", + "/usr/share/ca-certificates/mozilla/TrustAsia_Global_Root_CA_G4.crt", + "/usr/share/ca-certificates/mozilla/Trustwave_Global_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/Trustwave_Global_ECC_P256_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/Trustwave_Global_ECC_P384_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/TunTrust_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/UCA_Extended_Validation_Root.crt", + "/usr/share/ca-certificates/mozilla/UCA_Global_G2_Root.crt", + "/usr/share/ca-certificates/mozilla/USERTrust_ECC_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/USERTrust_RSA_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/XRamp_Global_CA_Root.crt", + "/usr/share/ca-certificates/mozilla/certSIGN_ROOT_CA.crt", + "/usr/share/ca-certificates/mozilla/certSIGN_Root_CA_G2.crt", + "/usr/share/ca-certificates/mozilla/e-Szigno_Root_CA_2017.crt", + "/usr/share/ca-certificates/mozilla/ePKI_Root_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/emSign_ECC_Root_CA_-_C3.crt", + "/usr/share/ca-certificates/mozilla/emSign_ECC_Root_CA_-_G3.crt", + "/usr/share/ca-certificates/mozilla/emSign_Root_CA_-_C1.crt", + "/usr/share/ca-certificates/mozilla/emSign_Root_CA_-_G1.crt", + "/usr/share/ca-certificates/mozilla/vTrus_ECC_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/vTrus_Root_CA.crt", + "/usr/share/doc/ca-certificates/README.Debian", + "/usr/share/doc/ca-certificates/changelog.gz", + "/usr/share/doc/ca-certificates/copyright", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/Makefile", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/README", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/ca-certificates-local.triggers", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/changelog", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/compat", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/control", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/copyright", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/postrm", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/rules", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/source/format", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/local/Local_Root_CA.crt", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/local/Makefile", + "/usr/share/man/man8/update-ca-certificates.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "coreutils@9.7-3", + "Name": "coreutils", + "Identifier": { + "PURL": "pkg:deb/debian/coreutils@9.7-3?arch=amd64\u0026distro=debian-13.7", + "UID": "cb4a55f50bda2393" + }, + "Version": "9.7", + "Release": "3", + "Arch": "amd64", + "SrcName": "coreutils", + "SrcVersion": "9.7", + "SrcRelease": "3", + "Licenses": [ + "GPL-3.0-or-later", + "BSD-4-Clause-UC", + "GPL-3.0-only", + "ISC", + "FSFULLR", + "GFDL-1.3-no-invariants-only", + "GFDL-1.3-only" + ], + "Maintainer": "Michael Stone \u003cmstone@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/[", + "/usr/bin/arch", + "/usr/bin/b2sum", + "/usr/bin/base32", + "/usr/bin/base64", + "/usr/bin/basename", + "/usr/bin/basenc", + "/usr/bin/cat", + "/usr/bin/chcon", + "/usr/bin/chgrp", + "/usr/bin/chmod", + "/usr/bin/chown", + "/usr/bin/cksum", + "/usr/bin/comm", + "/usr/bin/cp", + "/usr/bin/csplit", + "/usr/bin/cut", + "/usr/bin/date", + "/usr/bin/dd", + "/usr/bin/df", + "/usr/bin/dir", + "/usr/bin/dircolors", + "/usr/bin/dirname", + "/usr/bin/du", + "/usr/bin/echo", + "/usr/bin/env", + "/usr/bin/expand", + "/usr/bin/expr", + "/usr/bin/factor", + "/usr/bin/false", + "/usr/bin/fmt", + "/usr/bin/fold", + "/usr/bin/groups", + "/usr/bin/head", + "/usr/bin/hostid", + "/usr/bin/id", + "/usr/bin/install", + "/usr/bin/join", + "/usr/bin/link", + "/usr/bin/ln", + "/usr/bin/logname", + "/usr/bin/ls", + "/usr/bin/md5sum", + "/usr/bin/mkdir", + "/usr/bin/mkfifo", + "/usr/bin/mknod", + "/usr/bin/mktemp", + "/usr/bin/mv", + "/usr/bin/nice", + "/usr/bin/nl", + "/usr/bin/nohup", + "/usr/bin/nproc", + "/usr/bin/numfmt", + "/usr/bin/od", + "/usr/bin/paste", + "/usr/bin/pathchk", + "/usr/bin/pinky", + "/usr/bin/pr", + "/usr/bin/printenv", + "/usr/bin/printf", + "/usr/bin/ptx", + "/usr/bin/pwd", + "/usr/bin/readlink", + "/usr/bin/realpath", + "/usr/bin/rm", + "/usr/bin/rmdir", + "/usr/bin/runcon", + "/usr/bin/seq", + "/usr/bin/sha1sum", + "/usr/bin/sha224sum", + "/usr/bin/sha256sum", + "/usr/bin/sha384sum", + "/usr/bin/sha512sum", + "/usr/bin/shred", + "/usr/bin/shuf", + "/usr/bin/sleep", + "/usr/bin/sort", + "/usr/bin/split", + "/usr/bin/stat", + "/usr/bin/stdbuf", + "/usr/bin/stty", + "/usr/bin/sum", + "/usr/bin/sync", + "/usr/bin/tac", + "/usr/bin/tail", + "/usr/bin/tee", + "/usr/bin/test", + "/usr/bin/timeout", + "/usr/bin/touch", + "/usr/bin/tr", + "/usr/bin/true", + "/usr/bin/truncate", + "/usr/bin/tsort", + "/usr/bin/tty", + "/usr/bin/uname", + "/usr/bin/unexpand", + "/usr/bin/uniq", + "/usr/bin/unlink", + "/usr/bin/users", + "/usr/bin/vdir", + "/usr/bin/wc", + "/usr/bin/who", + "/usr/bin/whoami", + "/usr/bin/yes", + "/usr/libexec/coreutils/libstdbuf.so", + "/usr/sbin/chroot", + "/usr/share/doc/coreutils/AUTHORS", + "/usr/share/doc/coreutils/NEWS.gz", + "/usr/share/doc/coreutils/README.Debian", + "/usr/share/doc/coreutils/README.gz", + "/usr/share/doc/coreutils/THANKS.gz", + "/usr/share/doc/coreutils/TODO.gz", + "/usr/share/doc/coreutils/changelog.Debian.gz", + "/usr/share/doc/coreutils/changelog.gz", + "/usr/share/doc/coreutils/copyright", + "/usr/share/info/coreutils.info.gz", + "/usr/share/lintian/overrides/coreutils", + "/usr/share/locale/af/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/be/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/bg/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ca/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/cs/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/da/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/de/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/el/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/eo/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/es/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/et/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/eu/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/fi/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/fr/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ga/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/gl/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/hr/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/hu/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ia/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/id/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/it/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ja/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ka/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/kk/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ko/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/lg/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/lt/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ms/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/nb/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/nl/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/pl/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/pt/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ro/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ru/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/sk/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/sl/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/sr/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/sv/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ta/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/tr/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/uk/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/vi/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/coreutils.mo", + "/usr/share/man/man1/arch.1.gz", + "/usr/share/man/man1/b2sum.1.gz", + "/usr/share/man/man1/base32.1.gz", + "/usr/share/man/man1/base64.1.gz", + "/usr/share/man/man1/basename.1.gz", + "/usr/share/man/man1/basenc.1.gz", + "/usr/share/man/man1/cat.1.gz", + "/usr/share/man/man1/chcon.1.gz", + "/usr/share/man/man1/chgrp.1.gz", + "/usr/share/man/man1/chmod.1.gz", + "/usr/share/man/man1/chown.1.gz", + "/usr/share/man/man1/cksum.1.gz", + "/usr/share/man/man1/comm.1.gz", + "/usr/share/man/man1/cp.1.gz", + "/usr/share/man/man1/csplit.1.gz", + "/usr/share/man/man1/cut.1.gz", + "/usr/share/man/man1/date.1.gz", + "/usr/share/man/man1/dd.1.gz", + "/usr/share/man/man1/df.1.gz", + "/usr/share/man/man1/dir.1.gz", + "/usr/share/man/man1/dircolors.1.gz", + "/usr/share/man/man1/dirname.1.gz", + "/usr/share/man/man1/du.1.gz", + "/usr/share/man/man1/echo.1.gz", + "/usr/share/man/man1/env.1.gz", + "/usr/share/man/man1/expand.1.gz", + "/usr/share/man/man1/expr.1.gz", + "/usr/share/man/man1/factor.1.gz", + "/usr/share/man/man1/false.1.gz", + "/usr/share/man/man1/fmt.1.gz", + "/usr/share/man/man1/fold.1.gz", + "/usr/share/man/man1/groups.1.gz", + "/usr/share/man/man1/head.1.gz", + "/usr/share/man/man1/hostid.1.gz", + "/usr/share/man/man1/id.1.gz", + "/usr/share/man/man1/install.1.gz", + "/usr/share/man/man1/join.1.gz", + "/usr/share/man/man1/link.1.gz", + "/usr/share/man/man1/ln.1.gz", + "/usr/share/man/man1/logname.1.gz", + "/usr/share/man/man1/ls.1.gz", + "/usr/share/man/man1/md5sum.1.gz", + "/usr/share/man/man1/mkdir.1.gz", + "/usr/share/man/man1/mkfifo.1.gz", + "/usr/share/man/man1/mknod.1.gz", + "/usr/share/man/man1/mktemp.1.gz", + "/usr/share/man/man1/mv.1.gz", + "/usr/share/man/man1/nice.1.gz", + "/usr/share/man/man1/nl.1.gz", + "/usr/share/man/man1/nohup.1.gz", + "/usr/share/man/man1/nproc.1.gz", + "/usr/share/man/man1/numfmt.1.gz", + "/usr/share/man/man1/od.1.gz", + "/usr/share/man/man1/paste.1.gz", + "/usr/share/man/man1/pathchk.1.gz", + "/usr/share/man/man1/pinky.1.gz", + "/usr/share/man/man1/pr.1.gz", + "/usr/share/man/man1/printenv.1.gz", + "/usr/share/man/man1/printf.1.gz", + "/usr/share/man/man1/ptx.1.gz", + "/usr/share/man/man1/pwd.1.gz", + "/usr/share/man/man1/readlink.1.gz", + "/usr/share/man/man1/realpath.1.gz", + "/usr/share/man/man1/rm.1.gz", + "/usr/share/man/man1/rmdir.1.gz", + "/usr/share/man/man1/runcon.1.gz", + "/usr/share/man/man1/seq.1.gz", + "/usr/share/man/man1/sha1sum.1.gz", + "/usr/share/man/man1/sha224sum.1.gz", + "/usr/share/man/man1/sha256sum.1.gz", + "/usr/share/man/man1/sha384sum.1.gz", + "/usr/share/man/man1/sha512sum.1.gz", + "/usr/share/man/man1/shred.1.gz", + "/usr/share/man/man1/shuf.1.gz", + "/usr/share/man/man1/sleep.1.gz", + "/usr/share/man/man1/sort.1.gz", + "/usr/share/man/man1/split.1.gz", + "/usr/share/man/man1/stat.1.gz", + "/usr/share/man/man1/stdbuf.1.gz", + "/usr/share/man/man1/stty.1.gz", + "/usr/share/man/man1/sum.1.gz", + "/usr/share/man/man1/sync.1.gz", + "/usr/share/man/man1/tac.1.gz", + "/usr/share/man/man1/tail.1.gz", + "/usr/share/man/man1/tee.1.gz", + "/usr/share/man/man1/test.1.gz", + "/usr/share/man/man1/timeout.1.gz", + "/usr/share/man/man1/touch.1.gz", + "/usr/share/man/man1/tr.1.gz", + "/usr/share/man/man1/true.1.gz", + "/usr/share/man/man1/truncate.1.gz", + "/usr/share/man/man1/tsort.1.gz", + "/usr/share/man/man1/tty.1.gz", + "/usr/share/man/man1/uname.1.gz", + "/usr/share/man/man1/unexpand.1.gz", + "/usr/share/man/man1/uniq.1.gz", + "/usr/share/man/man1/unlink.1.gz", + "/usr/share/man/man1/users.1.gz", + "/usr/share/man/man1/vdir.1.gz", + "/usr/share/man/man1/wc.1.gz", + "/usr/share/man/man1/who.1.gz", + "/usr/share/man/man1/whoami.1.gz", + "/usr/share/man/man1/yes.1.gz", + "/usr/share/man/man8/chroot.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "dash@0.5.12-12", + "Name": "dash", + "Identifier": { + "PURL": "pkg:deb/debian/dash@0.5.12-12?arch=amd64\u0026distro=debian-13.7", + "UID": "4990b2098a2a3724" + }, + "Version": "0.5.12", + "Release": "12", + "Arch": "amd64", + "SrcName": "dash", + "SrcVersion": "0.5.12", + "SrcRelease": "12", + "Licenses": [ + "BSD-3-Clause", + "public-domain", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Andrej Shadura \u003candrewsh@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "debianutils@5.23.2" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/dash", + "/usr/share/debianutils/shells.d/dash", + "/usr/share/doc/dash/README.Debian.diet", + "/usr/share/doc/dash/README.source", + "/usr/share/doc/dash/changelog.Debian.gz", + "/usr/share/doc/dash/changelog.gz", + "/usr/share/doc/dash/copyright", + "/usr/share/lintian/overrides/dash", + "/usr/share/man/man1/dash.1.gz", + "/usr/share/menu/dash" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "debconf@1.5.91", + "Name": "debconf", + "Identifier": { + "PURL": "pkg:deb/debian/debconf@1.5.91?arch=all\u0026distro=debian-13.7", + "UID": "f7c8b7ba83ed5cfe" + }, + "Version": "1.5.91", + "Arch": "all", + "SrcName": "debconf", + "SrcVersion": "1.5.91", + "Licenses": [ + "BSD-2-Clause" + ], + "Maintainer": "Debconf Developers \u003cdebconf-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/debconf", + "/usr/bin/debconf-apt-progress", + "/usr/bin/debconf-communicate", + "/usr/bin/debconf-copydb", + "/usr/bin/debconf-escape", + "/usr/bin/debconf-set-selections", + "/usr/bin/debconf-show", + "/usr/sbin/dpkg-preconfigure", + "/usr/sbin/dpkg-reconfigure", + "/usr/share/bash-completion/completions/debconf", + "/usr/share/debconf/confmodule", + "/usr/share/debconf/confmodule.sh", + "/usr/share/debconf/debconf.conf", + "/usr/share/debconf/fix_db.pl", + "/usr/share/debconf/frontend", + "/usr/share/doc/debconf/README.Debian", + "/usr/share/doc/debconf/changelog.gz", + "/usr/share/doc/debconf/copyright", + "/usr/share/lintian/overrides/debconf", + "/usr/share/man/man1/debconf-apt-progress.1.gz", + "/usr/share/man/man1/debconf-communicate.1.gz", + "/usr/share/man/man1/debconf-copydb.1.gz", + "/usr/share/man/man1/debconf-escape.1.gz", + "/usr/share/man/man1/debconf-set-selections.1.gz", + "/usr/share/man/man1/debconf-show.1.gz", + "/usr/share/man/man1/debconf.1.gz", + "/usr/share/man/man8/dpkg-preconfigure.8.gz", + "/usr/share/man/man8/dpkg-reconfigure.8.gz", + "/usr/share/perl5/Debconf/AutoSelect.pm", + "/usr/share/perl5/Debconf/Base.pm", + "/usr/share/perl5/Debconf/Client/ConfModule.pm", + "/usr/share/perl5/Debconf/ConfModule.pm", + "/usr/share/perl5/Debconf/Config.pm", + "/usr/share/perl5/Debconf/Db.pm", + "/usr/share/perl5/Debconf/DbDriver.pm", + "/usr/share/perl5/Debconf/DbDriver/Backup.pm", + "/usr/share/perl5/Debconf/DbDriver/Cache.pm", + "/usr/share/perl5/Debconf/DbDriver/Copy.pm", + "/usr/share/perl5/Debconf/DbDriver/Debug.pm", + "/usr/share/perl5/Debconf/DbDriver/DirTree.pm", + "/usr/share/perl5/Debconf/DbDriver/Directory.pm", + "/usr/share/perl5/Debconf/DbDriver/File.pm", + "/usr/share/perl5/Debconf/DbDriver/LDAP.pm", + "/usr/share/perl5/Debconf/DbDriver/PackageDir.pm", + "/usr/share/perl5/Debconf/DbDriver/Pipe.pm", + "/usr/share/perl5/Debconf/DbDriver/Stack.pm", + "/usr/share/perl5/Debconf/Element.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Boolean.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Error.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Note.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Password.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Progress.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Select.pm", + "/usr/share/perl5/Debconf/Element/Dialog/String.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Text.pm", + "/usr/share/perl5/Debconf/Element/Editor/Boolean.pm", + "/usr/share/perl5/Debconf/Element/Editor/Error.pm", + "/usr/share/perl5/Debconf/Element/Editor/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Editor/Note.pm", + "/usr/share/perl5/Debconf/Element/Editor/Password.pm", + "/usr/share/perl5/Debconf/Element/Editor/Progress.pm", + "/usr/share/perl5/Debconf/Element/Editor/Select.pm", + "/usr/share/perl5/Debconf/Element/Editor/String.pm", + "/usr/share/perl5/Debconf/Element/Editor/Text.pm", + "/usr/share/perl5/Debconf/Element/Gnome.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Boolean.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Error.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Note.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Password.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Progress.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Select.pm", + "/usr/share/perl5/Debconf/Element/Gnome/String.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Text.pm", + "/usr/share/perl5/Debconf/Element/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Boolean.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Error.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Note.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Password.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Progress.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Select.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/String.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Text.pm", + "/usr/share/perl5/Debconf/Element/Select.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Boolean.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Error.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Note.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Password.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Progress.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Select.pm", + "/usr/share/perl5/Debconf/Element/Teletype/String.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Text.pm", + "/usr/share/perl5/Debconf/Element/Web/Boolean.pm", + "/usr/share/perl5/Debconf/Element/Web/Error.pm", + "/usr/share/perl5/Debconf/Element/Web/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Web/Note.pm", + "/usr/share/perl5/Debconf/Element/Web/Password.pm", + "/usr/share/perl5/Debconf/Element/Web/Progress.pm", + "/usr/share/perl5/Debconf/Element/Web/Select.pm", + "/usr/share/perl5/Debconf/Element/Web/String.pm", + "/usr/share/perl5/Debconf/Element/Web/Text.pm", + "/usr/share/perl5/Debconf/Encoding.pm", + "/usr/share/perl5/Debconf/Format.pm", + "/usr/share/perl5/Debconf/Format/822.pm", + "/usr/share/perl5/Debconf/FrontEnd.pm", + "/usr/share/perl5/Debconf/FrontEnd/Dialog.pm", + "/usr/share/perl5/Debconf/FrontEnd/Editor.pm", + "/usr/share/perl5/Debconf/FrontEnd/Gnome.pm", + "/usr/share/perl5/Debconf/FrontEnd/Kde.pm", + "/usr/share/perl5/Debconf/FrontEnd/Noninteractive.pm", + "/usr/share/perl5/Debconf/FrontEnd/Passthrough.pm", + "/usr/share/perl5/Debconf/FrontEnd/Readline.pm", + "/usr/share/perl5/Debconf/FrontEnd/ScreenSize.pm", + "/usr/share/perl5/Debconf/FrontEnd/Teletype.pm", + "/usr/share/perl5/Debconf/FrontEnd/Text.pm", + "/usr/share/perl5/Debconf/FrontEnd/Web.pm", + "/usr/share/perl5/Debconf/Gettext.pm", + "/usr/share/perl5/Debconf/Iterator.pm", + "/usr/share/perl5/Debconf/Log.pm", + "/usr/share/perl5/Debconf/Path.pm", + "/usr/share/perl5/Debconf/Priority.pm", + "/usr/share/perl5/Debconf/Question.pm", + "/usr/share/perl5/Debconf/Template.pm", + "/usr/share/perl5/Debconf/Template/Transient.pm", + "/usr/share/perl5/Debconf/TmpFile.pm", + "/usr/share/perl5/Debian/DebConf/Client/ConfModule.pm", + "/usr/share/pixmaps/debian-logo.png" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "debian-archive-keyring@2025.1", + "Name": "debian-archive-keyring", + "Identifier": { + "PURL": "pkg:deb/debian/debian-archive-keyring@2025.1?arch=all\u0026distro=debian-13.7", + "UID": "a22d861380b1187c" + }, + "Version": "2025.1", + "Arch": "all", + "SrcName": "debian-archive-keyring", + "SrcVersion": "2025.1", + "Licenses": [ + "GPL-2.0-or-later" + ], + "Maintainer": "Debian Release Team \u003cpackages@release.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/share/doc/debian-archive-keyring/NEWS.Debian.gz", + "/usr/share/doc/debian-archive-keyring/README", + "/usr/share/doc/debian-archive-keyring/changelog.gz", + "/usr/share/doc/debian-archive-keyring/copyright", + "/usr/share/keyrings/debian-archive-bookworm-automatic.pgp", + "/usr/share/keyrings/debian-archive-bookworm-security-automatic.pgp", + "/usr/share/keyrings/debian-archive-bookworm-stable.pgp", + "/usr/share/keyrings/debian-archive-bullseye-automatic.pgp", + "/usr/share/keyrings/debian-archive-bullseye-security-automatic.pgp", + "/usr/share/keyrings/debian-archive-bullseye-stable.pgp", + "/usr/share/keyrings/debian-archive-keyring.pgp", + "/usr/share/keyrings/debian-archive-removed-keys.pgp", + "/usr/share/keyrings/debian-archive-trixie-automatic.pgp", + "/usr/share/keyrings/debian-archive-trixie-security-automatic.pgp", + "/usr/share/keyrings/debian-archive-trixie-stable.pgp" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "debianutils@5.23.2", + "Name": "debianutils", + "Identifier": { + "PURL": "pkg:deb/debian/debianutils@5.23.2?arch=amd64\u0026distro=debian-13.7", + "UID": "3c5d0b66afafddbb" + }, + "Version": "5.23.2", + "Arch": "amd64", + "SrcName": "debianutils", + "SrcVersion": "5.23.2", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "public-domain", + "SMAIL-GPL" + ], + "Maintainer": "Ileana Dumitrescu \u003cileanadumitrescu95@gmail.com\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/ischroot", + "/usr/bin/run-parts", + "/usr/bin/savelog", + "/usr/bin/tempfile", + "/usr/bin/which.debianutils", + "/usr/sbin/add-shell", + "/usr/sbin/installkernel", + "/usr/sbin/remove-shell", + "/usr/sbin/update-shells", + "/usr/share/debianutils/shells", + "/usr/share/doc/debianutils/README.shells", + "/usr/share/doc/debianutils/changelog.gz", + "/usr/share/doc/debianutils/copyright", + "/usr/share/man/de/man1/which.debianutils.1.gz", + "/usr/share/man/de/man8/add-shell.8.gz", + "/usr/share/man/de/man8/installkernel.8.gz", + "/usr/share/man/de/man8/remove-shell.8.gz", + "/usr/share/man/de/man8/run-parts.8.gz", + "/usr/share/man/de/man8/savelog.8.gz", + "/usr/share/man/es/man1/which.debianutils.1.gz", + "/usr/share/man/es/man8/add-shell.8.gz", + "/usr/share/man/es/man8/installkernel.8.gz", + "/usr/share/man/es/man8/remove-shell.8.gz", + "/usr/share/man/es/man8/run-parts.8.gz", + "/usr/share/man/es/man8/savelog.8.gz", + "/usr/share/man/fr/man1/which.debianutils.1.gz", + "/usr/share/man/fr/man8/add-shell.8.gz", + "/usr/share/man/fr/man8/installkernel.8.gz", + "/usr/share/man/fr/man8/remove-shell.8.gz", + "/usr/share/man/fr/man8/run-parts.8.gz", + "/usr/share/man/fr/man8/savelog.8.gz", + "/usr/share/man/it/man1/which.debianutils.1.gz", + "/usr/share/man/it/man8/add-shell.8.gz", + "/usr/share/man/it/man8/installkernel.8.gz", + "/usr/share/man/it/man8/remove-shell.8.gz", + "/usr/share/man/it/man8/run-parts.8.gz", + "/usr/share/man/it/man8/savelog.8.gz", + "/usr/share/man/ja/man1/which.debianutils.1.gz", + "/usr/share/man/ja/man8/add-shell.8.gz", + "/usr/share/man/ja/man8/installkernel.8.gz", + "/usr/share/man/ja/man8/remove-shell.8.gz", + "/usr/share/man/ja/man8/run-parts.8.gz", + "/usr/share/man/ja/man8/savelog.8.gz", + "/usr/share/man/man1/ischroot.1.gz", + "/usr/share/man/man1/tempfile.1.gz", + "/usr/share/man/man1/which.debianutils.1.gz", + "/usr/share/man/man8/add-shell.8.gz", + "/usr/share/man/man8/installkernel.8.gz", + "/usr/share/man/man8/remove-shell.8.gz", + "/usr/share/man/man8/run-parts.8.gz", + "/usr/share/man/man8/savelog.8.gz", + "/usr/share/man/man8/update-shells.8.gz", + "/usr/share/man/pl/man1/which.debianutils.1.gz", + "/usr/share/man/pl/man8/add-shell.8.gz", + "/usr/share/man/pl/man8/installkernel.8.gz", + "/usr/share/man/pl/man8/remove-shell.8.gz", + "/usr/share/man/pl/man8/run-parts.8.gz", + "/usr/share/man/pl/man8/savelog.8.gz", + "/usr/share/man/pt/man1/which.debianutils.1.gz", + "/usr/share/man/pt/man8/add-shell.8.gz", + "/usr/share/man/pt/man8/installkernel.8.gz", + "/usr/share/man/pt/man8/remove-shell.8.gz", + "/usr/share/man/pt/man8/run-parts.8.gz", + "/usr/share/man/pt/man8/savelog.8.gz", + "/usr/share/man/sl/man1/which.debianutils.1.gz", + "/usr/share/man/sl/man8/add-shell.8.gz", + "/usr/share/man/sl/man8/installkernel.8.gz", + "/usr/share/man/sl/man8/remove-shell.8.gz", + "/usr/share/man/sl/man8/run-parts.8.gz", + "/usr/share/man/sl/man8/savelog.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "diffutils@1:3.10-4", + "Name": "diffutils", + "Identifier": { + "PURL": "pkg:deb/debian/diffutils@3.10-4?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "852f693a78aaa149" + }, + "Version": "3.10", + "Release": "4", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "diffutils", + "SrcVersion": "3.10", + "SrcRelease": "4", + "SrcEpoch": 1, + "Licenses": [ + "GPL-3.0-or-later", + "FSFULLR", + "LGPL-2.1-or-later", + "GPL-3.0-with-autoconf-exception+", + "GPL-3.0-only", + "GPL-3+ with texinfo exception", + "LGPL-2.0-or-later", + "GPL-2.0-or-later", + "X11", + "FSFAP", + "GFDL-1.3-no-invariants-only", + "LGPL-3.0-or-later", + "LGPL-3.0-only", + "public-domain", + "LGPL-2.0-only", + "LGPL-2.1-only", + "GPL-2.0-only", + "GFDL-1.3-only" + ], + "Maintainer": "Santiago Vila \u003csanvila@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/cmp", + "/usr/bin/diff", + "/usr/bin/diff3", + "/usr/bin/sdiff", + "/usr/share/doc/diffutils/NEWS.gz", + "/usr/share/doc/diffutils/changelog.Debian.gz", + "/usr/share/doc/diffutils/changelog.gz", + "/usr/share/doc/diffutils/copyright", + "/usr/share/info/diffutils.info.gz", + "/usr/share/locale/bg/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ca/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/cs/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/da/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/de/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/el/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/eo/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/es/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/fi/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/fr/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ga/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/gl/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/he/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/hr/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/hu/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/id/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/it/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ja/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ka/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ko/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/lv/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ms/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/nb/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/nl/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/pl/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/pt/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ro/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ru/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/sr/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/sv/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/tr/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/uk/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/vi/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/diffutils.mo", + "/usr/share/man/man1/cmp.1.gz", + "/usr/share/man/man1/diff.1.gz", + "/usr/share/man/man1/diff3.1.gz", + "/usr/share/man/man1/sdiff.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "dpkg@1.22.22", + "Name": "dpkg", + "Identifier": { + "PURL": "pkg:deb/debian/dpkg@1.22.22?arch=amd64\u0026distro=debian-13.7", + "UID": "7b97f27e3bec0417" + }, + "Version": "1.22.22", + "Arch": "amd64", + "SrcName": "dpkg", + "SrcVersion": "1.22.22", + "Licenses": [ + "GPL-2.0-or-later", + "public-domain-s-s-d", + "GPL-2.0-only" + ], + "Maintainer": "Dpkg Developers \u003cdebian-dpkg@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "tar@1.35+dfsg-3.1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/dpkg", + "/usr/bin/dpkg-deb", + "/usr/bin/dpkg-divert", + "/usr/bin/dpkg-maintscript-helper", + "/usr/bin/dpkg-query", + "/usr/bin/dpkg-realpath", + "/usr/bin/dpkg-split", + "/usr/bin/dpkg-statoverride", + "/usr/bin/dpkg-trigger", + "/usr/bin/update-alternatives", + "/usr/lib/systemd/system/dpkg-db-backup.service", + "/usr/lib/systemd/system/dpkg-db-backup.timer", + "/usr/libexec/dpkg/dpkg-db-backup", + "/usr/libexec/dpkg/dpkg-db-keeper", + "/usr/sbin/start-stop-daemon", + "/usr/share/doc/dpkg/AUTHORS", + "/usr/share/doc/dpkg/README.api", + "/usr/share/doc/dpkg/README.bug-usertags.gz", + "/usr/share/doc/dpkg/README.feature-removal-schedule.gz", + "/usr/share/doc/dpkg/THANKS.gz", + "/usr/share/doc/dpkg/changelog.gz", + "/usr/share/doc/dpkg/copyright", + "/usr/share/dpkg/abitable", + "/usr/share/dpkg/cputable", + "/usr/share/dpkg/ostable", + "/usr/share/dpkg/sh/dpkg-error.sh", + "/usr/share/dpkg/tupletable", + "/usr/share/lintian/overrides/dpkg", + "/usr/share/lintian/profiles/dpkg/main.profile", + "/usr/share/locale/ast/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/bs/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ca/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/cs/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/da/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/de/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/dz/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/el/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/eo/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/es/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/et/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/eu/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/fr/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/gl/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/hu/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/id/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/it/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ja/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/km/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ko/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ku/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/lt/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/mr/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/nb/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ne/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/nl/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/nn/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/oc/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/pa/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/pl/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/pt/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ro/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ru/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/sk/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/sv/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/th/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/tl/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/tr/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/vi/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/dpkg.mo", + "/usr/share/man/de/man1/dpkg-deb.1.gz", + "/usr/share/man/de/man1/dpkg-divert.1.gz", + "/usr/share/man/de/man1/dpkg-maintscript-helper.1.gz", + "/usr/share/man/de/man1/dpkg-query.1.gz", + "/usr/share/man/de/man1/dpkg-realpath.1.gz", + "/usr/share/man/de/man1/dpkg-split.1.gz", + "/usr/share/man/de/man1/dpkg-statoverride.1.gz", + "/usr/share/man/de/man1/dpkg-trigger.1.gz", + "/usr/share/man/de/man1/dpkg.1.gz", + "/usr/share/man/de/man1/update-alternatives.1.gz", + "/usr/share/man/de/man5/dpkg.cfg.5.gz", + "/usr/share/man/de/man8/start-stop-daemon.8.gz", + "/usr/share/man/es/man5/dpkg.cfg.5.gz", + "/usr/share/man/fr/man1/dpkg-divert.1.gz", + "/usr/share/man/fr/man1/dpkg-maintscript-helper.1.gz", + "/usr/share/man/fr/man1/dpkg-query.1.gz", + "/usr/share/man/fr/man1/dpkg-realpath.1.gz", + "/usr/share/man/fr/man1/dpkg-split.1.gz", + "/usr/share/man/fr/man1/dpkg-trigger.1.gz", + "/usr/share/man/fr/man1/update-alternatives.1.gz", + "/usr/share/man/fr/man5/dpkg.cfg.5.gz", + "/usr/share/man/fr/man8/start-stop-daemon.8.gz", + "/usr/share/man/it/man5/dpkg.cfg.5.gz", + "/usr/share/man/ja/man5/dpkg.cfg.5.gz", + "/usr/share/man/man1/dpkg-deb.1.gz", + "/usr/share/man/man1/dpkg-divert.1.gz", + "/usr/share/man/man1/dpkg-maintscript-helper.1.gz", + "/usr/share/man/man1/dpkg-query.1.gz", + "/usr/share/man/man1/dpkg-realpath.1.gz", + "/usr/share/man/man1/dpkg-split.1.gz", + "/usr/share/man/man1/dpkg-statoverride.1.gz", + "/usr/share/man/man1/dpkg-trigger.1.gz", + "/usr/share/man/man1/dpkg.1.gz", + "/usr/share/man/man1/update-alternatives.1.gz", + "/usr/share/man/man5/dpkg.cfg.5.gz", + "/usr/share/man/man8/start-stop-daemon.8.gz", + "/usr/share/man/nl/man1/dpkg-deb.1.gz", + "/usr/share/man/nl/man1/dpkg-divert.1.gz", + "/usr/share/man/nl/man1/dpkg-maintscript-helper.1.gz", + "/usr/share/man/nl/man1/dpkg-query.1.gz", + "/usr/share/man/nl/man1/dpkg-realpath.1.gz", + "/usr/share/man/nl/man1/dpkg-split.1.gz", + "/usr/share/man/nl/man1/dpkg-statoverride.1.gz", + "/usr/share/man/nl/man1/dpkg-trigger.1.gz", + "/usr/share/man/nl/man1/dpkg.1.gz", + "/usr/share/man/nl/man1/update-alternatives.1.gz", + "/usr/share/man/nl/man5/dpkg.cfg.5.gz", + "/usr/share/man/nl/man8/start-stop-daemon.8.gz", + "/usr/share/man/pl/man5/dpkg.cfg.5.gz", + "/usr/share/man/pt/man1/dpkg-deb.1.gz", + "/usr/share/man/pt/man1/dpkg-divert.1.gz", + "/usr/share/man/pt/man1/dpkg-maintscript-helper.1.gz", + "/usr/share/man/pt/man1/dpkg-query.1.gz", + "/usr/share/man/pt/man1/dpkg-realpath.1.gz", + "/usr/share/man/pt/man1/dpkg-split.1.gz", + "/usr/share/man/pt/man1/dpkg-statoverride.1.gz", + "/usr/share/man/pt/man1/dpkg-trigger.1.gz", + "/usr/share/man/pt/man1/dpkg.1.gz", + "/usr/share/man/pt/man1/update-alternatives.1.gz", + "/usr/share/man/pt/man5/dpkg.cfg.5.gz", + "/usr/share/man/pt/man8/start-stop-daemon.8.gz", + "/usr/share/man/sv/man1/dpkg-deb.1.gz", + "/usr/share/man/sv/man1/dpkg-divert.1.gz", + "/usr/share/man/sv/man1/dpkg-maintscript-helper.1.gz", + "/usr/share/man/sv/man1/dpkg-query.1.gz", + "/usr/share/man/sv/man1/dpkg-realpath.1.gz", + "/usr/share/man/sv/man1/dpkg-split.1.gz", + "/usr/share/man/sv/man1/dpkg-statoverride.1.gz", + "/usr/share/man/sv/man1/dpkg-trigger.1.gz", + "/usr/share/man/sv/man1/dpkg.1.gz", + "/usr/share/man/sv/man1/update-alternatives.1.gz", + "/usr/share/man/sv/man5/dpkg.cfg.5.gz", + "/usr/share/man/sv/man8/start-stop-daemon.8.gz", + "/usr/share/polkit-1/actions/org.dpkg.pkexec.update-alternatives.policy" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "findutils@4.10.0-3", + "Name": "findutils", + "Identifier": { + "PURL": "pkg:deb/debian/findutils@4.10.0-3?arch=amd64\u0026distro=debian-13.7", + "UID": "12e741692291b42a" + }, + "Version": "4.10.0", + "Release": "3", + "Arch": "amd64", + "SrcName": "findutils", + "SrcVersion": "4.10.0", + "SrcRelease": "3", + "Licenses": [ + "GFDL-1.3-no-invariants-or-later", + "GPL-3.0-or-later", + "FSFAP", + "GPL-2+ with Autoconf-data exception", + "GPL-3+ with Autoconf-data exception", + "FSFULLR", + "GPL-2.0-or-later", + "X11", + "public-domain", + "LGPL-2.1-or-later", + "GPL with automake exception", + "LGPL-2.0-or-later", + "LGPL-3.0-or-later", + "BSD-3-Clause", + "GPL-3+ with Bison-2.2 exception", + "LGPL-3.0-only", + "ISC", + "GFDL-1.3-only", + "GPL-2.0-only", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only" + ], + "Maintainer": "Andreas Metzler \u003cametzler@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/find", + "/usr/bin/xargs", + "/usr/share/doc-base/findutils.findutils", + "/usr/share/doc/findutils/NEWS.gz", + "/usr/share/doc/findutils/README.gz", + "/usr/share/doc/findutils/TODO", + "/usr/share/doc/findutils/changelog.Debian.gz", + "/usr/share/doc/findutils/changelog.gz", + "/usr/share/doc/findutils/copyright", + "/usr/share/info/find-maint.info.gz", + "/usr/share/info/find.info.gz", + "/usr/share/locale/be/LC_MESSAGES/findutils.mo", + "/usr/share/locale/bg/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ca/LC_MESSAGES/findutils.mo", + "/usr/share/locale/cs/LC_MESSAGES/findutils.mo", + "/usr/share/locale/da/LC_MESSAGES/findutils.mo", + "/usr/share/locale/de/LC_MESSAGES/findutils.mo", + "/usr/share/locale/el/LC_MESSAGES/findutils.mo", + "/usr/share/locale/eo/LC_MESSAGES/findutils.mo", + "/usr/share/locale/es/LC_MESSAGES/findutils.mo", + "/usr/share/locale/et/LC_MESSAGES/findutils.mo", + "/usr/share/locale/fi/LC_MESSAGES/findutils.mo", + "/usr/share/locale/fr/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ga/LC_MESSAGES/findutils.mo", + "/usr/share/locale/gl/LC_MESSAGES/findutils.mo", + "/usr/share/locale/hr/LC_MESSAGES/findutils.mo", + "/usr/share/locale/hu/LC_MESSAGES/findutils.mo", + "/usr/share/locale/id/LC_MESSAGES/findutils.mo", + "/usr/share/locale/it/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ja/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ka/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ko/LC_MESSAGES/findutils.mo", + "/usr/share/locale/lg/LC_MESSAGES/findutils.mo", + "/usr/share/locale/lt/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ms/LC_MESSAGES/findutils.mo", + "/usr/share/locale/nb/LC_MESSAGES/findutils.mo", + "/usr/share/locale/nl/LC_MESSAGES/findutils.mo", + "/usr/share/locale/pl/LC_MESSAGES/findutils.mo", + "/usr/share/locale/pt/LC_MESSAGES/findutils.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ro/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ru/LC_MESSAGES/findutils.mo", + "/usr/share/locale/sk/LC_MESSAGES/findutils.mo", + "/usr/share/locale/sl/LC_MESSAGES/findutils.mo", + "/usr/share/locale/sr/LC_MESSAGES/findutils.mo", + "/usr/share/locale/sv/LC_MESSAGES/findutils.mo", + "/usr/share/locale/tr/LC_MESSAGES/findutils.mo", + "/usr/share/locale/uk/LC_MESSAGES/findutils.mo", + "/usr/share/locale/vi/LC_MESSAGES/findutils.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/findutils.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/findutils.mo", + "/usr/share/man/man1/find.1.gz", + "/usr/share/man/man1/xargs.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "gcc-14-base@14.2.0-19", + "Name": "gcc-14-base", + "Identifier": { + "PURL": "pkg:deb/debian/gcc-14-base@14.2.0-19?arch=amd64\u0026distro=debian-13.7", + "UID": "371c061d08215a1b" + }, + "Version": "14.2.0", + "Release": "19", + "Arch": "amd64", + "SrcName": "gcc-14", + "SrcVersion": "14.2.0", + "SrcRelease": "19", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-3.0-only", + "GFDL-1.2-only", + "Artistic-2.0", + "LGPL-2.0-or-later" + ], + "Maintainer": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/share/doc/gcc-14-base/README.Debian.amd64.gz", + "/usr/share/doc/gcc-14-base/TODO.Debian", + "/usr/share/doc/gcc-14-base/changelog.Debian.gz", + "/usr/share/doc/gcc-14-base/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "grep@3.11-4", + "Name": "grep", + "Identifier": { + "PURL": "pkg:deb/debian/grep@3.11-4?arch=amd64\u0026distro=debian-13.7", + "UID": "6ce8b4eed9c0d137" + }, + "Version": "3.11", + "Release": "4", + "Arch": "amd64", + "SrcName": "grep", + "SrcVersion": "3.11", + "SrcRelease": "4", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-3.0-only" + ], + "Maintainer": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/egrep", + "/usr/bin/fgrep", + "/usr/bin/grep", + "/usr/bin/rgrep", + "/usr/share/doc/grep/AUTHORS", + "/usr/share/doc/grep/NEWS.Debian.gz", + "/usr/share/doc/grep/NEWS.gz", + "/usr/share/doc/grep/README", + "/usr/share/doc/grep/THANKS.gz", + "/usr/share/doc/grep/TODO.gz", + "/usr/share/doc/grep/changelog.Debian.gz", + "/usr/share/doc/grep/changelog.gz", + "/usr/share/doc/grep/copyright", + "/usr/share/info/grep.info.gz", + "/usr/share/locale/af/LC_MESSAGES/grep.mo", + "/usr/share/locale/be/LC_MESSAGES/grep.mo", + "/usr/share/locale/bg/LC_MESSAGES/grep.mo", + "/usr/share/locale/ca/LC_MESSAGES/grep.mo", + "/usr/share/locale/cs/LC_MESSAGES/grep.mo", + "/usr/share/locale/da/LC_MESSAGES/grep.mo", + "/usr/share/locale/de/LC_MESSAGES/grep.mo", + "/usr/share/locale/el/LC_MESSAGES/grep.mo", + "/usr/share/locale/eo/LC_MESSAGES/grep.mo", + "/usr/share/locale/es/LC_MESSAGES/grep.mo", + "/usr/share/locale/et/LC_MESSAGES/grep.mo", + "/usr/share/locale/eu/LC_MESSAGES/grep.mo", + "/usr/share/locale/fi/LC_MESSAGES/grep.mo", + "/usr/share/locale/fr/LC_MESSAGES/grep.mo", + "/usr/share/locale/ga/LC_MESSAGES/grep.mo", + "/usr/share/locale/gl/LC_MESSAGES/grep.mo", + "/usr/share/locale/he/LC_MESSAGES/grep.mo", + "/usr/share/locale/hr/LC_MESSAGES/grep.mo", + "/usr/share/locale/hu/LC_MESSAGES/grep.mo", + "/usr/share/locale/id/LC_MESSAGES/grep.mo", + "/usr/share/locale/it/LC_MESSAGES/grep.mo", + "/usr/share/locale/ja/LC_MESSAGES/grep.mo", + "/usr/share/locale/ka/LC_MESSAGES/grep.mo", + "/usr/share/locale/ko/LC_MESSAGES/grep.mo", + "/usr/share/locale/ky/LC_MESSAGES/grep.mo", + "/usr/share/locale/lt/LC_MESSAGES/grep.mo", + "/usr/share/locale/nb/LC_MESSAGES/grep.mo", + "/usr/share/locale/nl/LC_MESSAGES/grep.mo", + "/usr/share/locale/pa/LC_MESSAGES/grep.mo", + "/usr/share/locale/pl/LC_MESSAGES/grep.mo", + "/usr/share/locale/pt/LC_MESSAGES/grep.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/grep.mo", + "/usr/share/locale/ro/LC_MESSAGES/grep.mo", + "/usr/share/locale/ru/LC_MESSAGES/grep.mo", + "/usr/share/locale/sk/LC_MESSAGES/grep.mo", + "/usr/share/locale/sl/LC_MESSAGES/grep.mo", + "/usr/share/locale/sr/LC_MESSAGES/grep.mo", + "/usr/share/locale/sv/LC_MESSAGES/grep.mo", + "/usr/share/locale/ta/LC_MESSAGES/grep.mo", + "/usr/share/locale/th/LC_MESSAGES/grep.mo", + "/usr/share/locale/tr/LC_MESSAGES/grep.mo", + "/usr/share/locale/uk/LC_MESSAGES/grep.mo", + "/usr/share/locale/vi/LC_MESSAGES/grep.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/grep.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/grep.mo", + "/usr/share/man/man1/grep.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "gzip@1.13-1+deb13u1", + "Name": "gzip", + "Identifier": { + "PURL": "pkg:deb/debian/gzip@1.13-1%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "c0a7ec9e6d41cadf" + }, + "Version": "1.13", + "Release": "1+deb13u1", + "Arch": "amd64", + "SrcName": "gzip", + "SrcVersion": "1.13", + "SrcRelease": "1+deb13u1", + "Licenses": [ + "GPL-3.0-or-later", + "GFDL-1.3+-no-invariant", + "FSF-manpages", + "GPL-3.0-only", + "GFDL-3" + ], + "Maintainer": "Milan Kupcevic \u003cmilan@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "InstalledFiles": [ + "/usr/bin/gunzip", + "/usr/bin/gzexe", + "/usr/bin/gzip", + "/usr/bin/zcat", + "/usr/bin/zcmp", + "/usr/bin/zdiff", + "/usr/bin/zegrep", + "/usr/bin/zfgrep", + "/usr/bin/zforce", + "/usr/bin/zgrep", + "/usr/bin/zless", + "/usr/bin/zmore", + "/usr/bin/znew", + "/usr/share/doc/gzip/NEWS.gz", + "/usr/share/doc/gzip/README.gz", + "/usr/share/doc/gzip/TODO", + "/usr/share/doc/gzip/changelog.Debian.gz", + "/usr/share/doc/gzip/changelog.gz", + "/usr/share/doc/gzip/copyright", + "/usr/share/info/gzip.info.gz", + "/usr/share/man/man1/gzexe.1.gz", + "/usr/share/man/man1/gzip.1.gz", + "/usr/share/man/man1/zdiff.1.gz", + "/usr/share/man/man1/zforce.1.gz", + "/usr/share/man/man1/zgrep.1.gz", + "/usr/share/man/man1/zless.1.gz", + "/usr/share/man/man1/zmore.1.gz", + "/usr/share/man/man1/znew.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "hostname@3.25", + "Name": "hostname", + "Identifier": { + "PURL": "pkg:deb/debian/hostname@3.25?arch=amd64\u0026distro=debian-13.7", + "UID": "641772722328aedf" + }, + "Version": "3.25", + "Arch": "amd64", + "SrcName": "hostname", + "SrcVersion": "3.25", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Michael Meskes \u003cmeskes@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/hostname", + "/usr/share/doc/hostname/changelog.gz", + "/usr/share/doc/hostname/copyright", + "/usr/share/man/man1/hostname.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "init-system-helpers@1.69~deb13u1", + "Name": "init-system-helpers", + "Identifier": { + "PURL": "pkg:deb/debian/init-system-helpers@1.69~deb13u1?arch=all\u0026distro=debian-13.7", + "UID": "cb52819ec2f1a236" + }, + "Version": "1.69~deb13u1", + "Arch": "all", + "SrcName": "init-system-helpers", + "SrcVersion": "1.69~deb13u1", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/deb-systemd-helper", + "/usr/bin/deb-systemd-invoke", + "/usr/sbin/invoke-rc.d", + "/usr/sbin/service", + "/usr/sbin/update-rc.d", + "/usr/share/bug/init-system-helpers/control", + "/usr/share/doc/init-system-helpers/README.invoke-rc.d.gz", + "/usr/share/doc/init-system-helpers/README.policy-rc.d.gz", + "/usr/share/doc/init-system-helpers/changelog.gz", + "/usr/share/doc/init-system-helpers/copyright", + "/usr/share/lintian/overrides/init-system-helpers", + "/usr/share/man/man1/deb-systemd-helper.1p.gz", + "/usr/share/man/man1/deb-systemd-invoke.1p.gz", + "/usr/share/man/man8/invoke-rc.d.8.gz", + "/usr/share/man/man8/service.8.gz", + "/usr/share/man/man8/update-rc.d.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libacl1@2.3.2-2+b1", + "Name": "libacl1", + "Identifier": { + "PURL": "pkg:deb/debian/libacl1@2.3.2-2%2Bb1?arch=amd64\u0026distro=debian-13.7", + "UID": "cc40ccea052c10a8" + }, + "Version": "2.3.2", + "Release": "2+b1", + "Arch": "amd64", + "SrcName": "acl", + "SrcVersion": "2.3.2", + "SrcRelease": "2", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "LGPL-2.0-or-later", + "LGPL-2.1-only" + ], + "Maintainer": "Guillem Jover \u003cguillem@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libacl.so.1.1.2302", + "/usr/share/doc/libacl1/changelog.Debian.amd64.gz", + "/usr/share/doc/libacl1/changelog.Debian.gz", + "/usr/share/doc/libacl1/changelog.gz", + "/usr/share/doc/libacl1/copyright", + "/usr/share/lintian/overrides/libacl1" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libapt-pkg7.0@3.0.3", + "Name": "libapt-pkg7.0", + "Identifier": { + "PURL": "pkg:deb/debian/libapt-pkg7.0@3.0.3?arch=amd64\u0026distro=debian-13.7", + "UID": "74c29d34562cd172" + }, + "Version": "3.0.3", + "Arch": "amd64", + "SrcName": "apt", + "SrcVersion": "3.0.3", + "Licenses": [ + "GPL-2.0-or-later", + "curl", + "BSD-3-Clause", + "MIT", + "GPL-2.0-only" + ], + "Maintainer": "APT Development Team \u003cdeity@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libbz2-1.0@1.0.8-6", + "libc6@2.41-12+deb13u4", + "libgcc-s1@14.2.0-19", + "liblz4-1@1.10.0-4", + "liblzma5@5.8.1-1+deb13u1", + "libssl3t64@3.5.7-1~deb13u2", + "libstdc++6@14.2.0-19", + "libsystemd0@257.13-1~deb13u1", + "libudev1@257.13-1~deb13u1", + "libxxhash0@0.8.3-2", + "libzstd1@1.5.7+dfsg-1", + "zlib1g@1:1.3.dfsg+really1.3.1-1+b1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libapt-pkg.so.7.0.0", + "/usr/share/doc/libapt-pkg7.0/NEWS.Debian.gz", + "/usr/share/doc/libapt-pkg7.0/changelog.gz", + "/usr/share/doc/libapt-pkg7.0/copyright", + "/usr/share/locale/ar/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ast/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/bg/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/bs/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ca/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/cs/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/cy/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/da/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/de/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/dz/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/el/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/es/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/eu/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/fi/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/fr/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/gl/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/hu/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/it/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ja/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/km/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ko/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ku/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/lt/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/mr/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/nb/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ne/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/nl/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/nn/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/pl/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/pt/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ro/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ru/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/sk/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/sl/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/sv/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/th/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/tl/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/tr/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/uk/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/vi/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/libapt-pkg7.0.mo" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libattr1@1:2.5.2-3", + "Name": "libattr1", + "Identifier": { + "PURL": "pkg:deb/debian/libattr1@2.5.2-3?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "d04226e5c9c60381" + }, + "Version": "2.5.2", + "Release": "3", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "attr", + "SrcVersion": "2.5.2", + "SrcRelease": "3", + "SrcEpoch": 1, + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "LGPL-2.0-or-later", + "LGPL-2.1-only" + ], + "Maintainer": "Guillem Jover \u003cguillem@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libattr.so.1.1.2502", + "/usr/share/doc/libattr1/changelog.Debian.gz", + "/usr/share/doc/libattr1/changelog.gz", + "/usr/share/doc/libattr1/copyright", + "/usr/share/lintian/overrides/libattr1" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libaudit-common@1:4.0.2-2+deb13u1", + "Name": "libaudit-common", + "Identifier": { + "PURL": "pkg:deb/debian/libaudit-common@4.0.2-2%2Bdeb13u1?arch=all\u0026distro=debian-13.7\u0026epoch=1", + "UID": "7a7f4d470acd218a" + }, + "Version": "4.0.2", + "Release": "2+deb13u1", + "Epoch": 1, + "Arch": "all", + "SrcName": "audit", + "SrcVersion": "4.0.2", + "SrcRelease": "2+deb13u1", + "SrcEpoch": 1, + "Licenses": [ + "GPL-2.0-only", + "LGPL-2.1-only", + "GPL-1.0-only" + ], + "Maintainer": "Laurent Bigonville \u003cbigon@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "InstalledFiles": [ + "/usr/share/doc/libaudit-common/changelog.Debian.gz", + "/usr/share/doc/libaudit-common/changelog.gz", + "/usr/share/doc/libaudit-common/copyright", + "/usr/share/man/man5/libaudit.conf.5.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libaudit1@1:4.0.2-2+deb13u1", + "Name": "libaudit1", + "Identifier": { + "PURL": "pkg:deb/debian/libaudit1@4.0.2-2%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "592c19b2956c925e" + }, + "Version": "4.0.2", + "Release": "2+deb13u1", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "audit", + "SrcVersion": "4.0.2", + "SrcRelease": "2+deb13u1", + "SrcEpoch": 1, + "Licenses": [ + "GPL-2.0-only", + "LGPL-2.1-only", + "GPL-1.0-only" + ], + "Maintainer": "Laurent Bigonville \u003cbigon@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libaudit-common@1:4.0.2-2+deb13u1", + "libc6@2.41-12+deb13u4", + "libcap-ng0@0.8.5-4+b1" + ], + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libaudit.so.1.0.0", + "/usr/share/doc/libaudit1/changelog.Debian.gz", + "/usr/share/doc/libaudit1/changelog.gz", + "/usr/share/doc/libaudit1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libblkid1@2.41.5-0+deb13u1", + "Name": "libblkid1", + "Identifier": { + "PURL": "pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "e20c3ed37f6020d7" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libblkid.so.1.1.0", + "/usr/share/doc/libblkid1/NEWS.Debian.gz", + "/usr/share/doc/libblkid1/changelog.Debian.gz", + "/usr/share/doc/libblkid1/changelog.gz", + "/usr/share/doc/libblkid1/copyright", + "/usr/share/lintian/overrides/libblkid1" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libbsd0@0.12.2-2", + "Name": "libbsd0", + "Identifier": { + "PURL": "pkg:deb/debian/libbsd0@0.12.2-2?arch=amd64\u0026distro=debian-13.7", + "UID": "1de87442fee280ff" + }, + "Version": "0.12.2", + "Release": "2", + "Arch": "amd64", + "SrcName": "libbsd", + "SrcVersion": "0.12.2", + "SrcRelease": "2", + "Licenses": [ + "BSD-3-Clause", + "BSD-3-clause-Regents", + "BSD-2-Clause-NetBSD", + "BSD-3-clause-author", + "BSD-3-clause-John-Birrell", + "BSD-5-clause-Peter-Wemm", + "BSD-2-Clause", + "BSD-2-clause-verbatim", + "BSD-2-clause-author", + "ISC", + "ISC-Original", + "MIT", + "public-domain", + "Beerware" + ], + "Maintainer": "Guillem Jover \u003cguillem@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libmd0@1.1.0-2+b1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libbsd.so.0.12.2", + "/usr/share/doc/libbsd0/changelog.Debian.gz", + "/usr/share/doc/libbsd0/changelog.gz", + "/usr/share/doc/libbsd0/copyright", + "/usr/share/lintian/overrides/libbsd0" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libbz2-1.0@1.0.8-6", + "Name": "libbz2-1.0", + "Identifier": { + "PURL": "pkg:deb/debian/libbz2-1.0@1.0.8-6?arch=amd64\u0026distro=debian-13.7", + "UID": "3589bfcff9e95a4f" + }, + "Version": "1.0.8", + "Release": "6", + "Arch": "amd64", + "SrcName": "bzip2", + "SrcVersion": "1.0.8", + "SrcRelease": "6", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-only" + ], + "Maintainer": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libbz2.so.1.0.4", + "/usr/share/doc/libbz2-1.0/changelog.Debian.gz", + "/usr/share/doc/libbz2-1.0/changelog.gz", + "/usr/share/doc/libbz2-1.0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libc-bin@2.41-12+deb13u4", + "Name": "libc-bin", + "Identifier": { + "PURL": "pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64\u0026distro=debian-13.7", + "UID": "270b2986988165f2" + }, + "Version": "2.41", + "Release": "12+deb13u4", + "Arch": "amd64", + "SrcName": "glibc", + "SrcVersion": "2.41", + "SrcRelease": "12+deb13u4", + "Licenses": [ + "LGPL-2.1-or-later", + "LGPL-2.0-or-later", + "LGPL-2.1+-with-link-exception", + "LGPL-3.0-or-later", + "GPL-2.0-or-later", + "GPL-2+-with-link-exception", + "GPL-2.0-only", + "GPL-3.0-or-later", + "FSFAP", + "Carnegie", + "Inner-Net", + "MIT-like-Lord", + "BSD-like-Spencer", + "PCRE", + "BSD-3-clause-Carnegie", + "Unicode-DFS-2016", + "BSL-1.0", + "SunPro", + "CORE-MATH", + "BSD-3-clause-Berkeley", + "BSD-3-clause-WIDE", + "BSD-2-Clause", + "BSD-3-clause-Oracle", + "DEC", + "IBM", + "ISC", + "Univ-Coimbra", + "public-domain", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "InstalledFiles": [ + "/usr/bin/getconf", + "/usr/bin/getent", + "/usr/bin/iconv", + "/usr/bin/ldd", + "/usr/bin/locale", + "/usr/bin/localedef", + "/usr/bin/pldd", + "/usr/bin/tzselect", + "/usr/bin/zdump", + "/usr/lib/locale/C.utf8/LC_ADDRESS", + "/usr/lib/locale/C.utf8/LC_COLLATE", + "/usr/lib/locale/C.utf8/LC_CTYPE", + "/usr/lib/locale/C.utf8/LC_IDENTIFICATION", + "/usr/lib/locale/C.utf8/LC_MEASUREMENT", + "/usr/lib/locale/C.utf8/LC_MESSAGES/SYS_LC_MESSAGES", + "/usr/lib/locale/C.utf8/LC_MONETARY", + "/usr/lib/locale/C.utf8/LC_NAME", + "/usr/lib/locale/C.utf8/LC_NUMERIC", + "/usr/lib/locale/C.utf8/LC_PAPER", + "/usr/lib/locale/C.utf8/LC_TELEPHONE", + "/usr/lib/locale/C.utf8/LC_TIME", + "/usr/sbin/iconvconfig", + "/usr/sbin/ldconfig", + "/usr/sbin/zic", + "/usr/share/doc/libc-bin/changelog.Debian.gz", + "/usr/share/doc/libc-bin/changelog.gz", + "/usr/share/doc/libc-bin/copyright", + "/usr/share/libc-bin/nsswitch.conf", + "/usr/share/lintian/overrides/libc-bin", + "/usr/share/man/man1/getconf.1.gz", + "/usr/share/man/man1/tzselect.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libc6@2.41-12+deb13u4", + "Name": "libc6", + "Identifier": { + "PURL": "pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64\u0026distro=debian-13.7", + "UID": "17d3a030715e36c7" + }, + "Version": "2.41", + "Release": "12+deb13u4", + "Arch": "amd64", + "SrcName": "glibc", + "SrcVersion": "2.41", + "SrcRelease": "12+deb13u4", + "Licenses": [ + "LGPL-2.1-or-later", + "LGPL-2.0-or-later", + "LGPL-2.1+-with-link-exception", + "LGPL-3.0-or-later", + "GPL-2.0-or-later", + "GPL-2+-with-link-exception", + "GPL-2.0-only", + "GPL-3.0-or-later", + "FSFAP", + "Carnegie", + "Inner-Net", + "MIT-like-Lord", + "BSD-like-Spencer", + "PCRE", + "BSD-3-clause-Carnegie", + "Unicode-DFS-2016", + "BSL-1.0", + "SunPro", + "CORE-MATH", + "BSD-3-clause-Berkeley", + "BSD-3-clause-WIDE", + "BSD-2-Clause", + "BSD-3-clause-Oracle", + "DEC", + "IBM", + "ISC", + "Univ-Coimbra", + "public-domain", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libgcc-s1@14.2.0-19" + ], + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/gconv/ANSI_X3.110.so", + "/usr/lib/x86_64-linux-gnu/gconv/ARMSCII-8.so", + "/usr/lib/x86_64-linux-gnu/gconv/ASMO_449.so", + "/usr/lib/x86_64-linux-gnu/gconv/BIG5.so", + "/usr/lib/x86_64-linux-gnu/gconv/BIG5HKSCS.so", + "/usr/lib/x86_64-linux-gnu/gconv/BRF.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP10007.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1125.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1250.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1251.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1252.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1253.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1254.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1255.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1256.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1257.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1258.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP737.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP770.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP771.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP772.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP773.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP774.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP775.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP932.so", + "/usr/lib/x86_64-linux-gnu/gconv/CSN_369103.so", + "/usr/lib/x86_64-linux-gnu/gconv/CWI.so", + "/usr/lib/x86_64-linux-gnu/gconv/DEC-MCS.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-AT-DE-A.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-AT-DE.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-CA-FR.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-DK-NO-A.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-DK-NO.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-ES-A.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-ES-S.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-ES.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-FI-SE-A.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-FI-SE.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-FR.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-IS-FRISS.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-IT.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-PT.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-UK.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-US.so", + "/usr/lib/x86_64-linux-gnu/gconv/ECMA-CYRILLIC.so", + "/usr/lib/x86_64-linux-gnu/gconv/EUC-CN.so", + "/usr/lib/x86_64-linux-gnu/gconv/EUC-JISX0213.so", + "/usr/lib/x86_64-linux-gnu/gconv/EUC-JP-MS.so", + "/usr/lib/x86_64-linux-gnu/gconv/EUC-JP.so", + "/usr/lib/x86_64-linux-gnu/gconv/EUC-KR.so", + "/usr/lib/x86_64-linux-gnu/gconv/EUC-TW.so", + "/usr/lib/x86_64-linux-gnu/gconv/GB18030.so", + "/usr/lib/x86_64-linux-gnu/gconv/GBBIG5.so", + "/usr/lib/x86_64-linux-gnu/gconv/GBGBK.so", + "/usr/lib/x86_64-linux-gnu/gconv/GBK.so", + "/usr/lib/x86_64-linux-gnu/gconv/GEORGIAN-ACADEMY.so", + "/usr/lib/x86_64-linux-gnu/gconv/GEORGIAN-PS.so", + "/usr/lib/x86_64-linux-gnu/gconv/GOST_19768-74.so", + "/usr/lib/x86_64-linux-gnu/gconv/GREEK-CCITT.so", + "/usr/lib/x86_64-linux-gnu/gconv/GREEK7-OLD.so", + "/usr/lib/x86_64-linux-gnu/gconv/GREEK7.so", + "/usr/lib/x86_64-linux-gnu/gconv/HP-GREEK8.so", + "/usr/lib/x86_64-linux-gnu/gconv/HP-ROMAN8.so", + "/usr/lib/x86_64-linux-gnu/gconv/HP-ROMAN9.so", + "/usr/lib/x86_64-linux-gnu/gconv/HP-THAI8.so", + "/usr/lib/x86_64-linux-gnu/gconv/HP-TURKISH8.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM037.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM038.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1004.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1008.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1008_420.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1025.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1026.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1046.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1047.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1097.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1112.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1122.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1123.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1124.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1129.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1130.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1132.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1133.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1137.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1140.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1141.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1142.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1143.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1144.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1145.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1146.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1147.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1148.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1149.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1153.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1154.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1155.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1156.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1157.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1158.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1160.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1161.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1162.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1163.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1164.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1166.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1167.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM12712.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1364.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1371.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1388.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1390.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1399.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM16804.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM256.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM273.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM274.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM275.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM277.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM278.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM280.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM281.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM284.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM285.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM290.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM297.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM420.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM423.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM424.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM437.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM4517.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM4899.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM4909.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM4971.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM500.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM5347.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM803.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM850.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM851.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM852.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM855.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM856.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM857.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM858.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM860.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM861.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM862.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM863.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM864.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM865.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM866.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM866NAV.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM868.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM869.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM870.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM871.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM874.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM875.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM880.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM891.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM901.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM902.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM903.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM9030.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM904.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM905.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM9066.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM918.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM921.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM922.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM930.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM932.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM933.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM935.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM937.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM939.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM943.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM9448.so", + "/usr/lib/x86_64-linux-gnu/gconv/IEC_P27-1.so", + "/usr/lib/x86_64-linux-gnu/gconv/INIS-8.so", + "/usr/lib/x86_64-linux-gnu/gconv/INIS-CYRILLIC.so", + "/usr/lib/x86_64-linux-gnu/gconv/INIS.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISIRI-3342.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-2022-CN-EXT.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-2022-CN.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-2022-JP-3.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-2022-JP.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-2022-KR.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-IR-197.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-IR-209.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO646.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-1.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-10.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-11.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-13.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-14.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-15.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-16.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-2.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-3.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-4.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-5.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-6.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-7.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-8.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-9.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-9E.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_10367-BOX.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_11548-1.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_2033.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_5427-EXT.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_5427.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_5428.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_6937-2.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_6937.so", + "/usr/lib/x86_64-linux-gnu/gconv/JOHAB.so", + "/usr/lib/x86_64-linux-gnu/gconv/KOI-8.so", + "/usr/lib/x86_64-linux-gnu/gconv/KOI8-R.so", + "/usr/lib/x86_64-linux-gnu/gconv/KOI8-RU.so", + "/usr/lib/x86_64-linux-gnu/gconv/KOI8-T.so", + "/usr/lib/x86_64-linux-gnu/gconv/KOI8-U.so", + "/usr/lib/x86_64-linux-gnu/gconv/LATIN-GREEK-1.so", + "/usr/lib/x86_64-linux-gnu/gconv/LATIN-GREEK.so", + "/usr/lib/x86_64-linux-gnu/gconv/MAC-CENTRALEUROPE.so", + "/usr/lib/x86_64-linux-gnu/gconv/MAC-IS.so", + "/usr/lib/x86_64-linux-gnu/gconv/MAC-SAMI.so", + "/usr/lib/x86_64-linux-gnu/gconv/MAC-UK.so", + "/usr/lib/x86_64-linux-gnu/gconv/MACINTOSH.so", + "/usr/lib/x86_64-linux-gnu/gconv/MIK.so", + "/usr/lib/x86_64-linux-gnu/gconv/NATS-DANO.so", + "/usr/lib/x86_64-linux-gnu/gconv/NATS-SEFI.so", + "/usr/lib/x86_64-linux-gnu/gconv/PT154.so", + "/usr/lib/x86_64-linux-gnu/gconv/RK1048.so", + "/usr/lib/x86_64-linux-gnu/gconv/SAMI-WS2.so", + "/usr/lib/x86_64-linux-gnu/gconv/SHIFT_JISX0213.so", + "/usr/lib/x86_64-linux-gnu/gconv/SJIS.so", + "/usr/lib/x86_64-linux-gnu/gconv/T.61.so", + "/usr/lib/x86_64-linux-gnu/gconv/TCVN5712-1.so", + "/usr/lib/x86_64-linux-gnu/gconv/TIS-620.so", + "/usr/lib/x86_64-linux-gnu/gconv/TSCII.so", + "/usr/lib/x86_64-linux-gnu/gconv/UHC.so", + "/usr/lib/x86_64-linux-gnu/gconv/UNICODE.so", + "/usr/lib/x86_64-linux-gnu/gconv/UTF-16.so", + "/usr/lib/x86_64-linux-gnu/gconv/UTF-32.so", + "/usr/lib/x86_64-linux-gnu/gconv/UTF-7.so", + "/usr/lib/x86_64-linux-gnu/gconv/VISCII.so", + "/usr/lib/x86_64-linux-gnu/gconv/gconv-modules", + "/usr/lib/x86_64-linux-gnu/gconv/gconv-modules.cache", + "/usr/lib/x86_64-linux-gnu/gconv/gconv-modules.d/gconv-modules-extra.conf", + "/usr/lib/x86_64-linux-gnu/gconv/libCNS.so", + "/usr/lib/x86_64-linux-gnu/gconv/libGB.so", + "/usr/lib/x86_64-linux-gnu/gconv/libISOIR165.so", + "/usr/lib/x86_64-linux-gnu/gconv/libJIS.so", + "/usr/lib/x86_64-linux-gnu/gconv/libJISX0213.so", + "/usr/lib/x86_64-linux-gnu/gconv/libKSC.so", + "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", + "/usr/lib/x86_64-linux-gnu/libBrokenLocale.so.1", + "/usr/lib/x86_64-linux-gnu/libanl.so.1", + "/usr/lib/x86_64-linux-gnu/libc.so.6", + "/usr/lib/x86_64-linux-gnu/libc_malloc_debug.so.0", + "/usr/lib/x86_64-linux-gnu/libdl.so.2", + "/usr/lib/x86_64-linux-gnu/libm.so.6", + "/usr/lib/x86_64-linux-gnu/libmemusage.so", + "/usr/lib/x86_64-linux-gnu/libmvec.so.1", + "/usr/lib/x86_64-linux-gnu/libnsl.so.1", + "/usr/lib/x86_64-linux-gnu/libnss_compat.so.2", + "/usr/lib/x86_64-linux-gnu/libnss_dns.so.2", + "/usr/lib/x86_64-linux-gnu/libnss_files.so.2", + "/usr/lib/x86_64-linux-gnu/libnss_hesiod.so.2", + "/usr/lib/x86_64-linux-gnu/libpcprofile.so", + "/usr/lib/x86_64-linux-gnu/libpthread.so.0", + "/usr/lib/x86_64-linux-gnu/libresolv.so.2", + "/usr/lib/x86_64-linux-gnu/librt.so.1", + "/usr/lib/x86_64-linux-gnu/libthread_db.so.1", + "/usr/lib/x86_64-linux-gnu/libutil.so.1", + "/usr/share/doc/libc6/NEWS.Debian.gz", + "/usr/share/doc/libc6/NEWS.gz", + "/usr/share/doc/libc6/README.Debian.gz", + "/usr/share/doc/libc6/README.hesiod.gz", + "/usr/share/doc/libc6/changelog.Debian.gz", + "/usr/share/doc/libc6/changelog.gz", + "/usr/share/doc/libc6/copyright", + "/usr/share/lintian/overrides/libc6" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libcap-ng0@0.8.5-4+b1", + "Name": "libcap-ng0", + "Identifier": { + "PURL": "pkg:deb/debian/libcap-ng0@0.8.5-4%2Bb1?arch=amd64\u0026distro=debian-13.7", + "UID": "6ebeba515cbfa716" + }, + "Version": "0.8.5", + "Release": "4+b1", + "Arch": "amd64", + "SrcName": "libcap-ng", + "SrcVersion": "0.8.5", + "SrcRelease": "4", + "Licenses": [ + "LGPL-2.1-or-later", + "GPL-2.0-or-later", + "GPL-3.0-only", + "LGPL-2.1-only", + "GPL-2.0-only" + ], + "Maintainer": "Håvard F. Aasen \u003chavard.f.aasen@pfft.no\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libcap-ng.so.0.0.0", + "/usr/lib/x86_64-linux-gnu/libdrop_ambient.so.0.0.0", + "/usr/share/doc/libcap-ng0/changelog.Debian.amd64.gz", + "/usr/share/doc/libcap-ng0/changelog.Debian.gz", + "/usr/share/doc/libcap-ng0/changelog.gz", + "/usr/share/doc/libcap-ng0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libcap2@1:2.75-10+deb13u1+b3", + "Name": "libcap2", + "Identifier": { + "PURL": "pkg:deb/debian/libcap2@2.75-10%2Bdeb13u1%2Bb3?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "1784518f50875bc" + }, + "Version": "2.75", + "Release": "10+deb13u1+b3", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "libcap2", + "SrcVersion": "2.75", + "SrcRelease": "10+deb13u1", + "SrcEpoch": 1, + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-only", + "GPL-2.0-or-later" + ], + "Maintainer": "Christian Kastner \u003cckk@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libcap.so.2.75", + "/usr/lib/x86_64-linux-gnu/libpsx.so.2.75", + "/usr/share/doc/libcap2/changelog.Debian.amd64.gz", + "/usr/share/doc/libcap2/changelog.Debian.gz", + "/usr/share/doc/libcap2/changelog.gz", + "/usr/share/doc/libcap2/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libcrypt1@1:4.4.38-1", + "Name": "libcrypt1", + "Identifier": { + "PURL": "pkg:deb/debian/libcrypt1@4.4.38-1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "bcf9a53d19864571" + }, + "Version": "4.4.38", + "Release": "1", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "libxcrypt", + "SrcVersion": "4.4.38", + "SrcRelease": "1", + "SrcEpoch": 1, + "Maintainer": "Marco d'Itri \u003cmd@linux.it\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libcrypt.so.1.1.0", + "/usr/share/doc/libcrypt1/changelog.Debian.gz", + "/usr/share/doc/libcrypt1/changelog.gz", + "/usr/share/doc/libcrypt1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libdb5.3t64@5.3.28+dfsg2-9", + "Name": "libdb5.3t64", + "Identifier": { + "PURL": "pkg:deb/debian/libdb5.3t64@5.3.28%2Bdfsg2-9?arch=amd64\u0026distro=debian-13.7", + "UID": "6644476cfc0a6297" + }, + "Version": "5.3.28+dfsg2", + "Release": "9", + "Arch": "amd64", + "SrcName": "db5.3", + "SrcVersion": "5.3.28+dfsg2", + "SrcRelease": "9", + "Licenses": [ + "Sleepycat", + "BSD-3-Clause", + "MS-PL", + "GPL-2.0-or-later", + "Artistic-2.0", + "X11", + "MIT-old", + "TCL-like", + "BSD-3-clause-fjord", + "GPL-3.0-only", + "Zlib" + ], + "Maintainer": "Debian QA Group \u003cpackages@qa.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libdb-5.3.so", + "/usr/share/doc/libdb5.3t64/build_signature_amd64.txt", + "/usr/share/doc/libdb5.3t64/changelog.Debian.gz", + "/usr/share/doc/libdb5.3t64/copyright", + "/usr/share/lintian/overrides/libdb5.3t64" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libdebconfclient0@0.280", + "Name": "libdebconfclient0", + "Identifier": { + "PURL": "pkg:deb/debian/libdebconfclient0@0.280?arch=amd64\u0026distro=debian-13.7", + "UID": "cd0c9dc2c6921f31" + }, + "Version": "0.280", + "Arch": "amd64", + "SrcName": "cdebconf", + "SrcVersion": "0.280", + "Licenses": [ + "BSD-2-Clause", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Debian Install System Team \u003cdebian-boot@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libdebconfclient.so.0.0.0", + "/usr/share/doc/libdebconfclient0/changelog.gz", + "/usr/share/doc/libdebconfclient0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libffi8@3.4.8-2", + "Name": "libffi8", + "Identifier": { + "PURL": "pkg:deb/debian/libffi8@3.4.8-2?arch=amd64\u0026distro=debian-13.7", + "UID": "228a6da53492f741" + }, + "Version": "3.4.8", + "Release": "2", + "Arch": "amd64", + "SrcName": "libffi", + "SrcVersion": "3.4.8", + "SrcRelease": "2", + "Licenses": [ + "MIT", + "X11", + "GPL-2.0-or-later", + "GPL-3.0-or-later", + "MPL-1.1", + "LGPL-2.1-or-later", + "public-domain" + ], + "Maintainer": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libffi.so.8.1.4", + "/usr/share/doc/libffi8/changelog.Debian.gz", + "/usr/share/doc/libffi8/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libgcc-s1@14.2.0-19", + "Name": "libgcc-s1", + "Identifier": { + "PURL": "pkg:deb/debian/libgcc-s1@14.2.0-19?arch=amd64\u0026distro=debian-13.7", + "UID": "5f801be708edc088" + }, + "Version": "14.2.0", + "Release": "19", + "Arch": "amd64", + "SrcName": "gcc-14", + "SrcVersion": "14.2.0", + "SrcRelease": "19", + "Maintainer": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "gcc-14-base@14.2.0-19", + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libgcc_s.so.1", + "/usr/share/lintian/overrides/libgcc-s1" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libgdbm6t64@1.24-2", + "Name": "libgdbm6t64", + "Identifier": { + "PURL": "pkg:deb/debian/libgdbm6t64@1.24-2?arch=amd64\u0026distro=debian-13.7", + "UID": "22d26fcd3d7e2796" + }, + "Version": "1.24", + "Release": "2", + "Arch": "amd64", + "SrcName": "gdbm", + "SrcVersion": "1.24", + "SrcRelease": "2", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-2.0-or-later", + "GFDL-1.3-no-invariants-or-later", + "GPL-3.0-only", + "GPL-2.0-only" + ], + "Maintainer": "Nicolas Mora \u003cbabelouest@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libgdbm.so.6.0.0", + "/usr/share/doc/libgdbm6t64/changelog.Debian.gz", + "/usr/share/doc/libgdbm6t64/changelog.gz", + "/usr/share/doc/libgdbm6t64/copyright", + "/usr/share/lintian/overrides/libgdbm6t64" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libgmp10@2:6.3.0+dfsg-3", + "Name": "libgmp10", + "Identifier": { + "PURL": "pkg:deb/debian/libgmp10@6.3.0%2Bdfsg-3?arch=amd64\u0026distro=debian-13.7\u0026epoch=2", + "UID": "472e354773202f0f" + }, + "Version": "6.3.0+dfsg", + "Release": "3", + "Epoch": 2, + "Arch": "amd64", + "SrcName": "gmp", + "SrcVersion": "6.3.0+dfsg", + "SrcRelease": "3", + "SrcEpoch": 2, + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-3.0-or-later", + "GPL-3.0-or-later", + "GPL-3+ with Bison exception", + "GPL-2.0-only", + "GPL-3.0-only", + "LGPL-3.0-only" + ], + "Maintainer": "Debian Science Maintainers \u003cdebian-science-maintainers@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libgmp.so.10.5.0", + "/usr/share/doc/libgmp10/README.Debian", + "/usr/share/doc/libgmp10/changelog.Debian.gz", + "/usr/share/doc/libgmp10/changelog.gz", + "/usr/share/doc/libgmp10/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libhogweed6t64@3.10.1-1", + "Name": "libhogweed6t64", + "Identifier": { + "PURL": "pkg:deb/debian/libhogweed6t64@3.10.1-1?arch=amd64\u0026distro=debian-13.7", + "UID": "2df7ce16a99c5e01" + }, + "Version": "3.10.1", + "Release": "1", + "Arch": "amd64", + "SrcName": "nettle", + "SrcVersion": "3.10.1", + "SrcRelease": "1", + "Licenses": [ + "LGPL-3.0-or-later", + "GPL-2.0-or-later", + "LGPL-2.0-or-later", + "LGPL-2.0-only", + "MIT", + "GPL-3.0-with-autoconf-exception+", + "public-domain", + "GPL-2.0-only", + "GAP" + ], + "Maintainer": "Magnus Holmgren \u003cholmgren@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libgmp10@2:6.3.0+dfsg-3", + "libnettle8t64@3.10.1-1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libhogweed.so.6.10", + "/usr/share/doc/libhogweed6t64/changelog.Debian.gz", + "/usr/share/doc/libhogweed6t64/changelog.gz", + "/usr/share/doc/libhogweed6t64/copyright", + "/usr/share/lintian/overrides/libhogweed6t64" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "liblastlog2-2@2.41.5-0+deb13u1", + "Name": "liblastlog2-2", + "Identifier": { + "PURL": "pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "481f2fda004b182b" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libsqlite3-0@3.46.1-7+deb13u2" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/liblastlog2.so.2.0.0", + "/usr/share/doc/liblastlog2-2/NEWS.Debian.gz", + "/usr/share/doc/liblastlog2-2/changelog.Debian.gz", + "/usr/share/doc/liblastlog2-2/changelog.gz", + "/usr/share/doc/liblastlog2-2/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "liblz4-1@1.10.0-4", + "Name": "liblz4-1", + "Identifier": { + "PURL": "pkg:deb/debian/liblz4-1@1.10.0-4?arch=amd64\u0026distro=debian-13.7", + "UID": "dcc7de8e33942d8c" + }, + "Version": "1.10.0", + "Release": "4", + "Arch": "amd64", + "SrcName": "lz4", + "SrcVersion": "1.10.0", + "SrcRelease": "4", + "Licenses": [ + "GPL-2.0-or-later", + "BSD-2-Clause", + "GPL-2.0-only" + ], + "Maintainer": "Nobuhiro Iwamatsu \u003ciwamatsu@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libxxhash0@0.8.3-2" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/liblz4.so.1.10.0", + "/usr/share/doc/liblz4-1/changelog.Debian.gz", + "/usr/share/doc/liblz4-1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "liblzma5@5.8.1-1+deb13u1", + "Name": "liblzma5", + "Identifier": { + "PURL": "pkg:deb/debian/liblzma5@5.8.1-1%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "9a7ed5b23f87efec" + }, + "Version": "5.8.1", + "Release": "1+deb13u1", + "Arch": "amd64", + "SrcName": "xz-utils", + "SrcVersion": "5.8.1", + "SrcRelease": "1+deb13u1", + "Licenses": [ + "0BSD", + "GPL-2.0-or-later", + "LGPL-2.1-or-later", + "FSFULLR", + "GPL-3.0-or-later-WITH-Autoconf-exception-macro", + "none", + "PD", + "permissive-nowarranty", + "FSFUL", + "noderivs", + "PD-debian", + "LGPL-2.1-only", + "GPL-2.0-only", + "GPL-3.0-only" + ], + "Maintainer": "Sebastian Andrzej Siewior \u003csebastian@breakpoint.cc\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/liblzma.so.5.8.1", + "/usr/share/doc/liblzma5/AUTHORS", + "/usr/share/doc/liblzma5/NEWS.gz", + "/usr/share/doc/liblzma5/THANKS.gz", + "/usr/share/doc/liblzma5/changelog.Debian.gz", + "/usr/share/doc/liblzma5/changelog.gz", + "/usr/share/doc/liblzma5/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libmd0@1.1.0-2+b1", + "Name": "libmd0", + "Identifier": { + "PURL": "pkg:deb/debian/libmd0@1.1.0-2%2Bb1?arch=amd64\u0026distro=debian-13.7", + "UID": "6f55e5e0a3458581" + }, + "Version": "1.1.0", + "Release": "2+b1", + "Arch": "amd64", + "SrcName": "libmd", + "SrcVersion": "1.1.0", + "SrcRelease": "2", + "Licenses": [ + "BSD-3-Clause", + "BSD-3-clause-Aaron-D-Gifford", + "BSD-2-Clause", + "BSD-2-Clause-NetBSD", + "ISC", + "Beerware", + "public-domain-md4", + "public-domain-md5", + "public-domain-sha1" + ], + "Maintainer": "Guillem Jover \u003cguillem@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libmd.so.0.1.0", + "/usr/share/doc/libmd0/changelog.Debian.amd64.gz", + "/usr/share/doc/libmd0/changelog.Debian.gz", + "/usr/share/doc/libmd0/changelog.gz", + "/usr/share/doc/libmd0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libmount1@2.41.5-0+deb13u1", + "Name": "libmount1", + "Identifier": { + "PURL": "pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "d0bfdcf72ddff375" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libblkid1@2.41.5-0+deb13u1", + "libc6@2.41-12+deb13u4", + "libselinux1@3.8.1-1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libmount.so.1.1.0", + "/usr/share/doc/libmount1/NEWS.Debian.gz", + "/usr/share/doc/libmount1/changelog.Debian.gz", + "/usr/share/doc/libmount1/changelog.gz", + "/usr/share/doc/libmount1/copyright", + "/usr/share/lintian/overrides/libmount1" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libncursesw6@6.5+20250216-2", + "Name": "libncursesw6", + "Identifier": { + "PURL": "pkg:deb/debian/libncursesw6@6.5%2B20250216-2?arch=amd64\u0026distro=debian-13.7", + "UID": "7121209a6392dd9e" + }, + "Version": "6.5+20250216", + "Release": "2", + "Arch": "amd64", + "SrcName": "ncurses", + "SrcVersion": "6.5+20250216", + "SrcRelease": "2", + "Maintainer": "Ncurses Maintainers \u003cncurses@packages.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libtinfo6@6.5+20250216-2" + ], + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libformw.so.6.5", + "/usr/lib/x86_64-linux-gnu/libmenuw.so.6.5", + "/usr/lib/x86_64-linux-gnu/libncursesw.so.6.5", + "/usr/lib/x86_64-linux-gnu/libpanelw.so.6.5" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libnettle8t64@3.10.1-1", + "Name": "libnettle8t64", + "Identifier": { + "PURL": "pkg:deb/debian/libnettle8t64@3.10.1-1?arch=amd64\u0026distro=debian-13.7", + "UID": "bbd391fef91ccd16" + }, + "Version": "3.10.1", + "Release": "1", + "Arch": "amd64", + "SrcName": "nettle", + "SrcVersion": "3.10.1", + "SrcRelease": "1", + "Licenses": [ + "LGPL-3.0-or-later", + "GPL-2.0-or-later", + "LGPL-2.0-or-later", + "LGPL-2.0-only", + "MIT", + "GPL-3.0-with-autoconf-exception+", + "public-domain", + "GPL-2.0-only", + "GAP" + ], + "Maintainer": "Magnus Holmgren \u003cholmgren@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libnettle.so.8.10", + "/usr/share/doc/libnettle8t64/NEWS.gz", + "/usr/share/doc/libnettle8t64/README", + "/usr/share/doc/libnettle8t64/changelog.Debian.gz", + "/usr/share/doc/libnettle8t64/changelog.gz", + "/usr/share/doc/libnettle8t64/copyright", + "/usr/share/lintian/overrides/libnettle8t64" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libpam-modules@1.7.0-5", + "Name": "libpam-modules", + "Identifier": { + "PURL": "pkg:deb/debian/libpam-modules@1.7.0-5?arch=amd64\u0026distro=debian-13.7", + "UID": "274a704398461ef0" + }, + "Version": "1.7.0", + "Release": "5", + "Arch": "amd64", + "SrcName": "pam", + "SrcVersion": "1.7.0", + "SrcRelease": "5", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later", + "GPL-1.0-only", + "GPL-2.0-only", + "GPL-3.0-only", + "GPL-3+ with Bison exception", + "BSD-tcp_wrappers", + "LGPL-2.0-or-later", + "LGPL-2.0-only", + "public-domain", + "Beerware" + ], + "Maintainer": "Sam Hartman \u003chartmans@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/security/pam_access.so", + "/usr/lib/x86_64-linux-gnu/security/pam_canonicalize_user.so", + "/usr/lib/x86_64-linux-gnu/security/pam_debug.so", + "/usr/lib/x86_64-linux-gnu/security/pam_deny.so", + "/usr/lib/x86_64-linux-gnu/security/pam_echo.so", + "/usr/lib/x86_64-linux-gnu/security/pam_env.so", + "/usr/lib/x86_64-linux-gnu/security/pam_exec.so", + "/usr/lib/x86_64-linux-gnu/security/pam_faildelay.so", + "/usr/lib/x86_64-linux-gnu/security/pam_faillock.so", + "/usr/lib/x86_64-linux-gnu/security/pam_filter.so", + "/usr/lib/x86_64-linux-gnu/security/pam_ftp.so", + "/usr/lib/x86_64-linux-gnu/security/pam_group.so", + "/usr/lib/x86_64-linux-gnu/security/pam_issue.so", + "/usr/lib/x86_64-linux-gnu/security/pam_keyinit.so", + "/usr/lib/x86_64-linux-gnu/security/pam_limits.so", + "/usr/lib/x86_64-linux-gnu/security/pam_listfile.so", + "/usr/lib/x86_64-linux-gnu/security/pam_localuser.so", + "/usr/lib/x86_64-linux-gnu/security/pam_loginuid.so", + "/usr/lib/x86_64-linux-gnu/security/pam_mail.so", + "/usr/lib/x86_64-linux-gnu/security/pam_mkhomedir.so", + "/usr/lib/x86_64-linux-gnu/security/pam_motd.so", + "/usr/lib/x86_64-linux-gnu/security/pam_namespace.so", + "/usr/lib/x86_64-linux-gnu/security/pam_nologin.so", + "/usr/lib/x86_64-linux-gnu/security/pam_permit.so", + "/usr/lib/x86_64-linux-gnu/security/pam_pwhistory.so", + "/usr/lib/x86_64-linux-gnu/security/pam_rhosts.so", + "/usr/lib/x86_64-linux-gnu/security/pam_rootok.so", + "/usr/lib/x86_64-linux-gnu/security/pam_securetty.so", + "/usr/lib/x86_64-linux-gnu/security/pam_selinux.so", + "/usr/lib/x86_64-linux-gnu/security/pam_sepermit.so", + "/usr/lib/x86_64-linux-gnu/security/pam_setquota.so", + "/usr/lib/x86_64-linux-gnu/security/pam_shells.so", + "/usr/lib/x86_64-linux-gnu/security/pam_stress.so", + "/usr/lib/x86_64-linux-gnu/security/pam_succeed_if.so", + "/usr/lib/x86_64-linux-gnu/security/pam_time.so", + "/usr/lib/x86_64-linux-gnu/security/pam_timestamp.so", + "/usr/lib/x86_64-linux-gnu/security/pam_tty_audit.so", + "/usr/lib/x86_64-linux-gnu/security/pam_umask.so", + "/usr/lib/x86_64-linux-gnu/security/pam_unix.so", + "/usr/lib/x86_64-linux-gnu/security/pam_userdb.so", + "/usr/lib/x86_64-linux-gnu/security/pam_usertype.so", + "/usr/lib/x86_64-linux-gnu/security/pam_warn.so", + "/usr/lib/x86_64-linux-gnu/security/pam_wheel.so", + "/usr/lib/x86_64-linux-gnu/security/pam_xauth.so", + "/usr/share/doc/libpam-modules/NEWS.Debian.gz", + "/usr/share/doc/libpam-modules/changelog.Debian.gz", + "/usr/share/doc/libpam-modules/changelog.gz", + "/usr/share/doc/libpam-modules/copyright", + "/usr/share/doc/libpam-modules/examples/upperLOWER.c", + "/usr/share/lintian/overrides/libpam-modules", + "/usr/share/pam-configs/mkhomedir" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libpam-modules-bin@1.7.0-5", + "Name": "libpam-modules-bin", + "Identifier": { + "PURL": "pkg:deb/debian/libpam-modules-bin@1.7.0-5?arch=amd64\u0026distro=debian-13.7", + "UID": "dbbd2b9769d4b438" + }, + "Version": "1.7.0", + "Release": "5", + "Arch": "amd64", + "SrcName": "pam", + "SrcVersion": "1.7.0", + "SrcRelease": "5", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later", + "GPL-1.0-only", + "GPL-2.0-only", + "GPL-3.0-only", + "GPL-3+ with Bison exception", + "BSD-tcp_wrappers", + "LGPL-2.0-or-later", + "LGPL-2.0-only", + "public-domain", + "Beerware" + ], + "Maintainer": "Sam Hartman \u003chartmans@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libaudit1@1:4.0.2-2+deb13u1", + "libc6@2.41-12+deb13u4", + "libcrypt1@1:4.4.38-1", + "libpam0g@1.7.0-5", + "libselinux1@3.8.1-1", + "libsystemd0@257.13-1~deb13u1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/systemd/system/pam_namespace.service", + "/usr/sbin/faillock", + "/usr/sbin/mkhomedir_helper", + "/usr/sbin/pam_namespace_helper", + "/usr/sbin/pam_timestamp_check", + "/usr/sbin/pwhistory_helper", + "/usr/sbin/unix_chkpwd", + "/usr/sbin/unix_update", + "/usr/share/doc/libpam-modules-bin/changelog.Debian.gz", + "/usr/share/doc/libpam-modules-bin/changelog.gz", + "/usr/share/doc/libpam-modules-bin/copyright", + "/usr/share/lintian/overrides/libpam-modules-bin" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libpam-runtime@1.7.0-5", + "Name": "libpam-runtime", + "Identifier": { + "PURL": "pkg:deb/debian/libpam-runtime@1.7.0-5?arch=all\u0026distro=debian-13.7", + "UID": "1d4f3eaf1c0f9548" + }, + "Version": "1.7.0", + "Release": "5", + "Arch": "all", + "SrcName": "pam", + "SrcVersion": "1.7.0", + "SrcRelease": "5", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later", + "GPL-1.0-only", + "GPL-2.0-only", + "GPL-3.0-only", + "GPL-3+ with Bison exception", + "BSD-tcp_wrappers", + "LGPL-2.0-or-later", + "LGPL-2.0-only", + "public-domain", + "Beerware" + ], + "Maintainer": "Sam Hartman \u003chartmans@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "debconf@1.5.91", + "libpam-modules@1.7.0-5" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/sbin/pam-auth-update", + "/usr/sbin/pam_getenv", + "/usr/share/doc/libpam-runtime/changelog.Debian.gz", + "/usr/share/doc/libpam-runtime/changelog.gz", + "/usr/share/doc/libpam-runtime/copyright", + "/usr/share/lintian/overrides/libpam-runtime", + "/usr/share/locale/af/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/am/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ar/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/as/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/az/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/be/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/bg/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/bn/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/bn_IN/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/bs/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ca/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/cs/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/cy/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/da/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/de/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/de_CH/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/el/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/eo/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/es/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/et/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/eu/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/fa/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/fi/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/fr/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ga/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/gl/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/gu/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/he/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/hi/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/hr/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/hu/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ia/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/id/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/is/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/it/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ja/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ka/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/kk/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/km/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/kn/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ko/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/kw_GB/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ky/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/lt/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/lv/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/mk/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ml/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/mn/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/mr/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ms/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/my/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/nb/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ne/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/nl/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/nn/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/or/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/pa/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/pl/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/pt/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ro/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ru/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/si/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/sk/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/sl/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/sq/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/sr/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/sr@latin/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/sv/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ta/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/te/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/tg/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/th/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/tr/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/uk/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ur/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/vi/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/yo/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/zh_HK/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/zu/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/man/man5/access.conf.5.gz", + "/usr/share/man/man5/faillock.conf.5.gz", + "/usr/share/man/man5/group.conf.5.gz", + "/usr/share/man/man5/limits.conf.5.gz", + "/usr/share/man/man5/namespace.conf.5.gz", + "/usr/share/man/man5/pam.conf.5.gz", + "/usr/share/man/man5/pam_env.conf.5.gz", + "/usr/share/man/man5/pwhistory.conf.5.gz", + "/usr/share/man/man5/sepermit.conf.5.gz", + "/usr/share/man/man5/time.conf.5.gz", + "/usr/share/man/man7/PAM.7.gz", + "/usr/share/man/man8/faillock.8.gz", + "/usr/share/man/man8/mkhomedir_helper.8.gz", + "/usr/share/man/man8/pam-auth-update.8.gz", + "/usr/share/man/man8/pam_access.8.gz", + "/usr/share/man/man8/pam_canonicalize_user.8.gz", + "/usr/share/man/man8/pam_debug.8.gz", + "/usr/share/man/man8/pam_deny.8.gz", + "/usr/share/man/man8/pam_echo.8.gz", + "/usr/share/man/man8/pam_env.8.gz", + "/usr/share/man/man8/pam_exec.8.gz", + "/usr/share/man/man8/pam_faildelay.8.gz", + "/usr/share/man/man8/pam_faillock.8.gz", + "/usr/share/man/man8/pam_filter.8.gz", + "/usr/share/man/man8/pam_ftp.8.gz", + "/usr/share/man/man8/pam_getenv.8.gz", + "/usr/share/man/man8/pam_group.8.gz", + "/usr/share/man/man8/pam_issue.8.gz", + "/usr/share/man/man8/pam_keyinit.8.gz", + "/usr/share/man/man8/pam_limits.8.gz", + "/usr/share/man/man8/pam_listfile.8.gz", + "/usr/share/man/man8/pam_localuser.8.gz", + "/usr/share/man/man8/pam_loginuid.8.gz", + "/usr/share/man/man8/pam_mail.8.gz", + "/usr/share/man/man8/pam_mkhomedir.8.gz", + "/usr/share/man/man8/pam_motd.8.gz", + "/usr/share/man/man8/pam_namespace.8.gz", + "/usr/share/man/man8/pam_namespace_helper.8.gz", + "/usr/share/man/man8/pam_nologin.8.gz", + "/usr/share/man/man8/pam_permit.8.gz", + "/usr/share/man/man8/pam_pwhistory.8.gz", + "/usr/share/man/man8/pam_rhosts.8.gz", + "/usr/share/man/man8/pam_rootok.8.gz", + "/usr/share/man/man8/pam_securetty.8.gz", + "/usr/share/man/man8/pam_selinux.8.gz", + "/usr/share/man/man8/pam_sepermit.8.gz", + "/usr/share/man/man8/pam_setquota.8.gz", + "/usr/share/man/man8/pam_shells.8.gz", + "/usr/share/man/man8/pam_stress.8.gz", + "/usr/share/man/man8/pam_succeed_if.8.gz", + "/usr/share/man/man8/pam_time.8.gz", + "/usr/share/man/man8/pam_timestamp.8.gz", + "/usr/share/man/man8/pam_timestamp_check.8.gz", + "/usr/share/man/man8/pam_tty_audit.8.gz", + "/usr/share/man/man8/pam_umask.8.gz", + "/usr/share/man/man8/pam_unix.8.gz", + "/usr/share/man/man8/pam_userdb.8.gz", + "/usr/share/man/man8/pam_usertype.8.gz", + "/usr/share/man/man8/pam_warn.8.gz", + "/usr/share/man/man8/pam_wheel.8.gz", + "/usr/share/man/man8/pam_xauth.8.gz", + "/usr/share/man/man8/pwhistory_helper.8.gz", + "/usr/share/man/man8/unix_chkpwd.8.gz", + "/usr/share/man/man8/unix_update.8.gz", + "/usr/share/pam-configs/unix", + "/usr/share/pam/common-account", + "/usr/share/pam/common-account.md5sums", + "/usr/share/pam/common-auth", + "/usr/share/pam/common-auth.md5sums", + "/usr/share/pam/common-password", + "/usr/share/pam/common-password.md5sums", + "/usr/share/pam/common-session", + "/usr/share/pam/common-session-noninteractive", + "/usr/share/pam/common-session-noninteractive.md5sums", + "/usr/share/pam/common-session.md5sums" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libpam0g@1.7.0-5", + "Name": "libpam0g", + "Identifier": { + "PURL": "pkg:deb/debian/libpam0g@1.7.0-5?arch=amd64\u0026distro=debian-13.7", + "UID": "ea209b4d4ec86f20" + }, + "Version": "1.7.0", + "Release": "5", + "Arch": "amd64", + "SrcName": "pam", + "SrcVersion": "1.7.0", + "SrcRelease": "5", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later", + "GPL-1.0-only", + "GPL-2.0-only", + "GPL-3.0-only", + "GPL-3+ with Bison exception", + "BSD-tcp_wrappers", + "LGPL-2.0-or-later", + "LGPL-2.0-only", + "public-domain", + "Beerware" + ], + "Maintainer": "Sam Hartman \u003chartmans@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "debconf@1.5.91", + "libaudit1@1:4.0.2-2+deb13u1", + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libpam.so.0.85.1", + "/usr/lib/x86_64-linux-gnu/libpam_misc.so.0.82.1", + "/usr/lib/x86_64-linux-gnu/libpamc.so.0.82.1", + "/usr/share/doc/libpam0g/Debian-PAM-MiniPolicy.gz", + "/usr/share/doc/libpam0g/README", + "/usr/share/doc/libpam0g/README.Debian", + "/usr/share/doc/libpam0g/TODO.Debian", + "/usr/share/doc/libpam0g/changelog.Debian.gz", + "/usr/share/doc/libpam0g/changelog.gz", + "/usr/share/doc/libpam0g/copyright", + "/usr/share/lintian/overrides/libpam0g" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libpcre2-8-0@10.46-1~deb13u2", + "Name": "libpcre2-8-0", + "Identifier": { + "PURL": "pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u2?arch=amd64\u0026distro=debian-13.7", + "UID": "659916a4b0eed8ca" + }, + "Version": "10.46", + "Release": "1~deb13u2", + "Arch": "amd64", + "SrcName": "pcre2", + "SrcVersion": "10.46", + "SrcRelease": "1~deb13u2", + "Licenses": [ + "BSD-3-clause-Cambridge with BINARY LIBRARY-LIKE PACKAGES exception", + "BSD-3-Clause", + "X11", + "BSD-2-Clause", + "public-domain" + ], + "Maintainer": "Matthew Vernon \u003cmatthew@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libpcre2-8.so.0.14.0", + "/usr/share/doc/libpcre2-8-0/README.Debian", + "/usr/share/doc/libpcre2-8-0/changelog.Debian.gz", + "/usr/share/doc/libpcre2-8-0/changelog.gz", + "/usr/share/doc/libpcre2-8-0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libreadline8t64@8.2-6", + "Name": "libreadline8t64", + "Identifier": { + "PURL": "pkg:deb/debian/libreadline8t64@8.2-6?arch=amd64\u0026distro=debian-13.7", + "UID": "55c7596306f21341" + }, + "Version": "8.2", + "Release": "6", + "Arch": "amd64", + "SrcName": "readline", + "SrcVersion": "8.2", + "SrcRelease": "6", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-3.0-only", + "GPL-2.0-or-later", + "GPL-2.0-only", + "GFDL-1.3-no-invariants-or-later", + "GFDL-1.3-or-later", + "ISC-no-attribution" + ], + "Maintainer": "Matthias Klose \u003cdoko@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libtinfo6@6.5+20250216-2", + "readline-common@8.2-6" + ], + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libhistory.so.8.2", + "/usr/lib/x86_64-linux-gnu/libreadline.so.8.2", + "/usr/share/doc/libreadline8t64/README.Debian", + "/usr/share/doc/libreadline8t64/USAGE", + "/usr/share/doc/libreadline8t64/changelog.Debian.gz", + "/usr/share/doc/libreadline8t64/changelog.gz", + "/usr/share/doc/libreadline8t64/copyright", + "/usr/share/doc/libreadline8t64/examples/Inputrc", + "/usr/share/doc/libreadline8t64/inputrc.arrows" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libseccomp2@2.6.0-2", + "Name": "libseccomp2", + "Identifier": { + "PURL": "pkg:deb/debian/libseccomp2@2.6.0-2?arch=amd64\u0026distro=debian-13.7", + "UID": "2af8140f63038666" + }, + "Version": "2.6.0", + "Release": "2", + "Arch": "amd64", + "SrcName": "libseccomp", + "SrcVersion": "2.6.0", + "SrcRelease": "2", + "Licenses": [ + "LGPL-2.1-only" + ], + "Maintainer": "Kees Cook \u003ckees@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libseccomp.so.2.6.0", + "/usr/share/doc/libseccomp2/changelog.Debian.gz", + "/usr/share/doc/libseccomp2/changelog.gz", + "/usr/share/doc/libseccomp2/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libselinux1@3.8.1-1", + "Name": "libselinux1", + "Identifier": { + "PURL": "pkg:deb/debian/libselinux1@3.8.1-1?arch=amd64\u0026distro=debian-13.7", + "UID": "6438bf6d1a389445" + }, + "Version": "3.8.1", + "Release": "1", + "Arch": "amd64", + "SrcName": "libselinux", + "SrcVersion": "3.8.1", + "SrcRelease": "1", + "Licenses": [ + "public-domain", + "GPL-2.0-only" + ], + "Maintainer": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libpcre2-8-0@10.46-1~deb13u2" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/tmpfiles.d/libselinux1.conf", + "/usr/lib/x86_64-linux-gnu/libselinux.so.1", + "/usr/share/doc/libselinux1/changelog.Debian.gz", + "/usr/share/doc/libselinux1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libsemanage-common@3.8.1-1", + "Name": "libsemanage-common", + "Identifier": { + "PURL": "pkg:deb/debian/libsemanage-common@3.8.1-1?arch=all\u0026distro=debian-13.7", + "UID": "ecc6b54d8bc6318c" + }, + "Version": "3.8.1", + "Release": "1", + "Arch": "all", + "SrcName": "libsemanage", + "SrcVersion": "3.8.1", + "SrcRelease": "1", + "Licenses": [ + "LGPL-2.1-or-later", + "LGPL-2.1-only", + "GPL-2.0-only" + ], + "Maintainer": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/share/doc/libsemanage-common/changelog.Debian.gz", + "/usr/share/doc/libsemanage-common/copyright", + "/usr/share/man/man5/semanage.conf.5.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libsemanage2@3.8.1-1", + "Name": "libsemanage2", + "Identifier": { + "PURL": "pkg:deb/debian/libsemanage2@3.8.1-1?arch=amd64\u0026distro=debian-13.7", + "UID": "9b85e9240d41ffa5" + }, + "Version": "3.8.1", + "Release": "1", + "Arch": "amd64", + "SrcName": "libsemanage", + "SrcVersion": "3.8.1", + "SrcRelease": "1", + "Licenses": [ + "LGPL-2.1-or-later", + "LGPL-2.1-only", + "GPL-2.0-only" + ], + "Maintainer": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libaudit1@1:4.0.2-2+deb13u1", + "libbz2-1.0@1.0.8-6", + "libc6@2.41-12+deb13u4", + "libselinux1@3.8.1-1", + "libsemanage-common@3.8.1-1", + "libsepol2@3.8.1-1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libsemanage.so.2", + "/usr/share/doc/libsemanage2/changelog.Debian.gz", + "/usr/share/doc/libsemanage2/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libsepol2@3.8.1-1", + "Name": "libsepol2", + "Identifier": { + "PURL": "pkg:deb/debian/libsepol2@3.8.1-1?arch=amd64\u0026distro=debian-13.7", + "UID": "ab7918253426cd4" + }, + "Version": "3.8.1", + "Release": "1", + "Arch": "amd64", + "SrcName": "libsepol", + "SrcVersion": "3.8.1", + "SrcRelease": "1", + "Licenses": [ + "LGPL-2.1-or-later", + "LGPL-2.1-only", + "Zlib", + "GPL-2.0-only", + "GPL-2.0-or-later" + ], + "Maintainer": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libsepol.so.2", + "/usr/share/doc/libsepol2/changelog.Debian.gz", + "/usr/share/doc/libsepol2/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libsmartcols1@2.41.5-0+deb13u1", + "Name": "libsmartcols1", + "Identifier": { + "PURL": "pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "94502fa5e10395c7" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libsmartcols.so.1.1.0", + "/usr/share/doc/libsmartcols1/NEWS.Debian.gz", + "/usr/share/doc/libsmartcols1/changelog.Debian.gz", + "/usr/share/doc/libsmartcols1/changelog.gz", + "/usr/share/doc/libsmartcols1/copyright", + "/usr/share/lintian/overrides/libsmartcols1" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libsqlite3-0@3.46.1-7+deb13u2", + "Name": "libsqlite3-0", + "Identifier": { + "PURL": "pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u2?arch=amd64\u0026distro=debian-13.7", + "UID": "be1a4f437baf7d0e" + }, + "Version": "3.46.1", + "Release": "7+deb13u2", + "Arch": "amd64", + "SrcName": "sqlite3", + "SrcVersion": "3.46.1", + "SrcRelease": "7+deb13u2", + "Licenses": [ + "public-domain", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libsqlite3.so.0.8.6", + "/usr/share/doc/libsqlite3-0/README.Debian", + "/usr/share/doc/libsqlite3-0/changelog.Debian.gz", + "/usr/share/doc/libsqlite3-0/changelog.gz", + "/usr/share/doc/libsqlite3-0/changelog.html.gz", + "/usr/share/doc/libsqlite3-0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libssl3t64@3.5.7-1~deb13u2", + "Name": "libssl3t64", + "Identifier": { + "PURL": "pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64\u0026distro=debian-13.7", + "UID": "b50e51302f462e9e" + }, + "Version": "3.5.7", + "Release": "1~deb13u2", + "Arch": "amd64", + "SrcName": "openssl", + "SrcVersion": "3.5.7", + "SrcRelease": "1~deb13u2", + "Licenses": [ + "Apache-2.0", + "Artistic-2.0", + "GPL-1.0-or-later", + "GPL-1.0-only" + ], + "Maintainer": "Debian OpenSSL Team \u003cpkg-openssl-devel@alioth-lists.debian.net\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libzstd1@1.5.7+dfsg-1", + "openssl-provider-legacy@3.5.7-1~deb13u2", + "zlib1g@1:1.3.dfsg+really1.3.1-1+b1" + ], + "Layer": { + "Digest": "sha256:dbd0b7849e6c06b61e1fa6b7ffe053f246ce0075890620e3db64b47bb662433a", + "DiffID": "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/engines-3/afalg.so", + "/usr/lib/x86_64-linux-gnu/engines-3/loader_attic.so", + "/usr/lib/x86_64-linux-gnu/engines-3/padlock.so", + "/usr/lib/x86_64-linux-gnu/libcrypto.so.3", + "/usr/lib/x86_64-linux-gnu/libssl.so.3", + "/usr/share/doc/libssl3t64/NEWS.Debian.gz", + "/usr/share/doc/libssl3t64/changelog.Debian.gz", + "/usr/share/doc/libssl3t64/changelog.gz", + "/usr/share/doc/libssl3t64/copyright", + "/usr/share/lintian/overrides/libssl3t64" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libstdc++6@14.2.0-19", + "Name": "libstdc++6", + "Identifier": { + "PURL": "pkg:deb/debian/libstdc%2B%2B6@14.2.0-19?arch=amd64\u0026distro=debian-13.7", + "UID": "13f22117cb429f4d" + }, + "Version": "14.2.0", + "Release": "19", + "Arch": "amd64", + "SrcName": "gcc-14", + "SrcVersion": "14.2.0", + "SrcRelease": "19", + "Maintainer": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "gcc-14-base@14.2.0-19", + "libc6@2.41-12+deb13u4", + "libgcc-s1@14.2.0-19" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libstdc++.so.6.0.33", + "/usr/share/gcc/python/libstdcxx/__init__.py", + "/usr/share/gcc/python/libstdcxx/v6/__init__.py", + "/usr/share/gcc/python/libstdcxx/v6/printers.py", + "/usr/share/gcc/python/libstdcxx/v6/xmethods.py", + "/usr/share/gdb/auto-load/usr/lib/x86_64-linux-gnu/libstdc++.so.6.0.33-gdb.py" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libsystemd0@257.13-1~deb13u1", + "Name": "libsystemd0", + "Identifier": { + "PURL": "pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "b0cd86eb50280666" + }, + "Version": "257.13", + "Release": "1~deb13u1", + "Arch": "amd64", + "SrcName": "systemd", + "SrcVersion": "257.13", + "SrcRelease": "1~deb13u1", + "Licenses": [ + "LGPL-2.1-or-later", + "CC0-1.0", + "GPL-2 with Linux-syscall-note exception", + "MIT", + "public-domain", + "GPL-2.0-or-later", + "GPL-2.0-only", + "LGPL-2.1-only" + ], + "Maintainer": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libcap2@1:2.75-10+deb13u1+b3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0", + "/usr/share/doc/libsystemd0/NEWS.Debian.gz", + "/usr/share/doc/libsystemd0/changelog.Debian.gz", + "/usr/share/doc/libsystemd0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libtinfo6@6.5+20250216-2", + "Name": "libtinfo6", + "Identifier": { + "PURL": "pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64\u0026distro=debian-13.7", + "UID": "c19e4ba0186ba329" + }, + "Version": "6.5+20250216", + "Release": "2", + "Arch": "amd64", + "SrcName": "ncurses", + "SrcVersion": "6.5+20250216", + "SrcRelease": "2", + "Licenses": [ + "MIT/X11", + "X11", + "BSD-3-Clause" + ], + "Maintainer": "Ncurses Maintainers \u003cncurses@packages.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libtic.so.6.5", + "/usr/lib/x86_64-linux-gnu/libtinfo.so.6.5", + "/usr/share/doc/libtinfo6/changelog.Debian.gz", + "/usr/share/doc/libtinfo6/changelog.gz", + "/usr/share/doc/libtinfo6/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libudev1@257.13-1~deb13u1", + "Name": "libudev1", + "Identifier": { + "PURL": "pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "9d7053ae266a0055" + }, + "Version": "257.13", + "Release": "1~deb13u1", + "Arch": "amd64", + "SrcName": "systemd", + "SrcVersion": "257.13", + "SrcRelease": "1~deb13u1", + "Licenses": [ + "LGPL-2.1-or-later", + "CC0-1.0", + "GPL-2 with Linux-syscall-note exception", + "MIT", + "public-domain", + "GPL-2.0-or-later", + "GPL-2.0-only", + "LGPL-2.1-only" + ], + "Maintainer": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libcap2@1:2.75-10+deb13u1+b3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libudev.so.1.7.10", + "/usr/share/doc/libudev1/NEWS.Debian.gz", + "/usr/share/doc/libudev1/changelog.Debian.gz", + "/usr/share/doc/libudev1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libuuid1@2.41.5-0+deb13u1", + "Name": "libuuid1", + "Identifier": { + "PURL": "pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "3a03f1816c93c994" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libuuid.so.1.3.0", + "/usr/share/doc/libuuid1/NEWS.Debian.gz", + "/usr/share/doc/libuuid1/changelog.Debian.gz", + "/usr/share/doc/libuuid1/changelog.gz", + "/usr/share/doc/libuuid1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libxxhash0@0.8.3-2", + "Name": "libxxhash0", + "Identifier": { + "PURL": "pkg:deb/debian/libxxhash0@0.8.3-2?arch=amd64\u0026distro=debian-13.7", + "UID": "29b199fff138a1f3" + }, + "Version": "0.8.3", + "Release": "2", + "Arch": "amd64", + "SrcName": "xxhash", + "SrcVersion": "0.8.3", + "SrcRelease": "2", + "Licenses": [ + "BSD-2-Clause", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Josue Ortega \u003cjosue@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libxxhash.so.0.8.3", + "/usr/share/doc/libxxhash0/changelog.Debian.gz", + "/usr/share/doc/libxxhash0/changelog.gz", + "/usr/share/doc/libxxhash0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libzstd1@1.5.7+dfsg-1", + "Name": "libzstd1", + "Identifier": { + "PURL": "pkg:deb/debian/libzstd1@1.5.7%2Bdfsg-1?arch=amd64\u0026distro=debian-13.7", + "UID": "1edaaf7c1b6cdf0a" + }, + "Version": "1.5.7+dfsg", + "Release": "1", + "Arch": "amd64", + "SrcName": "libzstd", + "SrcVersion": "1.5.7+dfsg", + "SrcRelease": "1", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-only", + "Zlib", + "MIT" + ], + "Maintainer": "RPM packaging team \u003cteam+pkg-rpm@tracker.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libzstd.so.1.5.7", + "/usr/share/doc/libzstd1/changelog.Debian.gz", + "/usr/share/doc/libzstd1/changelog.gz", + "/usr/share/doc/libzstd1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "login@1:4.16.0-2+really2.41.5-0+deb13u1", + "Name": "login", + "Identifier": { + "PURL": "pkg:deb/debian/login@4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "dc99754e767c40b9" + }, + "Version": "4.16.0-2+really2.41.5", + "Release": "0+deb13u1", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libaudit1@1:4.0.2-2+deb13u1", + "libc6@2.41-12+deb13u4", + "libcrypt1@1:4.4.38-1", + "libpam-modules@1.7.0-5", + "libpam-runtime@1.7.0-5", + "libpam0g@1.7.0-5" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/login", + "/usr/bin/newgrp", + "/usr/sbin/nologin", + "/usr/share/bash-completion/completions/newgrp", + "/usr/share/doc/login/NEWS.Debian.gz", + "/usr/share/doc/login/changelog.Debian.gz", + "/usr/share/doc/login/changelog.gz", + "/usr/share/doc/login/copyright", + "/usr/share/lintian/overrides/login", + "/usr/share/man/de/man1/login.1.gz", + "/usr/share/man/de/man1/newgrp.1.gz", + "/usr/share/man/de/man8/nologin.8.gz", + "/usr/share/man/fr/man1/login.1.gz", + "/usr/share/man/man1/login.1.gz", + "/usr/share/man/man1/newgrp.1.gz", + "/usr/share/man/man8/nologin.8.gz", + "/usr/share/man/pl/man1/login.1.gz", + "/usr/share/man/pl/man1/newgrp.1.gz", + "/usr/share/man/pl/man8/nologin.8.gz", + "/usr/share/man/ro/man1/login.1.gz", + "/usr/share/man/ro/man1/newgrp.1.gz", + "/usr/share/man/ro/man8/nologin.8.gz", + "/usr/share/man/sr/man1/login.1.gz", + "/usr/share/man/sr/man1/newgrp.1.gz", + "/usr/share/man/sr/man8/nologin.8.gz", + "/usr/share/man/uk/man1/login.1.gz", + "/usr/share/man/uk/man1/newgrp.1.gz", + "/usr/share/man/uk/man8/nologin.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "login.defs@1:4.17.4-2", + "Name": "login.defs", + "Identifier": { + "PURL": "pkg:deb/debian/login.defs@4.17.4-2?arch=all\u0026distro=debian-13.7\u0026epoch=1", + "UID": "b6a337588c67d5a3" + }, + "Version": "4.17.4", + "Release": "2", + "Epoch": 1, + "Arch": "all", + "SrcName": "shadow", + "SrcVersion": "4.17.4", + "SrcRelease": "2", + "SrcEpoch": 1, + "Licenses": [ + "BSD-3-Clause", + "GPL-1.0-only", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/share/doc/login.defs/NEWS.Debian.gz", + "/usr/share/doc/login.defs/changelog.Debian.gz", + "/usr/share/doc/login.defs/changelog.gz", + "/usr/share/doc/login.defs/copyright", + "/usr/share/man/de/man5/login.defs.5.gz", + "/usr/share/man/fr/man5/login.defs.5.gz", + "/usr/share/man/it/man5/login.defs.5.gz", + "/usr/share/man/ja/man5/login.defs.5.gz", + "/usr/share/man/man5/login.defs.5.gz", + "/usr/share/man/ru/man5/login.defs.5.gz", + "/usr/share/man/uk/man5/login.defs.5.gz", + "/usr/share/man/zh_CN/man5/login.defs.5.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "mawk@1.3.4.20250131-1", + "Name": "mawk", + "Identifier": { + "PURL": "pkg:deb/debian/mawk@1.3.4.20250131-1?arch=amd64\u0026distro=debian-13.7", + "UID": "fc097c5651b898a7" + }, + "Version": "1.3.4.20250131", + "Release": "1", + "Arch": "amd64", + "SrcName": "mawk", + "SrcVersion": "1.3.4.20250131", + "SrcRelease": "1", + "Licenses": [ + "GPL-2.0-only", + "X11", + "CC-BY-3.0" + ], + "Maintainer": "Boyuan Yang \u003cbyang@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/mawk", + "/usr/share/doc/mawk/ACKNOWLEDGMENT", + "/usr/share/doc/mawk/README", + "/usr/share/doc/mawk/changelog.Debian.gz", + "/usr/share/doc/mawk/changelog.gz", + "/usr/share/doc/mawk/copyright", + "/usr/share/doc/mawk/examples/ct_length.awk", + "/usr/share/doc/mawk/examples/decl.awk", + "/usr/share/doc/mawk/examples/deps.awk", + "/usr/share/doc/mawk/examples/eatc.awk", + "/usr/share/doc/mawk/examples/gdecl.awk", + "/usr/share/doc/mawk/examples/hcal", + "/usr/share/doc/mawk/examples/hical", + "/usr/share/doc/mawk/examples/nocomment.awk", + "/usr/share/doc/mawk/examples/primes.awk", + "/usr/share/doc/mawk/examples/qsort.awk", + "/usr/share/man/man1/mawk.1.gz", + "/usr/share/man/man7/mawk-arrays.7.gz", + "/usr/share/man/man7/mawk-code.7.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "mount@2.41.5-0+deb13u1", + "Name": "mount", + "Identifier": { + "PURL": "pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "d781ec5616a75c78" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/mount", + "/usr/bin/umount", + "/usr/sbin/losetup", + "/usr/sbin/swapoff", + "/usr/sbin/swapon", + "/usr/share/bash-completion/completions/losetup", + "/usr/share/bash-completion/completions/mount", + "/usr/share/bash-completion/completions/swapoff", + "/usr/share/bash-completion/completions/swapon", + "/usr/share/bash-completion/completions/umount", + "/usr/share/doc/mount/NEWS.Debian.gz", + "/usr/share/doc/mount/changelog.Debian.gz", + "/usr/share/doc/mount/changelog.gz", + "/usr/share/doc/mount/copyright", + "/usr/share/doc/mount/examples/filesystems", + "/usr/share/doc/mount/examples/fstab", + "/usr/share/doc/mount/examples/mount.fstab", + "/usr/share/doc/mount/mount.txt", + "/usr/share/lintian/overrides/mount", + "/usr/share/man/man5/fstab.5.gz", + "/usr/share/man/man8/losetup.8.gz", + "/usr/share/man/man8/mount.8.gz", + "/usr/share/man/man8/swapon.8.gz", + "/usr/share/man/man8/umount.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "ncurses-base@6.5+20250216-2", + "Name": "ncurses-base", + "Identifier": { + "PURL": "pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all\u0026distro=debian-13.7", + "UID": "767a0231348a5cb5" + }, + "Version": "6.5+20250216", + "Release": "2", + "Arch": "all", + "SrcName": "ncurses", + "SrcVersion": "6.5+20250216", + "SrcRelease": "2", + "Licenses": [ + "MIT/X11", + "X11", + "BSD-3-Clause" + ], + "Maintainer": "Ncurses Maintainers \u003cncurses@packages.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/share/doc/ncurses-base/FAQ", + "/usr/share/doc/ncurses-base/TODO.Debian", + "/usr/share/doc/ncurses-base/changelog.Debian.gz", + "/usr/share/doc/ncurses-base/changelog.gz", + "/usr/share/doc/ncurses-base/copyright", + "/usr/share/lintian/overrides/ncurses-base", + "/usr/share/tabset/std", + "/usr/share/tabset/stdcrt", + "/usr/share/tabset/vt100", + "/usr/share/tabset/vt300", + "/usr/share/terminfo/E/Eterm", + "/usr/share/terminfo/a/ansi", + "/usr/share/terminfo/c/cons25", + "/usr/share/terminfo/c/cygwin", + "/usr/share/terminfo/d/dumb", + "/usr/share/terminfo/h/hurd", + "/usr/share/terminfo/l/linux", + "/usr/share/terminfo/m/mach", + "/usr/share/terminfo/m/mach-bold", + "/usr/share/terminfo/m/mach-color", + "/usr/share/terminfo/m/mach-gnu", + "/usr/share/terminfo/m/mach-gnu-color", + "/usr/share/terminfo/p/pcansi", + "/usr/share/terminfo/r/rxvt", + "/usr/share/terminfo/r/rxvt-basic", + "/usr/share/terminfo/r/rxvt-unicode", + "/usr/share/terminfo/r/rxvt-unicode-256color", + "/usr/share/terminfo/s/screen", + "/usr/share/terminfo/s/screen-256color", + "/usr/share/terminfo/s/screen-256color-bce", + "/usr/share/terminfo/s/screen-bce", + "/usr/share/terminfo/s/screen-s", + "/usr/share/terminfo/s/screen-w", + "/usr/share/terminfo/s/screen.xterm-256color", + "/usr/share/terminfo/s/sun", + "/usr/share/terminfo/t/tmux", + "/usr/share/terminfo/t/tmux-256color", + "/usr/share/terminfo/v/vt100", + "/usr/share/terminfo/v/vt102", + "/usr/share/terminfo/v/vt220", + "/usr/share/terminfo/v/vt52", + "/usr/share/terminfo/w/wsvt25", + "/usr/share/terminfo/w/wsvt25m", + "/usr/share/terminfo/x/xterm", + "/usr/share/terminfo/x/xterm-256color", + "/usr/share/terminfo/x/xterm-color", + "/usr/share/terminfo/x/xterm-mono", + "/usr/share/terminfo/x/xterm-r5", + "/usr/share/terminfo/x/xterm-r6", + "/usr/share/terminfo/x/xterm-vt220", + "/usr/share/terminfo/x/xterm-xfree86" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "ncurses-bin@6.5+20250216-2", + "Name": "ncurses-bin", + "Identifier": { + "PURL": "pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64\u0026distro=debian-13.7", + "UID": "5b541563cf6587e5" + }, + "Version": "6.5+20250216", + "Release": "2", + "Arch": "amd64", + "SrcName": "ncurses", + "SrcVersion": "6.5+20250216", + "SrcRelease": "2", + "Licenses": [ + "MIT/X11", + "X11", + "BSD-3-Clause" + ], + "Maintainer": "Ncurses Maintainers \u003cncurses@packages.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/clear", + "/usr/bin/infocmp", + "/usr/bin/tabs", + "/usr/bin/tic", + "/usr/bin/toe", + "/usr/bin/tput", + "/usr/bin/tset", + "/usr/share/doc/ncurses-bin/changelog.Debian.gz", + "/usr/share/doc/ncurses-bin/changelog.gz", + "/usr/share/doc/ncurses-bin/copyright", + "/usr/share/man/man1/captoinfo.1.gz", + "/usr/share/man/man1/clear.1.gz", + "/usr/share/man/man1/infocmp.1.gz", + "/usr/share/man/man1/infotocap.1.gz", + "/usr/share/man/man1/tabs.1.gz", + "/usr/share/man/man1/tic.1.gz", + "/usr/share/man/man1/toe.1.gz", + "/usr/share/man/man1/tput.1.gz", + "/usr/share/man/man1/tset.1.gz", + "/usr/share/man/man5/scr_dump.5.gz", + "/usr/share/man/man5/term.5.gz", + "/usr/share/man/man5/terminfo.5.gz", + "/usr/share/man/man5/user_caps.5.gz", + "/usr/share/man/man7/term.7.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "netbase@6.5", + "Name": "netbase", + "Identifier": { + "PURL": "pkg:deb/debian/netbase@6.5?arch=all\u0026distro=debian-13.7", + "UID": "9929ff265179fc61" + }, + "Version": "6.5", + "Arch": "all", + "SrcName": "netbase", + "SrcVersion": "6.5", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Marco d'Itri \u003cmd@linux.it\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:dbd0b7849e6c06b61e1fa6b7ffe053f246ce0075890620e3db64b47bb662433a", + "DiffID": "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca" + }, + "InstalledFiles": [ + "/usr/share/doc/netbase/changelog.gz", + "/usr/share/doc/netbase/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "openssl@3.5.7-1~deb13u2", + "Name": "openssl", + "Identifier": { + "PURL": "pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64\u0026distro=debian-13.7", + "UID": "83d900f21e0ed5ab" + }, + "Version": "3.5.7", + "Release": "1~deb13u2", + "Arch": "amd64", + "SrcName": "openssl", + "SrcVersion": "3.5.7", + "SrcRelease": "1~deb13u2", + "Licenses": [ + "Apache-2.0", + "Artistic-2.0", + "GPL-1.0-or-later", + "GPL-1.0-only" + ], + "Maintainer": "Debian OpenSSL Team \u003cpkg-openssl-devel@alioth-lists.debian.net\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libssl3t64@3.5.7-1~deb13u2" + ], + "Layer": { + "Digest": "sha256:dbd0b7849e6c06b61e1fa6b7ffe053f246ce0075890620e3db64b47bb662433a", + "DiffID": "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca" + }, + "InstalledFiles": [ + "/usr/bin/c_rehash", + "/usr/bin/openssl", + "/usr/lib/ssl/misc/CA.pl", + "/usr/lib/ssl/misc/tsget.pl", + "/usr/share/doc/openssl/HOWTO/certificates.txt.gz", + "/usr/share/doc/openssl/HOWTO/documenting-functions-and-macros.md.gz", + "/usr/share/doc/openssl/HOWTO/keys.txt.gz", + "/usr/share/doc/openssl/NEWS.md.gz", + "/usr/share/doc/openssl/README-ENGINES.md.gz", + "/usr/share/doc/openssl/README-PROVIDERS.md.gz", + "/usr/share/doc/openssl/README-QUIC.md.gz", + "/usr/share/doc/openssl/README.Debian", + "/usr/share/doc/openssl/README.md.gz", + "/usr/share/doc/openssl/changelog.Debian.gz", + "/usr/share/doc/openssl/changelog.gz", + "/usr/share/doc/openssl/copyright", + "/usr/share/doc/openssl/fingerprints.txt", + "/usr/share/lintian/overrides/openssl", + "/usr/share/man/man1/CA.pl.1ssl.gz", + "/usr/share/man/man1/openssl-asn1parse.1ssl.gz", + "/usr/share/man/man1/openssl-ca.1ssl.gz", + "/usr/share/man/man1/openssl-ciphers.1ssl.gz", + "/usr/share/man/man1/openssl-cmds.1ssl.gz", + "/usr/share/man/man1/openssl-cmp.1ssl.gz", + "/usr/share/man/man1/openssl-cms.1ssl.gz", + "/usr/share/man/man1/openssl-crl.1ssl.gz", + "/usr/share/man/man1/openssl-crl2pkcs7.1ssl.gz", + "/usr/share/man/man1/openssl-dgst.1ssl.gz", + "/usr/share/man/man1/openssl-dhparam.1ssl.gz", + "/usr/share/man/man1/openssl-dsa.1ssl.gz", + "/usr/share/man/man1/openssl-dsaparam.1ssl.gz", + "/usr/share/man/man1/openssl-ec.1ssl.gz", + "/usr/share/man/man1/openssl-ecparam.1ssl.gz", + "/usr/share/man/man1/openssl-enc.1ssl.gz", + "/usr/share/man/man1/openssl-engine.1ssl.gz", + "/usr/share/man/man1/openssl-errstr.1ssl.gz", + "/usr/share/man/man1/openssl-fipsinstall.1ssl.gz", + "/usr/share/man/man1/openssl-format-options.1ssl.gz", + "/usr/share/man/man1/openssl-gendsa.1ssl.gz", + "/usr/share/man/man1/openssl-genpkey.1ssl.gz", + "/usr/share/man/man1/openssl-genrsa.1ssl.gz", + "/usr/share/man/man1/openssl-info.1ssl.gz", + "/usr/share/man/man1/openssl-kdf.1ssl.gz", + "/usr/share/man/man1/openssl-list.1ssl.gz", + "/usr/share/man/man1/openssl-mac.1ssl.gz", + "/usr/share/man/man1/openssl-namedisplay-options.1ssl.gz", + "/usr/share/man/man1/openssl-nseq.1ssl.gz", + "/usr/share/man/man1/openssl-ocsp.1ssl.gz", + "/usr/share/man/man1/openssl-passphrase-options.1ssl.gz", + "/usr/share/man/man1/openssl-passwd.1ssl.gz", + "/usr/share/man/man1/openssl-pkcs12.1ssl.gz", + "/usr/share/man/man1/openssl-pkcs7.1ssl.gz", + "/usr/share/man/man1/openssl-pkcs8.1ssl.gz", + "/usr/share/man/man1/openssl-pkey.1ssl.gz", + "/usr/share/man/man1/openssl-pkeyparam.1ssl.gz", + "/usr/share/man/man1/openssl-pkeyutl.1ssl.gz", + "/usr/share/man/man1/openssl-prime.1ssl.gz", + "/usr/share/man/man1/openssl-rand.1ssl.gz", + "/usr/share/man/man1/openssl-rehash.1ssl.gz", + "/usr/share/man/man1/openssl-req.1ssl.gz", + "/usr/share/man/man1/openssl-rsa.1ssl.gz", + "/usr/share/man/man1/openssl-rsautl.1ssl.gz", + "/usr/share/man/man1/openssl-s_client.1ssl.gz", + "/usr/share/man/man1/openssl-s_server.1ssl.gz", + "/usr/share/man/man1/openssl-s_time.1ssl.gz", + "/usr/share/man/man1/openssl-sess_id.1ssl.gz", + "/usr/share/man/man1/openssl-skeyutl.1ssl.gz", + "/usr/share/man/man1/openssl-smime.1ssl.gz", + "/usr/share/man/man1/openssl-speed.1ssl.gz", + "/usr/share/man/man1/openssl-spkac.1ssl.gz", + "/usr/share/man/man1/openssl-srp.1ssl.gz", + "/usr/share/man/man1/openssl-storeutl.1ssl.gz", + "/usr/share/man/man1/openssl-ts.1ssl.gz", + "/usr/share/man/man1/openssl-verification-options.1ssl.gz", + "/usr/share/man/man1/openssl-verify.1ssl.gz", + "/usr/share/man/man1/openssl-version.1ssl.gz", + "/usr/share/man/man1/openssl-x509.1ssl.gz", + "/usr/share/man/man1/openssl.1ssl.gz", + "/usr/share/man/man1/tsget.1ssl.gz", + "/usr/share/man/man5/config.5ssl.gz", + "/usr/share/man/man5/fips_config.5ssl.gz", + "/usr/share/man/man5/x509v3_config.5ssl.gz", + "/usr/share/man/man7/EVP_ASYM_CIPHER-RSA.7ssl.gz", + "/usr/share/man/man7/EVP_ASYM_CIPHER-SM2.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-AES.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-ARIA.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-BLOWFISH.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-CAMELLIA.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-CAST.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-CHACHA.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-DES.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-IDEA.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-NULL.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-RC2.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-RC4.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-RC5.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-SEED.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-SM4.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-ARGON2.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-HKDF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-HMAC-DRBG.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-KB.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-KRB5KDF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-PBKDF1.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-PBKDF2.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-PKCS12KDF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-PVKKDF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-SCRYPT.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-SS.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-SSHKDF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-TLS13_KDF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-TLS1_PRF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-X942-ASN1.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-X942-CONCAT.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-X963.7ssl.gz", + "/usr/share/man/man7/EVP_KEM-EC.7ssl.gz", + "/usr/share/man/man7/EVP_KEM-ML-KEM.7ssl.gz", + "/usr/share/man/man7/EVP_KEM-RSA.7ssl.gz", + "/usr/share/man/man7/EVP_KEM-X25519.7ssl.gz", + "/usr/share/man/man7/EVP_KEYEXCH-DH.7ssl.gz", + "/usr/share/man/man7/EVP_KEYEXCH-ECDH.7ssl.gz", + "/usr/share/man/man7/EVP_KEYEXCH-X25519.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-BLAKE2.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-CMAC.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-GMAC.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-HMAC.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-KMAC.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-Poly1305.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-Siphash.7ssl.gz", + "/usr/share/man/man7/EVP_MD-BLAKE2.7ssl.gz", + "/usr/share/man/man7/EVP_MD-KECCAK.7ssl.gz", + "/usr/share/man/man7/EVP_MD-MD2.7ssl.gz", + "/usr/share/man/man7/EVP_MD-MD4.7ssl.gz", + "/usr/share/man/man7/EVP_MD-MD5-SHA1.7ssl.gz", + "/usr/share/man/man7/EVP_MD-MD5.7ssl.gz", + "/usr/share/man/man7/EVP_MD-MDC2.7ssl.gz", + "/usr/share/man/man7/EVP_MD-NULL.7ssl.gz", + "/usr/share/man/man7/EVP_MD-RIPEMD160.7ssl.gz", + "/usr/share/man/man7/EVP_MD-SHA1.7ssl.gz", + "/usr/share/man/man7/EVP_MD-SHA2.7ssl.gz", + "/usr/share/man/man7/EVP_MD-SHA3.7ssl.gz", + "/usr/share/man/man7/EVP_MD-SHAKE.7ssl.gz", + "/usr/share/man/man7/EVP_MD-SM3.7ssl.gz", + "/usr/share/man/man7/EVP_MD-WHIRLPOOL.7ssl.gz", + "/usr/share/man/man7/EVP_MD-common.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-DH.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-DSA.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-EC.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-FFC.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-HMAC.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-ML-DSA.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-ML-KEM.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-RSA.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-SLH-DSA.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-SM2.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-X25519.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-CRNG-TEST.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-CTR-DRBG.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-HASH-DRBG.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-HMAC-DRBG.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-JITTER.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-SEED-SRC.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-TEST-RAND.7ssl.gz", + "/usr/share/man/man7/EVP_RAND.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-DSA.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-ECDSA.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-ED25519.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-HMAC.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-ML-DSA.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-RSA.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-SLH-DSA.7ssl.gz", + "/usr/share/man/man7/OSSL_PROVIDER-FIPS.7ssl.gz", + "/usr/share/man/man7/OSSL_PROVIDER-base.7ssl.gz", + "/usr/share/man/man7/OSSL_PROVIDER-default.7ssl.gz", + "/usr/share/man/man7/OSSL_PROVIDER-legacy.7ssl.gz", + "/usr/share/man/man7/OSSL_PROVIDER-null.7ssl.gz", + "/usr/share/man/man7/OSSL_STORE-winstore.7ssl.gz", + "/usr/share/man/man7/RAND.7ssl.gz", + "/usr/share/man/man7/RSA-PSS.7ssl.gz", + "/usr/share/man/man7/X25519.7ssl.gz", + "/usr/share/man/man7/bio.7ssl.gz", + "/usr/share/man/man7/ct.7ssl.gz", + "/usr/share/man/man7/des_modes.7ssl.gz", + "/usr/share/man/man7/evp.7ssl.gz", + "/usr/share/man/man7/fips_module.7ssl.gz", + "/usr/share/man/man7/life_cycle-cipher.7ssl.gz", + "/usr/share/man/man7/life_cycle-digest.7ssl.gz", + "/usr/share/man/man7/life_cycle-kdf.7ssl.gz", + "/usr/share/man/man7/life_cycle-mac.7ssl.gz", + "/usr/share/man/man7/life_cycle-pkey.7ssl.gz", + "/usr/share/man/man7/life_cycle-rand.7ssl.gz", + "/usr/share/man/man7/openssl-core.h.7ssl.gz", + "/usr/share/man/man7/openssl-core_dispatch.h.7ssl.gz", + "/usr/share/man/man7/openssl-core_names.h.7ssl.gz", + "/usr/share/man/man7/openssl-env.7ssl.gz", + "/usr/share/man/man7/openssl-glossary.7ssl.gz", + "/usr/share/man/man7/openssl-qlog.7ssl.gz", + "/usr/share/man/man7/openssl-quic-concurrency.7ssl.gz", + "/usr/share/man/man7/openssl-quic.7ssl.gz", + "/usr/share/man/man7/openssl-threads.7ssl.gz", + "/usr/share/man/man7/openssl_user_macros.7ssl.gz", + "/usr/share/man/man7/ossl-guide-introduction.7ssl.gz", + "/usr/share/man/man7/ossl-guide-libcrypto-introduction.7ssl.gz", + "/usr/share/man/man7/ossl-guide-libraries-introduction.7ssl.gz", + "/usr/share/man/man7/ossl-guide-libssl-introduction.7ssl.gz", + "/usr/share/man/man7/ossl-guide-migration.7ssl.gz", + "/usr/share/man/man7/ossl-guide-quic-client-block.7ssl.gz", + "/usr/share/man/man7/ossl-guide-quic-client-non-block.7ssl.gz", + "/usr/share/man/man7/ossl-guide-quic-introduction.7ssl.gz", + "/usr/share/man/man7/ossl-guide-quic-multi-stream.7ssl.gz", + "/usr/share/man/man7/ossl-guide-quic-server-block.7ssl.gz", + "/usr/share/man/man7/ossl-guide-quic-server-non-block.7ssl.gz", + "/usr/share/man/man7/ossl-guide-tls-client-block.7ssl.gz", + "/usr/share/man/man7/ossl-guide-tls-client-non-block.7ssl.gz", + "/usr/share/man/man7/ossl-guide-tls-introduction.7ssl.gz", + "/usr/share/man/man7/ossl-guide-tls-server-block.7ssl.gz", + "/usr/share/man/man7/ossl_store-file.7ssl.gz", + "/usr/share/man/man7/ossl_store.7ssl.gz", + "/usr/share/man/man7/passphrase-encoding.7ssl.gz", + "/usr/share/man/man7/property.7ssl.gz", + "/usr/share/man/man7/provider-asym_cipher.7ssl.gz", + "/usr/share/man/man7/provider-base.7ssl.gz", + "/usr/share/man/man7/provider-cipher.7ssl.gz", + "/usr/share/man/man7/provider-decoder.7ssl.gz", + "/usr/share/man/man7/provider-digest.7ssl.gz", + "/usr/share/man/man7/provider-encoder.7ssl.gz", + "/usr/share/man/man7/provider-kdf.7ssl.gz", + "/usr/share/man/man7/provider-kem.7ssl.gz", + "/usr/share/man/man7/provider-keyexch.7ssl.gz", + "/usr/share/man/man7/provider-keymgmt.7ssl.gz", + "/usr/share/man/man7/provider-mac.7ssl.gz", + "/usr/share/man/man7/provider-object.7ssl.gz", + "/usr/share/man/man7/provider-rand.7ssl.gz", + "/usr/share/man/man7/provider-signature.7ssl.gz", + "/usr/share/man/man7/provider-skeymgmt.7ssl.gz", + "/usr/share/man/man7/provider-storemgmt.7ssl.gz", + "/usr/share/man/man7/provider.7ssl.gz", + "/usr/share/man/man7/proxy-certificates.7ssl.gz", + "/usr/share/man/man7/x509.7ssl.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "openssl-provider-legacy@3.5.7-1~deb13u2", + "Name": "openssl-provider-legacy", + "Identifier": { + "PURL": "pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64\u0026distro=debian-13.7", + "UID": "5950cac2e0786c63" + }, + "Version": "3.5.7", + "Release": "1~deb13u2", + "Arch": "amd64", + "SrcName": "openssl", + "SrcVersion": "3.5.7", + "SrcRelease": "1~deb13u2", + "Licenses": [ + "Apache-2.0", + "Artistic-2.0", + "GPL-1.0-or-later", + "GPL-1.0-only" + ], + "Maintainer": "Debian OpenSSL Team \u003cpkg-openssl-devel@alioth-lists.debian.net\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libssl3t64@3.5.7-1~deb13u2" + ], + "Layer": { + "Digest": "sha256:dbd0b7849e6c06b61e1fa6b7ffe053f246ce0075890620e3db64b47bb662433a", + "DiffID": "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/ossl-modules/legacy.so", + "/usr/share/doc/openssl-provider-legacy/changelog.Debian.gz", + "/usr/share/doc/openssl-provider-legacy/changelog.gz", + "/usr/share/doc/openssl-provider-legacy/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "passwd@1:4.17.4-2", + "Name": "passwd", + "Identifier": { + "PURL": "pkg:deb/debian/passwd@4.17.4-2?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "7e83ab5858a7a76d" + }, + "Version": "4.17.4", + "Release": "2", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "shadow", + "SrcVersion": "4.17.4", + "SrcRelease": "2", + "SrcEpoch": 1, + "Licenses": [ + "BSD-3-Clause", + "GPL-1.0-only", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "base-passwd@3.6.7", + "libacl1@2.3.2-2+b1", + "libattr1@1:2.5.2-3", + "libaudit1@1:4.0.2-2+deb13u1", + "libbsd0@0.12.2-2", + "libc6@2.41-12+deb13u4", + "libcrypt1@1:4.4.38-1", + "libpam-modules@1.7.0-5", + "libpam0g@1.7.0-5", + "libselinux1@3.8.1-1", + "libsemanage2@3.8.1-1", + "login.defs@1:4.17.4-2" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/chage", + "/usr/bin/chfn", + "/usr/bin/chsh", + "/usr/bin/expiry", + "/usr/bin/gpasswd", + "/usr/bin/passwd", + "/usr/lib/tmpfiles.d/passwd.conf", + "/usr/sbin/chgpasswd", + "/usr/sbin/chpasswd", + "/usr/sbin/groupadd", + "/usr/sbin/groupdel", + "/usr/sbin/groupmod", + "/usr/sbin/grpck", + "/usr/sbin/grpconv", + "/usr/sbin/grpunconv", + "/usr/sbin/newusers", + "/usr/sbin/pwck", + "/usr/sbin/pwconv", + "/usr/sbin/pwunconv", + "/usr/sbin/shadowconfig", + "/usr/sbin/useradd", + "/usr/sbin/userdel", + "/usr/sbin/usermod", + "/usr/sbin/vipw", + "/usr/share/doc/passwd/NEWS.Debian.gz", + "/usr/share/doc/passwd/README.Debian", + "/usr/share/doc/passwd/TODO.Debian", + "/usr/share/doc/passwd/changelog.Debian.gz", + "/usr/share/doc/passwd/changelog.gz", + "/usr/share/doc/passwd/copyright", + "/usr/share/doc/passwd/examples/passwd.expire.cron", + "/usr/share/lintian/overrides/passwd", + "/usr/share/locale/bs/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ca/LC_MESSAGES/shadow.mo", + "/usr/share/locale/cs/LC_MESSAGES/shadow.mo", + "/usr/share/locale/da/LC_MESSAGES/shadow.mo", + "/usr/share/locale/de/LC_MESSAGES/shadow.mo", + "/usr/share/locale/dz/LC_MESSAGES/shadow.mo", + "/usr/share/locale/el/LC_MESSAGES/shadow.mo", + "/usr/share/locale/es/LC_MESSAGES/shadow.mo", + "/usr/share/locale/eu/LC_MESSAGES/shadow.mo", + "/usr/share/locale/fi/LC_MESSAGES/shadow.mo", + "/usr/share/locale/fr/LC_MESSAGES/shadow.mo", + "/usr/share/locale/gl/LC_MESSAGES/shadow.mo", + "/usr/share/locale/he/LC_MESSAGES/shadow.mo", + "/usr/share/locale/hu/LC_MESSAGES/shadow.mo", + "/usr/share/locale/id/LC_MESSAGES/shadow.mo", + "/usr/share/locale/it/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ja/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ka/LC_MESSAGES/shadow.mo", + "/usr/share/locale/kk/LC_MESSAGES/shadow.mo", + "/usr/share/locale/km/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ko/LC_MESSAGES/shadow.mo", + "/usr/share/locale/nb/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ne/LC_MESSAGES/shadow.mo", + "/usr/share/locale/nl/LC_MESSAGES/shadow.mo", + "/usr/share/locale/nn/LC_MESSAGES/shadow.mo", + "/usr/share/locale/pl/LC_MESSAGES/shadow.mo", + "/usr/share/locale/pt/LC_MESSAGES/shadow.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ro/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ru/LC_MESSAGES/shadow.mo", + "/usr/share/locale/sk/LC_MESSAGES/shadow.mo", + "/usr/share/locale/sq/LC_MESSAGES/shadow.mo", + "/usr/share/locale/sv/LC_MESSAGES/shadow.mo", + "/usr/share/locale/tl/LC_MESSAGES/shadow.mo", + "/usr/share/locale/tr/LC_MESSAGES/shadow.mo", + "/usr/share/locale/uk/LC_MESSAGES/shadow.mo", + "/usr/share/locale/vi/LC_MESSAGES/shadow.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/shadow.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/shadow.mo", + "/usr/share/man/cs/man1/expiry.1.gz", + "/usr/share/man/cs/man1/gpasswd.1.gz", + "/usr/share/man/cs/man5/gshadow.5.gz", + "/usr/share/man/cs/man5/passwd.5.gz", + "/usr/share/man/cs/man5/shadow.5.gz", + "/usr/share/man/cs/man8/groupadd.8.gz", + "/usr/share/man/cs/man8/groupdel.8.gz", + "/usr/share/man/cs/man8/groupmod.8.gz", + "/usr/share/man/cs/man8/grpck.8.gz", + "/usr/share/man/cs/man8/vipw.8.gz", + "/usr/share/man/da/man1/chfn.1.gz", + "/usr/share/man/da/man5/gshadow.5.gz", + "/usr/share/man/da/man8/groupdel.8.gz", + "/usr/share/man/da/man8/vipw.8.gz", + "/usr/share/man/de/man1/chage.1.gz", + "/usr/share/man/de/man1/chfn.1.gz", + "/usr/share/man/de/man1/chsh.1.gz", + "/usr/share/man/de/man1/expiry.1.gz", + "/usr/share/man/de/man1/gpasswd.1.gz", + "/usr/share/man/de/man1/passwd.1.gz", + "/usr/share/man/de/man5/gshadow.5.gz", + "/usr/share/man/de/man5/passwd.5.gz", + "/usr/share/man/de/man5/shadow.5.gz", + "/usr/share/man/de/man8/chgpasswd.8.gz", + "/usr/share/man/de/man8/chpasswd.8.gz", + "/usr/share/man/de/man8/groupadd.8.gz", + "/usr/share/man/de/man8/groupdel.8.gz", + "/usr/share/man/de/man8/groupmod.8.gz", + "/usr/share/man/de/man8/grpck.8.gz", + "/usr/share/man/de/man8/newusers.8.gz", + "/usr/share/man/de/man8/pwck.8.gz", + "/usr/share/man/de/man8/pwconv.8.gz", + "/usr/share/man/de/man8/useradd.8.gz", + "/usr/share/man/de/man8/userdel.8.gz", + "/usr/share/man/de/man8/usermod.8.gz", + "/usr/share/man/de/man8/vipw.8.gz", + "/usr/share/man/fi/man1/chfn.1.gz", + "/usr/share/man/fi/man1/chsh.1.gz", + "/usr/share/man/fr/man1/chage.1.gz", + "/usr/share/man/fr/man1/chfn.1.gz", + "/usr/share/man/fr/man1/chsh.1.gz", + "/usr/share/man/fr/man1/expiry.1.gz", + "/usr/share/man/fr/man1/gpasswd.1.gz", + "/usr/share/man/fr/man1/passwd.1.gz", + "/usr/share/man/fr/man5/gshadow.5.gz", + "/usr/share/man/fr/man5/passwd.5.gz", + "/usr/share/man/fr/man5/shadow.5.gz", + "/usr/share/man/fr/man5/subgid.5.gz", + "/usr/share/man/fr/man5/subuid.5.gz", + "/usr/share/man/fr/man8/chgpasswd.8.gz", + "/usr/share/man/fr/man8/chpasswd.8.gz", + "/usr/share/man/fr/man8/groupadd.8.gz", + "/usr/share/man/fr/man8/groupdel.8.gz", + "/usr/share/man/fr/man8/groupmod.8.gz", + "/usr/share/man/fr/man8/grpck.8.gz", + "/usr/share/man/fr/man8/newusers.8.gz", + "/usr/share/man/fr/man8/pwck.8.gz", + "/usr/share/man/fr/man8/pwconv.8.gz", + "/usr/share/man/fr/man8/useradd.8.gz", + "/usr/share/man/fr/man8/userdel.8.gz", + "/usr/share/man/fr/man8/usermod.8.gz", + "/usr/share/man/fr/man8/vipw.8.gz", + "/usr/share/man/hu/man1/chsh.1.gz", + "/usr/share/man/hu/man1/gpasswd.1.gz", + "/usr/share/man/hu/man1/passwd.1.gz", + "/usr/share/man/hu/man5/passwd.5.gz", + "/usr/share/man/id/man1/chsh.1.gz", + "/usr/share/man/id/man8/useradd.8.gz", + "/usr/share/man/it/man1/chage.1.gz", + "/usr/share/man/it/man1/chfn.1.gz", + "/usr/share/man/it/man1/chsh.1.gz", + "/usr/share/man/it/man1/expiry.1.gz", + "/usr/share/man/it/man1/gpasswd.1.gz", + "/usr/share/man/it/man1/passwd.1.gz", + "/usr/share/man/it/man5/gshadow.5.gz", + "/usr/share/man/it/man5/passwd.5.gz", + "/usr/share/man/it/man5/shadow.5.gz", + "/usr/share/man/it/man8/chgpasswd.8.gz", + "/usr/share/man/it/man8/chpasswd.8.gz", + "/usr/share/man/it/man8/groupadd.8.gz", + "/usr/share/man/it/man8/groupdel.8.gz", + "/usr/share/man/it/man8/groupmod.8.gz", + "/usr/share/man/it/man8/grpck.8.gz", + "/usr/share/man/it/man8/newusers.8.gz", + "/usr/share/man/it/man8/pwck.8.gz", + "/usr/share/man/it/man8/pwconv.8.gz", + "/usr/share/man/it/man8/useradd.8.gz", + "/usr/share/man/it/man8/userdel.8.gz", + "/usr/share/man/it/man8/usermod.8.gz", + "/usr/share/man/it/man8/vipw.8.gz", + "/usr/share/man/ja/man1/chage.1.gz", + "/usr/share/man/ja/man1/chfn.1.gz", + "/usr/share/man/ja/man1/chsh.1.gz", + "/usr/share/man/ja/man1/expiry.1.gz", + "/usr/share/man/ja/man1/gpasswd.1.gz", + "/usr/share/man/ja/man1/passwd.1.gz", + "/usr/share/man/ja/man5/passwd.5.gz", + "/usr/share/man/ja/man5/shadow.5.gz", + "/usr/share/man/ja/man8/chpasswd.8.gz", + "/usr/share/man/ja/man8/groupadd.8.gz", + "/usr/share/man/ja/man8/groupdel.8.gz", + "/usr/share/man/ja/man8/groupmod.8.gz", + "/usr/share/man/ja/man8/grpck.8.gz", + "/usr/share/man/ja/man8/newusers.8.gz", + "/usr/share/man/ja/man8/pwck.8.gz", + "/usr/share/man/ja/man8/pwconv.8.gz", + "/usr/share/man/ja/man8/useradd.8.gz", + "/usr/share/man/ja/man8/userdel.8.gz", + "/usr/share/man/ja/man8/usermod.8.gz", + "/usr/share/man/ja/man8/vipw.8.gz", + "/usr/share/man/ko/man1/chfn.1.gz", + "/usr/share/man/ko/man1/chsh.1.gz", + "/usr/share/man/ko/man5/passwd.5.gz", + "/usr/share/man/ko/man8/vipw.8.gz", + "/usr/share/man/man1/chage.1.gz", + "/usr/share/man/man1/chfn.1.gz", + "/usr/share/man/man1/chsh.1.gz", + "/usr/share/man/man1/expiry.1.gz", + "/usr/share/man/man1/gpasswd.1.gz", + "/usr/share/man/man1/passwd.1.gz", + "/usr/share/man/man5/gshadow.5.gz", + "/usr/share/man/man5/passwd.5.gz", + "/usr/share/man/man5/shadow.5.gz", + "/usr/share/man/man5/subgid.5.gz", + "/usr/share/man/man5/subuid.5.gz", + "/usr/share/man/man8/chgpasswd.8.gz", + "/usr/share/man/man8/chpasswd.8.gz", + "/usr/share/man/man8/groupadd.8.gz", + "/usr/share/man/man8/groupdel.8.gz", + "/usr/share/man/man8/groupmod.8.gz", + "/usr/share/man/man8/grpck.8.gz", + "/usr/share/man/man8/newusers.8.gz", + "/usr/share/man/man8/pwck.8.gz", + "/usr/share/man/man8/pwconv.8.gz", + "/usr/share/man/man8/shadowconfig.8.gz", + "/usr/share/man/man8/useradd.8.gz", + "/usr/share/man/man8/userdel.8.gz", + "/usr/share/man/man8/usermod.8.gz", + "/usr/share/man/man8/vipw.8.gz", + "/usr/share/man/pl/man1/chage.1.gz", + "/usr/share/man/pl/man1/chsh.1.gz", + "/usr/share/man/pl/man1/expiry.1.gz", + "/usr/share/man/pl/man8/groupadd.8.gz", + "/usr/share/man/pl/man8/groupdel.8.gz", + "/usr/share/man/pl/man8/groupmod.8.gz", + "/usr/share/man/pl/man8/grpck.8.gz", + "/usr/share/man/pl/man8/userdel.8.gz", + "/usr/share/man/pl/man8/usermod.8.gz", + "/usr/share/man/pl/man8/vipw.8.gz", + "/usr/share/man/pt_BR/man1/gpasswd.1.gz", + "/usr/share/man/pt_BR/man5/passwd.5.gz", + "/usr/share/man/pt_BR/man5/shadow.5.gz", + "/usr/share/man/pt_BR/man8/groupadd.8.gz", + "/usr/share/man/pt_BR/man8/groupdel.8.gz", + "/usr/share/man/pt_BR/man8/groupmod.8.gz", + "/usr/share/man/ru/man1/chage.1.gz", + "/usr/share/man/ru/man1/chfn.1.gz", + "/usr/share/man/ru/man1/chsh.1.gz", + "/usr/share/man/ru/man1/expiry.1.gz", + "/usr/share/man/ru/man1/gpasswd.1.gz", + "/usr/share/man/ru/man1/passwd.1.gz", + "/usr/share/man/ru/man5/gshadow.5.gz", + "/usr/share/man/ru/man5/passwd.5.gz", + "/usr/share/man/ru/man5/shadow.5.gz", + "/usr/share/man/ru/man8/chgpasswd.8.gz", + "/usr/share/man/ru/man8/chpasswd.8.gz", + "/usr/share/man/ru/man8/groupadd.8.gz", + "/usr/share/man/ru/man8/groupdel.8.gz", + "/usr/share/man/ru/man8/groupmod.8.gz", + "/usr/share/man/ru/man8/grpck.8.gz", + "/usr/share/man/ru/man8/newusers.8.gz", + "/usr/share/man/ru/man8/pwck.8.gz", + "/usr/share/man/ru/man8/pwconv.8.gz", + "/usr/share/man/ru/man8/useradd.8.gz", + "/usr/share/man/ru/man8/userdel.8.gz", + "/usr/share/man/ru/man8/usermod.8.gz", + "/usr/share/man/ru/man8/vipw.8.gz", + "/usr/share/man/sv/man1/chage.1.gz", + "/usr/share/man/sv/man1/chsh.1.gz", + "/usr/share/man/sv/man1/expiry.1.gz", + "/usr/share/man/sv/man1/passwd.1.gz", + "/usr/share/man/sv/man5/gshadow.5.gz", + "/usr/share/man/sv/man5/passwd.5.gz", + "/usr/share/man/sv/man8/groupadd.8.gz", + "/usr/share/man/sv/man8/groupdel.8.gz", + "/usr/share/man/sv/man8/groupmod.8.gz", + "/usr/share/man/sv/man8/grpck.8.gz", + "/usr/share/man/sv/man8/pwck.8.gz", + "/usr/share/man/sv/man8/userdel.8.gz", + "/usr/share/man/sv/man8/vipw.8.gz", + "/usr/share/man/tr/man1/chage.1.gz", + "/usr/share/man/tr/man1/chfn.1.gz", + "/usr/share/man/tr/man1/passwd.1.gz", + "/usr/share/man/tr/man5/passwd.5.gz", + "/usr/share/man/tr/man5/shadow.5.gz", + "/usr/share/man/tr/man8/groupadd.8.gz", + "/usr/share/man/tr/man8/groupdel.8.gz", + "/usr/share/man/tr/man8/groupmod.8.gz", + "/usr/share/man/tr/man8/useradd.8.gz", + "/usr/share/man/tr/man8/userdel.8.gz", + "/usr/share/man/tr/man8/usermod.8.gz", + "/usr/share/man/uk/man1/chage.1.gz", + "/usr/share/man/uk/man1/chfn.1.gz", + "/usr/share/man/uk/man1/chsh.1.gz", + "/usr/share/man/uk/man1/expiry.1.gz", + "/usr/share/man/uk/man1/gpasswd.1.gz", + "/usr/share/man/uk/man1/passwd.1.gz", + "/usr/share/man/uk/man5/gshadow.5.gz", + "/usr/share/man/uk/man5/passwd.5.gz", + "/usr/share/man/uk/man5/shadow.5.gz", + "/usr/share/man/uk/man8/chgpasswd.8.gz", + "/usr/share/man/uk/man8/chpasswd.8.gz", + "/usr/share/man/uk/man8/groupadd.8.gz", + "/usr/share/man/uk/man8/groupdel.8.gz", + "/usr/share/man/uk/man8/groupmod.8.gz", + "/usr/share/man/uk/man8/grpck.8.gz", + "/usr/share/man/uk/man8/newusers.8.gz", + "/usr/share/man/uk/man8/pwck.8.gz", + "/usr/share/man/uk/man8/pwconv.8.gz", + "/usr/share/man/uk/man8/useradd.8.gz", + "/usr/share/man/uk/man8/userdel.8.gz", + "/usr/share/man/uk/man8/usermod.8.gz", + "/usr/share/man/uk/man8/vipw.8.gz", + "/usr/share/man/zh_CN/man1/chage.1.gz", + "/usr/share/man/zh_CN/man1/chfn.1.gz", + "/usr/share/man/zh_CN/man1/chsh.1.gz", + "/usr/share/man/zh_CN/man1/expiry.1.gz", + "/usr/share/man/zh_CN/man1/gpasswd.1.gz", + "/usr/share/man/zh_CN/man1/passwd.1.gz", + "/usr/share/man/zh_CN/man5/gshadow.5.gz", + "/usr/share/man/zh_CN/man5/passwd.5.gz", + "/usr/share/man/zh_CN/man5/shadow.5.gz", + "/usr/share/man/zh_CN/man8/chgpasswd.8.gz", + "/usr/share/man/zh_CN/man8/chpasswd.8.gz", + "/usr/share/man/zh_CN/man8/groupadd.8.gz", + "/usr/share/man/zh_CN/man8/groupdel.8.gz", + "/usr/share/man/zh_CN/man8/groupmod.8.gz", + "/usr/share/man/zh_CN/man8/grpck.8.gz", + "/usr/share/man/zh_CN/man8/newusers.8.gz", + "/usr/share/man/zh_CN/man8/pwck.8.gz", + "/usr/share/man/zh_CN/man8/pwconv.8.gz", + "/usr/share/man/zh_CN/man8/useradd.8.gz", + "/usr/share/man/zh_CN/man8/userdel.8.gz", + "/usr/share/man/zh_CN/man8/usermod.8.gz", + "/usr/share/man/zh_CN/man8/vipw.8.gz", + "/usr/share/man/zh_TW/man1/chfn.1.gz", + "/usr/share/man/zh_TW/man1/chsh.1.gz", + "/usr/share/man/zh_TW/man5/passwd.5.gz", + "/usr/share/man/zh_TW/man8/chpasswd.8.gz", + "/usr/share/man/zh_TW/man8/groupadd.8.gz", + "/usr/share/man/zh_TW/man8/groupdel.8.gz", + "/usr/share/man/zh_TW/man8/groupmod.8.gz", + "/usr/share/man/zh_TW/man8/useradd.8.gz", + "/usr/share/man/zh_TW/man8/userdel.8.gz", + "/usr/share/man/zh_TW/man8/usermod.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "perl-base@5.40.1-6+deb13u1", + "Name": "perl-base", + "Identifier": { + "PURL": "pkg:deb/debian/perl-base@5.40.1-6%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "aa65e528dbb05e9e" + }, + "Version": "5.40.1", + "Release": "6+deb13u1", + "Arch": "amd64", + "SrcName": "perl", + "SrcVersion": "5.40.1", + "SrcRelease": "6+deb13u1", + "Licenses": [ + "GPL-1.0-or-later", + "Artistic-2.0", + "MIT", + "REGCOMP", + "GPL-2.0-with-bison-exception+", + "Unicode", + "BZIP", + "Zlib", + "GPL-2.0-or-later", + "FSFAP", + "BSD-3-clause-with-weird-numbering", + "CC0-1.0", + "TEXT-TABS", + "BSD-4-clause-POWERDOG", + "BSD-3-clause-GENERIC", + "BSD-3-Clause", + "SDBM-PUBLIC-DOMAIN", + "DONT-CHANGE-THE-GPL", + "Artistic-dist", + "LGPL-2.1-only", + "GPL-1.0-only", + "GPL-2.0-only", + "Artistic-2" + ], + "Maintainer": "Niko Tyni \u003cntyni@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "InstalledFiles": [ + "/usr/bin/perl", + "/usr/bin/perl5.40.1", + "/usr/lib/x86_64-linux-gnu/perl-base/AutoLoader.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Carp.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Carp/Heavy.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Config.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Config_git.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/Config_heavy.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/Cwd.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/DynaLoader.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Errno.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Exporter.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Exporter/Heavy.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Fcntl.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/File/Basename.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/File/Glob.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/File/Path.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/File/Spec.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/File/Spec/Unix.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/File/Temp.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/FileHandle.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Getopt/Long.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Getopt/Long/Parser.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Hash/Util.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/File.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Handle.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Pipe.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Seekable.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Select.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Socket.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Socket/INET.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Socket/IP.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Socket/UNIX.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IPC/Open2.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IPC/Open3.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/List/Util.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/POSIX.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Scalar/Util.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/SelectSaver.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Socket.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Symbol.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Text/ParseWords.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Text/Tabs.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Text/Wrap.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Tie/Hash.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/XSLoader.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/attributes.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/Cwd/Cwd.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/Fcntl/Fcntl.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/File/Glob/Glob.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/Hash/Util/Util.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/IO/IO.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/List/Util/Util.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/POSIX/POSIX.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/Socket/Socket.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/attributes/attributes.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/re/re.so", + "/usr/lib/x86_64-linux-gnu/perl-base/base.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/builtin.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/bytes.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/constant.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/feature.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/fields.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/integer.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/lib.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/locale.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/overload.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/overloading.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/parent.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/re.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/strict.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Age.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Bc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Bmg.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Bpb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Bpt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Cf.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Ea.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/EqUIdeo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/GCB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Gc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Hst.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Identif2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Identifi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/InPC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/InSC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Isc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Jg.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Jt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Lb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Lc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/NFCQC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/NFDQC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/NFKCCF.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/NFKCQC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/NFKDQC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Na1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/NameAlia.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Nt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Nv.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/PerlDeci.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/SB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Sc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Scx.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Tc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Uc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Vo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/WB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/_PerlLB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/_PerlSCX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/NA.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V100.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V11.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V110.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V120.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V130.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V140.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V150.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V20.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V30.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V31.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V32.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V40.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V41.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V50.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V51.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V52.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V60.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V61.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V70.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V80.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V90.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Alpha/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/AL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/AN.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/B.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/BN.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/CS.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/EN.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/ES.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/ET.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/L.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/NSM.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/ON.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/R.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/WS.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/BidiC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/BidiM/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Blk/NB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bpt/C.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bpt/N.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bpt/O.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CE/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CI/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CWCF/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CWCM/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CWKCF/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CWL/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CWT/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CWU/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Cased/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/A.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/AL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/AR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/ATAR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/B.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/BR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/DB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/NK.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/NR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/OV.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/VR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CompEx/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/DI/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dash/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dep/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dia/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Com.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Enc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Fin.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Font.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Init.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Iso.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Med.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Nar.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Nb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/NonCanon.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Sqr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Sub.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Sup.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Vert.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/EBase/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/EComp/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/EPres/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ea/A.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ea/H.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ea/N.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ea/Na.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ea/W.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Emoji/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ext/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/ExtPict/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/CN.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/EX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/LV.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/LVT.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/PP.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/SM.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/XX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/C.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Cf.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Cn.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/L.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/LC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Ll.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Lm.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Lo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Lu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/M.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Mc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Me.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Mn.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/N.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Nd.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Nl.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/No.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/P.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Pc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Pd.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Pe.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Pf.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Pi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Po.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Ps.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/S.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Sc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Sk.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Sm.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/So.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Z.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Zs.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GrBase/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GrExt/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Hex/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Hst/NA.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Hyphen/T.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IDC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IDS/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdStatus/Allowed.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdStatus/Restrict.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/DefaultI.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/Exclusio.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/Inclusio.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/LimitedU.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/NotChara.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/NotNFKC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/NotXID.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/Obsolete.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/Recommen.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/Technica.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/Uncommon.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ideo/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/10_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/11_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/12_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/12_1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/13_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/14_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/15_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/2_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/2_1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/3_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/3_1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/3_2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/4_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/4_1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/5_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/5_1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/5_2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/6_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/6_1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/6_2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/6_3.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/7_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/8_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/9_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/Bottom.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/BottomAn.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/Left.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/LeftAndR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/NA.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/Overstru.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/Right.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/Top.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/TopAndBo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/TopAndL2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/TopAndLe.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/TopAndRi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/VisualOr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Avagraha.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Bindu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Cantilla.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona3.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona4.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona5.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona6.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona7.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona8.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona9.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consonan.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Geminati.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Invisibl.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Nukta.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Number.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Other.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/PureKill.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Syllable.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/ToneMark.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Virama.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Visarga.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Vowel.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/VowelDep.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/VowelInd.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Ain.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Alef.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Beh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Dal.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/FarsiYeh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Feh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Gaf.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Hah.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/HanifiRo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Kaf.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Lam.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/NoJoinin.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Noon.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Qaf.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Reh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Sad.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Seen.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Tah.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Waw.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Yeh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jt/C.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jt/D.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jt/L.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jt/R.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jt/T.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jt/U.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/AI.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/AL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/BA.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/BB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/CJ.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/CL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/CM.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/EX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/GL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/ID.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/IN.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/IS.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/NS.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/NU.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/OP.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/PO.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/PR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/QU.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/SA.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/XX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lower/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Math/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFCQC/M.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFCQC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFDQC/N.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFDQC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFKCQC/N.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFKCQC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFKDQC/N.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFKDQC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nt/Di.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nt/None.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nt/Nu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/10.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/100.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/10000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/100000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/11.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/12.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/13.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/14.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/15.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/16.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/17.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/18.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/19.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1_16.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1_2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1_3.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1_4.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1_6.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1_8.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/20.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/200.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/2000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/20000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/2_3.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/3.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/30.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/300.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/3000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/30000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/3_16.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/3_4.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/4.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/40.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/400.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/4000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/40000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/5.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/50.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/500.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/5000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/50000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/6.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/60.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/600.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/6000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/60000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/7.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/70.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/700.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/7000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/70000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/8.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/80.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/800.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/8000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/80000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/9.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/90.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/900.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/9000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/90000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/PCM/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/PatSyn/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Alnum.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Assigned.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Blank.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Graph.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/PerlWord.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/PosixPun.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Print.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/SpacePer.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Title.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Word.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/XPosixPu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlAny.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlCh2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlCha.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlFol.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlIDC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlIDS.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlIsI.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlNch.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlPat.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlPr2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlPro.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlQuo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/QMark/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/AT.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/CL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/EX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/FO.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/LE.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/LO.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/NU.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/SC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/ST.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/Sp.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/UP.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/XX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SD/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/STerm/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Arab.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Beng.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Cprt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Cyrl.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Deva.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Dupl.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Geor.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Glag.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Gong.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Gonm.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Gran.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Grek.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Gujr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Guru.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Han.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Hang.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Hira.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Kana.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Knda.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Latn.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Limb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Linb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Mlym.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Mong.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Mult.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Orya.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Sinh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Syrc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Taml.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Telu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Zinh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Zyyy.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Adlm.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Arab.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Armn.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Beng.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Bhks.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Bopo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Cakm.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Cham.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Copt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Cprt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Cyrl.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Deva.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Diak.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Dupl.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Ethi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Geor.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Glag.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Gong.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Gonm.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Gran.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Grek.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Gujr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Guru.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Han.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Hang.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Hebr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Hira.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Hmng.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Hmnp.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Kana.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Khar.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Khmr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Khoj.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Knda.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Kthi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Lana.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Lao.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Latn.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Limb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Lina.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Linb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Mlym.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Mong.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Mult.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Mymr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Nand.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Nko.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Orya.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Phlp.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Rohg.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Shrd.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Sind.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Sinh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Syrc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Tagb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Takr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Talu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Taml.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Tang.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Telu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Thaa.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Tibt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Tirh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Vith.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Xsux.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Yezi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Yi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Zinh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Zyyy.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Zzzz.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Term/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/UIdeo/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Upper/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/VS/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Vo/R.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Vo/Tr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Vo/Tu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Vo/U.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/EX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/Extend.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/FO.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/HL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/KA.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/LE.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/MB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/ML.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/MN.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/NU.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/WSegSpac.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/XX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/XIDC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/XIDS/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/utf8.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/vars.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/warnings.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/warnings/register.pm", + "/usr/share/doc/perl-base/changelog.Debian.gz", + "/usr/share/doc/perl-base/changelog.gz", + "/usr/share/doc/perl-base/copyright", + "/usr/share/doc/perl/AUTHORS.gz", + "/usr/share/doc/perl/Documentation", + "/usr/share/lintian/overrides/perl-base", + "/usr/share/man/man1/perl.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "readline-common@8.2-6", + "Name": "readline-common", + "Identifier": { + "PURL": "pkg:deb/debian/readline-common@8.2-6?arch=all\u0026distro=debian-13.7", + "UID": "c4beab42d2a9a634" + }, + "Version": "8.2", + "Release": "6", + "Arch": "all", + "SrcName": "readline", + "SrcVersion": "8.2", + "SrcRelease": "6", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-3.0-only", + "GPL-2.0-or-later", + "GPL-2.0-only", + "GFDL-1.3-no-invariants-or-later", + "GFDL-1.3-or-later", + "ISC-no-attribution" + ], + "Maintainer": "Matthias Klose \u003cdoko@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "InstalledFiles": [ + "/usr/share/doc/readline-common/changelog.Debian.gz", + "/usr/share/doc/readline-common/changelog.gz", + "/usr/share/doc/readline-common/copyright", + "/usr/share/doc/readline-common/inputrc.arrows", + "/usr/share/info/rluserman.info.gz", + "/usr/share/lintian/overrides/readline-common", + "/usr/share/man/man3/history.3readline.gz", + "/usr/share/man/man3/readline.3readline.gz", + "/usr/share/readline/inputrc" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "sed@4.9-2+deb13u1", + "Name": "sed", + "Identifier": { + "PURL": "pkg:deb/debian/sed@4.9-2%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "a041ea16982bb927" + }, + "Version": "4.9", + "Release": "2+deb13u1", + "Arch": "amd64", + "SrcName": "sed", + "SrcVersion": "4.9", + "SrcRelease": "2+deb13u1", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-3.0-only", + "X11", + "GFDL-1.3-no-invariants-or-later", + "GFDL-1.3-only", + "ISC", + "BSD-4-Clause-UC", + "BSL-1", + "pcre" + ], + "Maintainer": "Clint Adams \u003cclint@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/sed", + "/usr/share/doc/sed/AUTHORS", + "/usr/share/doc/sed/BUGS.gz", + "/usr/share/doc/sed/NEWS.gz", + "/usr/share/doc/sed/README", + "/usr/share/doc/sed/THANKS.gz", + "/usr/share/doc/sed/changelog.Debian.gz", + "/usr/share/doc/sed/changelog.gz", + "/usr/share/doc/sed/copyright", + "/usr/share/doc/sed/examples/dc.sed", + "/usr/share/doc/sed/sedfaq.txt.gz", + "/usr/share/info/sed.info.gz", + "/usr/share/locale/af/LC_MESSAGES/sed.mo", + "/usr/share/locale/ast/LC_MESSAGES/sed.mo", + "/usr/share/locale/bg/LC_MESSAGES/sed.mo", + "/usr/share/locale/ca/LC_MESSAGES/sed.mo", + "/usr/share/locale/cs/LC_MESSAGES/sed.mo", + "/usr/share/locale/da/LC_MESSAGES/sed.mo", + "/usr/share/locale/de/LC_MESSAGES/sed.mo", + "/usr/share/locale/el/LC_MESSAGES/sed.mo", + "/usr/share/locale/eo/LC_MESSAGES/sed.mo", + "/usr/share/locale/es/LC_MESSAGES/sed.mo", + "/usr/share/locale/et/LC_MESSAGES/sed.mo", + "/usr/share/locale/eu/LC_MESSAGES/sed.mo", + "/usr/share/locale/fi/LC_MESSAGES/sed.mo", + "/usr/share/locale/fr/LC_MESSAGES/sed.mo", + "/usr/share/locale/ga/LC_MESSAGES/sed.mo", + "/usr/share/locale/gl/LC_MESSAGES/sed.mo", + "/usr/share/locale/he/LC_MESSAGES/sed.mo", + "/usr/share/locale/hr/LC_MESSAGES/sed.mo", + "/usr/share/locale/hu/LC_MESSAGES/sed.mo", + "/usr/share/locale/id/LC_MESSAGES/sed.mo", + "/usr/share/locale/it/LC_MESSAGES/sed.mo", + "/usr/share/locale/ja/LC_MESSAGES/sed.mo", + "/usr/share/locale/ka/LC_MESSAGES/sed.mo", + "/usr/share/locale/ko/LC_MESSAGES/sed.mo", + "/usr/share/locale/nb/LC_MESSAGES/sed.mo", + "/usr/share/locale/nl/LC_MESSAGES/sed.mo", + "/usr/share/locale/pl/LC_MESSAGES/sed.mo", + "/usr/share/locale/pt/LC_MESSAGES/sed.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/sed.mo", + "/usr/share/locale/ro/LC_MESSAGES/sed.mo", + "/usr/share/locale/ru/LC_MESSAGES/sed.mo", + "/usr/share/locale/sk/LC_MESSAGES/sed.mo", + "/usr/share/locale/sl/LC_MESSAGES/sed.mo", + "/usr/share/locale/sr/LC_MESSAGES/sed.mo", + "/usr/share/locale/sv/LC_MESSAGES/sed.mo", + "/usr/share/locale/tr/LC_MESSAGES/sed.mo", + "/usr/share/locale/uk/LC_MESSAGES/sed.mo", + "/usr/share/locale/vi/LC_MESSAGES/sed.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/sed.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/sed.mo", + "/usr/share/man/man1/sed.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "sqv@1.3.0-3+b2", + "Name": "sqv", + "Identifier": { + "PURL": "pkg:deb/debian/sqv@1.3.0-3%2Bb2?arch=amd64\u0026distro=debian-13.7", + "UID": "71acebf687a567ad" + }, + "Version": "1.3.0", + "Release": "3+b2", + "Arch": "amd64", + "SrcName": "rust-sequoia-sqv", + "SrcVersion": "1.3.0", + "SrcRelease": "3", + "Licenses": [ + "LGPL-2.0-or-later", + "LGPL-2.0-only" + ], + "Maintainer": "Debian Rust Maintainers \u003cpkg-rust-maintainers@alioth-lists.debian.net\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4", + "libgcc-s1@14.2.0-19", + "libgmp10@2:6.3.0+dfsg-3", + "libhogweed6t64@3.10.1-1", + "libnettle8t64@3.10.1-1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/sqv", + "/usr/share/bash-completion/completions/sqv.bash", + "/usr/share/doc/sqv/NEWS.gz", + "/usr/share/doc/sqv/changelog.Debian.amd64.gz", + "/usr/share/doc/sqv/changelog.Debian.gz", + "/usr/share/doc/sqv/copyright", + "/usr/share/fish/completions/sqv.fish", + "/usr/share/man/man1/sqv.1.gz", + "/usr/share/zsh/vendor-completions/_sqv" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "sysvinit-utils@3.14-4", + "Name": "sysvinit-utils", + "Identifier": { + "PURL": "pkg:deb/debian/sysvinit-utils@3.14-4?arch=amd64\u0026distro=debian-13.7", + "UID": "19ecbcb3d5bf6b26" + }, + "Version": "3.14", + "Release": "4", + "Arch": "amd64", + "SrcName": "sysvinit", + "SrcVersion": "3.14", + "SrcRelease": "4", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-2.1-or-later", + "GPL-3.0-only", + "GPL-2.0-only", + "LGPL-2.1-only" + ], + "Maintainer": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/init/init-d-script", + "/usr/lib/init/vars.sh", + "/usr/lib/lsb/init-functions", + "/usr/lib/lsb/init-functions.d/00-verbose", + "/usr/sbin/fstab-decode", + "/usr/sbin/killall5", + "/usr/share/doc/sysvinit-utils/changelog.Debian.gz", + "/usr/share/doc/sysvinit-utils/copyright", + "/usr/share/man/man5/init-d-script.5.gz", + "/usr/share/man/man8/fstab-decode.8.gz", + "/usr/share/man/man8/killall5.8.gz", + "/usr/share/man/man8/pidof.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "tar@1.35+dfsg-3.1", + "Name": "tar", + "Identifier": { + "PURL": "pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64\u0026distro=debian-13.7", + "UID": "4f69996c49afbaca" + }, + "Version": "1.35+dfsg", + "Release": "3.1", + "Arch": "amd64", + "SrcName": "tar", + "SrcVersion": "1.35+dfsg", + "SrcRelease": "3.1", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-3.0-only", + "GPL-3+ with Bison exception", + "LGPL-2.1-or-later", + "LGPL-2.1-only", + "LGPL-3.0-or-later", + "LGPL-3.0-only", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Janos Lenart \u003cocsi@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/tar", + "/usr/lib/mime/packages/tar", + "/usr/sbin/rmt-tar", + "/usr/sbin/tarcat", + "/usr/share/doc/tar/AUTHORS", + "/usr/share/doc/tar/NEWS.gz", + "/usr/share/doc/tar/README.Debian", + "/usr/share/doc/tar/THANKS.gz", + "/usr/share/doc/tar/changelog.1.gz", + "/usr/share/doc/tar/changelog.Debian.gz", + "/usr/share/doc/tar/changelog.gz", + "/usr/share/doc/tar/copyright", + "/usr/share/locale/bg/LC_MESSAGES/tar.mo", + "/usr/share/locale/ca/LC_MESSAGES/tar.mo", + "/usr/share/locale/cs/LC_MESSAGES/tar.mo", + "/usr/share/locale/da/LC_MESSAGES/tar.mo", + "/usr/share/locale/de/LC_MESSAGES/tar.mo", + "/usr/share/locale/el/LC_MESSAGES/tar.mo", + "/usr/share/locale/eo/LC_MESSAGES/tar.mo", + "/usr/share/locale/es/LC_MESSAGES/tar.mo", + "/usr/share/locale/et/LC_MESSAGES/tar.mo", + "/usr/share/locale/eu/LC_MESSAGES/tar.mo", + "/usr/share/locale/fi/LC_MESSAGES/tar.mo", + "/usr/share/locale/fr/LC_MESSAGES/tar.mo", + "/usr/share/locale/ga/LC_MESSAGES/tar.mo", + "/usr/share/locale/gl/LC_MESSAGES/tar.mo", + "/usr/share/locale/hr/LC_MESSAGES/tar.mo", + "/usr/share/locale/hu/LC_MESSAGES/tar.mo", + "/usr/share/locale/id/LC_MESSAGES/tar.mo", + "/usr/share/locale/it/LC_MESSAGES/tar.mo", + "/usr/share/locale/ja/LC_MESSAGES/tar.mo", + "/usr/share/locale/ka/LC_MESSAGES/tar.mo", + "/usr/share/locale/ko/LC_MESSAGES/tar.mo", + "/usr/share/locale/ky/LC_MESSAGES/tar.mo", + "/usr/share/locale/ms/LC_MESSAGES/tar.mo", + "/usr/share/locale/nb/LC_MESSAGES/tar.mo", + "/usr/share/locale/nl/LC_MESSAGES/tar.mo", + "/usr/share/locale/pl/LC_MESSAGES/tar.mo", + "/usr/share/locale/pt/LC_MESSAGES/tar.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/tar.mo", + "/usr/share/locale/ro/LC_MESSAGES/tar.mo", + "/usr/share/locale/ru/LC_MESSAGES/tar.mo", + "/usr/share/locale/sk/LC_MESSAGES/tar.mo", + "/usr/share/locale/sl/LC_MESSAGES/tar.mo", + "/usr/share/locale/sr/LC_MESSAGES/tar.mo", + "/usr/share/locale/sv/LC_MESSAGES/tar.mo", + "/usr/share/locale/tr/LC_MESSAGES/tar.mo", + "/usr/share/locale/uk/LC_MESSAGES/tar.mo", + "/usr/share/locale/vi/LC_MESSAGES/tar.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/tar.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/tar.mo", + "/usr/share/man/man1/tar.1.gz", + "/usr/share/man/man1/tarcat.1.gz", + "/usr/share/man/man8/rmt-tar.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "tzdata@2026c-0+deb13u1", + "Name": "tzdata", + "Identifier": { + "PURL": "pkg:deb/debian/tzdata@2026c-0%2Bdeb13u1?arch=all\u0026distro=debian-13.7", + "UID": "aa0b87a2a5fdbc54" + }, + "Version": "2026c", + "Release": "0+deb13u1", + "Arch": "all", + "SrcName": "tzdata", + "SrcVersion": "2026c", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "public-domain" + ], + "Maintainer": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "debconf@1.5.91" + ], + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "InstalledFiles": [ + "/usr/share/doc/tzdata/NEWS.Debian.gz", + "/usr/share/doc/tzdata/README.Debian", + "/usr/share/doc/tzdata/changelog.Debian.gz", + "/usr/share/doc/tzdata/changelog.gz", + "/usr/share/doc/tzdata/copyright", + "/usr/share/lintian/overrides/tzdata", + "/usr/share/zoneinfo/Africa/Abidjan", + "/usr/share/zoneinfo/Africa/Accra", + "/usr/share/zoneinfo/Africa/Addis_Ababa", + "/usr/share/zoneinfo/Africa/Algiers", + "/usr/share/zoneinfo/Africa/Asmara", + "/usr/share/zoneinfo/Africa/Bamako", + "/usr/share/zoneinfo/Africa/Bangui", + "/usr/share/zoneinfo/Africa/Banjul", + "/usr/share/zoneinfo/Africa/Bissau", + "/usr/share/zoneinfo/Africa/Blantyre", + "/usr/share/zoneinfo/Africa/Brazzaville", + "/usr/share/zoneinfo/Africa/Bujumbura", + "/usr/share/zoneinfo/Africa/Cairo", + "/usr/share/zoneinfo/Africa/Casablanca", + "/usr/share/zoneinfo/Africa/Ceuta", + "/usr/share/zoneinfo/Africa/Conakry", + "/usr/share/zoneinfo/Africa/Dakar", + "/usr/share/zoneinfo/Africa/Dar_es_Salaam", + "/usr/share/zoneinfo/Africa/Djibouti", + "/usr/share/zoneinfo/Africa/Douala", + "/usr/share/zoneinfo/Africa/El_Aaiun", + "/usr/share/zoneinfo/Africa/Freetown", + "/usr/share/zoneinfo/Africa/Gaborone", + "/usr/share/zoneinfo/Africa/Harare", + "/usr/share/zoneinfo/Africa/Johannesburg", + "/usr/share/zoneinfo/Africa/Juba", + "/usr/share/zoneinfo/Africa/Kampala", + "/usr/share/zoneinfo/Africa/Khartoum", + "/usr/share/zoneinfo/Africa/Kigali", + "/usr/share/zoneinfo/Africa/Kinshasa", + "/usr/share/zoneinfo/Africa/Lagos", + "/usr/share/zoneinfo/Africa/Libreville", + "/usr/share/zoneinfo/Africa/Lome", + "/usr/share/zoneinfo/Africa/Luanda", + "/usr/share/zoneinfo/Africa/Lubumbashi", + "/usr/share/zoneinfo/Africa/Lusaka", + "/usr/share/zoneinfo/Africa/Malabo", + "/usr/share/zoneinfo/Africa/Maputo", + "/usr/share/zoneinfo/Africa/Maseru", + "/usr/share/zoneinfo/Africa/Mbabane", + "/usr/share/zoneinfo/Africa/Mogadishu", + "/usr/share/zoneinfo/Africa/Monrovia", + "/usr/share/zoneinfo/Africa/Nairobi", + "/usr/share/zoneinfo/Africa/Ndjamena", + "/usr/share/zoneinfo/Africa/Niamey", + "/usr/share/zoneinfo/Africa/Nouakchott", + "/usr/share/zoneinfo/Africa/Ouagadougou", + "/usr/share/zoneinfo/Africa/Porto-Novo", + "/usr/share/zoneinfo/Africa/Sao_Tome", + "/usr/share/zoneinfo/Africa/Tripoli", + "/usr/share/zoneinfo/Africa/Tunis", + "/usr/share/zoneinfo/Africa/Windhoek", + "/usr/share/zoneinfo/America/Adak", + "/usr/share/zoneinfo/America/Anchorage", + "/usr/share/zoneinfo/America/Anguilla", + "/usr/share/zoneinfo/America/Antigua", + "/usr/share/zoneinfo/America/Araguaina", + "/usr/share/zoneinfo/America/Argentina/Buenos_Aires", + "/usr/share/zoneinfo/America/Argentina/Catamarca", + "/usr/share/zoneinfo/America/Argentina/Cordoba", + "/usr/share/zoneinfo/America/Argentina/Jujuy", + "/usr/share/zoneinfo/America/Argentina/La_Rioja", + "/usr/share/zoneinfo/America/Argentina/Mendoza", + "/usr/share/zoneinfo/America/Argentina/Rio_Gallegos", + "/usr/share/zoneinfo/America/Argentina/Salta", + "/usr/share/zoneinfo/America/Argentina/San_Juan", + "/usr/share/zoneinfo/America/Argentina/San_Luis", + "/usr/share/zoneinfo/America/Argentina/Tucuman", + "/usr/share/zoneinfo/America/Argentina/Ushuaia", + "/usr/share/zoneinfo/America/Aruba", + "/usr/share/zoneinfo/America/Asuncion", + "/usr/share/zoneinfo/America/Atikokan", + "/usr/share/zoneinfo/America/Bahia", + "/usr/share/zoneinfo/America/Bahia_Banderas", + "/usr/share/zoneinfo/America/Barbados", + "/usr/share/zoneinfo/America/Belem", + "/usr/share/zoneinfo/America/Belize", + "/usr/share/zoneinfo/America/Blanc-Sablon", + "/usr/share/zoneinfo/America/Boa_Vista", + "/usr/share/zoneinfo/America/Bogota", + "/usr/share/zoneinfo/America/Boise", + "/usr/share/zoneinfo/America/Cambridge_Bay", + "/usr/share/zoneinfo/America/Campo_Grande", + "/usr/share/zoneinfo/America/Cancun", + "/usr/share/zoneinfo/America/Caracas", + "/usr/share/zoneinfo/America/Cayenne", + "/usr/share/zoneinfo/America/Cayman", + "/usr/share/zoneinfo/America/Chicago", + "/usr/share/zoneinfo/America/Chihuahua", + "/usr/share/zoneinfo/America/Ciudad_Juarez", + "/usr/share/zoneinfo/America/Costa_Rica", + "/usr/share/zoneinfo/America/Coyhaique", + "/usr/share/zoneinfo/America/Creston", + "/usr/share/zoneinfo/America/Cuiaba", + "/usr/share/zoneinfo/America/Curacao", + "/usr/share/zoneinfo/America/Danmarkshavn", + "/usr/share/zoneinfo/America/Dawson", + "/usr/share/zoneinfo/America/Dawson_Creek", + "/usr/share/zoneinfo/America/Denver", + "/usr/share/zoneinfo/America/Detroit", + "/usr/share/zoneinfo/America/Dominica", + "/usr/share/zoneinfo/America/Edmonton", + "/usr/share/zoneinfo/America/Eirunepe", + "/usr/share/zoneinfo/America/El_Salvador", + "/usr/share/zoneinfo/America/Fort_Nelson", + "/usr/share/zoneinfo/America/Fortaleza", + "/usr/share/zoneinfo/America/Glace_Bay", + "/usr/share/zoneinfo/America/Goose_Bay", + "/usr/share/zoneinfo/America/Grand_Turk", + "/usr/share/zoneinfo/America/Grenada", + "/usr/share/zoneinfo/America/Guadeloupe", + "/usr/share/zoneinfo/America/Guatemala", + "/usr/share/zoneinfo/America/Guayaquil", + "/usr/share/zoneinfo/America/Guyana", + "/usr/share/zoneinfo/America/Halifax", + "/usr/share/zoneinfo/America/Havana", + "/usr/share/zoneinfo/America/Hermosillo", + "/usr/share/zoneinfo/America/Indiana/Indianapolis", + "/usr/share/zoneinfo/America/Indiana/Knox", + "/usr/share/zoneinfo/America/Indiana/Marengo", + "/usr/share/zoneinfo/America/Indiana/Petersburg", + "/usr/share/zoneinfo/America/Indiana/Tell_City", + "/usr/share/zoneinfo/America/Indiana/Vevay", + "/usr/share/zoneinfo/America/Indiana/Vincennes", + "/usr/share/zoneinfo/America/Indiana/Winamac", + "/usr/share/zoneinfo/America/Inuvik", + "/usr/share/zoneinfo/America/Iqaluit", + "/usr/share/zoneinfo/America/Jamaica", + "/usr/share/zoneinfo/America/Juneau", + "/usr/share/zoneinfo/America/Kentucky/Louisville", + "/usr/share/zoneinfo/America/Kentucky/Monticello", + "/usr/share/zoneinfo/America/La_Paz", + "/usr/share/zoneinfo/America/Lima", + "/usr/share/zoneinfo/America/Los_Angeles", + "/usr/share/zoneinfo/America/Maceio", + "/usr/share/zoneinfo/America/Managua", + "/usr/share/zoneinfo/America/Manaus", + "/usr/share/zoneinfo/America/Martinique", + "/usr/share/zoneinfo/America/Matamoros", + "/usr/share/zoneinfo/America/Mazatlan", + "/usr/share/zoneinfo/America/Menominee", + "/usr/share/zoneinfo/America/Merida", + "/usr/share/zoneinfo/America/Metlakatla", + "/usr/share/zoneinfo/America/Mexico_City", + "/usr/share/zoneinfo/America/Miquelon", + "/usr/share/zoneinfo/America/Moncton", + "/usr/share/zoneinfo/America/Monterrey", + "/usr/share/zoneinfo/America/Montevideo", + "/usr/share/zoneinfo/America/Montserrat", + "/usr/share/zoneinfo/America/Nassau", + "/usr/share/zoneinfo/America/New_York", + "/usr/share/zoneinfo/America/Nome", + "/usr/share/zoneinfo/America/Noronha", + "/usr/share/zoneinfo/America/North_Dakota/Beulah", + "/usr/share/zoneinfo/America/North_Dakota/Center", + "/usr/share/zoneinfo/America/North_Dakota/New_Salem", + "/usr/share/zoneinfo/America/Nuuk", + "/usr/share/zoneinfo/America/Ojinaga", + "/usr/share/zoneinfo/America/Panama", + "/usr/share/zoneinfo/America/Paramaribo", + "/usr/share/zoneinfo/America/Phoenix", + "/usr/share/zoneinfo/America/Port-au-Prince", + "/usr/share/zoneinfo/America/Port_of_Spain", + "/usr/share/zoneinfo/America/Porto_Velho", + "/usr/share/zoneinfo/America/Puerto_Rico", + "/usr/share/zoneinfo/America/Punta_Arenas", + "/usr/share/zoneinfo/America/Rankin_Inlet", + "/usr/share/zoneinfo/America/Recife", + "/usr/share/zoneinfo/America/Regina", + "/usr/share/zoneinfo/America/Resolute", + "/usr/share/zoneinfo/America/Rio_Branco", + "/usr/share/zoneinfo/America/Santarem", + "/usr/share/zoneinfo/America/Santiago", + "/usr/share/zoneinfo/America/Santo_Domingo", + "/usr/share/zoneinfo/America/Sao_Paulo", + "/usr/share/zoneinfo/America/Scoresbysund", + "/usr/share/zoneinfo/America/Sitka", + "/usr/share/zoneinfo/America/St_Johns", + "/usr/share/zoneinfo/America/St_Kitts", + "/usr/share/zoneinfo/America/St_Lucia", + "/usr/share/zoneinfo/America/St_Thomas", + "/usr/share/zoneinfo/America/St_Vincent", + "/usr/share/zoneinfo/America/Swift_Current", + "/usr/share/zoneinfo/America/Tegucigalpa", + "/usr/share/zoneinfo/America/Thule", + "/usr/share/zoneinfo/America/Tijuana", + "/usr/share/zoneinfo/America/Toronto", + "/usr/share/zoneinfo/America/Tortola", + "/usr/share/zoneinfo/America/Vancouver", + "/usr/share/zoneinfo/America/Whitehorse", + "/usr/share/zoneinfo/America/Winnipeg", + "/usr/share/zoneinfo/America/Yakutat", + "/usr/share/zoneinfo/Antarctica/Casey", + "/usr/share/zoneinfo/Antarctica/Davis", + "/usr/share/zoneinfo/Antarctica/DumontDUrville", + "/usr/share/zoneinfo/Antarctica/Macquarie", + "/usr/share/zoneinfo/Antarctica/Mawson", + "/usr/share/zoneinfo/Antarctica/McMurdo", + "/usr/share/zoneinfo/Antarctica/Palmer", + "/usr/share/zoneinfo/Antarctica/Rothera", + "/usr/share/zoneinfo/Antarctica/Syowa", + "/usr/share/zoneinfo/Antarctica/Troll", + "/usr/share/zoneinfo/Antarctica/Vostok", + "/usr/share/zoneinfo/Asia/Aden", + "/usr/share/zoneinfo/Asia/Almaty", + "/usr/share/zoneinfo/Asia/Amman", + "/usr/share/zoneinfo/Asia/Anadyr", + "/usr/share/zoneinfo/Asia/Aqtau", + "/usr/share/zoneinfo/Asia/Aqtobe", + "/usr/share/zoneinfo/Asia/Ashgabat", + "/usr/share/zoneinfo/Asia/Atyrau", + "/usr/share/zoneinfo/Asia/Baghdad", + "/usr/share/zoneinfo/Asia/Bahrain", + "/usr/share/zoneinfo/Asia/Baku", + "/usr/share/zoneinfo/Asia/Bangkok", + "/usr/share/zoneinfo/Asia/Barnaul", + "/usr/share/zoneinfo/Asia/Beirut", + "/usr/share/zoneinfo/Asia/Bishkek", + "/usr/share/zoneinfo/Asia/Brunei", + "/usr/share/zoneinfo/Asia/Chita", + "/usr/share/zoneinfo/Asia/Colombo", + "/usr/share/zoneinfo/Asia/Damascus", + "/usr/share/zoneinfo/Asia/Dhaka", + "/usr/share/zoneinfo/Asia/Dili", + "/usr/share/zoneinfo/Asia/Dubai", + "/usr/share/zoneinfo/Asia/Dushanbe", + "/usr/share/zoneinfo/Asia/Famagusta", + "/usr/share/zoneinfo/Asia/Gaza", + "/usr/share/zoneinfo/Asia/Hebron", + "/usr/share/zoneinfo/Asia/Ho_Chi_Minh", + "/usr/share/zoneinfo/Asia/Hong_Kong", + "/usr/share/zoneinfo/Asia/Hovd", + "/usr/share/zoneinfo/Asia/Irkutsk", + "/usr/share/zoneinfo/Asia/Jakarta", + "/usr/share/zoneinfo/Asia/Jayapura", + "/usr/share/zoneinfo/Asia/Jerusalem", + "/usr/share/zoneinfo/Asia/Kabul", + "/usr/share/zoneinfo/Asia/Kamchatka", + "/usr/share/zoneinfo/Asia/Karachi", + "/usr/share/zoneinfo/Asia/Kathmandu", + "/usr/share/zoneinfo/Asia/Khandyga", + "/usr/share/zoneinfo/Asia/Kolkata", + "/usr/share/zoneinfo/Asia/Krasnoyarsk", + "/usr/share/zoneinfo/Asia/Kuala_Lumpur", + "/usr/share/zoneinfo/Asia/Kuching", + "/usr/share/zoneinfo/Asia/Kuwait", + "/usr/share/zoneinfo/Asia/Macau", + "/usr/share/zoneinfo/Asia/Magadan", + "/usr/share/zoneinfo/Asia/Makassar", + "/usr/share/zoneinfo/Asia/Manila", + "/usr/share/zoneinfo/Asia/Muscat", + "/usr/share/zoneinfo/Asia/Nicosia", + "/usr/share/zoneinfo/Asia/Novokuznetsk", + "/usr/share/zoneinfo/Asia/Novosibirsk", + "/usr/share/zoneinfo/Asia/Omsk", + "/usr/share/zoneinfo/Asia/Oral", + "/usr/share/zoneinfo/Asia/Phnom_Penh", + "/usr/share/zoneinfo/Asia/Pontianak", + "/usr/share/zoneinfo/Asia/Pyongyang", + "/usr/share/zoneinfo/Asia/Qatar", + "/usr/share/zoneinfo/Asia/Qostanay", + "/usr/share/zoneinfo/Asia/Qyzylorda", + "/usr/share/zoneinfo/Asia/Riyadh", + "/usr/share/zoneinfo/Asia/Sakhalin", + "/usr/share/zoneinfo/Asia/Samarkand", + "/usr/share/zoneinfo/Asia/Seoul", + "/usr/share/zoneinfo/Asia/Shanghai", + "/usr/share/zoneinfo/Asia/Singapore", + "/usr/share/zoneinfo/Asia/Srednekolymsk", + "/usr/share/zoneinfo/Asia/Taipei", + "/usr/share/zoneinfo/Asia/Tashkent", + "/usr/share/zoneinfo/Asia/Tbilisi", + "/usr/share/zoneinfo/Asia/Tehran", + "/usr/share/zoneinfo/Asia/Thimphu", + "/usr/share/zoneinfo/Asia/Tokyo", + "/usr/share/zoneinfo/Asia/Tomsk", + "/usr/share/zoneinfo/Asia/Ulaanbaatar", + "/usr/share/zoneinfo/Asia/Urumqi", + "/usr/share/zoneinfo/Asia/Ust-Nera", + "/usr/share/zoneinfo/Asia/Vientiane", + "/usr/share/zoneinfo/Asia/Vladivostok", + "/usr/share/zoneinfo/Asia/Yakutsk", + "/usr/share/zoneinfo/Asia/Yangon", + "/usr/share/zoneinfo/Asia/Yekaterinburg", + "/usr/share/zoneinfo/Asia/Yerevan", + "/usr/share/zoneinfo/Atlantic/Azores", + "/usr/share/zoneinfo/Atlantic/Bermuda", + "/usr/share/zoneinfo/Atlantic/Canary", + "/usr/share/zoneinfo/Atlantic/Cape_Verde", + "/usr/share/zoneinfo/Atlantic/Faroe", + "/usr/share/zoneinfo/Atlantic/Madeira", + "/usr/share/zoneinfo/Atlantic/Reykjavik", + "/usr/share/zoneinfo/Atlantic/South_Georgia", + "/usr/share/zoneinfo/Atlantic/St_Helena", + "/usr/share/zoneinfo/Atlantic/Stanley", + "/usr/share/zoneinfo/Australia/Adelaide", + "/usr/share/zoneinfo/Australia/Brisbane", + "/usr/share/zoneinfo/Australia/Broken_Hill", + "/usr/share/zoneinfo/Australia/Darwin", + "/usr/share/zoneinfo/Australia/Eucla", + "/usr/share/zoneinfo/Australia/Hobart", + "/usr/share/zoneinfo/Australia/Lindeman", + "/usr/share/zoneinfo/Australia/Lord_Howe", + "/usr/share/zoneinfo/Australia/Melbourne", + "/usr/share/zoneinfo/Australia/Perth", + "/usr/share/zoneinfo/Australia/Sydney", + "/usr/share/zoneinfo/Etc/GMT", + "/usr/share/zoneinfo/Etc/GMT+1", + "/usr/share/zoneinfo/Etc/GMT+10", + "/usr/share/zoneinfo/Etc/GMT+11", + "/usr/share/zoneinfo/Etc/GMT+12", + "/usr/share/zoneinfo/Etc/GMT+2", + "/usr/share/zoneinfo/Etc/GMT+3", + "/usr/share/zoneinfo/Etc/GMT+4", + "/usr/share/zoneinfo/Etc/GMT+5", + "/usr/share/zoneinfo/Etc/GMT+6", + "/usr/share/zoneinfo/Etc/GMT+7", + "/usr/share/zoneinfo/Etc/GMT+8", + "/usr/share/zoneinfo/Etc/GMT+9", + "/usr/share/zoneinfo/Etc/GMT-1", + "/usr/share/zoneinfo/Etc/GMT-10", + "/usr/share/zoneinfo/Etc/GMT-11", + "/usr/share/zoneinfo/Etc/GMT-12", + "/usr/share/zoneinfo/Etc/GMT-13", + "/usr/share/zoneinfo/Etc/GMT-14", + "/usr/share/zoneinfo/Etc/GMT-2", + "/usr/share/zoneinfo/Etc/GMT-3", + "/usr/share/zoneinfo/Etc/GMT-4", + "/usr/share/zoneinfo/Etc/GMT-5", + "/usr/share/zoneinfo/Etc/GMT-6", + "/usr/share/zoneinfo/Etc/GMT-7", + "/usr/share/zoneinfo/Etc/GMT-8", + "/usr/share/zoneinfo/Etc/GMT-9", + "/usr/share/zoneinfo/Etc/UTC", + "/usr/share/zoneinfo/Europe/Amsterdam", + "/usr/share/zoneinfo/Europe/Andorra", + "/usr/share/zoneinfo/Europe/Astrakhan", + "/usr/share/zoneinfo/Europe/Athens", + "/usr/share/zoneinfo/Europe/Belgrade", + "/usr/share/zoneinfo/Europe/Berlin", + "/usr/share/zoneinfo/Europe/Brussels", + "/usr/share/zoneinfo/Europe/Bucharest", + "/usr/share/zoneinfo/Europe/Budapest", + "/usr/share/zoneinfo/Europe/Chisinau", + "/usr/share/zoneinfo/Europe/Copenhagen", + "/usr/share/zoneinfo/Europe/Dublin", + "/usr/share/zoneinfo/Europe/Gibraltar", + "/usr/share/zoneinfo/Europe/Guernsey", + "/usr/share/zoneinfo/Europe/Helsinki", + "/usr/share/zoneinfo/Europe/Isle_of_Man", + "/usr/share/zoneinfo/Europe/Istanbul", + "/usr/share/zoneinfo/Europe/Jersey", + "/usr/share/zoneinfo/Europe/Kaliningrad", + "/usr/share/zoneinfo/Europe/Kirov", + "/usr/share/zoneinfo/Europe/Kyiv", + "/usr/share/zoneinfo/Europe/Lisbon", + "/usr/share/zoneinfo/Europe/Ljubljana", + "/usr/share/zoneinfo/Europe/London", + "/usr/share/zoneinfo/Europe/Luxembourg", + "/usr/share/zoneinfo/Europe/Madrid", + "/usr/share/zoneinfo/Europe/Malta", + "/usr/share/zoneinfo/Europe/Minsk", + "/usr/share/zoneinfo/Europe/Monaco", + "/usr/share/zoneinfo/Europe/Moscow", + "/usr/share/zoneinfo/Europe/Oslo", + "/usr/share/zoneinfo/Europe/Paris", + "/usr/share/zoneinfo/Europe/Prague", + "/usr/share/zoneinfo/Europe/Riga", + "/usr/share/zoneinfo/Europe/Rome", + "/usr/share/zoneinfo/Europe/Samara", + "/usr/share/zoneinfo/Europe/Sarajevo", + "/usr/share/zoneinfo/Europe/Saratov", + "/usr/share/zoneinfo/Europe/Simferopol", + "/usr/share/zoneinfo/Europe/Skopje", + "/usr/share/zoneinfo/Europe/Sofia", + "/usr/share/zoneinfo/Europe/Stockholm", + "/usr/share/zoneinfo/Europe/Tallinn", + "/usr/share/zoneinfo/Europe/Tirane", + "/usr/share/zoneinfo/Europe/Ulyanovsk", + "/usr/share/zoneinfo/Europe/Vaduz", + "/usr/share/zoneinfo/Europe/Vienna", + "/usr/share/zoneinfo/Europe/Vilnius", + "/usr/share/zoneinfo/Europe/Volgograd", + "/usr/share/zoneinfo/Europe/Warsaw", + "/usr/share/zoneinfo/Europe/Zagreb", + "/usr/share/zoneinfo/Europe/Zurich", + "/usr/share/zoneinfo/Factory", + "/usr/share/zoneinfo/Indian/Antananarivo", + "/usr/share/zoneinfo/Indian/Chagos", + "/usr/share/zoneinfo/Indian/Christmas", + "/usr/share/zoneinfo/Indian/Cocos", + "/usr/share/zoneinfo/Indian/Comoro", + "/usr/share/zoneinfo/Indian/Kerguelen", + "/usr/share/zoneinfo/Indian/Mahe", + "/usr/share/zoneinfo/Indian/Maldives", + "/usr/share/zoneinfo/Indian/Mauritius", + "/usr/share/zoneinfo/Indian/Mayotte", + "/usr/share/zoneinfo/Indian/Reunion", + "/usr/share/zoneinfo/Pacific/Apia", + "/usr/share/zoneinfo/Pacific/Auckland", + "/usr/share/zoneinfo/Pacific/Bougainville", + "/usr/share/zoneinfo/Pacific/Chatham", + "/usr/share/zoneinfo/Pacific/Chuuk", + "/usr/share/zoneinfo/Pacific/Easter", + "/usr/share/zoneinfo/Pacific/Efate", + "/usr/share/zoneinfo/Pacific/Fakaofo", + "/usr/share/zoneinfo/Pacific/Fiji", + "/usr/share/zoneinfo/Pacific/Funafuti", + "/usr/share/zoneinfo/Pacific/Galapagos", + "/usr/share/zoneinfo/Pacific/Gambier", + "/usr/share/zoneinfo/Pacific/Guadalcanal", + "/usr/share/zoneinfo/Pacific/Guam", + "/usr/share/zoneinfo/Pacific/Honolulu", + "/usr/share/zoneinfo/Pacific/Kanton", + "/usr/share/zoneinfo/Pacific/Kiritimati", + "/usr/share/zoneinfo/Pacific/Kosrae", + "/usr/share/zoneinfo/Pacific/Kwajalein", + "/usr/share/zoneinfo/Pacific/Majuro", + "/usr/share/zoneinfo/Pacific/Marquesas", + "/usr/share/zoneinfo/Pacific/Midway", + "/usr/share/zoneinfo/Pacific/Nauru", + "/usr/share/zoneinfo/Pacific/Niue", + "/usr/share/zoneinfo/Pacific/Norfolk", + "/usr/share/zoneinfo/Pacific/Noumea", + "/usr/share/zoneinfo/Pacific/Pago_Pago", + "/usr/share/zoneinfo/Pacific/Palau", + "/usr/share/zoneinfo/Pacific/Pitcairn", + "/usr/share/zoneinfo/Pacific/Pohnpei", + "/usr/share/zoneinfo/Pacific/Port_Moresby", + "/usr/share/zoneinfo/Pacific/Rarotonga", + "/usr/share/zoneinfo/Pacific/Saipan", + "/usr/share/zoneinfo/Pacific/Tahiti", + "/usr/share/zoneinfo/Pacific/Tarawa", + "/usr/share/zoneinfo/Pacific/Tongatapu", + "/usr/share/zoneinfo/Pacific/Wake", + "/usr/share/zoneinfo/Pacific/Wallis", + "/usr/share/zoneinfo/iso3166.tab", + "/usr/share/zoneinfo/leap-seconds.list", + "/usr/share/zoneinfo/leapseconds", + "/usr/share/zoneinfo/tzdata.zi", + "/usr/share/zoneinfo/zone.tab", + "/usr/share/zoneinfo/zone1970.tab", + "/usr/share/zoneinfo/zonenow.tab" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "util-linux@2.41.5-0+deb13u1", + "Name": "util-linux", + "Identifier": { + "PURL": "pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "e4d9863928456765" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/choom", + "/usr/bin/chrt", + "/usr/bin/dmesg", + "/usr/bin/fallocate", + "/usr/bin/findmnt", + "/usr/bin/flock", + "/usr/bin/getopt", + "/usr/bin/hardlink", + "/usr/bin/ionice", + "/usr/bin/ipcmk", + "/usr/bin/ipcrm", + "/usr/bin/ipcs", + "/usr/bin/lsblk", + "/usr/bin/lscpu", + "/usr/bin/lsipc", + "/usr/bin/lslocks", + "/usr/bin/lslogins", + "/usr/bin/lsmem", + "/usr/bin/lsns", + "/usr/bin/mcookie", + "/usr/bin/more", + "/usr/bin/mountpoint", + "/usr/bin/namei", + "/usr/bin/nsenter", + "/usr/bin/partx", + "/usr/bin/prlimit", + "/usr/bin/rename.ul", + "/usr/bin/rev", + "/usr/bin/setarch", + "/usr/bin/setpriv", + "/usr/bin/setsid", + "/usr/bin/setterm", + "/usr/bin/su", + "/usr/bin/taskset", + "/usr/bin/uclampset", + "/usr/bin/unshare", + "/usr/bin/wdctl", + "/usr/bin/whereis", + "/usr/lib/mime/packages/util-linux", + "/usr/lib/systemd/system/fstrim.service", + "/usr/lib/systemd/system/fstrim.timer", + "/usr/sbin/agetty", + "/usr/sbin/blkdiscard", + "/usr/sbin/blkid", + "/usr/sbin/blkzone", + "/usr/sbin/blockdev", + "/usr/sbin/chcpu", + "/usr/sbin/chmem", + "/usr/sbin/findfs", + "/usr/sbin/fsck", + "/usr/sbin/fsfreeze", + "/usr/sbin/fstrim", + "/usr/sbin/isosize", + "/usr/sbin/ldattach", + "/usr/sbin/mkfs", + "/usr/sbin/mkswap", + "/usr/sbin/pivot_root", + "/usr/sbin/readprofile", + "/usr/sbin/rtcwake", + "/usr/sbin/runuser", + "/usr/sbin/sulogin", + "/usr/sbin/swaplabel", + "/usr/sbin/switch_root", + "/usr/sbin/wipefs", + "/usr/sbin/zramctl", + "/usr/share/bash-completion/completions/blkdiscard", + "/usr/share/bash-completion/completions/blkid", + "/usr/share/bash-completion/completions/blkzone", + "/usr/share/bash-completion/completions/blockdev", + "/usr/share/bash-completion/completions/chcpu", + "/usr/share/bash-completion/completions/chmem", + "/usr/share/bash-completion/completions/chrt", + "/usr/share/bash-completion/completions/dmesg", + "/usr/share/bash-completion/completions/fallocate", + "/usr/share/bash-completion/completions/findfs", + "/usr/share/bash-completion/completions/findmnt", + "/usr/share/bash-completion/completions/flock", + "/usr/share/bash-completion/completions/fsck", + "/usr/share/bash-completion/completions/fsfreeze", + "/usr/share/bash-completion/completions/fstrim", + "/usr/share/bash-completion/completions/getopt", + "/usr/share/bash-completion/completions/hardlink", + "/usr/share/bash-completion/completions/ionice", + "/usr/share/bash-completion/completions/ipcmk", + "/usr/share/bash-completion/completions/ipcrm", + "/usr/share/bash-completion/completions/ipcs", + "/usr/share/bash-completion/completions/isosize", + "/usr/share/bash-completion/completions/ldattach", + "/usr/share/bash-completion/completions/lsblk", + "/usr/share/bash-completion/completions/lscpu", + "/usr/share/bash-completion/completions/lsipc", + "/usr/share/bash-completion/completions/lslocks", + "/usr/share/bash-completion/completions/lslogins", + "/usr/share/bash-completion/completions/lsmem", + "/usr/share/bash-completion/completions/lsns", + "/usr/share/bash-completion/completions/mcookie", + "/usr/share/bash-completion/completions/mkfs", + "/usr/share/bash-completion/completions/mkswap", + "/usr/share/bash-completion/completions/more", + "/usr/share/bash-completion/completions/mountpoint", + "/usr/share/bash-completion/completions/namei", + "/usr/share/bash-completion/completions/nsenter", + "/usr/share/bash-completion/completions/partx", + "/usr/share/bash-completion/completions/pivot_root", + "/usr/share/bash-completion/completions/prlimit", + "/usr/share/bash-completion/completions/readprofile", + "/usr/share/bash-completion/completions/rename.ul", + "/usr/share/bash-completion/completions/rev", + "/usr/share/bash-completion/completions/rtcwake", + "/usr/share/bash-completion/completions/setarch", + "/usr/share/bash-completion/completions/setpriv", + "/usr/share/bash-completion/completions/setsid", + "/usr/share/bash-completion/completions/setterm", + "/usr/share/bash-completion/completions/su", + "/usr/share/bash-completion/completions/swaplabel", + "/usr/share/bash-completion/completions/taskset", + "/usr/share/bash-completion/completions/uclampset", + "/usr/share/bash-completion/completions/unshare", + "/usr/share/bash-completion/completions/wdctl", + "/usr/share/bash-completion/completions/whereis", + "/usr/share/bash-completion/completions/wipefs", + "/usr/share/bash-completion/completions/zramctl", + "/usr/share/doc/util-linux/00-about-docs.txt", + "/usr/share/doc/util-linux/AUTHORS.gz", + "/usr/share/doc/util-linux/NEWS.Debian.gz", + "/usr/share/doc/util-linux/PAM-configuration.txt", + "/usr/share/doc/util-linux/README.Debian", + "/usr/share/doc/util-linux/blkid.txt", + "/usr/share/doc/util-linux/cal.txt", + "/usr/share/doc/util-linux/changelog.Debian.gz", + "/usr/share/doc/util-linux/changelog.gz", + "/usr/share/doc/util-linux/col.txt", + "/usr/share/doc/util-linux/copyright", + "/usr/share/doc/util-linux/deprecated.txt", + "/usr/share/doc/util-linux/examples/getopt-example.bash", + "/usr/share/doc/util-linux/getopt.txt", + "/usr/share/doc/util-linux/getopt_changelog.txt", + "/usr/share/doc/util-linux/howto-build-sys.txt", + "/usr/share/doc/util-linux/howto-compilation.txt", + "/usr/share/doc/util-linux/howto-contribute.txt.gz", + "/usr/share/doc/util-linux/howto-debug.txt", + "/usr/share/doc/util-linux/howto-man-page.txt", + "/usr/share/doc/util-linux/howto-pull-request.txt.gz", + "/usr/share/doc/util-linux/howto-tests.txt", + "/usr/share/doc/util-linux/howto-usage-function.txt.gz", + "/usr/share/doc/util-linux/hwclock.txt", + "/usr/share/doc/util-linux/modems-with-agetty.txt", + "/usr/share/doc/util-linux/mount.txt", + "/usr/share/doc/util-linux/parse-date.txt.gz", + "/usr/share/doc/util-linux/pg.txt", + "/usr/share/doc/util-linux/poeigl.txt.gz", + "/usr/share/doc/util-linux/release-schedule.txt", + "/usr/share/doc/util-linux/releases/v2.13-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.14-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.15-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.16-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.17-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.18-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.19-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.20-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.21-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.22-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.23-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.24-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.25-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.26-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.27-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.28-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.29-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.30-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.31-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.32-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.33-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.34-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.35-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.36-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.37-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.38-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.39-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.40-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.41-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.41.1-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.41.2-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.41.3-ReleaseNotes", + "/usr/share/doc/util-linux/releases/v2.41.4-ReleaseNotes", + "/usr/share/doc/util-linux/releases/v2.41.5-ReleaseNotes", + "/usr/share/lintian/overrides/util-linux", + "/usr/share/man/man1/choom.1.gz", + "/usr/share/man/man1/chrt.1.gz", + "/usr/share/man/man1/dmesg.1.gz", + "/usr/share/man/man1/fallocate.1.gz", + "/usr/share/man/man1/flock.1.gz", + "/usr/share/man/man1/getopt.1.gz", + "/usr/share/man/man1/hardlink.1.gz", + "/usr/share/man/man1/ionice.1.gz", + "/usr/share/man/man1/ipcmk.1.gz", + "/usr/share/man/man1/ipcrm.1.gz", + "/usr/share/man/man1/ipcs.1.gz", + "/usr/share/man/man1/lscpu.1.gz", + "/usr/share/man/man1/lsipc.1.gz", + "/usr/share/man/man1/lslogins.1.gz", + "/usr/share/man/man1/lsmem.1.gz", + "/usr/share/man/man1/mcookie.1.gz", + "/usr/share/man/man1/more.1.gz", + "/usr/share/man/man1/mountpoint.1.gz", + "/usr/share/man/man1/namei.1.gz", + "/usr/share/man/man1/nsenter.1.gz", + "/usr/share/man/man1/prlimit.1.gz", + "/usr/share/man/man1/rename.ul.1.gz", + "/usr/share/man/man1/rev.1.gz", + "/usr/share/man/man1/runuser.1.gz", + "/usr/share/man/man1/setpriv.1.gz", + "/usr/share/man/man1/setsid.1.gz", + "/usr/share/man/man1/setterm.1.gz", + "/usr/share/man/man1/su.1.gz", + "/usr/share/man/man1/taskset.1.gz", + "/usr/share/man/man1/uclampset.1.gz", + "/usr/share/man/man1/unshare.1.gz", + "/usr/share/man/man1/whereis.1.gz", + "/usr/share/man/man5/adjtime_config.5.gz", + "/usr/share/man/man5/scols-filter.5.gz", + "/usr/share/man/man5/terminal-colors.d.5.gz", + "/usr/share/man/man8/agetty.8.gz", + "/usr/share/man/man8/blkdiscard.8.gz", + "/usr/share/man/man8/blkid.8.gz", + "/usr/share/man/man8/blkzone.8.gz", + "/usr/share/man/man8/blockdev.8.gz", + "/usr/share/man/man8/chcpu.8.gz", + "/usr/share/man/man8/chmem.8.gz", + "/usr/share/man/man8/findfs.8.gz", + "/usr/share/man/man8/findmnt.8.gz", + "/usr/share/man/man8/fsck.8.gz", + "/usr/share/man/man8/fsfreeze.8.gz", + "/usr/share/man/man8/fstrim.8.gz", + "/usr/share/man/man8/isosize.8.gz", + "/usr/share/man/man8/ldattach.8.gz", + "/usr/share/man/man8/lsblk.8.gz", + "/usr/share/man/man8/lslocks.8.gz", + "/usr/share/man/man8/lsns.8.gz", + "/usr/share/man/man8/mkfs.8.gz", + "/usr/share/man/man8/mkswap.8.gz", + "/usr/share/man/man8/partx.8.gz", + "/usr/share/man/man8/pivot_root.8.gz", + "/usr/share/man/man8/readprofile.8.gz", + "/usr/share/man/man8/rtcwake.8.gz", + "/usr/share/man/man8/setarch.8.gz", + "/usr/share/man/man8/sulogin.8.gz", + "/usr/share/man/man8/swaplabel.8.gz", + "/usr/share/man/man8/switch_root.8.gz", + "/usr/share/man/man8/wdctl.8.gz", + "/usr/share/man/man8/wipefs.8.gz", + "/usr/share/man/man8/zramctl.8.gz", + "/usr/share/util-linux/logcheck/ignore.d.server/util-linux" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "zlib1g@1:1.3.dfsg+really1.3.1-1+b1", + "Name": "zlib1g", + "Identifier": { + "PURL": "pkg:deb/debian/zlib1g@1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "ec1c0574f56f96a0" + }, + "Version": "1.3.dfsg+really1.3.1", + "Release": "1+b1", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "zlib", + "SrcVersion": "1.3.dfsg+really1.3.1", + "SrcRelease": "1", + "SrcEpoch": 1, + "Licenses": [ + "Zlib" + ], + "Maintainer": "Mark Brown \u003cbroonie@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u4" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libz.so.1.3.1", + "/usr/share/doc/zlib1g/changelog.Debian.amd64.gz", + "/usr/share/doc/zlib1g/changelog.Debian.gz", + "/usr/share/doc/zlib1g/changelog.gz", + "/usr/share/doc/zlib1g/copyright" + ], + "AnalyzedBy": "dpkg" + } + ], + "Vulnerabilities": [ + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "bsdutils@1:2.41.5-0+deb13u1", + "PkgName": "bsdutils", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/bsdutils@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "a4b47561565a3535" + }, + "InstalledVersion": "1:2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:3ad91c60b53738106b62b12de284dbd6f63048436e12c82b29503bf346ba6cc7", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "bsdutils@1:2.41.5-0+deb13u1", + "PkgName": "bsdutils", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/bsdutils@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "a4b47561565a3535" + }, + "InstalledVersion": "1:2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:8e01b03d02c14ea460721b9e45ea0f5941809c91d8fe8da6e4859c4c0ae05505", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "bsdutils@1:2.41.5-0+deb13u1", + "PkgName": "bsdutils", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/bsdutils@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "a4b47561565a3535" + }, + "InstalledVersion": "1:2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:dae6f3dfd2152871ef9f4ea27e0c5f924e7a306a01a087cab35f478f5c96c3e2", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "bsdutils@1:2.41.5-0+deb13u1", + "PkgName": "bsdutils", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/bsdutils@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "a4b47561565a3535" + }, + "InstalledVersion": "1:2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:5f5892f07f1d21d54d61e87216c55d707598d40a5cd8d006d053bb7b76f248b7", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-54369", + "PkgID": "libacl1@2.3.2-2+b1", + "PkgName": "libacl1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libacl1@2.3.2-2%2Bb1?arch=amd64\u0026distro=debian-13.7", + "UID": "cc40ccea052c10a8" + }, + "InstalledVersion": "2.3.2-2+b1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54369", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:d46db7f8baa3d0ea532805f98a07d7ffe1277b5ca6ef9b0c3dc323b0e2235b04", + "Title": "acl: Symlink traversal privilege escalation via libacl functions", + "Description": "acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:34351", + "https://access.redhat.com/errata/RHSA-2026:42736", + "https://access.redhat.com/errata/RHSA-2026:42739", + "https://access.redhat.com/errata/RHSA-2026:43420", + "https://access.redhat.com/errata/RHSA-2026:44481", + "https://access.redhat.com/errata/RHSA-2026:46836", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:53371", + "https://access.redhat.com/errata/RHSA-2026:54769", + "https://access.redhat.com/errata/RHSA-2026:58981", + "https://access.redhat.com/errata/RHSA-2026:64805", + "https://access.redhat.com/security/cve/CVE-2026-54369", + "https://bugzilla.redhat.com/2490277", + "https://bugzilla.redhat.com/2490279", + "https://bugzilla.redhat.com/show_bug.cgi?id=2490277", + "https://bugzilla.redhat.com/show_bug.cgi?id=2490279", + "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5", + "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54369", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54370", + "https://errata.almalinux.org/9/ALSA-2026-42736.html", + "https://errata.rockylinux.org/RLSA-2026:42736", + "https://linux.oracle.com/cve/CVE-2026-54369.html", + "https://linux.oracle.com/errata/ELSA-2026-43420.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54369", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json", + "https://www.cve.org/CVERecord?id=CVE-2026-54369", + "https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions" + ], + "PublishedDate": "2026-06-29T14:16:57.487Z", + "LastModifiedDate": "2026-09-09T13:20:30.973Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "libblkid1@2.41.5-0+deb13u1", + "PkgName": "libblkid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "e20c3ed37f6020d7" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:9a3d7228fd994a56401778710cfe4406f828066d29650015e84ffdc0990023ea", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "libblkid1@2.41.5-0+deb13u1", + "PkgName": "libblkid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "e20c3ed37f6020d7" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:0453ad78c69c2253ac155d8ceeec61a28e59bd402e9c2e8c29a894d91331d262", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "libblkid1@2.41.5-0+deb13u1", + "PkgName": "libblkid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "e20c3ed37f6020d7" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:a2cafc14196b51b5ad72da39033579cfa871b3e1e9c99219baa5d907af816402", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "libblkid1@2.41.5-0+deb13u1", + "PkgName": "libblkid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "e20c3ed37f6020d7" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:c643939b7381fd4ede6a89b97be8690181c564647ad3f6d4b1a563fc43a096f9", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "liblastlog2-2@2.41.5-0+deb13u1", + "PkgName": "liblastlog2-2", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "481f2fda004b182b" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:bba7cffa505b27a91b81c8bfc28c85a05528544636593c01ff5adcf5c158e1e9", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "liblastlog2-2@2.41.5-0+deb13u1", + "PkgName": "liblastlog2-2", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "481f2fda004b182b" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:0b04739a81cec06d17213f36fd06b58a10e72fa17226a60b217dfcccdabeab9b", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "liblastlog2-2@2.41.5-0+deb13u1", + "PkgName": "liblastlog2-2", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "481f2fda004b182b" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:7a9afa0af8610d2f1ece67a489b41616f3dd08cf49604e4d46d3de2e53254ed2", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "liblastlog2-2@2.41.5-0+deb13u1", + "PkgName": "liblastlog2-2", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "481f2fda004b182b" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:3cc760cc3acd41960240900b08665c64a32eaf09fad90a10f06405f650aefab1", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "libmount1@2.41.5-0+deb13u1", + "PkgName": "libmount1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "d0bfdcf72ddff375" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:23a5a5dacc16775e98c692e28ea50d7c9c0e2b303ac472ac765a3e2c822c4094", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "libmount1@2.41.5-0+deb13u1", + "PkgName": "libmount1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "d0bfdcf72ddff375" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:b14b68d94d599001b4a92d51b6c892a9ceb4b397149a3f60e2dca82728c973ae", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "libmount1@2.41.5-0+deb13u1", + "PkgName": "libmount1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "d0bfdcf72ddff375" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:2f2abf84080c3c222a713dcf1257aac25116c9a2358bd8f92058f6bd060bf02f", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "libmount1@2.41.5-0+deb13u1", + "PkgName": "libmount1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "d0bfdcf72ddff375" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:6283bffe67110cbc5731ce59fe411a71cddf0edade19f5236405193e780a6568", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2025-69720", + "PkgID": "libncursesw6@6.5+20250216-2", + "PkgName": "libncursesw6", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libncursesw6@6.5%2B20250216-2?arch=amd64\u0026distro=debian-13.7", + "UID": "7121209a6392dd9e" + }, + "InstalledVersion": "6.5+20250216-2", + "Status": "affected", + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-69720", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:7f78ce3d85418953b3d142f15ec5c3af622d2464b51b50c2426c579bb907f8b9", + "Title": "ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.", + "Description": "The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-121", + "CWE-120" + ], + "VendorSeverity": { + "alma": 2, + "azure": 4, + "cbl-mariner": 4, + "julia": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:5913", + "https://access.redhat.com/security/cve/CVE-2025-69720", + "https://bugzilla.redhat.com/2449037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2449037", + "https://cert-portal.siemens.com/productcert/html/ssa-253495.html", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69720", + "https://errata.almalinux.org/10/ALSA-2026-5913.html", + "https://errata.rockylinux.org/RLSA-2026:5913", + "https://github.com/Cao-Wuhui/CVE-2025-69720", + "https://github.com/advisories/GHSA-9952-mrqj-h4jh", + "https://invisible-island.net/archives/ncurses/6.5", + "https://invisible-island.net/archives/ncurses/6.5/", + "https://invisible-island.net/ncurses", + "https://invisible-island.net/ncurses/", + "https://linux.oracle.com/cve/CVE-2025-69720.html", + "https://linux.oracle.com/errata/ELSA-2026-5913.html", + "https://marc.info/?l=ncurses-bug\u0026m=176539968328570\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176540731801330\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176545557728083\u0026w=2", + "https://nvd.nist.gov/vuln/detail/CVE-2025-69720", + "https://ubuntu.com/security/notices/USN-8503-1", + "https://www.cve.org/CVERecord?id=CVE-2025-69720" + ], + "PublishedDate": "2026-03-19T15:16:21.293Z", + "LastModifiedDate": "2026-06-17T10:00:50.423Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "libsmartcols1@2.41.5-0+deb13u1", + "PkgName": "libsmartcols1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "94502fa5e10395c7" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:945cf58679b0d2a4ba75b4d7e4ff5c7b2ddbedc2aba58e9443b1380b26b56e5d", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "libsmartcols1@2.41.5-0+deb13u1", + "PkgName": "libsmartcols1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "94502fa5e10395c7" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:cbfe7db759f6a88938aff8477d8bdd994a99241fa7996d31ecd1b93d54af359a", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "libsmartcols1@2.41.5-0+deb13u1", + "PkgName": "libsmartcols1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "94502fa5e10395c7" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:960b338f66176fc62313a33f2b9717ae10bb208bf118ea3546bb2505656f4b7e", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "libsmartcols1@2.41.5-0+deb13u1", + "PkgName": "libsmartcols1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "94502fa5e10395c7" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:2ac6a74ff5eddeea18a3ecd44e592fae68436019a6c643d4e76f7e1dad5242aa", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-16742", + "PkgID": "libsystemd0@257.13-1~deb13u1", + "PkgName": "libsystemd0", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "b0cd86eb50280666" + }, + "InstalledVersion": "257.13-1~deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-16742", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:b6a2fee9e6a22e4c33d40669d7e0ffbcdb7d390529ade82fc19d52d4fbe9091b", + "Title": "systemd: systemd-homed: Local privilege escalation via missing home-record signature verification", + "Description": "systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user", + "Severity": "HIGH", + "CweIDs": [ + "CWE-269", + "CWE-347" + ], + "VendorSeverity": { + "azure": 2, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-16742", + "https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-16742", + "https://ubuntu.com/security/notices/USN-8626-1", + "https://www.cve.org/CVERecord?id=CVE-2026-16742" + ], + "PublishedDate": "2026-08-10T14:17:21.277Z", + "LastModifiedDate": "2026-09-01T20:54:51.287Z" + }, + { + "VulnerabilityID": "CVE-2025-69720", + "PkgID": "libtinfo6@6.5+20250216-2", + "PkgName": "libtinfo6", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64\u0026distro=debian-13.7", + "UID": "c19e4ba0186ba329" + }, + "InstalledVersion": "6.5+20250216-2", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-69720", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:857f21b7cb26bcd4ae0702104f81fa3d751e5d2027854be3c40070bef6399003", + "Title": "ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.", + "Description": "The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-121", + "CWE-120" + ], + "VendorSeverity": { + "alma": 2, + "azure": 4, + "cbl-mariner": 4, + "julia": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:5913", + "https://access.redhat.com/security/cve/CVE-2025-69720", + "https://bugzilla.redhat.com/2449037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2449037", + "https://cert-portal.siemens.com/productcert/html/ssa-253495.html", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69720", + "https://errata.almalinux.org/10/ALSA-2026-5913.html", + "https://errata.rockylinux.org/RLSA-2026:5913", + "https://github.com/Cao-Wuhui/CVE-2025-69720", + "https://github.com/advisories/GHSA-9952-mrqj-h4jh", + "https://invisible-island.net/archives/ncurses/6.5", + "https://invisible-island.net/archives/ncurses/6.5/", + "https://invisible-island.net/ncurses", + "https://invisible-island.net/ncurses/", + "https://linux.oracle.com/cve/CVE-2025-69720.html", + "https://linux.oracle.com/errata/ELSA-2026-5913.html", + "https://marc.info/?l=ncurses-bug\u0026m=176539968328570\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176540731801330\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176545557728083\u0026w=2", + "https://nvd.nist.gov/vuln/detail/CVE-2025-69720", + "https://ubuntu.com/security/notices/USN-8503-1", + "https://www.cve.org/CVERecord?id=CVE-2025-69720" + ], + "PublishedDate": "2026-03-19T15:16:21.293Z", + "LastModifiedDate": "2026-06-17T10:00:50.423Z" + }, + { + "VulnerabilityID": "CVE-2026-16742", + "PkgID": "libudev1@257.13-1~deb13u1", + "PkgName": "libudev1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "9d7053ae266a0055" + }, + "InstalledVersion": "257.13-1~deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-16742", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:14fc9084b4892457108f14f496adbb82728a22f6453d0233622f8b07080c3411", + "Title": "systemd: systemd-homed: Local privilege escalation via missing home-record signature verification", + "Description": "systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user", + "Severity": "HIGH", + "CweIDs": [ + "CWE-269", + "CWE-347" + ], + "VendorSeverity": { + "azure": 2, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-16742", + "https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-16742", + "https://ubuntu.com/security/notices/USN-8626-1", + "https://www.cve.org/CVERecord?id=CVE-2026-16742" + ], + "PublishedDate": "2026-08-10T14:17:21.277Z", + "LastModifiedDate": "2026-09-01T20:54:51.287Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "libuuid1@2.41.5-0+deb13u1", + "PkgName": "libuuid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "3a03f1816c93c994" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:24bb10890048bda45f4a3e40f77cc7e33be390e94458b89812238380ace62701", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "libuuid1@2.41.5-0+deb13u1", + "PkgName": "libuuid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "3a03f1816c93c994" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:0c4803c75cb9ac6fb78dc5f096030e9b5ead0379551ec35432a4d01b7f29eafe", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "libuuid1@2.41.5-0+deb13u1", + "PkgName": "libuuid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "3a03f1816c93c994" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:623c8f44abcb230824abd8c393ffe5c3187bea80ef98f74d8d09c2052f593b6b", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "libuuid1@2.41.5-0+deb13u1", + "PkgName": "libuuid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "3a03f1816c93c994" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:b0e38f35dc1826304845a2c91fa296be32433694f469955963a59bb539de93bc", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "login@1:4.16.0-2+really2.41.5-0+deb13u1", + "PkgName": "login", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/login@4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "dc99754e767c40b9" + }, + "InstalledVersion": "1:4.16.0-2+really2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:459ff602403954ce0fa71f051f3c35136b307f887cd0a827a1de5f5ef9edcba1", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "login@1:4.16.0-2+really2.41.5-0+deb13u1", + "PkgName": "login", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/login@4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "dc99754e767c40b9" + }, + "InstalledVersion": "1:4.16.0-2+really2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:1a69da9fd1cf292dcedd0cafa3e9c17b7a2b1551c65c4e1058c04c5b979a9095", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "login@1:4.16.0-2+really2.41.5-0+deb13u1", + "PkgName": "login", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/login@4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "dc99754e767c40b9" + }, + "InstalledVersion": "1:4.16.0-2+really2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:891a8e0800de6db390c692dd39273a4cd15e7d2ce5547ac7580b229596fa67d7", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "login@1:4.16.0-2+really2.41.5-0+deb13u1", + "PkgName": "login", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/login@4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7\u0026epoch=1", + "UID": "dc99754e767c40b9" + }, + "InstalledVersion": "1:4.16.0-2+really2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:a5e4947d1bb34a2f07dbedbe22ed9e11d73ded521d5fb4ae57e55836afd291f1", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "mount@2.41.5-0+deb13u1", + "PkgName": "mount", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "d781ec5616a75c78" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:65b769b8c0123a64ca13a20bd77e77897e9b33d17977d0afb44265da1dd0276e", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "mount@2.41.5-0+deb13u1", + "PkgName": "mount", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "d781ec5616a75c78" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:79008bd39dd499021dd46c88db80e4379de08dca004a510807d675ab1525b547", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "mount@2.41.5-0+deb13u1", + "PkgName": "mount", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "d781ec5616a75c78" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:262ed438f21b036a10cb0fc96733a6aecc828638943f62935de2ba86b995bfe3", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "mount@2.41.5-0+deb13u1", + "PkgName": "mount", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "d781ec5616a75c78" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:c58e7b7a0f663d68b3df7b2c57755925bcf6c83021f376f459793dcc6c9a3a3d", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2025-69720", + "PkgID": "ncurses-base@6.5+20250216-2", + "PkgName": "ncurses-base", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all\u0026distro=debian-13.7", + "UID": "767a0231348a5cb5" + }, + "InstalledVersion": "6.5+20250216-2", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-69720", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:d871427164dc9a53da6bd09f33e517e96d79c52753cfcf678490fae12839e9c1", + "Title": "ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.", + "Description": "The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-121", + "CWE-120" + ], + "VendorSeverity": { + "alma": 2, + "azure": 4, + "cbl-mariner": 4, + "julia": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:5913", + "https://access.redhat.com/security/cve/CVE-2025-69720", + "https://bugzilla.redhat.com/2449037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2449037", + "https://cert-portal.siemens.com/productcert/html/ssa-253495.html", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69720", + "https://errata.almalinux.org/10/ALSA-2026-5913.html", + "https://errata.rockylinux.org/RLSA-2026:5913", + "https://github.com/Cao-Wuhui/CVE-2025-69720", + "https://github.com/advisories/GHSA-9952-mrqj-h4jh", + "https://invisible-island.net/archives/ncurses/6.5", + "https://invisible-island.net/archives/ncurses/6.5/", + "https://invisible-island.net/ncurses", + "https://invisible-island.net/ncurses/", + "https://linux.oracle.com/cve/CVE-2025-69720.html", + "https://linux.oracle.com/errata/ELSA-2026-5913.html", + "https://marc.info/?l=ncurses-bug\u0026m=176539968328570\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176540731801330\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176545557728083\u0026w=2", + "https://nvd.nist.gov/vuln/detail/CVE-2025-69720", + "https://ubuntu.com/security/notices/USN-8503-1", + "https://www.cve.org/CVERecord?id=CVE-2025-69720" + ], + "PublishedDate": "2026-03-19T15:16:21.293Z", + "LastModifiedDate": "2026-06-17T10:00:50.423Z" + }, + { + "VulnerabilityID": "CVE-2025-69720", + "PkgID": "ncurses-bin@6.5+20250216-2", + "PkgName": "ncurses-bin", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64\u0026distro=debian-13.7", + "UID": "5b541563cf6587e5" + }, + "InstalledVersion": "6.5+20250216-2", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-69720", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:6a586a706841eea74f1853c7cc0140910f20f1629fb0a50c3dbc9ee2c5b1ccfc", + "Title": "ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.", + "Description": "The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-121", + "CWE-120" + ], + "VendorSeverity": { + "alma": 2, + "azure": 4, + "cbl-mariner": 4, + "julia": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:5913", + "https://access.redhat.com/security/cve/CVE-2025-69720", + "https://bugzilla.redhat.com/2449037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2449037", + "https://cert-portal.siemens.com/productcert/html/ssa-253495.html", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69720", + "https://errata.almalinux.org/10/ALSA-2026-5913.html", + "https://errata.rockylinux.org/RLSA-2026:5913", + "https://github.com/Cao-Wuhui/CVE-2025-69720", + "https://github.com/advisories/GHSA-9952-mrqj-h4jh", + "https://invisible-island.net/archives/ncurses/6.5", + "https://invisible-island.net/archives/ncurses/6.5/", + "https://invisible-island.net/ncurses", + "https://invisible-island.net/ncurses/", + "https://linux.oracle.com/cve/CVE-2025-69720.html", + "https://linux.oracle.com/errata/ELSA-2026-5913.html", + "https://marc.info/?l=ncurses-bug\u0026m=176539968328570\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176540731801330\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176545557728083\u0026w=2", + "https://nvd.nist.gov/vuln/detail/CVE-2025-69720", + "https://ubuntu.com/security/notices/USN-8503-1", + "https://www.cve.org/CVERecord?id=CVE-2025-69720" + ], + "PublishedDate": "2026-03-19T15:16:21.293Z", + "LastModifiedDate": "2026-06-17T10:00:50.423Z" + }, + { + "VulnerabilityID": "CVE-2026-9538", + "PkgID": "perl-base@5.40.1-6+deb13u1", + "PkgName": "perl-base", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/perl-base@5.40.1-6%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "aa65e528dbb05e9e" + }, + "InstalledVersion": "5.40.1-6+deb13u1", + "Status": "fix_deferred", + "Layer": { + "Digest": "sha256:5386c81827afade7582d825d28da8534f91b3ed06f5158a35d7af88033c445f4", + "DiffID": "sha256:7fde1caf0353c17db0031a67dce2ca9e35ae5495b13533acb6153286821a91b1" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-9538", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:e38f6a9ec2184ee82af3aaa4980c03ed5ec14c1f1101a946a548dffac4c9fda2", + "Title": "perl-Archive-Tar: perl-Archive-Tar: Denial of Service via crafted tar header with large entry size", + "Description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle-\u003eread($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "nvd": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/05/26/4", + "https://access.redhat.com/errata/RHSA-2026:49525", + "https://access.redhat.com/security/cve/CVE-2026-9538", + "https://bugzilla.redhat.com/2481315", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481315", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9538", + "https://errata.almalinux.org/9/ALSA-2026-49525.html", + "https://errata.rockylinux.org/RLSA-2026:49525", + "https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch", + "https://linux.oracle.com/cve/CVE-2026-9538.html", + "https://linux.oracle.com/errata/ELSA-2026-49525.html", + "https://lists.security.metacpan.org/cve-announce/msg/40396448/", + "https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes", + "https://nvd.nist.gov/vuln/detail/CVE-2026-9538", + "https://ubuntu.com/security/notices/USN-8684-1", + "https://www.cve.org/CVERecord?id=CVE-2026-9538" + ], + "PublishedDate": "2026-05-26T02:16:41.15Z", + "LastModifiedDate": "2026-07-23T11:10:00.12Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "util-linux@2.41.5-0+deb13u1", + "PkgName": "util-linux", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "e4d9863928456765" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:1c3c30eb88ee6e960c9531721084d1c7e1f1109dd70f5ef5e4c97518a55dfaaa", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "util-linux@2.41.5-0+deb13u1", + "PkgName": "util-linux", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "e4d9863928456765" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:2f900af01303d90ed050709f5b5691057113b10325105d49e348da2bbd3e7456", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "util-linux@2.41.5-0+deb13u1", + "PkgName": "util-linux", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "e4d9863928456765" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:8ff287cc975c973087a28acbc93e5cd7098daa14055c38cd64948ac64554854a", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "util-linux@2.41.5-0+deb13u1", + "PkgName": "util-linux", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.7", + "UID": "e4d9863928456765" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:7202d4ba7b434b49752cc645788f01f743444caec9eacd8290da470dc380ad04", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + } + ] + }, + { + "Target": "Python", + "Class": "lang-pkgs", + "Type": "python-pkg", + "Packages": [ + { + "ID": "CacheControl@0.14.4", + "Name": "CacheControl", + "Identifier": { + "PURL": "pkg:pypi/cachecontrol@0.14.4", + "UID": "918db5f3147f4498", + "BOMRef": "pkg:pypi/CacheControl@0.14.4" + }, + "Version": "0.14.4", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "annotated-doc", + "Identifier": { + "PURL": "pkg:pypi/annotated-doc@0.0.5", + "UID": "fb6ac2c1f334acc0" + }, + "Version": "0.0.5", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/annotated_doc-0.0.5.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "annotated-types", + "Identifier": { + "PURL": "pkg:pypi/annotated-types@0.8.0", + "UID": "1847359b2b3688a4" + }, + "Version": "0.8.0", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/annotated_types-0.8.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "anyio", + "Identifier": { + "PURL": "pkg:pypi/anyio@4.15.1", + "UID": "f568878f56f7e387" + }, + "Version": "4.15.1", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/anyio-4.15.1.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "boto3", + "Identifier": { + "PURL": "pkg:pypi/boto3@1.38.23", + "UID": "5303fef458b64a5b" + }, + "Version": "1.38.23", + "Licenses": [ + "Apache-2.0" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/boto3-1.38.23.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "botocore", + "Identifier": { + "PURL": "pkg:pypi/botocore@1.38.46", + "UID": "c63f075ac8b3aefe" + }, + "Version": "1.38.46", + "Licenses": [ + "Apache-2.0" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/botocore-1.38.46.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "certifi@2026.6.17", + "Name": "certifi", + "Identifier": { + "PURL": "pkg:pypi/certifi@2026.6.17", + "UID": "4be2e2d698b876a3", + "BOMRef": "pkg:pypi/certifi@2026.6.17" + }, + "Version": "2026.6.17", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "certifi", + "Identifier": { + "PURL": "pkg:pypi/certifi@2026.7.22", + "UID": "48a7d4734aaf4881" + }, + "Version": "2026.7.22", + "Licenses": [ + "MPL-2.0" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/certifi-2026.7.22.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "click", + "Identifier": { + "PURL": "pkg:pypi/click@8.5.0", + "UID": "1726c35a3b1d5d0d" + }, + "Version": "8.5.0", + "Licenses": [ + "BSD-3-Clause" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/click-8.5.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "distlib@0.4.2", + "Name": "distlib", + "Identifier": { + "PURL": "pkg:pypi/distlib@0.4.2", + "UID": "eaa5d2119fe45ab3", + "BOMRef": "pkg:pypi/distlib@0.4.2" + }, + "Version": "0.4.2", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "distro@1.9.0", + "Name": "distro", + "Identifier": { + "PURL": "pkg:pypi/distro@1.9.0", + "UID": "b90ac562dcd78c67", + "BOMRef": "pkg:pypi/distro@1.9.0" + }, + "Version": "1.9.0", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "fastapi", + "Identifier": { + "PURL": "pkg:pypi/fastapi@0.141.1", + "UID": "723de6e031cff522" + }, + "Version": "0.141.1", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/fastapi-0.141.1.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "h11", + "Identifier": { + "PURL": "pkg:pypi/h11@0.16.0", + "UID": "2ec0fe64a8b38d3a" + }, + "Version": "0.16.0", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/h11-0.16.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "httpcore", + "Identifier": { + "PURL": "pkg:pypi/httpcore@1.0.9", + "UID": "336ebe8bbce379bb" + }, + "Version": "1.0.9", + "Licenses": [ + "BSD-3-Clause" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/httpcore-1.0.9.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "httpx", + "Identifier": { + "PURL": "pkg:pypi/httpx@0.28.1", + "UID": "e625874b858226c9" + }, + "Version": "0.28.1", + "Licenses": [ + "BSD-3-Clause" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/httpx-0.28.1.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "idna@3.18", + "Name": "idna", + "Identifier": { + "PURL": "pkg:pypi/idna@3.18", + "UID": "c584d1beb1ab5d75", + "BOMRef": "pkg:pypi/idna@3.18" + }, + "Version": "3.18", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "idna", + "Identifier": { + "PURL": "pkg:pypi/idna@3.19", + "UID": "e695a226ff219946" + }, + "Version": "3.19", + "Licenses": [ + "BSD-3-Clause" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/idna-3.19.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "jmespath", + "Identifier": { + "PURL": "pkg:pypi/jmespath@1.1.0", + "UID": "483d80446fb1b18d" + }, + "Version": "1.1.0", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/jmespath-1.1.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "msgpack@1.1.2", + "Name": "msgpack", + "Identifier": { + "PURL": "pkg:pypi/msgpack@1.1.2", + "UID": "9d7d565367050f92", + "BOMRef": "pkg:pypi/msgpack@1.1.2" + }, + "Version": "1.1.2", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "packaging@26.2", + "Name": "packaging", + "Identifier": { + "PURL": "pkg:pypi/packaging@26.2", + "UID": "831135d2638194e3", + "BOMRef": "pkg:pypi/packaging@26.2" + }, + "Version": "26.2", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "pip", + "Identifier": { + "PURL": "pkg:pypi/pip@26.2.1", + "UID": "6ecafc08becca283" + }, + "Version": "26.2.1", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/pip-26.2.1.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "platformdirs@4.10.0", + "Name": "platformdirs", + "Identifier": { + "PURL": "pkg:pypi/platformdirs@4.10.0", + "UID": "bceb43cd8faea0db", + "BOMRef": "pkg:pypi/platformdirs@4.10.0" + }, + "Version": "4.10.0", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "psycopg", + "Identifier": { + "PURL": "pkg:pypi/psycopg@3.2.9", + "UID": "5b465f1802331f69" + }, + "Version": "3.2.9", + "Licenses": [ + "LGPL-3.0-only" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/psycopg-3.2.9.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "psycopg-binary", + "Identifier": { + "PURL": "pkg:pypi/psycopg-binary@3.2.9", + "UID": "c793f12682d80d9c" + }, + "Version": "3.2.9", + "Licenses": [ + "LGPL-3.0-only" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/psycopg_binary-3.2.9.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "pydantic", + "Identifier": { + "PURL": "pkg:pypi/pydantic@2.13.5", + "UID": "e034257422817e0d" + }, + "Version": "2.13.5", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/pydantic-2.13.5.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "pydantic_core", + "Identifier": { + "PURL": "pkg:pypi/pydantic-core@2.46.5", + "UID": "ffe3dd4972d2489c" + }, + "Version": "2.46.5", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/pydantic_core-2.46.5.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "pygments@2.20.0", + "Name": "pygments", + "Identifier": { + "PURL": "pkg:pypi/pygments@2.20.0", + "UID": "1cc1d55af1817d9", + "BOMRef": "pkg:pypi/pygments@2.20.0" + }, + "Version": "2.20.0", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "pyproject-hooks@1.2.0", + "Name": "pyproject-hooks", + "Identifier": { + "PURL": "pkg:pypi/pyproject-hooks@1.2.0", + "UID": "e523f408361e0fcc", + "BOMRef": "pkg:pypi/pyproject-hooks@1.2.0" + }, + "Version": "1.2.0", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "python-dateutil", + "Identifier": { + "PURL": "pkg:pypi/python-dateutil@2.9.0.post0", + "UID": "f8462eb573af85ab" + }, + "Version": "2.9.0.post0", + "Licenses": [ + "BSD-3-Clause", + "Apache-2.0" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/python_dateutil-2.9.0.post0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "requests@2.34.2", + "Name": "requests", + "Identifier": { + "PURL": "pkg:pypi/requests@2.34.2", + "UID": "7d2a8fbdb98d5bb8", + "BOMRef": "pkg:pypi/requests@2.34.2" + }, + "Version": "2.34.2", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "resolvelib@1.2.1", + "Name": "resolvelib", + "Identifier": { + "PURL": "pkg:pypi/resolvelib@1.2.1", + "UID": "47e96669d04f0ad5", + "BOMRef": "pkg:pypi/resolvelib@1.2.1" + }, + "Version": "1.2.1", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "rich@14.2.0", + "Name": "rich", + "Identifier": { + "PURL": "pkg:pypi/rich@14.2.0", + "UID": "72917d9a472273b5", + "BOMRef": "pkg:pypi/rich@14.2.0" + }, + "Version": "14.2.0", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "s3transfer", + "Identifier": { + "PURL": "pkg:pypi/s3transfer@0.13.1", + "UID": "e2f35e3d22fa0f40" + }, + "Version": "0.13.1", + "Licenses": [ + "Apache-2.0" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/s3transfer-0.13.1.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "setuptools@70.3.0", + "Name": "setuptools", + "Identifier": { + "PURL": "pkg:pypi/setuptools@70.3.0", + "UID": "4bc74a0ad6dbc16b", + "BOMRef": "pkg:pypi/setuptools@70.3.0" + }, + "Version": "70.3.0", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "six", + "Identifier": { + "PURL": "pkg:pypi/six@1.17.0", + "UID": "3c749e9680577add" + }, + "Version": "1.17.0", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/six-1.17.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "starlette", + "Identifier": { + "PURL": "pkg:pypi/starlette@1.6.0", + "UID": "faa3f25b0d188eac" + }, + "Version": "1.6.0", + "Licenses": [ + "BSD-3-Clause" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/starlette-1.6.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "tomli@2.4.1", + "Name": "tomli", + "Identifier": { + "PURL": "pkg:pypi/tomli@2.4.1", + "UID": "2cb2a60390da1ea0", + "BOMRef": "pkg:pypi/tomli@2.4.1" + }, + "Version": "2.4.1", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "tomli-w@1.2.0", + "Name": "tomli-w", + "Identifier": { + "PURL": "pkg:pypi/tomli-w@1.2.0", + "UID": "313a1c5a485a20fb", + "BOMRef": "pkg:pypi/tomli-w@1.2.0" + }, + "Version": "1.2.0", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "truststore@0.10.4", + "Name": "truststore", + "Identifier": { + "PURL": "pkg:pypi/truststore@0.10.4", + "UID": "46df0f1b1d8069cd", + "BOMRef": "pkg:pypi/truststore@0.10.4" + }, + "Version": "0.10.4", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "typing-inspection", + "Identifier": { + "PURL": "pkg:pypi/typing-inspection@0.4.4", + "UID": "53f9ffc7d6a5637e" + }, + "Version": "0.4.4", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/typing_inspection-0.4.4.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "typing_extensions", + "Identifier": { + "PURL": "pkg:pypi/typing-extensions@4.16.0", + "UID": "723d87d1aaa6dd8" + }, + "Version": "4.16.0", + "Licenses": [ + "PSF-2.0" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/typing_extensions-4.16.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "urllib3", + "Identifier": { + "PURL": "pkg:pypi/urllib3@2.7.0", + "UID": "fd0c49cd6c1fd2de" + }, + "Version": "2.7.0", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/urllib3-2.7.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "urllib3@2.7.0", + "Name": "urllib3", + "Identifier": { + "PURL": "pkg:pypi/urllib3@2.7.0", + "UID": "7471a9a22bc9de38", + "BOMRef": "pkg:pypi/urllib3@2.7.0" + }, + "Version": "2.7.0", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "uvicorn", + "Identifier": { + "PURL": "pkg:pypi/uvicorn@0.34.2", + "UID": "36df7c4f20b1ff11" + }, + "Version": "0.34.2", + "Licenses": [ + "BSD-3-Clause" + ], + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/uvicorn-0.34.2.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + } + ], + "Vulnerabilities": [ + { + "VulnerabilityID": "GHSA-6v7p-g79w-8964", + "PkgID": "msgpack@1.1.2", + "PkgName": "msgpack", + "PkgIdentifier": { + "PURL": "pkg:pypi/msgpack@1.1.2", + "UID": "9d7d565367050f92", + "BOMRef": "pkg:pypi/msgpack@1.1.2" + }, + "InstalledVersion": "1.1.2", + "FixedVersion": "1.2.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://github.com/advisories/GHSA-6v7p-g79w-8964", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:44031fc1c3c11a91b2f2f4160b1ab573f506d4a3b738994f6502116a86734c90", + "Title": "MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error", + "Description": "### Impact\n\nIf the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.\n\nIf the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.\n\n### Patches\n\nv1.2.1\n\n### Workarounds\n\nUsers should create a new Unpacker instead of reusing the same Unpacker after an error occurs.\n\nApplying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct data. If an error occurs during Streaming Unpacking, the Stream and Streaming Unpacker should be discarded.\n\nTherefore, this is not just a workaround but the correct solution. The above patch only prevents crashes from incorrect usage.", + "Severity": "HIGH", + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/msgpack/msgpack-python", + "https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d", + "https://github.com/msgpack/msgpack-python/releases/tag/v1.2.1", + "https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964" + ], + "PublishedDate": "2026-06-19T21:42:55Z", + "LastModifiedDate": "2026-06-19T21:42:55Z" + }, + { + "VulnerabilityID": "CVE-2025-47273", + "VendorIDs": [ + "GHSA-5rjg-fvgr-3xxf" + ], + "PkgID": "setuptools@70.3.0", + "PkgName": "setuptools", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@70.3.0", + "UID": "4bc74a0ad6dbc16b", + "BOMRef": "pkg:pypi/setuptools@70.3.0" + }, + "InstalledVersion": "70.3.0", + "FixedVersion": "78.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:83071e5190369ba312251b2baecbcbd3017ee229900d4f9fe2158e1d5e54c708", + "DiffID": "sha256:e6af94c1062188a2f669eeda958175f4f0a948a63808668e3579020c93f314eb" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47273", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:9a081cae88965569ac9cd7857e9f6b77a6a37a2293dfc7399f317829acbe209e", + "Title": "setuptools: Path Traversal Vulnerability in setuptools PackageIndex", + "Description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:10407", + "https://access.redhat.com/errata/RHSA-2025:13578", + "https://access.redhat.com/security/cve/CVE-2025-47273", + "https://bugzilla.redhat.com/2366982", + "https://bugzilla.redhat.com/show_bug.cgi?id=2366982", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47273", + "https://errata.almalinux.org/9/ALSA-2025-13578.html", + "https://errata.rockylinux.org/RLSA-2025:10407", + "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88", + "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b", + "https://github.com/pypa/setuptools/issues/4946", + "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf", + "https://linux.oracle.com/cve/CVE-2025-47273.html", + "https://linux.oracle.com/errata/ELSA-2025-9940.html", + "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47273", + "https://ubuntu.com/security/notices/USN-7544-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47273" + ], + "PublishedDate": "2025-05-17T16:15:19.11Z", + "LastModifiedDate": "2026-06-17T09:27:38.827Z" + } + ] + } + ] +} diff --git a/output/security/minio-container-audit.json b/output/security/minio-container-audit.json new file mode 100644 index 0000000..a49fb72 --- /dev/null +++ b/output/security/minio-container-audit.json @@ -0,0 +1,39625 @@ +{ + "SchemaVersion": 2, + "Trivy": { + "Version": "0.74.0" + }, + "ReportID": "01a0a011-bc7a-769e-8e59-7167cbdf1fd9", + "CreatedAt": "2026-09-14T13:18:32.058437987Z", + "ArtifactID": "sha256:b0021c51a5a85985af4ddfab010e224b69cd831568285691b9b13db9ee76fcb2", + "ArtifactName": "minio/minio:RELEASE.2025-04-22T22-12-26Z", + "ArtifactType": "container_image", + "Metadata": { + "Size": 183746048, + "OS": { + "Family": "redhat", + "Name": "9.5" + }, + "ImageID": "sha256:a1ea29fa28355559ef137d71fc570e508a214ec84ff8083e39bc5428980b015e", + "DiffIDs": [ + "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e", + "sha256:bc8d5ed2193938439a95fa8b8256301104924deaa5e2df62026818a9b92619b6", + "sha256:1e5736bac4860c785c0fe3cfd874e5fd7e4631941b4919b67333665bdcdd33d4", + "sha256:377437d01d363dfac06639b2e942d0086e6c4b0afeee0da67c058a0e6e2c3ae7", + "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5", + "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e", + "sha256:4db63df9b91482cf93a66f5d34242f617cea615377972dd8674177c039ee1c20", + "sha256:cb743dd6c4f365b166bfec3332c98bcbc2b2116cf87dbee9ca90db7d14d3db42", + "sha256:f25e4be494e05101f9bf80f741a571357a2439838c19feea243fdb51d8ed4b9e", + "sha256:7ecae2500df912b4f6c8fae4abc21832758cfdf70998dff9f83d90d33d5d48dc" + ], + "RepoTags": [ + "minio/minio:RELEASE.2025-04-22T22-12-26Z" + ], + "RepoDigests": [ + "minio/minio@sha256:a1ea29fa28355559ef137d71fc570e508a214ec84ff8083e39bc5428980b015e" + ], + "Reference": "minio/minio:RELEASE.2025-04-22T22-12-26Z", + "ImageConfig": { + "architecture": "amd64", + "created": "2025-04-22T22:35:01.339428192Z", + "history": [ + { + "created": "2025-04-08T13:18:27.257570981Z", + "created_by": "/bin/sh -c #(nop) LABEL maintainer=\"Red Hat, Inc.\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.27281221Z", + "created_by": "/bin/sh -c #(nop) LABEL vendor=\"Red Hat, Inc.\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.288233662Z", + "created_by": "/bin/sh -c #(nop) LABEL url=\"https://www.redhat.com\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.302998822Z", + "created_by": "/bin/sh -c #(nop) LABEL com.redhat.component=\"ubi9-micro-container\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.317878945Z", + "created_by": "/bin/sh -c #(nop) LABEL name=\"ubi9/ubi-micro\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.332983541Z", + "created_by": "/bin/sh -c #(nop) LABEL version=\"9.5\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.347414426Z", + "created_by": "/bin/sh -c #(nop) LABEL distribution-scope=\"public\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.362465591Z", + "created_by": "/bin/sh -c #(nop) LABEL com.redhat.license_terms=\"https://www.redhat.com/en/about/red-hat-end-user-license-agreements#UBI\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.377628099Z", + "created_by": "/bin/sh -c #(nop) LABEL summary=\"ubi9 micro image\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.393741772Z", + "created_by": "/bin/sh -c #(nop) LABEL description=\"Very small image which doesn't install the package manager.\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.409833805Z", + "created_by": "/bin/sh -c #(nop) LABEL io.k8s.description=\"Very small image which doesn't install the package manager.\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.426163903Z", + "created_by": "/bin/sh -c #(nop) LABEL io.k8s.display-name=\"Red Hat Universal Base Image 9 Micro\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.441469282Z", + "created_by": "/bin/sh -c #(nop) LABEL io.openshift.expose-services=\"\"", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.628468866Z", + "created_by": "/bin/sh -c #(nop) COPY dir:e090fe0145de863f979c9f4d5f82227794d4b5093816cb9fbf959c10a2c1dc02 in / ", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.714517006Z", + "created_by": "/bin/sh -c #(nop) COPY file:b37d593713ee21ad52a4cd1424dc019a24f7966f85df0ac4b86d234302695328 in /etc/yum.repos.d/ ", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.732323368Z", + "created_by": "/bin/sh -c #(nop) CMD /bin/sh", + "empty_layer": true + }, + { + "created": "2025-04-08T13:18:27.82076626Z", + "created_by": "/bin/sh -c #(nop) LABEL \"build-date\"=\"2025-04-08T13:18:18\" \"architecture\"=\"x86_64\" \"vcs-type\"=\"git\" \"vcs-ref\"=\"519a52b1bc2ef31e2633c20f34a0df840e159172\" \"build-date\"=\"2025-04-08T13:14:37Z\" \"release\"=\"1744118077\"" + }, + { + "created": "2025-04-08T13:18:31.000302221Z", + "created_by": "/bin/sh", + "comment": "FROM quay.io/redhat-user-workloads/osci-rhel-containers-tenant/rhel-9-5/ubi9-micro-9-5:519a52b1bc2ef31e2633c20f34a0df840e159172-linux-x86-64" + }, + { + "created": "2025-04-22T22:34:38.073800107Z", + "created_by": "ARG RELEASE=RELEASE.2025-04-22T22-12-26Z", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2025-04-22T22:34:38.073800107Z", + "created_by": "LABEL name=MinIO vendor=MinIO Inc \u003cdev@min.io\u003e maintainer=MinIO Inc \u003cdev@min.io\u003e version=RELEASE.2025-04-22T22-12-26Z release=RELEASE.2025-04-22T22-12-26Z summary=MinIO is a High Performance Object Storage, API compatible with Amazon S3 cloud storage service. description=MinIO object storage is fundamentally different. Designed for performance and the S3 API, it is 100% open-source. MinIO is ideal for large, private cloud environments with stringent security requirements and delivers mission-critical availability across a diverse range of workloads.", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2025-04-22T22:34:38.073800107Z", + "created_by": "ENV MINIO_ACCESS_KEY_FILE=access_key MINIO_SECRET_KEY_FILE=secret_key MINIO_ROOT_USER_FILE=access_key MINIO_ROOT_PASSWORD_FILE=secret_key MINIO_KMS_SECRET_KEY_FILE=kms_master_key MINIO_UPDATE_MINISIGN_PUBKEY=RWTx5Zr1tiHQLwG9keckT0c45M3AGeHD6IvimQHpyRywVWGbP1aVSGav MINIO_CONFIG_ENV_FILE=config.env MC_CONFIG_DIR=/tmp/.mc", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2025-04-22T22:34:38.073800107Z", + "created_by": "RUN |1 RELEASE=RELEASE.2025-04-22T22-12-26Z /bin/sh -c chmod -R 777 /usr/bin # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2025-04-22T22:35:00.985056588Z", + "created_by": "COPY /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2025-04-22T22:35:01.021887301Z", + "created_by": "COPY /go/bin/minio* /usr/bin/ # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2025-04-22T22:35:01.202201472Z", + "created_by": "COPY /go/bin/mc* /usr/bin/ # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2025-04-22T22:35:01.236599948Z", + "created_by": "COPY /go/bin/curl* /usr/bin/ # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2025-04-22T22:35:01.27946432Z", + "created_by": "COPY CREDITS /licenses/CREDITS # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2025-04-22T22:35:01.310192937Z", + "created_by": "COPY LICENSE /licenses/LICENSE # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2025-04-22T22:35:01.339428192Z", + "created_by": "COPY dockerscripts/docker-entrypoint.sh /usr/bin/docker-entrypoint.sh # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2025-04-22T22:35:01.339428192Z", + "created_by": "EXPOSE map[9000/tcp:{}]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2025-04-22T22:35:01.339428192Z", + "created_by": "VOLUME [/data]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2025-04-22T22:35:01.339428192Z", + "created_by": "ENTRYPOINT [\"/usr/bin/docker-entrypoint.sh\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2025-04-22T22:35:01.339428192Z", + "created_by": "CMD [\"minio\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + } + ], + "os": "linux", + "rootfs": { + "type": "layers", + "diff_ids": [ + "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e", + "sha256:bc8d5ed2193938439a95fa8b8256301104924deaa5e2df62026818a9b92619b6", + "sha256:1e5736bac4860c785c0fe3cfd874e5fd7e4631941b4919b67333665bdcdd33d4", + "sha256:377437d01d363dfac06639b2e942d0086e6c4b0afeee0da67c058a0e6e2c3ae7", + "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5", + "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e", + "sha256:4db63df9b91482cf93a66f5d34242f617cea615377972dd8674177c039ee1c20", + "sha256:cb743dd6c4f365b166bfec3332c98bcbc2b2116cf87dbee9ca90db7d14d3db42", + "sha256:f25e4be494e05101f9bf80f741a571357a2439838c19feea243fdb51d8ed4b9e", + "sha256:7ecae2500df912b4f6c8fae4abc21832758cfdf70998dff9f83d90d33d5d48dc" + ] + }, + "config": { + "Cmd": [ + "minio" + ], + "Entrypoint": [ + "/usr/bin/docker-entrypoint.sh" + ], + "Env": [ + "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", + "MINIO_ACCESS_KEY_FILE=access_key", + "MINIO_SECRET_KEY_FILE=secret_key", + "MINIO_ROOT_USER_FILE=access_key", + "MINIO_ROOT_PASSWORD_FILE=secret_key", + "MINIO_KMS_SECRET_KEY_FILE=kms_master_key", + "MINIO_UPDATE_MINISIGN_PUBKEY=RWTx5Zr1tiHQLwG9keckT0c45M3AGeHD6IvimQHpyRywVWGbP1aVSGav", + "MINIO_CONFIG_ENV_FILE=config.env", + "MC_CONFIG_DIR=/tmp/.mc" + ], + "Labels": { + "architecture": "x86_64", + "build-date": "2025-04-08T13:14:37Z", + "com.redhat.component": "ubi9-micro-container", + "com.redhat.license_terms": "https://www.redhat.com/en/about/red-hat-end-user-license-agreements#UBI", + "description": "MinIO object storage is fundamentally different. Designed for performance and the S3 API, it is 100% open-source. MinIO is ideal for large, private cloud environments with stringent security requirements and delivers mission-critical availability across a diverse range of workloads.", + "distribution-scope": "public", + "io.buildah.version": "1.39.0-dev", + "io.k8s.description": "Very small image which doesn't install the package manager.", + "io.k8s.display-name": "Red Hat Universal Base Image 9 Micro", + "io.openshift.expose-services": "", + "maintainer": "MinIO Inc \u003cdev@min.io\u003e", + "name": "MinIO", + "release": "RELEASE.2025-04-22T22-12-26Z", + "summary": "MinIO is a High Performance Object Storage, API compatible with Amazon S3 cloud storage service.", + "url": "https://www.redhat.com", + "vcs-ref": "519a52b1bc2ef31e2633c20f34a0df840e159172", + "vcs-type": "git", + "vendor": "MinIO Inc \u003cdev@min.io\u003e", + "version": "RELEASE.2025-04-22T22-12-26Z" + }, + "Volumes": { + "/data": {} + }, + "WorkingDir": "/", + "ExposedPorts": { + "9000/tcp": {} + }, + "ArgsEscaped": true + } + }, + "Layers": [ + { + "Size": 23498752, + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + { + "Size": 4096, + "Digest": "sha256:8c577d69454d55b6e5bffdebaaa4026898f417005e86dba1bca027935774c21f", + "DiffID": "sha256:bc8d5ed2193938439a95fa8b8256301104924deaa5e2df62026818a9b92619b6" + }, + { + "Size": 3547136, + "Digest": "sha256:546fbfcace6536ab2e96351ffe76b9431dfbaa742a5fe7a76e6920f1d8383b71", + "DiffID": "sha256:1e5736bac4860c785c0fe3cfd874e5fd7e4631941b4919b67333665bdcdd33d4" + }, + { + "Size": 225792, + "Digest": "sha256:d0c8865a030236212964e817f56a5554cdebb8ecb04909756282ce5e2f2b41c4", + "DiffID": "sha256:377437d01d363dfac06639b2e942d0086e6c4b0afeee0da67c058a0e6e2c3ae7" + }, + { + "Size": 118854656, + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + { + "Size": 30184448, + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + { + "Size": 5506048, + "Digest": "sha256:62481e699c81d80a3df48f9a08a8bea10918ac8981ff00b5d09a8098156ac75e", + "DiffID": "sha256:4db63df9b91482cf93a66f5d34242f617cea615377972dd8674177c039ee1c20" + }, + { + "Size": 1884672, + "Digest": "sha256:68a66c893f7ce4098eac3f50758c8e2b6aa8750b979ca90345609eb3af0a95b9", + "DiffID": "sha256:cb743dd6c4f365b166bfec3332c98bcbc2b2116cf87dbee9ca90db7d14d3db42" + }, + { + "Size": 36864, + "Digest": "sha256:d7ab9c0b242a9f5411ee1b71ab98134a0e7505cd0a632b0dcf446ad43e97c570", + "DiffID": "sha256:f25e4be494e05101f9bf80f741a571357a2439838c19feea243fdb51d8ed4b9e" + }, + { + "Size": 3584, + "Digest": "sha256:39c8ce9a80d2ca7f544f57a5a00617176a86e0760bc1aa46cf17d3f34bf3807d", + "DiffID": "sha256:7ecae2500df912b4f6c8fae4abc21832758cfdf70998dff9f83d90d33d5d48dc" + } + ] + }, + "Results": [ + { + "Target": "minio/minio:RELEASE.2025-04-22T22-12-26Z (redhat 9.5)", + "Class": "os-pkgs", + "Type": "redhat", + "Packages": [ + { + "ID": "basesystem@11-13.el9.noarch", + "Name": "basesystem", + "Identifier": { + "PURL": "pkg:rpm/redhat/basesystem@11-13.el9?arch=noarch\u0026distro=redhat-9.5", + "UID": "1c862ae7d0e741ec" + }, + "Version": "11", + "Release": "13.el9", + "Arch": "noarch", + "SrcName": "basesystem", + "SrcVersion": "11", + "SrcRelease": "13.el9", + "Licenses": [ + "Public Domain" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "filesystem@3.16-5.el9.x86_64", + "setup@2.13.7-10.el9.noarch" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:16605e0013938a5e21ffdf777cfa86ce", + "AnalyzedBy": "rpm" + }, + { + "ID": "bash@5.1.8-9.el9.x86_64", + "Name": "bash", + "Identifier": { + "PURL": "pkg:rpm/redhat/bash@5.1.8-9.el9?arch=x86_64\u0026distro=redhat-9.5", + "UID": "395fa8d3cbf3cbfe" + }, + "Version": "5.1.8", + "Release": "9.el9", + "Arch": "x86_64", + "SrcName": "bash", + "SrcVersion": "5.1.8", + "SrcRelease": "9.el9", + "Licenses": [ + "GPLv3+" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "filesystem@3.16-5.el9.x86_64", + "glibc@2.34-125.el9_5.3.x86_64", + "ncurses-libs@6.2-10.20210508.el9.x86_64" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:57e93b1739cc3512f9f29dcaa8a38055", + "InstalledFiles": [ + "/etc/skel/.bash_logout", + "/etc/skel/.bash_profile", + "/etc/skel/.bashrc", + "/usr/bin/alias", + "/usr/bin/bash", + "/usr/bin/bashbug", + "/usr/bin/bashbug-64", + "/usr/bin/bg", + "/usr/bin/cd", + "/usr/bin/command", + "/usr/bin/fc", + "/usr/bin/fg", + "/usr/bin/getopts", + "/usr/bin/hash", + "/usr/bin/jobs", + "/usr/bin/read", + "/usr/bin/sh", + "/usr/bin/type", + "/usr/bin/ulimit", + "/usr/bin/umask", + "/usr/bin/unalias", + "/usr/bin/wait", + "/usr/lib/.build-id", + "/usr/lib/.build-id/42", + "/usr/lib/.build-id/42/cf5733b0cde9cc1e03a785e0b32b4b1caa147f", + "/usr/share/doc/bash", + "/usr/share/doc/bash/FAQ", + "/usr/share/doc/bash/INTRO", + "/usr/share/doc/bash/RBASH", + "/usr/share/doc/bash/README", + "/usr/share/doc/bash/bash.html", + "/usr/share/doc/bash/bashref.html", + "/usr/share/info/bash.info.gz", + "/usr/share/licenses/bash", + "/usr/share/licenses/bash/COPYING", + "/usr/share/locale/af/LC_MESSAGES/bash.mo", + "/usr/share/locale/bg/LC_MESSAGES/bash.mo", + "/usr/share/locale/ca/LC_MESSAGES/bash.mo", + "/usr/share/locale/cs/LC_MESSAGES/bash.mo", + "/usr/share/locale/da/LC_MESSAGES/bash.mo", + "/usr/share/locale/de/LC_MESSAGES/bash.mo", + "/usr/share/locale/el/LC_MESSAGES/bash.mo", + "/usr/share/locale/en@boldquot/LC_MESSAGES/bash.mo", + "/usr/share/locale/en@quot/LC_MESSAGES/bash.mo", + "/usr/share/locale/eo/LC_MESSAGES/bash.mo", + "/usr/share/locale/es/LC_MESSAGES/bash.mo", + "/usr/share/locale/et/LC_MESSAGES/bash.mo", + "/usr/share/locale/fi/LC_MESSAGES/bash.mo", + "/usr/share/locale/fr/LC_MESSAGES/bash.mo", + "/usr/share/locale/ga/LC_MESSAGES/bash.mo", + "/usr/share/locale/gl/LC_MESSAGES/bash.mo", + "/usr/share/locale/hr/LC_MESSAGES/bash.mo", + "/usr/share/locale/hu/LC_MESSAGES/bash.mo", + "/usr/share/locale/id/LC_MESSAGES/bash.mo", + "/usr/share/locale/it/LC_MESSAGES/bash.mo", + "/usr/share/locale/ja/LC_MESSAGES/bash.mo", + "/usr/share/locale/ko/LC_MESSAGES/bash.mo", + "/usr/share/locale/lt/LC_MESSAGES/bash.mo", + "/usr/share/locale/nb/LC_MESSAGES/bash.mo", + "/usr/share/locale/nl/LC_MESSAGES/bash.mo", + "/usr/share/locale/pl/LC_MESSAGES/bash.mo", + "/usr/share/locale/pt/LC_MESSAGES/bash.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/bash.mo", + "/usr/share/locale/ro/LC_MESSAGES/bash.mo", + "/usr/share/locale/ru/LC_MESSAGES/bash.mo", + "/usr/share/locale/sk/LC_MESSAGES/bash.mo", + "/usr/share/locale/sl/LC_MESSAGES/bash.mo", + "/usr/share/locale/sr/LC_MESSAGES/bash.mo", + "/usr/share/locale/sv/LC_MESSAGES/bash.mo", + "/usr/share/locale/tr/LC_MESSAGES/bash.mo", + "/usr/share/locale/uk/LC_MESSAGES/bash.mo", + "/usr/share/locale/vi/LC_MESSAGES/bash.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/bash.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/bash.mo", + "/usr/share/man/man1/..1.gz", + "/usr/share/man/man1/:.1.gz", + "/usr/share/man/man1/[.1.gz", + "/usr/share/man/man1/alias.1.gz", + "/usr/share/man/man1/bash.1.gz", + "/usr/share/man/man1/bashbug-64.1.gz", + "/usr/share/man/man1/bashbug.1.gz", + "/usr/share/man/man1/bg.1.gz", + "/usr/share/man/man1/bind.1.gz", + "/usr/share/man/man1/break.1.gz", + "/usr/share/man/man1/builtin.1.gz", + "/usr/share/man/man1/builtins.1.gz", + "/usr/share/man/man1/caller.1.gz", + "/usr/share/man/man1/cd.1.gz", + "/usr/share/man/man1/command.1.gz", + "/usr/share/man/man1/compgen.1.gz", + "/usr/share/man/man1/complete.1.gz", + "/usr/share/man/man1/compopt.1.gz", + "/usr/share/man/man1/continue.1.gz", + "/usr/share/man/man1/declare.1.gz", + "/usr/share/man/man1/dirs.1.gz", + "/usr/share/man/man1/disown.1.gz", + "/usr/share/man/man1/enable.1.gz", + "/usr/share/man/man1/eval.1.gz", + "/usr/share/man/man1/exec.1.gz", + "/usr/share/man/man1/exit.1.gz", + "/usr/share/man/man1/export.1.gz", + "/usr/share/man/man1/fc.1.gz", + "/usr/share/man/man1/fg.1.gz", + "/usr/share/man/man1/getopts.1.gz", + "/usr/share/man/man1/hash.1.gz", + "/usr/share/man/man1/help.1.gz", + "/usr/share/man/man1/history.1.gz", + "/usr/share/man/man1/jobs.1.gz", + "/usr/share/man/man1/let.1.gz", + "/usr/share/man/man1/local.1.gz", + "/usr/share/man/man1/logout.1.gz", + "/usr/share/man/man1/mapfile.1.gz", + "/usr/share/man/man1/popd.1.gz", + "/usr/share/man/man1/pushd.1.gz", + "/usr/share/man/man1/read.1.gz", + "/usr/share/man/man1/readonly.1.gz", + "/usr/share/man/man1/return.1.gz", + "/usr/share/man/man1/set.1.gz", + "/usr/share/man/man1/sh.1.gz", + "/usr/share/man/man1/shift.1.gz", + "/usr/share/man/man1/shopt.1.gz", + "/usr/share/man/man1/source.1.gz", + "/usr/share/man/man1/suspend.1.gz", + "/usr/share/man/man1/times.1.gz", + "/usr/share/man/man1/trap.1.gz", + "/usr/share/man/man1/type.1.gz", + "/usr/share/man/man1/typeset.1.gz", + "/usr/share/man/man1/ulimit.1.gz", + "/usr/share/man/man1/umask.1.gz", + "/usr/share/man/man1/unalias.1.gz", + "/usr/share/man/man1/unset.1.gz", + "/usr/share/man/man1/wait.1.gz" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "coreutils-single@8.32-36.el9.x86_64", + "Name": "coreutils-single", + "Identifier": { + "PURL": "pkg:rpm/redhat/coreutils-single@8.32-36.el9?arch=x86_64\u0026distro=redhat-9.5", + "UID": "a716f72869f12955" + }, + "Version": "8.32", + "Release": "36.el9", + "Arch": "x86_64", + "SrcName": "coreutils", + "SrcVersion": "8.32", + "SrcRelease": "36.el9", + "Licenses": [ + "GPLv3+" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "glibc@2.34-125.el9_5.3.x86_64", + "libacl@2.3.1-4.el9.x86_64", + "libattr@2.5.1-3.el9.x86_64", + "libcap@2.48-9.el9_2.x86_64", + "libselinux@3.6-1.el9.x86_64" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:c609233846d156be82a31c09a203270e", + "InstalledFiles": [ + "/usr/bin/[", + "/usr/bin/arch", + "/usr/bin/b2sum", + "/usr/bin/base32", + "/usr/bin/base64", + "/usr/bin/basename", + "/usr/bin/basenc", + "/usr/bin/cat", + "/usr/bin/chcon", + "/usr/bin/chgrp", + "/usr/bin/chmod", + "/usr/bin/chown", + "/usr/bin/cksum", + "/usr/bin/comm", + "/usr/bin/coreutils", + "/usr/bin/cp", + "/usr/bin/csplit", + "/usr/bin/cut", + "/usr/bin/date", + "/usr/bin/dd", + "/usr/bin/df", + "/usr/bin/dir", + "/usr/bin/dircolors", + "/usr/bin/dirname", + "/usr/bin/du", + "/usr/bin/echo", + "/usr/bin/env", + "/usr/bin/expand", + "/usr/bin/expr", + "/usr/bin/factor", + "/usr/bin/false", + "/usr/bin/fmt", + "/usr/bin/fold", + "/usr/bin/groups", + "/usr/bin/head", + "/usr/bin/hostid", + "/usr/bin/id", + "/usr/bin/install", + "/usr/bin/join", + "/usr/bin/link", + "/usr/bin/ln", + "/usr/bin/logname", + "/usr/bin/ls", + "/usr/bin/md5sum", + "/usr/bin/mkdir", + "/usr/bin/mkfifo", + "/usr/bin/mknod", + "/usr/bin/mktemp", + "/usr/bin/mv", + "/usr/bin/nice", + "/usr/bin/nl", + "/usr/bin/nohup", + "/usr/bin/nproc", + "/usr/bin/numfmt", + "/usr/bin/od", + "/usr/bin/paste", + "/usr/bin/pathchk", + "/usr/bin/pinky", + "/usr/bin/pr", + "/usr/bin/printenv", + "/usr/bin/printf", + "/usr/bin/ptx", + "/usr/bin/pwd", + "/usr/bin/readlink", + "/usr/bin/realpath", + "/usr/bin/rm", + "/usr/bin/rmdir", + "/usr/bin/runcon", + "/usr/bin/seq", + "/usr/bin/sha1sum", + "/usr/bin/sha224sum", + "/usr/bin/sha256sum", + "/usr/bin/sha384sum", + "/usr/bin/sha512sum", + "/usr/bin/shred", + "/usr/bin/shuf", + "/usr/bin/sleep", + "/usr/bin/sort", + "/usr/bin/split", + "/usr/bin/stat", + "/usr/bin/stdbuf", + "/usr/bin/stty", + "/usr/bin/sum", + "/usr/bin/sync", + "/usr/bin/tac", + "/usr/bin/tail", + "/usr/bin/tee", + "/usr/bin/test", + "/usr/bin/timeout", + "/usr/bin/touch", + "/usr/bin/tr", + "/usr/bin/true", + "/usr/bin/truncate", + "/usr/bin/tsort", + "/usr/bin/tty", + "/usr/bin/uname", + "/usr/bin/unexpand", + "/usr/bin/uniq", + "/usr/bin/unlink", + "/usr/bin/users", + "/usr/bin/vdir", + "/usr/bin/wc", + "/usr/bin/who", + "/usr/bin/whoami", + "/usr/bin/yes", + "/usr/lib/.build-id", + "/usr/lib/.build-id/0c/6d9b71bad8a4c6ed5dc55276123a815c8251df", + "/usr/lib/.build-id/97/93dc4273c18b618f92efcf9b3b3052138b3b6c", + "/usr/libexec/coreutils", + "/usr/libexec/coreutils/libstdbuf.so", + "/usr/sbin/chroot", + "/usr/share/licenses/coreutils-single", + "/usr/share/licenses/coreutils-single/COPYING" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "filesystem@3.16-5.el9.x86_64", + "Name": "filesystem", + "Identifier": { + "PURL": "pkg:rpm/redhat/filesystem@3.16-5.el9?arch=x86_64\u0026distro=redhat-9.5", + "UID": "6011bafd08a11476" + }, + "Version": "3.16", + "Release": "5.el9", + "Arch": "x86_64", + "SrcName": "filesystem", + "SrcVersion": "3.16", + "SrcRelease": "5.el9", + "Licenses": [ + "Public Domain" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "bash@5.1.8-9.el9.x86_64", + "setup@2.13.7-10.el9.noarch" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:af1812d471b0fc3456fa0a17b3500775", + "InstalledFiles": [ + "/", + "/afs", + "/bin", + "/boot", + "/dev", + "/etc", + "/etc/X11", + "/etc/X11/applnk", + "/etc/X11/fontpath.d", + "/etc/X11/xinit", + "/etc/X11/xinit/xinitrc.d", + "/etc/X11/xinit/xinput.d", + "/etc/bash_completion.d", + "/etc/default", + "/etc/opt", + "/etc/pki", + "/etc/pm", + "/etc/pm/config.d", + "/etc/pm/power.d", + "/etc/pm/sleep.d", + "/etc/rwtab.d", + "/etc/skel", + "/etc/statetab.d", + "/etc/sysconfig", + "/etc/xdg", + "/etc/xdg/autostart", + "/home", + "/lib", + "/lib64", + "/media", + "/mnt", + "/opt", + "/proc", + "/root", + "/run", + "/sbin", + "/srv", + "/sys", + "/tmp", + "/usr", + "/usr/bin", + "/usr/games", + "/usr/include", + "/usr/lib", + "/usr/lib/debug", + "/usr/lib/debug/.dwz", + "/usr/lib/debug/bin", + "/usr/lib/debug/lib", + "/usr/lib/debug/lib64", + "/usr/lib/debug/sbin", + "/usr/lib/debug/usr", + "/usr/lib/debug/usr/.dwz", + "/usr/lib/debug/usr/bin", + "/usr/lib/debug/usr/lib", + "/usr/lib/debug/usr/lib64", + "/usr/lib/debug/usr/sbin", + "/usr/lib/games", + "/usr/lib/locale", + "/usr/lib/modules", + "/usr/lib/sysimage", + "/usr/lib64", + "/usr/lib64/X11", + "/usr/lib64/bpf", + "/usr/lib64/games", + "/usr/lib64/pm-utils", + "/usr/lib64/pm-utils/module.d", + "/usr/lib64/pm-utils/power.d", + "/usr/lib64/pm-utils/sleep.d", + "/usr/libexec", + "/usr/local", + "/usr/local/bin", + "/usr/local/etc", + "/usr/local/games", + "/usr/local/include", + "/usr/local/lib", + "/usr/local/lib64", + "/usr/local/lib64/bpf", + "/usr/local/libexec", + "/usr/local/sbin", + "/usr/local/share", + "/usr/local/share/applications", + "/usr/local/share/info", + "/usr/local/share/man", + "/usr/local/share/man/man1", + "/usr/local/share/man/man1x", + "/usr/local/share/man/man2", + "/usr/local/share/man/man2x", + "/usr/local/share/man/man3", + "/usr/local/share/man/man3x", + "/usr/local/share/man/man4", + "/usr/local/share/man/man4x", + "/usr/local/share/man/man5", + "/usr/local/share/man/man5x", + "/usr/local/share/man/man6", + "/usr/local/share/man/man6x", + "/usr/local/share/man/man7", + "/usr/local/share/man/man7x", + "/usr/local/share/man/man8", + "/usr/local/share/man/man8x", + "/usr/local/share/man/man9", + "/usr/local/share/man/man9x", + "/usr/local/share/man/mann", + "/usr/local/src", + "/usr/sbin", + "/usr/share", + "/usr/share/X11", + "/usr/share/X11/fonts", + "/usr/share/aclocal", + "/usr/share/appdata", + "/usr/share/applications", + "/usr/share/augeas", + "/usr/share/augeas/lenses", + "/usr/share/backgrounds", + "/usr/share/bash-completion", + "/usr/share/bash-completion/completions", + "/usr/share/bash-completion/helpers", + "/usr/share/desktop-directories", + "/usr/share/dict", + "/usr/share/doc", + "/usr/share/empty", + "/usr/share/fish", + "/usr/share/fish/vendor_completions.d", + "/usr/share/games", + "/usr/share/gnome", + "/usr/share/help", + "/usr/share/icons", + "/usr/share/idl", + "/usr/share/info", + "/usr/share/licenses", + "/usr/share/locale", + "/usr/share/locale/aa", + "/usr/share/locale/aa/LC_MESSAGES", + "/usr/share/locale/ab", + "/usr/share/locale/ab/LC_MESSAGES", + "/usr/share/locale/ace", + "/usr/share/locale/ace/LC_MESSAGES", + "/usr/share/locale/ach", + "/usr/share/locale/ach/LC_MESSAGES", + "/usr/share/locale/ada", + "/usr/share/locale/ada/LC_MESSAGES", + "/usr/share/locale/ady", + "/usr/share/locale/ady/LC_MESSAGES", + "/usr/share/locale/ae", + "/usr/share/locale/ae/LC_MESSAGES", + "/usr/share/locale/af", + "/usr/share/locale/af/LC_MESSAGES", + "/usr/share/locale/af_ZA", + "/usr/share/locale/af_ZA/LC_MESSAGES", + "/usr/share/locale/afa", + "/usr/share/locale/afa/LC_MESSAGES", + "/usr/share/locale/afh", + "/usr/share/locale/afh/LC_MESSAGES", + "/usr/share/locale/agr", + "/usr/share/locale/agr/LC_MESSAGES", + "/usr/share/locale/ain", + "/usr/share/locale/ain/LC_MESSAGES", + "/usr/share/locale/ak", + "/usr/share/locale/ak/LC_MESSAGES", + "/usr/share/locale/akk", + "/usr/share/locale/akk/LC_MESSAGES", + "/usr/share/locale/ale", + "/usr/share/locale/ale/LC_MESSAGES", + "/usr/share/locale/alg", + "/usr/share/locale/alg/LC_MESSAGES", + "/usr/share/locale/aln", + "/usr/share/locale/aln/LC_MESSAGES", + "/usr/share/locale/alt", + "/usr/share/locale/alt/LC_MESSAGES", + "/usr/share/locale/am", + "/usr/share/locale/am/LC_MESSAGES", + "/usr/share/locale/an", + "/usr/share/locale/an/LC_MESSAGES", + "/usr/share/locale/ang", + "/usr/share/locale/ang/LC_MESSAGES", + "/usr/share/locale/anp", + "/usr/share/locale/anp/LC_MESSAGES", + "/usr/share/locale/apa", + "/usr/share/locale/apa/LC_MESSAGES", + "/usr/share/locale/ar", + "/usr/share/locale/ar/LC_MESSAGES", + "/usr/share/locale/ar_DZ", + "/usr/share/locale/ar_DZ/LC_MESSAGES", + "/usr/share/locale/ar_SY", + "/usr/share/locale/ar_SY/LC_MESSAGES", + "/usr/share/locale/arc", + "/usr/share/locale/arc/LC_MESSAGES", + "/usr/share/locale/arn", + "/usr/share/locale/arn/LC_MESSAGES", + "/usr/share/locale/arp", + "/usr/share/locale/arp/LC_MESSAGES", + "/usr/share/locale/art", + "/usr/share/locale/art/LC_MESSAGES", + "/usr/share/locale/arw", + "/usr/share/locale/arw/LC_MESSAGES", + "/usr/share/locale/as", + "/usr/share/locale/as/LC_MESSAGES", + "/usr/share/locale/ast", + "/usr/share/locale/ast/LC_MESSAGES", + "/usr/share/locale/ath", + "/usr/share/locale/ath/LC_MESSAGES", + "/usr/share/locale/aus", + "/usr/share/locale/aus/LC_MESSAGES", + "/usr/share/locale/av", + "/usr/share/locale/av/LC_MESSAGES", + "/usr/share/locale/awa", + "/usr/share/locale/awa/LC_MESSAGES", + "/usr/share/locale/ay", + "/usr/share/locale/ay/LC_MESSAGES", + "/usr/share/locale/ayc", + "/usr/share/locale/ayc/LC_MESSAGES", + "/usr/share/locale/aym", + "/usr/share/locale/aym/LC_MESSAGES", + "/usr/share/locale/az", + "/usr/share/locale/az/LC_MESSAGES", + "/usr/share/locale/az_AZ", + "/usr/share/locale/az_AZ/LC_MESSAGES", + "/usr/share/locale/az_IR", + "/usr/share/locale/az_IR/LC_MESSAGES", + "/usr/share/locale/ba", + "/usr/share/locale/ba/LC_MESSAGES", + "/usr/share/locale/bad", + "/usr/share/locale/bad/LC_MESSAGES", + "/usr/share/locale/bai", + "/usr/share/locale/bai/LC_MESSAGES", + "/usr/share/locale/bal", + "/usr/share/locale/bal/LC_MESSAGES", + "/usr/share/locale/ban", + "/usr/share/locale/ban/LC_MESSAGES", + "/usr/share/locale/bas", + "/usr/share/locale/bas/LC_MESSAGES", + "/usr/share/locale/bat", + "/usr/share/locale/bat/LC_MESSAGES", + "/usr/share/locale/be", + "/usr/share/locale/be/LC_MESSAGES", + "/usr/share/locale/be@latin", + "/usr/share/locale/be@latin/LC_MESSAGES", + "/usr/share/locale/bej", + "/usr/share/locale/bej/LC_MESSAGES", + "/usr/share/locale/bem", + "/usr/share/locale/bem/LC_MESSAGES", + "/usr/share/locale/ber", + "/usr/share/locale/ber/LC_MESSAGES", + "/usr/share/locale/bg", + "/usr/share/locale/bg/LC_MESSAGES", + "/usr/share/locale/bg_BG", + "/usr/share/locale/bg_BG/LC_MESSAGES", + "/usr/share/locale/bh", + "/usr/share/locale/bh/LC_MESSAGES", + "/usr/share/locale/bho", + "/usr/share/locale/bho/LC_MESSAGES", + "/usr/share/locale/bi", + "/usr/share/locale/bi/LC_MESSAGES", + "/usr/share/locale/bik", + "/usr/share/locale/bik/LC_MESSAGES", + "/usr/share/locale/bin", + "/usr/share/locale/bin/LC_MESSAGES", + "/usr/share/locale/bla", + "/usr/share/locale/bla/LC_MESSAGES", + "/usr/share/locale/bm", + "/usr/share/locale/bm/LC_MESSAGES", + "/usr/share/locale/bn", + "/usr/share/locale/bn/LC_MESSAGES", + "/usr/share/locale/bn_BD", + "/usr/share/locale/bn_BD/LC_MESSAGES", + "/usr/share/locale/bn_IN", + "/usr/share/locale/bn_IN/LC_MESSAGES", + "/usr/share/locale/bnt", + "/usr/share/locale/bnt/LC_MESSAGES", + "/usr/share/locale/bo", + "/usr/share/locale/bo/LC_MESSAGES", + "/usr/share/locale/br", + "/usr/share/locale/br/LC_MESSAGES", + "/usr/share/locale/bra", + "/usr/share/locale/bra/LC_MESSAGES", + "/usr/share/locale/brx", + "/usr/share/locale/brx/LC_MESSAGES", + "/usr/share/locale/bs", + "/usr/share/locale/bs/LC_MESSAGES", + "/usr/share/locale/bs_BA", + "/usr/share/locale/bs_BA/LC_MESSAGES", + "/usr/share/locale/btk", + "/usr/share/locale/btk/LC_MESSAGES", + "/usr/share/locale/bua", + "/usr/share/locale/bua/LC_MESSAGES", + "/usr/share/locale/bug", + "/usr/share/locale/bug/LC_MESSAGES", + "/usr/share/locale/byn", + "/usr/share/locale/byn/LC_MESSAGES", + "/usr/share/locale/ca", + "/usr/share/locale/ca.us-ascii", + "/usr/share/locale/ca.us-ascii/LC_MESSAGES", + "/usr/share/locale/ca/LC_MESSAGES", + "/usr/share/locale/ca@valencia", + "/usr/share/locale/ca@valencia/LC_MESSAGES", + "/usr/share/locale/ca_AD", + "/usr/share/locale/ca_AD/LC_MESSAGES", + "/usr/share/locale/ca_ES", + "/usr/share/locale/ca_ES/LC_MESSAGES", + "/usr/share/locale/ca_FR", + "/usr/share/locale/ca_FR/LC_MESSAGES", + "/usr/share/locale/ca_IT", + "/usr/share/locale/ca_IT/LC_MESSAGES", + "/usr/share/locale/cad", + "/usr/share/locale/cad/LC_MESSAGES", + "/usr/share/locale/cai", + "/usr/share/locale/cai/LC_MESSAGES", + "/usr/share/locale/car", + "/usr/share/locale/car/LC_MESSAGES", + "/usr/share/locale/cau", + "/usr/share/locale/cau/LC_MESSAGES", + "/usr/share/locale/ce", + "/usr/share/locale/ce/LC_MESSAGES", + "/usr/share/locale/ceb", + "/usr/share/locale/ceb/LC_MESSAGES", + "/usr/share/locale/cel", + "/usr/share/locale/cel/LC_MESSAGES", + "/usr/share/locale/cgg", + "/usr/share/locale/cgg/LC_MESSAGES", + "/usr/share/locale/ch", + "/usr/share/locale/ch/LC_MESSAGES", + "/usr/share/locale/chb", + "/usr/share/locale/chb/LC_MESSAGES", + "/usr/share/locale/chg", + "/usr/share/locale/chg/LC_MESSAGES", + "/usr/share/locale/chk", + "/usr/share/locale/chk/LC_MESSAGES", + "/usr/share/locale/chm", + "/usr/share/locale/chm/LC_MESSAGES", + "/usr/share/locale/chn", + "/usr/share/locale/chn/LC_MESSAGES", + "/usr/share/locale/cho", + "/usr/share/locale/cho/LC_MESSAGES", + "/usr/share/locale/chp", + "/usr/share/locale/chp/LC_MESSAGES", + "/usr/share/locale/chr", + "/usr/share/locale/chr/LC_MESSAGES", + "/usr/share/locale/chy", + "/usr/share/locale/chy/LC_MESSAGES", + "/usr/share/locale/ckb", + "/usr/share/locale/ckb/LC_MESSAGES", + "/usr/share/locale/cmc", + "/usr/share/locale/cmc/LC_MESSAGES", + "/usr/share/locale/cmn", + "/usr/share/locale/cmn/LC_MESSAGES", + "/usr/share/locale/cn", + "/usr/share/locale/cn/LC_MESSAGES", + "/usr/share/locale/co", + "/usr/share/locale/co/LC_MESSAGES", + "/usr/share/locale/cop", + "/usr/share/locale/cop/LC_MESSAGES", + "/usr/share/locale/cpe", + "/usr/share/locale/cpe/LC_MESSAGES", + "/usr/share/locale/cpf", + "/usr/share/locale/cpf/LC_MESSAGES", + "/usr/share/locale/cpp", + "/usr/share/locale/cpp/LC_MESSAGES", + "/usr/share/locale/cr", + "/usr/share/locale/cr/LC_MESSAGES", + "/usr/share/locale/crh", + "/usr/share/locale/crh/LC_MESSAGES", + "/usr/share/locale/crp", + "/usr/share/locale/crp/LC_MESSAGES", + "/usr/share/locale/cs", + "/usr/share/locale/cs.cp1250", + "/usr/share/locale/cs.cp1250/LC_MESSAGES", + "/usr/share/locale/cs/LC_MESSAGES", + "/usr/share/locale/cs_CZ", + "/usr/share/locale/cs_CZ/LC_MESSAGES", + "/usr/share/locale/csb", + "/usr/share/locale/csb/LC_MESSAGES", + "/usr/share/locale/cu", + "/usr/share/locale/cu/LC_MESSAGES", + "/usr/share/locale/cus", + "/usr/share/locale/cus/LC_MESSAGES", + "/usr/share/locale/cv", + "/usr/share/locale/cv/LC_MESSAGES", + "/usr/share/locale/cy", + "/usr/share/locale/cy/LC_MESSAGES", + "/usr/share/locale/da", + "/usr/share/locale/da/LC_MESSAGES", + "/usr/share/locale/da_DK", + "/usr/share/locale/da_DK/LC_MESSAGES", + "/usr/share/locale/dak", + "/usr/share/locale/dak/LC_MESSAGES", + "/usr/share/locale/dar", + "/usr/share/locale/dar/LC_MESSAGES", + "/usr/share/locale/day", + "/usr/share/locale/day/LC_MESSAGES", + "/usr/share/locale/de", + "/usr/share/locale/de-CH", + "/usr/share/locale/de-CH/LC_MESSAGES", + "/usr/share/locale/de.us-ascii", + "/usr/share/locale/de.us-ascii/LC_MESSAGES", + "/usr/share/locale/de/LC_MESSAGES", + "/usr/share/locale/de@hebrew", + "/usr/share/locale/de@hebrew/LC_MESSAGES", + "/usr/share/locale/de_AT", + "/usr/share/locale/de_AT/LC_MESSAGES", + "/usr/share/locale/de_CH", + "/usr/share/locale/de_CH/LC_MESSAGES", + "/usr/share/locale/de_DE", + "/usr/share/locale/de_DE/LC_MESSAGES", + "/usr/share/locale/del", + "/usr/share/locale/del/LC_MESSAGES", + "/usr/share/locale/den", + "/usr/share/locale/den/LC_MESSAGES", + "/usr/share/locale/dgr", + "/usr/share/locale/dgr/LC_MESSAGES", + "/usr/share/locale/din", + "/usr/share/locale/din/LC_MESSAGES", + "/usr/share/locale/doi", + "/usr/share/locale/doi/LC_MESSAGES", + "/usr/share/locale/dra", + "/usr/share/locale/dra/LC_MESSAGES", + "/usr/share/locale/dsb", + "/usr/share/locale/dsb/LC_MESSAGES", + "/usr/share/locale/dua", + "/usr/share/locale/dua/LC_MESSAGES", + "/usr/share/locale/dum", + "/usr/share/locale/dum/LC_MESSAGES", + "/usr/share/locale/dv", + "/usr/share/locale/dv/LC_MESSAGES", + "/usr/share/locale/dyu", + "/usr/share/locale/dyu/LC_MESSAGES", + "/usr/share/locale/dz", + "/usr/share/locale/dz/LC_MESSAGES", + "/usr/share/locale/ee", + "/usr/share/locale/ee/LC_MESSAGES", + "/usr/share/locale/efi", + "/usr/share/locale/efi/LC_MESSAGES", + "/usr/share/locale/egy", + "/usr/share/locale/egy/LC_MESSAGES", + "/usr/share/locale/eka", + "/usr/share/locale/eka/LC_MESSAGES", + "/usr/share/locale/el", + "/usr/share/locale/el/LC_MESSAGES", + "/usr/share/locale/el_GR", + "/usr/share/locale/el_GR/LC_MESSAGES", + "/usr/share/locale/elx", + "/usr/share/locale/elx/LC_MESSAGES", + "/usr/share/locale/en", + "/usr/share/locale/en/LC_MESSAGES", + "/usr/share/locale/en@arabic", + "/usr/share/locale/en@arabic/LC_MESSAGES", + "/usr/share/locale/en@boldquot", + "/usr/share/locale/en@boldquot/LC_MESSAGES", + "/usr/share/locale/en@cyrillic", + "/usr/share/locale/en@cyrillic/LC_MESSAGES", + "/usr/share/locale/en@greek", + "/usr/share/locale/en@greek/LC_MESSAGES", + "/usr/share/locale/en@hebrew", + "/usr/share/locale/en@hebrew/LC_MESSAGES", + "/usr/share/locale/en@piglatin", + "/usr/share/locale/en@piglatin/LC_MESSAGES", + "/usr/share/locale/en@quot", + "/usr/share/locale/en@quot/LC_MESSAGES", + "/usr/share/locale/en@shaw", + "/usr/share/locale/en@shaw/LC_MESSAGES", + "/usr/share/locale/en_AU", + "/usr/share/locale/en_AU/LC_MESSAGES", + "/usr/share/locale/en_CA", + "/usr/share/locale/en_CA/LC_MESSAGES", + "/usr/share/locale/en_CZ", + "/usr/share/locale/en_CZ/LC_MESSAGES", + "/usr/share/locale/en_GB", + "/usr/share/locale/en_GB/LC_MESSAGES", + "/usr/share/locale/en_IE", + "/usr/share/locale/en_IE/LC_MESSAGES", + "/usr/share/locale/en_NZ", + "/usr/share/locale/en_NZ/LC_MESSAGES", + "/usr/share/locale/en_US", + "/usr/share/locale/en_US/LC_MESSAGES", + "/usr/share/locale/en_US@piglatin", + "/usr/share/locale/en_US@piglatin/LC_MESSAGES", + "/usr/share/locale/en_ZA", + "/usr/share/locale/en_ZA/LC_MESSAGES", + "/usr/share/locale/enm", + "/usr/share/locale/enm/LC_MESSAGES", + "/usr/share/locale/eo", + "/usr/share/locale/eo/LC_MESSAGES", + "/usr/share/locale/es", + "/usr/share/locale/es.us-ascii", + "/usr/share/locale/es.us-ascii/LC_MESSAGES", + "/usr/share/locale/es/LC_MESSAGES", + "/usr/share/locale/es_AR", + "/usr/share/locale/es_AR/LC_MESSAGES", + "/usr/share/locale/es_CL", + "/usr/share/locale/es_CL/LC_MESSAGES", + "/usr/share/locale/es_CO", + "/usr/share/locale/es_CO/LC_MESSAGES", + "/usr/share/locale/es_CR", + "/usr/share/locale/es_CR/LC_MESSAGES", + "/usr/share/locale/es_DO", + "/usr/share/locale/es_DO/LC_MESSAGES", + "/usr/share/locale/es_EC", + "/usr/share/locale/es_EC/LC_MESSAGES", + "/usr/share/locale/es_ES", + "/usr/share/locale/es_ES/LC_MESSAGES", + "/usr/share/locale/es_GT", + "/usr/share/locale/es_GT/LC_MESSAGES", + "/usr/share/locale/es_HN", + "/usr/share/locale/es_HN/LC_MESSAGES", + "/usr/share/locale/es_MX", + "/usr/share/locale/es_MX/LC_MESSAGES", + "/usr/share/locale/es_NI", + "/usr/share/locale/es_NI/LC_MESSAGES", + "/usr/share/locale/es_PA", + "/usr/share/locale/es_PA/LC_MESSAGES", + "/usr/share/locale/es_PE", + "/usr/share/locale/es_PE/LC_MESSAGES", + "/usr/share/locale/es_PR", + "/usr/share/locale/es_PR/LC_MESSAGES", + "/usr/share/locale/es_PY", + "/usr/share/locale/es_PY/LC_MESSAGES", + "/usr/share/locale/es_SV", + "/usr/share/locale/es_SV/LC_MESSAGES", + "/usr/share/locale/es_US", + "/usr/share/locale/es_US/LC_MESSAGES", + "/usr/share/locale/es_UY", + "/usr/share/locale/es_UY/LC_MESSAGES", + "/usr/share/locale/es_VE", + "/usr/share/locale/es_VE/LC_MESSAGES", + "/usr/share/locale/et", + "/usr/share/locale/et/LC_MESSAGES", + "/usr/share/locale/et_EE", + "/usr/share/locale/et_EE/LC_MESSAGES", + "/usr/share/locale/eu", + "/usr/share/locale/eu/LC_MESSAGES", + "/usr/share/locale/eu_ES", + "/usr/share/locale/eu_ES/LC_MESSAGES", + "/usr/share/locale/ewo", + "/usr/share/locale/ewo/LC_MESSAGES", + "/usr/share/locale/fa", + "/usr/share/locale/fa/LC_MESSAGES", + "/usr/share/locale/fa_AF", + "/usr/share/locale/fa_AF/LC_MESSAGES", + "/usr/share/locale/fa_IR", + "/usr/share/locale/fa_IR/LC_MESSAGES", + "/usr/share/locale/fan", + "/usr/share/locale/fan/LC_MESSAGES", + "/usr/share/locale/fat", + "/usr/share/locale/fat/LC_MESSAGES", + "/usr/share/locale/ff", + "/usr/share/locale/ff/LC_MESSAGES", + "/usr/share/locale/fi", + "/usr/share/locale/fi/LC_MESSAGES", + "/usr/share/locale/fi_FI", + "/usr/share/locale/fi_FI/LC_MESSAGES", + "/usr/share/locale/fil", + "/usr/share/locale/fil/LC_MESSAGES", + "/usr/share/locale/fiu", + "/usr/share/locale/fiu/LC_MESSAGES", + "/usr/share/locale/fj", + "/usr/share/locale/fj/LC_MESSAGES", + "/usr/share/locale/fo", + "/usr/share/locale/fo/LC_MESSAGES", + "/usr/share/locale/fon", + "/usr/share/locale/fon/LC_MESSAGES", + "/usr/share/locale/fr", + "/usr/share/locale/fr.us-ascii", + "/usr/share/locale/fr.us-ascii/LC_MESSAGES", + "/usr/share/locale/fr/LC_MESSAGES", + "/usr/share/locale/fr_CA", + "/usr/share/locale/fr_CA/LC_MESSAGES", + "/usr/share/locale/fr_CH", + "/usr/share/locale/fr_CH/LC_MESSAGES", + "/usr/share/locale/fr_FR", + "/usr/share/locale/fr_FR/LC_MESSAGES", + "/usr/share/locale/frm", + "/usr/share/locale/frm/LC_MESSAGES", + "/usr/share/locale/fro", + "/usr/share/locale/fro/LC_MESSAGES", + "/usr/share/locale/frp", + "/usr/share/locale/frp/LC_MESSAGES", + "/usr/share/locale/frr", + "/usr/share/locale/frr/LC_MESSAGES", + "/usr/share/locale/frs", + "/usr/share/locale/frs/LC_MESSAGES", + "/usr/share/locale/fur", + "/usr/share/locale/fur/LC_MESSAGES", + "/usr/share/locale/fy", + "/usr/share/locale/fy/LC_MESSAGES", + "/usr/share/locale/ga", + "/usr/share/locale/ga/LC_MESSAGES", + "/usr/share/locale/gaa", + "/usr/share/locale/gaa/LC_MESSAGES", + "/usr/share/locale/gay", + "/usr/share/locale/gay/LC_MESSAGES", + "/usr/share/locale/gba", + "/usr/share/locale/gba/LC_MESSAGES", + "/usr/share/locale/gd", + "/usr/share/locale/gd/LC_MESSAGES", + "/usr/share/locale/gem", + "/usr/share/locale/gem/LC_MESSAGES", + "/usr/share/locale/gez", + "/usr/share/locale/gez/LC_MESSAGES", + "/usr/share/locale/gil", + "/usr/share/locale/gil/LC_MESSAGES", + "/usr/share/locale/gl", + "/usr/share/locale/gl/LC_MESSAGES", + "/usr/share/locale/gl_ES", + "/usr/share/locale/gl_ES/LC_MESSAGES", + "/usr/share/locale/gmh", + "/usr/share/locale/gmh/LC_MESSAGES", + "/usr/share/locale/gn", + "/usr/share/locale/gn/LC_MESSAGES", + "/usr/share/locale/goh", + "/usr/share/locale/goh/LC_MESSAGES", + "/usr/share/locale/gom", + "/usr/share/locale/gom/LC_MESSAGES", + "/usr/share/locale/gon", + "/usr/share/locale/gon/LC_MESSAGES", + "/usr/share/locale/gor", + "/usr/share/locale/gor/LC_MESSAGES", + "/usr/share/locale/gos", + "/usr/share/locale/gos/LC_MESSAGES", + "/usr/share/locale/got", + "/usr/share/locale/got/LC_MESSAGES", + "/usr/share/locale/grb", + "/usr/share/locale/grb/LC_MESSAGES", + "/usr/share/locale/grc", + "/usr/share/locale/grc/LC_MESSAGES", + "/usr/share/locale/gsw", + "/usr/share/locale/gsw/LC_MESSAGES", + "/usr/share/locale/gu", + "/usr/share/locale/gu/LC_MESSAGES", + "/usr/share/locale/guc", + "/usr/share/locale/guc/LC_MESSAGES", + "/usr/share/locale/gv", + "/usr/share/locale/gv/LC_MESSAGES", + "/usr/share/locale/gwi", + "/usr/share/locale/gwi/LC_MESSAGES", + "/usr/share/locale/ha", + "/usr/share/locale/ha/LC_MESSAGES", + "/usr/share/locale/hai", + "/usr/share/locale/hai/LC_MESSAGES", + "/usr/share/locale/haw", + "/usr/share/locale/haw/LC_MESSAGES", + "/usr/share/locale/he", + "/usr/share/locale/he/LC_MESSAGES", + "/usr/share/locale/he_IL", + "/usr/share/locale/he_IL/LC_MESSAGES", + "/usr/share/locale/hi", + "/usr/share/locale/hi/LC_MESSAGES", + "/usr/share/locale/hi_IN", + "/usr/share/locale/hi_IN/LC_MESSAGES", + "/usr/share/locale/hil", + "/usr/share/locale/hil/LC_MESSAGES", + "/usr/share/locale/him", + "/usr/share/locale/him/LC_MESSAGES", + "/usr/share/locale/hit", + "/usr/share/locale/hit/LC_MESSAGES", + "/usr/share/locale/hmn", + "/usr/share/locale/hmn/LC_MESSAGES", + "/usr/share/locale/hne", + "/usr/share/locale/hne/LC_MESSAGES", + "/usr/share/locale/ho", + "/usr/share/locale/ho/LC_MESSAGES", + "/usr/share/locale/hr", + "/usr/share/locale/hr/LC_MESSAGES", + "/usr/share/locale/hr_HR", + "/usr/share/locale/hr_HR/LC_MESSAGES", + "/usr/share/locale/hsb", + "/usr/share/locale/hsb/LC_MESSAGES", + "/usr/share/locale/ht", + "/usr/share/locale/ht/LC_MESSAGES", + "/usr/share/locale/hu", + "/usr/share/locale/hu/LC_MESSAGES", + "/usr/share/locale/hu_HU", + "/usr/share/locale/hu_HU/LC_MESSAGES", + "/usr/share/locale/hup", + "/usr/share/locale/hup/LC_MESSAGES", + "/usr/share/locale/hus", + "/usr/share/locale/hus/LC_MESSAGES", + "/usr/share/locale/hy", + "/usr/share/locale/hy/LC_MESSAGES", + "/usr/share/locale/hz", + "/usr/share/locale/hz/LC_MESSAGES", + "/usr/share/locale/ia", + "/usr/share/locale/ia/LC_MESSAGES", + "/usr/share/locale/iba", + "/usr/share/locale/iba/LC_MESSAGES", + "/usr/share/locale/ibo", + "/usr/share/locale/ibo/LC_MESSAGES", + "/usr/share/locale/id", + "/usr/share/locale/id/LC_MESSAGES", + "/usr/share/locale/id_ID", + "/usr/share/locale/id_ID/LC_MESSAGES", + "/usr/share/locale/ie", + "/usr/share/locale/ie/LC_MESSAGES", + "/usr/share/locale/ig", + "/usr/share/locale/ig/LC_MESSAGES", + "/usr/share/locale/ii", + "/usr/share/locale/ii/LC_MESSAGES", + "/usr/share/locale/ijo", + "/usr/share/locale/ijo/LC_MESSAGES", + "/usr/share/locale/ik", + "/usr/share/locale/ik/LC_MESSAGES", + "/usr/share/locale/ilo", + "/usr/share/locale/ilo/LC_MESSAGES", + "/usr/share/locale/inc", + "/usr/share/locale/inc/LC_MESSAGES", + "/usr/share/locale/ine", + "/usr/share/locale/ine/LC_MESSAGES", + "/usr/share/locale/inh", + "/usr/share/locale/inh/LC_MESSAGES", + "/usr/share/locale/io", + "/usr/share/locale/io/LC_MESSAGES", + "/usr/share/locale/ira", + "/usr/share/locale/ira/LC_MESSAGES", + "/usr/share/locale/iro", + "/usr/share/locale/iro/LC_MESSAGES", + "/usr/share/locale/is", + "/usr/share/locale/is/LC_MESSAGES", + "/usr/share/locale/it", + "/usr/share/locale/it/LC_MESSAGES", + "/usr/share/locale/it_IT", + "/usr/share/locale/it_IT/LC_MESSAGES", + "/usr/share/locale/iu", + "/usr/share/locale/iu/LC_MESSAGES", + "/usr/share/locale/ja", + "/usr/share/locale/ja.euc-jp", + "/usr/share/locale/ja.euc-jp/LC_MESSAGES", + "/usr/share/locale/ja/LC_MESSAGES", + "/usr/share/locale/ja_JP", + "/usr/share/locale/ja_JP/LC_MESSAGES", + "/usr/share/locale/jbo", + "/usr/share/locale/jbo/LC_MESSAGES", + "/usr/share/locale/jpr", + "/usr/share/locale/jpr/LC_MESSAGES", + "/usr/share/locale/jrb", + "/usr/share/locale/jrb/LC_MESSAGES", + "/usr/share/locale/jv", + "/usr/share/locale/jv/LC_MESSAGES", + "/usr/share/locale/ka", + "/usr/share/locale/ka/LC_MESSAGES", + "/usr/share/locale/ka_GE", + "/usr/share/locale/ka_GE/LC_MESSAGES", + "/usr/share/locale/kaa", + "/usr/share/locale/kaa/LC_MESSAGES", + "/usr/share/locale/kab", + "/usr/share/locale/kab/LC_MESSAGES", + "/usr/share/locale/kac", + "/usr/share/locale/kac/LC_MESSAGES", + "/usr/share/locale/kam", + "/usr/share/locale/kam/LC_MESSAGES", + "/usr/share/locale/kar", + "/usr/share/locale/kar/LC_MESSAGES", + "/usr/share/locale/kaw", + "/usr/share/locale/kaw/LC_MESSAGES", + "/usr/share/locale/kbd", + "/usr/share/locale/kbd/LC_MESSAGES", + "/usr/share/locale/kg", + "/usr/share/locale/kg/LC_MESSAGES", + "/usr/share/locale/kha", + "/usr/share/locale/kha/LC_MESSAGES", + "/usr/share/locale/khi", + "/usr/share/locale/khi/LC_MESSAGES", + "/usr/share/locale/kho", + "/usr/share/locale/kho/LC_MESSAGES", + "/usr/share/locale/ki", + "/usr/share/locale/ki/LC_MESSAGES", + "/usr/share/locale/kj", + "/usr/share/locale/kj/LC_MESSAGES", + "/usr/share/locale/kk", + "/usr/share/locale/kk/LC_MESSAGES", + "/usr/share/locale/kl", + "/usr/share/locale/kl/LC_MESSAGES", + "/usr/share/locale/km", + "/usr/share/locale/km/LC_MESSAGES", + "/usr/share/locale/km_KH", + "/usr/share/locale/km_KH/LC_MESSAGES", + "/usr/share/locale/kmb", + "/usr/share/locale/kmb/LC_MESSAGES", + "/usr/share/locale/kn", + "/usr/share/locale/kn/LC_MESSAGES", + "/usr/share/locale/ko", + "/usr/share/locale/ko/LC_MESSAGES", + "/usr/share/locale/ko_KR", + "/usr/share/locale/ko_KR/LC_MESSAGES", + "/usr/share/locale/kok", + "/usr/share/locale/kok/LC_MESSAGES", + "/usr/share/locale/kok@latin", + "/usr/share/locale/kok@latin/LC_MESSAGES", + "/usr/share/locale/kos", + "/usr/share/locale/kos/LC_MESSAGES", + "/usr/share/locale/kpe", + "/usr/share/locale/kpe/LC_MESSAGES", + "/usr/share/locale/kr", + "/usr/share/locale/kr/LC_MESSAGES", + "/usr/share/locale/krc", + "/usr/share/locale/krc/LC_MESSAGES", + "/usr/share/locale/krl", + "/usr/share/locale/krl/LC_MESSAGES", + "/usr/share/locale/kro", + "/usr/share/locale/kro/LC_MESSAGES", + "/usr/share/locale/kru", + "/usr/share/locale/kru/LC_MESSAGES", + "/usr/share/locale/ks", + "/usr/share/locale/ks/LC_MESSAGES", + "/usr/share/locale/ks@aran", + "/usr/share/locale/ks@aran/LC_MESSAGES", + "/usr/share/locale/ks@devanagari", + "/usr/share/locale/ks@devanagari/LC_MESSAGES", + "/usr/share/locale/ksw", + "/usr/share/locale/ksw/LC_MESSAGES", + "/usr/share/locale/ku", + "/usr/share/locale/ku/LC_MESSAGES", + "/usr/share/locale/ku_IQ", + "/usr/share/locale/ku_IQ/LC_MESSAGES", + "/usr/share/locale/kum", + "/usr/share/locale/kum/LC_MESSAGES", + "/usr/share/locale/kut", + "/usr/share/locale/kut/LC_MESSAGES", + "/usr/share/locale/kv", + "/usr/share/locale/kv/LC_MESSAGES", + "/usr/share/locale/kw", + "/usr/share/locale/kw/LC_MESSAGES", + "/usr/share/locale/kw@kkcor", + "/usr/share/locale/kw@kkcor/LC_MESSAGES", + "/usr/share/locale/kw@uccor", + "/usr/share/locale/kw@uccor/LC_MESSAGES", + "/usr/share/locale/kw_GB", + "/usr/share/locale/kw_GB/LC_MESSAGES", + "/usr/share/locale/ky", + "/usr/share/locale/ky/LC_MESSAGES", + "/usr/share/locale/l10n", + "/usr/share/locale/l10n/LC_MESSAGES", + "/usr/share/locale/la", + "/usr/share/locale/la/LC_MESSAGES", + "/usr/share/locale/lad", + "/usr/share/locale/lad/LC_MESSAGES", + "/usr/share/locale/lah", + "/usr/share/locale/lah/LC_MESSAGES", + "/usr/share/locale/lam", + "/usr/share/locale/lam/LC_MESSAGES", + "/usr/share/locale/lb", + "/usr/share/locale/lb/LC_MESSAGES", + "/usr/share/locale/lez", + "/usr/share/locale/lez/LC_MESSAGES", + "/usr/share/locale/lg", + "/usr/share/locale/lg/LC_MESSAGES", + "/usr/share/locale/li", + "/usr/share/locale/li/LC_MESSAGES", + "/usr/share/locale/ln", + "/usr/share/locale/ln/LC_MESSAGES", + "/usr/share/locale/lo", + "/usr/share/locale/lo/LC_MESSAGES", + "/usr/share/locale/lo_LA", + "/usr/share/locale/lo_LA/LC_MESSAGES", + "/usr/share/locale/lol", + "/usr/share/locale/lol/LC_MESSAGES", + "/usr/share/locale/loz", + "/usr/share/locale/loz/LC_MESSAGES", + "/usr/share/locale/lt", + "/usr/share/locale/lt/LC_MESSAGES", + "/usr/share/locale/lt_LT", + "/usr/share/locale/lt_LT/LC_MESSAGES", + "/usr/share/locale/ltg", + "/usr/share/locale/ltg/LC_MESSAGES", + "/usr/share/locale/lu", + "/usr/share/locale/lu/LC_MESSAGES", + "/usr/share/locale/lua", + "/usr/share/locale/lua/LC_MESSAGES", + "/usr/share/locale/lui", + "/usr/share/locale/lui/LC_MESSAGES", + "/usr/share/locale/lun", + "/usr/share/locale/lun/LC_MESSAGES", + "/usr/share/locale/luo", + "/usr/share/locale/luo/LC_MESSAGES", + "/usr/share/locale/lus", + "/usr/share/locale/lus/LC_MESSAGES", + "/usr/share/locale/lv", + "/usr/share/locale/lv/LC_MESSAGES", + "/usr/share/locale/lv_LV", + "/usr/share/locale/lv_LV/LC_MESSAGES", + "/usr/share/locale/mad", + "/usr/share/locale/mad/LC_MESSAGES", + "/usr/share/locale/mag", + "/usr/share/locale/mag/LC_MESSAGES", + "/usr/share/locale/mai", + "/usr/share/locale/mai/LC_MESSAGES", + "/usr/share/locale/mak", + "/usr/share/locale/mak/LC_MESSAGES", + "/usr/share/locale/man", + "/usr/share/locale/man/LC_MESSAGES", + "/usr/share/locale/map", + "/usr/share/locale/map/LC_MESSAGES", + "/usr/share/locale/mas", + "/usr/share/locale/mas/LC_MESSAGES", + "/usr/share/locale/mdf", + "/usr/share/locale/mdf/LC_MESSAGES", + "/usr/share/locale/mdr", + "/usr/share/locale/mdr/LC_MESSAGES", + "/usr/share/locale/men", + "/usr/share/locale/men/LC_MESSAGES", + "/usr/share/locale/mg", + "/usr/share/locale/mg/LC_MESSAGES", + "/usr/share/locale/mga", + "/usr/share/locale/mga/LC_MESSAGES", + "/usr/share/locale/mh", + "/usr/share/locale/mh/LC_MESSAGES", + "/usr/share/locale/mhr", + "/usr/share/locale/mhr/LC_MESSAGES", + "/usr/share/locale/mi", + "/usr/share/locale/mi/LC_MESSAGES", + "/usr/share/locale/mic", + "/usr/share/locale/mic/LC_MESSAGES", + "/usr/share/locale/min", + "/usr/share/locale/min/LC_MESSAGES", + "/usr/share/locale/mis", + "/usr/share/locale/mis/LC_MESSAGES", + "/usr/share/locale/mk", + "/usr/share/locale/mk/LC_MESSAGES", + "/usr/share/locale/mk_MK", + "/usr/share/locale/mk_MK/LC_MESSAGES", + "/usr/share/locale/mkh", + "/usr/share/locale/mkh/LC_MESSAGES", + "/usr/share/locale/ml", + "/usr/share/locale/ml/LC_MESSAGES", + "/usr/share/locale/ml_IN", + "/usr/share/locale/ml_IN/LC_MESSAGES", + "/usr/share/locale/mn", + "/usr/share/locale/mn/LC_MESSAGES", + "/usr/share/locale/mnc", + "/usr/share/locale/mnc/LC_MESSAGES", + "/usr/share/locale/mni", + "/usr/share/locale/mni/LC_MESSAGES", + "/usr/share/locale/mni@beng", + "/usr/share/locale/mni@beng/LC_MESSAGES", + "/usr/share/locale/mni@bengali", + "/usr/share/locale/mni@bengali/LC_MESSAGES", + "/usr/share/locale/mni@meiteimayek", + "/usr/share/locale/mni@meiteimayek/LC_MESSAGES", + "/usr/share/locale/mnk", + "/usr/share/locale/mnk/LC_MESSAGES", + "/usr/share/locale/mno", + "/usr/share/locale/mno/LC_MESSAGES", + "/usr/share/locale/moh", + "/usr/share/locale/moh/LC_MESSAGES", + "/usr/share/locale/mos", + "/usr/share/locale/mos/LC_MESSAGES", + "/usr/share/locale/mr", + "/usr/share/locale/mr/LC_MESSAGES", + "/usr/share/locale/mr_IN", + "/usr/share/locale/mr_IN/LC_MESSAGES", + "/usr/share/locale/ms", + "/usr/share/locale/ms/LC_MESSAGES", + "/usr/share/locale/ms_MY", + "/usr/share/locale/ms_MY/LC_MESSAGES", + "/usr/share/locale/mt", + "/usr/share/locale/mt/LC_MESSAGES", + "/usr/share/locale/mul", + "/usr/share/locale/mul/LC_MESSAGES", + "/usr/share/locale/mun", + "/usr/share/locale/mun/LC_MESSAGES", + "/usr/share/locale/mus", + "/usr/share/locale/mus/LC_MESSAGES", + "/usr/share/locale/mvo", + "/usr/share/locale/mvo/LC_MESSAGES", + "/usr/share/locale/mwl", + "/usr/share/locale/mwl/LC_MESSAGES", + "/usr/share/locale/mwr", + "/usr/share/locale/mwr/LC_MESSAGES", + "/usr/share/locale/my", + "/usr/share/locale/my/LC_MESSAGES", + "/usr/share/locale/my_MM", + "/usr/share/locale/my_MM/LC_MESSAGES", + "/usr/share/locale/myn", + "/usr/share/locale/myn/LC_MESSAGES", + "/usr/share/locale/myv", + "/usr/share/locale/myv/LC_MESSAGES", + "/usr/share/locale/na", + "/usr/share/locale/na/LC_MESSAGES", + "/usr/share/locale/nah", + "/usr/share/locale/nah/LC_MESSAGES", + "/usr/share/locale/nai", + "/usr/share/locale/nai/LC_MESSAGES", + "/usr/share/locale/nan", + "/usr/share/locale/nan/LC_MESSAGES", + "/usr/share/locale/nap", + "/usr/share/locale/nap/LC_MESSAGES", + "/usr/share/locale/nb", + "/usr/share/locale/nb/LC_MESSAGES", + "/usr/share/locale/nb_NO", + "/usr/share/locale/nb_NO/LC_MESSAGES", + "/usr/share/locale/nd", + "/usr/share/locale/nd/LC_MESSAGES", + "/usr/share/locale/nds", + "/usr/share/locale/nds/LC_MESSAGES", + "/usr/share/locale/ne", + "/usr/share/locale/ne/LC_MESSAGES", + "/usr/share/locale/new", + "/usr/share/locale/new/LC_MESSAGES", + "/usr/share/locale/ng", + "/usr/share/locale/ng/LC_MESSAGES", + "/usr/share/locale/nia", + "/usr/share/locale/nia/LC_MESSAGES", + "/usr/share/locale/nic", + "/usr/share/locale/nic/LC_MESSAGES", + "/usr/share/locale/niu", + "/usr/share/locale/niu/LC_MESSAGES", + "/usr/share/locale/nl", + "/usr/share/locale/nl.us-ascii", + "/usr/share/locale/nl.us-ascii/LC_MESSAGES", + "/usr/share/locale/nl/LC_MESSAGES", + "/usr/share/locale/nl_BE", + "/usr/share/locale/nl_BE/LC_MESSAGES", + "/usr/share/locale/nl_NL", + "/usr/share/locale/nl_NL/LC_MESSAGES", + "/usr/share/locale/nn", + "/usr/share/locale/nn/LC_MESSAGES", + "/usr/share/locale/nn_NO", + "/usr/share/locale/nn_NO/LC_MESSAGES", + "/usr/share/locale/no", + "/usr/share/locale/no.us-ascii", + "/usr/share/locale/no.us-ascii/LC_MESSAGES", + "/usr/share/locale/no/LC_MESSAGES", + "/usr/share/locale/no_NO", + "/usr/share/locale/no_NO/LC_MESSAGES", + "/usr/share/locale/nog", + "/usr/share/locale/nog/LC_MESSAGES", + "/usr/share/locale/non", + "/usr/share/locale/non/LC_MESSAGES", + "/usr/share/locale/nqo", + "/usr/share/locale/nqo/LC_MESSAGES", + "/usr/share/locale/nr", + "/usr/share/locale/nr/LC_MESSAGES", + "/usr/share/locale/nso", + "/usr/share/locale/nso/LC_MESSAGES", + "/usr/share/locale/nub", + "/usr/share/locale/nub/LC_MESSAGES", + "/usr/share/locale/nv", + "/usr/share/locale/nv/LC_MESSAGES", + "/usr/share/locale/nwc", + "/usr/share/locale/nwc/LC_MESSAGES", + "/usr/share/locale/ny", + "/usr/share/locale/ny/LC_MESSAGES", + "/usr/share/locale/nym", + "/usr/share/locale/nym/LC_MESSAGES", + "/usr/share/locale/nyn", + "/usr/share/locale/nyn/LC_MESSAGES", + "/usr/share/locale/nyo", + "/usr/share/locale/nyo/LC_MESSAGES", + "/usr/share/locale/nzi", + "/usr/share/locale/nzi/LC_MESSAGES", + "/usr/share/locale/oc", + "/usr/share/locale/oc/LC_MESSAGES", + "/usr/share/locale/oj", + "/usr/share/locale/oj/LC_MESSAGES", + "/usr/share/locale/om", + "/usr/share/locale/om/LC_MESSAGES", + "/usr/share/locale/or", + "/usr/share/locale/or/LC_MESSAGES", + "/usr/share/locale/or_IN", + "/usr/share/locale/or_IN/LC_MESSAGES", + "/usr/share/locale/os", + "/usr/share/locale/os/LC_MESSAGES", + "/usr/share/locale/osa", + "/usr/share/locale/osa/LC_MESSAGES", + "/usr/share/locale/ota", + "/usr/share/locale/ota/LC_MESSAGES", + "/usr/share/locale/oto", + "/usr/share/locale/oto/LC_MESSAGES", + "/usr/share/locale/pa", + "/usr/share/locale/pa/LC_MESSAGES", + "/usr/share/locale/paa", + "/usr/share/locale/paa/LC_MESSAGES", + "/usr/share/locale/pag", + "/usr/share/locale/pag/LC_MESSAGES", + "/usr/share/locale/pal", + "/usr/share/locale/pal/LC_MESSAGES", + "/usr/share/locale/pam", + "/usr/share/locale/pam/LC_MESSAGES", + "/usr/share/locale/pap", + "/usr/share/locale/pap/LC_MESSAGES", + "/usr/share/locale/pau", + "/usr/share/locale/pau/LC_MESSAGES", + "/usr/share/locale/pbs", + "/usr/share/locale/pbs/LC_MESSAGES", + "/usr/share/locale/peo", + "/usr/share/locale/peo/LC_MESSAGES", + "/usr/share/locale/phi", + "/usr/share/locale/phi/LC_MESSAGES", + "/usr/share/locale/phn", + "/usr/share/locale/phn/LC_MESSAGES", + "/usr/share/locale/pi", + "/usr/share/locale/pi/LC_MESSAGES", + "/usr/share/locale/pis", + "/usr/share/locale/pis/LC_MESSAGES", + "/usr/share/locale/pl", + "/usr/share/locale/pl/LC_MESSAGES", + "/usr/share/locale/pl_PL", + "/usr/share/locale/pl_PL/LC_MESSAGES", + "/usr/share/locale/pms", + "/usr/share/locale/pms/LC_MESSAGES", + "/usr/share/locale/pon", + "/usr/share/locale/pon/LC_MESSAGES", + "/usr/share/locale/pra", + "/usr/share/locale/pra/LC_MESSAGES", + "/usr/share/locale/pro", + "/usr/share/locale/pro/LC_MESSAGES", + "/usr/share/locale/ps", + "/usr/share/locale/ps/LC_MESSAGES", + "/usr/share/locale/pt", + "/usr/share/locale/pt.us-ascii", + "/usr/share/locale/pt.us-ascii/LC_MESSAGES", + "/usr/share/locale/pt/LC_MESSAGES", + "/usr/share/locale/pt_BR", + "/usr/share/locale/pt_BR.us-ascii", + "/usr/share/locale/pt_BR.us-ascii/LC_MESSAGES", + "/usr/share/locale/pt_BR/LC_MESSAGES", + "/usr/share/locale/pt_PT", + "/usr/share/locale/pt_PT/LC_MESSAGES", + "/usr/share/locale/qaa-qtz", + "/usr/share/locale/qaa-qtz/LC_MESSAGES", + "/usr/share/locale/qu", + "/usr/share/locale/qu/LC_MESSAGES", + "/usr/share/locale/quy", + "/usr/share/locale/quy/LC_MESSAGES", + "/usr/share/locale/quz", + "/usr/share/locale/quz/LC_MESSAGES", + "/usr/share/locale/raj", + "/usr/share/locale/raj/LC_MESSAGES", + "/usr/share/locale/rap", + "/usr/share/locale/rap/LC_MESSAGES", + "/usr/share/locale/rar", + "/usr/share/locale/rar/LC_MESSAGES", + "/usr/share/locale/rm", + "/usr/share/locale/rm/LC_MESSAGES", + "/usr/share/locale/rn", + "/usr/share/locale/rn/LC_MESSAGES", + "/usr/share/locale/ro", + "/usr/share/locale/ro/LC_MESSAGES", + "/usr/share/locale/ro_RO", + "/usr/share/locale/ro_RO/LC_MESSAGES", + "/usr/share/locale/roa", + "/usr/share/locale/roa/LC_MESSAGES", + "/usr/share/locale/rom", + "/usr/share/locale/rom/LC_MESSAGES", + "/usr/share/locale/ru", + "/usr/share/locale/ru/LC_MESSAGES", + "/usr/share/locale/ru_RU", + "/usr/share/locale/ru_RU.KOI8-R", + "/usr/share/locale/ru_RU.KOI8-R/LC_MESSAGES", + "/usr/share/locale/ru_RU/LC_MESSAGES", + "/usr/share/locale/rue", + "/usr/share/locale/rue/LC_MESSAGES", + "/usr/share/locale/rup", + "/usr/share/locale/rup/LC_MESSAGES", + "/usr/share/locale/rw", + "/usr/share/locale/rw/LC_MESSAGES", + "/usr/share/locale/sa", + "/usr/share/locale/sa/LC_MESSAGES", + "/usr/share/locale/sad", + "/usr/share/locale/sad/LC_MESSAGES", + "/usr/share/locale/sah", + "/usr/share/locale/sah/LC_MESSAGES", + "/usr/share/locale/sai", + "/usr/share/locale/sai/LC_MESSAGES", + "/usr/share/locale/sal", + "/usr/share/locale/sal/LC_MESSAGES", + "/usr/share/locale/sam", + "/usr/share/locale/sam/LC_MESSAGES", + "/usr/share/locale/sas", + "/usr/share/locale/sas/LC_MESSAGES", + "/usr/share/locale/sat", + "/usr/share/locale/sat/LC_MESSAGES", + "/usr/share/locale/sat@deva", + "/usr/share/locale/sat@deva/LC_MESSAGES", + "/usr/share/locale/sat@olchiki", + "/usr/share/locale/sat@olchiki/LC_MESSAGES", + "/usr/share/locale/sc", + "/usr/share/locale/sc/LC_MESSAGES", + "/usr/share/locale/scn", + "/usr/share/locale/scn/LC_MESSAGES", + "/usr/share/locale/sco", + "/usr/share/locale/sco/LC_MESSAGES", + "/usr/share/locale/sd", + "/usr/share/locale/sd/LC_MESSAGES", + "/usr/share/locale/sd@deva", + "/usr/share/locale/sd@deva/LC_MESSAGES", + "/usr/share/locale/se", + "/usr/share/locale/se/LC_MESSAGES", + "/usr/share/locale/sel", + "/usr/share/locale/sel/LC_MESSAGES", + "/usr/share/locale/sem", + "/usr/share/locale/sem/LC_MESSAGES", + "/usr/share/locale/sg", + "/usr/share/locale/sg/LC_MESSAGES", + "/usr/share/locale/sga", + "/usr/share/locale/sga/LC_MESSAGES", + "/usr/share/locale/sgn", + "/usr/share/locale/sgn/LC_MESSAGES", + "/usr/share/locale/shn", + "/usr/share/locale/shn/LC_MESSAGES", + "/usr/share/locale/shs", + "/usr/share/locale/shs/LC_MESSAGES", + "/usr/share/locale/si", + "/usr/share/locale/si/LC_MESSAGES", + "/usr/share/locale/si_LK", + "/usr/share/locale/si_LK/LC_MESSAGES", + "/usr/share/locale/sid", + "/usr/share/locale/sid/LC_MESSAGES", + "/usr/share/locale/sio", + "/usr/share/locale/sio/LC_MESSAGES", + "/usr/share/locale/sit", + "/usr/share/locale/sit/LC_MESSAGES", + "/usr/share/locale/sk", + "/usr/share/locale/sk.cp1250", + "/usr/share/locale/sk.cp1250/LC_MESSAGES", + "/usr/share/locale/sk/LC_MESSAGES", + "/usr/share/locale/sk_SK", + "/usr/share/locale/sk_SK/LC_MESSAGES", + "/usr/share/locale/sl", + "/usr/share/locale/sl/LC_MESSAGES", + "/usr/share/locale/sl_SI", + "/usr/share/locale/sl_SI/LC_MESSAGES", + "/usr/share/locale/sla", + "/usr/share/locale/sla/LC_MESSAGES", + "/usr/share/locale/sm", + "/usr/share/locale/sm/LC_MESSAGES", + "/usr/share/locale/sma", + "/usr/share/locale/sma/LC_MESSAGES", + "/usr/share/locale/smi", + "/usr/share/locale/smi/LC_MESSAGES", + "/usr/share/locale/smj", + "/usr/share/locale/smj/LC_MESSAGES", + "/usr/share/locale/smn", + "/usr/share/locale/smn/LC_MESSAGES", + "/usr/share/locale/sms", + "/usr/share/locale/sms/LC_MESSAGES", + "/usr/share/locale/sn", + "/usr/share/locale/sn/LC_MESSAGES", + "/usr/share/locale/snk", + "/usr/share/locale/snk/LC_MESSAGES", + "/usr/share/locale/so", + "/usr/share/locale/so/LC_MESSAGES", + "/usr/share/locale/sog", + "/usr/share/locale/sog/LC_MESSAGES", + "/usr/share/locale/son", + "/usr/share/locale/son/LC_MESSAGES", + "/usr/share/locale/sp", + "/usr/share/locale/sp/LC_MESSAGES", + "/usr/share/locale/sq", + "/usr/share/locale/sq/LC_MESSAGES", + "/usr/share/locale/sq_AL", + "/usr/share/locale/sq_AL/LC_MESSAGES", + "/usr/share/locale/sr", + "/usr/share/locale/sr/LC_MESSAGES", + "/usr/share/locale/sr@Latn", + "/usr/share/locale/sr@Latn/LC_MESSAGES", + "/usr/share/locale/sr@ije", + "/usr/share/locale/sr@ije/LC_MESSAGES", + "/usr/share/locale/sr@ijekavian", + "/usr/share/locale/sr@ijekavian/LC_MESSAGES", + "/usr/share/locale/sr@ijekavianlatin", + "/usr/share/locale/sr@ijekavianlatin/LC_MESSAGES", + "/usr/share/locale/sr@latin", + "/usr/share/locale/sr@latin/LC_MESSAGES", + "/usr/share/locale/sr_ME", + "/usr/share/locale/sr_ME/LC_MESSAGES", + "/usr/share/locale/sr_RS", + "/usr/share/locale/sr_RS/LC_MESSAGES", + "/usr/share/locale/sr_RS@latin", + "/usr/share/locale/sr_RS@latin/LC_MESSAGES", + "/usr/share/locale/srd", + "/usr/share/locale/srd/LC_MESSAGES", + "/usr/share/locale/srn", + "/usr/share/locale/srn/LC_MESSAGES", + "/usr/share/locale/srr", + "/usr/share/locale/srr/LC_MESSAGES", + "/usr/share/locale/ss", + "/usr/share/locale/ss/LC_MESSAGES", + "/usr/share/locale/ssa", + "/usr/share/locale/ssa/LC_MESSAGES", + "/usr/share/locale/st", + "/usr/share/locale/st/LC_MESSAGES", + "/usr/share/locale/su", + "/usr/share/locale/su/LC_MESSAGES", + "/usr/share/locale/suk", + "/usr/share/locale/suk/LC_MESSAGES", + "/usr/share/locale/sus", + "/usr/share/locale/sus/LC_MESSAGES", + "/usr/share/locale/sux", + "/usr/share/locale/sux/LC_MESSAGES", + "/usr/share/locale/sv", + "/usr/share/locale/sv/LC_MESSAGES", + "/usr/share/locale/sv_SE", + "/usr/share/locale/sv_SE/LC_MESSAGES", + "/usr/share/locale/sw", + "/usr/share/locale/sw/LC_MESSAGES", + "/usr/share/locale/syc", + "/usr/share/locale/syc/LC_MESSAGES", + "/usr/share/locale/syr", + "/usr/share/locale/syr/LC_MESSAGES", + "/usr/share/locale/szl", + "/usr/share/locale/szl/LC_MESSAGES", + "/usr/share/locale/ta", + "/usr/share/locale/ta/LC_MESSAGES", + "/usr/share/locale/ta_IN", + "/usr/share/locale/ta_IN/LC_MESSAGES", + "/usr/share/locale/ta_LK", + "/usr/share/locale/ta_LK/LC_MESSAGES", + "/usr/share/locale/tai", + "/usr/share/locale/tai/LC_MESSAGES", + "/usr/share/locale/te", + "/usr/share/locale/te/LC_MESSAGES", + "/usr/share/locale/tem", + "/usr/share/locale/tem/LC_MESSAGES", + "/usr/share/locale/ter", + "/usr/share/locale/ter/LC_MESSAGES", + "/usr/share/locale/tet", + "/usr/share/locale/tet/LC_MESSAGES", + "/usr/share/locale/tg", + "/usr/share/locale/tg/LC_MESSAGES", + "/usr/share/locale/th", + "/usr/share/locale/th/LC_MESSAGES", + "/usr/share/locale/th_TH", + "/usr/share/locale/th_TH/LC_MESSAGES", + "/usr/share/locale/ti", + "/usr/share/locale/ti/LC_MESSAGES", + "/usr/share/locale/tig", + "/usr/share/locale/tig/LC_MESSAGES", + "/usr/share/locale/tiv", + "/usr/share/locale/tiv/LC_MESSAGES", + "/usr/share/locale/tk", + "/usr/share/locale/tk/LC_MESSAGES", + "/usr/share/locale/tkl", + "/usr/share/locale/tkl/LC_MESSAGES", + "/usr/share/locale/tl", + "/usr/share/locale/tl/LC_MESSAGES", + "/usr/share/locale/tl_PH", + "/usr/share/locale/tl_PH/LC_MESSAGES", + "/usr/share/locale/tlh", + "/usr/share/locale/tlh/LC_MESSAGES", + "/usr/share/locale/tli", + "/usr/share/locale/tli/LC_MESSAGES", + "/usr/share/locale/tmh", + "/usr/share/locale/tmh/LC_MESSAGES", + "/usr/share/locale/tn", + "/usr/share/locale/tn/LC_MESSAGES", + "/usr/share/locale/to", + "/usr/share/locale/to/LC_MESSAGES", + "/usr/share/locale/tog", + "/usr/share/locale/tog/LC_MESSAGES", + "/usr/share/locale/ton", + "/usr/share/locale/ton/LC_MESSAGES", + "/usr/share/locale/tpi", + "/usr/share/locale/tpi/LC_MESSAGES", + "/usr/share/locale/tr", + "/usr/share/locale/tr/LC_MESSAGES", + "/usr/share/locale/tr_TR", + "/usr/share/locale/tr_TR/LC_MESSAGES", + "/usr/share/locale/ts", + "/usr/share/locale/ts/LC_MESSAGES", + "/usr/share/locale/tsi", + "/usr/share/locale/tsi/LC_MESSAGES", + "/usr/share/locale/tt", + "/usr/share/locale/tt/LC_MESSAGES", + "/usr/share/locale/tt@iqtelif", + "/usr/share/locale/tt@iqtelif/LC_MESSAGES", + "/usr/share/locale/tt_RU", + "/usr/share/locale/tt_RU/LC_MESSAGES", + "/usr/share/locale/tum", + "/usr/share/locale/tum/LC_MESSAGES", + "/usr/share/locale/tup", + "/usr/share/locale/tup/LC_MESSAGES", + "/usr/share/locale/tut", + "/usr/share/locale/tut/LC_MESSAGES", + "/usr/share/locale/tvl", + "/usr/share/locale/tvl/LC_MESSAGES", + "/usr/share/locale/tw", + "/usr/share/locale/tw/LC_MESSAGES", + "/usr/share/locale/ty", + "/usr/share/locale/ty/LC_MESSAGES", + "/usr/share/locale/tyv", + "/usr/share/locale/tyv/LC_MESSAGES", + "/usr/share/locale/tzm", + "/usr/share/locale/tzm/LC_MESSAGES", + "/usr/share/locale/tzo", + "/usr/share/locale/tzo/LC_MESSAGES", + "/usr/share/locale/ua", + "/usr/share/locale/ua/LC_MESSAGES", + "/usr/share/locale/udm", + "/usr/share/locale/udm/LC_MESSAGES", + "/usr/share/locale/ug", + "/usr/share/locale/ug/LC_MESSAGES", + "/usr/share/locale/uga", + "/usr/share/locale/uga/LC_MESSAGES", + "/usr/share/locale/uk", + "/usr/share/locale/uk/LC_MESSAGES", + "/usr/share/locale/uk_UA", + "/usr/share/locale/uk_UA/LC_MESSAGES", + "/usr/share/locale/umb", + "/usr/share/locale/umb/LC_MESSAGES", + "/usr/share/locale/und", + "/usr/share/locale/und/LC_MESSAGES", + "/usr/share/locale/ur", + "/usr/share/locale/ur/LC_MESSAGES", + "/usr/share/locale/ur_PK", + "/usr/share/locale/ur_PK/LC_MESSAGES", + "/usr/share/locale/uz", + "/usr/share/locale/uz/LC_MESSAGES", + "/usr/share/locale/uz@Cyrl", + "/usr/share/locale/uz@Cyrl/LC_MESSAGES", + "/usr/share/locale/uz@Latn", + "/usr/share/locale/uz@Latn/LC_MESSAGES", + "/usr/share/locale/uz@cyrillic", + "/usr/share/locale/uz@cyrillic/LC_MESSAGES", + "/usr/share/locale/vai", + "/usr/share/locale/vai/LC_MESSAGES", + "/usr/share/locale/ve", + "/usr/share/locale/ve/LC_MESSAGES", + "/usr/share/locale/vec", + "/usr/share/locale/vec/LC_MESSAGES", + "/usr/share/locale/ven", + "/usr/share/locale/ven/LC_MESSAGES", + "/usr/share/locale/vi", + "/usr/share/locale/vi/LC_MESSAGES", + "/usr/share/locale/vi_VN", + "/usr/share/locale/vi_VN/LC_MESSAGES", + "/usr/share/locale/vo", + "/usr/share/locale/vo/LC_MESSAGES", + "/usr/share/locale/vot", + "/usr/share/locale/vot/LC_MESSAGES", + "/usr/share/locale/wa", + "/usr/share/locale/wa/LC_MESSAGES", + "/usr/share/locale/wae", + "/usr/share/locale/wae/LC_MESSAGES", + "/usr/share/locale/wak", + "/usr/share/locale/wak/LC_MESSAGES", + "/usr/share/locale/wal", + "/usr/share/locale/wal/LC_MESSAGES", + "/usr/share/locale/war", + "/usr/share/locale/war/LC_MESSAGES", + "/usr/share/locale/was", + "/usr/share/locale/was/LC_MESSAGES", + "/usr/share/locale/wba", + "/usr/share/locale/wba/LC_MESSAGES", + "/usr/share/locale/wen", + "/usr/share/locale/wen/LC_MESSAGES", + "/usr/share/locale/wo", + "/usr/share/locale/wo/LC_MESSAGES", + "/usr/share/locale/xal", + "/usr/share/locale/xal/LC_MESSAGES", + "/usr/share/locale/xh", + "/usr/share/locale/xh/LC_MESSAGES", + "/usr/share/locale/yao", + "/usr/share/locale/yao/LC_MESSAGES", + "/usr/share/locale/yap", + "/usr/share/locale/yap/LC_MESSAGES", + "/usr/share/locale/yi", + "/usr/share/locale/yi/LC_MESSAGES", + "/usr/share/locale/yo", + "/usr/share/locale/yo/LC_MESSAGES", + "/usr/share/locale/ypk", + "/usr/share/locale/ypk/LC_MESSAGES", + "/usr/share/locale/za", + "/usr/share/locale/za/LC_MESSAGES", + "/usr/share/locale/zam", + "/usr/share/locale/zam/LC_MESSAGES", + "/usr/share/locale/zap", + "/usr/share/locale/zap/LC_MESSAGES", + "/usr/share/locale/zbl", + "/usr/share/locale/zbl/LC_MESSAGES", + "/usr/share/locale/zen", + "/usr/share/locale/zen/LC_MESSAGES", + "/usr/share/locale/zgh", + "/usr/share/locale/zgh/LC_MESSAGES", + "/usr/share/locale/zh", + "/usr/share/locale/zh-Hans", + "/usr/share/locale/zh-Hans/LC_MESSAGES", + "/usr/share/locale/zh-Hant", + "/usr/share/locale/zh-Hant/LC_MESSAGES", + "/usr/share/locale/zh/LC_MESSAGES", + "/usr/share/locale/zh_CN", + "/usr/share/locale/zh_CN.GB2312", + "/usr/share/locale/zh_CN.GB2312/LC_MESSAGES", + "/usr/share/locale/zh_CN/LC_MESSAGES", + "/usr/share/locale/zh_HK", + "/usr/share/locale/zh_HK/LC_MESSAGES", + "/usr/share/locale/zh_TW", + "/usr/share/locale/zh_TW.Big5", + "/usr/share/locale/zh_TW.Big5/LC_MESSAGES", + "/usr/share/locale/zh_TW/LC_MESSAGES", + "/usr/share/locale/znd", + "/usr/share/locale/znd/LC_MESSAGES", + "/usr/share/locale/zu", + "/usr/share/locale/zu/LC_MESSAGES", + "/usr/share/locale/zun", + "/usr/share/locale/zun/LC_MESSAGES", + "/usr/share/locale/zxx", + "/usr/share/locale/zxx/LC_MESSAGES", + "/usr/share/locale/zza", + "/usr/share/locale/zza/LC_MESSAGES", + "/usr/share/man", + "/usr/share/man/aa", + "/usr/share/man/aa/man0p", + "/usr/share/man/aa/man1", + "/usr/share/man/aa/man1p", + "/usr/share/man/aa/man1x", + "/usr/share/man/aa/man2", + "/usr/share/man/aa/man2x", + "/usr/share/man/aa/man3", + "/usr/share/man/aa/man3p", + "/usr/share/man/aa/man3x", + "/usr/share/man/aa/man4", + "/usr/share/man/aa/man4x", + "/usr/share/man/aa/man5", + "/usr/share/man/aa/man5x", + "/usr/share/man/aa/man6", + "/usr/share/man/aa/man6x", + "/usr/share/man/aa/man7", + "/usr/share/man/aa/man7x", + "/usr/share/man/aa/man8", + "/usr/share/man/aa/man8x", + "/usr/share/man/aa/man9", + "/usr/share/man/aa/man9x", + "/usr/share/man/aa/mann", + "/usr/share/man/ab", + "/usr/share/man/ab/man0p", + "/usr/share/man/ab/man1", + "/usr/share/man/ab/man1p", + "/usr/share/man/ab/man1x", + "/usr/share/man/ab/man2", + "/usr/share/man/ab/man2x", + "/usr/share/man/ab/man3", + "/usr/share/man/ab/man3p", + "/usr/share/man/ab/man3x", + "/usr/share/man/ab/man4", + "/usr/share/man/ab/man4x", + "/usr/share/man/ab/man5", + "/usr/share/man/ab/man5x", + "/usr/share/man/ab/man6", + "/usr/share/man/ab/man6x", + "/usr/share/man/ab/man7", + "/usr/share/man/ab/man7x", + "/usr/share/man/ab/man8", + "/usr/share/man/ab/man8x", + "/usr/share/man/ab/man9", + "/usr/share/man/ab/man9x", + "/usr/share/man/ab/mann", + "/usr/share/man/ace", + "/usr/share/man/ace/man0p", + "/usr/share/man/ace/man1", + "/usr/share/man/ace/man1p", + "/usr/share/man/ace/man1x", + "/usr/share/man/ace/man2", + "/usr/share/man/ace/man2x", + "/usr/share/man/ace/man3", + "/usr/share/man/ace/man3p", + "/usr/share/man/ace/man3x", + "/usr/share/man/ace/man4", + "/usr/share/man/ace/man4x", + "/usr/share/man/ace/man5", + "/usr/share/man/ace/man5x", + "/usr/share/man/ace/man6", + "/usr/share/man/ace/man6x", + "/usr/share/man/ace/man7", + "/usr/share/man/ace/man7x", + "/usr/share/man/ace/man8", + "/usr/share/man/ace/man8x", + "/usr/share/man/ace/man9", + "/usr/share/man/ace/man9x", + "/usr/share/man/ace/mann", + "/usr/share/man/ach", + "/usr/share/man/ach/man0p", + "/usr/share/man/ach/man1", + "/usr/share/man/ach/man1p", + "/usr/share/man/ach/man1x", + "/usr/share/man/ach/man2", + "/usr/share/man/ach/man2x", + "/usr/share/man/ach/man3", + "/usr/share/man/ach/man3p", + "/usr/share/man/ach/man3x", + "/usr/share/man/ach/man4", + "/usr/share/man/ach/man4x", + "/usr/share/man/ach/man5", + "/usr/share/man/ach/man5x", + "/usr/share/man/ach/man6", + "/usr/share/man/ach/man6x", + "/usr/share/man/ach/man7", + "/usr/share/man/ach/man7x", + "/usr/share/man/ach/man8", + "/usr/share/man/ach/man8x", + "/usr/share/man/ach/man9", + "/usr/share/man/ach/man9x", + "/usr/share/man/ach/mann", + "/usr/share/man/ada", + "/usr/share/man/ada/man0p", + "/usr/share/man/ada/man1", + "/usr/share/man/ada/man1p", + "/usr/share/man/ada/man1x", + "/usr/share/man/ada/man2", + "/usr/share/man/ada/man2x", + "/usr/share/man/ada/man3", + "/usr/share/man/ada/man3p", + "/usr/share/man/ada/man3x", + "/usr/share/man/ada/man4", + "/usr/share/man/ada/man4x", + "/usr/share/man/ada/man5", + "/usr/share/man/ada/man5x", + "/usr/share/man/ada/man6", + "/usr/share/man/ada/man6x", + "/usr/share/man/ada/man7", + "/usr/share/man/ada/man7x", + "/usr/share/man/ada/man8", + "/usr/share/man/ada/man8x", + "/usr/share/man/ada/man9", + "/usr/share/man/ada/man9x", + "/usr/share/man/ada/mann", + "/usr/share/man/ady", + "/usr/share/man/ady/man0p", + "/usr/share/man/ady/man1", + "/usr/share/man/ady/man1p", + "/usr/share/man/ady/man1x", + "/usr/share/man/ady/man2", + "/usr/share/man/ady/man2x", + "/usr/share/man/ady/man3", + "/usr/share/man/ady/man3p", + "/usr/share/man/ady/man3x", + "/usr/share/man/ady/man4", + "/usr/share/man/ady/man4x", + "/usr/share/man/ady/man5", + "/usr/share/man/ady/man5x", + "/usr/share/man/ady/man6", + "/usr/share/man/ady/man6x", + "/usr/share/man/ady/man7", + "/usr/share/man/ady/man7x", + "/usr/share/man/ady/man8", + "/usr/share/man/ady/man8x", + "/usr/share/man/ady/man9", + "/usr/share/man/ady/man9x", + "/usr/share/man/ady/mann", + "/usr/share/man/ae", + "/usr/share/man/ae/man0p", + "/usr/share/man/ae/man1", + "/usr/share/man/ae/man1p", + "/usr/share/man/ae/man1x", + "/usr/share/man/ae/man2", + "/usr/share/man/ae/man2x", + "/usr/share/man/ae/man3", + "/usr/share/man/ae/man3p", + "/usr/share/man/ae/man3x", + "/usr/share/man/ae/man4", + "/usr/share/man/ae/man4x", + "/usr/share/man/ae/man5", + "/usr/share/man/ae/man5x", + "/usr/share/man/ae/man6", + "/usr/share/man/ae/man6x", + "/usr/share/man/ae/man7", + "/usr/share/man/ae/man7x", + "/usr/share/man/ae/man8", + "/usr/share/man/ae/man8x", + "/usr/share/man/ae/man9", + "/usr/share/man/ae/man9x", + "/usr/share/man/ae/mann", + "/usr/share/man/af", + "/usr/share/man/af/man0p", + "/usr/share/man/af/man1", + "/usr/share/man/af/man1p", + "/usr/share/man/af/man1x", + "/usr/share/man/af/man2", + "/usr/share/man/af/man2x", + "/usr/share/man/af/man3", + "/usr/share/man/af/man3p", + "/usr/share/man/af/man3x", + "/usr/share/man/af/man4", + "/usr/share/man/af/man4x", + "/usr/share/man/af/man5", + "/usr/share/man/af/man5x", + "/usr/share/man/af/man6", + "/usr/share/man/af/man6x", + "/usr/share/man/af/man7", + "/usr/share/man/af/man7x", + "/usr/share/man/af/man8", + "/usr/share/man/af/man8x", + "/usr/share/man/af/man9", + "/usr/share/man/af/man9x", + "/usr/share/man/af/mann", + "/usr/share/man/af_ZA", + "/usr/share/man/af_ZA/man0p", + "/usr/share/man/af_ZA/man1", + "/usr/share/man/af_ZA/man1p", + "/usr/share/man/af_ZA/man1x", + "/usr/share/man/af_ZA/man2", + "/usr/share/man/af_ZA/man2x", + "/usr/share/man/af_ZA/man3", + "/usr/share/man/af_ZA/man3p", + "/usr/share/man/af_ZA/man3x", + "/usr/share/man/af_ZA/man4", + "/usr/share/man/af_ZA/man4x", + "/usr/share/man/af_ZA/man5", + "/usr/share/man/af_ZA/man5x", + "/usr/share/man/af_ZA/man6", + "/usr/share/man/af_ZA/man6x", + "/usr/share/man/af_ZA/man7", + "/usr/share/man/af_ZA/man7x", + "/usr/share/man/af_ZA/man8", + "/usr/share/man/af_ZA/man8x", + "/usr/share/man/af_ZA/man9", + "/usr/share/man/af_ZA/man9x", + "/usr/share/man/af_ZA/mann", + "/usr/share/man/afa", + "/usr/share/man/afa/man0p", + "/usr/share/man/afa/man1", + "/usr/share/man/afa/man1p", + "/usr/share/man/afa/man1x", + "/usr/share/man/afa/man2", + "/usr/share/man/afa/man2x", + "/usr/share/man/afa/man3", + "/usr/share/man/afa/man3p", + "/usr/share/man/afa/man3x", + "/usr/share/man/afa/man4", + "/usr/share/man/afa/man4x", + "/usr/share/man/afa/man5", + "/usr/share/man/afa/man5x", + "/usr/share/man/afa/man6", + "/usr/share/man/afa/man6x", + "/usr/share/man/afa/man7", + "/usr/share/man/afa/man7x", + "/usr/share/man/afa/man8", + "/usr/share/man/afa/man8x", + "/usr/share/man/afa/man9", + "/usr/share/man/afa/man9x", + "/usr/share/man/afa/mann", + "/usr/share/man/afh", + "/usr/share/man/afh/man0p", + "/usr/share/man/afh/man1", + "/usr/share/man/afh/man1p", + "/usr/share/man/afh/man1x", + "/usr/share/man/afh/man2", + "/usr/share/man/afh/man2x", + "/usr/share/man/afh/man3", + "/usr/share/man/afh/man3p", + "/usr/share/man/afh/man3x", + "/usr/share/man/afh/man4", + "/usr/share/man/afh/man4x", + "/usr/share/man/afh/man5", + "/usr/share/man/afh/man5x", + "/usr/share/man/afh/man6", + "/usr/share/man/afh/man6x", + "/usr/share/man/afh/man7", + "/usr/share/man/afh/man7x", + "/usr/share/man/afh/man8", + "/usr/share/man/afh/man8x", + "/usr/share/man/afh/man9", + "/usr/share/man/afh/man9x", + "/usr/share/man/afh/mann", + "/usr/share/man/agr", + "/usr/share/man/agr/man0p", + "/usr/share/man/agr/man1", + "/usr/share/man/agr/man1p", + "/usr/share/man/agr/man1x", + "/usr/share/man/agr/man2", + "/usr/share/man/agr/man2x", + "/usr/share/man/agr/man3", + "/usr/share/man/agr/man3p", + "/usr/share/man/agr/man3x", + "/usr/share/man/agr/man4", + "/usr/share/man/agr/man4x", + "/usr/share/man/agr/man5", + "/usr/share/man/agr/man5x", + "/usr/share/man/agr/man6", + "/usr/share/man/agr/man6x", + "/usr/share/man/agr/man7", + "/usr/share/man/agr/man7x", + "/usr/share/man/agr/man8", + "/usr/share/man/agr/man8x", + "/usr/share/man/agr/man9", + "/usr/share/man/agr/man9x", + "/usr/share/man/agr/mann", + "/usr/share/man/ain", + "/usr/share/man/ain/man0p", + "/usr/share/man/ain/man1", + "/usr/share/man/ain/man1p", + "/usr/share/man/ain/man1x", + "/usr/share/man/ain/man2", + "/usr/share/man/ain/man2x", + "/usr/share/man/ain/man3", + "/usr/share/man/ain/man3p", + "/usr/share/man/ain/man3x", + "/usr/share/man/ain/man4", + "/usr/share/man/ain/man4x", + "/usr/share/man/ain/man5", + "/usr/share/man/ain/man5x", + "/usr/share/man/ain/man6", + "/usr/share/man/ain/man6x", + "/usr/share/man/ain/man7", + "/usr/share/man/ain/man7x", + "/usr/share/man/ain/man8", + "/usr/share/man/ain/man8x", + "/usr/share/man/ain/man9", + "/usr/share/man/ain/man9x", + "/usr/share/man/ain/mann", + "/usr/share/man/ak", + "/usr/share/man/ak/man0p", + "/usr/share/man/ak/man1", + "/usr/share/man/ak/man1p", + "/usr/share/man/ak/man1x", + "/usr/share/man/ak/man2", + "/usr/share/man/ak/man2x", + "/usr/share/man/ak/man3", + "/usr/share/man/ak/man3p", + "/usr/share/man/ak/man3x", + "/usr/share/man/ak/man4", + "/usr/share/man/ak/man4x", + "/usr/share/man/ak/man5", + "/usr/share/man/ak/man5x", + "/usr/share/man/ak/man6", + "/usr/share/man/ak/man6x", + "/usr/share/man/ak/man7", + "/usr/share/man/ak/man7x", + "/usr/share/man/ak/man8", + "/usr/share/man/ak/man8x", + "/usr/share/man/ak/man9", + "/usr/share/man/ak/man9x", + "/usr/share/man/ak/mann", + "/usr/share/man/akk", + "/usr/share/man/akk/man0p", + "/usr/share/man/akk/man1", + "/usr/share/man/akk/man1p", + "/usr/share/man/akk/man1x", + "/usr/share/man/akk/man2", + "/usr/share/man/akk/man2x", + "/usr/share/man/akk/man3", + "/usr/share/man/akk/man3p", + "/usr/share/man/akk/man3x", + "/usr/share/man/akk/man4", + "/usr/share/man/akk/man4x", + "/usr/share/man/akk/man5", + "/usr/share/man/akk/man5x", + "/usr/share/man/akk/man6", + "/usr/share/man/akk/man6x", + "/usr/share/man/akk/man7", + "/usr/share/man/akk/man7x", + "/usr/share/man/akk/man8", + "/usr/share/man/akk/man8x", + "/usr/share/man/akk/man9", + "/usr/share/man/akk/man9x", + "/usr/share/man/akk/mann", + "/usr/share/man/ale", + "/usr/share/man/ale/man0p", + "/usr/share/man/ale/man1", + "/usr/share/man/ale/man1p", + "/usr/share/man/ale/man1x", + "/usr/share/man/ale/man2", + "/usr/share/man/ale/man2x", + "/usr/share/man/ale/man3", + "/usr/share/man/ale/man3p", + "/usr/share/man/ale/man3x", + "/usr/share/man/ale/man4", + "/usr/share/man/ale/man4x", + "/usr/share/man/ale/man5", + "/usr/share/man/ale/man5x", + "/usr/share/man/ale/man6", + "/usr/share/man/ale/man6x", + "/usr/share/man/ale/man7", + "/usr/share/man/ale/man7x", + "/usr/share/man/ale/man8", + "/usr/share/man/ale/man8x", + "/usr/share/man/ale/man9", + "/usr/share/man/ale/man9x", + "/usr/share/man/ale/mann", + "/usr/share/man/alg", + "/usr/share/man/alg/man0p", + "/usr/share/man/alg/man1", + "/usr/share/man/alg/man1p", + "/usr/share/man/alg/man1x", + "/usr/share/man/alg/man2", + "/usr/share/man/alg/man2x", + "/usr/share/man/alg/man3", + "/usr/share/man/alg/man3p", + "/usr/share/man/alg/man3x", + "/usr/share/man/alg/man4", + "/usr/share/man/alg/man4x", + "/usr/share/man/alg/man5", + "/usr/share/man/alg/man5x", + "/usr/share/man/alg/man6", + "/usr/share/man/alg/man6x", + "/usr/share/man/alg/man7", + "/usr/share/man/alg/man7x", + "/usr/share/man/alg/man8", + "/usr/share/man/alg/man8x", + "/usr/share/man/alg/man9", + "/usr/share/man/alg/man9x", + "/usr/share/man/alg/mann", + "/usr/share/man/aln", + "/usr/share/man/aln/man0p", + "/usr/share/man/aln/man1", + "/usr/share/man/aln/man1p", + "/usr/share/man/aln/man1x", + "/usr/share/man/aln/man2", + "/usr/share/man/aln/man2x", + "/usr/share/man/aln/man3", + "/usr/share/man/aln/man3p", + "/usr/share/man/aln/man3x", + "/usr/share/man/aln/man4", + "/usr/share/man/aln/man4x", + "/usr/share/man/aln/man5", + "/usr/share/man/aln/man5x", + "/usr/share/man/aln/man6", + "/usr/share/man/aln/man6x", + "/usr/share/man/aln/man7", + "/usr/share/man/aln/man7x", + "/usr/share/man/aln/man8", + "/usr/share/man/aln/man8x", + "/usr/share/man/aln/man9", + "/usr/share/man/aln/man9x", + "/usr/share/man/aln/mann", + "/usr/share/man/alt", + "/usr/share/man/alt/man0p", + "/usr/share/man/alt/man1", + "/usr/share/man/alt/man1p", + "/usr/share/man/alt/man1x", + "/usr/share/man/alt/man2", + "/usr/share/man/alt/man2x", + "/usr/share/man/alt/man3", + "/usr/share/man/alt/man3p", + "/usr/share/man/alt/man3x", + "/usr/share/man/alt/man4", + "/usr/share/man/alt/man4x", + "/usr/share/man/alt/man5", + "/usr/share/man/alt/man5x", + "/usr/share/man/alt/man6", + "/usr/share/man/alt/man6x", + "/usr/share/man/alt/man7", + "/usr/share/man/alt/man7x", + "/usr/share/man/alt/man8", + "/usr/share/man/alt/man8x", + "/usr/share/man/alt/man9", + "/usr/share/man/alt/man9x", + "/usr/share/man/alt/mann", + "/usr/share/man/am", + "/usr/share/man/am/man0p", + "/usr/share/man/am/man1", + "/usr/share/man/am/man1p", + "/usr/share/man/am/man1x", + "/usr/share/man/am/man2", + "/usr/share/man/am/man2x", + "/usr/share/man/am/man3", + "/usr/share/man/am/man3p", + "/usr/share/man/am/man3x", + "/usr/share/man/am/man4", + "/usr/share/man/am/man4x", + "/usr/share/man/am/man5", + "/usr/share/man/am/man5x", + "/usr/share/man/am/man6", + "/usr/share/man/am/man6x", + "/usr/share/man/am/man7", + "/usr/share/man/am/man7x", + "/usr/share/man/am/man8", + "/usr/share/man/am/man8x", + "/usr/share/man/am/man9", + "/usr/share/man/am/man9x", + "/usr/share/man/am/mann", + "/usr/share/man/an", + "/usr/share/man/an/man0p", + "/usr/share/man/an/man1", + "/usr/share/man/an/man1p", + "/usr/share/man/an/man1x", + "/usr/share/man/an/man2", + "/usr/share/man/an/man2x", + "/usr/share/man/an/man3", + "/usr/share/man/an/man3p", + "/usr/share/man/an/man3x", + "/usr/share/man/an/man4", + "/usr/share/man/an/man4x", + "/usr/share/man/an/man5", + "/usr/share/man/an/man5x", + "/usr/share/man/an/man6", + "/usr/share/man/an/man6x", + "/usr/share/man/an/man7", + "/usr/share/man/an/man7x", + "/usr/share/man/an/man8", + "/usr/share/man/an/man8x", + "/usr/share/man/an/man9", + "/usr/share/man/an/man9x", + "/usr/share/man/an/mann", + "/usr/share/man/ang", + "/usr/share/man/ang/man0p", + "/usr/share/man/ang/man1", + "/usr/share/man/ang/man1p", + "/usr/share/man/ang/man1x", + "/usr/share/man/ang/man2", + "/usr/share/man/ang/man2x", + "/usr/share/man/ang/man3", + "/usr/share/man/ang/man3p", + "/usr/share/man/ang/man3x", + "/usr/share/man/ang/man4", + "/usr/share/man/ang/man4x", + "/usr/share/man/ang/man5", + "/usr/share/man/ang/man5x", + "/usr/share/man/ang/man6", + "/usr/share/man/ang/man6x", + "/usr/share/man/ang/man7", + "/usr/share/man/ang/man7x", + "/usr/share/man/ang/man8", + "/usr/share/man/ang/man8x", + "/usr/share/man/ang/man9", + "/usr/share/man/ang/man9x", + "/usr/share/man/ang/mann", + "/usr/share/man/anp", + "/usr/share/man/anp/man0p", + "/usr/share/man/anp/man1", + "/usr/share/man/anp/man1p", + "/usr/share/man/anp/man1x", + "/usr/share/man/anp/man2", + "/usr/share/man/anp/man2x", + "/usr/share/man/anp/man3", + "/usr/share/man/anp/man3p", + "/usr/share/man/anp/man3x", + "/usr/share/man/anp/man4", + "/usr/share/man/anp/man4x", + "/usr/share/man/anp/man5", + "/usr/share/man/anp/man5x", + "/usr/share/man/anp/man6", + "/usr/share/man/anp/man6x", + "/usr/share/man/anp/man7", + "/usr/share/man/anp/man7x", + "/usr/share/man/anp/man8", + "/usr/share/man/anp/man8x", + "/usr/share/man/anp/man9", + "/usr/share/man/anp/man9x", + "/usr/share/man/anp/mann", + "/usr/share/man/apa", + "/usr/share/man/apa/man0p", + "/usr/share/man/apa/man1", + "/usr/share/man/apa/man1p", + "/usr/share/man/apa/man1x", + "/usr/share/man/apa/man2", + "/usr/share/man/apa/man2x", + "/usr/share/man/apa/man3", + "/usr/share/man/apa/man3p", + "/usr/share/man/apa/man3x", + "/usr/share/man/apa/man4", + "/usr/share/man/apa/man4x", + "/usr/share/man/apa/man5", + "/usr/share/man/apa/man5x", + "/usr/share/man/apa/man6", + "/usr/share/man/apa/man6x", + "/usr/share/man/apa/man7", + "/usr/share/man/apa/man7x", + "/usr/share/man/apa/man8", + "/usr/share/man/apa/man8x", + "/usr/share/man/apa/man9", + "/usr/share/man/apa/man9x", + "/usr/share/man/apa/mann", + "/usr/share/man/ar", + "/usr/share/man/ar/man0p", + "/usr/share/man/ar/man1", + "/usr/share/man/ar/man1p", + "/usr/share/man/ar/man1x", + "/usr/share/man/ar/man2", + "/usr/share/man/ar/man2x", + "/usr/share/man/ar/man3", + "/usr/share/man/ar/man3p", + "/usr/share/man/ar/man3x", + "/usr/share/man/ar/man4", + "/usr/share/man/ar/man4x", + "/usr/share/man/ar/man5", + "/usr/share/man/ar/man5x", + "/usr/share/man/ar/man6", + "/usr/share/man/ar/man6x", + "/usr/share/man/ar/man7", + "/usr/share/man/ar/man7x", + "/usr/share/man/ar/man8", + "/usr/share/man/ar/man8x", + "/usr/share/man/ar/man9", + "/usr/share/man/ar/man9x", + "/usr/share/man/ar/mann", + "/usr/share/man/ar_DZ", + "/usr/share/man/ar_DZ/man0p", + "/usr/share/man/ar_DZ/man1", + "/usr/share/man/ar_DZ/man1p", + "/usr/share/man/ar_DZ/man1x", + "/usr/share/man/ar_DZ/man2", + "/usr/share/man/ar_DZ/man2x", + "/usr/share/man/ar_DZ/man3", + "/usr/share/man/ar_DZ/man3p", + "/usr/share/man/ar_DZ/man3x", + "/usr/share/man/ar_DZ/man4", + "/usr/share/man/ar_DZ/man4x", + "/usr/share/man/ar_DZ/man5", + "/usr/share/man/ar_DZ/man5x", + "/usr/share/man/ar_DZ/man6", + "/usr/share/man/ar_DZ/man6x", + "/usr/share/man/ar_DZ/man7", + "/usr/share/man/ar_DZ/man7x", + "/usr/share/man/ar_DZ/man8", + "/usr/share/man/ar_DZ/man8x", + "/usr/share/man/ar_DZ/man9", + "/usr/share/man/ar_DZ/man9x", + "/usr/share/man/ar_DZ/mann", + "/usr/share/man/ar_SY", + "/usr/share/man/ar_SY/man0p", + "/usr/share/man/ar_SY/man1", + "/usr/share/man/ar_SY/man1p", + "/usr/share/man/ar_SY/man1x", + "/usr/share/man/ar_SY/man2", + "/usr/share/man/ar_SY/man2x", + "/usr/share/man/ar_SY/man3", + "/usr/share/man/ar_SY/man3p", + "/usr/share/man/ar_SY/man3x", + "/usr/share/man/ar_SY/man4", + "/usr/share/man/ar_SY/man4x", + "/usr/share/man/ar_SY/man5", + "/usr/share/man/ar_SY/man5x", + "/usr/share/man/ar_SY/man6", + "/usr/share/man/ar_SY/man6x", + "/usr/share/man/ar_SY/man7", + "/usr/share/man/ar_SY/man7x", + "/usr/share/man/ar_SY/man8", + "/usr/share/man/ar_SY/man8x", + "/usr/share/man/ar_SY/man9", + "/usr/share/man/ar_SY/man9x", + "/usr/share/man/ar_SY/mann", + "/usr/share/man/arc", + "/usr/share/man/arc/man0p", + "/usr/share/man/arc/man1", + "/usr/share/man/arc/man1p", + "/usr/share/man/arc/man1x", + "/usr/share/man/arc/man2", + "/usr/share/man/arc/man2x", + "/usr/share/man/arc/man3", + "/usr/share/man/arc/man3p", + "/usr/share/man/arc/man3x", + "/usr/share/man/arc/man4", + "/usr/share/man/arc/man4x", + "/usr/share/man/arc/man5", + "/usr/share/man/arc/man5x", + "/usr/share/man/arc/man6", + "/usr/share/man/arc/man6x", + "/usr/share/man/arc/man7", + "/usr/share/man/arc/man7x", + "/usr/share/man/arc/man8", + "/usr/share/man/arc/man8x", + "/usr/share/man/arc/man9", + "/usr/share/man/arc/man9x", + "/usr/share/man/arc/mann", + "/usr/share/man/arn", + "/usr/share/man/arn/man0p", + "/usr/share/man/arn/man1", + "/usr/share/man/arn/man1p", + "/usr/share/man/arn/man1x", + "/usr/share/man/arn/man2", + "/usr/share/man/arn/man2x", + "/usr/share/man/arn/man3", + "/usr/share/man/arn/man3p", + "/usr/share/man/arn/man3x", + "/usr/share/man/arn/man4", + "/usr/share/man/arn/man4x", + "/usr/share/man/arn/man5", + "/usr/share/man/arn/man5x", + "/usr/share/man/arn/man6", + "/usr/share/man/arn/man6x", + "/usr/share/man/arn/man7", + "/usr/share/man/arn/man7x", + "/usr/share/man/arn/man8", + "/usr/share/man/arn/man8x", + "/usr/share/man/arn/man9", + "/usr/share/man/arn/man9x", + "/usr/share/man/arn/mann", + "/usr/share/man/arp", + "/usr/share/man/arp/man0p", + "/usr/share/man/arp/man1", + "/usr/share/man/arp/man1p", + "/usr/share/man/arp/man1x", + "/usr/share/man/arp/man2", + "/usr/share/man/arp/man2x", + "/usr/share/man/arp/man3", + "/usr/share/man/arp/man3p", + "/usr/share/man/arp/man3x", + "/usr/share/man/arp/man4", + "/usr/share/man/arp/man4x", + "/usr/share/man/arp/man5", + "/usr/share/man/arp/man5x", + "/usr/share/man/arp/man6", + "/usr/share/man/arp/man6x", + "/usr/share/man/arp/man7", + "/usr/share/man/arp/man7x", + "/usr/share/man/arp/man8", + "/usr/share/man/arp/man8x", + "/usr/share/man/arp/man9", + "/usr/share/man/arp/man9x", + "/usr/share/man/arp/mann", + "/usr/share/man/art", + "/usr/share/man/art/man0p", + "/usr/share/man/art/man1", + "/usr/share/man/art/man1p", + "/usr/share/man/art/man1x", + "/usr/share/man/art/man2", + "/usr/share/man/art/man2x", + "/usr/share/man/art/man3", + "/usr/share/man/art/man3p", + "/usr/share/man/art/man3x", + "/usr/share/man/art/man4", + "/usr/share/man/art/man4x", + "/usr/share/man/art/man5", + "/usr/share/man/art/man5x", + "/usr/share/man/art/man6", + "/usr/share/man/art/man6x", + "/usr/share/man/art/man7", + "/usr/share/man/art/man7x", + "/usr/share/man/art/man8", + "/usr/share/man/art/man8x", + "/usr/share/man/art/man9", + "/usr/share/man/art/man9x", + "/usr/share/man/art/mann", + "/usr/share/man/arw", + "/usr/share/man/arw/man0p", + "/usr/share/man/arw/man1", + "/usr/share/man/arw/man1p", + "/usr/share/man/arw/man1x", + "/usr/share/man/arw/man2", + "/usr/share/man/arw/man2x", + "/usr/share/man/arw/man3", + "/usr/share/man/arw/man3p", + "/usr/share/man/arw/man3x", + "/usr/share/man/arw/man4", + "/usr/share/man/arw/man4x", + "/usr/share/man/arw/man5", + "/usr/share/man/arw/man5x", + "/usr/share/man/arw/man6", + "/usr/share/man/arw/man6x", + "/usr/share/man/arw/man7", + "/usr/share/man/arw/man7x", + "/usr/share/man/arw/man8", + "/usr/share/man/arw/man8x", + "/usr/share/man/arw/man9", + "/usr/share/man/arw/man9x", + "/usr/share/man/arw/mann", + "/usr/share/man/as", + "/usr/share/man/as/man0p", + "/usr/share/man/as/man1", + "/usr/share/man/as/man1p", + "/usr/share/man/as/man1x", + "/usr/share/man/as/man2", + "/usr/share/man/as/man2x", + "/usr/share/man/as/man3", + "/usr/share/man/as/man3p", + "/usr/share/man/as/man3x", + "/usr/share/man/as/man4", + "/usr/share/man/as/man4x", + "/usr/share/man/as/man5", + "/usr/share/man/as/man5x", + "/usr/share/man/as/man6", + "/usr/share/man/as/man6x", + "/usr/share/man/as/man7", + "/usr/share/man/as/man7x", + "/usr/share/man/as/man8", + "/usr/share/man/as/man8x", + "/usr/share/man/as/man9", + "/usr/share/man/as/man9x", + "/usr/share/man/as/mann", + "/usr/share/man/ast", + "/usr/share/man/ast/man0p", + "/usr/share/man/ast/man1", + "/usr/share/man/ast/man1p", + "/usr/share/man/ast/man1x", + "/usr/share/man/ast/man2", + "/usr/share/man/ast/man2x", + "/usr/share/man/ast/man3", + "/usr/share/man/ast/man3p", + "/usr/share/man/ast/man3x", + "/usr/share/man/ast/man4", + "/usr/share/man/ast/man4x", + "/usr/share/man/ast/man5", + "/usr/share/man/ast/man5x", + "/usr/share/man/ast/man6", + "/usr/share/man/ast/man6x", + "/usr/share/man/ast/man7", + "/usr/share/man/ast/man7x", + "/usr/share/man/ast/man8", + "/usr/share/man/ast/man8x", + "/usr/share/man/ast/man9", + "/usr/share/man/ast/man9x", + "/usr/share/man/ast/mann", + "/usr/share/man/ath", + "/usr/share/man/ath/man0p", + "/usr/share/man/ath/man1", + "/usr/share/man/ath/man1p", + "/usr/share/man/ath/man1x", + "/usr/share/man/ath/man2", + "/usr/share/man/ath/man2x", + "/usr/share/man/ath/man3", + "/usr/share/man/ath/man3p", + "/usr/share/man/ath/man3x", + "/usr/share/man/ath/man4", + "/usr/share/man/ath/man4x", + "/usr/share/man/ath/man5", + "/usr/share/man/ath/man5x", + "/usr/share/man/ath/man6", + "/usr/share/man/ath/man6x", + "/usr/share/man/ath/man7", + "/usr/share/man/ath/man7x", + "/usr/share/man/ath/man8", + "/usr/share/man/ath/man8x", + "/usr/share/man/ath/man9", + "/usr/share/man/ath/man9x", + "/usr/share/man/ath/mann", + "/usr/share/man/aus", + "/usr/share/man/aus/man0p", + "/usr/share/man/aus/man1", + "/usr/share/man/aus/man1p", + "/usr/share/man/aus/man1x", + "/usr/share/man/aus/man2", + "/usr/share/man/aus/man2x", + "/usr/share/man/aus/man3", + "/usr/share/man/aus/man3p", + "/usr/share/man/aus/man3x", + "/usr/share/man/aus/man4", + "/usr/share/man/aus/man4x", + "/usr/share/man/aus/man5", + "/usr/share/man/aus/man5x", + "/usr/share/man/aus/man6", + "/usr/share/man/aus/man6x", + "/usr/share/man/aus/man7", + "/usr/share/man/aus/man7x", + "/usr/share/man/aus/man8", + "/usr/share/man/aus/man8x", + "/usr/share/man/aus/man9", + "/usr/share/man/aus/man9x", + "/usr/share/man/aus/mann", + "/usr/share/man/av", + "/usr/share/man/av/man0p", + "/usr/share/man/av/man1", + "/usr/share/man/av/man1p", + "/usr/share/man/av/man1x", + "/usr/share/man/av/man2", + "/usr/share/man/av/man2x", + "/usr/share/man/av/man3", + "/usr/share/man/av/man3p", + "/usr/share/man/av/man3x", + "/usr/share/man/av/man4", + "/usr/share/man/av/man4x", + "/usr/share/man/av/man5", + "/usr/share/man/av/man5x", + "/usr/share/man/av/man6", + "/usr/share/man/av/man6x", + "/usr/share/man/av/man7", + "/usr/share/man/av/man7x", + "/usr/share/man/av/man8", + "/usr/share/man/av/man8x", + "/usr/share/man/av/man9", + "/usr/share/man/av/man9x", + "/usr/share/man/av/mann", + "/usr/share/man/awa", + "/usr/share/man/awa/man0p", + "/usr/share/man/awa/man1", + "/usr/share/man/awa/man1p", + "/usr/share/man/awa/man1x", + "/usr/share/man/awa/man2", + "/usr/share/man/awa/man2x", + "/usr/share/man/awa/man3", + "/usr/share/man/awa/man3p", + "/usr/share/man/awa/man3x", + "/usr/share/man/awa/man4", + "/usr/share/man/awa/man4x", + "/usr/share/man/awa/man5", + "/usr/share/man/awa/man5x", + "/usr/share/man/awa/man6", + "/usr/share/man/awa/man6x", + "/usr/share/man/awa/man7", + "/usr/share/man/awa/man7x", + "/usr/share/man/awa/man8", + "/usr/share/man/awa/man8x", + "/usr/share/man/awa/man9", + "/usr/share/man/awa/man9x", + "/usr/share/man/awa/mann", + "/usr/share/man/ay", + "/usr/share/man/ay/man0p", + "/usr/share/man/ay/man1", + "/usr/share/man/ay/man1p", + "/usr/share/man/ay/man1x", + "/usr/share/man/ay/man2", + "/usr/share/man/ay/man2x", + "/usr/share/man/ay/man3", + "/usr/share/man/ay/man3p", + "/usr/share/man/ay/man3x", + "/usr/share/man/ay/man4", + "/usr/share/man/ay/man4x", + "/usr/share/man/ay/man5", + "/usr/share/man/ay/man5x", + "/usr/share/man/ay/man6", + "/usr/share/man/ay/man6x", + "/usr/share/man/ay/man7", + "/usr/share/man/ay/man7x", + "/usr/share/man/ay/man8", + "/usr/share/man/ay/man8x", + "/usr/share/man/ay/man9", + "/usr/share/man/ay/man9x", + "/usr/share/man/ay/mann", + "/usr/share/man/ayc", + "/usr/share/man/ayc/man0p", + "/usr/share/man/ayc/man1", + "/usr/share/man/ayc/man1p", + "/usr/share/man/ayc/man1x", + "/usr/share/man/ayc/man2", + "/usr/share/man/ayc/man2x", + "/usr/share/man/ayc/man3", + "/usr/share/man/ayc/man3p", + "/usr/share/man/ayc/man3x", + "/usr/share/man/ayc/man4", + "/usr/share/man/ayc/man4x", + "/usr/share/man/ayc/man5", + "/usr/share/man/ayc/man5x", + "/usr/share/man/ayc/man6", + "/usr/share/man/ayc/man6x", + "/usr/share/man/ayc/man7", + "/usr/share/man/ayc/man7x", + "/usr/share/man/ayc/man8", + "/usr/share/man/ayc/man8x", + "/usr/share/man/ayc/man9", + "/usr/share/man/ayc/man9x", + "/usr/share/man/ayc/mann", + "/usr/share/man/aym", + "/usr/share/man/aym/man0p", + "/usr/share/man/aym/man1", + "/usr/share/man/aym/man1p", + "/usr/share/man/aym/man1x", + "/usr/share/man/aym/man2", + "/usr/share/man/aym/man2x", + "/usr/share/man/aym/man3", + "/usr/share/man/aym/man3p", + "/usr/share/man/aym/man3x", + "/usr/share/man/aym/man4", + "/usr/share/man/aym/man4x", + "/usr/share/man/aym/man5", + "/usr/share/man/aym/man5x", + "/usr/share/man/aym/man6", + "/usr/share/man/aym/man6x", + "/usr/share/man/aym/man7", + "/usr/share/man/aym/man7x", + "/usr/share/man/aym/man8", + "/usr/share/man/aym/man8x", + "/usr/share/man/aym/man9", + "/usr/share/man/aym/man9x", + "/usr/share/man/aym/mann", + "/usr/share/man/az", + "/usr/share/man/az/man0p", + "/usr/share/man/az/man1", + "/usr/share/man/az/man1p", + "/usr/share/man/az/man1x", + "/usr/share/man/az/man2", + "/usr/share/man/az/man2x", + "/usr/share/man/az/man3", + "/usr/share/man/az/man3p", + "/usr/share/man/az/man3x", + "/usr/share/man/az/man4", + "/usr/share/man/az/man4x", + "/usr/share/man/az/man5", + "/usr/share/man/az/man5x", + "/usr/share/man/az/man6", + "/usr/share/man/az/man6x", + "/usr/share/man/az/man7", + "/usr/share/man/az/man7x", + "/usr/share/man/az/man8", + "/usr/share/man/az/man8x", + "/usr/share/man/az/man9", + "/usr/share/man/az/man9x", + "/usr/share/man/az/mann", + "/usr/share/man/az_AZ", + "/usr/share/man/az_AZ/man0p", + "/usr/share/man/az_AZ/man1", + "/usr/share/man/az_AZ/man1p", + "/usr/share/man/az_AZ/man1x", + "/usr/share/man/az_AZ/man2", + "/usr/share/man/az_AZ/man2x", + "/usr/share/man/az_AZ/man3", + "/usr/share/man/az_AZ/man3p", + "/usr/share/man/az_AZ/man3x", + "/usr/share/man/az_AZ/man4", + "/usr/share/man/az_AZ/man4x", + "/usr/share/man/az_AZ/man5", + "/usr/share/man/az_AZ/man5x", + "/usr/share/man/az_AZ/man6", + "/usr/share/man/az_AZ/man6x", + "/usr/share/man/az_AZ/man7", + "/usr/share/man/az_AZ/man7x", + "/usr/share/man/az_AZ/man8", + "/usr/share/man/az_AZ/man8x", + "/usr/share/man/az_AZ/man9", + "/usr/share/man/az_AZ/man9x", + "/usr/share/man/az_AZ/mann", + "/usr/share/man/az_IR", + "/usr/share/man/az_IR/man0p", + "/usr/share/man/az_IR/man1", + "/usr/share/man/az_IR/man1p", + "/usr/share/man/az_IR/man1x", + "/usr/share/man/az_IR/man2", + "/usr/share/man/az_IR/man2x", + "/usr/share/man/az_IR/man3", + "/usr/share/man/az_IR/man3p", + "/usr/share/man/az_IR/man3x", + "/usr/share/man/az_IR/man4", + "/usr/share/man/az_IR/man4x", + "/usr/share/man/az_IR/man5", + "/usr/share/man/az_IR/man5x", + "/usr/share/man/az_IR/man6", + "/usr/share/man/az_IR/man6x", + "/usr/share/man/az_IR/man7", + "/usr/share/man/az_IR/man7x", + "/usr/share/man/az_IR/man8", + "/usr/share/man/az_IR/man8x", + "/usr/share/man/az_IR/man9", + "/usr/share/man/az_IR/man9x", + "/usr/share/man/az_IR/mann", + "/usr/share/man/ba", + "/usr/share/man/ba/man0p", + "/usr/share/man/ba/man1", + "/usr/share/man/ba/man1p", + "/usr/share/man/ba/man1x", + "/usr/share/man/ba/man2", + "/usr/share/man/ba/man2x", + "/usr/share/man/ba/man3", + "/usr/share/man/ba/man3p", + "/usr/share/man/ba/man3x", + "/usr/share/man/ba/man4", + "/usr/share/man/ba/man4x", + "/usr/share/man/ba/man5", + "/usr/share/man/ba/man5x", + "/usr/share/man/ba/man6", + "/usr/share/man/ba/man6x", + "/usr/share/man/ba/man7", + "/usr/share/man/ba/man7x", + "/usr/share/man/ba/man8", + "/usr/share/man/ba/man8x", + "/usr/share/man/ba/man9", + "/usr/share/man/ba/man9x", + "/usr/share/man/ba/mann", + "/usr/share/man/bad", + "/usr/share/man/bad/man0p", + "/usr/share/man/bad/man1", + "/usr/share/man/bad/man1p", + "/usr/share/man/bad/man1x", + "/usr/share/man/bad/man2", + "/usr/share/man/bad/man2x", + "/usr/share/man/bad/man3", + "/usr/share/man/bad/man3p", + "/usr/share/man/bad/man3x", + "/usr/share/man/bad/man4", + "/usr/share/man/bad/man4x", + "/usr/share/man/bad/man5", + "/usr/share/man/bad/man5x", + "/usr/share/man/bad/man6", + "/usr/share/man/bad/man6x", + "/usr/share/man/bad/man7", + "/usr/share/man/bad/man7x", + "/usr/share/man/bad/man8", + "/usr/share/man/bad/man8x", + "/usr/share/man/bad/man9", + "/usr/share/man/bad/man9x", + "/usr/share/man/bad/mann", + "/usr/share/man/bai", + "/usr/share/man/bai/man0p", + "/usr/share/man/bai/man1", + "/usr/share/man/bai/man1p", + "/usr/share/man/bai/man1x", + "/usr/share/man/bai/man2", + "/usr/share/man/bai/man2x", + "/usr/share/man/bai/man3", + "/usr/share/man/bai/man3p", + "/usr/share/man/bai/man3x", + "/usr/share/man/bai/man4", + "/usr/share/man/bai/man4x", + "/usr/share/man/bai/man5", + "/usr/share/man/bai/man5x", + "/usr/share/man/bai/man6", + "/usr/share/man/bai/man6x", + "/usr/share/man/bai/man7", + "/usr/share/man/bai/man7x", + "/usr/share/man/bai/man8", + "/usr/share/man/bai/man8x", + "/usr/share/man/bai/man9", + "/usr/share/man/bai/man9x", + "/usr/share/man/bai/mann", + "/usr/share/man/bal", + "/usr/share/man/bal/man0p", + "/usr/share/man/bal/man1", + "/usr/share/man/bal/man1p", + "/usr/share/man/bal/man1x", + "/usr/share/man/bal/man2", + "/usr/share/man/bal/man2x", + "/usr/share/man/bal/man3", + "/usr/share/man/bal/man3p", + "/usr/share/man/bal/man3x", + "/usr/share/man/bal/man4", + "/usr/share/man/bal/man4x", + "/usr/share/man/bal/man5", + "/usr/share/man/bal/man5x", + "/usr/share/man/bal/man6", + "/usr/share/man/bal/man6x", + "/usr/share/man/bal/man7", + "/usr/share/man/bal/man7x", + "/usr/share/man/bal/man8", + "/usr/share/man/bal/man8x", + "/usr/share/man/bal/man9", + "/usr/share/man/bal/man9x", + "/usr/share/man/bal/mann", + "/usr/share/man/ban", + "/usr/share/man/ban/man0p", + "/usr/share/man/ban/man1", + "/usr/share/man/ban/man1p", + "/usr/share/man/ban/man1x", + "/usr/share/man/ban/man2", + "/usr/share/man/ban/man2x", + "/usr/share/man/ban/man3", + "/usr/share/man/ban/man3p", + "/usr/share/man/ban/man3x", + "/usr/share/man/ban/man4", + "/usr/share/man/ban/man4x", + "/usr/share/man/ban/man5", + "/usr/share/man/ban/man5x", + "/usr/share/man/ban/man6", + "/usr/share/man/ban/man6x", + "/usr/share/man/ban/man7", + "/usr/share/man/ban/man7x", + "/usr/share/man/ban/man8", + "/usr/share/man/ban/man8x", + "/usr/share/man/ban/man9", + "/usr/share/man/ban/man9x", + "/usr/share/man/ban/mann", + "/usr/share/man/bas", + "/usr/share/man/bas/man0p", + "/usr/share/man/bas/man1", + "/usr/share/man/bas/man1p", + "/usr/share/man/bas/man1x", + "/usr/share/man/bas/man2", + "/usr/share/man/bas/man2x", + "/usr/share/man/bas/man3", + "/usr/share/man/bas/man3p", + "/usr/share/man/bas/man3x", + "/usr/share/man/bas/man4", + "/usr/share/man/bas/man4x", + "/usr/share/man/bas/man5", + "/usr/share/man/bas/man5x", + "/usr/share/man/bas/man6", + "/usr/share/man/bas/man6x", + "/usr/share/man/bas/man7", + "/usr/share/man/bas/man7x", + "/usr/share/man/bas/man8", + "/usr/share/man/bas/man8x", + "/usr/share/man/bas/man9", + "/usr/share/man/bas/man9x", + "/usr/share/man/bas/mann", + "/usr/share/man/bat", + "/usr/share/man/bat/man0p", + "/usr/share/man/bat/man1", + "/usr/share/man/bat/man1p", + "/usr/share/man/bat/man1x", + "/usr/share/man/bat/man2", + "/usr/share/man/bat/man2x", + "/usr/share/man/bat/man3", + "/usr/share/man/bat/man3p", + "/usr/share/man/bat/man3x", + "/usr/share/man/bat/man4", + "/usr/share/man/bat/man4x", + "/usr/share/man/bat/man5", + "/usr/share/man/bat/man5x", + "/usr/share/man/bat/man6", + "/usr/share/man/bat/man6x", + "/usr/share/man/bat/man7", + "/usr/share/man/bat/man7x", + "/usr/share/man/bat/man8", + "/usr/share/man/bat/man8x", + "/usr/share/man/bat/man9", + "/usr/share/man/bat/man9x", + "/usr/share/man/bat/mann", + "/usr/share/man/be", + "/usr/share/man/be/man0p", + "/usr/share/man/be/man1", + "/usr/share/man/be/man1p", + "/usr/share/man/be/man1x", + "/usr/share/man/be/man2", + "/usr/share/man/be/man2x", + "/usr/share/man/be/man3", + "/usr/share/man/be/man3p", + "/usr/share/man/be/man3x", + "/usr/share/man/be/man4", + "/usr/share/man/be/man4x", + "/usr/share/man/be/man5", + "/usr/share/man/be/man5x", + "/usr/share/man/be/man6", + "/usr/share/man/be/man6x", + "/usr/share/man/be/man7", + "/usr/share/man/be/man7x", + "/usr/share/man/be/man8", + "/usr/share/man/be/man8x", + "/usr/share/man/be/man9", + "/usr/share/man/be/man9x", + "/usr/share/man/be/mann", + "/usr/share/man/be@latin", + "/usr/share/man/be@latin/man0p", + "/usr/share/man/be@latin/man1", + "/usr/share/man/be@latin/man1p", + "/usr/share/man/be@latin/man1x", + "/usr/share/man/be@latin/man2", + "/usr/share/man/be@latin/man2x", + "/usr/share/man/be@latin/man3", + "/usr/share/man/be@latin/man3p", + "/usr/share/man/be@latin/man3x", + "/usr/share/man/be@latin/man4", + "/usr/share/man/be@latin/man4x", + "/usr/share/man/be@latin/man5", + "/usr/share/man/be@latin/man5x", + "/usr/share/man/be@latin/man6", + "/usr/share/man/be@latin/man6x", + "/usr/share/man/be@latin/man7", + "/usr/share/man/be@latin/man7x", + "/usr/share/man/be@latin/man8", + "/usr/share/man/be@latin/man8x", + "/usr/share/man/be@latin/man9", + "/usr/share/man/be@latin/man9x", + "/usr/share/man/be@latin/mann", + "/usr/share/man/bej", + "/usr/share/man/bej/man0p", + "/usr/share/man/bej/man1", + "/usr/share/man/bej/man1p", + "/usr/share/man/bej/man1x", + "/usr/share/man/bej/man2", + "/usr/share/man/bej/man2x", + "/usr/share/man/bej/man3", + "/usr/share/man/bej/man3p", + "/usr/share/man/bej/man3x", + "/usr/share/man/bej/man4", + "/usr/share/man/bej/man4x", + "/usr/share/man/bej/man5", + "/usr/share/man/bej/man5x", + "/usr/share/man/bej/man6", + "/usr/share/man/bej/man6x", + "/usr/share/man/bej/man7", + "/usr/share/man/bej/man7x", + "/usr/share/man/bej/man8", + "/usr/share/man/bej/man8x", + "/usr/share/man/bej/man9", + "/usr/share/man/bej/man9x", + "/usr/share/man/bej/mann", + "/usr/share/man/bem", + "/usr/share/man/bem/man0p", + "/usr/share/man/bem/man1", + "/usr/share/man/bem/man1p", + "/usr/share/man/bem/man1x", + "/usr/share/man/bem/man2", + "/usr/share/man/bem/man2x", + "/usr/share/man/bem/man3", + "/usr/share/man/bem/man3p", + "/usr/share/man/bem/man3x", + "/usr/share/man/bem/man4", + "/usr/share/man/bem/man4x", + "/usr/share/man/bem/man5", + "/usr/share/man/bem/man5x", + "/usr/share/man/bem/man6", + "/usr/share/man/bem/man6x", + "/usr/share/man/bem/man7", + "/usr/share/man/bem/man7x", + "/usr/share/man/bem/man8", + "/usr/share/man/bem/man8x", + "/usr/share/man/bem/man9", + "/usr/share/man/bem/man9x", + "/usr/share/man/bem/mann", + "/usr/share/man/ber", + "/usr/share/man/ber/man0p", + "/usr/share/man/ber/man1", + "/usr/share/man/ber/man1p", + "/usr/share/man/ber/man1x", + "/usr/share/man/ber/man2", + "/usr/share/man/ber/man2x", + "/usr/share/man/ber/man3", + "/usr/share/man/ber/man3p", + "/usr/share/man/ber/man3x", + "/usr/share/man/ber/man4", + "/usr/share/man/ber/man4x", + "/usr/share/man/ber/man5", + "/usr/share/man/ber/man5x", + "/usr/share/man/ber/man6", + "/usr/share/man/ber/man6x", + "/usr/share/man/ber/man7", + "/usr/share/man/ber/man7x", + "/usr/share/man/ber/man8", + "/usr/share/man/ber/man8x", + "/usr/share/man/ber/man9", + "/usr/share/man/ber/man9x", + "/usr/share/man/ber/mann", + "/usr/share/man/bg", + "/usr/share/man/bg/man0p", + "/usr/share/man/bg/man1", + "/usr/share/man/bg/man1p", + "/usr/share/man/bg/man1x", + "/usr/share/man/bg/man2", + "/usr/share/man/bg/man2x", + "/usr/share/man/bg/man3", + "/usr/share/man/bg/man3p", + "/usr/share/man/bg/man3x", + "/usr/share/man/bg/man4", + "/usr/share/man/bg/man4x", + "/usr/share/man/bg/man5", + "/usr/share/man/bg/man5x", + "/usr/share/man/bg/man6", + "/usr/share/man/bg/man6x", + "/usr/share/man/bg/man7", + "/usr/share/man/bg/man7x", + "/usr/share/man/bg/man8", + "/usr/share/man/bg/man8x", + "/usr/share/man/bg/man9", + "/usr/share/man/bg/man9x", + "/usr/share/man/bg/mann", + "/usr/share/man/bg_BG", + "/usr/share/man/bg_BG/man0p", + "/usr/share/man/bg_BG/man1", + "/usr/share/man/bg_BG/man1p", + "/usr/share/man/bg_BG/man1x", + "/usr/share/man/bg_BG/man2", + "/usr/share/man/bg_BG/man2x", + "/usr/share/man/bg_BG/man3", + "/usr/share/man/bg_BG/man3p", + "/usr/share/man/bg_BG/man3x", + "/usr/share/man/bg_BG/man4", + "/usr/share/man/bg_BG/man4x", + "/usr/share/man/bg_BG/man5", + "/usr/share/man/bg_BG/man5x", + "/usr/share/man/bg_BG/man6", + "/usr/share/man/bg_BG/man6x", + "/usr/share/man/bg_BG/man7", + "/usr/share/man/bg_BG/man7x", + "/usr/share/man/bg_BG/man8", + "/usr/share/man/bg_BG/man8x", + "/usr/share/man/bg_BG/man9", + "/usr/share/man/bg_BG/man9x", + "/usr/share/man/bg_BG/mann", + "/usr/share/man/bh", + "/usr/share/man/bh/man0p", + "/usr/share/man/bh/man1", + "/usr/share/man/bh/man1p", + "/usr/share/man/bh/man1x", + "/usr/share/man/bh/man2", + "/usr/share/man/bh/man2x", + "/usr/share/man/bh/man3", + "/usr/share/man/bh/man3p", + "/usr/share/man/bh/man3x", + "/usr/share/man/bh/man4", + "/usr/share/man/bh/man4x", + "/usr/share/man/bh/man5", + "/usr/share/man/bh/man5x", + "/usr/share/man/bh/man6", + "/usr/share/man/bh/man6x", + "/usr/share/man/bh/man7", + "/usr/share/man/bh/man7x", + "/usr/share/man/bh/man8", + "/usr/share/man/bh/man8x", + "/usr/share/man/bh/man9", + "/usr/share/man/bh/man9x", + "/usr/share/man/bh/mann", + "/usr/share/man/bho", + "/usr/share/man/bho/man0p", + "/usr/share/man/bho/man1", + "/usr/share/man/bho/man1p", + "/usr/share/man/bho/man1x", + "/usr/share/man/bho/man2", + "/usr/share/man/bho/man2x", + "/usr/share/man/bho/man3", + "/usr/share/man/bho/man3p", + "/usr/share/man/bho/man3x", + "/usr/share/man/bho/man4", + "/usr/share/man/bho/man4x", + "/usr/share/man/bho/man5", + "/usr/share/man/bho/man5x", + "/usr/share/man/bho/man6", + "/usr/share/man/bho/man6x", + "/usr/share/man/bho/man7", + "/usr/share/man/bho/man7x", + "/usr/share/man/bho/man8", + "/usr/share/man/bho/man8x", + "/usr/share/man/bho/man9", + "/usr/share/man/bho/man9x", + "/usr/share/man/bho/mann", + "/usr/share/man/bi", + "/usr/share/man/bi/man0p", + "/usr/share/man/bi/man1", + "/usr/share/man/bi/man1p", + "/usr/share/man/bi/man1x", + "/usr/share/man/bi/man2", + "/usr/share/man/bi/man2x", + "/usr/share/man/bi/man3", + "/usr/share/man/bi/man3p", + "/usr/share/man/bi/man3x", + "/usr/share/man/bi/man4", + "/usr/share/man/bi/man4x", + "/usr/share/man/bi/man5", + "/usr/share/man/bi/man5x", + "/usr/share/man/bi/man6", + "/usr/share/man/bi/man6x", + "/usr/share/man/bi/man7", + "/usr/share/man/bi/man7x", + "/usr/share/man/bi/man8", + "/usr/share/man/bi/man8x", + "/usr/share/man/bi/man9", + "/usr/share/man/bi/man9x", + "/usr/share/man/bi/mann", + "/usr/share/man/bik", + "/usr/share/man/bik/man0p", + "/usr/share/man/bik/man1", + "/usr/share/man/bik/man1p", + "/usr/share/man/bik/man1x", + "/usr/share/man/bik/man2", + "/usr/share/man/bik/man2x", + "/usr/share/man/bik/man3", + "/usr/share/man/bik/man3p", + "/usr/share/man/bik/man3x", + "/usr/share/man/bik/man4", + "/usr/share/man/bik/man4x", + "/usr/share/man/bik/man5", + "/usr/share/man/bik/man5x", + "/usr/share/man/bik/man6", + "/usr/share/man/bik/man6x", + "/usr/share/man/bik/man7", + "/usr/share/man/bik/man7x", + "/usr/share/man/bik/man8", + "/usr/share/man/bik/man8x", + "/usr/share/man/bik/man9", + "/usr/share/man/bik/man9x", + "/usr/share/man/bik/mann", + "/usr/share/man/bin", + "/usr/share/man/bin/man0p", + "/usr/share/man/bin/man1", + "/usr/share/man/bin/man1p", + "/usr/share/man/bin/man1x", + "/usr/share/man/bin/man2", + "/usr/share/man/bin/man2x", + "/usr/share/man/bin/man3", + "/usr/share/man/bin/man3p", + "/usr/share/man/bin/man3x", + "/usr/share/man/bin/man4", + "/usr/share/man/bin/man4x", + "/usr/share/man/bin/man5", + "/usr/share/man/bin/man5x", + "/usr/share/man/bin/man6", + "/usr/share/man/bin/man6x", + "/usr/share/man/bin/man7", + "/usr/share/man/bin/man7x", + "/usr/share/man/bin/man8", + "/usr/share/man/bin/man8x", + "/usr/share/man/bin/man9", + "/usr/share/man/bin/man9x", + "/usr/share/man/bin/mann", + "/usr/share/man/bla", + "/usr/share/man/bla/man0p", + "/usr/share/man/bla/man1", + "/usr/share/man/bla/man1p", + "/usr/share/man/bla/man1x", + "/usr/share/man/bla/man2", + "/usr/share/man/bla/man2x", + "/usr/share/man/bla/man3", + "/usr/share/man/bla/man3p", + "/usr/share/man/bla/man3x", + "/usr/share/man/bla/man4", + "/usr/share/man/bla/man4x", + "/usr/share/man/bla/man5", + "/usr/share/man/bla/man5x", + "/usr/share/man/bla/man6", + "/usr/share/man/bla/man6x", + "/usr/share/man/bla/man7", + "/usr/share/man/bla/man7x", + "/usr/share/man/bla/man8", + "/usr/share/man/bla/man8x", + "/usr/share/man/bla/man9", + "/usr/share/man/bla/man9x", + "/usr/share/man/bla/mann", + "/usr/share/man/bm", + "/usr/share/man/bm/man0p", + "/usr/share/man/bm/man1", + "/usr/share/man/bm/man1p", + "/usr/share/man/bm/man1x", + "/usr/share/man/bm/man2", + "/usr/share/man/bm/man2x", + "/usr/share/man/bm/man3", + "/usr/share/man/bm/man3p", + "/usr/share/man/bm/man3x", + "/usr/share/man/bm/man4", + "/usr/share/man/bm/man4x", + "/usr/share/man/bm/man5", + "/usr/share/man/bm/man5x", + "/usr/share/man/bm/man6", + "/usr/share/man/bm/man6x", + "/usr/share/man/bm/man7", + "/usr/share/man/bm/man7x", + "/usr/share/man/bm/man8", + "/usr/share/man/bm/man8x", + "/usr/share/man/bm/man9", + "/usr/share/man/bm/man9x", + "/usr/share/man/bm/mann", + "/usr/share/man/bn", + "/usr/share/man/bn/man0p", + "/usr/share/man/bn/man1", + "/usr/share/man/bn/man1p", + "/usr/share/man/bn/man1x", + "/usr/share/man/bn/man2", + "/usr/share/man/bn/man2x", + "/usr/share/man/bn/man3", + "/usr/share/man/bn/man3p", + "/usr/share/man/bn/man3x", + "/usr/share/man/bn/man4", + "/usr/share/man/bn/man4x", + "/usr/share/man/bn/man5", + "/usr/share/man/bn/man5x", + "/usr/share/man/bn/man6", + "/usr/share/man/bn/man6x", + "/usr/share/man/bn/man7", + "/usr/share/man/bn/man7x", + "/usr/share/man/bn/man8", + "/usr/share/man/bn/man8x", + "/usr/share/man/bn/man9", + "/usr/share/man/bn/man9x", + "/usr/share/man/bn/mann", + "/usr/share/man/bn_BD", + "/usr/share/man/bn_BD/man0p", + "/usr/share/man/bn_BD/man1", + "/usr/share/man/bn_BD/man1p", + "/usr/share/man/bn_BD/man1x", + "/usr/share/man/bn_BD/man2", + "/usr/share/man/bn_BD/man2x", + "/usr/share/man/bn_BD/man3", + "/usr/share/man/bn_BD/man3p", + "/usr/share/man/bn_BD/man3x", + "/usr/share/man/bn_BD/man4", + "/usr/share/man/bn_BD/man4x", + "/usr/share/man/bn_BD/man5", + "/usr/share/man/bn_BD/man5x", + "/usr/share/man/bn_BD/man6", + "/usr/share/man/bn_BD/man6x", + "/usr/share/man/bn_BD/man7", + "/usr/share/man/bn_BD/man7x", + "/usr/share/man/bn_BD/man8", + "/usr/share/man/bn_BD/man8x", + "/usr/share/man/bn_BD/man9", + "/usr/share/man/bn_BD/man9x", + "/usr/share/man/bn_BD/mann", + "/usr/share/man/bn_IN", + "/usr/share/man/bn_IN/man0p", + "/usr/share/man/bn_IN/man1", + "/usr/share/man/bn_IN/man1p", + "/usr/share/man/bn_IN/man1x", + "/usr/share/man/bn_IN/man2", + "/usr/share/man/bn_IN/man2x", + "/usr/share/man/bn_IN/man3", + "/usr/share/man/bn_IN/man3p", + "/usr/share/man/bn_IN/man3x", + "/usr/share/man/bn_IN/man4", + "/usr/share/man/bn_IN/man4x", + "/usr/share/man/bn_IN/man5", + "/usr/share/man/bn_IN/man5x", + "/usr/share/man/bn_IN/man6", + "/usr/share/man/bn_IN/man6x", + "/usr/share/man/bn_IN/man7", + "/usr/share/man/bn_IN/man7x", + "/usr/share/man/bn_IN/man8", + "/usr/share/man/bn_IN/man8x", + "/usr/share/man/bn_IN/man9", + "/usr/share/man/bn_IN/man9x", + "/usr/share/man/bn_IN/mann", + "/usr/share/man/bnt", + "/usr/share/man/bnt/man0p", + "/usr/share/man/bnt/man1", + "/usr/share/man/bnt/man1p", + "/usr/share/man/bnt/man1x", + "/usr/share/man/bnt/man2", + "/usr/share/man/bnt/man2x", + "/usr/share/man/bnt/man3", + "/usr/share/man/bnt/man3p", + "/usr/share/man/bnt/man3x", + "/usr/share/man/bnt/man4", + "/usr/share/man/bnt/man4x", + "/usr/share/man/bnt/man5", + "/usr/share/man/bnt/man5x", + "/usr/share/man/bnt/man6", + "/usr/share/man/bnt/man6x", + "/usr/share/man/bnt/man7", + "/usr/share/man/bnt/man7x", + "/usr/share/man/bnt/man8", + "/usr/share/man/bnt/man8x", + "/usr/share/man/bnt/man9", + "/usr/share/man/bnt/man9x", + "/usr/share/man/bnt/mann", + "/usr/share/man/bo", + "/usr/share/man/bo/man0p", + "/usr/share/man/bo/man1", + "/usr/share/man/bo/man1p", + "/usr/share/man/bo/man1x", + "/usr/share/man/bo/man2", + "/usr/share/man/bo/man2x", + "/usr/share/man/bo/man3", + "/usr/share/man/bo/man3p", + "/usr/share/man/bo/man3x", + "/usr/share/man/bo/man4", + "/usr/share/man/bo/man4x", + "/usr/share/man/bo/man5", + "/usr/share/man/bo/man5x", + "/usr/share/man/bo/man6", + "/usr/share/man/bo/man6x", + "/usr/share/man/bo/man7", + "/usr/share/man/bo/man7x", + "/usr/share/man/bo/man8", + "/usr/share/man/bo/man8x", + "/usr/share/man/bo/man9", + "/usr/share/man/bo/man9x", + "/usr/share/man/bo/mann", + "/usr/share/man/br", + "/usr/share/man/br/man0p", + "/usr/share/man/br/man1", + "/usr/share/man/br/man1p", + "/usr/share/man/br/man1x", + "/usr/share/man/br/man2", + "/usr/share/man/br/man2x", + "/usr/share/man/br/man3", + "/usr/share/man/br/man3p", + "/usr/share/man/br/man3x", + "/usr/share/man/br/man4", + "/usr/share/man/br/man4x", + "/usr/share/man/br/man5", + "/usr/share/man/br/man5x", + "/usr/share/man/br/man6", + "/usr/share/man/br/man6x", + "/usr/share/man/br/man7", + "/usr/share/man/br/man7x", + "/usr/share/man/br/man8", + "/usr/share/man/br/man8x", + "/usr/share/man/br/man9", + "/usr/share/man/br/man9x", + "/usr/share/man/br/mann", + "/usr/share/man/bra", + "/usr/share/man/bra/man0p", + "/usr/share/man/bra/man1", + "/usr/share/man/bra/man1p", + "/usr/share/man/bra/man1x", + "/usr/share/man/bra/man2", + "/usr/share/man/bra/man2x", + "/usr/share/man/bra/man3", + "/usr/share/man/bra/man3p", + "/usr/share/man/bra/man3x", + "/usr/share/man/bra/man4", + "/usr/share/man/bra/man4x", + "/usr/share/man/bra/man5", + "/usr/share/man/bra/man5x", + "/usr/share/man/bra/man6", + "/usr/share/man/bra/man6x", + "/usr/share/man/bra/man7", + "/usr/share/man/bra/man7x", + "/usr/share/man/bra/man8", + "/usr/share/man/bra/man8x", + "/usr/share/man/bra/man9", + "/usr/share/man/bra/man9x", + "/usr/share/man/bra/mann", + "/usr/share/man/brx", + "/usr/share/man/brx/man0p", + "/usr/share/man/brx/man1", + "/usr/share/man/brx/man1p", + "/usr/share/man/brx/man1x", + "/usr/share/man/brx/man2", + "/usr/share/man/brx/man2x", + "/usr/share/man/brx/man3", + "/usr/share/man/brx/man3p", + "/usr/share/man/brx/man3x", + "/usr/share/man/brx/man4", + "/usr/share/man/brx/man4x", + "/usr/share/man/brx/man5", + "/usr/share/man/brx/man5x", + "/usr/share/man/brx/man6", + "/usr/share/man/brx/man6x", + "/usr/share/man/brx/man7", + "/usr/share/man/brx/man7x", + "/usr/share/man/brx/man8", + "/usr/share/man/brx/man8x", + "/usr/share/man/brx/man9", + "/usr/share/man/brx/man9x", + "/usr/share/man/brx/mann", + "/usr/share/man/bs", + "/usr/share/man/bs/man0p", + "/usr/share/man/bs/man1", + "/usr/share/man/bs/man1p", + "/usr/share/man/bs/man1x", + "/usr/share/man/bs/man2", + "/usr/share/man/bs/man2x", + "/usr/share/man/bs/man3", + "/usr/share/man/bs/man3p", + "/usr/share/man/bs/man3x", + "/usr/share/man/bs/man4", + "/usr/share/man/bs/man4x", + "/usr/share/man/bs/man5", + "/usr/share/man/bs/man5x", + "/usr/share/man/bs/man6", + "/usr/share/man/bs/man6x", + "/usr/share/man/bs/man7", + "/usr/share/man/bs/man7x", + "/usr/share/man/bs/man8", + "/usr/share/man/bs/man8x", + "/usr/share/man/bs/man9", + "/usr/share/man/bs/man9x", + "/usr/share/man/bs/mann", + "/usr/share/man/bs_BA", + "/usr/share/man/bs_BA/man0p", + "/usr/share/man/bs_BA/man1", + "/usr/share/man/bs_BA/man1p", + "/usr/share/man/bs_BA/man1x", + "/usr/share/man/bs_BA/man2", + "/usr/share/man/bs_BA/man2x", + "/usr/share/man/bs_BA/man3", + "/usr/share/man/bs_BA/man3p", + "/usr/share/man/bs_BA/man3x", + "/usr/share/man/bs_BA/man4", + "/usr/share/man/bs_BA/man4x", + "/usr/share/man/bs_BA/man5", + "/usr/share/man/bs_BA/man5x", + "/usr/share/man/bs_BA/man6", + "/usr/share/man/bs_BA/man6x", + "/usr/share/man/bs_BA/man7", + "/usr/share/man/bs_BA/man7x", + "/usr/share/man/bs_BA/man8", + "/usr/share/man/bs_BA/man8x", + "/usr/share/man/bs_BA/man9", + "/usr/share/man/bs_BA/man9x", + "/usr/share/man/bs_BA/mann", + "/usr/share/man/btk", + "/usr/share/man/btk/man0p", + "/usr/share/man/btk/man1", + "/usr/share/man/btk/man1p", + "/usr/share/man/btk/man1x", + "/usr/share/man/btk/man2", + "/usr/share/man/btk/man2x", + "/usr/share/man/btk/man3", + "/usr/share/man/btk/man3p", + "/usr/share/man/btk/man3x", + "/usr/share/man/btk/man4", + "/usr/share/man/btk/man4x", + "/usr/share/man/btk/man5", + "/usr/share/man/btk/man5x", + "/usr/share/man/btk/man6", + "/usr/share/man/btk/man6x", + "/usr/share/man/btk/man7", + "/usr/share/man/btk/man7x", + "/usr/share/man/btk/man8", + "/usr/share/man/btk/man8x", + "/usr/share/man/btk/man9", + "/usr/share/man/btk/man9x", + "/usr/share/man/btk/mann", + "/usr/share/man/bua", + "/usr/share/man/bua/man0p", + "/usr/share/man/bua/man1", + "/usr/share/man/bua/man1p", + "/usr/share/man/bua/man1x", + "/usr/share/man/bua/man2", + "/usr/share/man/bua/man2x", + "/usr/share/man/bua/man3", + "/usr/share/man/bua/man3p", + "/usr/share/man/bua/man3x", + "/usr/share/man/bua/man4", + "/usr/share/man/bua/man4x", + "/usr/share/man/bua/man5", + "/usr/share/man/bua/man5x", + "/usr/share/man/bua/man6", + "/usr/share/man/bua/man6x", + "/usr/share/man/bua/man7", + "/usr/share/man/bua/man7x", + "/usr/share/man/bua/man8", + "/usr/share/man/bua/man8x", + "/usr/share/man/bua/man9", + "/usr/share/man/bua/man9x", + "/usr/share/man/bua/mann", + "/usr/share/man/bug", + "/usr/share/man/bug/man0p", + "/usr/share/man/bug/man1", + "/usr/share/man/bug/man1p", + "/usr/share/man/bug/man1x", + "/usr/share/man/bug/man2", + "/usr/share/man/bug/man2x", + "/usr/share/man/bug/man3", + "/usr/share/man/bug/man3p", + "/usr/share/man/bug/man3x", + "/usr/share/man/bug/man4", + "/usr/share/man/bug/man4x", + "/usr/share/man/bug/man5", + "/usr/share/man/bug/man5x", + "/usr/share/man/bug/man6", + "/usr/share/man/bug/man6x", + "/usr/share/man/bug/man7", + "/usr/share/man/bug/man7x", + "/usr/share/man/bug/man8", + "/usr/share/man/bug/man8x", + "/usr/share/man/bug/man9", + "/usr/share/man/bug/man9x", + "/usr/share/man/bug/mann", + "/usr/share/man/byn", + "/usr/share/man/byn/man0p", + "/usr/share/man/byn/man1", + "/usr/share/man/byn/man1p", + "/usr/share/man/byn/man1x", + "/usr/share/man/byn/man2", + "/usr/share/man/byn/man2x", + "/usr/share/man/byn/man3", + "/usr/share/man/byn/man3p", + "/usr/share/man/byn/man3x", + "/usr/share/man/byn/man4", + "/usr/share/man/byn/man4x", + "/usr/share/man/byn/man5", + "/usr/share/man/byn/man5x", + "/usr/share/man/byn/man6", + "/usr/share/man/byn/man6x", + "/usr/share/man/byn/man7", + "/usr/share/man/byn/man7x", + "/usr/share/man/byn/man8", + "/usr/share/man/byn/man8x", + "/usr/share/man/byn/man9", + "/usr/share/man/byn/man9x", + "/usr/share/man/byn/mann", + "/usr/share/man/ca", + "/usr/share/man/ca.us-ascii", + "/usr/share/man/ca.us-ascii/man0p", + "/usr/share/man/ca.us-ascii/man1", + "/usr/share/man/ca.us-ascii/man1p", + "/usr/share/man/ca.us-ascii/man1x", + "/usr/share/man/ca.us-ascii/man2", + "/usr/share/man/ca.us-ascii/man2x", + "/usr/share/man/ca.us-ascii/man3", + "/usr/share/man/ca.us-ascii/man3p", + "/usr/share/man/ca.us-ascii/man3x", + "/usr/share/man/ca.us-ascii/man4", + "/usr/share/man/ca.us-ascii/man4x", + "/usr/share/man/ca.us-ascii/man5", + "/usr/share/man/ca.us-ascii/man5x", + "/usr/share/man/ca.us-ascii/man6", + "/usr/share/man/ca.us-ascii/man6x", + "/usr/share/man/ca.us-ascii/man7", + "/usr/share/man/ca.us-ascii/man7x", + "/usr/share/man/ca.us-ascii/man8", + "/usr/share/man/ca.us-ascii/man8x", + "/usr/share/man/ca.us-ascii/man9", + "/usr/share/man/ca.us-ascii/man9x", + "/usr/share/man/ca.us-ascii/mann", + "/usr/share/man/ca/man0p", + "/usr/share/man/ca/man1", + "/usr/share/man/ca/man1p", + "/usr/share/man/ca/man1x", + "/usr/share/man/ca/man2", + "/usr/share/man/ca/man2x", + "/usr/share/man/ca/man3", + "/usr/share/man/ca/man3p", + "/usr/share/man/ca/man3x", + "/usr/share/man/ca/man4", + "/usr/share/man/ca/man4x", + "/usr/share/man/ca/man5", + "/usr/share/man/ca/man5x", + "/usr/share/man/ca/man6", + "/usr/share/man/ca/man6x", + "/usr/share/man/ca/man7", + "/usr/share/man/ca/man7x", + "/usr/share/man/ca/man8", + "/usr/share/man/ca/man8x", + "/usr/share/man/ca/man9", + "/usr/share/man/ca/man9x", + "/usr/share/man/ca/mann", + "/usr/share/man/ca@valencia", + "/usr/share/man/ca@valencia/man0p", + "/usr/share/man/ca@valencia/man1", + "/usr/share/man/ca@valencia/man1p", + "/usr/share/man/ca@valencia/man1x", + "/usr/share/man/ca@valencia/man2", + "/usr/share/man/ca@valencia/man2x", + "/usr/share/man/ca@valencia/man3", + "/usr/share/man/ca@valencia/man3p", + "/usr/share/man/ca@valencia/man3x", + "/usr/share/man/ca@valencia/man4", + "/usr/share/man/ca@valencia/man4x", + "/usr/share/man/ca@valencia/man5", + "/usr/share/man/ca@valencia/man5x", + "/usr/share/man/ca@valencia/man6", + "/usr/share/man/ca@valencia/man6x", + "/usr/share/man/ca@valencia/man7", + "/usr/share/man/ca@valencia/man7x", + "/usr/share/man/ca@valencia/man8", + "/usr/share/man/ca@valencia/man8x", + "/usr/share/man/ca@valencia/man9", + "/usr/share/man/ca@valencia/man9x", + "/usr/share/man/ca@valencia/mann", + "/usr/share/man/ca_AD", + "/usr/share/man/ca_AD/man0p", + "/usr/share/man/ca_AD/man1", + "/usr/share/man/ca_AD/man1p", + "/usr/share/man/ca_AD/man1x", + "/usr/share/man/ca_AD/man2", + "/usr/share/man/ca_AD/man2x", + "/usr/share/man/ca_AD/man3", + "/usr/share/man/ca_AD/man3p", + "/usr/share/man/ca_AD/man3x", + "/usr/share/man/ca_AD/man4", + "/usr/share/man/ca_AD/man4x", + "/usr/share/man/ca_AD/man5", + "/usr/share/man/ca_AD/man5x", + "/usr/share/man/ca_AD/man6", + "/usr/share/man/ca_AD/man6x", + "/usr/share/man/ca_AD/man7", + "/usr/share/man/ca_AD/man7x", + "/usr/share/man/ca_AD/man8", + "/usr/share/man/ca_AD/man8x", + "/usr/share/man/ca_AD/man9", + "/usr/share/man/ca_AD/man9x", + "/usr/share/man/ca_AD/mann", + "/usr/share/man/ca_ES", + "/usr/share/man/ca_ES/man0p", + "/usr/share/man/ca_ES/man1", + "/usr/share/man/ca_ES/man1p", + "/usr/share/man/ca_ES/man1x", + "/usr/share/man/ca_ES/man2", + "/usr/share/man/ca_ES/man2x", + "/usr/share/man/ca_ES/man3", + "/usr/share/man/ca_ES/man3p", + "/usr/share/man/ca_ES/man3x", + "/usr/share/man/ca_ES/man4", + "/usr/share/man/ca_ES/man4x", + "/usr/share/man/ca_ES/man5", + "/usr/share/man/ca_ES/man5x", + "/usr/share/man/ca_ES/man6", + "/usr/share/man/ca_ES/man6x", + "/usr/share/man/ca_ES/man7", + "/usr/share/man/ca_ES/man7x", + "/usr/share/man/ca_ES/man8", + "/usr/share/man/ca_ES/man8x", + "/usr/share/man/ca_ES/man9", + "/usr/share/man/ca_ES/man9x", + "/usr/share/man/ca_ES/mann", + "/usr/share/man/ca_FR", + "/usr/share/man/ca_FR/man0p", + "/usr/share/man/ca_FR/man1", + "/usr/share/man/ca_FR/man1p", + "/usr/share/man/ca_FR/man1x", + "/usr/share/man/ca_FR/man2", + "/usr/share/man/ca_FR/man2x", + "/usr/share/man/ca_FR/man3", + "/usr/share/man/ca_FR/man3p", + "/usr/share/man/ca_FR/man3x", + "/usr/share/man/ca_FR/man4", + "/usr/share/man/ca_FR/man4x", + "/usr/share/man/ca_FR/man5", + "/usr/share/man/ca_FR/man5x", + "/usr/share/man/ca_FR/man6", + "/usr/share/man/ca_FR/man6x", + "/usr/share/man/ca_FR/man7", + "/usr/share/man/ca_FR/man7x", + "/usr/share/man/ca_FR/man8", + "/usr/share/man/ca_FR/man8x", + "/usr/share/man/ca_FR/man9", + "/usr/share/man/ca_FR/man9x", + "/usr/share/man/ca_FR/mann", + "/usr/share/man/ca_IT", + "/usr/share/man/ca_IT/man0p", + "/usr/share/man/ca_IT/man1", + "/usr/share/man/ca_IT/man1p", + "/usr/share/man/ca_IT/man1x", + "/usr/share/man/ca_IT/man2", + "/usr/share/man/ca_IT/man2x", + "/usr/share/man/ca_IT/man3", + "/usr/share/man/ca_IT/man3p", + "/usr/share/man/ca_IT/man3x", + "/usr/share/man/ca_IT/man4", + "/usr/share/man/ca_IT/man4x", + "/usr/share/man/ca_IT/man5", + "/usr/share/man/ca_IT/man5x", + "/usr/share/man/ca_IT/man6", + "/usr/share/man/ca_IT/man6x", + "/usr/share/man/ca_IT/man7", + "/usr/share/man/ca_IT/man7x", + "/usr/share/man/ca_IT/man8", + "/usr/share/man/ca_IT/man8x", + "/usr/share/man/ca_IT/man9", + "/usr/share/man/ca_IT/man9x", + "/usr/share/man/ca_IT/mann", + "/usr/share/man/cad", + "/usr/share/man/cad/man0p", + "/usr/share/man/cad/man1", + "/usr/share/man/cad/man1p", + "/usr/share/man/cad/man1x", + "/usr/share/man/cad/man2", + "/usr/share/man/cad/man2x", + "/usr/share/man/cad/man3", + "/usr/share/man/cad/man3p", + "/usr/share/man/cad/man3x", + "/usr/share/man/cad/man4", + "/usr/share/man/cad/man4x", + "/usr/share/man/cad/man5", + "/usr/share/man/cad/man5x", + "/usr/share/man/cad/man6", + "/usr/share/man/cad/man6x", + "/usr/share/man/cad/man7", + "/usr/share/man/cad/man7x", + "/usr/share/man/cad/man8", + "/usr/share/man/cad/man8x", + "/usr/share/man/cad/man9", + "/usr/share/man/cad/man9x", + "/usr/share/man/cad/mann", + "/usr/share/man/cai", + "/usr/share/man/cai/man0p", + "/usr/share/man/cai/man1", + "/usr/share/man/cai/man1p", + "/usr/share/man/cai/man1x", + "/usr/share/man/cai/man2", + "/usr/share/man/cai/man2x", + "/usr/share/man/cai/man3", + "/usr/share/man/cai/man3p", + "/usr/share/man/cai/man3x", + "/usr/share/man/cai/man4", + "/usr/share/man/cai/man4x", + "/usr/share/man/cai/man5", + "/usr/share/man/cai/man5x", + "/usr/share/man/cai/man6", + "/usr/share/man/cai/man6x", + "/usr/share/man/cai/man7", + "/usr/share/man/cai/man7x", + "/usr/share/man/cai/man8", + "/usr/share/man/cai/man8x", + "/usr/share/man/cai/man9", + "/usr/share/man/cai/man9x", + "/usr/share/man/cai/mann", + "/usr/share/man/car", + "/usr/share/man/car/man0p", + "/usr/share/man/car/man1", + "/usr/share/man/car/man1p", + "/usr/share/man/car/man1x", + "/usr/share/man/car/man2", + "/usr/share/man/car/man2x", + "/usr/share/man/car/man3", + "/usr/share/man/car/man3p", + "/usr/share/man/car/man3x", + "/usr/share/man/car/man4", + "/usr/share/man/car/man4x", + "/usr/share/man/car/man5", + "/usr/share/man/car/man5x", + "/usr/share/man/car/man6", + "/usr/share/man/car/man6x", + "/usr/share/man/car/man7", + "/usr/share/man/car/man7x", + "/usr/share/man/car/man8", + "/usr/share/man/car/man8x", + "/usr/share/man/car/man9", + "/usr/share/man/car/man9x", + "/usr/share/man/car/mann", + "/usr/share/man/cau", + "/usr/share/man/cau/man0p", + "/usr/share/man/cau/man1", + "/usr/share/man/cau/man1p", + "/usr/share/man/cau/man1x", + "/usr/share/man/cau/man2", + "/usr/share/man/cau/man2x", + "/usr/share/man/cau/man3", + "/usr/share/man/cau/man3p", + "/usr/share/man/cau/man3x", + "/usr/share/man/cau/man4", + "/usr/share/man/cau/man4x", + "/usr/share/man/cau/man5", + "/usr/share/man/cau/man5x", + "/usr/share/man/cau/man6", + "/usr/share/man/cau/man6x", + "/usr/share/man/cau/man7", + "/usr/share/man/cau/man7x", + "/usr/share/man/cau/man8", + "/usr/share/man/cau/man8x", + "/usr/share/man/cau/man9", + "/usr/share/man/cau/man9x", + "/usr/share/man/cau/mann", + "/usr/share/man/ce", + "/usr/share/man/ce/man0p", + "/usr/share/man/ce/man1", + "/usr/share/man/ce/man1p", + "/usr/share/man/ce/man1x", + "/usr/share/man/ce/man2", + "/usr/share/man/ce/man2x", + "/usr/share/man/ce/man3", + "/usr/share/man/ce/man3p", + "/usr/share/man/ce/man3x", + "/usr/share/man/ce/man4", + "/usr/share/man/ce/man4x", + "/usr/share/man/ce/man5", + "/usr/share/man/ce/man5x", + "/usr/share/man/ce/man6", + "/usr/share/man/ce/man6x", + "/usr/share/man/ce/man7", + "/usr/share/man/ce/man7x", + "/usr/share/man/ce/man8", + "/usr/share/man/ce/man8x", + "/usr/share/man/ce/man9", + "/usr/share/man/ce/man9x", + "/usr/share/man/ce/mann", + "/usr/share/man/ceb", + "/usr/share/man/ceb/man0p", + "/usr/share/man/ceb/man1", + "/usr/share/man/ceb/man1p", + "/usr/share/man/ceb/man1x", + "/usr/share/man/ceb/man2", + "/usr/share/man/ceb/man2x", + "/usr/share/man/ceb/man3", + "/usr/share/man/ceb/man3p", + "/usr/share/man/ceb/man3x", + "/usr/share/man/ceb/man4", + "/usr/share/man/ceb/man4x", + "/usr/share/man/ceb/man5", + "/usr/share/man/ceb/man5x", + "/usr/share/man/ceb/man6", + "/usr/share/man/ceb/man6x", + "/usr/share/man/ceb/man7", + "/usr/share/man/ceb/man7x", + "/usr/share/man/ceb/man8", + "/usr/share/man/ceb/man8x", + "/usr/share/man/ceb/man9", + "/usr/share/man/ceb/man9x", + "/usr/share/man/ceb/mann", + "/usr/share/man/cel", + "/usr/share/man/cel/man0p", + "/usr/share/man/cel/man1", + "/usr/share/man/cel/man1p", + "/usr/share/man/cel/man1x", + "/usr/share/man/cel/man2", + "/usr/share/man/cel/man2x", + "/usr/share/man/cel/man3", + "/usr/share/man/cel/man3p", + "/usr/share/man/cel/man3x", + "/usr/share/man/cel/man4", + "/usr/share/man/cel/man4x", + "/usr/share/man/cel/man5", + "/usr/share/man/cel/man5x", + "/usr/share/man/cel/man6", + "/usr/share/man/cel/man6x", + "/usr/share/man/cel/man7", + "/usr/share/man/cel/man7x", + "/usr/share/man/cel/man8", + "/usr/share/man/cel/man8x", + "/usr/share/man/cel/man9", + "/usr/share/man/cel/man9x", + "/usr/share/man/cel/mann", + "/usr/share/man/cgg", + "/usr/share/man/cgg/man0p", + "/usr/share/man/cgg/man1", + "/usr/share/man/cgg/man1p", + "/usr/share/man/cgg/man1x", + "/usr/share/man/cgg/man2", + "/usr/share/man/cgg/man2x", + "/usr/share/man/cgg/man3", + "/usr/share/man/cgg/man3p", + "/usr/share/man/cgg/man3x", + "/usr/share/man/cgg/man4", + "/usr/share/man/cgg/man4x", + "/usr/share/man/cgg/man5", + "/usr/share/man/cgg/man5x", + "/usr/share/man/cgg/man6", + "/usr/share/man/cgg/man6x", + "/usr/share/man/cgg/man7", + "/usr/share/man/cgg/man7x", + "/usr/share/man/cgg/man8", + "/usr/share/man/cgg/man8x", + "/usr/share/man/cgg/man9", + "/usr/share/man/cgg/man9x", + "/usr/share/man/cgg/mann", + "/usr/share/man/ch", + "/usr/share/man/ch/man0p", + "/usr/share/man/ch/man1", + "/usr/share/man/ch/man1p", + "/usr/share/man/ch/man1x", + "/usr/share/man/ch/man2", + "/usr/share/man/ch/man2x", + "/usr/share/man/ch/man3", + "/usr/share/man/ch/man3p", + "/usr/share/man/ch/man3x", + "/usr/share/man/ch/man4", + "/usr/share/man/ch/man4x", + "/usr/share/man/ch/man5", + "/usr/share/man/ch/man5x", + "/usr/share/man/ch/man6", + "/usr/share/man/ch/man6x", + "/usr/share/man/ch/man7", + "/usr/share/man/ch/man7x", + "/usr/share/man/ch/man8", + "/usr/share/man/ch/man8x", + "/usr/share/man/ch/man9", + "/usr/share/man/ch/man9x", + "/usr/share/man/ch/mann", + "/usr/share/man/chb", + "/usr/share/man/chb/man0p", + "/usr/share/man/chb/man1", + "/usr/share/man/chb/man1p", + "/usr/share/man/chb/man1x", + "/usr/share/man/chb/man2", + "/usr/share/man/chb/man2x", + "/usr/share/man/chb/man3", + "/usr/share/man/chb/man3p", + "/usr/share/man/chb/man3x", + "/usr/share/man/chb/man4", + "/usr/share/man/chb/man4x", + "/usr/share/man/chb/man5", + "/usr/share/man/chb/man5x", + "/usr/share/man/chb/man6", + "/usr/share/man/chb/man6x", + "/usr/share/man/chb/man7", + "/usr/share/man/chb/man7x", + "/usr/share/man/chb/man8", + "/usr/share/man/chb/man8x", + "/usr/share/man/chb/man9", + "/usr/share/man/chb/man9x", + "/usr/share/man/chb/mann", + "/usr/share/man/chg", + "/usr/share/man/chg/man0p", + "/usr/share/man/chg/man1", + "/usr/share/man/chg/man1p", + "/usr/share/man/chg/man1x", + "/usr/share/man/chg/man2", + "/usr/share/man/chg/man2x", + "/usr/share/man/chg/man3", + "/usr/share/man/chg/man3p", + "/usr/share/man/chg/man3x", + "/usr/share/man/chg/man4", + "/usr/share/man/chg/man4x", + "/usr/share/man/chg/man5", + "/usr/share/man/chg/man5x", + "/usr/share/man/chg/man6", + "/usr/share/man/chg/man6x", + "/usr/share/man/chg/man7", + "/usr/share/man/chg/man7x", + "/usr/share/man/chg/man8", + "/usr/share/man/chg/man8x", + "/usr/share/man/chg/man9", + "/usr/share/man/chg/man9x", + "/usr/share/man/chg/mann", + "/usr/share/man/chk", + "/usr/share/man/chk/man0p", + "/usr/share/man/chk/man1", + "/usr/share/man/chk/man1p", + "/usr/share/man/chk/man1x", + "/usr/share/man/chk/man2", + "/usr/share/man/chk/man2x", + "/usr/share/man/chk/man3", + "/usr/share/man/chk/man3p", + "/usr/share/man/chk/man3x", + "/usr/share/man/chk/man4", + "/usr/share/man/chk/man4x", + "/usr/share/man/chk/man5", + "/usr/share/man/chk/man5x", + "/usr/share/man/chk/man6", + "/usr/share/man/chk/man6x", + "/usr/share/man/chk/man7", + "/usr/share/man/chk/man7x", + "/usr/share/man/chk/man8", + "/usr/share/man/chk/man8x", + "/usr/share/man/chk/man9", + "/usr/share/man/chk/man9x", + "/usr/share/man/chk/mann", + "/usr/share/man/chm", + "/usr/share/man/chm/man0p", + "/usr/share/man/chm/man1", + "/usr/share/man/chm/man1p", + "/usr/share/man/chm/man1x", + "/usr/share/man/chm/man2", + "/usr/share/man/chm/man2x", + "/usr/share/man/chm/man3", + "/usr/share/man/chm/man3p", + "/usr/share/man/chm/man3x", + "/usr/share/man/chm/man4", + "/usr/share/man/chm/man4x", + "/usr/share/man/chm/man5", + "/usr/share/man/chm/man5x", + "/usr/share/man/chm/man6", + "/usr/share/man/chm/man6x", + "/usr/share/man/chm/man7", + "/usr/share/man/chm/man7x", + "/usr/share/man/chm/man8", + "/usr/share/man/chm/man8x", + "/usr/share/man/chm/man9", + "/usr/share/man/chm/man9x", + "/usr/share/man/chm/mann", + "/usr/share/man/chn", + "/usr/share/man/chn/man0p", + "/usr/share/man/chn/man1", + "/usr/share/man/chn/man1p", + "/usr/share/man/chn/man1x", + "/usr/share/man/chn/man2", + "/usr/share/man/chn/man2x", + "/usr/share/man/chn/man3", + "/usr/share/man/chn/man3p", + "/usr/share/man/chn/man3x", + "/usr/share/man/chn/man4", + "/usr/share/man/chn/man4x", + "/usr/share/man/chn/man5", + "/usr/share/man/chn/man5x", + "/usr/share/man/chn/man6", + "/usr/share/man/chn/man6x", + "/usr/share/man/chn/man7", + "/usr/share/man/chn/man7x", + "/usr/share/man/chn/man8", + "/usr/share/man/chn/man8x", + "/usr/share/man/chn/man9", + "/usr/share/man/chn/man9x", + "/usr/share/man/chn/mann", + "/usr/share/man/cho", + "/usr/share/man/cho/man0p", + "/usr/share/man/cho/man1", + "/usr/share/man/cho/man1p", + "/usr/share/man/cho/man1x", + "/usr/share/man/cho/man2", + "/usr/share/man/cho/man2x", + "/usr/share/man/cho/man3", + "/usr/share/man/cho/man3p", + "/usr/share/man/cho/man3x", + "/usr/share/man/cho/man4", + "/usr/share/man/cho/man4x", + "/usr/share/man/cho/man5", + "/usr/share/man/cho/man5x", + "/usr/share/man/cho/man6", + "/usr/share/man/cho/man6x", + "/usr/share/man/cho/man7", + "/usr/share/man/cho/man7x", + "/usr/share/man/cho/man8", + "/usr/share/man/cho/man8x", + "/usr/share/man/cho/man9", + "/usr/share/man/cho/man9x", + "/usr/share/man/cho/mann", + "/usr/share/man/chp", + "/usr/share/man/chp/man0p", + "/usr/share/man/chp/man1", + "/usr/share/man/chp/man1p", + "/usr/share/man/chp/man1x", + "/usr/share/man/chp/man2", + "/usr/share/man/chp/man2x", + "/usr/share/man/chp/man3", + "/usr/share/man/chp/man3p", + "/usr/share/man/chp/man3x", + "/usr/share/man/chp/man4", + "/usr/share/man/chp/man4x", + "/usr/share/man/chp/man5", + "/usr/share/man/chp/man5x", + "/usr/share/man/chp/man6", + "/usr/share/man/chp/man6x", + "/usr/share/man/chp/man7", + "/usr/share/man/chp/man7x", + "/usr/share/man/chp/man8", + "/usr/share/man/chp/man8x", + "/usr/share/man/chp/man9", + "/usr/share/man/chp/man9x", + "/usr/share/man/chp/mann", + "/usr/share/man/chr", + "/usr/share/man/chr/man0p", + "/usr/share/man/chr/man1", + "/usr/share/man/chr/man1p", + "/usr/share/man/chr/man1x", + "/usr/share/man/chr/man2", + "/usr/share/man/chr/man2x", + "/usr/share/man/chr/man3", + "/usr/share/man/chr/man3p", + "/usr/share/man/chr/man3x", + "/usr/share/man/chr/man4", + "/usr/share/man/chr/man4x", + "/usr/share/man/chr/man5", + "/usr/share/man/chr/man5x", + "/usr/share/man/chr/man6", + "/usr/share/man/chr/man6x", + "/usr/share/man/chr/man7", + "/usr/share/man/chr/man7x", + "/usr/share/man/chr/man8", + "/usr/share/man/chr/man8x", + "/usr/share/man/chr/man9", + "/usr/share/man/chr/man9x", + "/usr/share/man/chr/mann", + "/usr/share/man/chy", + "/usr/share/man/chy/man0p", + "/usr/share/man/chy/man1", + "/usr/share/man/chy/man1p", + "/usr/share/man/chy/man1x", + "/usr/share/man/chy/man2", + "/usr/share/man/chy/man2x", + "/usr/share/man/chy/man3", + "/usr/share/man/chy/man3p", + "/usr/share/man/chy/man3x", + "/usr/share/man/chy/man4", + "/usr/share/man/chy/man4x", + "/usr/share/man/chy/man5", + "/usr/share/man/chy/man5x", + "/usr/share/man/chy/man6", + "/usr/share/man/chy/man6x", + "/usr/share/man/chy/man7", + "/usr/share/man/chy/man7x", + "/usr/share/man/chy/man8", + "/usr/share/man/chy/man8x", + "/usr/share/man/chy/man9", + "/usr/share/man/chy/man9x", + "/usr/share/man/chy/mann", + "/usr/share/man/ckb", + "/usr/share/man/ckb/man0p", + "/usr/share/man/ckb/man1", + "/usr/share/man/ckb/man1p", + "/usr/share/man/ckb/man1x", + "/usr/share/man/ckb/man2", + "/usr/share/man/ckb/man2x", + "/usr/share/man/ckb/man3", + "/usr/share/man/ckb/man3p", + "/usr/share/man/ckb/man3x", + "/usr/share/man/ckb/man4", + "/usr/share/man/ckb/man4x", + "/usr/share/man/ckb/man5", + "/usr/share/man/ckb/man5x", + "/usr/share/man/ckb/man6", + "/usr/share/man/ckb/man6x", + "/usr/share/man/ckb/man7", + "/usr/share/man/ckb/man7x", + "/usr/share/man/ckb/man8", + "/usr/share/man/ckb/man8x", + "/usr/share/man/ckb/man9", + "/usr/share/man/ckb/man9x", + "/usr/share/man/ckb/mann", + "/usr/share/man/cmc", + "/usr/share/man/cmc/man0p", + "/usr/share/man/cmc/man1", + "/usr/share/man/cmc/man1p", + "/usr/share/man/cmc/man1x", + "/usr/share/man/cmc/man2", + "/usr/share/man/cmc/man2x", + "/usr/share/man/cmc/man3", + "/usr/share/man/cmc/man3p", + "/usr/share/man/cmc/man3x", + "/usr/share/man/cmc/man4", + "/usr/share/man/cmc/man4x", + "/usr/share/man/cmc/man5", + "/usr/share/man/cmc/man5x", + "/usr/share/man/cmc/man6", + "/usr/share/man/cmc/man6x", + "/usr/share/man/cmc/man7", + "/usr/share/man/cmc/man7x", + "/usr/share/man/cmc/man8", + "/usr/share/man/cmc/man8x", + "/usr/share/man/cmc/man9", + "/usr/share/man/cmc/man9x", + "/usr/share/man/cmc/mann", + "/usr/share/man/cmn", + "/usr/share/man/cmn/man0p", + "/usr/share/man/cmn/man1", + "/usr/share/man/cmn/man1p", + "/usr/share/man/cmn/man1x", + "/usr/share/man/cmn/man2", + "/usr/share/man/cmn/man2x", + "/usr/share/man/cmn/man3", + "/usr/share/man/cmn/man3p", + "/usr/share/man/cmn/man3x", + "/usr/share/man/cmn/man4", + "/usr/share/man/cmn/man4x", + "/usr/share/man/cmn/man5", + "/usr/share/man/cmn/man5x", + "/usr/share/man/cmn/man6", + "/usr/share/man/cmn/man6x", + "/usr/share/man/cmn/man7", + "/usr/share/man/cmn/man7x", + "/usr/share/man/cmn/man8", + "/usr/share/man/cmn/man8x", + "/usr/share/man/cmn/man9", + "/usr/share/man/cmn/man9x", + "/usr/share/man/cmn/mann", + "/usr/share/man/cn", + "/usr/share/man/cn/man0p", + "/usr/share/man/cn/man1", + "/usr/share/man/cn/man1p", + "/usr/share/man/cn/man1x", + "/usr/share/man/cn/man2", + "/usr/share/man/cn/man2x", + "/usr/share/man/cn/man3", + "/usr/share/man/cn/man3p", + "/usr/share/man/cn/man3x", + "/usr/share/man/cn/man4", + "/usr/share/man/cn/man4x", + "/usr/share/man/cn/man5", + "/usr/share/man/cn/man5x", + "/usr/share/man/cn/man6", + "/usr/share/man/cn/man6x", + "/usr/share/man/cn/man7", + "/usr/share/man/cn/man7x", + "/usr/share/man/cn/man8", + "/usr/share/man/cn/man8x", + "/usr/share/man/cn/man9", + "/usr/share/man/cn/man9x", + "/usr/share/man/cn/mann", + "/usr/share/man/co", + "/usr/share/man/co/man0p", + "/usr/share/man/co/man1", + "/usr/share/man/co/man1p", + "/usr/share/man/co/man1x", + "/usr/share/man/co/man2", + "/usr/share/man/co/man2x", + "/usr/share/man/co/man3", + "/usr/share/man/co/man3p", + "/usr/share/man/co/man3x", + "/usr/share/man/co/man4", + "/usr/share/man/co/man4x", + "/usr/share/man/co/man5", + "/usr/share/man/co/man5x", + "/usr/share/man/co/man6", + "/usr/share/man/co/man6x", + "/usr/share/man/co/man7", + "/usr/share/man/co/man7x", + "/usr/share/man/co/man8", + "/usr/share/man/co/man8x", + "/usr/share/man/co/man9", + "/usr/share/man/co/man9x", + "/usr/share/man/co/mann", + "/usr/share/man/cop", + "/usr/share/man/cop/man0p", + "/usr/share/man/cop/man1", + "/usr/share/man/cop/man1p", + "/usr/share/man/cop/man1x", + "/usr/share/man/cop/man2", + "/usr/share/man/cop/man2x", + "/usr/share/man/cop/man3", + "/usr/share/man/cop/man3p", + "/usr/share/man/cop/man3x", + "/usr/share/man/cop/man4", + "/usr/share/man/cop/man4x", + "/usr/share/man/cop/man5", + "/usr/share/man/cop/man5x", + "/usr/share/man/cop/man6", + "/usr/share/man/cop/man6x", + "/usr/share/man/cop/man7", + "/usr/share/man/cop/man7x", + "/usr/share/man/cop/man8", + "/usr/share/man/cop/man8x", + "/usr/share/man/cop/man9", + "/usr/share/man/cop/man9x", + "/usr/share/man/cop/mann", + "/usr/share/man/cpe", + "/usr/share/man/cpe/man0p", + "/usr/share/man/cpe/man1", + "/usr/share/man/cpe/man1p", + "/usr/share/man/cpe/man1x", + "/usr/share/man/cpe/man2", + "/usr/share/man/cpe/man2x", + "/usr/share/man/cpe/man3", + "/usr/share/man/cpe/man3p", + "/usr/share/man/cpe/man3x", + "/usr/share/man/cpe/man4", + "/usr/share/man/cpe/man4x", + "/usr/share/man/cpe/man5", + "/usr/share/man/cpe/man5x", + "/usr/share/man/cpe/man6", + "/usr/share/man/cpe/man6x", + "/usr/share/man/cpe/man7", + "/usr/share/man/cpe/man7x", + "/usr/share/man/cpe/man8", + "/usr/share/man/cpe/man8x", + "/usr/share/man/cpe/man9", + "/usr/share/man/cpe/man9x", + "/usr/share/man/cpe/mann", + "/usr/share/man/cpf", + "/usr/share/man/cpf/man0p", + "/usr/share/man/cpf/man1", + "/usr/share/man/cpf/man1p", + "/usr/share/man/cpf/man1x", + "/usr/share/man/cpf/man2", + "/usr/share/man/cpf/man2x", + "/usr/share/man/cpf/man3", + "/usr/share/man/cpf/man3p", + "/usr/share/man/cpf/man3x", + "/usr/share/man/cpf/man4", + "/usr/share/man/cpf/man4x", + "/usr/share/man/cpf/man5", + "/usr/share/man/cpf/man5x", + "/usr/share/man/cpf/man6", + "/usr/share/man/cpf/man6x", + "/usr/share/man/cpf/man7", + "/usr/share/man/cpf/man7x", + "/usr/share/man/cpf/man8", + "/usr/share/man/cpf/man8x", + "/usr/share/man/cpf/man9", + "/usr/share/man/cpf/man9x", + "/usr/share/man/cpf/mann", + "/usr/share/man/cpp", + "/usr/share/man/cpp/man0p", + "/usr/share/man/cpp/man1", + "/usr/share/man/cpp/man1p", + "/usr/share/man/cpp/man1x", + "/usr/share/man/cpp/man2", + "/usr/share/man/cpp/man2x", + "/usr/share/man/cpp/man3", + "/usr/share/man/cpp/man3p", + "/usr/share/man/cpp/man3x", + "/usr/share/man/cpp/man4", + "/usr/share/man/cpp/man4x", + "/usr/share/man/cpp/man5", + "/usr/share/man/cpp/man5x", + "/usr/share/man/cpp/man6", + "/usr/share/man/cpp/man6x", + "/usr/share/man/cpp/man7", + "/usr/share/man/cpp/man7x", + "/usr/share/man/cpp/man8", + "/usr/share/man/cpp/man8x", + "/usr/share/man/cpp/man9", + "/usr/share/man/cpp/man9x", + "/usr/share/man/cpp/mann", + "/usr/share/man/cr", + "/usr/share/man/cr/man0p", + "/usr/share/man/cr/man1", + "/usr/share/man/cr/man1p", + "/usr/share/man/cr/man1x", + "/usr/share/man/cr/man2", + "/usr/share/man/cr/man2x", + "/usr/share/man/cr/man3", + "/usr/share/man/cr/man3p", + "/usr/share/man/cr/man3x", + "/usr/share/man/cr/man4", + "/usr/share/man/cr/man4x", + "/usr/share/man/cr/man5", + "/usr/share/man/cr/man5x", + "/usr/share/man/cr/man6", + "/usr/share/man/cr/man6x", + "/usr/share/man/cr/man7", + "/usr/share/man/cr/man7x", + "/usr/share/man/cr/man8", + "/usr/share/man/cr/man8x", + "/usr/share/man/cr/man9", + "/usr/share/man/cr/man9x", + "/usr/share/man/cr/mann", + "/usr/share/man/crh", + "/usr/share/man/crh/man0p", + "/usr/share/man/crh/man1", + "/usr/share/man/crh/man1p", + "/usr/share/man/crh/man1x", + "/usr/share/man/crh/man2", + "/usr/share/man/crh/man2x", + "/usr/share/man/crh/man3", + "/usr/share/man/crh/man3p", + "/usr/share/man/crh/man3x", + "/usr/share/man/crh/man4", + "/usr/share/man/crh/man4x", + "/usr/share/man/crh/man5", + "/usr/share/man/crh/man5x", + "/usr/share/man/crh/man6", + "/usr/share/man/crh/man6x", + "/usr/share/man/crh/man7", + "/usr/share/man/crh/man7x", + "/usr/share/man/crh/man8", + "/usr/share/man/crh/man8x", + "/usr/share/man/crh/man9", + "/usr/share/man/crh/man9x", + "/usr/share/man/crh/mann", + "/usr/share/man/crp", + "/usr/share/man/crp/man0p", + "/usr/share/man/crp/man1", + "/usr/share/man/crp/man1p", + "/usr/share/man/crp/man1x", + "/usr/share/man/crp/man2", + "/usr/share/man/crp/man2x", + "/usr/share/man/crp/man3", + "/usr/share/man/crp/man3p", + "/usr/share/man/crp/man3x", + "/usr/share/man/crp/man4", + "/usr/share/man/crp/man4x", + "/usr/share/man/crp/man5", + "/usr/share/man/crp/man5x", + "/usr/share/man/crp/man6", + "/usr/share/man/crp/man6x", + "/usr/share/man/crp/man7", + "/usr/share/man/crp/man7x", + "/usr/share/man/crp/man8", + "/usr/share/man/crp/man8x", + "/usr/share/man/crp/man9", + "/usr/share/man/crp/man9x", + "/usr/share/man/crp/mann", + "/usr/share/man/cs", + "/usr/share/man/cs.cp1250", + "/usr/share/man/cs.cp1250/man0p", + "/usr/share/man/cs.cp1250/man1", + "/usr/share/man/cs.cp1250/man1p", + "/usr/share/man/cs.cp1250/man1x", + "/usr/share/man/cs.cp1250/man2", + "/usr/share/man/cs.cp1250/man2x", + "/usr/share/man/cs.cp1250/man3", + "/usr/share/man/cs.cp1250/man3p", + "/usr/share/man/cs.cp1250/man3x", + "/usr/share/man/cs.cp1250/man4", + "/usr/share/man/cs.cp1250/man4x", + "/usr/share/man/cs.cp1250/man5", + "/usr/share/man/cs.cp1250/man5x", + "/usr/share/man/cs.cp1250/man6", + "/usr/share/man/cs.cp1250/man6x", + "/usr/share/man/cs.cp1250/man7", + "/usr/share/man/cs.cp1250/man7x", + "/usr/share/man/cs.cp1250/man8", + "/usr/share/man/cs.cp1250/man8x", + "/usr/share/man/cs.cp1250/man9", + "/usr/share/man/cs.cp1250/man9x", + "/usr/share/man/cs.cp1250/mann", + "/usr/share/man/cs/man0p", + "/usr/share/man/cs/man1", + "/usr/share/man/cs/man1p", + "/usr/share/man/cs/man1x", + "/usr/share/man/cs/man2", + "/usr/share/man/cs/man2x", + "/usr/share/man/cs/man3", + "/usr/share/man/cs/man3p", + "/usr/share/man/cs/man3x", + "/usr/share/man/cs/man4", + "/usr/share/man/cs/man4x", + "/usr/share/man/cs/man5", + "/usr/share/man/cs/man5x", + "/usr/share/man/cs/man6", + "/usr/share/man/cs/man6x", + "/usr/share/man/cs/man7", + "/usr/share/man/cs/man7x", + "/usr/share/man/cs/man8", + "/usr/share/man/cs/man8x", + "/usr/share/man/cs/man9", + "/usr/share/man/cs/man9x", + "/usr/share/man/cs/mann", + "/usr/share/man/cs_CZ", + "/usr/share/man/cs_CZ/man0p", + "/usr/share/man/cs_CZ/man1", + "/usr/share/man/cs_CZ/man1p", + "/usr/share/man/cs_CZ/man1x", + "/usr/share/man/cs_CZ/man2", + "/usr/share/man/cs_CZ/man2x", + "/usr/share/man/cs_CZ/man3", + "/usr/share/man/cs_CZ/man3p", + "/usr/share/man/cs_CZ/man3x", + "/usr/share/man/cs_CZ/man4", + "/usr/share/man/cs_CZ/man4x", + "/usr/share/man/cs_CZ/man5", + "/usr/share/man/cs_CZ/man5x", + "/usr/share/man/cs_CZ/man6", + "/usr/share/man/cs_CZ/man6x", + "/usr/share/man/cs_CZ/man7", + "/usr/share/man/cs_CZ/man7x", + "/usr/share/man/cs_CZ/man8", + "/usr/share/man/cs_CZ/man8x", + "/usr/share/man/cs_CZ/man9", + "/usr/share/man/cs_CZ/man9x", + "/usr/share/man/cs_CZ/mann", + "/usr/share/man/csb", + "/usr/share/man/csb/man0p", + "/usr/share/man/csb/man1", + "/usr/share/man/csb/man1p", + "/usr/share/man/csb/man1x", + "/usr/share/man/csb/man2", + "/usr/share/man/csb/man2x", + "/usr/share/man/csb/man3", + "/usr/share/man/csb/man3p", + "/usr/share/man/csb/man3x", + "/usr/share/man/csb/man4", + "/usr/share/man/csb/man4x", + "/usr/share/man/csb/man5", + "/usr/share/man/csb/man5x", + "/usr/share/man/csb/man6", + "/usr/share/man/csb/man6x", + "/usr/share/man/csb/man7", + "/usr/share/man/csb/man7x", + "/usr/share/man/csb/man8", + "/usr/share/man/csb/man8x", + "/usr/share/man/csb/man9", + "/usr/share/man/csb/man9x", + "/usr/share/man/csb/mann", + "/usr/share/man/cu", + "/usr/share/man/cu/man0p", + "/usr/share/man/cu/man1", + "/usr/share/man/cu/man1p", + "/usr/share/man/cu/man1x", + "/usr/share/man/cu/man2", + "/usr/share/man/cu/man2x", + "/usr/share/man/cu/man3", + "/usr/share/man/cu/man3p", + "/usr/share/man/cu/man3x", + "/usr/share/man/cu/man4", + "/usr/share/man/cu/man4x", + "/usr/share/man/cu/man5", + "/usr/share/man/cu/man5x", + "/usr/share/man/cu/man6", + "/usr/share/man/cu/man6x", + "/usr/share/man/cu/man7", + "/usr/share/man/cu/man7x", + "/usr/share/man/cu/man8", + "/usr/share/man/cu/man8x", + "/usr/share/man/cu/man9", + "/usr/share/man/cu/man9x", + "/usr/share/man/cu/mann", + "/usr/share/man/cus", + "/usr/share/man/cus/man0p", + "/usr/share/man/cus/man1", + "/usr/share/man/cus/man1p", + "/usr/share/man/cus/man1x", + "/usr/share/man/cus/man2", + "/usr/share/man/cus/man2x", + "/usr/share/man/cus/man3", + "/usr/share/man/cus/man3p", + "/usr/share/man/cus/man3x", + "/usr/share/man/cus/man4", + "/usr/share/man/cus/man4x", + "/usr/share/man/cus/man5", + "/usr/share/man/cus/man5x", + "/usr/share/man/cus/man6", + "/usr/share/man/cus/man6x", + "/usr/share/man/cus/man7", + "/usr/share/man/cus/man7x", + "/usr/share/man/cus/man8", + "/usr/share/man/cus/man8x", + "/usr/share/man/cus/man9", + "/usr/share/man/cus/man9x", + "/usr/share/man/cus/mann", + "/usr/share/man/cv", + "/usr/share/man/cv/man0p", + "/usr/share/man/cv/man1", + "/usr/share/man/cv/man1p", + "/usr/share/man/cv/man1x", + "/usr/share/man/cv/man2", + "/usr/share/man/cv/man2x", + "/usr/share/man/cv/man3", + "/usr/share/man/cv/man3p", + "/usr/share/man/cv/man3x", + "/usr/share/man/cv/man4", + "/usr/share/man/cv/man4x", + "/usr/share/man/cv/man5", + "/usr/share/man/cv/man5x", + "/usr/share/man/cv/man6", + "/usr/share/man/cv/man6x", + "/usr/share/man/cv/man7", + "/usr/share/man/cv/man7x", + "/usr/share/man/cv/man8", + "/usr/share/man/cv/man8x", + "/usr/share/man/cv/man9", + "/usr/share/man/cv/man9x", + "/usr/share/man/cv/mann", + "/usr/share/man/cy", + "/usr/share/man/cy/man0p", + "/usr/share/man/cy/man1", + "/usr/share/man/cy/man1p", + "/usr/share/man/cy/man1x", + "/usr/share/man/cy/man2", + "/usr/share/man/cy/man2x", + "/usr/share/man/cy/man3", + "/usr/share/man/cy/man3p", + "/usr/share/man/cy/man3x", + "/usr/share/man/cy/man4", + "/usr/share/man/cy/man4x", + "/usr/share/man/cy/man5", + "/usr/share/man/cy/man5x", + "/usr/share/man/cy/man6", + "/usr/share/man/cy/man6x", + "/usr/share/man/cy/man7", + "/usr/share/man/cy/man7x", + "/usr/share/man/cy/man8", + "/usr/share/man/cy/man8x", + "/usr/share/man/cy/man9", + "/usr/share/man/cy/man9x", + "/usr/share/man/cy/mann", + "/usr/share/man/da", + "/usr/share/man/da/man0p", + "/usr/share/man/da/man1", + "/usr/share/man/da/man1p", + "/usr/share/man/da/man1x", + "/usr/share/man/da/man2", + "/usr/share/man/da/man2x", + "/usr/share/man/da/man3", + "/usr/share/man/da/man3p", + "/usr/share/man/da/man3x", + "/usr/share/man/da/man4", + "/usr/share/man/da/man4x", + "/usr/share/man/da/man5", + "/usr/share/man/da/man5x", + "/usr/share/man/da/man6", + "/usr/share/man/da/man6x", + "/usr/share/man/da/man7", + "/usr/share/man/da/man7x", + "/usr/share/man/da/man8", + "/usr/share/man/da/man8x", + "/usr/share/man/da/man9", + "/usr/share/man/da/man9x", + "/usr/share/man/da/mann", + "/usr/share/man/da_DK", + "/usr/share/man/da_DK/man0p", + "/usr/share/man/da_DK/man1", + "/usr/share/man/da_DK/man1p", + "/usr/share/man/da_DK/man1x", + "/usr/share/man/da_DK/man2", + "/usr/share/man/da_DK/man2x", + "/usr/share/man/da_DK/man3", + "/usr/share/man/da_DK/man3p", + "/usr/share/man/da_DK/man3x", + "/usr/share/man/da_DK/man4", + "/usr/share/man/da_DK/man4x", + "/usr/share/man/da_DK/man5", + "/usr/share/man/da_DK/man5x", + "/usr/share/man/da_DK/man6", + "/usr/share/man/da_DK/man6x", + "/usr/share/man/da_DK/man7", + "/usr/share/man/da_DK/man7x", + "/usr/share/man/da_DK/man8", + "/usr/share/man/da_DK/man8x", + "/usr/share/man/da_DK/man9", + "/usr/share/man/da_DK/man9x", + "/usr/share/man/da_DK/mann", + "/usr/share/man/dak", + "/usr/share/man/dak/man0p", + "/usr/share/man/dak/man1", + "/usr/share/man/dak/man1p", + "/usr/share/man/dak/man1x", + "/usr/share/man/dak/man2", + "/usr/share/man/dak/man2x", + "/usr/share/man/dak/man3", + "/usr/share/man/dak/man3p", + "/usr/share/man/dak/man3x", + "/usr/share/man/dak/man4", + "/usr/share/man/dak/man4x", + "/usr/share/man/dak/man5", + "/usr/share/man/dak/man5x", + "/usr/share/man/dak/man6", + "/usr/share/man/dak/man6x", + "/usr/share/man/dak/man7", + "/usr/share/man/dak/man7x", + "/usr/share/man/dak/man8", + "/usr/share/man/dak/man8x", + "/usr/share/man/dak/man9", + "/usr/share/man/dak/man9x", + "/usr/share/man/dak/mann", + "/usr/share/man/dar", + "/usr/share/man/dar/man0p", + "/usr/share/man/dar/man1", + "/usr/share/man/dar/man1p", + "/usr/share/man/dar/man1x", + "/usr/share/man/dar/man2", + "/usr/share/man/dar/man2x", + "/usr/share/man/dar/man3", + "/usr/share/man/dar/man3p", + "/usr/share/man/dar/man3x", + "/usr/share/man/dar/man4", + "/usr/share/man/dar/man4x", + "/usr/share/man/dar/man5", + "/usr/share/man/dar/man5x", + "/usr/share/man/dar/man6", + "/usr/share/man/dar/man6x", + "/usr/share/man/dar/man7", + "/usr/share/man/dar/man7x", + "/usr/share/man/dar/man8", + "/usr/share/man/dar/man8x", + "/usr/share/man/dar/man9", + "/usr/share/man/dar/man9x", + "/usr/share/man/dar/mann", + "/usr/share/man/day", + "/usr/share/man/day/man0p", + "/usr/share/man/day/man1", + "/usr/share/man/day/man1p", + "/usr/share/man/day/man1x", + "/usr/share/man/day/man2", + "/usr/share/man/day/man2x", + "/usr/share/man/day/man3", + "/usr/share/man/day/man3p", + "/usr/share/man/day/man3x", + "/usr/share/man/day/man4", + "/usr/share/man/day/man4x", + "/usr/share/man/day/man5", + "/usr/share/man/day/man5x", + "/usr/share/man/day/man6", + "/usr/share/man/day/man6x", + "/usr/share/man/day/man7", + "/usr/share/man/day/man7x", + "/usr/share/man/day/man8", + "/usr/share/man/day/man8x", + "/usr/share/man/day/man9", + "/usr/share/man/day/man9x", + "/usr/share/man/day/mann", + "/usr/share/man/de", + "/usr/share/man/de-CH", + "/usr/share/man/de-CH/man0p", + "/usr/share/man/de-CH/man1", + "/usr/share/man/de-CH/man1p", + "/usr/share/man/de-CH/man1x", + "/usr/share/man/de-CH/man2", + "/usr/share/man/de-CH/man2x", + "/usr/share/man/de-CH/man3", + "/usr/share/man/de-CH/man3p", + "/usr/share/man/de-CH/man3x", + "/usr/share/man/de-CH/man4", + "/usr/share/man/de-CH/man4x", + "/usr/share/man/de-CH/man5", + "/usr/share/man/de-CH/man5x", + "/usr/share/man/de-CH/man6", + "/usr/share/man/de-CH/man6x", + "/usr/share/man/de-CH/man7", + "/usr/share/man/de-CH/man7x", + "/usr/share/man/de-CH/man8", + "/usr/share/man/de-CH/man8x", + "/usr/share/man/de-CH/man9", + "/usr/share/man/de-CH/man9x", + "/usr/share/man/de-CH/mann", + "/usr/share/man/de.us-ascii", + "/usr/share/man/de.us-ascii/man0p", + "/usr/share/man/de.us-ascii/man1", + "/usr/share/man/de.us-ascii/man1p", + "/usr/share/man/de.us-ascii/man1x", + "/usr/share/man/de.us-ascii/man2", + "/usr/share/man/de.us-ascii/man2x", + "/usr/share/man/de.us-ascii/man3", + "/usr/share/man/de.us-ascii/man3p", + "/usr/share/man/de.us-ascii/man3x", + "/usr/share/man/de.us-ascii/man4", + "/usr/share/man/de.us-ascii/man4x", + "/usr/share/man/de.us-ascii/man5", + "/usr/share/man/de.us-ascii/man5x", + "/usr/share/man/de.us-ascii/man6", + "/usr/share/man/de.us-ascii/man6x", + "/usr/share/man/de.us-ascii/man7", + "/usr/share/man/de.us-ascii/man7x", + "/usr/share/man/de.us-ascii/man8", + "/usr/share/man/de.us-ascii/man8x", + "/usr/share/man/de.us-ascii/man9", + "/usr/share/man/de.us-ascii/man9x", + "/usr/share/man/de.us-ascii/mann", + "/usr/share/man/de/man0p", + "/usr/share/man/de/man1", + "/usr/share/man/de/man1p", + "/usr/share/man/de/man1x", + "/usr/share/man/de/man2", + "/usr/share/man/de/man2x", + "/usr/share/man/de/man3", + "/usr/share/man/de/man3p", + "/usr/share/man/de/man3x", + "/usr/share/man/de/man4", + "/usr/share/man/de/man4x", + "/usr/share/man/de/man5", + "/usr/share/man/de/man5x", + "/usr/share/man/de/man6", + "/usr/share/man/de/man6x", + "/usr/share/man/de/man7", + "/usr/share/man/de/man7x", + "/usr/share/man/de/man8", + "/usr/share/man/de/man8x", + "/usr/share/man/de/man9", + "/usr/share/man/de/man9x", + "/usr/share/man/de/mann", + "/usr/share/man/de@hebrew", + "/usr/share/man/de@hebrew/man0p", + "/usr/share/man/de@hebrew/man1", + "/usr/share/man/de@hebrew/man1p", + "/usr/share/man/de@hebrew/man1x", + "/usr/share/man/de@hebrew/man2", + "/usr/share/man/de@hebrew/man2x", + "/usr/share/man/de@hebrew/man3", + "/usr/share/man/de@hebrew/man3p", + "/usr/share/man/de@hebrew/man3x", + "/usr/share/man/de@hebrew/man4", + "/usr/share/man/de@hebrew/man4x", + "/usr/share/man/de@hebrew/man5", + "/usr/share/man/de@hebrew/man5x", + "/usr/share/man/de@hebrew/man6", + "/usr/share/man/de@hebrew/man6x", + "/usr/share/man/de@hebrew/man7", + "/usr/share/man/de@hebrew/man7x", + "/usr/share/man/de@hebrew/man8", + "/usr/share/man/de@hebrew/man8x", + "/usr/share/man/de@hebrew/man9", + "/usr/share/man/de@hebrew/man9x", + "/usr/share/man/de@hebrew/mann", + "/usr/share/man/de_AT", + "/usr/share/man/de_AT/man0p", + "/usr/share/man/de_AT/man1", + "/usr/share/man/de_AT/man1p", + "/usr/share/man/de_AT/man1x", + "/usr/share/man/de_AT/man2", + "/usr/share/man/de_AT/man2x", + "/usr/share/man/de_AT/man3", + "/usr/share/man/de_AT/man3p", + "/usr/share/man/de_AT/man3x", + "/usr/share/man/de_AT/man4", + "/usr/share/man/de_AT/man4x", + "/usr/share/man/de_AT/man5", + "/usr/share/man/de_AT/man5x", + "/usr/share/man/de_AT/man6", + "/usr/share/man/de_AT/man6x", + "/usr/share/man/de_AT/man7", + "/usr/share/man/de_AT/man7x", + "/usr/share/man/de_AT/man8", + "/usr/share/man/de_AT/man8x", + "/usr/share/man/de_AT/man9", + "/usr/share/man/de_AT/man9x", + "/usr/share/man/de_AT/mann", + "/usr/share/man/de_CH", + "/usr/share/man/de_CH/man0p", + "/usr/share/man/de_CH/man1", + "/usr/share/man/de_CH/man1p", + "/usr/share/man/de_CH/man1x", + "/usr/share/man/de_CH/man2", + "/usr/share/man/de_CH/man2x", + "/usr/share/man/de_CH/man3", + "/usr/share/man/de_CH/man3p", + "/usr/share/man/de_CH/man3x", + "/usr/share/man/de_CH/man4", + "/usr/share/man/de_CH/man4x", + "/usr/share/man/de_CH/man5", + "/usr/share/man/de_CH/man5x", + "/usr/share/man/de_CH/man6", + "/usr/share/man/de_CH/man6x", + "/usr/share/man/de_CH/man7", + "/usr/share/man/de_CH/man7x", + "/usr/share/man/de_CH/man8", + "/usr/share/man/de_CH/man8x", + "/usr/share/man/de_CH/man9", + "/usr/share/man/de_CH/man9x", + "/usr/share/man/de_CH/mann", + "/usr/share/man/de_DE", + "/usr/share/man/de_DE/man0p", + "/usr/share/man/de_DE/man1", + "/usr/share/man/de_DE/man1p", + "/usr/share/man/de_DE/man1x", + "/usr/share/man/de_DE/man2", + "/usr/share/man/de_DE/man2x", + "/usr/share/man/de_DE/man3", + "/usr/share/man/de_DE/man3p", + "/usr/share/man/de_DE/man3x", + "/usr/share/man/de_DE/man4", + "/usr/share/man/de_DE/man4x", + "/usr/share/man/de_DE/man5", + "/usr/share/man/de_DE/man5x", + "/usr/share/man/de_DE/man6", + "/usr/share/man/de_DE/man6x", + "/usr/share/man/de_DE/man7", + "/usr/share/man/de_DE/man7x", + "/usr/share/man/de_DE/man8", + "/usr/share/man/de_DE/man8x", + "/usr/share/man/de_DE/man9", + "/usr/share/man/de_DE/man9x", + "/usr/share/man/de_DE/mann", + "/usr/share/man/del", + "/usr/share/man/del/man0p", + "/usr/share/man/del/man1", + "/usr/share/man/del/man1p", + "/usr/share/man/del/man1x", + "/usr/share/man/del/man2", + "/usr/share/man/del/man2x", + "/usr/share/man/del/man3", + "/usr/share/man/del/man3p", + "/usr/share/man/del/man3x", + "/usr/share/man/del/man4", + "/usr/share/man/del/man4x", + "/usr/share/man/del/man5", + "/usr/share/man/del/man5x", + "/usr/share/man/del/man6", + "/usr/share/man/del/man6x", + "/usr/share/man/del/man7", + "/usr/share/man/del/man7x", + "/usr/share/man/del/man8", + "/usr/share/man/del/man8x", + "/usr/share/man/del/man9", + "/usr/share/man/del/man9x", + "/usr/share/man/del/mann", + "/usr/share/man/den", + "/usr/share/man/den/man0p", + "/usr/share/man/den/man1", + "/usr/share/man/den/man1p", + "/usr/share/man/den/man1x", + "/usr/share/man/den/man2", + "/usr/share/man/den/man2x", + "/usr/share/man/den/man3", + "/usr/share/man/den/man3p", + "/usr/share/man/den/man3x", + "/usr/share/man/den/man4", + "/usr/share/man/den/man4x", + "/usr/share/man/den/man5", + "/usr/share/man/den/man5x", + "/usr/share/man/den/man6", + "/usr/share/man/den/man6x", + "/usr/share/man/den/man7", + "/usr/share/man/den/man7x", + "/usr/share/man/den/man8", + "/usr/share/man/den/man8x", + "/usr/share/man/den/man9", + "/usr/share/man/den/man9x", + "/usr/share/man/den/mann", + "/usr/share/man/dgr", + "/usr/share/man/dgr/man0p", + "/usr/share/man/dgr/man1", + "/usr/share/man/dgr/man1p", + "/usr/share/man/dgr/man1x", + "/usr/share/man/dgr/man2", + "/usr/share/man/dgr/man2x", + "/usr/share/man/dgr/man3", + "/usr/share/man/dgr/man3p", + "/usr/share/man/dgr/man3x", + "/usr/share/man/dgr/man4", + "/usr/share/man/dgr/man4x", + "/usr/share/man/dgr/man5", + "/usr/share/man/dgr/man5x", + "/usr/share/man/dgr/man6", + "/usr/share/man/dgr/man6x", + "/usr/share/man/dgr/man7", + "/usr/share/man/dgr/man7x", + "/usr/share/man/dgr/man8", + "/usr/share/man/dgr/man8x", + "/usr/share/man/dgr/man9", + "/usr/share/man/dgr/man9x", + "/usr/share/man/dgr/mann", + "/usr/share/man/din", + "/usr/share/man/din/man0p", + "/usr/share/man/din/man1", + "/usr/share/man/din/man1p", + "/usr/share/man/din/man1x", + "/usr/share/man/din/man2", + "/usr/share/man/din/man2x", + "/usr/share/man/din/man3", + "/usr/share/man/din/man3p", + "/usr/share/man/din/man3x", + "/usr/share/man/din/man4", + "/usr/share/man/din/man4x", + "/usr/share/man/din/man5", + "/usr/share/man/din/man5x", + "/usr/share/man/din/man6", + "/usr/share/man/din/man6x", + "/usr/share/man/din/man7", + "/usr/share/man/din/man7x", + "/usr/share/man/din/man8", + "/usr/share/man/din/man8x", + "/usr/share/man/din/man9", + "/usr/share/man/din/man9x", + "/usr/share/man/din/mann", + "/usr/share/man/doi", + "/usr/share/man/doi/man0p", + "/usr/share/man/doi/man1", + "/usr/share/man/doi/man1p", + "/usr/share/man/doi/man1x", + "/usr/share/man/doi/man2", + "/usr/share/man/doi/man2x", + "/usr/share/man/doi/man3", + "/usr/share/man/doi/man3p", + "/usr/share/man/doi/man3x", + "/usr/share/man/doi/man4", + "/usr/share/man/doi/man4x", + "/usr/share/man/doi/man5", + "/usr/share/man/doi/man5x", + "/usr/share/man/doi/man6", + "/usr/share/man/doi/man6x", + "/usr/share/man/doi/man7", + "/usr/share/man/doi/man7x", + "/usr/share/man/doi/man8", + "/usr/share/man/doi/man8x", + "/usr/share/man/doi/man9", + "/usr/share/man/doi/man9x", + "/usr/share/man/doi/mann", + "/usr/share/man/dra", + "/usr/share/man/dra/man0p", + "/usr/share/man/dra/man1", + "/usr/share/man/dra/man1p", + "/usr/share/man/dra/man1x", + "/usr/share/man/dra/man2", + "/usr/share/man/dra/man2x", + "/usr/share/man/dra/man3", + "/usr/share/man/dra/man3p", + "/usr/share/man/dra/man3x", + "/usr/share/man/dra/man4", + "/usr/share/man/dra/man4x", + "/usr/share/man/dra/man5", + "/usr/share/man/dra/man5x", + "/usr/share/man/dra/man6", + "/usr/share/man/dra/man6x", + "/usr/share/man/dra/man7", + "/usr/share/man/dra/man7x", + "/usr/share/man/dra/man8", + "/usr/share/man/dra/man8x", + "/usr/share/man/dra/man9", + "/usr/share/man/dra/man9x", + "/usr/share/man/dra/mann", + "/usr/share/man/dsb", + "/usr/share/man/dsb/man0p", + "/usr/share/man/dsb/man1", + "/usr/share/man/dsb/man1p", + "/usr/share/man/dsb/man1x", + "/usr/share/man/dsb/man2", + "/usr/share/man/dsb/man2x", + "/usr/share/man/dsb/man3", + "/usr/share/man/dsb/man3p", + "/usr/share/man/dsb/man3x", + "/usr/share/man/dsb/man4", + "/usr/share/man/dsb/man4x", + "/usr/share/man/dsb/man5", + "/usr/share/man/dsb/man5x", + "/usr/share/man/dsb/man6", + "/usr/share/man/dsb/man6x", + "/usr/share/man/dsb/man7", + "/usr/share/man/dsb/man7x", + "/usr/share/man/dsb/man8", + "/usr/share/man/dsb/man8x", + "/usr/share/man/dsb/man9", + "/usr/share/man/dsb/man9x", + "/usr/share/man/dsb/mann", + "/usr/share/man/dua", + "/usr/share/man/dua/man0p", + "/usr/share/man/dua/man1", + "/usr/share/man/dua/man1p", + "/usr/share/man/dua/man1x", + "/usr/share/man/dua/man2", + "/usr/share/man/dua/man2x", + "/usr/share/man/dua/man3", + "/usr/share/man/dua/man3p", + "/usr/share/man/dua/man3x", + "/usr/share/man/dua/man4", + "/usr/share/man/dua/man4x", + "/usr/share/man/dua/man5", + "/usr/share/man/dua/man5x", + "/usr/share/man/dua/man6", + "/usr/share/man/dua/man6x", + "/usr/share/man/dua/man7", + "/usr/share/man/dua/man7x", + "/usr/share/man/dua/man8", + "/usr/share/man/dua/man8x", + "/usr/share/man/dua/man9", + "/usr/share/man/dua/man9x", + "/usr/share/man/dua/mann", + "/usr/share/man/dum", + "/usr/share/man/dum/man0p", + "/usr/share/man/dum/man1", + "/usr/share/man/dum/man1p", + "/usr/share/man/dum/man1x", + "/usr/share/man/dum/man2", + "/usr/share/man/dum/man2x", + "/usr/share/man/dum/man3", + "/usr/share/man/dum/man3p", + "/usr/share/man/dum/man3x", + "/usr/share/man/dum/man4", + "/usr/share/man/dum/man4x", + "/usr/share/man/dum/man5", + "/usr/share/man/dum/man5x", + "/usr/share/man/dum/man6", + "/usr/share/man/dum/man6x", + "/usr/share/man/dum/man7", + "/usr/share/man/dum/man7x", + "/usr/share/man/dum/man8", + "/usr/share/man/dum/man8x", + "/usr/share/man/dum/man9", + "/usr/share/man/dum/man9x", + "/usr/share/man/dum/mann", + "/usr/share/man/dv", + "/usr/share/man/dv/man0p", + "/usr/share/man/dv/man1", + "/usr/share/man/dv/man1p", + "/usr/share/man/dv/man1x", + "/usr/share/man/dv/man2", + "/usr/share/man/dv/man2x", + "/usr/share/man/dv/man3", + "/usr/share/man/dv/man3p", + "/usr/share/man/dv/man3x", + "/usr/share/man/dv/man4", + "/usr/share/man/dv/man4x", + "/usr/share/man/dv/man5", + "/usr/share/man/dv/man5x", + "/usr/share/man/dv/man6", + "/usr/share/man/dv/man6x", + "/usr/share/man/dv/man7", + "/usr/share/man/dv/man7x", + "/usr/share/man/dv/man8", + "/usr/share/man/dv/man8x", + "/usr/share/man/dv/man9", + "/usr/share/man/dv/man9x", + "/usr/share/man/dv/mann", + "/usr/share/man/dyu", + "/usr/share/man/dyu/man0p", + "/usr/share/man/dyu/man1", + "/usr/share/man/dyu/man1p", + "/usr/share/man/dyu/man1x", + "/usr/share/man/dyu/man2", + "/usr/share/man/dyu/man2x", + "/usr/share/man/dyu/man3", + "/usr/share/man/dyu/man3p", + "/usr/share/man/dyu/man3x", + "/usr/share/man/dyu/man4", + "/usr/share/man/dyu/man4x", + "/usr/share/man/dyu/man5", + "/usr/share/man/dyu/man5x", + "/usr/share/man/dyu/man6", + "/usr/share/man/dyu/man6x", + "/usr/share/man/dyu/man7", + "/usr/share/man/dyu/man7x", + "/usr/share/man/dyu/man8", + "/usr/share/man/dyu/man8x", + "/usr/share/man/dyu/man9", + "/usr/share/man/dyu/man9x", + "/usr/share/man/dyu/mann", + "/usr/share/man/dz", + "/usr/share/man/dz/man0p", + "/usr/share/man/dz/man1", + "/usr/share/man/dz/man1p", + "/usr/share/man/dz/man1x", + "/usr/share/man/dz/man2", + "/usr/share/man/dz/man2x", + "/usr/share/man/dz/man3", + "/usr/share/man/dz/man3p", + "/usr/share/man/dz/man3x", + "/usr/share/man/dz/man4", + "/usr/share/man/dz/man4x", + "/usr/share/man/dz/man5", + "/usr/share/man/dz/man5x", + "/usr/share/man/dz/man6", + "/usr/share/man/dz/man6x", + "/usr/share/man/dz/man7", + "/usr/share/man/dz/man7x", + "/usr/share/man/dz/man8", + "/usr/share/man/dz/man8x", + "/usr/share/man/dz/man9", + "/usr/share/man/dz/man9x", + "/usr/share/man/dz/mann", + "/usr/share/man/ee", + "/usr/share/man/ee/man0p", + "/usr/share/man/ee/man1", + "/usr/share/man/ee/man1p", + "/usr/share/man/ee/man1x", + "/usr/share/man/ee/man2", + "/usr/share/man/ee/man2x", + "/usr/share/man/ee/man3", + "/usr/share/man/ee/man3p", + "/usr/share/man/ee/man3x", + "/usr/share/man/ee/man4", + "/usr/share/man/ee/man4x", + "/usr/share/man/ee/man5", + "/usr/share/man/ee/man5x", + "/usr/share/man/ee/man6", + "/usr/share/man/ee/man6x", + "/usr/share/man/ee/man7", + "/usr/share/man/ee/man7x", + "/usr/share/man/ee/man8", + "/usr/share/man/ee/man8x", + "/usr/share/man/ee/man9", + "/usr/share/man/ee/man9x", + "/usr/share/man/ee/mann", + "/usr/share/man/efi", + "/usr/share/man/efi/man0p", + "/usr/share/man/efi/man1", + "/usr/share/man/efi/man1p", + "/usr/share/man/efi/man1x", + "/usr/share/man/efi/man2", + "/usr/share/man/efi/man2x", + "/usr/share/man/efi/man3", + "/usr/share/man/efi/man3p", + "/usr/share/man/efi/man3x", + "/usr/share/man/efi/man4", + "/usr/share/man/efi/man4x", + "/usr/share/man/efi/man5", + "/usr/share/man/efi/man5x", + "/usr/share/man/efi/man6", + "/usr/share/man/efi/man6x", + "/usr/share/man/efi/man7", + "/usr/share/man/efi/man7x", + "/usr/share/man/efi/man8", + "/usr/share/man/efi/man8x", + "/usr/share/man/efi/man9", + "/usr/share/man/efi/man9x", + "/usr/share/man/efi/mann", + "/usr/share/man/egy", + "/usr/share/man/egy/man0p", + "/usr/share/man/egy/man1", + "/usr/share/man/egy/man1p", + "/usr/share/man/egy/man1x", + "/usr/share/man/egy/man2", + "/usr/share/man/egy/man2x", + "/usr/share/man/egy/man3", + "/usr/share/man/egy/man3p", + "/usr/share/man/egy/man3x", + "/usr/share/man/egy/man4", + "/usr/share/man/egy/man4x", + "/usr/share/man/egy/man5", + "/usr/share/man/egy/man5x", + "/usr/share/man/egy/man6", + "/usr/share/man/egy/man6x", + "/usr/share/man/egy/man7", + "/usr/share/man/egy/man7x", + "/usr/share/man/egy/man8", + "/usr/share/man/egy/man8x", + "/usr/share/man/egy/man9", + "/usr/share/man/egy/man9x", + "/usr/share/man/egy/mann", + "/usr/share/man/eka", + "/usr/share/man/eka/man0p", + "/usr/share/man/eka/man1", + "/usr/share/man/eka/man1p", + "/usr/share/man/eka/man1x", + "/usr/share/man/eka/man2", + "/usr/share/man/eka/man2x", + "/usr/share/man/eka/man3", + "/usr/share/man/eka/man3p", + "/usr/share/man/eka/man3x", + "/usr/share/man/eka/man4", + "/usr/share/man/eka/man4x", + "/usr/share/man/eka/man5", + "/usr/share/man/eka/man5x", + "/usr/share/man/eka/man6", + "/usr/share/man/eka/man6x", + "/usr/share/man/eka/man7", + "/usr/share/man/eka/man7x", + "/usr/share/man/eka/man8", + "/usr/share/man/eka/man8x", + "/usr/share/man/eka/man9", + "/usr/share/man/eka/man9x", + "/usr/share/man/eka/mann", + "/usr/share/man/el", + "/usr/share/man/el/man0p", + "/usr/share/man/el/man1", + "/usr/share/man/el/man1p", + "/usr/share/man/el/man1x", + "/usr/share/man/el/man2", + "/usr/share/man/el/man2x", + "/usr/share/man/el/man3", + "/usr/share/man/el/man3p", + "/usr/share/man/el/man3x", + "/usr/share/man/el/man4", + "/usr/share/man/el/man4x", + "/usr/share/man/el/man5", + "/usr/share/man/el/man5x", + "/usr/share/man/el/man6", + "/usr/share/man/el/man6x", + "/usr/share/man/el/man7", + "/usr/share/man/el/man7x", + "/usr/share/man/el/man8", + "/usr/share/man/el/man8x", + "/usr/share/man/el/man9", + "/usr/share/man/el/man9x", + "/usr/share/man/el/mann", + "/usr/share/man/el_GR", + "/usr/share/man/el_GR/man0p", + "/usr/share/man/el_GR/man1", + "/usr/share/man/el_GR/man1p", + "/usr/share/man/el_GR/man1x", + "/usr/share/man/el_GR/man2", + "/usr/share/man/el_GR/man2x", + "/usr/share/man/el_GR/man3", + "/usr/share/man/el_GR/man3p", + "/usr/share/man/el_GR/man3x", + "/usr/share/man/el_GR/man4", + "/usr/share/man/el_GR/man4x", + "/usr/share/man/el_GR/man5", + "/usr/share/man/el_GR/man5x", + "/usr/share/man/el_GR/man6", + "/usr/share/man/el_GR/man6x", + "/usr/share/man/el_GR/man7", + "/usr/share/man/el_GR/man7x", + "/usr/share/man/el_GR/man8", + "/usr/share/man/el_GR/man8x", + "/usr/share/man/el_GR/man9", + "/usr/share/man/el_GR/man9x", + "/usr/share/man/el_GR/mann", + "/usr/share/man/elx", + "/usr/share/man/elx/man0p", + "/usr/share/man/elx/man1", + "/usr/share/man/elx/man1p", + "/usr/share/man/elx/man1x", + "/usr/share/man/elx/man2", + "/usr/share/man/elx/man2x", + "/usr/share/man/elx/man3", + "/usr/share/man/elx/man3p", + "/usr/share/man/elx/man3x", + "/usr/share/man/elx/man4", + "/usr/share/man/elx/man4x", + "/usr/share/man/elx/man5", + "/usr/share/man/elx/man5x", + "/usr/share/man/elx/man6", + "/usr/share/man/elx/man6x", + "/usr/share/man/elx/man7", + "/usr/share/man/elx/man7x", + "/usr/share/man/elx/man8", + "/usr/share/man/elx/man8x", + "/usr/share/man/elx/man9", + "/usr/share/man/elx/man9x", + "/usr/share/man/elx/mann", + "/usr/share/man/en", + "/usr/share/man/en/man0p", + "/usr/share/man/en/man1", + "/usr/share/man/en/man1p", + "/usr/share/man/en/man1x", + "/usr/share/man/en/man2", + "/usr/share/man/en/man2x", + "/usr/share/man/en/man3", + "/usr/share/man/en/man3p", + "/usr/share/man/en/man3x", + "/usr/share/man/en/man4", + "/usr/share/man/en/man4x", + "/usr/share/man/en/man5", + "/usr/share/man/en/man5x", + "/usr/share/man/en/man6", + "/usr/share/man/en/man6x", + "/usr/share/man/en/man7", + "/usr/share/man/en/man7x", + "/usr/share/man/en/man8", + "/usr/share/man/en/man8x", + "/usr/share/man/en/man9", + "/usr/share/man/en/man9x", + "/usr/share/man/en/mann", + "/usr/share/man/en@arabic", + "/usr/share/man/en@arabic/man0p", + "/usr/share/man/en@arabic/man1", + "/usr/share/man/en@arabic/man1p", + "/usr/share/man/en@arabic/man1x", + "/usr/share/man/en@arabic/man2", + "/usr/share/man/en@arabic/man2x", + "/usr/share/man/en@arabic/man3", + "/usr/share/man/en@arabic/man3p", + "/usr/share/man/en@arabic/man3x", + "/usr/share/man/en@arabic/man4", + "/usr/share/man/en@arabic/man4x", + "/usr/share/man/en@arabic/man5", + "/usr/share/man/en@arabic/man5x", + "/usr/share/man/en@arabic/man6", + "/usr/share/man/en@arabic/man6x", + "/usr/share/man/en@arabic/man7", + "/usr/share/man/en@arabic/man7x", + "/usr/share/man/en@arabic/man8", + "/usr/share/man/en@arabic/man8x", + "/usr/share/man/en@arabic/man9", + "/usr/share/man/en@arabic/man9x", + "/usr/share/man/en@arabic/mann", + "/usr/share/man/en@boldquot", + "/usr/share/man/en@boldquot/man0p", + "/usr/share/man/en@boldquot/man1", + "/usr/share/man/en@boldquot/man1p", + "/usr/share/man/en@boldquot/man1x", + "/usr/share/man/en@boldquot/man2", + "/usr/share/man/en@boldquot/man2x", + "/usr/share/man/en@boldquot/man3", + "/usr/share/man/en@boldquot/man3p", + "/usr/share/man/en@boldquot/man3x", + "/usr/share/man/en@boldquot/man4", + "/usr/share/man/en@boldquot/man4x", + "/usr/share/man/en@boldquot/man5", + "/usr/share/man/en@boldquot/man5x", + "/usr/share/man/en@boldquot/man6", + "/usr/share/man/en@boldquot/man6x", + "/usr/share/man/en@boldquot/man7", + "/usr/share/man/en@boldquot/man7x", + "/usr/share/man/en@boldquot/man8", + "/usr/share/man/en@boldquot/man8x", + "/usr/share/man/en@boldquot/man9", + "/usr/share/man/en@boldquot/man9x", + "/usr/share/man/en@boldquot/mann", + "/usr/share/man/en@cyrillic", + "/usr/share/man/en@cyrillic/man0p", + "/usr/share/man/en@cyrillic/man1", + "/usr/share/man/en@cyrillic/man1p", + "/usr/share/man/en@cyrillic/man1x", + "/usr/share/man/en@cyrillic/man2", + "/usr/share/man/en@cyrillic/man2x", + "/usr/share/man/en@cyrillic/man3", + "/usr/share/man/en@cyrillic/man3p", + "/usr/share/man/en@cyrillic/man3x", + "/usr/share/man/en@cyrillic/man4", + "/usr/share/man/en@cyrillic/man4x", + "/usr/share/man/en@cyrillic/man5", + "/usr/share/man/en@cyrillic/man5x", + "/usr/share/man/en@cyrillic/man6", + "/usr/share/man/en@cyrillic/man6x", + "/usr/share/man/en@cyrillic/man7", + "/usr/share/man/en@cyrillic/man7x", + "/usr/share/man/en@cyrillic/man8", + "/usr/share/man/en@cyrillic/man8x", + "/usr/share/man/en@cyrillic/man9", + "/usr/share/man/en@cyrillic/man9x", + "/usr/share/man/en@cyrillic/mann", + "/usr/share/man/en@greek", + "/usr/share/man/en@greek/man0p", + "/usr/share/man/en@greek/man1", + "/usr/share/man/en@greek/man1p", + "/usr/share/man/en@greek/man1x", + "/usr/share/man/en@greek/man2", + "/usr/share/man/en@greek/man2x", + "/usr/share/man/en@greek/man3", + "/usr/share/man/en@greek/man3p", + "/usr/share/man/en@greek/man3x", + "/usr/share/man/en@greek/man4", + "/usr/share/man/en@greek/man4x", + "/usr/share/man/en@greek/man5", + "/usr/share/man/en@greek/man5x", + "/usr/share/man/en@greek/man6", + "/usr/share/man/en@greek/man6x", + "/usr/share/man/en@greek/man7", + "/usr/share/man/en@greek/man7x", + "/usr/share/man/en@greek/man8", + "/usr/share/man/en@greek/man8x", + "/usr/share/man/en@greek/man9", + "/usr/share/man/en@greek/man9x", + "/usr/share/man/en@greek/mann", + "/usr/share/man/en@hebrew", + "/usr/share/man/en@hebrew/man0p", + "/usr/share/man/en@hebrew/man1", + "/usr/share/man/en@hebrew/man1p", + "/usr/share/man/en@hebrew/man1x", + "/usr/share/man/en@hebrew/man2", + "/usr/share/man/en@hebrew/man2x", + "/usr/share/man/en@hebrew/man3", + "/usr/share/man/en@hebrew/man3p", + "/usr/share/man/en@hebrew/man3x", + "/usr/share/man/en@hebrew/man4", + "/usr/share/man/en@hebrew/man4x", + "/usr/share/man/en@hebrew/man5", + "/usr/share/man/en@hebrew/man5x", + "/usr/share/man/en@hebrew/man6", + "/usr/share/man/en@hebrew/man6x", + "/usr/share/man/en@hebrew/man7", + "/usr/share/man/en@hebrew/man7x", + "/usr/share/man/en@hebrew/man8", + "/usr/share/man/en@hebrew/man8x", + "/usr/share/man/en@hebrew/man9", + "/usr/share/man/en@hebrew/man9x", + "/usr/share/man/en@hebrew/mann", + "/usr/share/man/en@piglatin", + "/usr/share/man/en@piglatin/man0p", + "/usr/share/man/en@piglatin/man1", + "/usr/share/man/en@piglatin/man1p", + "/usr/share/man/en@piglatin/man1x", + "/usr/share/man/en@piglatin/man2", + "/usr/share/man/en@piglatin/man2x", + "/usr/share/man/en@piglatin/man3", + "/usr/share/man/en@piglatin/man3p", + "/usr/share/man/en@piglatin/man3x", + "/usr/share/man/en@piglatin/man4", + "/usr/share/man/en@piglatin/man4x", + "/usr/share/man/en@piglatin/man5", + "/usr/share/man/en@piglatin/man5x", + "/usr/share/man/en@piglatin/man6", + "/usr/share/man/en@piglatin/man6x", + "/usr/share/man/en@piglatin/man7", + "/usr/share/man/en@piglatin/man7x", + "/usr/share/man/en@piglatin/man8", + "/usr/share/man/en@piglatin/man8x", + "/usr/share/man/en@piglatin/man9", + "/usr/share/man/en@piglatin/man9x", + "/usr/share/man/en@piglatin/mann", + "/usr/share/man/en@quot", + "/usr/share/man/en@quot/man0p", + "/usr/share/man/en@quot/man1", + "/usr/share/man/en@quot/man1p", + "/usr/share/man/en@quot/man1x", + "/usr/share/man/en@quot/man2", + "/usr/share/man/en@quot/man2x", + "/usr/share/man/en@quot/man3", + "/usr/share/man/en@quot/man3p", + "/usr/share/man/en@quot/man3x", + "/usr/share/man/en@quot/man4", + "/usr/share/man/en@quot/man4x", + "/usr/share/man/en@quot/man5", + "/usr/share/man/en@quot/man5x", + "/usr/share/man/en@quot/man6", + "/usr/share/man/en@quot/man6x", + "/usr/share/man/en@quot/man7", + "/usr/share/man/en@quot/man7x", + "/usr/share/man/en@quot/man8", + "/usr/share/man/en@quot/man8x", + "/usr/share/man/en@quot/man9", + "/usr/share/man/en@quot/man9x", + "/usr/share/man/en@quot/mann", + "/usr/share/man/en@shaw", + "/usr/share/man/en@shaw/man0p", + "/usr/share/man/en@shaw/man1", + "/usr/share/man/en@shaw/man1p", + "/usr/share/man/en@shaw/man1x", + "/usr/share/man/en@shaw/man2", + "/usr/share/man/en@shaw/man2x", + "/usr/share/man/en@shaw/man3", + "/usr/share/man/en@shaw/man3p", + "/usr/share/man/en@shaw/man3x", + "/usr/share/man/en@shaw/man4", + "/usr/share/man/en@shaw/man4x", + "/usr/share/man/en@shaw/man5", + "/usr/share/man/en@shaw/man5x", + "/usr/share/man/en@shaw/man6", + "/usr/share/man/en@shaw/man6x", + "/usr/share/man/en@shaw/man7", + "/usr/share/man/en@shaw/man7x", + "/usr/share/man/en@shaw/man8", + "/usr/share/man/en@shaw/man8x", + "/usr/share/man/en@shaw/man9", + "/usr/share/man/en@shaw/man9x", + "/usr/share/man/en@shaw/mann", + "/usr/share/man/en_AU", + "/usr/share/man/en_AU/man0p", + "/usr/share/man/en_AU/man1", + "/usr/share/man/en_AU/man1p", + "/usr/share/man/en_AU/man1x", + "/usr/share/man/en_AU/man2", + "/usr/share/man/en_AU/man2x", + "/usr/share/man/en_AU/man3", + "/usr/share/man/en_AU/man3p", + "/usr/share/man/en_AU/man3x", + "/usr/share/man/en_AU/man4", + "/usr/share/man/en_AU/man4x", + "/usr/share/man/en_AU/man5", + "/usr/share/man/en_AU/man5x", + "/usr/share/man/en_AU/man6", + "/usr/share/man/en_AU/man6x", + "/usr/share/man/en_AU/man7", + "/usr/share/man/en_AU/man7x", + "/usr/share/man/en_AU/man8", + "/usr/share/man/en_AU/man8x", + "/usr/share/man/en_AU/man9", + "/usr/share/man/en_AU/man9x", + "/usr/share/man/en_AU/mann", + "/usr/share/man/en_CA", + "/usr/share/man/en_CA/man0p", + "/usr/share/man/en_CA/man1", + "/usr/share/man/en_CA/man1p", + "/usr/share/man/en_CA/man1x", + "/usr/share/man/en_CA/man2", + "/usr/share/man/en_CA/man2x", + "/usr/share/man/en_CA/man3", + "/usr/share/man/en_CA/man3p", + "/usr/share/man/en_CA/man3x", + "/usr/share/man/en_CA/man4", + "/usr/share/man/en_CA/man4x", + "/usr/share/man/en_CA/man5", + "/usr/share/man/en_CA/man5x", + "/usr/share/man/en_CA/man6", + "/usr/share/man/en_CA/man6x", + "/usr/share/man/en_CA/man7", + "/usr/share/man/en_CA/man7x", + "/usr/share/man/en_CA/man8", + "/usr/share/man/en_CA/man8x", + "/usr/share/man/en_CA/man9", + "/usr/share/man/en_CA/man9x", + "/usr/share/man/en_CA/mann", + "/usr/share/man/en_CZ", + "/usr/share/man/en_CZ/man0p", + "/usr/share/man/en_CZ/man1", + "/usr/share/man/en_CZ/man1p", + "/usr/share/man/en_CZ/man1x", + "/usr/share/man/en_CZ/man2", + "/usr/share/man/en_CZ/man2x", + "/usr/share/man/en_CZ/man3", + "/usr/share/man/en_CZ/man3p", + "/usr/share/man/en_CZ/man3x", + "/usr/share/man/en_CZ/man4", + "/usr/share/man/en_CZ/man4x", + "/usr/share/man/en_CZ/man5", + "/usr/share/man/en_CZ/man5x", + "/usr/share/man/en_CZ/man6", + "/usr/share/man/en_CZ/man6x", + "/usr/share/man/en_CZ/man7", + "/usr/share/man/en_CZ/man7x", + "/usr/share/man/en_CZ/man8", + "/usr/share/man/en_CZ/man8x", + "/usr/share/man/en_CZ/man9", + "/usr/share/man/en_CZ/man9x", + "/usr/share/man/en_CZ/mann", + "/usr/share/man/en_GB", + "/usr/share/man/en_GB/man0p", + "/usr/share/man/en_GB/man1", + "/usr/share/man/en_GB/man1p", + "/usr/share/man/en_GB/man1x", + "/usr/share/man/en_GB/man2", + "/usr/share/man/en_GB/man2x", + "/usr/share/man/en_GB/man3", + "/usr/share/man/en_GB/man3p", + "/usr/share/man/en_GB/man3x", + "/usr/share/man/en_GB/man4", + "/usr/share/man/en_GB/man4x", + "/usr/share/man/en_GB/man5", + "/usr/share/man/en_GB/man5x", + "/usr/share/man/en_GB/man6", + "/usr/share/man/en_GB/man6x", + "/usr/share/man/en_GB/man7", + "/usr/share/man/en_GB/man7x", + "/usr/share/man/en_GB/man8", + "/usr/share/man/en_GB/man8x", + "/usr/share/man/en_GB/man9", + "/usr/share/man/en_GB/man9x", + "/usr/share/man/en_GB/mann", + "/usr/share/man/en_IE", + "/usr/share/man/en_IE/man0p", + "/usr/share/man/en_IE/man1", + "/usr/share/man/en_IE/man1p", + "/usr/share/man/en_IE/man1x", + "/usr/share/man/en_IE/man2", + "/usr/share/man/en_IE/man2x", + "/usr/share/man/en_IE/man3", + "/usr/share/man/en_IE/man3p", + "/usr/share/man/en_IE/man3x", + "/usr/share/man/en_IE/man4", + "/usr/share/man/en_IE/man4x", + "/usr/share/man/en_IE/man5", + "/usr/share/man/en_IE/man5x", + "/usr/share/man/en_IE/man6", + "/usr/share/man/en_IE/man6x", + "/usr/share/man/en_IE/man7", + "/usr/share/man/en_IE/man7x", + "/usr/share/man/en_IE/man8", + "/usr/share/man/en_IE/man8x", + "/usr/share/man/en_IE/man9", + "/usr/share/man/en_IE/man9x", + "/usr/share/man/en_IE/mann", + "/usr/share/man/en_NZ", + "/usr/share/man/en_NZ/man0p", + "/usr/share/man/en_NZ/man1", + "/usr/share/man/en_NZ/man1p", + "/usr/share/man/en_NZ/man1x", + "/usr/share/man/en_NZ/man2", + "/usr/share/man/en_NZ/man2x", + "/usr/share/man/en_NZ/man3", + "/usr/share/man/en_NZ/man3p", + "/usr/share/man/en_NZ/man3x", + "/usr/share/man/en_NZ/man4", + "/usr/share/man/en_NZ/man4x", + "/usr/share/man/en_NZ/man5", + "/usr/share/man/en_NZ/man5x", + "/usr/share/man/en_NZ/man6", + "/usr/share/man/en_NZ/man6x", + "/usr/share/man/en_NZ/man7", + "/usr/share/man/en_NZ/man7x", + "/usr/share/man/en_NZ/man8", + "/usr/share/man/en_NZ/man8x", + "/usr/share/man/en_NZ/man9", + "/usr/share/man/en_NZ/man9x", + "/usr/share/man/en_NZ/mann", + "/usr/share/man/en_US", + "/usr/share/man/en_US/man0p", + "/usr/share/man/en_US/man1", + "/usr/share/man/en_US/man1p", + "/usr/share/man/en_US/man1x", + "/usr/share/man/en_US/man2", + "/usr/share/man/en_US/man2x", + "/usr/share/man/en_US/man3", + "/usr/share/man/en_US/man3p", + "/usr/share/man/en_US/man3x", + "/usr/share/man/en_US/man4", + "/usr/share/man/en_US/man4x", + "/usr/share/man/en_US/man5", + "/usr/share/man/en_US/man5x", + "/usr/share/man/en_US/man6", + "/usr/share/man/en_US/man6x", + "/usr/share/man/en_US/man7", + "/usr/share/man/en_US/man7x", + "/usr/share/man/en_US/man8", + "/usr/share/man/en_US/man8x", + "/usr/share/man/en_US/man9", + "/usr/share/man/en_US/man9x", + "/usr/share/man/en_US/mann", + "/usr/share/man/en_US@piglatin", + "/usr/share/man/en_US@piglatin/man0p", + "/usr/share/man/en_US@piglatin/man1", + "/usr/share/man/en_US@piglatin/man1p", + "/usr/share/man/en_US@piglatin/man1x", + "/usr/share/man/en_US@piglatin/man2", + "/usr/share/man/en_US@piglatin/man2x", + "/usr/share/man/en_US@piglatin/man3", + "/usr/share/man/en_US@piglatin/man3p", + "/usr/share/man/en_US@piglatin/man3x", + "/usr/share/man/en_US@piglatin/man4", + "/usr/share/man/en_US@piglatin/man4x", + "/usr/share/man/en_US@piglatin/man5", + "/usr/share/man/en_US@piglatin/man5x", + "/usr/share/man/en_US@piglatin/man6", + "/usr/share/man/en_US@piglatin/man6x", + "/usr/share/man/en_US@piglatin/man7", + "/usr/share/man/en_US@piglatin/man7x", + "/usr/share/man/en_US@piglatin/man8", + "/usr/share/man/en_US@piglatin/man8x", + "/usr/share/man/en_US@piglatin/man9", + "/usr/share/man/en_US@piglatin/man9x", + "/usr/share/man/en_US@piglatin/mann", + "/usr/share/man/en_ZA", + "/usr/share/man/en_ZA/man0p", + "/usr/share/man/en_ZA/man1", + "/usr/share/man/en_ZA/man1p", + "/usr/share/man/en_ZA/man1x", + "/usr/share/man/en_ZA/man2", + "/usr/share/man/en_ZA/man2x", + "/usr/share/man/en_ZA/man3", + "/usr/share/man/en_ZA/man3p", + "/usr/share/man/en_ZA/man3x", + "/usr/share/man/en_ZA/man4", + "/usr/share/man/en_ZA/man4x", + "/usr/share/man/en_ZA/man5", + "/usr/share/man/en_ZA/man5x", + "/usr/share/man/en_ZA/man6", + "/usr/share/man/en_ZA/man6x", + "/usr/share/man/en_ZA/man7", + "/usr/share/man/en_ZA/man7x", + "/usr/share/man/en_ZA/man8", + "/usr/share/man/en_ZA/man8x", + "/usr/share/man/en_ZA/man9", + "/usr/share/man/en_ZA/man9x", + "/usr/share/man/en_ZA/mann", + "/usr/share/man/enm", + "/usr/share/man/enm/man0p", + "/usr/share/man/enm/man1", + "/usr/share/man/enm/man1p", + "/usr/share/man/enm/man1x", + "/usr/share/man/enm/man2", + "/usr/share/man/enm/man2x", + "/usr/share/man/enm/man3", + "/usr/share/man/enm/man3p", + "/usr/share/man/enm/man3x", + "/usr/share/man/enm/man4", + "/usr/share/man/enm/man4x", + "/usr/share/man/enm/man5", + "/usr/share/man/enm/man5x", + "/usr/share/man/enm/man6", + "/usr/share/man/enm/man6x", + "/usr/share/man/enm/man7", + "/usr/share/man/enm/man7x", + "/usr/share/man/enm/man8", + "/usr/share/man/enm/man8x", + "/usr/share/man/enm/man9", + "/usr/share/man/enm/man9x", + "/usr/share/man/enm/mann", + "/usr/share/man/eo", + "/usr/share/man/eo/man0p", + "/usr/share/man/eo/man1", + "/usr/share/man/eo/man1p", + "/usr/share/man/eo/man1x", + "/usr/share/man/eo/man2", + "/usr/share/man/eo/man2x", + "/usr/share/man/eo/man3", + "/usr/share/man/eo/man3p", + "/usr/share/man/eo/man3x", + "/usr/share/man/eo/man4", + "/usr/share/man/eo/man4x", + "/usr/share/man/eo/man5", + "/usr/share/man/eo/man5x", + "/usr/share/man/eo/man6", + "/usr/share/man/eo/man6x", + "/usr/share/man/eo/man7", + "/usr/share/man/eo/man7x", + "/usr/share/man/eo/man8", + "/usr/share/man/eo/man8x", + "/usr/share/man/eo/man9", + "/usr/share/man/eo/man9x", + "/usr/share/man/eo/mann", + "/usr/share/man/es", + "/usr/share/man/es.us-ascii", + "/usr/share/man/es.us-ascii/man0p", + "/usr/share/man/es.us-ascii/man1", + "/usr/share/man/es.us-ascii/man1p", + "/usr/share/man/es.us-ascii/man1x", + "/usr/share/man/es.us-ascii/man2", + "/usr/share/man/es.us-ascii/man2x", + "/usr/share/man/es.us-ascii/man3", + "/usr/share/man/es.us-ascii/man3p", + "/usr/share/man/es.us-ascii/man3x", + "/usr/share/man/es.us-ascii/man4", + "/usr/share/man/es.us-ascii/man4x", + "/usr/share/man/es.us-ascii/man5", + "/usr/share/man/es.us-ascii/man5x", + "/usr/share/man/es.us-ascii/man6", + "/usr/share/man/es.us-ascii/man6x", + "/usr/share/man/es.us-ascii/man7", + "/usr/share/man/es.us-ascii/man7x", + "/usr/share/man/es.us-ascii/man8", + "/usr/share/man/es.us-ascii/man8x", + "/usr/share/man/es.us-ascii/man9", + "/usr/share/man/es.us-ascii/man9x", + "/usr/share/man/es.us-ascii/mann", + "/usr/share/man/es/man0p", + "/usr/share/man/es/man1", + "/usr/share/man/es/man1p", + "/usr/share/man/es/man1x", + "/usr/share/man/es/man2", + "/usr/share/man/es/man2x", + "/usr/share/man/es/man3", + "/usr/share/man/es/man3p", + "/usr/share/man/es/man3x", + "/usr/share/man/es/man4", + "/usr/share/man/es/man4x", + "/usr/share/man/es/man5", + "/usr/share/man/es/man5x", + "/usr/share/man/es/man6", + "/usr/share/man/es/man6x", + "/usr/share/man/es/man7", + "/usr/share/man/es/man7x", + "/usr/share/man/es/man8", + "/usr/share/man/es/man8x", + "/usr/share/man/es/man9", + "/usr/share/man/es/man9x", + "/usr/share/man/es/mann", + "/usr/share/man/es_AR", + "/usr/share/man/es_AR/man0p", + "/usr/share/man/es_AR/man1", + "/usr/share/man/es_AR/man1p", + "/usr/share/man/es_AR/man1x", + "/usr/share/man/es_AR/man2", + "/usr/share/man/es_AR/man2x", + "/usr/share/man/es_AR/man3", + "/usr/share/man/es_AR/man3p", + "/usr/share/man/es_AR/man3x", + "/usr/share/man/es_AR/man4", + "/usr/share/man/es_AR/man4x", + "/usr/share/man/es_AR/man5", + "/usr/share/man/es_AR/man5x", + "/usr/share/man/es_AR/man6", + "/usr/share/man/es_AR/man6x", + "/usr/share/man/es_AR/man7", + "/usr/share/man/es_AR/man7x", + "/usr/share/man/es_AR/man8", + "/usr/share/man/es_AR/man8x", + "/usr/share/man/es_AR/man9", + "/usr/share/man/es_AR/man9x", + "/usr/share/man/es_AR/mann", + "/usr/share/man/es_CL", + "/usr/share/man/es_CL/man0p", + "/usr/share/man/es_CL/man1", + "/usr/share/man/es_CL/man1p", + "/usr/share/man/es_CL/man1x", + "/usr/share/man/es_CL/man2", + "/usr/share/man/es_CL/man2x", + "/usr/share/man/es_CL/man3", + "/usr/share/man/es_CL/man3p", + "/usr/share/man/es_CL/man3x", + "/usr/share/man/es_CL/man4", + "/usr/share/man/es_CL/man4x", + "/usr/share/man/es_CL/man5", + "/usr/share/man/es_CL/man5x", + "/usr/share/man/es_CL/man6", + "/usr/share/man/es_CL/man6x", + "/usr/share/man/es_CL/man7", + "/usr/share/man/es_CL/man7x", + "/usr/share/man/es_CL/man8", + "/usr/share/man/es_CL/man8x", + "/usr/share/man/es_CL/man9", + "/usr/share/man/es_CL/man9x", + "/usr/share/man/es_CL/mann", + "/usr/share/man/es_CO", + "/usr/share/man/es_CO/man0p", + "/usr/share/man/es_CO/man1", + "/usr/share/man/es_CO/man1p", + "/usr/share/man/es_CO/man1x", + "/usr/share/man/es_CO/man2", + "/usr/share/man/es_CO/man2x", + "/usr/share/man/es_CO/man3", + "/usr/share/man/es_CO/man3p", + "/usr/share/man/es_CO/man3x", + "/usr/share/man/es_CO/man4", + "/usr/share/man/es_CO/man4x", + "/usr/share/man/es_CO/man5", + "/usr/share/man/es_CO/man5x", + "/usr/share/man/es_CO/man6", + "/usr/share/man/es_CO/man6x", + "/usr/share/man/es_CO/man7", + "/usr/share/man/es_CO/man7x", + "/usr/share/man/es_CO/man8", + "/usr/share/man/es_CO/man8x", + "/usr/share/man/es_CO/man9", + "/usr/share/man/es_CO/man9x", + "/usr/share/man/es_CO/mann", + "/usr/share/man/es_CR", + "/usr/share/man/es_CR/man0p", + "/usr/share/man/es_CR/man1", + "/usr/share/man/es_CR/man1p", + "/usr/share/man/es_CR/man1x", + "/usr/share/man/es_CR/man2", + "/usr/share/man/es_CR/man2x", + "/usr/share/man/es_CR/man3", + "/usr/share/man/es_CR/man3p", + "/usr/share/man/es_CR/man3x", + "/usr/share/man/es_CR/man4", + "/usr/share/man/es_CR/man4x", + "/usr/share/man/es_CR/man5", + "/usr/share/man/es_CR/man5x", + "/usr/share/man/es_CR/man6", + "/usr/share/man/es_CR/man6x", + "/usr/share/man/es_CR/man7", + "/usr/share/man/es_CR/man7x", + "/usr/share/man/es_CR/man8", + "/usr/share/man/es_CR/man8x", + "/usr/share/man/es_CR/man9", + "/usr/share/man/es_CR/man9x", + "/usr/share/man/es_CR/mann", + "/usr/share/man/es_DO", + "/usr/share/man/es_DO/man0p", + "/usr/share/man/es_DO/man1", + "/usr/share/man/es_DO/man1p", + "/usr/share/man/es_DO/man1x", + "/usr/share/man/es_DO/man2", + "/usr/share/man/es_DO/man2x", + "/usr/share/man/es_DO/man3", + "/usr/share/man/es_DO/man3p", + "/usr/share/man/es_DO/man3x", + "/usr/share/man/es_DO/man4", + "/usr/share/man/es_DO/man4x", + "/usr/share/man/es_DO/man5", + "/usr/share/man/es_DO/man5x", + "/usr/share/man/es_DO/man6", + "/usr/share/man/es_DO/man6x", + "/usr/share/man/es_DO/man7", + "/usr/share/man/es_DO/man7x", + "/usr/share/man/es_DO/man8", + "/usr/share/man/es_DO/man8x", + "/usr/share/man/es_DO/man9", + "/usr/share/man/es_DO/man9x", + "/usr/share/man/es_DO/mann", + "/usr/share/man/es_EC", + "/usr/share/man/es_EC/man0p", + "/usr/share/man/es_EC/man1", + "/usr/share/man/es_EC/man1p", + "/usr/share/man/es_EC/man1x", + "/usr/share/man/es_EC/man2", + "/usr/share/man/es_EC/man2x", + "/usr/share/man/es_EC/man3", + "/usr/share/man/es_EC/man3p", + "/usr/share/man/es_EC/man3x", + "/usr/share/man/es_EC/man4", + "/usr/share/man/es_EC/man4x", + "/usr/share/man/es_EC/man5", + "/usr/share/man/es_EC/man5x", + "/usr/share/man/es_EC/man6", + "/usr/share/man/es_EC/man6x", + "/usr/share/man/es_EC/man7", + "/usr/share/man/es_EC/man7x", + "/usr/share/man/es_EC/man8", + "/usr/share/man/es_EC/man8x", + "/usr/share/man/es_EC/man9", + "/usr/share/man/es_EC/man9x", + "/usr/share/man/es_EC/mann", + "/usr/share/man/es_ES", + "/usr/share/man/es_ES/man0p", + "/usr/share/man/es_ES/man1", + "/usr/share/man/es_ES/man1p", + "/usr/share/man/es_ES/man1x", + "/usr/share/man/es_ES/man2", + "/usr/share/man/es_ES/man2x", + "/usr/share/man/es_ES/man3", + "/usr/share/man/es_ES/man3p", + "/usr/share/man/es_ES/man3x", + "/usr/share/man/es_ES/man4", + "/usr/share/man/es_ES/man4x", + "/usr/share/man/es_ES/man5", + "/usr/share/man/es_ES/man5x", + "/usr/share/man/es_ES/man6", + "/usr/share/man/es_ES/man6x", + "/usr/share/man/es_ES/man7", + "/usr/share/man/es_ES/man7x", + "/usr/share/man/es_ES/man8", + "/usr/share/man/es_ES/man8x", + "/usr/share/man/es_ES/man9", + "/usr/share/man/es_ES/man9x", + "/usr/share/man/es_ES/mann", + "/usr/share/man/es_GT", + "/usr/share/man/es_GT/man0p", + "/usr/share/man/es_GT/man1", + "/usr/share/man/es_GT/man1p", + "/usr/share/man/es_GT/man1x", + "/usr/share/man/es_GT/man2", + "/usr/share/man/es_GT/man2x", + "/usr/share/man/es_GT/man3", + "/usr/share/man/es_GT/man3p", + "/usr/share/man/es_GT/man3x", + "/usr/share/man/es_GT/man4", + "/usr/share/man/es_GT/man4x", + "/usr/share/man/es_GT/man5", + "/usr/share/man/es_GT/man5x", + "/usr/share/man/es_GT/man6", + "/usr/share/man/es_GT/man6x", + "/usr/share/man/es_GT/man7", + "/usr/share/man/es_GT/man7x", + "/usr/share/man/es_GT/man8", + "/usr/share/man/es_GT/man8x", + "/usr/share/man/es_GT/man9", + "/usr/share/man/es_GT/man9x", + "/usr/share/man/es_GT/mann", + "/usr/share/man/es_HN", + "/usr/share/man/es_HN/man0p", + "/usr/share/man/es_HN/man1", + "/usr/share/man/es_HN/man1p", + "/usr/share/man/es_HN/man1x", + "/usr/share/man/es_HN/man2", + "/usr/share/man/es_HN/man2x", + "/usr/share/man/es_HN/man3", + "/usr/share/man/es_HN/man3p", + "/usr/share/man/es_HN/man3x", + "/usr/share/man/es_HN/man4", + "/usr/share/man/es_HN/man4x", + "/usr/share/man/es_HN/man5", + "/usr/share/man/es_HN/man5x", + "/usr/share/man/es_HN/man6", + "/usr/share/man/es_HN/man6x", + "/usr/share/man/es_HN/man7", + "/usr/share/man/es_HN/man7x", + "/usr/share/man/es_HN/man8", + "/usr/share/man/es_HN/man8x", + "/usr/share/man/es_HN/man9", + "/usr/share/man/es_HN/man9x", + "/usr/share/man/es_HN/mann", + "/usr/share/man/es_MX", + "/usr/share/man/es_MX/man0p", + "/usr/share/man/es_MX/man1", + "/usr/share/man/es_MX/man1p", + "/usr/share/man/es_MX/man1x", + "/usr/share/man/es_MX/man2", + "/usr/share/man/es_MX/man2x", + "/usr/share/man/es_MX/man3", + "/usr/share/man/es_MX/man3p", + "/usr/share/man/es_MX/man3x", + "/usr/share/man/es_MX/man4", + "/usr/share/man/es_MX/man4x", + "/usr/share/man/es_MX/man5", + "/usr/share/man/es_MX/man5x", + "/usr/share/man/es_MX/man6", + "/usr/share/man/es_MX/man6x", + "/usr/share/man/es_MX/man7", + "/usr/share/man/es_MX/man7x", + "/usr/share/man/es_MX/man8", + "/usr/share/man/es_MX/man8x", + "/usr/share/man/es_MX/man9", + "/usr/share/man/es_MX/man9x", + "/usr/share/man/es_MX/mann", + "/usr/share/man/es_NI", + "/usr/share/man/es_NI/man0p", + "/usr/share/man/es_NI/man1", + "/usr/share/man/es_NI/man1p", + "/usr/share/man/es_NI/man1x", + "/usr/share/man/es_NI/man2", + "/usr/share/man/es_NI/man2x", + "/usr/share/man/es_NI/man3", + "/usr/share/man/es_NI/man3p", + "/usr/share/man/es_NI/man3x", + "/usr/share/man/es_NI/man4", + "/usr/share/man/es_NI/man4x", + "/usr/share/man/es_NI/man5", + "/usr/share/man/es_NI/man5x", + "/usr/share/man/es_NI/man6", + "/usr/share/man/es_NI/man6x", + "/usr/share/man/es_NI/man7", + "/usr/share/man/es_NI/man7x", + "/usr/share/man/es_NI/man8", + "/usr/share/man/es_NI/man8x", + "/usr/share/man/es_NI/man9", + "/usr/share/man/es_NI/man9x", + "/usr/share/man/es_NI/mann", + "/usr/share/man/es_PA", + "/usr/share/man/es_PA/man0p", + "/usr/share/man/es_PA/man1", + "/usr/share/man/es_PA/man1p", + "/usr/share/man/es_PA/man1x", + "/usr/share/man/es_PA/man2", + "/usr/share/man/es_PA/man2x", + "/usr/share/man/es_PA/man3", + "/usr/share/man/es_PA/man3p", + "/usr/share/man/es_PA/man3x", + "/usr/share/man/es_PA/man4", + "/usr/share/man/es_PA/man4x", + "/usr/share/man/es_PA/man5", + "/usr/share/man/es_PA/man5x", + "/usr/share/man/es_PA/man6", + "/usr/share/man/es_PA/man6x", + "/usr/share/man/es_PA/man7", + "/usr/share/man/es_PA/man7x", + "/usr/share/man/es_PA/man8", + "/usr/share/man/es_PA/man8x", + "/usr/share/man/es_PA/man9", + "/usr/share/man/es_PA/man9x", + "/usr/share/man/es_PA/mann", + "/usr/share/man/es_PE", + "/usr/share/man/es_PE/man0p", + "/usr/share/man/es_PE/man1", + "/usr/share/man/es_PE/man1p", + "/usr/share/man/es_PE/man1x", + "/usr/share/man/es_PE/man2", + "/usr/share/man/es_PE/man2x", + "/usr/share/man/es_PE/man3", + "/usr/share/man/es_PE/man3p", + "/usr/share/man/es_PE/man3x", + "/usr/share/man/es_PE/man4", + "/usr/share/man/es_PE/man4x", + "/usr/share/man/es_PE/man5", + "/usr/share/man/es_PE/man5x", + "/usr/share/man/es_PE/man6", + "/usr/share/man/es_PE/man6x", + "/usr/share/man/es_PE/man7", + "/usr/share/man/es_PE/man7x", + "/usr/share/man/es_PE/man8", + "/usr/share/man/es_PE/man8x", + "/usr/share/man/es_PE/man9", + "/usr/share/man/es_PE/man9x", + "/usr/share/man/es_PE/mann", + "/usr/share/man/es_PR", + "/usr/share/man/es_PR/man0p", + "/usr/share/man/es_PR/man1", + "/usr/share/man/es_PR/man1p", + "/usr/share/man/es_PR/man1x", + "/usr/share/man/es_PR/man2", + "/usr/share/man/es_PR/man2x", + "/usr/share/man/es_PR/man3", + "/usr/share/man/es_PR/man3p", + "/usr/share/man/es_PR/man3x", + "/usr/share/man/es_PR/man4", + "/usr/share/man/es_PR/man4x", + "/usr/share/man/es_PR/man5", + "/usr/share/man/es_PR/man5x", + "/usr/share/man/es_PR/man6", + "/usr/share/man/es_PR/man6x", + "/usr/share/man/es_PR/man7", + "/usr/share/man/es_PR/man7x", + "/usr/share/man/es_PR/man8", + "/usr/share/man/es_PR/man8x", + "/usr/share/man/es_PR/man9", + "/usr/share/man/es_PR/man9x", + "/usr/share/man/es_PR/mann", + "/usr/share/man/es_PY", + "/usr/share/man/es_PY/man0p", + "/usr/share/man/es_PY/man1", + "/usr/share/man/es_PY/man1p", + "/usr/share/man/es_PY/man1x", + "/usr/share/man/es_PY/man2", + "/usr/share/man/es_PY/man2x", + "/usr/share/man/es_PY/man3", + "/usr/share/man/es_PY/man3p", + "/usr/share/man/es_PY/man3x", + "/usr/share/man/es_PY/man4", + "/usr/share/man/es_PY/man4x", + "/usr/share/man/es_PY/man5", + "/usr/share/man/es_PY/man5x", + "/usr/share/man/es_PY/man6", + "/usr/share/man/es_PY/man6x", + "/usr/share/man/es_PY/man7", + "/usr/share/man/es_PY/man7x", + "/usr/share/man/es_PY/man8", + "/usr/share/man/es_PY/man8x", + "/usr/share/man/es_PY/man9", + "/usr/share/man/es_PY/man9x", + "/usr/share/man/es_PY/mann", + "/usr/share/man/es_SV", + "/usr/share/man/es_SV/man0p", + "/usr/share/man/es_SV/man1", + "/usr/share/man/es_SV/man1p", + "/usr/share/man/es_SV/man1x", + "/usr/share/man/es_SV/man2", + "/usr/share/man/es_SV/man2x", + "/usr/share/man/es_SV/man3", + "/usr/share/man/es_SV/man3p", + "/usr/share/man/es_SV/man3x", + "/usr/share/man/es_SV/man4", + "/usr/share/man/es_SV/man4x", + "/usr/share/man/es_SV/man5", + "/usr/share/man/es_SV/man5x", + "/usr/share/man/es_SV/man6", + "/usr/share/man/es_SV/man6x", + "/usr/share/man/es_SV/man7", + "/usr/share/man/es_SV/man7x", + "/usr/share/man/es_SV/man8", + "/usr/share/man/es_SV/man8x", + "/usr/share/man/es_SV/man9", + "/usr/share/man/es_SV/man9x", + "/usr/share/man/es_SV/mann", + "/usr/share/man/es_US", + "/usr/share/man/es_US/man0p", + "/usr/share/man/es_US/man1", + "/usr/share/man/es_US/man1p", + "/usr/share/man/es_US/man1x", + "/usr/share/man/es_US/man2", + "/usr/share/man/es_US/man2x", + "/usr/share/man/es_US/man3", + "/usr/share/man/es_US/man3p", + "/usr/share/man/es_US/man3x", + "/usr/share/man/es_US/man4", + "/usr/share/man/es_US/man4x", + "/usr/share/man/es_US/man5", + "/usr/share/man/es_US/man5x", + "/usr/share/man/es_US/man6", + "/usr/share/man/es_US/man6x", + "/usr/share/man/es_US/man7", + "/usr/share/man/es_US/man7x", + "/usr/share/man/es_US/man8", + "/usr/share/man/es_US/man8x", + "/usr/share/man/es_US/man9", + "/usr/share/man/es_US/man9x", + "/usr/share/man/es_US/mann", + "/usr/share/man/es_UY", + "/usr/share/man/es_UY/man0p", + "/usr/share/man/es_UY/man1", + "/usr/share/man/es_UY/man1p", + "/usr/share/man/es_UY/man1x", + "/usr/share/man/es_UY/man2", + "/usr/share/man/es_UY/man2x", + "/usr/share/man/es_UY/man3", + "/usr/share/man/es_UY/man3p", + "/usr/share/man/es_UY/man3x", + "/usr/share/man/es_UY/man4", + "/usr/share/man/es_UY/man4x", + "/usr/share/man/es_UY/man5", + "/usr/share/man/es_UY/man5x", + "/usr/share/man/es_UY/man6", + "/usr/share/man/es_UY/man6x", + "/usr/share/man/es_UY/man7", + "/usr/share/man/es_UY/man7x", + "/usr/share/man/es_UY/man8", + "/usr/share/man/es_UY/man8x", + "/usr/share/man/es_UY/man9", + "/usr/share/man/es_UY/man9x", + "/usr/share/man/es_UY/mann", + "/usr/share/man/es_VE", + "/usr/share/man/es_VE/man0p", + "/usr/share/man/es_VE/man1", + "/usr/share/man/es_VE/man1p", + "/usr/share/man/es_VE/man1x", + "/usr/share/man/es_VE/man2", + "/usr/share/man/es_VE/man2x", + "/usr/share/man/es_VE/man3", + "/usr/share/man/es_VE/man3p", + "/usr/share/man/es_VE/man3x", + "/usr/share/man/es_VE/man4", + "/usr/share/man/es_VE/man4x", + "/usr/share/man/es_VE/man5", + "/usr/share/man/es_VE/man5x", + "/usr/share/man/es_VE/man6", + "/usr/share/man/es_VE/man6x", + "/usr/share/man/es_VE/man7", + "/usr/share/man/es_VE/man7x", + "/usr/share/man/es_VE/man8", + "/usr/share/man/es_VE/man8x", + "/usr/share/man/es_VE/man9", + "/usr/share/man/es_VE/man9x", + "/usr/share/man/es_VE/mann", + "/usr/share/man/et", + "/usr/share/man/et/man0p", + "/usr/share/man/et/man1", + "/usr/share/man/et/man1p", + "/usr/share/man/et/man1x", + "/usr/share/man/et/man2", + "/usr/share/man/et/man2x", + "/usr/share/man/et/man3", + "/usr/share/man/et/man3p", + "/usr/share/man/et/man3x", + "/usr/share/man/et/man4", + "/usr/share/man/et/man4x", + "/usr/share/man/et/man5", + "/usr/share/man/et/man5x", + "/usr/share/man/et/man6", + "/usr/share/man/et/man6x", + "/usr/share/man/et/man7", + "/usr/share/man/et/man7x", + "/usr/share/man/et/man8", + "/usr/share/man/et/man8x", + "/usr/share/man/et/man9", + "/usr/share/man/et/man9x", + "/usr/share/man/et/mann", + "/usr/share/man/et_EE", + "/usr/share/man/et_EE/man0p", + "/usr/share/man/et_EE/man1", + "/usr/share/man/et_EE/man1p", + "/usr/share/man/et_EE/man1x", + "/usr/share/man/et_EE/man2", + "/usr/share/man/et_EE/man2x", + "/usr/share/man/et_EE/man3", + "/usr/share/man/et_EE/man3p", + "/usr/share/man/et_EE/man3x", + "/usr/share/man/et_EE/man4", + "/usr/share/man/et_EE/man4x", + "/usr/share/man/et_EE/man5", + "/usr/share/man/et_EE/man5x", + "/usr/share/man/et_EE/man6", + "/usr/share/man/et_EE/man6x", + "/usr/share/man/et_EE/man7", + "/usr/share/man/et_EE/man7x", + "/usr/share/man/et_EE/man8", + "/usr/share/man/et_EE/man8x", + "/usr/share/man/et_EE/man9", + "/usr/share/man/et_EE/man9x", + "/usr/share/man/et_EE/mann", + "/usr/share/man/eu", + "/usr/share/man/eu/man0p", + "/usr/share/man/eu/man1", + "/usr/share/man/eu/man1p", + "/usr/share/man/eu/man1x", + "/usr/share/man/eu/man2", + "/usr/share/man/eu/man2x", + "/usr/share/man/eu/man3", + "/usr/share/man/eu/man3p", + "/usr/share/man/eu/man3x", + "/usr/share/man/eu/man4", + "/usr/share/man/eu/man4x", + "/usr/share/man/eu/man5", + "/usr/share/man/eu/man5x", + "/usr/share/man/eu/man6", + "/usr/share/man/eu/man6x", + "/usr/share/man/eu/man7", + "/usr/share/man/eu/man7x", + "/usr/share/man/eu/man8", + "/usr/share/man/eu/man8x", + "/usr/share/man/eu/man9", + "/usr/share/man/eu/man9x", + "/usr/share/man/eu/mann", + "/usr/share/man/eu_ES", + "/usr/share/man/eu_ES/man0p", + "/usr/share/man/eu_ES/man1", + "/usr/share/man/eu_ES/man1p", + "/usr/share/man/eu_ES/man1x", + "/usr/share/man/eu_ES/man2", + "/usr/share/man/eu_ES/man2x", + "/usr/share/man/eu_ES/man3", + "/usr/share/man/eu_ES/man3p", + "/usr/share/man/eu_ES/man3x", + "/usr/share/man/eu_ES/man4", + "/usr/share/man/eu_ES/man4x", + "/usr/share/man/eu_ES/man5", + "/usr/share/man/eu_ES/man5x", + "/usr/share/man/eu_ES/man6", + "/usr/share/man/eu_ES/man6x", + "/usr/share/man/eu_ES/man7", + "/usr/share/man/eu_ES/man7x", + "/usr/share/man/eu_ES/man8", + "/usr/share/man/eu_ES/man8x", + "/usr/share/man/eu_ES/man9", + "/usr/share/man/eu_ES/man9x", + "/usr/share/man/eu_ES/mann", + "/usr/share/man/ewo", + "/usr/share/man/ewo/man0p", + "/usr/share/man/ewo/man1", + "/usr/share/man/ewo/man1p", + "/usr/share/man/ewo/man1x", + "/usr/share/man/ewo/man2", + "/usr/share/man/ewo/man2x", + "/usr/share/man/ewo/man3", + "/usr/share/man/ewo/man3p", + "/usr/share/man/ewo/man3x", + "/usr/share/man/ewo/man4", + "/usr/share/man/ewo/man4x", + "/usr/share/man/ewo/man5", + "/usr/share/man/ewo/man5x", + "/usr/share/man/ewo/man6", + "/usr/share/man/ewo/man6x", + "/usr/share/man/ewo/man7", + "/usr/share/man/ewo/man7x", + "/usr/share/man/ewo/man8", + "/usr/share/man/ewo/man8x", + "/usr/share/man/ewo/man9", + "/usr/share/man/ewo/man9x", + "/usr/share/man/ewo/mann", + "/usr/share/man/fa", + "/usr/share/man/fa/man0p", + "/usr/share/man/fa/man1", + "/usr/share/man/fa/man1p", + "/usr/share/man/fa/man1x", + "/usr/share/man/fa/man2", + "/usr/share/man/fa/man2x", + "/usr/share/man/fa/man3", + "/usr/share/man/fa/man3p", + "/usr/share/man/fa/man3x", + "/usr/share/man/fa/man4", + "/usr/share/man/fa/man4x", + "/usr/share/man/fa/man5", + "/usr/share/man/fa/man5x", + "/usr/share/man/fa/man6", + "/usr/share/man/fa/man6x", + "/usr/share/man/fa/man7", + "/usr/share/man/fa/man7x", + "/usr/share/man/fa/man8", + "/usr/share/man/fa/man8x", + "/usr/share/man/fa/man9", + "/usr/share/man/fa/man9x", + "/usr/share/man/fa/mann", + "/usr/share/man/fa_AF", + "/usr/share/man/fa_AF/man0p", + "/usr/share/man/fa_AF/man1", + "/usr/share/man/fa_AF/man1p", + "/usr/share/man/fa_AF/man1x", + "/usr/share/man/fa_AF/man2", + "/usr/share/man/fa_AF/man2x", + "/usr/share/man/fa_AF/man3", + "/usr/share/man/fa_AF/man3p", + "/usr/share/man/fa_AF/man3x", + "/usr/share/man/fa_AF/man4", + "/usr/share/man/fa_AF/man4x", + "/usr/share/man/fa_AF/man5", + "/usr/share/man/fa_AF/man5x", + "/usr/share/man/fa_AF/man6", + "/usr/share/man/fa_AF/man6x", + "/usr/share/man/fa_AF/man7", + "/usr/share/man/fa_AF/man7x", + "/usr/share/man/fa_AF/man8", + "/usr/share/man/fa_AF/man8x", + "/usr/share/man/fa_AF/man9", + "/usr/share/man/fa_AF/man9x", + "/usr/share/man/fa_AF/mann", + "/usr/share/man/fa_IR", + "/usr/share/man/fa_IR/man0p", + "/usr/share/man/fa_IR/man1", + "/usr/share/man/fa_IR/man1p", + "/usr/share/man/fa_IR/man1x", + "/usr/share/man/fa_IR/man2", + "/usr/share/man/fa_IR/man2x", + "/usr/share/man/fa_IR/man3", + "/usr/share/man/fa_IR/man3p", + "/usr/share/man/fa_IR/man3x", + "/usr/share/man/fa_IR/man4", + "/usr/share/man/fa_IR/man4x", + "/usr/share/man/fa_IR/man5", + "/usr/share/man/fa_IR/man5x", + "/usr/share/man/fa_IR/man6", + "/usr/share/man/fa_IR/man6x", + "/usr/share/man/fa_IR/man7", + "/usr/share/man/fa_IR/man7x", + "/usr/share/man/fa_IR/man8", + "/usr/share/man/fa_IR/man8x", + "/usr/share/man/fa_IR/man9", + "/usr/share/man/fa_IR/man9x", + "/usr/share/man/fa_IR/mann", + "/usr/share/man/fan", + "/usr/share/man/fan/man0p", + "/usr/share/man/fan/man1", + "/usr/share/man/fan/man1p", + "/usr/share/man/fan/man1x", + "/usr/share/man/fan/man2", + "/usr/share/man/fan/man2x", + "/usr/share/man/fan/man3", + "/usr/share/man/fan/man3p", + "/usr/share/man/fan/man3x", + "/usr/share/man/fan/man4", + "/usr/share/man/fan/man4x", + "/usr/share/man/fan/man5", + "/usr/share/man/fan/man5x", + "/usr/share/man/fan/man6", + "/usr/share/man/fan/man6x", + "/usr/share/man/fan/man7", + "/usr/share/man/fan/man7x", + "/usr/share/man/fan/man8", + "/usr/share/man/fan/man8x", + "/usr/share/man/fan/man9", + "/usr/share/man/fan/man9x", + "/usr/share/man/fan/mann", + "/usr/share/man/fat", + "/usr/share/man/fat/man0p", + "/usr/share/man/fat/man1", + "/usr/share/man/fat/man1p", + "/usr/share/man/fat/man1x", + "/usr/share/man/fat/man2", + "/usr/share/man/fat/man2x", + "/usr/share/man/fat/man3", + "/usr/share/man/fat/man3p", + "/usr/share/man/fat/man3x", + "/usr/share/man/fat/man4", + "/usr/share/man/fat/man4x", + "/usr/share/man/fat/man5", + "/usr/share/man/fat/man5x", + "/usr/share/man/fat/man6", + "/usr/share/man/fat/man6x", + "/usr/share/man/fat/man7", + "/usr/share/man/fat/man7x", + "/usr/share/man/fat/man8", + "/usr/share/man/fat/man8x", + "/usr/share/man/fat/man9", + "/usr/share/man/fat/man9x", + "/usr/share/man/fat/mann", + "/usr/share/man/ff", + "/usr/share/man/ff/man0p", + "/usr/share/man/ff/man1", + "/usr/share/man/ff/man1p", + "/usr/share/man/ff/man1x", + "/usr/share/man/ff/man2", + "/usr/share/man/ff/man2x", + "/usr/share/man/ff/man3", + "/usr/share/man/ff/man3p", + "/usr/share/man/ff/man3x", + "/usr/share/man/ff/man4", + "/usr/share/man/ff/man4x", + "/usr/share/man/ff/man5", + "/usr/share/man/ff/man5x", + "/usr/share/man/ff/man6", + "/usr/share/man/ff/man6x", + "/usr/share/man/ff/man7", + "/usr/share/man/ff/man7x", + "/usr/share/man/ff/man8", + "/usr/share/man/ff/man8x", + "/usr/share/man/ff/man9", + "/usr/share/man/ff/man9x", + "/usr/share/man/ff/mann", + "/usr/share/man/fi", + "/usr/share/man/fi/man0p", + "/usr/share/man/fi/man1", + "/usr/share/man/fi/man1p", + "/usr/share/man/fi/man1x", + "/usr/share/man/fi/man2", + "/usr/share/man/fi/man2x", + "/usr/share/man/fi/man3", + "/usr/share/man/fi/man3p", + "/usr/share/man/fi/man3x", + "/usr/share/man/fi/man4", + "/usr/share/man/fi/man4x", + "/usr/share/man/fi/man5", + "/usr/share/man/fi/man5x", + "/usr/share/man/fi/man6", + "/usr/share/man/fi/man6x", + "/usr/share/man/fi/man7", + "/usr/share/man/fi/man7x", + "/usr/share/man/fi/man8", + "/usr/share/man/fi/man8x", + "/usr/share/man/fi/man9", + "/usr/share/man/fi/man9x", + "/usr/share/man/fi/mann", + "/usr/share/man/fi_FI", + "/usr/share/man/fi_FI/man0p", + "/usr/share/man/fi_FI/man1", + "/usr/share/man/fi_FI/man1p", + "/usr/share/man/fi_FI/man1x", + "/usr/share/man/fi_FI/man2", + "/usr/share/man/fi_FI/man2x", + "/usr/share/man/fi_FI/man3", + "/usr/share/man/fi_FI/man3p", + "/usr/share/man/fi_FI/man3x", + "/usr/share/man/fi_FI/man4", + "/usr/share/man/fi_FI/man4x", + "/usr/share/man/fi_FI/man5", + "/usr/share/man/fi_FI/man5x", + "/usr/share/man/fi_FI/man6", + "/usr/share/man/fi_FI/man6x", + "/usr/share/man/fi_FI/man7", + "/usr/share/man/fi_FI/man7x", + "/usr/share/man/fi_FI/man8", + "/usr/share/man/fi_FI/man8x", + "/usr/share/man/fi_FI/man9", + "/usr/share/man/fi_FI/man9x", + "/usr/share/man/fi_FI/mann", + "/usr/share/man/fil", + "/usr/share/man/fil/man0p", + "/usr/share/man/fil/man1", + "/usr/share/man/fil/man1p", + "/usr/share/man/fil/man1x", + "/usr/share/man/fil/man2", + "/usr/share/man/fil/man2x", + "/usr/share/man/fil/man3", + "/usr/share/man/fil/man3p", + "/usr/share/man/fil/man3x", + "/usr/share/man/fil/man4", + "/usr/share/man/fil/man4x", + "/usr/share/man/fil/man5", + "/usr/share/man/fil/man5x", + "/usr/share/man/fil/man6", + "/usr/share/man/fil/man6x", + "/usr/share/man/fil/man7", + "/usr/share/man/fil/man7x", + "/usr/share/man/fil/man8", + "/usr/share/man/fil/man8x", + "/usr/share/man/fil/man9", + "/usr/share/man/fil/man9x", + "/usr/share/man/fil/mann", + "/usr/share/man/fiu", + "/usr/share/man/fiu/man0p", + "/usr/share/man/fiu/man1", + "/usr/share/man/fiu/man1p", + "/usr/share/man/fiu/man1x", + "/usr/share/man/fiu/man2", + "/usr/share/man/fiu/man2x", + "/usr/share/man/fiu/man3", + "/usr/share/man/fiu/man3p", + "/usr/share/man/fiu/man3x", + "/usr/share/man/fiu/man4", + "/usr/share/man/fiu/man4x", + "/usr/share/man/fiu/man5", + "/usr/share/man/fiu/man5x", + "/usr/share/man/fiu/man6", + "/usr/share/man/fiu/man6x", + "/usr/share/man/fiu/man7", + "/usr/share/man/fiu/man7x", + "/usr/share/man/fiu/man8", + "/usr/share/man/fiu/man8x", + "/usr/share/man/fiu/man9", + "/usr/share/man/fiu/man9x", + "/usr/share/man/fiu/mann", + "/usr/share/man/fj", + "/usr/share/man/fj/man0p", + "/usr/share/man/fj/man1", + "/usr/share/man/fj/man1p", + "/usr/share/man/fj/man1x", + "/usr/share/man/fj/man2", + "/usr/share/man/fj/man2x", + "/usr/share/man/fj/man3", + "/usr/share/man/fj/man3p", + "/usr/share/man/fj/man3x", + "/usr/share/man/fj/man4", + "/usr/share/man/fj/man4x", + "/usr/share/man/fj/man5", + "/usr/share/man/fj/man5x", + "/usr/share/man/fj/man6", + "/usr/share/man/fj/man6x", + "/usr/share/man/fj/man7", + "/usr/share/man/fj/man7x", + "/usr/share/man/fj/man8", + "/usr/share/man/fj/man8x", + "/usr/share/man/fj/man9", + "/usr/share/man/fj/man9x", + "/usr/share/man/fj/mann", + "/usr/share/man/fo", + "/usr/share/man/fo/man0p", + "/usr/share/man/fo/man1", + "/usr/share/man/fo/man1p", + "/usr/share/man/fo/man1x", + "/usr/share/man/fo/man2", + "/usr/share/man/fo/man2x", + "/usr/share/man/fo/man3", + "/usr/share/man/fo/man3p", + "/usr/share/man/fo/man3x", + "/usr/share/man/fo/man4", + "/usr/share/man/fo/man4x", + "/usr/share/man/fo/man5", + "/usr/share/man/fo/man5x", + "/usr/share/man/fo/man6", + "/usr/share/man/fo/man6x", + "/usr/share/man/fo/man7", + "/usr/share/man/fo/man7x", + "/usr/share/man/fo/man8", + "/usr/share/man/fo/man8x", + "/usr/share/man/fo/man9", + "/usr/share/man/fo/man9x", + "/usr/share/man/fo/mann", + "/usr/share/man/fon", + "/usr/share/man/fon/man0p", + "/usr/share/man/fon/man1", + "/usr/share/man/fon/man1p", + "/usr/share/man/fon/man1x", + "/usr/share/man/fon/man2", + "/usr/share/man/fon/man2x", + "/usr/share/man/fon/man3", + "/usr/share/man/fon/man3p", + "/usr/share/man/fon/man3x", + "/usr/share/man/fon/man4", + "/usr/share/man/fon/man4x", + "/usr/share/man/fon/man5", + "/usr/share/man/fon/man5x", + "/usr/share/man/fon/man6", + "/usr/share/man/fon/man6x", + "/usr/share/man/fon/man7", + "/usr/share/man/fon/man7x", + "/usr/share/man/fon/man8", + "/usr/share/man/fon/man8x", + "/usr/share/man/fon/man9", + "/usr/share/man/fon/man9x", + "/usr/share/man/fon/mann", + "/usr/share/man/fr", + "/usr/share/man/fr.us-ascii", + "/usr/share/man/fr.us-ascii/man0p", + "/usr/share/man/fr.us-ascii/man1", + "/usr/share/man/fr.us-ascii/man1p", + "/usr/share/man/fr.us-ascii/man1x", + "/usr/share/man/fr.us-ascii/man2", + "/usr/share/man/fr.us-ascii/man2x", + "/usr/share/man/fr.us-ascii/man3", + "/usr/share/man/fr.us-ascii/man3p", + "/usr/share/man/fr.us-ascii/man3x", + "/usr/share/man/fr.us-ascii/man4", + "/usr/share/man/fr.us-ascii/man4x", + "/usr/share/man/fr.us-ascii/man5", + "/usr/share/man/fr.us-ascii/man5x", + "/usr/share/man/fr.us-ascii/man6", + "/usr/share/man/fr.us-ascii/man6x", + "/usr/share/man/fr.us-ascii/man7", + "/usr/share/man/fr.us-ascii/man7x", + "/usr/share/man/fr.us-ascii/man8", + "/usr/share/man/fr.us-ascii/man8x", + "/usr/share/man/fr.us-ascii/man9", + "/usr/share/man/fr.us-ascii/man9x", + "/usr/share/man/fr.us-ascii/mann", + "/usr/share/man/fr/man0p", + "/usr/share/man/fr/man1", + "/usr/share/man/fr/man1p", + "/usr/share/man/fr/man1x", + "/usr/share/man/fr/man2", + "/usr/share/man/fr/man2x", + "/usr/share/man/fr/man3", + "/usr/share/man/fr/man3p", + "/usr/share/man/fr/man3x", + "/usr/share/man/fr/man4", + "/usr/share/man/fr/man4x", + "/usr/share/man/fr/man5", + "/usr/share/man/fr/man5x", + "/usr/share/man/fr/man6", + "/usr/share/man/fr/man6x", + "/usr/share/man/fr/man7", + "/usr/share/man/fr/man7x", + "/usr/share/man/fr/man8", + "/usr/share/man/fr/man8x", + "/usr/share/man/fr/man9", + "/usr/share/man/fr/man9x", + "/usr/share/man/fr/mann", + "/usr/share/man/fr_CA", + "/usr/share/man/fr_CA/man0p", + "/usr/share/man/fr_CA/man1", + "/usr/share/man/fr_CA/man1p", + "/usr/share/man/fr_CA/man1x", + "/usr/share/man/fr_CA/man2", + "/usr/share/man/fr_CA/man2x", + "/usr/share/man/fr_CA/man3", + "/usr/share/man/fr_CA/man3p", + "/usr/share/man/fr_CA/man3x", + "/usr/share/man/fr_CA/man4", + "/usr/share/man/fr_CA/man4x", + "/usr/share/man/fr_CA/man5", + "/usr/share/man/fr_CA/man5x", + "/usr/share/man/fr_CA/man6", + "/usr/share/man/fr_CA/man6x", + "/usr/share/man/fr_CA/man7", + "/usr/share/man/fr_CA/man7x", + "/usr/share/man/fr_CA/man8", + "/usr/share/man/fr_CA/man8x", + "/usr/share/man/fr_CA/man9", + "/usr/share/man/fr_CA/man9x", + "/usr/share/man/fr_CA/mann", + "/usr/share/man/fr_CH", + "/usr/share/man/fr_CH/man0p", + "/usr/share/man/fr_CH/man1", + "/usr/share/man/fr_CH/man1p", + "/usr/share/man/fr_CH/man1x", + "/usr/share/man/fr_CH/man2", + "/usr/share/man/fr_CH/man2x", + "/usr/share/man/fr_CH/man3", + "/usr/share/man/fr_CH/man3p", + "/usr/share/man/fr_CH/man3x", + "/usr/share/man/fr_CH/man4", + "/usr/share/man/fr_CH/man4x", + "/usr/share/man/fr_CH/man5", + "/usr/share/man/fr_CH/man5x", + "/usr/share/man/fr_CH/man6", + "/usr/share/man/fr_CH/man6x", + "/usr/share/man/fr_CH/man7", + "/usr/share/man/fr_CH/man7x", + "/usr/share/man/fr_CH/man8", + "/usr/share/man/fr_CH/man8x", + "/usr/share/man/fr_CH/man9", + "/usr/share/man/fr_CH/man9x", + "/usr/share/man/fr_CH/mann", + "/usr/share/man/fr_FR", + "/usr/share/man/fr_FR/man0p", + "/usr/share/man/fr_FR/man1", + "/usr/share/man/fr_FR/man1p", + "/usr/share/man/fr_FR/man1x", + "/usr/share/man/fr_FR/man2", + "/usr/share/man/fr_FR/man2x", + "/usr/share/man/fr_FR/man3", + "/usr/share/man/fr_FR/man3p", + "/usr/share/man/fr_FR/man3x", + "/usr/share/man/fr_FR/man4", + "/usr/share/man/fr_FR/man4x", + "/usr/share/man/fr_FR/man5", + "/usr/share/man/fr_FR/man5x", + "/usr/share/man/fr_FR/man6", + "/usr/share/man/fr_FR/man6x", + "/usr/share/man/fr_FR/man7", + "/usr/share/man/fr_FR/man7x", + "/usr/share/man/fr_FR/man8", + "/usr/share/man/fr_FR/man8x", + "/usr/share/man/fr_FR/man9", + "/usr/share/man/fr_FR/man9x", + "/usr/share/man/fr_FR/mann", + "/usr/share/man/frm", + "/usr/share/man/frm/man0p", + "/usr/share/man/frm/man1", + "/usr/share/man/frm/man1p", + "/usr/share/man/frm/man1x", + "/usr/share/man/frm/man2", + "/usr/share/man/frm/man2x", + "/usr/share/man/frm/man3", + "/usr/share/man/frm/man3p", + "/usr/share/man/frm/man3x", + "/usr/share/man/frm/man4", + "/usr/share/man/frm/man4x", + "/usr/share/man/frm/man5", + "/usr/share/man/frm/man5x", + "/usr/share/man/frm/man6", + "/usr/share/man/frm/man6x", + "/usr/share/man/frm/man7", + "/usr/share/man/frm/man7x", + "/usr/share/man/frm/man8", + "/usr/share/man/frm/man8x", + "/usr/share/man/frm/man9", + "/usr/share/man/frm/man9x", + "/usr/share/man/frm/mann", + "/usr/share/man/fro", + "/usr/share/man/fro/man0p", + "/usr/share/man/fro/man1", + "/usr/share/man/fro/man1p", + "/usr/share/man/fro/man1x", + "/usr/share/man/fro/man2", + "/usr/share/man/fro/man2x", + "/usr/share/man/fro/man3", + "/usr/share/man/fro/man3p", + "/usr/share/man/fro/man3x", + "/usr/share/man/fro/man4", + "/usr/share/man/fro/man4x", + "/usr/share/man/fro/man5", + "/usr/share/man/fro/man5x", + "/usr/share/man/fro/man6", + "/usr/share/man/fro/man6x", + "/usr/share/man/fro/man7", + "/usr/share/man/fro/man7x", + "/usr/share/man/fro/man8", + "/usr/share/man/fro/man8x", + "/usr/share/man/fro/man9", + "/usr/share/man/fro/man9x", + "/usr/share/man/fro/mann", + "/usr/share/man/frp", + "/usr/share/man/frp/man0p", + "/usr/share/man/frp/man1", + "/usr/share/man/frp/man1p", + "/usr/share/man/frp/man1x", + "/usr/share/man/frp/man2", + "/usr/share/man/frp/man2x", + "/usr/share/man/frp/man3", + "/usr/share/man/frp/man3p", + "/usr/share/man/frp/man3x", + "/usr/share/man/frp/man4", + "/usr/share/man/frp/man4x", + "/usr/share/man/frp/man5", + "/usr/share/man/frp/man5x", + "/usr/share/man/frp/man6", + "/usr/share/man/frp/man6x", + "/usr/share/man/frp/man7", + "/usr/share/man/frp/man7x", + "/usr/share/man/frp/man8", + "/usr/share/man/frp/man8x", + "/usr/share/man/frp/man9", + "/usr/share/man/frp/man9x", + "/usr/share/man/frp/mann", + "/usr/share/man/frr", + "/usr/share/man/frr/man0p", + "/usr/share/man/frr/man1", + "/usr/share/man/frr/man1p", + "/usr/share/man/frr/man1x", + "/usr/share/man/frr/man2", + "/usr/share/man/frr/man2x", + "/usr/share/man/frr/man3", + "/usr/share/man/frr/man3p", + "/usr/share/man/frr/man3x", + "/usr/share/man/frr/man4", + "/usr/share/man/frr/man4x", + "/usr/share/man/frr/man5", + "/usr/share/man/frr/man5x", + "/usr/share/man/frr/man6", + "/usr/share/man/frr/man6x", + "/usr/share/man/frr/man7", + "/usr/share/man/frr/man7x", + "/usr/share/man/frr/man8", + "/usr/share/man/frr/man8x", + "/usr/share/man/frr/man9", + "/usr/share/man/frr/man9x", + "/usr/share/man/frr/mann", + "/usr/share/man/frs", + "/usr/share/man/frs/man0p", + "/usr/share/man/frs/man1", + "/usr/share/man/frs/man1p", + "/usr/share/man/frs/man1x", + "/usr/share/man/frs/man2", + "/usr/share/man/frs/man2x", + "/usr/share/man/frs/man3", + "/usr/share/man/frs/man3p", + "/usr/share/man/frs/man3x", + "/usr/share/man/frs/man4", + "/usr/share/man/frs/man4x", + "/usr/share/man/frs/man5", + "/usr/share/man/frs/man5x", + "/usr/share/man/frs/man6", + "/usr/share/man/frs/man6x", + "/usr/share/man/frs/man7", + "/usr/share/man/frs/man7x", + "/usr/share/man/frs/man8", + "/usr/share/man/frs/man8x", + "/usr/share/man/frs/man9", + "/usr/share/man/frs/man9x", + "/usr/share/man/frs/mann", + "/usr/share/man/fur", + "/usr/share/man/fur/man0p", + "/usr/share/man/fur/man1", + "/usr/share/man/fur/man1p", + "/usr/share/man/fur/man1x", + "/usr/share/man/fur/man2", + "/usr/share/man/fur/man2x", + "/usr/share/man/fur/man3", + "/usr/share/man/fur/man3p", + "/usr/share/man/fur/man3x", + "/usr/share/man/fur/man4", + "/usr/share/man/fur/man4x", + "/usr/share/man/fur/man5", + "/usr/share/man/fur/man5x", + "/usr/share/man/fur/man6", + "/usr/share/man/fur/man6x", + "/usr/share/man/fur/man7", + "/usr/share/man/fur/man7x", + "/usr/share/man/fur/man8", + "/usr/share/man/fur/man8x", + "/usr/share/man/fur/man9", + "/usr/share/man/fur/man9x", + "/usr/share/man/fur/mann", + "/usr/share/man/fy", + "/usr/share/man/fy/man0p", + "/usr/share/man/fy/man1", + "/usr/share/man/fy/man1p", + "/usr/share/man/fy/man1x", + "/usr/share/man/fy/man2", + "/usr/share/man/fy/man2x", + "/usr/share/man/fy/man3", + "/usr/share/man/fy/man3p", + "/usr/share/man/fy/man3x", + "/usr/share/man/fy/man4", + "/usr/share/man/fy/man4x", + "/usr/share/man/fy/man5", + "/usr/share/man/fy/man5x", + "/usr/share/man/fy/man6", + "/usr/share/man/fy/man6x", + "/usr/share/man/fy/man7", + "/usr/share/man/fy/man7x", + "/usr/share/man/fy/man8", + "/usr/share/man/fy/man8x", + "/usr/share/man/fy/man9", + "/usr/share/man/fy/man9x", + "/usr/share/man/fy/mann", + "/usr/share/man/ga", + "/usr/share/man/ga/man0p", + "/usr/share/man/ga/man1", + "/usr/share/man/ga/man1p", + "/usr/share/man/ga/man1x", + "/usr/share/man/ga/man2", + "/usr/share/man/ga/man2x", + "/usr/share/man/ga/man3", + "/usr/share/man/ga/man3p", + "/usr/share/man/ga/man3x", + "/usr/share/man/ga/man4", + "/usr/share/man/ga/man4x", + "/usr/share/man/ga/man5", + "/usr/share/man/ga/man5x", + "/usr/share/man/ga/man6", + "/usr/share/man/ga/man6x", + "/usr/share/man/ga/man7", + "/usr/share/man/ga/man7x", + "/usr/share/man/ga/man8", + "/usr/share/man/ga/man8x", + "/usr/share/man/ga/man9", + "/usr/share/man/ga/man9x", + "/usr/share/man/ga/mann", + "/usr/share/man/gaa", + "/usr/share/man/gaa/man0p", + "/usr/share/man/gaa/man1", + "/usr/share/man/gaa/man1p", + "/usr/share/man/gaa/man1x", + "/usr/share/man/gaa/man2", + "/usr/share/man/gaa/man2x", + "/usr/share/man/gaa/man3", + "/usr/share/man/gaa/man3p", + "/usr/share/man/gaa/man3x", + "/usr/share/man/gaa/man4", + "/usr/share/man/gaa/man4x", + "/usr/share/man/gaa/man5", + "/usr/share/man/gaa/man5x", + "/usr/share/man/gaa/man6", + "/usr/share/man/gaa/man6x", + "/usr/share/man/gaa/man7", + "/usr/share/man/gaa/man7x", + "/usr/share/man/gaa/man8", + "/usr/share/man/gaa/man8x", + "/usr/share/man/gaa/man9", + "/usr/share/man/gaa/man9x", + "/usr/share/man/gaa/mann", + "/usr/share/man/gay", + "/usr/share/man/gay/man0p", + "/usr/share/man/gay/man1", + "/usr/share/man/gay/man1p", + "/usr/share/man/gay/man1x", + "/usr/share/man/gay/man2", + "/usr/share/man/gay/man2x", + "/usr/share/man/gay/man3", + "/usr/share/man/gay/man3p", + "/usr/share/man/gay/man3x", + "/usr/share/man/gay/man4", + "/usr/share/man/gay/man4x", + "/usr/share/man/gay/man5", + "/usr/share/man/gay/man5x", + "/usr/share/man/gay/man6", + "/usr/share/man/gay/man6x", + "/usr/share/man/gay/man7", + "/usr/share/man/gay/man7x", + "/usr/share/man/gay/man8", + "/usr/share/man/gay/man8x", + "/usr/share/man/gay/man9", + "/usr/share/man/gay/man9x", + "/usr/share/man/gay/mann", + "/usr/share/man/gba", + "/usr/share/man/gba/man0p", + "/usr/share/man/gba/man1", + "/usr/share/man/gba/man1p", + "/usr/share/man/gba/man1x", + "/usr/share/man/gba/man2", + "/usr/share/man/gba/man2x", + "/usr/share/man/gba/man3", + "/usr/share/man/gba/man3p", + "/usr/share/man/gba/man3x", + "/usr/share/man/gba/man4", + "/usr/share/man/gba/man4x", + "/usr/share/man/gba/man5", + "/usr/share/man/gba/man5x", + "/usr/share/man/gba/man6", + "/usr/share/man/gba/man6x", + "/usr/share/man/gba/man7", + "/usr/share/man/gba/man7x", + "/usr/share/man/gba/man8", + "/usr/share/man/gba/man8x", + "/usr/share/man/gba/man9", + "/usr/share/man/gba/man9x", + "/usr/share/man/gba/mann", + "/usr/share/man/gd", + "/usr/share/man/gd/man0p", + "/usr/share/man/gd/man1", + "/usr/share/man/gd/man1p", + "/usr/share/man/gd/man1x", + "/usr/share/man/gd/man2", + "/usr/share/man/gd/man2x", + "/usr/share/man/gd/man3", + "/usr/share/man/gd/man3p", + "/usr/share/man/gd/man3x", + "/usr/share/man/gd/man4", + "/usr/share/man/gd/man4x", + "/usr/share/man/gd/man5", + "/usr/share/man/gd/man5x", + "/usr/share/man/gd/man6", + "/usr/share/man/gd/man6x", + "/usr/share/man/gd/man7", + "/usr/share/man/gd/man7x", + "/usr/share/man/gd/man8", + "/usr/share/man/gd/man8x", + "/usr/share/man/gd/man9", + "/usr/share/man/gd/man9x", + "/usr/share/man/gd/mann", + "/usr/share/man/gem", + "/usr/share/man/gem/man0p", + "/usr/share/man/gem/man1", + "/usr/share/man/gem/man1p", + "/usr/share/man/gem/man1x", + "/usr/share/man/gem/man2", + "/usr/share/man/gem/man2x", + "/usr/share/man/gem/man3", + "/usr/share/man/gem/man3p", + "/usr/share/man/gem/man3x", + "/usr/share/man/gem/man4", + "/usr/share/man/gem/man4x", + "/usr/share/man/gem/man5", + "/usr/share/man/gem/man5x", + "/usr/share/man/gem/man6", + "/usr/share/man/gem/man6x", + "/usr/share/man/gem/man7", + "/usr/share/man/gem/man7x", + "/usr/share/man/gem/man8", + "/usr/share/man/gem/man8x", + "/usr/share/man/gem/man9", + "/usr/share/man/gem/man9x", + "/usr/share/man/gem/mann", + "/usr/share/man/gez", + "/usr/share/man/gez/man0p", + "/usr/share/man/gez/man1", + "/usr/share/man/gez/man1p", + "/usr/share/man/gez/man1x", + "/usr/share/man/gez/man2", + "/usr/share/man/gez/man2x", + "/usr/share/man/gez/man3", + "/usr/share/man/gez/man3p", + "/usr/share/man/gez/man3x", + "/usr/share/man/gez/man4", + "/usr/share/man/gez/man4x", + "/usr/share/man/gez/man5", + "/usr/share/man/gez/man5x", + "/usr/share/man/gez/man6", + "/usr/share/man/gez/man6x", + "/usr/share/man/gez/man7", + "/usr/share/man/gez/man7x", + "/usr/share/man/gez/man8", + "/usr/share/man/gez/man8x", + "/usr/share/man/gez/man9", + "/usr/share/man/gez/man9x", + "/usr/share/man/gez/mann", + "/usr/share/man/gil", + "/usr/share/man/gil/man0p", + "/usr/share/man/gil/man1", + "/usr/share/man/gil/man1p", + "/usr/share/man/gil/man1x", + "/usr/share/man/gil/man2", + "/usr/share/man/gil/man2x", + "/usr/share/man/gil/man3", + "/usr/share/man/gil/man3p", + "/usr/share/man/gil/man3x", + "/usr/share/man/gil/man4", + "/usr/share/man/gil/man4x", + "/usr/share/man/gil/man5", + "/usr/share/man/gil/man5x", + "/usr/share/man/gil/man6", + "/usr/share/man/gil/man6x", + "/usr/share/man/gil/man7", + "/usr/share/man/gil/man7x", + "/usr/share/man/gil/man8", + "/usr/share/man/gil/man8x", + "/usr/share/man/gil/man9", + "/usr/share/man/gil/man9x", + "/usr/share/man/gil/mann", + "/usr/share/man/gl", + "/usr/share/man/gl/man0p", + "/usr/share/man/gl/man1", + "/usr/share/man/gl/man1p", + "/usr/share/man/gl/man1x", + "/usr/share/man/gl/man2", + "/usr/share/man/gl/man2x", + "/usr/share/man/gl/man3", + "/usr/share/man/gl/man3p", + "/usr/share/man/gl/man3x", + "/usr/share/man/gl/man4", + "/usr/share/man/gl/man4x", + "/usr/share/man/gl/man5", + "/usr/share/man/gl/man5x", + "/usr/share/man/gl/man6", + "/usr/share/man/gl/man6x", + "/usr/share/man/gl/man7", + "/usr/share/man/gl/man7x", + "/usr/share/man/gl/man8", + "/usr/share/man/gl/man8x", + "/usr/share/man/gl/man9", + "/usr/share/man/gl/man9x", + "/usr/share/man/gl/mann", + "/usr/share/man/gl_ES", + "/usr/share/man/gl_ES/man0p", + "/usr/share/man/gl_ES/man1", + "/usr/share/man/gl_ES/man1p", + "/usr/share/man/gl_ES/man1x", + "/usr/share/man/gl_ES/man2", + "/usr/share/man/gl_ES/man2x", + "/usr/share/man/gl_ES/man3", + "/usr/share/man/gl_ES/man3p", + "/usr/share/man/gl_ES/man3x", + "/usr/share/man/gl_ES/man4", + "/usr/share/man/gl_ES/man4x", + "/usr/share/man/gl_ES/man5", + "/usr/share/man/gl_ES/man5x", + "/usr/share/man/gl_ES/man6", + "/usr/share/man/gl_ES/man6x", + "/usr/share/man/gl_ES/man7", + "/usr/share/man/gl_ES/man7x", + "/usr/share/man/gl_ES/man8", + "/usr/share/man/gl_ES/man8x", + "/usr/share/man/gl_ES/man9", + "/usr/share/man/gl_ES/man9x", + "/usr/share/man/gl_ES/mann", + "/usr/share/man/gmh", + "/usr/share/man/gmh/man0p", + "/usr/share/man/gmh/man1", + "/usr/share/man/gmh/man1p", + "/usr/share/man/gmh/man1x", + "/usr/share/man/gmh/man2", + "/usr/share/man/gmh/man2x", + "/usr/share/man/gmh/man3", + "/usr/share/man/gmh/man3p", + "/usr/share/man/gmh/man3x", + "/usr/share/man/gmh/man4", + "/usr/share/man/gmh/man4x", + "/usr/share/man/gmh/man5", + "/usr/share/man/gmh/man5x", + "/usr/share/man/gmh/man6", + "/usr/share/man/gmh/man6x", + "/usr/share/man/gmh/man7", + "/usr/share/man/gmh/man7x", + "/usr/share/man/gmh/man8", + "/usr/share/man/gmh/man8x", + "/usr/share/man/gmh/man9", + "/usr/share/man/gmh/man9x", + "/usr/share/man/gmh/mann", + "/usr/share/man/gn", + "/usr/share/man/gn/man0p", + "/usr/share/man/gn/man1", + "/usr/share/man/gn/man1p", + "/usr/share/man/gn/man1x", + "/usr/share/man/gn/man2", + "/usr/share/man/gn/man2x", + "/usr/share/man/gn/man3", + "/usr/share/man/gn/man3p", + "/usr/share/man/gn/man3x", + "/usr/share/man/gn/man4", + "/usr/share/man/gn/man4x", + "/usr/share/man/gn/man5", + "/usr/share/man/gn/man5x", + "/usr/share/man/gn/man6", + "/usr/share/man/gn/man6x", + "/usr/share/man/gn/man7", + "/usr/share/man/gn/man7x", + "/usr/share/man/gn/man8", + "/usr/share/man/gn/man8x", + "/usr/share/man/gn/man9", + "/usr/share/man/gn/man9x", + "/usr/share/man/gn/mann", + "/usr/share/man/goh", + "/usr/share/man/goh/man0p", + "/usr/share/man/goh/man1", + "/usr/share/man/goh/man1p", + "/usr/share/man/goh/man1x", + "/usr/share/man/goh/man2", + "/usr/share/man/goh/man2x", + "/usr/share/man/goh/man3", + "/usr/share/man/goh/man3p", + "/usr/share/man/goh/man3x", + "/usr/share/man/goh/man4", + "/usr/share/man/goh/man4x", + "/usr/share/man/goh/man5", + "/usr/share/man/goh/man5x", + "/usr/share/man/goh/man6", + "/usr/share/man/goh/man6x", + "/usr/share/man/goh/man7", + "/usr/share/man/goh/man7x", + "/usr/share/man/goh/man8", + "/usr/share/man/goh/man8x", + "/usr/share/man/goh/man9", + "/usr/share/man/goh/man9x", + "/usr/share/man/goh/mann", + "/usr/share/man/gom", + "/usr/share/man/gom/man0p", + "/usr/share/man/gom/man1", + "/usr/share/man/gom/man1p", + "/usr/share/man/gom/man1x", + "/usr/share/man/gom/man2", + "/usr/share/man/gom/man2x", + "/usr/share/man/gom/man3", + "/usr/share/man/gom/man3p", + "/usr/share/man/gom/man3x", + "/usr/share/man/gom/man4", + "/usr/share/man/gom/man4x", + "/usr/share/man/gom/man5", + "/usr/share/man/gom/man5x", + "/usr/share/man/gom/man6", + "/usr/share/man/gom/man6x", + "/usr/share/man/gom/man7", + "/usr/share/man/gom/man7x", + "/usr/share/man/gom/man8", + "/usr/share/man/gom/man8x", + "/usr/share/man/gom/man9", + "/usr/share/man/gom/man9x", + "/usr/share/man/gom/mann", + "/usr/share/man/gon", + "/usr/share/man/gon/man0p", + "/usr/share/man/gon/man1", + "/usr/share/man/gon/man1p", + "/usr/share/man/gon/man1x", + "/usr/share/man/gon/man2", + "/usr/share/man/gon/man2x", + "/usr/share/man/gon/man3", + "/usr/share/man/gon/man3p", + "/usr/share/man/gon/man3x", + "/usr/share/man/gon/man4", + "/usr/share/man/gon/man4x", + "/usr/share/man/gon/man5", + "/usr/share/man/gon/man5x", + "/usr/share/man/gon/man6", + "/usr/share/man/gon/man6x", + "/usr/share/man/gon/man7", + "/usr/share/man/gon/man7x", + "/usr/share/man/gon/man8", + "/usr/share/man/gon/man8x", + "/usr/share/man/gon/man9", + "/usr/share/man/gon/man9x", + "/usr/share/man/gon/mann", + "/usr/share/man/gor", + "/usr/share/man/gor/man0p", + "/usr/share/man/gor/man1", + "/usr/share/man/gor/man1p", + "/usr/share/man/gor/man1x", + "/usr/share/man/gor/man2", + "/usr/share/man/gor/man2x", + "/usr/share/man/gor/man3", + "/usr/share/man/gor/man3p", + "/usr/share/man/gor/man3x", + "/usr/share/man/gor/man4", + "/usr/share/man/gor/man4x", + "/usr/share/man/gor/man5", + "/usr/share/man/gor/man5x", + "/usr/share/man/gor/man6", + "/usr/share/man/gor/man6x", + "/usr/share/man/gor/man7", + "/usr/share/man/gor/man7x", + "/usr/share/man/gor/man8", + "/usr/share/man/gor/man8x", + "/usr/share/man/gor/man9", + "/usr/share/man/gor/man9x", + "/usr/share/man/gor/mann", + "/usr/share/man/gos", + "/usr/share/man/gos/man0p", + "/usr/share/man/gos/man1", + "/usr/share/man/gos/man1p", + "/usr/share/man/gos/man1x", + "/usr/share/man/gos/man2", + "/usr/share/man/gos/man2x", + "/usr/share/man/gos/man3", + "/usr/share/man/gos/man3p", + "/usr/share/man/gos/man3x", + "/usr/share/man/gos/man4", + "/usr/share/man/gos/man4x", + "/usr/share/man/gos/man5", + "/usr/share/man/gos/man5x", + "/usr/share/man/gos/man6", + "/usr/share/man/gos/man6x", + "/usr/share/man/gos/man7", + "/usr/share/man/gos/man7x", + "/usr/share/man/gos/man8", + "/usr/share/man/gos/man8x", + "/usr/share/man/gos/man9", + "/usr/share/man/gos/man9x", + "/usr/share/man/gos/mann", + "/usr/share/man/got", + "/usr/share/man/got/man0p", + "/usr/share/man/got/man1", + "/usr/share/man/got/man1p", + "/usr/share/man/got/man1x", + "/usr/share/man/got/man2", + "/usr/share/man/got/man2x", + "/usr/share/man/got/man3", + "/usr/share/man/got/man3p", + "/usr/share/man/got/man3x", + "/usr/share/man/got/man4", + "/usr/share/man/got/man4x", + "/usr/share/man/got/man5", + "/usr/share/man/got/man5x", + "/usr/share/man/got/man6", + "/usr/share/man/got/man6x", + "/usr/share/man/got/man7", + "/usr/share/man/got/man7x", + "/usr/share/man/got/man8", + "/usr/share/man/got/man8x", + "/usr/share/man/got/man9", + "/usr/share/man/got/man9x", + "/usr/share/man/got/mann", + "/usr/share/man/grb", + "/usr/share/man/grb/man0p", + "/usr/share/man/grb/man1", + "/usr/share/man/grb/man1p", + "/usr/share/man/grb/man1x", + "/usr/share/man/grb/man2", + "/usr/share/man/grb/man2x", + "/usr/share/man/grb/man3", + "/usr/share/man/grb/man3p", + "/usr/share/man/grb/man3x", + "/usr/share/man/grb/man4", + "/usr/share/man/grb/man4x", + "/usr/share/man/grb/man5", + "/usr/share/man/grb/man5x", + "/usr/share/man/grb/man6", + "/usr/share/man/grb/man6x", + "/usr/share/man/grb/man7", + "/usr/share/man/grb/man7x", + "/usr/share/man/grb/man8", + "/usr/share/man/grb/man8x", + "/usr/share/man/grb/man9", + "/usr/share/man/grb/man9x", + "/usr/share/man/grb/mann", + "/usr/share/man/grc", + "/usr/share/man/grc/man0p", + "/usr/share/man/grc/man1", + "/usr/share/man/grc/man1p", + "/usr/share/man/grc/man1x", + "/usr/share/man/grc/man2", + "/usr/share/man/grc/man2x", + "/usr/share/man/grc/man3", + "/usr/share/man/grc/man3p", + "/usr/share/man/grc/man3x", + "/usr/share/man/grc/man4", + "/usr/share/man/grc/man4x", + "/usr/share/man/grc/man5", + "/usr/share/man/grc/man5x", + "/usr/share/man/grc/man6", + "/usr/share/man/grc/man6x", + "/usr/share/man/grc/man7", + "/usr/share/man/grc/man7x", + "/usr/share/man/grc/man8", + "/usr/share/man/grc/man8x", + "/usr/share/man/grc/man9", + "/usr/share/man/grc/man9x", + "/usr/share/man/grc/mann", + "/usr/share/man/gsw", + "/usr/share/man/gsw/man0p", + "/usr/share/man/gsw/man1", + "/usr/share/man/gsw/man1p", + "/usr/share/man/gsw/man1x", + "/usr/share/man/gsw/man2", + "/usr/share/man/gsw/man2x", + "/usr/share/man/gsw/man3", + "/usr/share/man/gsw/man3p", + "/usr/share/man/gsw/man3x", + "/usr/share/man/gsw/man4", + "/usr/share/man/gsw/man4x", + "/usr/share/man/gsw/man5", + "/usr/share/man/gsw/man5x", + "/usr/share/man/gsw/man6", + "/usr/share/man/gsw/man6x", + "/usr/share/man/gsw/man7", + "/usr/share/man/gsw/man7x", + "/usr/share/man/gsw/man8", + "/usr/share/man/gsw/man8x", + "/usr/share/man/gsw/man9", + "/usr/share/man/gsw/man9x", + "/usr/share/man/gsw/mann", + "/usr/share/man/gu", + "/usr/share/man/gu/man0p", + "/usr/share/man/gu/man1", + "/usr/share/man/gu/man1p", + "/usr/share/man/gu/man1x", + "/usr/share/man/gu/man2", + "/usr/share/man/gu/man2x", + "/usr/share/man/gu/man3", + "/usr/share/man/gu/man3p", + "/usr/share/man/gu/man3x", + "/usr/share/man/gu/man4", + "/usr/share/man/gu/man4x", + "/usr/share/man/gu/man5", + "/usr/share/man/gu/man5x", + "/usr/share/man/gu/man6", + "/usr/share/man/gu/man6x", + "/usr/share/man/gu/man7", + "/usr/share/man/gu/man7x", + "/usr/share/man/gu/man8", + "/usr/share/man/gu/man8x", + "/usr/share/man/gu/man9", + "/usr/share/man/gu/man9x", + "/usr/share/man/gu/mann", + "/usr/share/man/guc", + "/usr/share/man/guc/man0p", + "/usr/share/man/guc/man1", + "/usr/share/man/guc/man1p", + "/usr/share/man/guc/man1x", + "/usr/share/man/guc/man2", + "/usr/share/man/guc/man2x", + "/usr/share/man/guc/man3", + "/usr/share/man/guc/man3p", + "/usr/share/man/guc/man3x", + "/usr/share/man/guc/man4", + "/usr/share/man/guc/man4x", + "/usr/share/man/guc/man5", + "/usr/share/man/guc/man5x", + "/usr/share/man/guc/man6", + "/usr/share/man/guc/man6x", + "/usr/share/man/guc/man7", + "/usr/share/man/guc/man7x", + "/usr/share/man/guc/man8", + "/usr/share/man/guc/man8x", + "/usr/share/man/guc/man9", + "/usr/share/man/guc/man9x", + "/usr/share/man/guc/mann", + "/usr/share/man/gv", + "/usr/share/man/gv/man0p", + "/usr/share/man/gv/man1", + "/usr/share/man/gv/man1p", + "/usr/share/man/gv/man1x", + "/usr/share/man/gv/man2", + "/usr/share/man/gv/man2x", + "/usr/share/man/gv/man3", + "/usr/share/man/gv/man3p", + "/usr/share/man/gv/man3x", + "/usr/share/man/gv/man4", + "/usr/share/man/gv/man4x", + "/usr/share/man/gv/man5", + "/usr/share/man/gv/man5x", + "/usr/share/man/gv/man6", + "/usr/share/man/gv/man6x", + "/usr/share/man/gv/man7", + "/usr/share/man/gv/man7x", + "/usr/share/man/gv/man8", + "/usr/share/man/gv/man8x", + "/usr/share/man/gv/man9", + "/usr/share/man/gv/man9x", + "/usr/share/man/gv/mann", + "/usr/share/man/gwi", + "/usr/share/man/gwi/man0p", + "/usr/share/man/gwi/man1", + "/usr/share/man/gwi/man1p", + "/usr/share/man/gwi/man1x", + "/usr/share/man/gwi/man2", + "/usr/share/man/gwi/man2x", + "/usr/share/man/gwi/man3", + "/usr/share/man/gwi/man3p", + "/usr/share/man/gwi/man3x", + "/usr/share/man/gwi/man4", + "/usr/share/man/gwi/man4x", + "/usr/share/man/gwi/man5", + "/usr/share/man/gwi/man5x", + "/usr/share/man/gwi/man6", + "/usr/share/man/gwi/man6x", + "/usr/share/man/gwi/man7", + "/usr/share/man/gwi/man7x", + "/usr/share/man/gwi/man8", + "/usr/share/man/gwi/man8x", + "/usr/share/man/gwi/man9", + "/usr/share/man/gwi/man9x", + "/usr/share/man/gwi/mann", + "/usr/share/man/ha", + "/usr/share/man/ha/man0p", + "/usr/share/man/ha/man1", + "/usr/share/man/ha/man1p", + "/usr/share/man/ha/man1x", + "/usr/share/man/ha/man2", + "/usr/share/man/ha/man2x", + "/usr/share/man/ha/man3", + "/usr/share/man/ha/man3p", + "/usr/share/man/ha/man3x", + "/usr/share/man/ha/man4", + "/usr/share/man/ha/man4x", + "/usr/share/man/ha/man5", + "/usr/share/man/ha/man5x", + "/usr/share/man/ha/man6", + "/usr/share/man/ha/man6x", + "/usr/share/man/ha/man7", + "/usr/share/man/ha/man7x", + "/usr/share/man/ha/man8", + "/usr/share/man/ha/man8x", + "/usr/share/man/ha/man9", + "/usr/share/man/ha/man9x", + "/usr/share/man/ha/mann", + "/usr/share/man/hai", + "/usr/share/man/hai/man0p", + "/usr/share/man/hai/man1", + "/usr/share/man/hai/man1p", + "/usr/share/man/hai/man1x", + "/usr/share/man/hai/man2", + "/usr/share/man/hai/man2x", + "/usr/share/man/hai/man3", + "/usr/share/man/hai/man3p", + "/usr/share/man/hai/man3x", + "/usr/share/man/hai/man4", + "/usr/share/man/hai/man4x", + "/usr/share/man/hai/man5", + "/usr/share/man/hai/man5x", + "/usr/share/man/hai/man6", + "/usr/share/man/hai/man6x", + "/usr/share/man/hai/man7", + "/usr/share/man/hai/man7x", + "/usr/share/man/hai/man8", + "/usr/share/man/hai/man8x", + "/usr/share/man/hai/man9", + "/usr/share/man/hai/man9x", + "/usr/share/man/hai/mann", + "/usr/share/man/haw", + "/usr/share/man/haw/man0p", + "/usr/share/man/haw/man1", + "/usr/share/man/haw/man1p", + "/usr/share/man/haw/man1x", + "/usr/share/man/haw/man2", + "/usr/share/man/haw/man2x", + "/usr/share/man/haw/man3", + "/usr/share/man/haw/man3p", + "/usr/share/man/haw/man3x", + "/usr/share/man/haw/man4", + "/usr/share/man/haw/man4x", + "/usr/share/man/haw/man5", + "/usr/share/man/haw/man5x", + "/usr/share/man/haw/man6", + "/usr/share/man/haw/man6x", + "/usr/share/man/haw/man7", + "/usr/share/man/haw/man7x", + "/usr/share/man/haw/man8", + "/usr/share/man/haw/man8x", + "/usr/share/man/haw/man9", + "/usr/share/man/haw/man9x", + "/usr/share/man/haw/mann", + "/usr/share/man/he", + "/usr/share/man/he/man0p", + "/usr/share/man/he/man1", + "/usr/share/man/he/man1p", + "/usr/share/man/he/man1x", + "/usr/share/man/he/man2", + "/usr/share/man/he/man2x", + "/usr/share/man/he/man3", + "/usr/share/man/he/man3p", + "/usr/share/man/he/man3x", + "/usr/share/man/he/man4", + "/usr/share/man/he/man4x", + "/usr/share/man/he/man5", + "/usr/share/man/he/man5x", + "/usr/share/man/he/man6", + "/usr/share/man/he/man6x", + "/usr/share/man/he/man7", + "/usr/share/man/he/man7x", + "/usr/share/man/he/man8", + "/usr/share/man/he/man8x", + "/usr/share/man/he/man9", + "/usr/share/man/he/man9x", + "/usr/share/man/he/mann", + "/usr/share/man/he_IL", + "/usr/share/man/he_IL/man0p", + "/usr/share/man/he_IL/man1", + "/usr/share/man/he_IL/man1p", + "/usr/share/man/he_IL/man1x", + "/usr/share/man/he_IL/man2", + "/usr/share/man/he_IL/man2x", + "/usr/share/man/he_IL/man3", + "/usr/share/man/he_IL/man3p", + "/usr/share/man/he_IL/man3x", + "/usr/share/man/he_IL/man4", + "/usr/share/man/he_IL/man4x", + "/usr/share/man/he_IL/man5", + "/usr/share/man/he_IL/man5x", + "/usr/share/man/he_IL/man6", + "/usr/share/man/he_IL/man6x", + "/usr/share/man/he_IL/man7", + "/usr/share/man/he_IL/man7x", + "/usr/share/man/he_IL/man8", + "/usr/share/man/he_IL/man8x", + "/usr/share/man/he_IL/man9", + "/usr/share/man/he_IL/man9x", + "/usr/share/man/he_IL/mann", + "/usr/share/man/hi", + "/usr/share/man/hi/man0p", + "/usr/share/man/hi/man1", + "/usr/share/man/hi/man1p", + "/usr/share/man/hi/man1x", + "/usr/share/man/hi/man2", + "/usr/share/man/hi/man2x", + "/usr/share/man/hi/man3", + "/usr/share/man/hi/man3p", + "/usr/share/man/hi/man3x", + "/usr/share/man/hi/man4", + "/usr/share/man/hi/man4x", + "/usr/share/man/hi/man5", + "/usr/share/man/hi/man5x", + "/usr/share/man/hi/man6", + "/usr/share/man/hi/man6x", + "/usr/share/man/hi/man7", + "/usr/share/man/hi/man7x", + "/usr/share/man/hi/man8", + "/usr/share/man/hi/man8x", + "/usr/share/man/hi/man9", + "/usr/share/man/hi/man9x", + "/usr/share/man/hi/mann", + "/usr/share/man/hi_IN", + "/usr/share/man/hi_IN/man0p", + "/usr/share/man/hi_IN/man1", + "/usr/share/man/hi_IN/man1p", + "/usr/share/man/hi_IN/man1x", + "/usr/share/man/hi_IN/man2", + "/usr/share/man/hi_IN/man2x", + "/usr/share/man/hi_IN/man3", + "/usr/share/man/hi_IN/man3p", + "/usr/share/man/hi_IN/man3x", + "/usr/share/man/hi_IN/man4", + "/usr/share/man/hi_IN/man4x", + "/usr/share/man/hi_IN/man5", + "/usr/share/man/hi_IN/man5x", + "/usr/share/man/hi_IN/man6", + "/usr/share/man/hi_IN/man6x", + "/usr/share/man/hi_IN/man7", + "/usr/share/man/hi_IN/man7x", + "/usr/share/man/hi_IN/man8", + "/usr/share/man/hi_IN/man8x", + "/usr/share/man/hi_IN/man9", + "/usr/share/man/hi_IN/man9x", + "/usr/share/man/hi_IN/mann", + "/usr/share/man/hil", + "/usr/share/man/hil/man0p", + "/usr/share/man/hil/man1", + "/usr/share/man/hil/man1p", + "/usr/share/man/hil/man1x", + "/usr/share/man/hil/man2", + "/usr/share/man/hil/man2x", + "/usr/share/man/hil/man3", + "/usr/share/man/hil/man3p", + "/usr/share/man/hil/man3x", + "/usr/share/man/hil/man4", + "/usr/share/man/hil/man4x", + "/usr/share/man/hil/man5", + "/usr/share/man/hil/man5x", + "/usr/share/man/hil/man6", + "/usr/share/man/hil/man6x", + "/usr/share/man/hil/man7", + "/usr/share/man/hil/man7x", + "/usr/share/man/hil/man8", + "/usr/share/man/hil/man8x", + "/usr/share/man/hil/man9", + "/usr/share/man/hil/man9x", + "/usr/share/man/hil/mann", + "/usr/share/man/him", + "/usr/share/man/him/man0p", + "/usr/share/man/him/man1", + "/usr/share/man/him/man1p", + "/usr/share/man/him/man1x", + "/usr/share/man/him/man2", + "/usr/share/man/him/man2x", + "/usr/share/man/him/man3", + "/usr/share/man/him/man3p", + "/usr/share/man/him/man3x", + "/usr/share/man/him/man4", + "/usr/share/man/him/man4x", + "/usr/share/man/him/man5", + "/usr/share/man/him/man5x", + "/usr/share/man/him/man6", + "/usr/share/man/him/man6x", + "/usr/share/man/him/man7", + "/usr/share/man/him/man7x", + "/usr/share/man/him/man8", + "/usr/share/man/him/man8x", + "/usr/share/man/him/man9", + "/usr/share/man/him/man9x", + "/usr/share/man/him/mann", + "/usr/share/man/hit", + "/usr/share/man/hit/man0p", + "/usr/share/man/hit/man1", + "/usr/share/man/hit/man1p", + "/usr/share/man/hit/man1x", + "/usr/share/man/hit/man2", + "/usr/share/man/hit/man2x", + "/usr/share/man/hit/man3", + "/usr/share/man/hit/man3p", + "/usr/share/man/hit/man3x", + "/usr/share/man/hit/man4", + "/usr/share/man/hit/man4x", + "/usr/share/man/hit/man5", + "/usr/share/man/hit/man5x", + "/usr/share/man/hit/man6", + "/usr/share/man/hit/man6x", + "/usr/share/man/hit/man7", + "/usr/share/man/hit/man7x", + "/usr/share/man/hit/man8", + "/usr/share/man/hit/man8x", + "/usr/share/man/hit/man9", + "/usr/share/man/hit/man9x", + "/usr/share/man/hit/mann", + "/usr/share/man/hmn", + "/usr/share/man/hmn/man0p", + "/usr/share/man/hmn/man1", + "/usr/share/man/hmn/man1p", + "/usr/share/man/hmn/man1x", + "/usr/share/man/hmn/man2", + "/usr/share/man/hmn/man2x", + "/usr/share/man/hmn/man3", + "/usr/share/man/hmn/man3p", + "/usr/share/man/hmn/man3x", + "/usr/share/man/hmn/man4", + "/usr/share/man/hmn/man4x", + "/usr/share/man/hmn/man5", + "/usr/share/man/hmn/man5x", + "/usr/share/man/hmn/man6", + "/usr/share/man/hmn/man6x", + "/usr/share/man/hmn/man7", + "/usr/share/man/hmn/man7x", + "/usr/share/man/hmn/man8", + "/usr/share/man/hmn/man8x", + "/usr/share/man/hmn/man9", + "/usr/share/man/hmn/man9x", + "/usr/share/man/hmn/mann", + "/usr/share/man/hne", + "/usr/share/man/hne/man0p", + "/usr/share/man/hne/man1", + "/usr/share/man/hne/man1p", + "/usr/share/man/hne/man1x", + "/usr/share/man/hne/man2", + "/usr/share/man/hne/man2x", + "/usr/share/man/hne/man3", + "/usr/share/man/hne/man3p", + "/usr/share/man/hne/man3x", + "/usr/share/man/hne/man4", + "/usr/share/man/hne/man4x", + "/usr/share/man/hne/man5", + "/usr/share/man/hne/man5x", + "/usr/share/man/hne/man6", + "/usr/share/man/hne/man6x", + "/usr/share/man/hne/man7", + "/usr/share/man/hne/man7x", + "/usr/share/man/hne/man8", + "/usr/share/man/hne/man8x", + "/usr/share/man/hne/man9", + "/usr/share/man/hne/man9x", + "/usr/share/man/hne/mann", + "/usr/share/man/ho", + "/usr/share/man/ho/man0p", + "/usr/share/man/ho/man1", + "/usr/share/man/ho/man1p", + "/usr/share/man/ho/man1x", + "/usr/share/man/ho/man2", + "/usr/share/man/ho/man2x", + "/usr/share/man/ho/man3", + "/usr/share/man/ho/man3p", + "/usr/share/man/ho/man3x", + "/usr/share/man/ho/man4", + "/usr/share/man/ho/man4x", + "/usr/share/man/ho/man5", + "/usr/share/man/ho/man5x", + "/usr/share/man/ho/man6", + "/usr/share/man/ho/man6x", + "/usr/share/man/ho/man7", + "/usr/share/man/ho/man7x", + "/usr/share/man/ho/man8", + "/usr/share/man/ho/man8x", + "/usr/share/man/ho/man9", + "/usr/share/man/ho/man9x", + "/usr/share/man/ho/mann", + "/usr/share/man/hr", + "/usr/share/man/hr/man0p", + "/usr/share/man/hr/man1", + "/usr/share/man/hr/man1p", + "/usr/share/man/hr/man1x", + "/usr/share/man/hr/man2", + "/usr/share/man/hr/man2x", + "/usr/share/man/hr/man3", + "/usr/share/man/hr/man3p", + "/usr/share/man/hr/man3x", + "/usr/share/man/hr/man4", + "/usr/share/man/hr/man4x", + "/usr/share/man/hr/man5", + "/usr/share/man/hr/man5x", + "/usr/share/man/hr/man6", + "/usr/share/man/hr/man6x", + "/usr/share/man/hr/man7", + "/usr/share/man/hr/man7x", + "/usr/share/man/hr/man8", + "/usr/share/man/hr/man8x", + "/usr/share/man/hr/man9", + "/usr/share/man/hr/man9x", + "/usr/share/man/hr/mann", + "/usr/share/man/hr_HR", + "/usr/share/man/hr_HR/man0p", + "/usr/share/man/hr_HR/man1", + "/usr/share/man/hr_HR/man1p", + "/usr/share/man/hr_HR/man1x", + "/usr/share/man/hr_HR/man2", + "/usr/share/man/hr_HR/man2x", + "/usr/share/man/hr_HR/man3", + "/usr/share/man/hr_HR/man3p", + "/usr/share/man/hr_HR/man3x", + "/usr/share/man/hr_HR/man4", + "/usr/share/man/hr_HR/man4x", + "/usr/share/man/hr_HR/man5", + "/usr/share/man/hr_HR/man5x", + "/usr/share/man/hr_HR/man6", + "/usr/share/man/hr_HR/man6x", + "/usr/share/man/hr_HR/man7", + "/usr/share/man/hr_HR/man7x", + "/usr/share/man/hr_HR/man8", + "/usr/share/man/hr_HR/man8x", + "/usr/share/man/hr_HR/man9", + "/usr/share/man/hr_HR/man9x", + "/usr/share/man/hr_HR/mann", + "/usr/share/man/hsb", + "/usr/share/man/hsb/man0p", + "/usr/share/man/hsb/man1", + "/usr/share/man/hsb/man1p", + "/usr/share/man/hsb/man1x", + "/usr/share/man/hsb/man2", + "/usr/share/man/hsb/man2x", + "/usr/share/man/hsb/man3", + "/usr/share/man/hsb/man3p", + "/usr/share/man/hsb/man3x", + "/usr/share/man/hsb/man4", + "/usr/share/man/hsb/man4x", + "/usr/share/man/hsb/man5", + "/usr/share/man/hsb/man5x", + "/usr/share/man/hsb/man6", + "/usr/share/man/hsb/man6x", + "/usr/share/man/hsb/man7", + "/usr/share/man/hsb/man7x", + "/usr/share/man/hsb/man8", + "/usr/share/man/hsb/man8x", + "/usr/share/man/hsb/man9", + "/usr/share/man/hsb/man9x", + "/usr/share/man/hsb/mann", + "/usr/share/man/ht", + "/usr/share/man/ht/man0p", + "/usr/share/man/ht/man1", + "/usr/share/man/ht/man1p", + "/usr/share/man/ht/man1x", + "/usr/share/man/ht/man2", + "/usr/share/man/ht/man2x", + "/usr/share/man/ht/man3", + "/usr/share/man/ht/man3p", + "/usr/share/man/ht/man3x", + "/usr/share/man/ht/man4", + "/usr/share/man/ht/man4x", + "/usr/share/man/ht/man5", + "/usr/share/man/ht/man5x", + "/usr/share/man/ht/man6", + "/usr/share/man/ht/man6x", + "/usr/share/man/ht/man7", + "/usr/share/man/ht/man7x", + "/usr/share/man/ht/man8", + "/usr/share/man/ht/man8x", + "/usr/share/man/ht/man9", + "/usr/share/man/ht/man9x", + "/usr/share/man/ht/mann", + "/usr/share/man/hu", + "/usr/share/man/hu/man0p", + "/usr/share/man/hu/man1", + "/usr/share/man/hu/man1p", + "/usr/share/man/hu/man1x", + "/usr/share/man/hu/man2", + "/usr/share/man/hu/man2x", + "/usr/share/man/hu/man3", + "/usr/share/man/hu/man3p", + "/usr/share/man/hu/man3x", + "/usr/share/man/hu/man4", + "/usr/share/man/hu/man4x", + "/usr/share/man/hu/man5", + "/usr/share/man/hu/man5x", + "/usr/share/man/hu/man6", + "/usr/share/man/hu/man6x", + "/usr/share/man/hu/man7", + "/usr/share/man/hu/man7x", + "/usr/share/man/hu/man8", + "/usr/share/man/hu/man8x", + "/usr/share/man/hu/man9", + "/usr/share/man/hu/man9x", + "/usr/share/man/hu/mann", + "/usr/share/man/hu_HU", + "/usr/share/man/hu_HU/man0p", + "/usr/share/man/hu_HU/man1", + "/usr/share/man/hu_HU/man1p", + "/usr/share/man/hu_HU/man1x", + "/usr/share/man/hu_HU/man2", + "/usr/share/man/hu_HU/man2x", + "/usr/share/man/hu_HU/man3", + "/usr/share/man/hu_HU/man3p", + "/usr/share/man/hu_HU/man3x", + "/usr/share/man/hu_HU/man4", + "/usr/share/man/hu_HU/man4x", + "/usr/share/man/hu_HU/man5", + "/usr/share/man/hu_HU/man5x", + "/usr/share/man/hu_HU/man6", + "/usr/share/man/hu_HU/man6x", + "/usr/share/man/hu_HU/man7", + "/usr/share/man/hu_HU/man7x", + "/usr/share/man/hu_HU/man8", + "/usr/share/man/hu_HU/man8x", + "/usr/share/man/hu_HU/man9", + "/usr/share/man/hu_HU/man9x", + "/usr/share/man/hu_HU/mann", + "/usr/share/man/hup", + "/usr/share/man/hup/man0p", + "/usr/share/man/hup/man1", + "/usr/share/man/hup/man1p", + "/usr/share/man/hup/man1x", + "/usr/share/man/hup/man2", + "/usr/share/man/hup/man2x", + "/usr/share/man/hup/man3", + "/usr/share/man/hup/man3p", + "/usr/share/man/hup/man3x", + "/usr/share/man/hup/man4", + "/usr/share/man/hup/man4x", + "/usr/share/man/hup/man5", + "/usr/share/man/hup/man5x", + "/usr/share/man/hup/man6", + "/usr/share/man/hup/man6x", + "/usr/share/man/hup/man7", + "/usr/share/man/hup/man7x", + "/usr/share/man/hup/man8", + "/usr/share/man/hup/man8x", + "/usr/share/man/hup/man9", + "/usr/share/man/hup/man9x", + "/usr/share/man/hup/mann", + "/usr/share/man/hus", + "/usr/share/man/hus/man0p", + "/usr/share/man/hus/man1", + "/usr/share/man/hus/man1p", + "/usr/share/man/hus/man1x", + "/usr/share/man/hus/man2", + "/usr/share/man/hus/man2x", + "/usr/share/man/hus/man3", + "/usr/share/man/hus/man3p", + "/usr/share/man/hus/man3x", + "/usr/share/man/hus/man4", + "/usr/share/man/hus/man4x", + "/usr/share/man/hus/man5", + "/usr/share/man/hus/man5x", + "/usr/share/man/hus/man6", + "/usr/share/man/hus/man6x", + "/usr/share/man/hus/man7", + "/usr/share/man/hus/man7x", + "/usr/share/man/hus/man8", + "/usr/share/man/hus/man8x", + "/usr/share/man/hus/man9", + "/usr/share/man/hus/man9x", + "/usr/share/man/hus/mann", + "/usr/share/man/hy", + "/usr/share/man/hy/man0p", + "/usr/share/man/hy/man1", + "/usr/share/man/hy/man1p", + "/usr/share/man/hy/man1x", + "/usr/share/man/hy/man2", + "/usr/share/man/hy/man2x", + "/usr/share/man/hy/man3", + "/usr/share/man/hy/man3p", + "/usr/share/man/hy/man3x", + "/usr/share/man/hy/man4", + "/usr/share/man/hy/man4x", + "/usr/share/man/hy/man5", + "/usr/share/man/hy/man5x", + "/usr/share/man/hy/man6", + "/usr/share/man/hy/man6x", + "/usr/share/man/hy/man7", + "/usr/share/man/hy/man7x", + "/usr/share/man/hy/man8", + "/usr/share/man/hy/man8x", + "/usr/share/man/hy/man9", + "/usr/share/man/hy/man9x", + "/usr/share/man/hy/mann", + "/usr/share/man/hz", + "/usr/share/man/hz/man0p", + "/usr/share/man/hz/man1", + "/usr/share/man/hz/man1p", + "/usr/share/man/hz/man1x", + "/usr/share/man/hz/man2", + "/usr/share/man/hz/man2x", + "/usr/share/man/hz/man3", + "/usr/share/man/hz/man3p", + "/usr/share/man/hz/man3x", + "/usr/share/man/hz/man4", + "/usr/share/man/hz/man4x", + "/usr/share/man/hz/man5", + "/usr/share/man/hz/man5x", + "/usr/share/man/hz/man6", + "/usr/share/man/hz/man6x", + "/usr/share/man/hz/man7", + "/usr/share/man/hz/man7x", + "/usr/share/man/hz/man8", + "/usr/share/man/hz/man8x", + "/usr/share/man/hz/man9", + "/usr/share/man/hz/man9x", + "/usr/share/man/hz/mann", + "/usr/share/man/ia", + "/usr/share/man/ia/man0p", + "/usr/share/man/ia/man1", + "/usr/share/man/ia/man1p", + "/usr/share/man/ia/man1x", + "/usr/share/man/ia/man2", + "/usr/share/man/ia/man2x", + "/usr/share/man/ia/man3", + "/usr/share/man/ia/man3p", + "/usr/share/man/ia/man3x", + "/usr/share/man/ia/man4", + "/usr/share/man/ia/man4x", + "/usr/share/man/ia/man5", + "/usr/share/man/ia/man5x", + "/usr/share/man/ia/man6", + "/usr/share/man/ia/man6x", + "/usr/share/man/ia/man7", + "/usr/share/man/ia/man7x", + "/usr/share/man/ia/man8", + "/usr/share/man/ia/man8x", + "/usr/share/man/ia/man9", + "/usr/share/man/ia/man9x", + "/usr/share/man/ia/mann", + "/usr/share/man/iba", + "/usr/share/man/iba/man0p", + "/usr/share/man/iba/man1", + "/usr/share/man/iba/man1p", + "/usr/share/man/iba/man1x", + "/usr/share/man/iba/man2", + "/usr/share/man/iba/man2x", + "/usr/share/man/iba/man3", + "/usr/share/man/iba/man3p", + "/usr/share/man/iba/man3x", + "/usr/share/man/iba/man4", + "/usr/share/man/iba/man4x", + "/usr/share/man/iba/man5", + "/usr/share/man/iba/man5x", + "/usr/share/man/iba/man6", + "/usr/share/man/iba/man6x", + "/usr/share/man/iba/man7", + "/usr/share/man/iba/man7x", + "/usr/share/man/iba/man8", + "/usr/share/man/iba/man8x", + "/usr/share/man/iba/man9", + "/usr/share/man/iba/man9x", + "/usr/share/man/iba/mann", + "/usr/share/man/ibo", + "/usr/share/man/ibo/man0p", + "/usr/share/man/ibo/man1", + "/usr/share/man/ibo/man1p", + "/usr/share/man/ibo/man1x", + "/usr/share/man/ibo/man2", + "/usr/share/man/ibo/man2x", + "/usr/share/man/ibo/man3", + "/usr/share/man/ibo/man3p", + "/usr/share/man/ibo/man3x", + "/usr/share/man/ibo/man4", + "/usr/share/man/ibo/man4x", + "/usr/share/man/ibo/man5", + "/usr/share/man/ibo/man5x", + "/usr/share/man/ibo/man6", + "/usr/share/man/ibo/man6x", + "/usr/share/man/ibo/man7", + "/usr/share/man/ibo/man7x", + "/usr/share/man/ibo/man8", + "/usr/share/man/ibo/man8x", + "/usr/share/man/ibo/man9", + "/usr/share/man/ibo/man9x", + "/usr/share/man/ibo/mann", + "/usr/share/man/id", + "/usr/share/man/id/man0p", + "/usr/share/man/id/man1", + "/usr/share/man/id/man1p", + "/usr/share/man/id/man1x", + "/usr/share/man/id/man2", + "/usr/share/man/id/man2x", + "/usr/share/man/id/man3", + "/usr/share/man/id/man3p", + "/usr/share/man/id/man3x", + "/usr/share/man/id/man4", + "/usr/share/man/id/man4x", + "/usr/share/man/id/man5", + "/usr/share/man/id/man5x", + "/usr/share/man/id/man6", + "/usr/share/man/id/man6x", + "/usr/share/man/id/man7", + "/usr/share/man/id/man7x", + "/usr/share/man/id/man8", + "/usr/share/man/id/man8x", + "/usr/share/man/id/man9", + "/usr/share/man/id/man9x", + "/usr/share/man/id/mann", + "/usr/share/man/id_ID", + "/usr/share/man/id_ID/man0p", + "/usr/share/man/id_ID/man1", + "/usr/share/man/id_ID/man1p", + "/usr/share/man/id_ID/man1x", + "/usr/share/man/id_ID/man2", + "/usr/share/man/id_ID/man2x", + "/usr/share/man/id_ID/man3", + "/usr/share/man/id_ID/man3p", + "/usr/share/man/id_ID/man3x", + "/usr/share/man/id_ID/man4", + "/usr/share/man/id_ID/man4x", + "/usr/share/man/id_ID/man5", + "/usr/share/man/id_ID/man5x", + "/usr/share/man/id_ID/man6", + "/usr/share/man/id_ID/man6x", + "/usr/share/man/id_ID/man7", + "/usr/share/man/id_ID/man7x", + "/usr/share/man/id_ID/man8", + "/usr/share/man/id_ID/man8x", + "/usr/share/man/id_ID/man9", + "/usr/share/man/id_ID/man9x", + "/usr/share/man/id_ID/mann", + "/usr/share/man/ie", + "/usr/share/man/ie/man0p", + "/usr/share/man/ie/man1", + "/usr/share/man/ie/man1p", + "/usr/share/man/ie/man1x", + "/usr/share/man/ie/man2", + "/usr/share/man/ie/man2x", + "/usr/share/man/ie/man3", + "/usr/share/man/ie/man3p", + "/usr/share/man/ie/man3x", + "/usr/share/man/ie/man4", + "/usr/share/man/ie/man4x", + "/usr/share/man/ie/man5", + "/usr/share/man/ie/man5x", + "/usr/share/man/ie/man6", + "/usr/share/man/ie/man6x", + "/usr/share/man/ie/man7", + "/usr/share/man/ie/man7x", + "/usr/share/man/ie/man8", + "/usr/share/man/ie/man8x", + "/usr/share/man/ie/man9", + "/usr/share/man/ie/man9x", + "/usr/share/man/ie/mann", + "/usr/share/man/ig", + "/usr/share/man/ig/man0p", + "/usr/share/man/ig/man1", + "/usr/share/man/ig/man1p", + "/usr/share/man/ig/man1x", + "/usr/share/man/ig/man2", + "/usr/share/man/ig/man2x", + "/usr/share/man/ig/man3", + "/usr/share/man/ig/man3p", + "/usr/share/man/ig/man3x", + "/usr/share/man/ig/man4", + "/usr/share/man/ig/man4x", + "/usr/share/man/ig/man5", + "/usr/share/man/ig/man5x", + "/usr/share/man/ig/man6", + "/usr/share/man/ig/man6x", + "/usr/share/man/ig/man7", + "/usr/share/man/ig/man7x", + "/usr/share/man/ig/man8", + "/usr/share/man/ig/man8x", + "/usr/share/man/ig/man9", + "/usr/share/man/ig/man9x", + "/usr/share/man/ig/mann", + "/usr/share/man/ii", + "/usr/share/man/ii/man0p", + "/usr/share/man/ii/man1", + "/usr/share/man/ii/man1p", + "/usr/share/man/ii/man1x", + "/usr/share/man/ii/man2", + "/usr/share/man/ii/man2x", + "/usr/share/man/ii/man3", + "/usr/share/man/ii/man3p", + "/usr/share/man/ii/man3x", + "/usr/share/man/ii/man4", + "/usr/share/man/ii/man4x", + "/usr/share/man/ii/man5", + "/usr/share/man/ii/man5x", + "/usr/share/man/ii/man6", + "/usr/share/man/ii/man6x", + "/usr/share/man/ii/man7", + "/usr/share/man/ii/man7x", + "/usr/share/man/ii/man8", + "/usr/share/man/ii/man8x", + "/usr/share/man/ii/man9", + "/usr/share/man/ii/man9x", + "/usr/share/man/ii/mann", + "/usr/share/man/ijo", + "/usr/share/man/ijo/man0p", + "/usr/share/man/ijo/man1", + "/usr/share/man/ijo/man1p", + "/usr/share/man/ijo/man1x", + "/usr/share/man/ijo/man2", + "/usr/share/man/ijo/man2x", + "/usr/share/man/ijo/man3", + "/usr/share/man/ijo/man3p", + "/usr/share/man/ijo/man3x", + "/usr/share/man/ijo/man4", + "/usr/share/man/ijo/man4x", + "/usr/share/man/ijo/man5", + "/usr/share/man/ijo/man5x", + "/usr/share/man/ijo/man6", + "/usr/share/man/ijo/man6x", + "/usr/share/man/ijo/man7", + "/usr/share/man/ijo/man7x", + "/usr/share/man/ijo/man8", + "/usr/share/man/ijo/man8x", + "/usr/share/man/ijo/man9", + "/usr/share/man/ijo/man9x", + "/usr/share/man/ijo/mann", + "/usr/share/man/ik", + "/usr/share/man/ik/man0p", + "/usr/share/man/ik/man1", + "/usr/share/man/ik/man1p", + "/usr/share/man/ik/man1x", + "/usr/share/man/ik/man2", + "/usr/share/man/ik/man2x", + "/usr/share/man/ik/man3", + "/usr/share/man/ik/man3p", + "/usr/share/man/ik/man3x", + "/usr/share/man/ik/man4", + "/usr/share/man/ik/man4x", + "/usr/share/man/ik/man5", + "/usr/share/man/ik/man5x", + "/usr/share/man/ik/man6", + "/usr/share/man/ik/man6x", + "/usr/share/man/ik/man7", + "/usr/share/man/ik/man7x", + "/usr/share/man/ik/man8", + "/usr/share/man/ik/man8x", + "/usr/share/man/ik/man9", + "/usr/share/man/ik/man9x", + "/usr/share/man/ik/mann", + "/usr/share/man/ilo", + "/usr/share/man/ilo/man0p", + "/usr/share/man/ilo/man1", + "/usr/share/man/ilo/man1p", + "/usr/share/man/ilo/man1x", + "/usr/share/man/ilo/man2", + "/usr/share/man/ilo/man2x", + "/usr/share/man/ilo/man3", + "/usr/share/man/ilo/man3p", + "/usr/share/man/ilo/man3x", + "/usr/share/man/ilo/man4", + "/usr/share/man/ilo/man4x", + "/usr/share/man/ilo/man5", + "/usr/share/man/ilo/man5x", + "/usr/share/man/ilo/man6", + "/usr/share/man/ilo/man6x", + "/usr/share/man/ilo/man7", + "/usr/share/man/ilo/man7x", + "/usr/share/man/ilo/man8", + "/usr/share/man/ilo/man8x", + "/usr/share/man/ilo/man9", + "/usr/share/man/ilo/man9x", + "/usr/share/man/ilo/mann", + "/usr/share/man/inc", + "/usr/share/man/inc/man0p", + "/usr/share/man/inc/man1", + "/usr/share/man/inc/man1p", + "/usr/share/man/inc/man1x", + "/usr/share/man/inc/man2", + "/usr/share/man/inc/man2x", + "/usr/share/man/inc/man3", + "/usr/share/man/inc/man3p", + "/usr/share/man/inc/man3x", + "/usr/share/man/inc/man4", + "/usr/share/man/inc/man4x", + "/usr/share/man/inc/man5", + "/usr/share/man/inc/man5x", + "/usr/share/man/inc/man6", + "/usr/share/man/inc/man6x", + "/usr/share/man/inc/man7", + "/usr/share/man/inc/man7x", + "/usr/share/man/inc/man8", + "/usr/share/man/inc/man8x", + "/usr/share/man/inc/man9", + "/usr/share/man/inc/man9x", + "/usr/share/man/inc/mann", + "/usr/share/man/ine", + "/usr/share/man/ine/man0p", + "/usr/share/man/ine/man1", + "/usr/share/man/ine/man1p", + "/usr/share/man/ine/man1x", + "/usr/share/man/ine/man2", + "/usr/share/man/ine/man2x", + "/usr/share/man/ine/man3", + "/usr/share/man/ine/man3p", + "/usr/share/man/ine/man3x", + "/usr/share/man/ine/man4", + "/usr/share/man/ine/man4x", + "/usr/share/man/ine/man5", + "/usr/share/man/ine/man5x", + "/usr/share/man/ine/man6", + "/usr/share/man/ine/man6x", + "/usr/share/man/ine/man7", + "/usr/share/man/ine/man7x", + "/usr/share/man/ine/man8", + "/usr/share/man/ine/man8x", + "/usr/share/man/ine/man9", + "/usr/share/man/ine/man9x", + "/usr/share/man/ine/mann", + "/usr/share/man/inh", + "/usr/share/man/inh/man0p", + "/usr/share/man/inh/man1", + "/usr/share/man/inh/man1p", + "/usr/share/man/inh/man1x", + "/usr/share/man/inh/man2", + "/usr/share/man/inh/man2x", + "/usr/share/man/inh/man3", + "/usr/share/man/inh/man3p", + "/usr/share/man/inh/man3x", + "/usr/share/man/inh/man4", + "/usr/share/man/inh/man4x", + "/usr/share/man/inh/man5", + "/usr/share/man/inh/man5x", + "/usr/share/man/inh/man6", + "/usr/share/man/inh/man6x", + "/usr/share/man/inh/man7", + "/usr/share/man/inh/man7x", + "/usr/share/man/inh/man8", + "/usr/share/man/inh/man8x", + "/usr/share/man/inh/man9", + "/usr/share/man/inh/man9x", + "/usr/share/man/inh/mann", + "/usr/share/man/io", + "/usr/share/man/io/man0p", + "/usr/share/man/io/man1", + "/usr/share/man/io/man1p", + "/usr/share/man/io/man1x", + "/usr/share/man/io/man2", + "/usr/share/man/io/man2x", + "/usr/share/man/io/man3", + "/usr/share/man/io/man3p", + "/usr/share/man/io/man3x", + "/usr/share/man/io/man4", + "/usr/share/man/io/man4x", + "/usr/share/man/io/man5", + "/usr/share/man/io/man5x", + "/usr/share/man/io/man6", + "/usr/share/man/io/man6x", + "/usr/share/man/io/man7", + "/usr/share/man/io/man7x", + "/usr/share/man/io/man8", + "/usr/share/man/io/man8x", + "/usr/share/man/io/man9", + "/usr/share/man/io/man9x", + "/usr/share/man/io/mann", + "/usr/share/man/ira", + "/usr/share/man/ira/man0p", + "/usr/share/man/ira/man1", + "/usr/share/man/ira/man1p", + "/usr/share/man/ira/man1x", + "/usr/share/man/ira/man2", + "/usr/share/man/ira/man2x", + "/usr/share/man/ira/man3", + "/usr/share/man/ira/man3p", + "/usr/share/man/ira/man3x", + "/usr/share/man/ira/man4", + "/usr/share/man/ira/man4x", + "/usr/share/man/ira/man5", + "/usr/share/man/ira/man5x", + "/usr/share/man/ira/man6", + "/usr/share/man/ira/man6x", + "/usr/share/man/ira/man7", + "/usr/share/man/ira/man7x", + "/usr/share/man/ira/man8", + "/usr/share/man/ira/man8x", + "/usr/share/man/ira/man9", + "/usr/share/man/ira/man9x", + "/usr/share/man/ira/mann", + "/usr/share/man/iro", + "/usr/share/man/iro/man0p", + "/usr/share/man/iro/man1", + "/usr/share/man/iro/man1p", + "/usr/share/man/iro/man1x", + "/usr/share/man/iro/man2", + "/usr/share/man/iro/man2x", + "/usr/share/man/iro/man3", + "/usr/share/man/iro/man3p", + "/usr/share/man/iro/man3x", + "/usr/share/man/iro/man4", + "/usr/share/man/iro/man4x", + "/usr/share/man/iro/man5", + "/usr/share/man/iro/man5x", + "/usr/share/man/iro/man6", + "/usr/share/man/iro/man6x", + "/usr/share/man/iro/man7", + "/usr/share/man/iro/man7x", + "/usr/share/man/iro/man8", + "/usr/share/man/iro/man8x", + "/usr/share/man/iro/man9", + "/usr/share/man/iro/man9x", + "/usr/share/man/iro/mann", + "/usr/share/man/is", + "/usr/share/man/is/man0p", + "/usr/share/man/is/man1", + "/usr/share/man/is/man1p", + "/usr/share/man/is/man1x", + "/usr/share/man/is/man2", + "/usr/share/man/is/man2x", + "/usr/share/man/is/man3", + "/usr/share/man/is/man3p", + "/usr/share/man/is/man3x", + "/usr/share/man/is/man4", + "/usr/share/man/is/man4x", + "/usr/share/man/is/man5", + "/usr/share/man/is/man5x", + "/usr/share/man/is/man6", + "/usr/share/man/is/man6x", + "/usr/share/man/is/man7", + "/usr/share/man/is/man7x", + "/usr/share/man/is/man8", + "/usr/share/man/is/man8x", + "/usr/share/man/is/man9", + "/usr/share/man/is/man9x", + "/usr/share/man/is/mann", + "/usr/share/man/it", + "/usr/share/man/it/man0p", + "/usr/share/man/it/man1", + "/usr/share/man/it/man1p", + "/usr/share/man/it/man1x", + "/usr/share/man/it/man2", + "/usr/share/man/it/man2x", + "/usr/share/man/it/man3", + "/usr/share/man/it/man3p", + "/usr/share/man/it/man3x", + "/usr/share/man/it/man4", + "/usr/share/man/it/man4x", + "/usr/share/man/it/man5", + "/usr/share/man/it/man5x", + "/usr/share/man/it/man6", + "/usr/share/man/it/man6x", + "/usr/share/man/it/man7", + "/usr/share/man/it/man7x", + "/usr/share/man/it/man8", + "/usr/share/man/it/man8x", + "/usr/share/man/it/man9", + "/usr/share/man/it/man9x", + "/usr/share/man/it/mann", + "/usr/share/man/it_IT", + "/usr/share/man/it_IT/man0p", + "/usr/share/man/it_IT/man1", + "/usr/share/man/it_IT/man1p", + "/usr/share/man/it_IT/man1x", + "/usr/share/man/it_IT/man2", + "/usr/share/man/it_IT/man2x", + "/usr/share/man/it_IT/man3", + "/usr/share/man/it_IT/man3p", + "/usr/share/man/it_IT/man3x", + "/usr/share/man/it_IT/man4", + "/usr/share/man/it_IT/man4x", + "/usr/share/man/it_IT/man5", + "/usr/share/man/it_IT/man5x", + "/usr/share/man/it_IT/man6", + "/usr/share/man/it_IT/man6x", + "/usr/share/man/it_IT/man7", + "/usr/share/man/it_IT/man7x", + "/usr/share/man/it_IT/man8", + "/usr/share/man/it_IT/man8x", + "/usr/share/man/it_IT/man9", + "/usr/share/man/it_IT/man9x", + "/usr/share/man/it_IT/mann", + "/usr/share/man/iu", + "/usr/share/man/iu/man0p", + "/usr/share/man/iu/man1", + "/usr/share/man/iu/man1p", + "/usr/share/man/iu/man1x", + "/usr/share/man/iu/man2", + "/usr/share/man/iu/man2x", + "/usr/share/man/iu/man3", + "/usr/share/man/iu/man3p", + "/usr/share/man/iu/man3x", + "/usr/share/man/iu/man4", + "/usr/share/man/iu/man4x", + "/usr/share/man/iu/man5", + "/usr/share/man/iu/man5x", + "/usr/share/man/iu/man6", + "/usr/share/man/iu/man6x", + "/usr/share/man/iu/man7", + "/usr/share/man/iu/man7x", + "/usr/share/man/iu/man8", + "/usr/share/man/iu/man8x", + "/usr/share/man/iu/man9", + "/usr/share/man/iu/man9x", + "/usr/share/man/iu/mann", + "/usr/share/man/ja", + "/usr/share/man/ja.euc-jp", + "/usr/share/man/ja.euc-jp/man0p", + "/usr/share/man/ja.euc-jp/man1", + "/usr/share/man/ja.euc-jp/man1p", + "/usr/share/man/ja.euc-jp/man1x", + "/usr/share/man/ja.euc-jp/man2", + "/usr/share/man/ja.euc-jp/man2x", + "/usr/share/man/ja.euc-jp/man3", + "/usr/share/man/ja.euc-jp/man3p", + "/usr/share/man/ja.euc-jp/man3x", + "/usr/share/man/ja.euc-jp/man4", + "/usr/share/man/ja.euc-jp/man4x", + "/usr/share/man/ja.euc-jp/man5", + "/usr/share/man/ja.euc-jp/man5x", + "/usr/share/man/ja.euc-jp/man6", + "/usr/share/man/ja.euc-jp/man6x", + "/usr/share/man/ja.euc-jp/man7", + "/usr/share/man/ja.euc-jp/man7x", + "/usr/share/man/ja.euc-jp/man8", + "/usr/share/man/ja.euc-jp/man8x", + "/usr/share/man/ja.euc-jp/man9", + "/usr/share/man/ja.euc-jp/man9x", + "/usr/share/man/ja.euc-jp/mann", + "/usr/share/man/ja/man0p", + "/usr/share/man/ja/man1", + "/usr/share/man/ja/man1p", + "/usr/share/man/ja/man1x", + "/usr/share/man/ja/man2", + "/usr/share/man/ja/man2x", + "/usr/share/man/ja/man3", + "/usr/share/man/ja/man3p", + "/usr/share/man/ja/man3x", + "/usr/share/man/ja/man4", + "/usr/share/man/ja/man4x", + "/usr/share/man/ja/man5", + "/usr/share/man/ja/man5x", + "/usr/share/man/ja/man6", + "/usr/share/man/ja/man6x", + "/usr/share/man/ja/man7", + "/usr/share/man/ja/man7x", + "/usr/share/man/ja/man8", + "/usr/share/man/ja/man8x", + "/usr/share/man/ja/man9", + "/usr/share/man/ja/man9x", + "/usr/share/man/ja/mann", + "/usr/share/man/ja_JP", + "/usr/share/man/ja_JP/man0p", + "/usr/share/man/ja_JP/man1", + "/usr/share/man/ja_JP/man1p", + "/usr/share/man/ja_JP/man1x", + "/usr/share/man/ja_JP/man2", + "/usr/share/man/ja_JP/man2x", + "/usr/share/man/ja_JP/man3", + "/usr/share/man/ja_JP/man3p", + "/usr/share/man/ja_JP/man3x", + "/usr/share/man/ja_JP/man4", + "/usr/share/man/ja_JP/man4x", + "/usr/share/man/ja_JP/man5", + "/usr/share/man/ja_JP/man5x", + "/usr/share/man/ja_JP/man6", + "/usr/share/man/ja_JP/man6x", + "/usr/share/man/ja_JP/man7", + "/usr/share/man/ja_JP/man7x", + "/usr/share/man/ja_JP/man8", + "/usr/share/man/ja_JP/man8x", + "/usr/share/man/ja_JP/man9", + "/usr/share/man/ja_JP/man9x", + "/usr/share/man/ja_JP/mann", + "/usr/share/man/jbo", + "/usr/share/man/jbo/man0p", + "/usr/share/man/jbo/man1", + "/usr/share/man/jbo/man1p", + "/usr/share/man/jbo/man1x", + "/usr/share/man/jbo/man2", + "/usr/share/man/jbo/man2x", + "/usr/share/man/jbo/man3", + "/usr/share/man/jbo/man3p", + "/usr/share/man/jbo/man3x", + "/usr/share/man/jbo/man4", + "/usr/share/man/jbo/man4x", + "/usr/share/man/jbo/man5", + "/usr/share/man/jbo/man5x", + "/usr/share/man/jbo/man6", + "/usr/share/man/jbo/man6x", + "/usr/share/man/jbo/man7", + "/usr/share/man/jbo/man7x", + "/usr/share/man/jbo/man8", + "/usr/share/man/jbo/man8x", + "/usr/share/man/jbo/man9", + "/usr/share/man/jbo/man9x", + "/usr/share/man/jbo/mann", + "/usr/share/man/jpr", + "/usr/share/man/jpr/man0p", + "/usr/share/man/jpr/man1", + "/usr/share/man/jpr/man1p", + "/usr/share/man/jpr/man1x", + "/usr/share/man/jpr/man2", + "/usr/share/man/jpr/man2x", + "/usr/share/man/jpr/man3", + "/usr/share/man/jpr/man3p", + "/usr/share/man/jpr/man3x", + "/usr/share/man/jpr/man4", + "/usr/share/man/jpr/man4x", + "/usr/share/man/jpr/man5", + "/usr/share/man/jpr/man5x", + "/usr/share/man/jpr/man6", + "/usr/share/man/jpr/man6x", + "/usr/share/man/jpr/man7", + "/usr/share/man/jpr/man7x", + "/usr/share/man/jpr/man8", + "/usr/share/man/jpr/man8x", + "/usr/share/man/jpr/man9", + "/usr/share/man/jpr/man9x", + "/usr/share/man/jpr/mann", + "/usr/share/man/jrb", + "/usr/share/man/jrb/man0p", + "/usr/share/man/jrb/man1", + "/usr/share/man/jrb/man1p", + "/usr/share/man/jrb/man1x", + "/usr/share/man/jrb/man2", + "/usr/share/man/jrb/man2x", + "/usr/share/man/jrb/man3", + "/usr/share/man/jrb/man3p", + "/usr/share/man/jrb/man3x", + "/usr/share/man/jrb/man4", + "/usr/share/man/jrb/man4x", + "/usr/share/man/jrb/man5", + "/usr/share/man/jrb/man5x", + "/usr/share/man/jrb/man6", + "/usr/share/man/jrb/man6x", + "/usr/share/man/jrb/man7", + "/usr/share/man/jrb/man7x", + "/usr/share/man/jrb/man8", + "/usr/share/man/jrb/man8x", + "/usr/share/man/jrb/man9", + "/usr/share/man/jrb/man9x", + "/usr/share/man/jrb/mann", + "/usr/share/man/jv", + "/usr/share/man/jv/man0p", + "/usr/share/man/jv/man1", + "/usr/share/man/jv/man1p", + "/usr/share/man/jv/man1x", + "/usr/share/man/jv/man2", + "/usr/share/man/jv/man2x", + "/usr/share/man/jv/man3", + "/usr/share/man/jv/man3p", + "/usr/share/man/jv/man3x", + "/usr/share/man/jv/man4", + "/usr/share/man/jv/man4x", + "/usr/share/man/jv/man5", + "/usr/share/man/jv/man5x", + "/usr/share/man/jv/man6", + "/usr/share/man/jv/man6x", + "/usr/share/man/jv/man7", + "/usr/share/man/jv/man7x", + "/usr/share/man/jv/man8", + "/usr/share/man/jv/man8x", + "/usr/share/man/jv/man9", + "/usr/share/man/jv/man9x", + "/usr/share/man/jv/mann", + "/usr/share/man/ka", + "/usr/share/man/ka/man0p", + "/usr/share/man/ka/man1", + "/usr/share/man/ka/man1p", + "/usr/share/man/ka/man1x", + "/usr/share/man/ka/man2", + "/usr/share/man/ka/man2x", + "/usr/share/man/ka/man3", + "/usr/share/man/ka/man3p", + "/usr/share/man/ka/man3x", + "/usr/share/man/ka/man4", + "/usr/share/man/ka/man4x", + "/usr/share/man/ka/man5", + "/usr/share/man/ka/man5x", + "/usr/share/man/ka/man6", + "/usr/share/man/ka/man6x", + "/usr/share/man/ka/man7", + "/usr/share/man/ka/man7x", + "/usr/share/man/ka/man8", + "/usr/share/man/ka/man8x", + "/usr/share/man/ka/man9", + "/usr/share/man/ka/man9x", + "/usr/share/man/ka/mann", + "/usr/share/man/ka_GE", + "/usr/share/man/ka_GE/man0p", + "/usr/share/man/ka_GE/man1", + "/usr/share/man/ka_GE/man1p", + "/usr/share/man/ka_GE/man1x", + "/usr/share/man/ka_GE/man2", + "/usr/share/man/ka_GE/man2x", + "/usr/share/man/ka_GE/man3", + "/usr/share/man/ka_GE/man3p", + "/usr/share/man/ka_GE/man3x", + "/usr/share/man/ka_GE/man4", + "/usr/share/man/ka_GE/man4x", + "/usr/share/man/ka_GE/man5", + "/usr/share/man/ka_GE/man5x", + "/usr/share/man/ka_GE/man6", + "/usr/share/man/ka_GE/man6x", + "/usr/share/man/ka_GE/man7", + "/usr/share/man/ka_GE/man7x", + "/usr/share/man/ka_GE/man8", + "/usr/share/man/ka_GE/man8x", + "/usr/share/man/ka_GE/man9", + "/usr/share/man/ka_GE/man9x", + "/usr/share/man/ka_GE/mann", + "/usr/share/man/kaa", + "/usr/share/man/kaa/man0p", + "/usr/share/man/kaa/man1", + "/usr/share/man/kaa/man1p", + "/usr/share/man/kaa/man1x", + "/usr/share/man/kaa/man2", + "/usr/share/man/kaa/man2x", + "/usr/share/man/kaa/man3", + "/usr/share/man/kaa/man3p", + "/usr/share/man/kaa/man3x", + "/usr/share/man/kaa/man4", + "/usr/share/man/kaa/man4x", + "/usr/share/man/kaa/man5", + "/usr/share/man/kaa/man5x", + "/usr/share/man/kaa/man6", + "/usr/share/man/kaa/man6x", + "/usr/share/man/kaa/man7", + "/usr/share/man/kaa/man7x", + "/usr/share/man/kaa/man8", + "/usr/share/man/kaa/man8x", + "/usr/share/man/kaa/man9", + "/usr/share/man/kaa/man9x", + "/usr/share/man/kaa/mann", + "/usr/share/man/kab", + "/usr/share/man/kab/man0p", + "/usr/share/man/kab/man1", + "/usr/share/man/kab/man1p", + "/usr/share/man/kab/man1x", + "/usr/share/man/kab/man2", + "/usr/share/man/kab/man2x", + "/usr/share/man/kab/man3", + "/usr/share/man/kab/man3p", + "/usr/share/man/kab/man3x", + "/usr/share/man/kab/man4", + "/usr/share/man/kab/man4x", + "/usr/share/man/kab/man5", + "/usr/share/man/kab/man5x", + "/usr/share/man/kab/man6", + "/usr/share/man/kab/man6x", + "/usr/share/man/kab/man7", + "/usr/share/man/kab/man7x", + "/usr/share/man/kab/man8", + "/usr/share/man/kab/man8x", + "/usr/share/man/kab/man9", + "/usr/share/man/kab/man9x", + "/usr/share/man/kab/mann", + "/usr/share/man/kac", + "/usr/share/man/kac/man0p", + "/usr/share/man/kac/man1", + "/usr/share/man/kac/man1p", + "/usr/share/man/kac/man1x", + "/usr/share/man/kac/man2", + "/usr/share/man/kac/man2x", + "/usr/share/man/kac/man3", + "/usr/share/man/kac/man3p", + "/usr/share/man/kac/man3x", + "/usr/share/man/kac/man4", + "/usr/share/man/kac/man4x", + "/usr/share/man/kac/man5", + "/usr/share/man/kac/man5x", + "/usr/share/man/kac/man6", + "/usr/share/man/kac/man6x", + "/usr/share/man/kac/man7", + "/usr/share/man/kac/man7x", + "/usr/share/man/kac/man8", + "/usr/share/man/kac/man8x", + "/usr/share/man/kac/man9", + "/usr/share/man/kac/man9x", + "/usr/share/man/kac/mann", + "/usr/share/man/kam", + "/usr/share/man/kam/man0p", + "/usr/share/man/kam/man1", + "/usr/share/man/kam/man1p", + "/usr/share/man/kam/man1x", + "/usr/share/man/kam/man2", + "/usr/share/man/kam/man2x", + "/usr/share/man/kam/man3", + "/usr/share/man/kam/man3p", + "/usr/share/man/kam/man3x", + "/usr/share/man/kam/man4", + "/usr/share/man/kam/man4x", + "/usr/share/man/kam/man5", + "/usr/share/man/kam/man5x", + "/usr/share/man/kam/man6", + "/usr/share/man/kam/man6x", + "/usr/share/man/kam/man7", + "/usr/share/man/kam/man7x", + "/usr/share/man/kam/man8", + "/usr/share/man/kam/man8x", + "/usr/share/man/kam/man9", + "/usr/share/man/kam/man9x", + "/usr/share/man/kam/mann", + "/usr/share/man/kar", + "/usr/share/man/kar/man0p", + "/usr/share/man/kar/man1", + "/usr/share/man/kar/man1p", + "/usr/share/man/kar/man1x", + "/usr/share/man/kar/man2", + "/usr/share/man/kar/man2x", + "/usr/share/man/kar/man3", + "/usr/share/man/kar/man3p", + "/usr/share/man/kar/man3x", + "/usr/share/man/kar/man4", + "/usr/share/man/kar/man4x", + "/usr/share/man/kar/man5", + "/usr/share/man/kar/man5x", + "/usr/share/man/kar/man6", + "/usr/share/man/kar/man6x", + "/usr/share/man/kar/man7", + "/usr/share/man/kar/man7x", + "/usr/share/man/kar/man8", + "/usr/share/man/kar/man8x", + "/usr/share/man/kar/man9", + "/usr/share/man/kar/man9x", + "/usr/share/man/kar/mann", + "/usr/share/man/kaw", + "/usr/share/man/kaw/man0p", + "/usr/share/man/kaw/man1", + "/usr/share/man/kaw/man1p", + "/usr/share/man/kaw/man1x", + "/usr/share/man/kaw/man2", + "/usr/share/man/kaw/man2x", + "/usr/share/man/kaw/man3", + "/usr/share/man/kaw/man3p", + "/usr/share/man/kaw/man3x", + "/usr/share/man/kaw/man4", + "/usr/share/man/kaw/man4x", + "/usr/share/man/kaw/man5", + "/usr/share/man/kaw/man5x", + "/usr/share/man/kaw/man6", + "/usr/share/man/kaw/man6x", + "/usr/share/man/kaw/man7", + "/usr/share/man/kaw/man7x", + "/usr/share/man/kaw/man8", + "/usr/share/man/kaw/man8x", + "/usr/share/man/kaw/man9", + "/usr/share/man/kaw/man9x", + "/usr/share/man/kaw/mann", + "/usr/share/man/kbd", + "/usr/share/man/kbd/man0p", + "/usr/share/man/kbd/man1", + "/usr/share/man/kbd/man1p", + "/usr/share/man/kbd/man1x", + "/usr/share/man/kbd/man2", + "/usr/share/man/kbd/man2x", + "/usr/share/man/kbd/man3", + "/usr/share/man/kbd/man3p", + "/usr/share/man/kbd/man3x", + "/usr/share/man/kbd/man4", + "/usr/share/man/kbd/man4x", + "/usr/share/man/kbd/man5", + "/usr/share/man/kbd/man5x", + "/usr/share/man/kbd/man6", + "/usr/share/man/kbd/man6x", + "/usr/share/man/kbd/man7", + "/usr/share/man/kbd/man7x", + "/usr/share/man/kbd/man8", + "/usr/share/man/kbd/man8x", + "/usr/share/man/kbd/man9", + "/usr/share/man/kbd/man9x", + "/usr/share/man/kbd/mann", + "/usr/share/man/kg", + "/usr/share/man/kg/man0p", + "/usr/share/man/kg/man1", + "/usr/share/man/kg/man1p", + "/usr/share/man/kg/man1x", + "/usr/share/man/kg/man2", + "/usr/share/man/kg/man2x", + "/usr/share/man/kg/man3", + "/usr/share/man/kg/man3p", + "/usr/share/man/kg/man3x", + "/usr/share/man/kg/man4", + "/usr/share/man/kg/man4x", + "/usr/share/man/kg/man5", + "/usr/share/man/kg/man5x", + "/usr/share/man/kg/man6", + "/usr/share/man/kg/man6x", + "/usr/share/man/kg/man7", + "/usr/share/man/kg/man7x", + "/usr/share/man/kg/man8", + "/usr/share/man/kg/man8x", + "/usr/share/man/kg/man9", + "/usr/share/man/kg/man9x", + "/usr/share/man/kg/mann", + "/usr/share/man/kha", + "/usr/share/man/kha/man0p", + "/usr/share/man/kha/man1", + "/usr/share/man/kha/man1p", + "/usr/share/man/kha/man1x", + "/usr/share/man/kha/man2", + "/usr/share/man/kha/man2x", + "/usr/share/man/kha/man3", + "/usr/share/man/kha/man3p", + "/usr/share/man/kha/man3x", + "/usr/share/man/kha/man4", + "/usr/share/man/kha/man4x", + "/usr/share/man/kha/man5", + "/usr/share/man/kha/man5x", + "/usr/share/man/kha/man6", + "/usr/share/man/kha/man6x", + "/usr/share/man/kha/man7", + "/usr/share/man/kha/man7x", + "/usr/share/man/kha/man8", + "/usr/share/man/kha/man8x", + "/usr/share/man/kha/man9", + "/usr/share/man/kha/man9x", + "/usr/share/man/kha/mann", + "/usr/share/man/khi", + "/usr/share/man/khi/man0p", + "/usr/share/man/khi/man1", + "/usr/share/man/khi/man1p", + "/usr/share/man/khi/man1x", + "/usr/share/man/khi/man2", + "/usr/share/man/khi/man2x", + "/usr/share/man/khi/man3", + "/usr/share/man/khi/man3p", + "/usr/share/man/khi/man3x", + "/usr/share/man/khi/man4", + "/usr/share/man/khi/man4x", + "/usr/share/man/khi/man5", + "/usr/share/man/khi/man5x", + "/usr/share/man/khi/man6", + "/usr/share/man/khi/man6x", + "/usr/share/man/khi/man7", + "/usr/share/man/khi/man7x", + "/usr/share/man/khi/man8", + "/usr/share/man/khi/man8x", + "/usr/share/man/khi/man9", + "/usr/share/man/khi/man9x", + "/usr/share/man/khi/mann", + "/usr/share/man/kho", + "/usr/share/man/kho/man0p", + "/usr/share/man/kho/man1", + "/usr/share/man/kho/man1p", + "/usr/share/man/kho/man1x", + "/usr/share/man/kho/man2", + "/usr/share/man/kho/man2x", + "/usr/share/man/kho/man3", + "/usr/share/man/kho/man3p", + "/usr/share/man/kho/man3x", + "/usr/share/man/kho/man4", + "/usr/share/man/kho/man4x", + "/usr/share/man/kho/man5", + "/usr/share/man/kho/man5x", + "/usr/share/man/kho/man6", + "/usr/share/man/kho/man6x", + "/usr/share/man/kho/man7", + "/usr/share/man/kho/man7x", + "/usr/share/man/kho/man8", + "/usr/share/man/kho/man8x", + "/usr/share/man/kho/man9", + "/usr/share/man/kho/man9x", + "/usr/share/man/kho/mann", + "/usr/share/man/ki", + "/usr/share/man/ki/man0p", + "/usr/share/man/ki/man1", + "/usr/share/man/ki/man1p", + "/usr/share/man/ki/man1x", + "/usr/share/man/ki/man2", + "/usr/share/man/ki/man2x", + "/usr/share/man/ki/man3", + "/usr/share/man/ki/man3p", + "/usr/share/man/ki/man3x", + "/usr/share/man/ki/man4", + "/usr/share/man/ki/man4x", + "/usr/share/man/ki/man5", + "/usr/share/man/ki/man5x", + "/usr/share/man/ki/man6", + "/usr/share/man/ki/man6x", + "/usr/share/man/ki/man7", + "/usr/share/man/ki/man7x", + "/usr/share/man/ki/man8", + "/usr/share/man/ki/man8x", + "/usr/share/man/ki/man9", + "/usr/share/man/ki/man9x", + "/usr/share/man/ki/mann", + "/usr/share/man/kj", + "/usr/share/man/kj/man0p", + "/usr/share/man/kj/man1", + "/usr/share/man/kj/man1p", + "/usr/share/man/kj/man1x", + "/usr/share/man/kj/man2", + "/usr/share/man/kj/man2x", + "/usr/share/man/kj/man3", + "/usr/share/man/kj/man3p", + "/usr/share/man/kj/man3x", + "/usr/share/man/kj/man4", + "/usr/share/man/kj/man4x", + "/usr/share/man/kj/man5", + "/usr/share/man/kj/man5x", + "/usr/share/man/kj/man6", + "/usr/share/man/kj/man6x", + "/usr/share/man/kj/man7", + "/usr/share/man/kj/man7x", + "/usr/share/man/kj/man8", + "/usr/share/man/kj/man8x", + "/usr/share/man/kj/man9", + "/usr/share/man/kj/man9x", + "/usr/share/man/kj/mann", + "/usr/share/man/kk", + "/usr/share/man/kk/man0p", + "/usr/share/man/kk/man1", + "/usr/share/man/kk/man1p", + "/usr/share/man/kk/man1x", + "/usr/share/man/kk/man2", + "/usr/share/man/kk/man2x", + "/usr/share/man/kk/man3", + "/usr/share/man/kk/man3p", + "/usr/share/man/kk/man3x", + "/usr/share/man/kk/man4", + "/usr/share/man/kk/man4x", + "/usr/share/man/kk/man5", + "/usr/share/man/kk/man5x", + "/usr/share/man/kk/man6", + "/usr/share/man/kk/man6x", + "/usr/share/man/kk/man7", + "/usr/share/man/kk/man7x", + "/usr/share/man/kk/man8", + "/usr/share/man/kk/man8x", + "/usr/share/man/kk/man9", + "/usr/share/man/kk/man9x", + "/usr/share/man/kk/mann", + "/usr/share/man/kl", + "/usr/share/man/kl/man0p", + "/usr/share/man/kl/man1", + "/usr/share/man/kl/man1p", + "/usr/share/man/kl/man1x", + "/usr/share/man/kl/man2", + "/usr/share/man/kl/man2x", + "/usr/share/man/kl/man3", + "/usr/share/man/kl/man3p", + "/usr/share/man/kl/man3x", + "/usr/share/man/kl/man4", + "/usr/share/man/kl/man4x", + "/usr/share/man/kl/man5", + "/usr/share/man/kl/man5x", + "/usr/share/man/kl/man6", + "/usr/share/man/kl/man6x", + "/usr/share/man/kl/man7", + "/usr/share/man/kl/man7x", + "/usr/share/man/kl/man8", + "/usr/share/man/kl/man8x", + "/usr/share/man/kl/man9", + "/usr/share/man/kl/man9x", + "/usr/share/man/kl/mann", + "/usr/share/man/km", + "/usr/share/man/km/man0p", + "/usr/share/man/km/man1", + "/usr/share/man/km/man1p", + "/usr/share/man/km/man1x", + "/usr/share/man/km/man2", + "/usr/share/man/km/man2x", + "/usr/share/man/km/man3", + "/usr/share/man/km/man3p", + "/usr/share/man/km/man3x", + "/usr/share/man/km/man4", + "/usr/share/man/km/man4x", + "/usr/share/man/km/man5", + "/usr/share/man/km/man5x", + "/usr/share/man/km/man6", + "/usr/share/man/km/man6x", + "/usr/share/man/km/man7", + "/usr/share/man/km/man7x", + "/usr/share/man/km/man8", + "/usr/share/man/km/man8x", + "/usr/share/man/km/man9", + "/usr/share/man/km/man9x", + "/usr/share/man/km/mann", + "/usr/share/man/km_KH", + "/usr/share/man/km_KH/man0p", + "/usr/share/man/km_KH/man1", + "/usr/share/man/km_KH/man1p", + "/usr/share/man/km_KH/man1x", + "/usr/share/man/km_KH/man2", + "/usr/share/man/km_KH/man2x", + "/usr/share/man/km_KH/man3", + "/usr/share/man/km_KH/man3p", + "/usr/share/man/km_KH/man3x", + "/usr/share/man/km_KH/man4", + "/usr/share/man/km_KH/man4x", + "/usr/share/man/km_KH/man5", + "/usr/share/man/km_KH/man5x", + "/usr/share/man/km_KH/man6", + "/usr/share/man/km_KH/man6x", + "/usr/share/man/km_KH/man7", + "/usr/share/man/km_KH/man7x", + "/usr/share/man/km_KH/man8", + "/usr/share/man/km_KH/man8x", + "/usr/share/man/km_KH/man9", + "/usr/share/man/km_KH/man9x", + "/usr/share/man/km_KH/mann", + "/usr/share/man/kmb", + "/usr/share/man/kmb/man0p", + "/usr/share/man/kmb/man1", + "/usr/share/man/kmb/man1p", + "/usr/share/man/kmb/man1x", + "/usr/share/man/kmb/man2", + "/usr/share/man/kmb/man2x", + "/usr/share/man/kmb/man3", + "/usr/share/man/kmb/man3p", + "/usr/share/man/kmb/man3x", + "/usr/share/man/kmb/man4", + "/usr/share/man/kmb/man4x", + "/usr/share/man/kmb/man5", + "/usr/share/man/kmb/man5x", + "/usr/share/man/kmb/man6", + "/usr/share/man/kmb/man6x", + "/usr/share/man/kmb/man7", + "/usr/share/man/kmb/man7x", + "/usr/share/man/kmb/man8", + "/usr/share/man/kmb/man8x", + "/usr/share/man/kmb/man9", + "/usr/share/man/kmb/man9x", + "/usr/share/man/kmb/mann", + "/usr/share/man/kn", + "/usr/share/man/kn/man0p", + "/usr/share/man/kn/man1", + "/usr/share/man/kn/man1p", + "/usr/share/man/kn/man1x", + "/usr/share/man/kn/man2", + "/usr/share/man/kn/man2x", + "/usr/share/man/kn/man3", + "/usr/share/man/kn/man3p", + "/usr/share/man/kn/man3x", + "/usr/share/man/kn/man4", + "/usr/share/man/kn/man4x", + "/usr/share/man/kn/man5", + "/usr/share/man/kn/man5x", + "/usr/share/man/kn/man6", + "/usr/share/man/kn/man6x", + "/usr/share/man/kn/man7", + "/usr/share/man/kn/man7x", + "/usr/share/man/kn/man8", + "/usr/share/man/kn/man8x", + "/usr/share/man/kn/man9", + "/usr/share/man/kn/man9x", + "/usr/share/man/kn/mann", + "/usr/share/man/ko", + "/usr/share/man/ko/man0p", + "/usr/share/man/ko/man1", + "/usr/share/man/ko/man1p", + "/usr/share/man/ko/man1x", + "/usr/share/man/ko/man2", + "/usr/share/man/ko/man2x", + "/usr/share/man/ko/man3", + "/usr/share/man/ko/man3p", + "/usr/share/man/ko/man3x", + "/usr/share/man/ko/man4", + "/usr/share/man/ko/man4x", + "/usr/share/man/ko/man5", + "/usr/share/man/ko/man5x", + "/usr/share/man/ko/man6", + "/usr/share/man/ko/man6x", + "/usr/share/man/ko/man7", + "/usr/share/man/ko/man7x", + "/usr/share/man/ko/man8", + "/usr/share/man/ko/man8x", + "/usr/share/man/ko/man9", + "/usr/share/man/ko/man9x", + "/usr/share/man/ko/mann", + "/usr/share/man/ko_KR", + "/usr/share/man/ko_KR/man0p", + "/usr/share/man/ko_KR/man1", + "/usr/share/man/ko_KR/man1p", + "/usr/share/man/ko_KR/man1x", + "/usr/share/man/ko_KR/man2", + "/usr/share/man/ko_KR/man2x", + "/usr/share/man/ko_KR/man3", + "/usr/share/man/ko_KR/man3p", + "/usr/share/man/ko_KR/man3x", + "/usr/share/man/ko_KR/man4", + "/usr/share/man/ko_KR/man4x", + "/usr/share/man/ko_KR/man5", + "/usr/share/man/ko_KR/man5x", + "/usr/share/man/ko_KR/man6", + "/usr/share/man/ko_KR/man6x", + "/usr/share/man/ko_KR/man7", + "/usr/share/man/ko_KR/man7x", + "/usr/share/man/ko_KR/man8", + "/usr/share/man/ko_KR/man8x", + "/usr/share/man/ko_KR/man9", + "/usr/share/man/ko_KR/man9x", + "/usr/share/man/ko_KR/mann", + "/usr/share/man/kok", + "/usr/share/man/kok/man0p", + "/usr/share/man/kok/man1", + "/usr/share/man/kok/man1p", + "/usr/share/man/kok/man1x", + "/usr/share/man/kok/man2", + "/usr/share/man/kok/man2x", + "/usr/share/man/kok/man3", + "/usr/share/man/kok/man3p", + "/usr/share/man/kok/man3x", + "/usr/share/man/kok/man4", + "/usr/share/man/kok/man4x", + "/usr/share/man/kok/man5", + "/usr/share/man/kok/man5x", + "/usr/share/man/kok/man6", + "/usr/share/man/kok/man6x", + "/usr/share/man/kok/man7", + "/usr/share/man/kok/man7x", + "/usr/share/man/kok/man8", + "/usr/share/man/kok/man8x", + "/usr/share/man/kok/man9", + "/usr/share/man/kok/man9x", + "/usr/share/man/kok/mann", + "/usr/share/man/kok@latin", + "/usr/share/man/kok@latin/man0p", + "/usr/share/man/kok@latin/man1", + "/usr/share/man/kok@latin/man1p", + "/usr/share/man/kok@latin/man1x", + "/usr/share/man/kok@latin/man2", + "/usr/share/man/kok@latin/man2x", + "/usr/share/man/kok@latin/man3", + "/usr/share/man/kok@latin/man3p", + "/usr/share/man/kok@latin/man3x", + "/usr/share/man/kok@latin/man4", + "/usr/share/man/kok@latin/man4x", + "/usr/share/man/kok@latin/man5", + "/usr/share/man/kok@latin/man5x", + "/usr/share/man/kok@latin/man6", + "/usr/share/man/kok@latin/man6x", + "/usr/share/man/kok@latin/man7", + "/usr/share/man/kok@latin/man7x", + "/usr/share/man/kok@latin/man8", + "/usr/share/man/kok@latin/man8x", + "/usr/share/man/kok@latin/man9", + "/usr/share/man/kok@latin/man9x", + "/usr/share/man/kok@latin/mann", + "/usr/share/man/kos", + "/usr/share/man/kos/man0p", + "/usr/share/man/kos/man1", + "/usr/share/man/kos/man1p", + "/usr/share/man/kos/man1x", + "/usr/share/man/kos/man2", + "/usr/share/man/kos/man2x", + "/usr/share/man/kos/man3", + "/usr/share/man/kos/man3p", + "/usr/share/man/kos/man3x", + "/usr/share/man/kos/man4", + "/usr/share/man/kos/man4x", + "/usr/share/man/kos/man5", + "/usr/share/man/kos/man5x", + "/usr/share/man/kos/man6", + "/usr/share/man/kos/man6x", + "/usr/share/man/kos/man7", + "/usr/share/man/kos/man7x", + "/usr/share/man/kos/man8", + "/usr/share/man/kos/man8x", + "/usr/share/man/kos/man9", + "/usr/share/man/kos/man9x", + "/usr/share/man/kos/mann", + "/usr/share/man/kpe", + "/usr/share/man/kpe/man0p", + "/usr/share/man/kpe/man1", + "/usr/share/man/kpe/man1p", + "/usr/share/man/kpe/man1x", + "/usr/share/man/kpe/man2", + "/usr/share/man/kpe/man2x", + "/usr/share/man/kpe/man3", + "/usr/share/man/kpe/man3p", + "/usr/share/man/kpe/man3x", + "/usr/share/man/kpe/man4", + "/usr/share/man/kpe/man4x", + "/usr/share/man/kpe/man5", + "/usr/share/man/kpe/man5x", + "/usr/share/man/kpe/man6", + "/usr/share/man/kpe/man6x", + "/usr/share/man/kpe/man7", + "/usr/share/man/kpe/man7x", + "/usr/share/man/kpe/man8", + "/usr/share/man/kpe/man8x", + "/usr/share/man/kpe/man9", + "/usr/share/man/kpe/man9x", + "/usr/share/man/kpe/mann", + "/usr/share/man/kr", + "/usr/share/man/kr/man0p", + "/usr/share/man/kr/man1", + "/usr/share/man/kr/man1p", + "/usr/share/man/kr/man1x", + "/usr/share/man/kr/man2", + "/usr/share/man/kr/man2x", + "/usr/share/man/kr/man3", + "/usr/share/man/kr/man3p", + "/usr/share/man/kr/man3x", + "/usr/share/man/kr/man4", + "/usr/share/man/kr/man4x", + "/usr/share/man/kr/man5", + "/usr/share/man/kr/man5x", + "/usr/share/man/kr/man6", + "/usr/share/man/kr/man6x", + "/usr/share/man/kr/man7", + "/usr/share/man/kr/man7x", + "/usr/share/man/kr/man8", + "/usr/share/man/kr/man8x", + "/usr/share/man/kr/man9", + "/usr/share/man/kr/man9x", + "/usr/share/man/kr/mann", + "/usr/share/man/krc", + "/usr/share/man/krc/man0p", + "/usr/share/man/krc/man1", + "/usr/share/man/krc/man1p", + "/usr/share/man/krc/man1x", + "/usr/share/man/krc/man2", + "/usr/share/man/krc/man2x", + "/usr/share/man/krc/man3", + "/usr/share/man/krc/man3p", + "/usr/share/man/krc/man3x", + "/usr/share/man/krc/man4", + "/usr/share/man/krc/man4x", + "/usr/share/man/krc/man5", + "/usr/share/man/krc/man5x", + "/usr/share/man/krc/man6", + "/usr/share/man/krc/man6x", + "/usr/share/man/krc/man7", + "/usr/share/man/krc/man7x", + "/usr/share/man/krc/man8", + "/usr/share/man/krc/man8x", + "/usr/share/man/krc/man9", + "/usr/share/man/krc/man9x", + "/usr/share/man/krc/mann", + "/usr/share/man/krl", + "/usr/share/man/krl/man0p", + "/usr/share/man/krl/man1", + "/usr/share/man/krl/man1p", + "/usr/share/man/krl/man1x", + "/usr/share/man/krl/man2", + "/usr/share/man/krl/man2x", + "/usr/share/man/krl/man3", + "/usr/share/man/krl/man3p", + "/usr/share/man/krl/man3x", + "/usr/share/man/krl/man4", + "/usr/share/man/krl/man4x", + "/usr/share/man/krl/man5", + "/usr/share/man/krl/man5x", + "/usr/share/man/krl/man6", + "/usr/share/man/krl/man6x", + "/usr/share/man/krl/man7", + "/usr/share/man/krl/man7x", + "/usr/share/man/krl/man8", + "/usr/share/man/krl/man8x", + "/usr/share/man/krl/man9", + "/usr/share/man/krl/man9x", + "/usr/share/man/krl/mann", + "/usr/share/man/kro", + "/usr/share/man/kro/man0p", + "/usr/share/man/kro/man1", + "/usr/share/man/kro/man1p", + "/usr/share/man/kro/man1x", + "/usr/share/man/kro/man2", + "/usr/share/man/kro/man2x", + "/usr/share/man/kro/man3", + "/usr/share/man/kro/man3p", + "/usr/share/man/kro/man3x", + "/usr/share/man/kro/man4", + "/usr/share/man/kro/man4x", + "/usr/share/man/kro/man5", + "/usr/share/man/kro/man5x", + "/usr/share/man/kro/man6", + "/usr/share/man/kro/man6x", + "/usr/share/man/kro/man7", + "/usr/share/man/kro/man7x", + "/usr/share/man/kro/man8", + "/usr/share/man/kro/man8x", + "/usr/share/man/kro/man9", + "/usr/share/man/kro/man9x", + "/usr/share/man/kro/mann", + "/usr/share/man/kru", + "/usr/share/man/kru/man0p", + "/usr/share/man/kru/man1", + "/usr/share/man/kru/man1p", + "/usr/share/man/kru/man1x", + "/usr/share/man/kru/man2", + "/usr/share/man/kru/man2x", + "/usr/share/man/kru/man3", + "/usr/share/man/kru/man3p", + "/usr/share/man/kru/man3x", + "/usr/share/man/kru/man4", + "/usr/share/man/kru/man4x", + "/usr/share/man/kru/man5", + "/usr/share/man/kru/man5x", + "/usr/share/man/kru/man6", + "/usr/share/man/kru/man6x", + "/usr/share/man/kru/man7", + "/usr/share/man/kru/man7x", + "/usr/share/man/kru/man8", + "/usr/share/man/kru/man8x", + "/usr/share/man/kru/man9", + "/usr/share/man/kru/man9x", + "/usr/share/man/kru/mann", + "/usr/share/man/ks", + "/usr/share/man/ks/man0p", + "/usr/share/man/ks/man1", + "/usr/share/man/ks/man1p", + "/usr/share/man/ks/man1x", + "/usr/share/man/ks/man2", + "/usr/share/man/ks/man2x", + "/usr/share/man/ks/man3", + "/usr/share/man/ks/man3p", + "/usr/share/man/ks/man3x", + "/usr/share/man/ks/man4", + "/usr/share/man/ks/man4x", + "/usr/share/man/ks/man5", + "/usr/share/man/ks/man5x", + "/usr/share/man/ks/man6", + "/usr/share/man/ks/man6x", + "/usr/share/man/ks/man7", + "/usr/share/man/ks/man7x", + "/usr/share/man/ks/man8", + "/usr/share/man/ks/man8x", + "/usr/share/man/ks/man9", + "/usr/share/man/ks/man9x", + "/usr/share/man/ks/mann", + "/usr/share/man/ks@aran", + "/usr/share/man/ks@aran/man0p", + "/usr/share/man/ks@aran/man1", + "/usr/share/man/ks@aran/man1p", + "/usr/share/man/ks@aran/man1x", + "/usr/share/man/ks@aran/man2", + "/usr/share/man/ks@aran/man2x", + "/usr/share/man/ks@aran/man3", + "/usr/share/man/ks@aran/man3p", + "/usr/share/man/ks@aran/man3x", + "/usr/share/man/ks@aran/man4", + "/usr/share/man/ks@aran/man4x", + "/usr/share/man/ks@aran/man5", + "/usr/share/man/ks@aran/man5x", + "/usr/share/man/ks@aran/man6", + "/usr/share/man/ks@aran/man6x", + "/usr/share/man/ks@aran/man7", + "/usr/share/man/ks@aran/man7x", + "/usr/share/man/ks@aran/man8", + "/usr/share/man/ks@aran/man8x", + "/usr/share/man/ks@aran/man9", + "/usr/share/man/ks@aran/man9x", + "/usr/share/man/ks@aran/mann", + "/usr/share/man/ks@devanagari", + "/usr/share/man/ks@devanagari/man0p", + "/usr/share/man/ks@devanagari/man1", + "/usr/share/man/ks@devanagari/man1p", + "/usr/share/man/ks@devanagari/man1x", + "/usr/share/man/ks@devanagari/man2", + "/usr/share/man/ks@devanagari/man2x", + "/usr/share/man/ks@devanagari/man3", + "/usr/share/man/ks@devanagari/man3p", + "/usr/share/man/ks@devanagari/man3x", + "/usr/share/man/ks@devanagari/man4", + "/usr/share/man/ks@devanagari/man4x", + "/usr/share/man/ks@devanagari/man5", + "/usr/share/man/ks@devanagari/man5x", + "/usr/share/man/ks@devanagari/man6", + "/usr/share/man/ks@devanagari/man6x", + "/usr/share/man/ks@devanagari/man7", + "/usr/share/man/ks@devanagari/man7x", + "/usr/share/man/ks@devanagari/man8", + "/usr/share/man/ks@devanagari/man8x", + "/usr/share/man/ks@devanagari/man9", + "/usr/share/man/ks@devanagari/man9x", + "/usr/share/man/ks@devanagari/mann", + "/usr/share/man/ksw", + "/usr/share/man/ksw/man0p", + "/usr/share/man/ksw/man1", + "/usr/share/man/ksw/man1p", + "/usr/share/man/ksw/man1x", + "/usr/share/man/ksw/man2", + "/usr/share/man/ksw/man2x", + "/usr/share/man/ksw/man3", + "/usr/share/man/ksw/man3p", + "/usr/share/man/ksw/man3x", + "/usr/share/man/ksw/man4", + "/usr/share/man/ksw/man4x", + "/usr/share/man/ksw/man5", + "/usr/share/man/ksw/man5x", + "/usr/share/man/ksw/man6", + "/usr/share/man/ksw/man6x", + "/usr/share/man/ksw/man7", + "/usr/share/man/ksw/man7x", + "/usr/share/man/ksw/man8", + "/usr/share/man/ksw/man8x", + "/usr/share/man/ksw/man9", + "/usr/share/man/ksw/man9x", + "/usr/share/man/ksw/mann", + "/usr/share/man/ku", + "/usr/share/man/ku/man0p", + "/usr/share/man/ku/man1", + "/usr/share/man/ku/man1p", + "/usr/share/man/ku/man1x", + "/usr/share/man/ku/man2", + "/usr/share/man/ku/man2x", + "/usr/share/man/ku/man3", + "/usr/share/man/ku/man3p", + "/usr/share/man/ku/man3x", + "/usr/share/man/ku/man4", + "/usr/share/man/ku/man4x", + "/usr/share/man/ku/man5", + "/usr/share/man/ku/man5x", + "/usr/share/man/ku/man6", + "/usr/share/man/ku/man6x", + "/usr/share/man/ku/man7", + "/usr/share/man/ku/man7x", + "/usr/share/man/ku/man8", + "/usr/share/man/ku/man8x", + "/usr/share/man/ku/man9", + "/usr/share/man/ku/man9x", + "/usr/share/man/ku/mann", + "/usr/share/man/ku_IQ", + "/usr/share/man/ku_IQ/man0p", + "/usr/share/man/ku_IQ/man1", + "/usr/share/man/ku_IQ/man1p", + "/usr/share/man/ku_IQ/man1x", + "/usr/share/man/ku_IQ/man2", + "/usr/share/man/ku_IQ/man2x", + "/usr/share/man/ku_IQ/man3", + "/usr/share/man/ku_IQ/man3p", + "/usr/share/man/ku_IQ/man3x", + "/usr/share/man/ku_IQ/man4", + "/usr/share/man/ku_IQ/man4x", + "/usr/share/man/ku_IQ/man5", + "/usr/share/man/ku_IQ/man5x", + "/usr/share/man/ku_IQ/man6", + "/usr/share/man/ku_IQ/man6x", + "/usr/share/man/ku_IQ/man7", + "/usr/share/man/ku_IQ/man7x", + "/usr/share/man/ku_IQ/man8", + "/usr/share/man/ku_IQ/man8x", + "/usr/share/man/ku_IQ/man9", + "/usr/share/man/ku_IQ/man9x", + "/usr/share/man/ku_IQ/mann", + "/usr/share/man/kum", + "/usr/share/man/kum/man0p", + "/usr/share/man/kum/man1", + "/usr/share/man/kum/man1p", + "/usr/share/man/kum/man1x", + "/usr/share/man/kum/man2", + "/usr/share/man/kum/man2x", + "/usr/share/man/kum/man3", + "/usr/share/man/kum/man3p", + "/usr/share/man/kum/man3x", + "/usr/share/man/kum/man4", + "/usr/share/man/kum/man4x", + "/usr/share/man/kum/man5", + "/usr/share/man/kum/man5x", + "/usr/share/man/kum/man6", + "/usr/share/man/kum/man6x", + "/usr/share/man/kum/man7", + "/usr/share/man/kum/man7x", + "/usr/share/man/kum/man8", + "/usr/share/man/kum/man8x", + "/usr/share/man/kum/man9", + "/usr/share/man/kum/man9x", + "/usr/share/man/kum/mann", + "/usr/share/man/kut", + "/usr/share/man/kut/man0p", + "/usr/share/man/kut/man1", + "/usr/share/man/kut/man1p", + "/usr/share/man/kut/man1x", + "/usr/share/man/kut/man2", + "/usr/share/man/kut/man2x", + "/usr/share/man/kut/man3", + "/usr/share/man/kut/man3p", + "/usr/share/man/kut/man3x", + "/usr/share/man/kut/man4", + "/usr/share/man/kut/man4x", + "/usr/share/man/kut/man5", + "/usr/share/man/kut/man5x", + "/usr/share/man/kut/man6", + "/usr/share/man/kut/man6x", + "/usr/share/man/kut/man7", + "/usr/share/man/kut/man7x", + "/usr/share/man/kut/man8", + "/usr/share/man/kut/man8x", + "/usr/share/man/kut/man9", + "/usr/share/man/kut/man9x", + "/usr/share/man/kut/mann", + "/usr/share/man/kv", + "/usr/share/man/kv/man0p", + "/usr/share/man/kv/man1", + "/usr/share/man/kv/man1p", + "/usr/share/man/kv/man1x", + "/usr/share/man/kv/man2", + "/usr/share/man/kv/man2x", + "/usr/share/man/kv/man3", + "/usr/share/man/kv/man3p", + "/usr/share/man/kv/man3x", + "/usr/share/man/kv/man4", + "/usr/share/man/kv/man4x", + "/usr/share/man/kv/man5", + "/usr/share/man/kv/man5x", + "/usr/share/man/kv/man6", + "/usr/share/man/kv/man6x", + "/usr/share/man/kv/man7", + "/usr/share/man/kv/man7x", + "/usr/share/man/kv/man8", + "/usr/share/man/kv/man8x", + "/usr/share/man/kv/man9", + "/usr/share/man/kv/man9x", + "/usr/share/man/kv/mann", + "/usr/share/man/kw", + "/usr/share/man/kw/man0p", + "/usr/share/man/kw/man1", + "/usr/share/man/kw/man1p", + "/usr/share/man/kw/man1x", + "/usr/share/man/kw/man2", + "/usr/share/man/kw/man2x", + "/usr/share/man/kw/man3", + "/usr/share/man/kw/man3p", + "/usr/share/man/kw/man3x", + "/usr/share/man/kw/man4", + "/usr/share/man/kw/man4x", + "/usr/share/man/kw/man5", + "/usr/share/man/kw/man5x", + "/usr/share/man/kw/man6", + "/usr/share/man/kw/man6x", + "/usr/share/man/kw/man7", + "/usr/share/man/kw/man7x", + "/usr/share/man/kw/man8", + "/usr/share/man/kw/man8x", + "/usr/share/man/kw/man9", + "/usr/share/man/kw/man9x", + "/usr/share/man/kw/mann", + "/usr/share/man/kw@kkcor", + "/usr/share/man/kw@kkcor/man0p", + "/usr/share/man/kw@kkcor/man1", + "/usr/share/man/kw@kkcor/man1p", + "/usr/share/man/kw@kkcor/man1x", + "/usr/share/man/kw@kkcor/man2", + "/usr/share/man/kw@kkcor/man2x", + "/usr/share/man/kw@kkcor/man3", + "/usr/share/man/kw@kkcor/man3p", + "/usr/share/man/kw@kkcor/man3x", + "/usr/share/man/kw@kkcor/man4", + "/usr/share/man/kw@kkcor/man4x", + "/usr/share/man/kw@kkcor/man5", + "/usr/share/man/kw@kkcor/man5x", + "/usr/share/man/kw@kkcor/man6", + "/usr/share/man/kw@kkcor/man6x", + "/usr/share/man/kw@kkcor/man7", + "/usr/share/man/kw@kkcor/man7x", + "/usr/share/man/kw@kkcor/man8", + "/usr/share/man/kw@kkcor/man8x", + "/usr/share/man/kw@kkcor/man9", + "/usr/share/man/kw@kkcor/man9x", + "/usr/share/man/kw@kkcor/mann", + "/usr/share/man/kw@uccor", + "/usr/share/man/kw@uccor/man0p", + "/usr/share/man/kw@uccor/man1", + "/usr/share/man/kw@uccor/man1p", + "/usr/share/man/kw@uccor/man1x", + "/usr/share/man/kw@uccor/man2", + "/usr/share/man/kw@uccor/man2x", + "/usr/share/man/kw@uccor/man3", + "/usr/share/man/kw@uccor/man3p", + "/usr/share/man/kw@uccor/man3x", + "/usr/share/man/kw@uccor/man4", + "/usr/share/man/kw@uccor/man4x", + "/usr/share/man/kw@uccor/man5", + "/usr/share/man/kw@uccor/man5x", + "/usr/share/man/kw@uccor/man6", + "/usr/share/man/kw@uccor/man6x", + "/usr/share/man/kw@uccor/man7", + "/usr/share/man/kw@uccor/man7x", + "/usr/share/man/kw@uccor/man8", + "/usr/share/man/kw@uccor/man8x", + "/usr/share/man/kw@uccor/man9", + "/usr/share/man/kw@uccor/man9x", + "/usr/share/man/kw@uccor/mann", + "/usr/share/man/kw_GB", + "/usr/share/man/kw_GB/man0p", + "/usr/share/man/kw_GB/man1", + "/usr/share/man/kw_GB/man1p", + "/usr/share/man/kw_GB/man1x", + "/usr/share/man/kw_GB/man2", + "/usr/share/man/kw_GB/man2x", + "/usr/share/man/kw_GB/man3", + "/usr/share/man/kw_GB/man3p", + "/usr/share/man/kw_GB/man3x", + "/usr/share/man/kw_GB/man4", + "/usr/share/man/kw_GB/man4x", + "/usr/share/man/kw_GB/man5", + "/usr/share/man/kw_GB/man5x", + "/usr/share/man/kw_GB/man6", + "/usr/share/man/kw_GB/man6x", + "/usr/share/man/kw_GB/man7", + "/usr/share/man/kw_GB/man7x", + "/usr/share/man/kw_GB/man8", + "/usr/share/man/kw_GB/man8x", + "/usr/share/man/kw_GB/man9", + "/usr/share/man/kw_GB/man9x", + "/usr/share/man/kw_GB/mann", + "/usr/share/man/ky", + "/usr/share/man/ky/man0p", + "/usr/share/man/ky/man1", + "/usr/share/man/ky/man1p", + "/usr/share/man/ky/man1x", + "/usr/share/man/ky/man2", + "/usr/share/man/ky/man2x", + "/usr/share/man/ky/man3", + "/usr/share/man/ky/man3p", + "/usr/share/man/ky/man3x", + "/usr/share/man/ky/man4", + "/usr/share/man/ky/man4x", + "/usr/share/man/ky/man5", + "/usr/share/man/ky/man5x", + "/usr/share/man/ky/man6", + "/usr/share/man/ky/man6x", + "/usr/share/man/ky/man7", + "/usr/share/man/ky/man7x", + "/usr/share/man/ky/man8", + "/usr/share/man/ky/man8x", + "/usr/share/man/ky/man9", + "/usr/share/man/ky/man9x", + "/usr/share/man/ky/mann", + "/usr/share/man/l10n", + "/usr/share/man/l10n/man0p", + "/usr/share/man/l10n/man1", + "/usr/share/man/l10n/man1p", + "/usr/share/man/l10n/man1x", + "/usr/share/man/l10n/man2", + "/usr/share/man/l10n/man2x", + "/usr/share/man/l10n/man3", + "/usr/share/man/l10n/man3p", + "/usr/share/man/l10n/man3x", + "/usr/share/man/l10n/man4", + "/usr/share/man/l10n/man4x", + "/usr/share/man/l10n/man5", + "/usr/share/man/l10n/man5x", + "/usr/share/man/l10n/man6", + "/usr/share/man/l10n/man6x", + "/usr/share/man/l10n/man7", + "/usr/share/man/l10n/man7x", + "/usr/share/man/l10n/man8", + "/usr/share/man/l10n/man8x", + "/usr/share/man/l10n/man9", + "/usr/share/man/l10n/man9x", + "/usr/share/man/l10n/mann", + "/usr/share/man/la", + "/usr/share/man/la/man0p", + "/usr/share/man/la/man1", + "/usr/share/man/la/man1p", + "/usr/share/man/la/man1x", + "/usr/share/man/la/man2", + "/usr/share/man/la/man2x", + "/usr/share/man/la/man3", + "/usr/share/man/la/man3p", + "/usr/share/man/la/man3x", + "/usr/share/man/la/man4", + "/usr/share/man/la/man4x", + "/usr/share/man/la/man5", + "/usr/share/man/la/man5x", + "/usr/share/man/la/man6", + "/usr/share/man/la/man6x", + "/usr/share/man/la/man7", + "/usr/share/man/la/man7x", + "/usr/share/man/la/man8", + "/usr/share/man/la/man8x", + "/usr/share/man/la/man9", + "/usr/share/man/la/man9x", + "/usr/share/man/la/mann", + "/usr/share/man/lad", + "/usr/share/man/lad/man0p", + "/usr/share/man/lad/man1", + "/usr/share/man/lad/man1p", + "/usr/share/man/lad/man1x", + "/usr/share/man/lad/man2", + "/usr/share/man/lad/man2x", + "/usr/share/man/lad/man3", + "/usr/share/man/lad/man3p", + "/usr/share/man/lad/man3x", + "/usr/share/man/lad/man4", + "/usr/share/man/lad/man4x", + "/usr/share/man/lad/man5", + "/usr/share/man/lad/man5x", + "/usr/share/man/lad/man6", + "/usr/share/man/lad/man6x", + "/usr/share/man/lad/man7", + "/usr/share/man/lad/man7x", + "/usr/share/man/lad/man8", + "/usr/share/man/lad/man8x", + "/usr/share/man/lad/man9", + "/usr/share/man/lad/man9x", + "/usr/share/man/lad/mann", + "/usr/share/man/lah", + "/usr/share/man/lah/man0p", + "/usr/share/man/lah/man1", + "/usr/share/man/lah/man1p", + "/usr/share/man/lah/man1x", + "/usr/share/man/lah/man2", + "/usr/share/man/lah/man2x", + "/usr/share/man/lah/man3", + "/usr/share/man/lah/man3p", + "/usr/share/man/lah/man3x", + "/usr/share/man/lah/man4", + "/usr/share/man/lah/man4x", + "/usr/share/man/lah/man5", + "/usr/share/man/lah/man5x", + "/usr/share/man/lah/man6", + "/usr/share/man/lah/man6x", + "/usr/share/man/lah/man7", + "/usr/share/man/lah/man7x", + "/usr/share/man/lah/man8", + "/usr/share/man/lah/man8x", + "/usr/share/man/lah/man9", + "/usr/share/man/lah/man9x", + "/usr/share/man/lah/mann", + "/usr/share/man/lam", + "/usr/share/man/lam/man0p", + "/usr/share/man/lam/man1", + "/usr/share/man/lam/man1p", + "/usr/share/man/lam/man1x", + "/usr/share/man/lam/man2", + "/usr/share/man/lam/man2x", + "/usr/share/man/lam/man3", + "/usr/share/man/lam/man3p", + "/usr/share/man/lam/man3x", + "/usr/share/man/lam/man4", + "/usr/share/man/lam/man4x", + "/usr/share/man/lam/man5", + "/usr/share/man/lam/man5x", + "/usr/share/man/lam/man6", + "/usr/share/man/lam/man6x", + "/usr/share/man/lam/man7", + "/usr/share/man/lam/man7x", + "/usr/share/man/lam/man8", + "/usr/share/man/lam/man8x", + "/usr/share/man/lam/man9", + "/usr/share/man/lam/man9x", + "/usr/share/man/lam/mann", + "/usr/share/man/lb", + "/usr/share/man/lb/man0p", + "/usr/share/man/lb/man1", + "/usr/share/man/lb/man1p", + "/usr/share/man/lb/man1x", + "/usr/share/man/lb/man2", + "/usr/share/man/lb/man2x", + "/usr/share/man/lb/man3", + "/usr/share/man/lb/man3p", + "/usr/share/man/lb/man3x", + "/usr/share/man/lb/man4", + "/usr/share/man/lb/man4x", + "/usr/share/man/lb/man5", + "/usr/share/man/lb/man5x", + "/usr/share/man/lb/man6", + "/usr/share/man/lb/man6x", + "/usr/share/man/lb/man7", + "/usr/share/man/lb/man7x", + "/usr/share/man/lb/man8", + "/usr/share/man/lb/man8x", + "/usr/share/man/lb/man9", + "/usr/share/man/lb/man9x", + "/usr/share/man/lb/mann", + "/usr/share/man/lez", + "/usr/share/man/lez/man0p", + "/usr/share/man/lez/man1", + "/usr/share/man/lez/man1p", + "/usr/share/man/lez/man1x", + "/usr/share/man/lez/man2", + "/usr/share/man/lez/man2x", + "/usr/share/man/lez/man3", + "/usr/share/man/lez/man3p", + "/usr/share/man/lez/man3x", + "/usr/share/man/lez/man4", + "/usr/share/man/lez/man4x", + "/usr/share/man/lez/man5", + "/usr/share/man/lez/man5x", + "/usr/share/man/lez/man6", + "/usr/share/man/lez/man6x", + "/usr/share/man/lez/man7", + "/usr/share/man/lez/man7x", + "/usr/share/man/lez/man8", + "/usr/share/man/lez/man8x", + "/usr/share/man/lez/man9", + "/usr/share/man/lez/man9x", + "/usr/share/man/lez/mann", + "/usr/share/man/lg", + "/usr/share/man/lg/man0p", + "/usr/share/man/lg/man1", + "/usr/share/man/lg/man1p", + "/usr/share/man/lg/man1x", + "/usr/share/man/lg/man2", + "/usr/share/man/lg/man2x", + "/usr/share/man/lg/man3", + "/usr/share/man/lg/man3p", + "/usr/share/man/lg/man3x", + "/usr/share/man/lg/man4", + "/usr/share/man/lg/man4x", + "/usr/share/man/lg/man5", + "/usr/share/man/lg/man5x", + "/usr/share/man/lg/man6", + "/usr/share/man/lg/man6x", + "/usr/share/man/lg/man7", + "/usr/share/man/lg/man7x", + "/usr/share/man/lg/man8", + "/usr/share/man/lg/man8x", + "/usr/share/man/lg/man9", + "/usr/share/man/lg/man9x", + "/usr/share/man/lg/mann", + "/usr/share/man/li", + "/usr/share/man/li/man0p", + "/usr/share/man/li/man1", + "/usr/share/man/li/man1p", + "/usr/share/man/li/man1x", + "/usr/share/man/li/man2", + "/usr/share/man/li/man2x", + "/usr/share/man/li/man3", + "/usr/share/man/li/man3p", + "/usr/share/man/li/man3x", + "/usr/share/man/li/man4", + "/usr/share/man/li/man4x", + "/usr/share/man/li/man5", + "/usr/share/man/li/man5x", + "/usr/share/man/li/man6", + "/usr/share/man/li/man6x", + "/usr/share/man/li/man7", + "/usr/share/man/li/man7x", + "/usr/share/man/li/man8", + "/usr/share/man/li/man8x", + "/usr/share/man/li/man9", + "/usr/share/man/li/man9x", + "/usr/share/man/li/mann", + "/usr/share/man/ln", + "/usr/share/man/ln/man0p", + "/usr/share/man/ln/man1", + "/usr/share/man/ln/man1p", + "/usr/share/man/ln/man1x", + "/usr/share/man/ln/man2", + "/usr/share/man/ln/man2x", + "/usr/share/man/ln/man3", + "/usr/share/man/ln/man3p", + "/usr/share/man/ln/man3x", + "/usr/share/man/ln/man4", + "/usr/share/man/ln/man4x", + "/usr/share/man/ln/man5", + "/usr/share/man/ln/man5x", + "/usr/share/man/ln/man6", + "/usr/share/man/ln/man6x", + "/usr/share/man/ln/man7", + "/usr/share/man/ln/man7x", + "/usr/share/man/ln/man8", + "/usr/share/man/ln/man8x", + "/usr/share/man/ln/man9", + "/usr/share/man/ln/man9x", + "/usr/share/man/ln/mann", + "/usr/share/man/lo", + "/usr/share/man/lo/man0p", + "/usr/share/man/lo/man1", + "/usr/share/man/lo/man1p", + "/usr/share/man/lo/man1x", + "/usr/share/man/lo/man2", + "/usr/share/man/lo/man2x", + "/usr/share/man/lo/man3", + "/usr/share/man/lo/man3p", + "/usr/share/man/lo/man3x", + "/usr/share/man/lo/man4", + "/usr/share/man/lo/man4x", + "/usr/share/man/lo/man5", + "/usr/share/man/lo/man5x", + "/usr/share/man/lo/man6", + "/usr/share/man/lo/man6x", + "/usr/share/man/lo/man7", + "/usr/share/man/lo/man7x", + "/usr/share/man/lo/man8", + "/usr/share/man/lo/man8x", + "/usr/share/man/lo/man9", + "/usr/share/man/lo/man9x", + "/usr/share/man/lo/mann", + "/usr/share/man/lo_LA", + "/usr/share/man/lo_LA/man0p", + "/usr/share/man/lo_LA/man1", + "/usr/share/man/lo_LA/man1p", + "/usr/share/man/lo_LA/man1x", + "/usr/share/man/lo_LA/man2", + "/usr/share/man/lo_LA/man2x", + "/usr/share/man/lo_LA/man3", + "/usr/share/man/lo_LA/man3p", + "/usr/share/man/lo_LA/man3x", + "/usr/share/man/lo_LA/man4", + "/usr/share/man/lo_LA/man4x", + "/usr/share/man/lo_LA/man5", + "/usr/share/man/lo_LA/man5x", + "/usr/share/man/lo_LA/man6", + "/usr/share/man/lo_LA/man6x", + "/usr/share/man/lo_LA/man7", + "/usr/share/man/lo_LA/man7x", + "/usr/share/man/lo_LA/man8", + "/usr/share/man/lo_LA/man8x", + "/usr/share/man/lo_LA/man9", + "/usr/share/man/lo_LA/man9x", + "/usr/share/man/lo_LA/mann", + "/usr/share/man/lol", + "/usr/share/man/lol/man0p", + "/usr/share/man/lol/man1", + "/usr/share/man/lol/man1p", + "/usr/share/man/lol/man1x", + "/usr/share/man/lol/man2", + "/usr/share/man/lol/man2x", + "/usr/share/man/lol/man3", + "/usr/share/man/lol/man3p", + "/usr/share/man/lol/man3x", + "/usr/share/man/lol/man4", + "/usr/share/man/lol/man4x", + "/usr/share/man/lol/man5", + "/usr/share/man/lol/man5x", + "/usr/share/man/lol/man6", + "/usr/share/man/lol/man6x", + "/usr/share/man/lol/man7", + "/usr/share/man/lol/man7x", + "/usr/share/man/lol/man8", + "/usr/share/man/lol/man8x", + "/usr/share/man/lol/man9", + "/usr/share/man/lol/man9x", + "/usr/share/man/lol/mann", + "/usr/share/man/loz", + "/usr/share/man/loz/man0p", + "/usr/share/man/loz/man1", + "/usr/share/man/loz/man1p", + "/usr/share/man/loz/man1x", + "/usr/share/man/loz/man2", + "/usr/share/man/loz/man2x", + "/usr/share/man/loz/man3", + "/usr/share/man/loz/man3p", + "/usr/share/man/loz/man3x", + "/usr/share/man/loz/man4", + "/usr/share/man/loz/man4x", + "/usr/share/man/loz/man5", + "/usr/share/man/loz/man5x", + "/usr/share/man/loz/man6", + "/usr/share/man/loz/man6x", + "/usr/share/man/loz/man7", + "/usr/share/man/loz/man7x", + "/usr/share/man/loz/man8", + "/usr/share/man/loz/man8x", + "/usr/share/man/loz/man9", + "/usr/share/man/loz/man9x", + "/usr/share/man/loz/mann", + "/usr/share/man/lt", + "/usr/share/man/lt/man0p", + "/usr/share/man/lt/man1", + "/usr/share/man/lt/man1p", + "/usr/share/man/lt/man1x", + "/usr/share/man/lt/man2", + "/usr/share/man/lt/man2x", + "/usr/share/man/lt/man3", + "/usr/share/man/lt/man3p", + "/usr/share/man/lt/man3x", + "/usr/share/man/lt/man4", + "/usr/share/man/lt/man4x", + "/usr/share/man/lt/man5", + "/usr/share/man/lt/man5x", + "/usr/share/man/lt/man6", + "/usr/share/man/lt/man6x", + "/usr/share/man/lt/man7", + "/usr/share/man/lt/man7x", + "/usr/share/man/lt/man8", + "/usr/share/man/lt/man8x", + "/usr/share/man/lt/man9", + "/usr/share/man/lt/man9x", + "/usr/share/man/lt/mann", + "/usr/share/man/lt_LT", + "/usr/share/man/lt_LT/man0p", + "/usr/share/man/lt_LT/man1", + "/usr/share/man/lt_LT/man1p", + "/usr/share/man/lt_LT/man1x", + "/usr/share/man/lt_LT/man2", + "/usr/share/man/lt_LT/man2x", + "/usr/share/man/lt_LT/man3", + "/usr/share/man/lt_LT/man3p", + "/usr/share/man/lt_LT/man3x", + "/usr/share/man/lt_LT/man4", + "/usr/share/man/lt_LT/man4x", + "/usr/share/man/lt_LT/man5", + "/usr/share/man/lt_LT/man5x", + "/usr/share/man/lt_LT/man6", + "/usr/share/man/lt_LT/man6x", + "/usr/share/man/lt_LT/man7", + "/usr/share/man/lt_LT/man7x", + "/usr/share/man/lt_LT/man8", + "/usr/share/man/lt_LT/man8x", + "/usr/share/man/lt_LT/man9", + "/usr/share/man/lt_LT/man9x", + "/usr/share/man/lt_LT/mann", + "/usr/share/man/ltg", + "/usr/share/man/ltg/man0p", + "/usr/share/man/ltg/man1", + "/usr/share/man/ltg/man1p", + "/usr/share/man/ltg/man1x", + "/usr/share/man/ltg/man2", + "/usr/share/man/ltg/man2x", + "/usr/share/man/ltg/man3", + "/usr/share/man/ltg/man3p", + "/usr/share/man/ltg/man3x", + "/usr/share/man/ltg/man4", + "/usr/share/man/ltg/man4x", + "/usr/share/man/ltg/man5", + "/usr/share/man/ltg/man5x", + "/usr/share/man/ltg/man6", + "/usr/share/man/ltg/man6x", + "/usr/share/man/ltg/man7", + "/usr/share/man/ltg/man7x", + "/usr/share/man/ltg/man8", + "/usr/share/man/ltg/man8x", + "/usr/share/man/ltg/man9", + "/usr/share/man/ltg/man9x", + "/usr/share/man/ltg/mann", + "/usr/share/man/lu", + "/usr/share/man/lu/man0p", + "/usr/share/man/lu/man1", + "/usr/share/man/lu/man1p", + "/usr/share/man/lu/man1x", + "/usr/share/man/lu/man2", + "/usr/share/man/lu/man2x", + "/usr/share/man/lu/man3", + "/usr/share/man/lu/man3p", + "/usr/share/man/lu/man3x", + "/usr/share/man/lu/man4", + "/usr/share/man/lu/man4x", + "/usr/share/man/lu/man5", + "/usr/share/man/lu/man5x", + "/usr/share/man/lu/man6", + "/usr/share/man/lu/man6x", + "/usr/share/man/lu/man7", + "/usr/share/man/lu/man7x", + "/usr/share/man/lu/man8", + "/usr/share/man/lu/man8x", + "/usr/share/man/lu/man9", + "/usr/share/man/lu/man9x", + "/usr/share/man/lu/mann", + "/usr/share/man/lua", + "/usr/share/man/lua/man0p", + "/usr/share/man/lua/man1", + "/usr/share/man/lua/man1p", + "/usr/share/man/lua/man1x", + "/usr/share/man/lua/man2", + "/usr/share/man/lua/man2x", + "/usr/share/man/lua/man3", + "/usr/share/man/lua/man3p", + "/usr/share/man/lua/man3x", + "/usr/share/man/lua/man4", + "/usr/share/man/lua/man4x", + "/usr/share/man/lua/man5", + "/usr/share/man/lua/man5x", + "/usr/share/man/lua/man6", + "/usr/share/man/lua/man6x", + "/usr/share/man/lua/man7", + "/usr/share/man/lua/man7x", + "/usr/share/man/lua/man8", + "/usr/share/man/lua/man8x", + "/usr/share/man/lua/man9", + "/usr/share/man/lua/man9x", + "/usr/share/man/lua/mann", + "/usr/share/man/lui", + "/usr/share/man/lui/man0p", + "/usr/share/man/lui/man1", + "/usr/share/man/lui/man1p", + "/usr/share/man/lui/man1x", + "/usr/share/man/lui/man2", + "/usr/share/man/lui/man2x", + "/usr/share/man/lui/man3", + "/usr/share/man/lui/man3p", + "/usr/share/man/lui/man3x", + "/usr/share/man/lui/man4", + "/usr/share/man/lui/man4x", + "/usr/share/man/lui/man5", + "/usr/share/man/lui/man5x", + "/usr/share/man/lui/man6", + "/usr/share/man/lui/man6x", + "/usr/share/man/lui/man7", + "/usr/share/man/lui/man7x", + "/usr/share/man/lui/man8", + "/usr/share/man/lui/man8x", + "/usr/share/man/lui/man9", + "/usr/share/man/lui/man9x", + "/usr/share/man/lui/mann", + "/usr/share/man/lun", + "/usr/share/man/lun/man0p", + "/usr/share/man/lun/man1", + "/usr/share/man/lun/man1p", + "/usr/share/man/lun/man1x", + "/usr/share/man/lun/man2", + "/usr/share/man/lun/man2x", + "/usr/share/man/lun/man3", + "/usr/share/man/lun/man3p", + "/usr/share/man/lun/man3x", + "/usr/share/man/lun/man4", + "/usr/share/man/lun/man4x", + "/usr/share/man/lun/man5", + "/usr/share/man/lun/man5x", + "/usr/share/man/lun/man6", + "/usr/share/man/lun/man6x", + "/usr/share/man/lun/man7", + "/usr/share/man/lun/man7x", + "/usr/share/man/lun/man8", + "/usr/share/man/lun/man8x", + "/usr/share/man/lun/man9", + "/usr/share/man/lun/man9x", + "/usr/share/man/lun/mann", + "/usr/share/man/luo", + "/usr/share/man/luo/man0p", + "/usr/share/man/luo/man1", + "/usr/share/man/luo/man1p", + "/usr/share/man/luo/man1x", + "/usr/share/man/luo/man2", + "/usr/share/man/luo/man2x", + "/usr/share/man/luo/man3", + "/usr/share/man/luo/man3p", + "/usr/share/man/luo/man3x", + "/usr/share/man/luo/man4", + "/usr/share/man/luo/man4x", + "/usr/share/man/luo/man5", + "/usr/share/man/luo/man5x", + "/usr/share/man/luo/man6", + "/usr/share/man/luo/man6x", + "/usr/share/man/luo/man7", + "/usr/share/man/luo/man7x", + "/usr/share/man/luo/man8", + "/usr/share/man/luo/man8x", + "/usr/share/man/luo/man9", + "/usr/share/man/luo/man9x", + "/usr/share/man/luo/mann", + "/usr/share/man/lus", + "/usr/share/man/lus/man0p", + "/usr/share/man/lus/man1", + "/usr/share/man/lus/man1p", + "/usr/share/man/lus/man1x", + "/usr/share/man/lus/man2", + "/usr/share/man/lus/man2x", + "/usr/share/man/lus/man3", + "/usr/share/man/lus/man3p", + "/usr/share/man/lus/man3x", + "/usr/share/man/lus/man4", + "/usr/share/man/lus/man4x", + "/usr/share/man/lus/man5", + "/usr/share/man/lus/man5x", + "/usr/share/man/lus/man6", + "/usr/share/man/lus/man6x", + "/usr/share/man/lus/man7", + "/usr/share/man/lus/man7x", + "/usr/share/man/lus/man8", + "/usr/share/man/lus/man8x", + "/usr/share/man/lus/man9", + "/usr/share/man/lus/man9x", + "/usr/share/man/lus/mann", + "/usr/share/man/lv", + "/usr/share/man/lv/man0p", + "/usr/share/man/lv/man1", + "/usr/share/man/lv/man1p", + "/usr/share/man/lv/man1x", + "/usr/share/man/lv/man2", + "/usr/share/man/lv/man2x", + "/usr/share/man/lv/man3", + "/usr/share/man/lv/man3p", + "/usr/share/man/lv/man3x", + "/usr/share/man/lv/man4", + "/usr/share/man/lv/man4x", + "/usr/share/man/lv/man5", + "/usr/share/man/lv/man5x", + "/usr/share/man/lv/man6", + "/usr/share/man/lv/man6x", + "/usr/share/man/lv/man7", + "/usr/share/man/lv/man7x", + "/usr/share/man/lv/man8", + "/usr/share/man/lv/man8x", + "/usr/share/man/lv/man9", + "/usr/share/man/lv/man9x", + "/usr/share/man/lv/mann", + "/usr/share/man/lv_LV", + "/usr/share/man/lv_LV/man0p", + "/usr/share/man/lv_LV/man1", + "/usr/share/man/lv_LV/man1p", + "/usr/share/man/lv_LV/man1x", + "/usr/share/man/lv_LV/man2", + "/usr/share/man/lv_LV/man2x", + "/usr/share/man/lv_LV/man3", + "/usr/share/man/lv_LV/man3p", + "/usr/share/man/lv_LV/man3x", + "/usr/share/man/lv_LV/man4", + "/usr/share/man/lv_LV/man4x", + "/usr/share/man/lv_LV/man5", + "/usr/share/man/lv_LV/man5x", + "/usr/share/man/lv_LV/man6", + "/usr/share/man/lv_LV/man6x", + "/usr/share/man/lv_LV/man7", + "/usr/share/man/lv_LV/man7x", + "/usr/share/man/lv_LV/man8", + "/usr/share/man/lv_LV/man8x", + "/usr/share/man/lv_LV/man9", + "/usr/share/man/lv_LV/man9x", + "/usr/share/man/lv_LV/mann", + "/usr/share/man/mad", + "/usr/share/man/mad/man0p", + "/usr/share/man/mad/man1", + "/usr/share/man/mad/man1p", + "/usr/share/man/mad/man1x", + "/usr/share/man/mad/man2", + "/usr/share/man/mad/man2x", + "/usr/share/man/mad/man3", + "/usr/share/man/mad/man3p", + "/usr/share/man/mad/man3x", + "/usr/share/man/mad/man4", + "/usr/share/man/mad/man4x", + "/usr/share/man/mad/man5", + "/usr/share/man/mad/man5x", + "/usr/share/man/mad/man6", + "/usr/share/man/mad/man6x", + "/usr/share/man/mad/man7", + "/usr/share/man/mad/man7x", + "/usr/share/man/mad/man8", + "/usr/share/man/mad/man8x", + "/usr/share/man/mad/man9", + "/usr/share/man/mad/man9x", + "/usr/share/man/mad/mann", + "/usr/share/man/mag", + "/usr/share/man/mag/man0p", + "/usr/share/man/mag/man1", + "/usr/share/man/mag/man1p", + "/usr/share/man/mag/man1x", + "/usr/share/man/mag/man2", + "/usr/share/man/mag/man2x", + "/usr/share/man/mag/man3", + "/usr/share/man/mag/man3p", + "/usr/share/man/mag/man3x", + "/usr/share/man/mag/man4", + "/usr/share/man/mag/man4x", + "/usr/share/man/mag/man5", + "/usr/share/man/mag/man5x", + "/usr/share/man/mag/man6", + "/usr/share/man/mag/man6x", + "/usr/share/man/mag/man7", + "/usr/share/man/mag/man7x", + "/usr/share/man/mag/man8", + "/usr/share/man/mag/man8x", + "/usr/share/man/mag/man9", + "/usr/share/man/mag/man9x", + "/usr/share/man/mag/mann", + "/usr/share/man/mai", + "/usr/share/man/mai/man0p", + "/usr/share/man/mai/man1", + "/usr/share/man/mai/man1p", + "/usr/share/man/mai/man1x", + "/usr/share/man/mai/man2", + "/usr/share/man/mai/man2x", + "/usr/share/man/mai/man3", + "/usr/share/man/mai/man3p", + "/usr/share/man/mai/man3x", + "/usr/share/man/mai/man4", + "/usr/share/man/mai/man4x", + "/usr/share/man/mai/man5", + "/usr/share/man/mai/man5x", + "/usr/share/man/mai/man6", + "/usr/share/man/mai/man6x", + "/usr/share/man/mai/man7", + "/usr/share/man/mai/man7x", + "/usr/share/man/mai/man8", + "/usr/share/man/mai/man8x", + "/usr/share/man/mai/man9", + "/usr/share/man/mai/man9x", + "/usr/share/man/mai/mann", + "/usr/share/man/mak", + "/usr/share/man/mak/man0p", + "/usr/share/man/mak/man1", + "/usr/share/man/mak/man1p", + "/usr/share/man/mak/man1x", + "/usr/share/man/mak/man2", + "/usr/share/man/mak/man2x", + "/usr/share/man/mak/man3", + "/usr/share/man/mak/man3p", + "/usr/share/man/mak/man3x", + "/usr/share/man/mak/man4", + "/usr/share/man/mak/man4x", + "/usr/share/man/mak/man5", + "/usr/share/man/mak/man5x", + "/usr/share/man/mak/man6", + "/usr/share/man/mak/man6x", + "/usr/share/man/mak/man7", + "/usr/share/man/mak/man7x", + "/usr/share/man/mak/man8", + "/usr/share/man/mak/man8x", + "/usr/share/man/mak/man9", + "/usr/share/man/mak/man9x", + "/usr/share/man/mak/mann", + "/usr/share/man/man", + "/usr/share/man/man/man0p", + "/usr/share/man/man/man1", + "/usr/share/man/man/man1p", + "/usr/share/man/man/man1x", + "/usr/share/man/man/man2", + "/usr/share/man/man/man2x", + "/usr/share/man/man/man3", + "/usr/share/man/man/man3p", + "/usr/share/man/man/man3x", + "/usr/share/man/man/man4", + "/usr/share/man/man/man4x", + "/usr/share/man/man/man5", + "/usr/share/man/man/man5x", + "/usr/share/man/man/man6", + "/usr/share/man/man/man6x", + "/usr/share/man/man/man7", + "/usr/share/man/man/man7x", + "/usr/share/man/man/man8", + "/usr/share/man/man/man8x", + "/usr/share/man/man/man9", + "/usr/share/man/man/man9x", + "/usr/share/man/man/mann", + "/usr/share/man/man0p", + "/usr/share/man/man1", + "/usr/share/man/man1p", + "/usr/share/man/man1x", + "/usr/share/man/man2", + "/usr/share/man/man2x", + "/usr/share/man/man3", + "/usr/share/man/man3p", + "/usr/share/man/man3x", + "/usr/share/man/man4", + "/usr/share/man/man4x", + "/usr/share/man/man5", + "/usr/share/man/man5x", + "/usr/share/man/man6", + "/usr/share/man/man6x", + "/usr/share/man/man7", + "/usr/share/man/man7x", + "/usr/share/man/man8", + "/usr/share/man/man8x", + "/usr/share/man/man9", + "/usr/share/man/man9x", + "/usr/share/man/mann", + "/usr/share/man/map", + "/usr/share/man/map/man0p", + "/usr/share/man/map/man1", + "/usr/share/man/map/man1p", + "/usr/share/man/map/man1x", + "/usr/share/man/map/man2", + "/usr/share/man/map/man2x", + "/usr/share/man/map/man3", + "/usr/share/man/map/man3p", + "/usr/share/man/map/man3x", + "/usr/share/man/map/man4", + "/usr/share/man/map/man4x", + "/usr/share/man/map/man5", + "/usr/share/man/map/man5x", + "/usr/share/man/map/man6", + "/usr/share/man/map/man6x", + "/usr/share/man/map/man7", + "/usr/share/man/map/man7x", + "/usr/share/man/map/man8", + "/usr/share/man/map/man8x", + "/usr/share/man/map/man9", + "/usr/share/man/map/man9x", + "/usr/share/man/map/mann", + "/usr/share/man/mas", + "/usr/share/man/mas/man0p", + "/usr/share/man/mas/man1", + "/usr/share/man/mas/man1p", + "/usr/share/man/mas/man1x", + "/usr/share/man/mas/man2", + "/usr/share/man/mas/man2x", + "/usr/share/man/mas/man3", + "/usr/share/man/mas/man3p", + "/usr/share/man/mas/man3x", + "/usr/share/man/mas/man4", + "/usr/share/man/mas/man4x", + "/usr/share/man/mas/man5", + "/usr/share/man/mas/man5x", + "/usr/share/man/mas/man6", + "/usr/share/man/mas/man6x", + "/usr/share/man/mas/man7", + "/usr/share/man/mas/man7x", + "/usr/share/man/mas/man8", + "/usr/share/man/mas/man8x", + "/usr/share/man/mas/man9", + "/usr/share/man/mas/man9x", + "/usr/share/man/mas/mann", + "/usr/share/man/mdf", + "/usr/share/man/mdf/man0p", + "/usr/share/man/mdf/man1", + "/usr/share/man/mdf/man1p", + "/usr/share/man/mdf/man1x", + "/usr/share/man/mdf/man2", + "/usr/share/man/mdf/man2x", + "/usr/share/man/mdf/man3", + "/usr/share/man/mdf/man3p", + "/usr/share/man/mdf/man3x", + "/usr/share/man/mdf/man4", + "/usr/share/man/mdf/man4x", + "/usr/share/man/mdf/man5", + "/usr/share/man/mdf/man5x", + "/usr/share/man/mdf/man6", + "/usr/share/man/mdf/man6x", + "/usr/share/man/mdf/man7", + "/usr/share/man/mdf/man7x", + "/usr/share/man/mdf/man8", + "/usr/share/man/mdf/man8x", + "/usr/share/man/mdf/man9", + "/usr/share/man/mdf/man9x", + "/usr/share/man/mdf/mann", + "/usr/share/man/mdr", + "/usr/share/man/mdr/man0p", + "/usr/share/man/mdr/man1", + "/usr/share/man/mdr/man1p", + "/usr/share/man/mdr/man1x", + "/usr/share/man/mdr/man2", + "/usr/share/man/mdr/man2x", + "/usr/share/man/mdr/man3", + "/usr/share/man/mdr/man3p", + "/usr/share/man/mdr/man3x", + "/usr/share/man/mdr/man4", + "/usr/share/man/mdr/man4x", + "/usr/share/man/mdr/man5", + "/usr/share/man/mdr/man5x", + "/usr/share/man/mdr/man6", + "/usr/share/man/mdr/man6x", + "/usr/share/man/mdr/man7", + "/usr/share/man/mdr/man7x", + "/usr/share/man/mdr/man8", + "/usr/share/man/mdr/man8x", + "/usr/share/man/mdr/man9", + "/usr/share/man/mdr/man9x", + "/usr/share/man/mdr/mann", + "/usr/share/man/men", + "/usr/share/man/men/man0p", + "/usr/share/man/men/man1", + "/usr/share/man/men/man1p", + "/usr/share/man/men/man1x", + "/usr/share/man/men/man2", + "/usr/share/man/men/man2x", + "/usr/share/man/men/man3", + "/usr/share/man/men/man3p", + "/usr/share/man/men/man3x", + "/usr/share/man/men/man4", + "/usr/share/man/men/man4x", + "/usr/share/man/men/man5", + "/usr/share/man/men/man5x", + "/usr/share/man/men/man6", + "/usr/share/man/men/man6x", + "/usr/share/man/men/man7", + "/usr/share/man/men/man7x", + "/usr/share/man/men/man8", + "/usr/share/man/men/man8x", + "/usr/share/man/men/man9", + "/usr/share/man/men/man9x", + "/usr/share/man/men/mann", + "/usr/share/man/mg", + "/usr/share/man/mg/man0p", + "/usr/share/man/mg/man1", + "/usr/share/man/mg/man1p", + "/usr/share/man/mg/man1x", + "/usr/share/man/mg/man2", + "/usr/share/man/mg/man2x", + "/usr/share/man/mg/man3", + "/usr/share/man/mg/man3p", + "/usr/share/man/mg/man3x", + "/usr/share/man/mg/man4", + "/usr/share/man/mg/man4x", + "/usr/share/man/mg/man5", + "/usr/share/man/mg/man5x", + "/usr/share/man/mg/man6", + "/usr/share/man/mg/man6x", + "/usr/share/man/mg/man7", + "/usr/share/man/mg/man7x", + "/usr/share/man/mg/man8", + "/usr/share/man/mg/man8x", + "/usr/share/man/mg/man9", + "/usr/share/man/mg/man9x", + "/usr/share/man/mg/mann", + "/usr/share/man/mga", + "/usr/share/man/mga/man0p", + "/usr/share/man/mga/man1", + "/usr/share/man/mga/man1p", + "/usr/share/man/mga/man1x", + "/usr/share/man/mga/man2", + "/usr/share/man/mga/man2x", + "/usr/share/man/mga/man3", + "/usr/share/man/mga/man3p", + "/usr/share/man/mga/man3x", + "/usr/share/man/mga/man4", + "/usr/share/man/mga/man4x", + "/usr/share/man/mga/man5", + "/usr/share/man/mga/man5x", + "/usr/share/man/mga/man6", + "/usr/share/man/mga/man6x", + "/usr/share/man/mga/man7", + "/usr/share/man/mga/man7x", + "/usr/share/man/mga/man8", + "/usr/share/man/mga/man8x", + "/usr/share/man/mga/man9", + "/usr/share/man/mga/man9x", + "/usr/share/man/mga/mann", + "/usr/share/man/mh", + "/usr/share/man/mh/man0p", + "/usr/share/man/mh/man1", + "/usr/share/man/mh/man1p", + "/usr/share/man/mh/man1x", + "/usr/share/man/mh/man2", + "/usr/share/man/mh/man2x", + "/usr/share/man/mh/man3", + "/usr/share/man/mh/man3p", + "/usr/share/man/mh/man3x", + "/usr/share/man/mh/man4", + "/usr/share/man/mh/man4x", + "/usr/share/man/mh/man5", + "/usr/share/man/mh/man5x", + "/usr/share/man/mh/man6", + "/usr/share/man/mh/man6x", + "/usr/share/man/mh/man7", + "/usr/share/man/mh/man7x", + "/usr/share/man/mh/man8", + "/usr/share/man/mh/man8x", + "/usr/share/man/mh/man9", + "/usr/share/man/mh/man9x", + "/usr/share/man/mh/mann", + "/usr/share/man/mhr", + "/usr/share/man/mhr/man0p", + "/usr/share/man/mhr/man1", + "/usr/share/man/mhr/man1p", + "/usr/share/man/mhr/man1x", + "/usr/share/man/mhr/man2", + "/usr/share/man/mhr/man2x", + "/usr/share/man/mhr/man3", + "/usr/share/man/mhr/man3p", + "/usr/share/man/mhr/man3x", + "/usr/share/man/mhr/man4", + "/usr/share/man/mhr/man4x", + "/usr/share/man/mhr/man5", + "/usr/share/man/mhr/man5x", + "/usr/share/man/mhr/man6", + "/usr/share/man/mhr/man6x", + "/usr/share/man/mhr/man7", + "/usr/share/man/mhr/man7x", + "/usr/share/man/mhr/man8", + "/usr/share/man/mhr/man8x", + "/usr/share/man/mhr/man9", + "/usr/share/man/mhr/man9x", + "/usr/share/man/mhr/mann", + "/usr/share/man/mi", + "/usr/share/man/mi/man0p", + "/usr/share/man/mi/man1", + "/usr/share/man/mi/man1p", + "/usr/share/man/mi/man1x", + "/usr/share/man/mi/man2", + "/usr/share/man/mi/man2x", + "/usr/share/man/mi/man3", + "/usr/share/man/mi/man3p", + "/usr/share/man/mi/man3x", + "/usr/share/man/mi/man4", + "/usr/share/man/mi/man4x", + "/usr/share/man/mi/man5", + "/usr/share/man/mi/man5x", + "/usr/share/man/mi/man6", + "/usr/share/man/mi/man6x", + "/usr/share/man/mi/man7", + "/usr/share/man/mi/man7x", + "/usr/share/man/mi/man8", + "/usr/share/man/mi/man8x", + "/usr/share/man/mi/man9", + "/usr/share/man/mi/man9x", + "/usr/share/man/mi/mann", + "/usr/share/man/mic", + "/usr/share/man/mic/man0p", + "/usr/share/man/mic/man1", + "/usr/share/man/mic/man1p", + "/usr/share/man/mic/man1x", + "/usr/share/man/mic/man2", + "/usr/share/man/mic/man2x", + "/usr/share/man/mic/man3", + "/usr/share/man/mic/man3p", + "/usr/share/man/mic/man3x", + "/usr/share/man/mic/man4", + "/usr/share/man/mic/man4x", + "/usr/share/man/mic/man5", + "/usr/share/man/mic/man5x", + "/usr/share/man/mic/man6", + "/usr/share/man/mic/man6x", + "/usr/share/man/mic/man7", + "/usr/share/man/mic/man7x", + "/usr/share/man/mic/man8", + "/usr/share/man/mic/man8x", + "/usr/share/man/mic/man9", + "/usr/share/man/mic/man9x", + "/usr/share/man/mic/mann", + "/usr/share/man/min", + "/usr/share/man/min/man0p", + "/usr/share/man/min/man1", + "/usr/share/man/min/man1p", + "/usr/share/man/min/man1x", + "/usr/share/man/min/man2", + "/usr/share/man/min/man2x", + "/usr/share/man/min/man3", + "/usr/share/man/min/man3p", + "/usr/share/man/min/man3x", + "/usr/share/man/min/man4", + "/usr/share/man/min/man4x", + "/usr/share/man/min/man5", + "/usr/share/man/min/man5x", + "/usr/share/man/min/man6", + "/usr/share/man/min/man6x", + "/usr/share/man/min/man7", + "/usr/share/man/min/man7x", + "/usr/share/man/min/man8", + "/usr/share/man/min/man8x", + "/usr/share/man/min/man9", + "/usr/share/man/min/man9x", + "/usr/share/man/min/mann", + "/usr/share/man/mis", + "/usr/share/man/mis/man0p", + "/usr/share/man/mis/man1", + "/usr/share/man/mis/man1p", + "/usr/share/man/mis/man1x", + "/usr/share/man/mis/man2", + "/usr/share/man/mis/man2x", + "/usr/share/man/mis/man3", + "/usr/share/man/mis/man3p", + "/usr/share/man/mis/man3x", + "/usr/share/man/mis/man4", + "/usr/share/man/mis/man4x", + "/usr/share/man/mis/man5", + "/usr/share/man/mis/man5x", + "/usr/share/man/mis/man6", + "/usr/share/man/mis/man6x", + "/usr/share/man/mis/man7", + "/usr/share/man/mis/man7x", + "/usr/share/man/mis/man8", + "/usr/share/man/mis/man8x", + "/usr/share/man/mis/man9", + "/usr/share/man/mis/man9x", + "/usr/share/man/mis/mann", + "/usr/share/man/mk", + "/usr/share/man/mk/man0p", + "/usr/share/man/mk/man1", + "/usr/share/man/mk/man1p", + "/usr/share/man/mk/man1x", + "/usr/share/man/mk/man2", + "/usr/share/man/mk/man2x", + "/usr/share/man/mk/man3", + "/usr/share/man/mk/man3p", + "/usr/share/man/mk/man3x", + "/usr/share/man/mk/man4", + "/usr/share/man/mk/man4x", + "/usr/share/man/mk/man5", + "/usr/share/man/mk/man5x", + "/usr/share/man/mk/man6", + "/usr/share/man/mk/man6x", + "/usr/share/man/mk/man7", + "/usr/share/man/mk/man7x", + "/usr/share/man/mk/man8", + "/usr/share/man/mk/man8x", + "/usr/share/man/mk/man9", + "/usr/share/man/mk/man9x", + "/usr/share/man/mk/mann", + "/usr/share/man/mk_MK", + "/usr/share/man/mk_MK/man0p", + "/usr/share/man/mk_MK/man1", + "/usr/share/man/mk_MK/man1p", + "/usr/share/man/mk_MK/man1x", + "/usr/share/man/mk_MK/man2", + "/usr/share/man/mk_MK/man2x", + "/usr/share/man/mk_MK/man3", + "/usr/share/man/mk_MK/man3p", + "/usr/share/man/mk_MK/man3x", + "/usr/share/man/mk_MK/man4", + "/usr/share/man/mk_MK/man4x", + "/usr/share/man/mk_MK/man5", + "/usr/share/man/mk_MK/man5x", + "/usr/share/man/mk_MK/man6", + "/usr/share/man/mk_MK/man6x", + "/usr/share/man/mk_MK/man7", + "/usr/share/man/mk_MK/man7x", + "/usr/share/man/mk_MK/man8", + "/usr/share/man/mk_MK/man8x", + "/usr/share/man/mk_MK/man9", + "/usr/share/man/mk_MK/man9x", + "/usr/share/man/mk_MK/mann", + "/usr/share/man/mkh", + "/usr/share/man/mkh/man0p", + "/usr/share/man/mkh/man1", + "/usr/share/man/mkh/man1p", + "/usr/share/man/mkh/man1x", + "/usr/share/man/mkh/man2", + "/usr/share/man/mkh/man2x", + "/usr/share/man/mkh/man3", + "/usr/share/man/mkh/man3p", + "/usr/share/man/mkh/man3x", + "/usr/share/man/mkh/man4", + "/usr/share/man/mkh/man4x", + "/usr/share/man/mkh/man5", + "/usr/share/man/mkh/man5x", + "/usr/share/man/mkh/man6", + "/usr/share/man/mkh/man6x", + "/usr/share/man/mkh/man7", + "/usr/share/man/mkh/man7x", + "/usr/share/man/mkh/man8", + "/usr/share/man/mkh/man8x", + "/usr/share/man/mkh/man9", + "/usr/share/man/mkh/man9x", + "/usr/share/man/mkh/mann", + "/usr/share/man/ml", + "/usr/share/man/ml/man0p", + "/usr/share/man/ml/man1", + "/usr/share/man/ml/man1p", + "/usr/share/man/ml/man1x", + "/usr/share/man/ml/man2", + "/usr/share/man/ml/man2x", + "/usr/share/man/ml/man3", + "/usr/share/man/ml/man3p", + "/usr/share/man/ml/man3x", + "/usr/share/man/ml/man4", + "/usr/share/man/ml/man4x", + "/usr/share/man/ml/man5", + "/usr/share/man/ml/man5x", + "/usr/share/man/ml/man6", + "/usr/share/man/ml/man6x", + "/usr/share/man/ml/man7", + "/usr/share/man/ml/man7x", + "/usr/share/man/ml/man8", + "/usr/share/man/ml/man8x", + "/usr/share/man/ml/man9", + "/usr/share/man/ml/man9x", + "/usr/share/man/ml/mann", + "/usr/share/man/ml_IN", + "/usr/share/man/ml_IN/man0p", + "/usr/share/man/ml_IN/man1", + "/usr/share/man/ml_IN/man1p", + "/usr/share/man/ml_IN/man1x", + "/usr/share/man/ml_IN/man2", + "/usr/share/man/ml_IN/man2x", + "/usr/share/man/ml_IN/man3", + "/usr/share/man/ml_IN/man3p", + "/usr/share/man/ml_IN/man3x", + "/usr/share/man/ml_IN/man4", + "/usr/share/man/ml_IN/man4x", + "/usr/share/man/ml_IN/man5", + "/usr/share/man/ml_IN/man5x", + "/usr/share/man/ml_IN/man6", + "/usr/share/man/ml_IN/man6x", + "/usr/share/man/ml_IN/man7", + "/usr/share/man/ml_IN/man7x", + "/usr/share/man/ml_IN/man8", + "/usr/share/man/ml_IN/man8x", + "/usr/share/man/ml_IN/man9", + "/usr/share/man/ml_IN/man9x", + "/usr/share/man/ml_IN/mann", + "/usr/share/man/mn", + "/usr/share/man/mn/man0p", + "/usr/share/man/mn/man1", + "/usr/share/man/mn/man1p", + "/usr/share/man/mn/man1x", + "/usr/share/man/mn/man2", + "/usr/share/man/mn/man2x", + "/usr/share/man/mn/man3", + "/usr/share/man/mn/man3p", + "/usr/share/man/mn/man3x", + "/usr/share/man/mn/man4", + "/usr/share/man/mn/man4x", + "/usr/share/man/mn/man5", + "/usr/share/man/mn/man5x", + "/usr/share/man/mn/man6", + "/usr/share/man/mn/man6x", + "/usr/share/man/mn/man7", + "/usr/share/man/mn/man7x", + "/usr/share/man/mn/man8", + "/usr/share/man/mn/man8x", + "/usr/share/man/mn/man9", + "/usr/share/man/mn/man9x", + "/usr/share/man/mn/mann", + "/usr/share/man/mnc", + "/usr/share/man/mnc/man0p", + "/usr/share/man/mnc/man1", + "/usr/share/man/mnc/man1p", + "/usr/share/man/mnc/man1x", + "/usr/share/man/mnc/man2", + "/usr/share/man/mnc/man2x", + "/usr/share/man/mnc/man3", + "/usr/share/man/mnc/man3p", + "/usr/share/man/mnc/man3x", + "/usr/share/man/mnc/man4", + "/usr/share/man/mnc/man4x", + "/usr/share/man/mnc/man5", + "/usr/share/man/mnc/man5x", + "/usr/share/man/mnc/man6", + "/usr/share/man/mnc/man6x", + "/usr/share/man/mnc/man7", + "/usr/share/man/mnc/man7x", + "/usr/share/man/mnc/man8", + "/usr/share/man/mnc/man8x", + "/usr/share/man/mnc/man9", + "/usr/share/man/mnc/man9x", + "/usr/share/man/mnc/mann", + "/usr/share/man/mni", + "/usr/share/man/mni/man0p", + "/usr/share/man/mni/man1", + "/usr/share/man/mni/man1p", + "/usr/share/man/mni/man1x", + "/usr/share/man/mni/man2", + "/usr/share/man/mni/man2x", + "/usr/share/man/mni/man3", + "/usr/share/man/mni/man3p", + "/usr/share/man/mni/man3x", + "/usr/share/man/mni/man4", + "/usr/share/man/mni/man4x", + "/usr/share/man/mni/man5", + "/usr/share/man/mni/man5x", + "/usr/share/man/mni/man6", + "/usr/share/man/mni/man6x", + "/usr/share/man/mni/man7", + "/usr/share/man/mni/man7x", + "/usr/share/man/mni/man8", + "/usr/share/man/mni/man8x", + "/usr/share/man/mni/man9", + "/usr/share/man/mni/man9x", + "/usr/share/man/mni/mann", + "/usr/share/man/mni@beng", + "/usr/share/man/mni@beng/man0p", + "/usr/share/man/mni@beng/man1", + "/usr/share/man/mni@beng/man1p", + "/usr/share/man/mni@beng/man1x", + "/usr/share/man/mni@beng/man2", + "/usr/share/man/mni@beng/man2x", + "/usr/share/man/mni@beng/man3", + "/usr/share/man/mni@beng/man3p", + "/usr/share/man/mni@beng/man3x", + "/usr/share/man/mni@beng/man4", + "/usr/share/man/mni@beng/man4x", + "/usr/share/man/mni@beng/man5", + "/usr/share/man/mni@beng/man5x", + "/usr/share/man/mni@beng/man6", + "/usr/share/man/mni@beng/man6x", + "/usr/share/man/mni@beng/man7", + "/usr/share/man/mni@beng/man7x", + "/usr/share/man/mni@beng/man8", + "/usr/share/man/mni@beng/man8x", + "/usr/share/man/mni@beng/man9", + "/usr/share/man/mni@beng/man9x", + "/usr/share/man/mni@beng/mann", + "/usr/share/man/mni@bengali", + "/usr/share/man/mni@bengali/man0p", + "/usr/share/man/mni@bengali/man1", + "/usr/share/man/mni@bengali/man1p", + "/usr/share/man/mni@bengali/man1x", + "/usr/share/man/mni@bengali/man2", + "/usr/share/man/mni@bengali/man2x", + "/usr/share/man/mni@bengali/man3", + "/usr/share/man/mni@bengali/man3p", + "/usr/share/man/mni@bengali/man3x", + "/usr/share/man/mni@bengali/man4", + "/usr/share/man/mni@bengali/man4x", + "/usr/share/man/mni@bengali/man5", + "/usr/share/man/mni@bengali/man5x", + "/usr/share/man/mni@bengali/man6", + "/usr/share/man/mni@bengali/man6x", + "/usr/share/man/mni@bengali/man7", + "/usr/share/man/mni@bengali/man7x", + "/usr/share/man/mni@bengali/man8", + "/usr/share/man/mni@bengali/man8x", + "/usr/share/man/mni@bengali/man9", + "/usr/share/man/mni@bengali/man9x", + "/usr/share/man/mni@bengali/mann", + "/usr/share/man/mni@meiteimayek", + "/usr/share/man/mni@meiteimayek/man0p", + "/usr/share/man/mni@meiteimayek/man1", + "/usr/share/man/mni@meiteimayek/man1p", + "/usr/share/man/mni@meiteimayek/man1x", + "/usr/share/man/mni@meiteimayek/man2", + "/usr/share/man/mni@meiteimayek/man2x", + "/usr/share/man/mni@meiteimayek/man3", + "/usr/share/man/mni@meiteimayek/man3p", + "/usr/share/man/mni@meiteimayek/man3x", + "/usr/share/man/mni@meiteimayek/man4", + "/usr/share/man/mni@meiteimayek/man4x", + "/usr/share/man/mni@meiteimayek/man5", + "/usr/share/man/mni@meiteimayek/man5x", + "/usr/share/man/mni@meiteimayek/man6", + "/usr/share/man/mni@meiteimayek/man6x", + "/usr/share/man/mni@meiteimayek/man7", + "/usr/share/man/mni@meiteimayek/man7x", + "/usr/share/man/mni@meiteimayek/man8", + "/usr/share/man/mni@meiteimayek/man8x", + "/usr/share/man/mni@meiteimayek/man9", + "/usr/share/man/mni@meiteimayek/man9x", + "/usr/share/man/mni@meiteimayek/mann", + "/usr/share/man/mnk", + "/usr/share/man/mnk/man0p", + "/usr/share/man/mnk/man1", + "/usr/share/man/mnk/man1p", + "/usr/share/man/mnk/man1x", + "/usr/share/man/mnk/man2", + "/usr/share/man/mnk/man2x", + "/usr/share/man/mnk/man3", + "/usr/share/man/mnk/man3p", + "/usr/share/man/mnk/man3x", + "/usr/share/man/mnk/man4", + "/usr/share/man/mnk/man4x", + "/usr/share/man/mnk/man5", + "/usr/share/man/mnk/man5x", + "/usr/share/man/mnk/man6", + "/usr/share/man/mnk/man6x", + "/usr/share/man/mnk/man7", + "/usr/share/man/mnk/man7x", + "/usr/share/man/mnk/man8", + "/usr/share/man/mnk/man8x", + "/usr/share/man/mnk/man9", + "/usr/share/man/mnk/man9x", + "/usr/share/man/mnk/mann", + "/usr/share/man/mno", + "/usr/share/man/mno/man0p", + "/usr/share/man/mno/man1", + "/usr/share/man/mno/man1p", + "/usr/share/man/mno/man1x", + "/usr/share/man/mno/man2", + "/usr/share/man/mno/man2x", + "/usr/share/man/mno/man3", + "/usr/share/man/mno/man3p", + "/usr/share/man/mno/man3x", + "/usr/share/man/mno/man4", + "/usr/share/man/mno/man4x", + "/usr/share/man/mno/man5", + "/usr/share/man/mno/man5x", + "/usr/share/man/mno/man6", + "/usr/share/man/mno/man6x", + "/usr/share/man/mno/man7", + "/usr/share/man/mno/man7x", + "/usr/share/man/mno/man8", + "/usr/share/man/mno/man8x", + "/usr/share/man/mno/man9", + "/usr/share/man/mno/man9x", + "/usr/share/man/mno/mann", + "/usr/share/man/moh", + "/usr/share/man/moh/man0p", + "/usr/share/man/moh/man1", + "/usr/share/man/moh/man1p", + "/usr/share/man/moh/man1x", + "/usr/share/man/moh/man2", + "/usr/share/man/moh/man2x", + "/usr/share/man/moh/man3", + "/usr/share/man/moh/man3p", + "/usr/share/man/moh/man3x", + "/usr/share/man/moh/man4", + "/usr/share/man/moh/man4x", + "/usr/share/man/moh/man5", + "/usr/share/man/moh/man5x", + "/usr/share/man/moh/man6", + "/usr/share/man/moh/man6x", + "/usr/share/man/moh/man7", + "/usr/share/man/moh/man7x", + "/usr/share/man/moh/man8", + "/usr/share/man/moh/man8x", + "/usr/share/man/moh/man9", + "/usr/share/man/moh/man9x", + "/usr/share/man/moh/mann", + "/usr/share/man/mos", + "/usr/share/man/mos/man0p", + "/usr/share/man/mos/man1", + "/usr/share/man/mos/man1p", + "/usr/share/man/mos/man1x", + "/usr/share/man/mos/man2", + "/usr/share/man/mos/man2x", + "/usr/share/man/mos/man3", + "/usr/share/man/mos/man3p", + "/usr/share/man/mos/man3x", + "/usr/share/man/mos/man4", + "/usr/share/man/mos/man4x", + "/usr/share/man/mos/man5", + "/usr/share/man/mos/man5x", + "/usr/share/man/mos/man6", + "/usr/share/man/mos/man6x", + "/usr/share/man/mos/man7", + "/usr/share/man/mos/man7x", + "/usr/share/man/mos/man8", + "/usr/share/man/mos/man8x", + "/usr/share/man/mos/man9", + "/usr/share/man/mos/man9x", + "/usr/share/man/mos/mann", + "/usr/share/man/mr", + "/usr/share/man/mr/man0p", + "/usr/share/man/mr/man1", + "/usr/share/man/mr/man1p", + "/usr/share/man/mr/man1x", + "/usr/share/man/mr/man2", + "/usr/share/man/mr/man2x", + "/usr/share/man/mr/man3", + "/usr/share/man/mr/man3p", + "/usr/share/man/mr/man3x", + "/usr/share/man/mr/man4", + "/usr/share/man/mr/man4x", + "/usr/share/man/mr/man5", + "/usr/share/man/mr/man5x", + "/usr/share/man/mr/man6", + "/usr/share/man/mr/man6x", + "/usr/share/man/mr/man7", + "/usr/share/man/mr/man7x", + "/usr/share/man/mr/man8", + "/usr/share/man/mr/man8x", + "/usr/share/man/mr/man9", + "/usr/share/man/mr/man9x", + "/usr/share/man/mr/mann", + "/usr/share/man/mr_IN", + "/usr/share/man/mr_IN/man0p", + "/usr/share/man/mr_IN/man1", + "/usr/share/man/mr_IN/man1p", + "/usr/share/man/mr_IN/man1x", + "/usr/share/man/mr_IN/man2", + "/usr/share/man/mr_IN/man2x", + "/usr/share/man/mr_IN/man3", + "/usr/share/man/mr_IN/man3p", + "/usr/share/man/mr_IN/man3x", + "/usr/share/man/mr_IN/man4", + "/usr/share/man/mr_IN/man4x", + "/usr/share/man/mr_IN/man5", + "/usr/share/man/mr_IN/man5x", + "/usr/share/man/mr_IN/man6", + "/usr/share/man/mr_IN/man6x", + "/usr/share/man/mr_IN/man7", + "/usr/share/man/mr_IN/man7x", + "/usr/share/man/mr_IN/man8", + "/usr/share/man/mr_IN/man8x", + "/usr/share/man/mr_IN/man9", + "/usr/share/man/mr_IN/man9x", + "/usr/share/man/mr_IN/mann", + "/usr/share/man/ms", + "/usr/share/man/ms/man0p", + "/usr/share/man/ms/man1", + "/usr/share/man/ms/man1p", + "/usr/share/man/ms/man1x", + "/usr/share/man/ms/man2", + "/usr/share/man/ms/man2x", + "/usr/share/man/ms/man3", + "/usr/share/man/ms/man3p", + "/usr/share/man/ms/man3x", + "/usr/share/man/ms/man4", + "/usr/share/man/ms/man4x", + "/usr/share/man/ms/man5", + "/usr/share/man/ms/man5x", + "/usr/share/man/ms/man6", + "/usr/share/man/ms/man6x", + "/usr/share/man/ms/man7", + "/usr/share/man/ms/man7x", + "/usr/share/man/ms/man8", + "/usr/share/man/ms/man8x", + "/usr/share/man/ms/man9", + "/usr/share/man/ms/man9x", + "/usr/share/man/ms/mann", + "/usr/share/man/ms_MY", + "/usr/share/man/ms_MY/man0p", + "/usr/share/man/ms_MY/man1", + "/usr/share/man/ms_MY/man1p", + "/usr/share/man/ms_MY/man1x", + "/usr/share/man/ms_MY/man2", + "/usr/share/man/ms_MY/man2x", + "/usr/share/man/ms_MY/man3", + "/usr/share/man/ms_MY/man3p", + "/usr/share/man/ms_MY/man3x", + "/usr/share/man/ms_MY/man4", + "/usr/share/man/ms_MY/man4x", + "/usr/share/man/ms_MY/man5", + "/usr/share/man/ms_MY/man5x", + "/usr/share/man/ms_MY/man6", + "/usr/share/man/ms_MY/man6x", + "/usr/share/man/ms_MY/man7", + "/usr/share/man/ms_MY/man7x", + "/usr/share/man/ms_MY/man8", + "/usr/share/man/ms_MY/man8x", + "/usr/share/man/ms_MY/man9", + "/usr/share/man/ms_MY/man9x", + "/usr/share/man/ms_MY/mann", + "/usr/share/man/mt", + "/usr/share/man/mt/man0p", + "/usr/share/man/mt/man1", + "/usr/share/man/mt/man1p", + "/usr/share/man/mt/man1x", + "/usr/share/man/mt/man2", + "/usr/share/man/mt/man2x", + "/usr/share/man/mt/man3", + "/usr/share/man/mt/man3p", + "/usr/share/man/mt/man3x", + "/usr/share/man/mt/man4", + "/usr/share/man/mt/man4x", + "/usr/share/man/mt/man5", + "/usr/share/man/mt/man5x", + "/usr/share/man/mt/man6", + "/usr/share/man/mt/man6x", + "/usr/share/man/mt/man7", + "/usr/share/man/mt/man7x", + "/usr/share/man/mt/man8", + "/usr/share/man/mt/man8x", + "/usr/share/man/mt/man9", + "/usr/share/man/mt/man9x", + "/usr/share/man/mt/mann", + "/usr/share/man/mul", + "/usr/share/man/mul/man0p", + "/usr/share/man/mul/man1", + "/usr/share/man/mul/man1p", + "/usr/share/man/mul/man1x", + "/usr/share/man/mul/man2", + "/usr/share/man/mul/man2x", + "/usr/share/man/mul/man3", + "/usr/share/man/mul/man3p", + "/usr/share/man/mul/man3x", + "/usr/share/man/mul/man4", + "/usr/share/man/mul/man4x", + "/usr/share/man/mul/man5", + "/usr/share/man/mul/man5x", + "/usr/share/man/mul/man6", + "/usr/share/man/mul/man6x", + "/usr/share/man/mul/man7", + "/usr/share/man/mul/man7x", + "/usr/share/man/mul/man8", + "/usr/share/man/mul/man8x", + "/usr/share/man/mul/man9", + "/usr/share/man/mul/man9x", + "/usr/share/man/mul/mann", + "/usr/share/man/mun", + "/usr/share/man/mun/man0p", + "/usr/share/man/mun/man1", + "/usr/share/man/mun/man1p", + "/usr/share/man/mun/man1x", + "/usr/share/man/mun/man2", + "/usr/share/man/mun/man2x", + "/usr/share/man/mun/man3", + "/usr/share/man/mun/man3p", + "/usr/share/man/mun/man3x", + "/usr/share/man/mun/man4", + "/usr/share/man/mun/man4x", + "/usr/share/man/mun/man5", + "/usr/share/man/mun/man5x", + "/usr/share/man/mun/man6", + "/usr/share/man/mun/man6x", + "/usr/share/man/mun/man7", + "/usr/share/man/mun/man7x", + "/usr/share/man/mun/man8", + "/usr/share/man/mun/man8x", + "/usr/share/man/mun/man9", + "/usr/share/man/mun/man9x", + "/usr/share/man/mun/mann", + "/usr/share/man/mus", + "/usr/share/man/mus/man0p", + "/usr/share/man/mus/man1", + "/usr/share/man/mus/man1p", + "/usr/share/man/mus/man1x", + "/usr/share/man/mus/man2", + "/usr/share/man/mus/man2x", + "/usr/share/man/mus/man3", + "/usr/share/man/mus/man3p", + "/usr/share/man/mus/man3x", + "/usr/share/man/mus/man4", + "/usr/share/man/mus/man4x", + "/usr/share/man/mus/man5", + "/usr/share/man/mus/man5x", + "/usr/share/man/mus/man6", + "/usr/share/man/mus/man6x", + "/usr/share/man/mus/man7", + "/usr/share/man/mus/man7x", + "/usr/share/man/mus/man8", + "/usr/share/man/mus/man8x", + "/usr/share/man/mus/man9", + "/usr/share/man/mus/man9x", + "/usr/share/man/mus/mann", + "/usr/share/man/mvo", + "/usr/share/man/mvo/man0p", + "/usr/share/man/mvo/man1", + "/usr/share/man/mvo/man1p", + "/usr/share/man/mvo/man1x", + "/usr/share/man/mvo/man2", + "/usr/share/man/mvo/man2x", + "/usr/share/man/mvo/man3", + "/usr/share/man/mvo/man3p", + "/usr/share/man/mvo/man3x", + "/usr/share/man/mvo/man4", + "/usr/share/man/mvo/man4x", + "/usr/share/man/mvo/man5", + "/usr/share/man/mvo/man5x", + "/usr/share/man/mvo/man6", + "/usr/share/man/mvo/man6x", + "/usr/share/man/mvo/man7", + "/usr/share/man/mvo/man7x", + "/usr/share/man/mvo/man8", + "/usr/share/man/mvo/man8x", + "/usr/share/man/mvo/man9", + "/usr/share/man/mvo/man9x", + "/usr/share/man/mvo/mann", + "/usr/share/man/mwl", + "/usr/share/man/mwl/man0p", + "/usr/share/man/mwl/man1", + "/usr/share/man/mwl/man1p", + "/usr/share/man/mwl/man1x", + "/usr/share/man/mwl/man2", + "/usr/share/man/mwl/man2x", + "/usr/share/man/mwl/man3", + "/usr/share/man/mwl/man3p", + "/usr/share/man/mwl/man3x", + "/usr/share/man/mwl/man4", + "/usr/share/man/mwl/man4x", + "/usr/share/man/mwl/man5", + "/usr/share/man/mwl/man5x", + "/usr/share/man/mwl/man6", + "/usr/share/man/mwl/man6x", + "/usr/share/man/mwl/man7", + "/usr/share/man/mwl/man7x", + "/usr/share/man/mwl/man8", + "/usr/share/man/mwl/man8x", + "/usr/share/man/mwl/man9", + "/usr/share/man/mwl/man9x", + "/usr/share/man/mwl/mann", + "/usr/share/man/mwr", + "/usr/share/man/mwr/man0p", + "/usr/share/man/mwr/man1", + "/usr/share/man/mwr/man1p", + "/usr/share/man/mwr/man1x", + "/usr/share/man/mwr/man2", + "/usr/share/man/mwr/man2x", + "/usr/share/man/mwr/man3", + "/usr/share/man/mwr/man3p", + "/usr/share/man/mwr/man3x", + "/usr/share/man/mwr/man4", + "/usr/share/man/mwr/man4x", + "/usr/share/man/mwr/man5", + "/usr/share/man/mwr/man5x", + "/usr/share/man/mwr/man6", + "/usr/share/man/mwr/man6x", + "/usr/share/man/mwr/man7", + "/usr/share/man/mwr/man7x", + "/usr/share/man/mwr/man8", + "/usr/share/man/mwr/man8x", + "/usr/share/man/mwr/man9", + "/usr/share/man/mwr/man9x", + "/usr/share/man/mwr/mann", + "/usr/share/man/my", + "/usr/share/man/my/man0p", + "/usr/share/man/my/man1", + "/usr/share/man/my/man1p", + "/usr/share/man/my/man1x", + "/usr/share/man/my/man2", + "/usr/share/man/my/man2x", + "/usr/share/man/my/man3", + "/usr/share/man/my/man3p", + "/usr/share/man/my/man3x", + "/usr/share/man/my/man4", + "/usr/share/man/my/man4x", + "/usr/share/man/my/man5", + "/usr/share/man/my/man5x", + "/usr/share/man/my/man6", + "/usr/share/man/my/man6x", + "/usr/share/man/my/man7", + "/usr/share/man/my/man7x", + "/usr/share/man/my/man8", + "/usr/share/man/my/man8x", + "/usr/share/man/my/man9", + "/usr/share/man/my/man9x", + "/usr/share/man/my/mann", + "/usr/share/man/my_MM", + "/usr/share/man/my_MM/man0p", + "/usr/share/man/my_MM/man1", + "/usr/share/man/my_MM/man1p", + "/usr/share/man/my_MM/man1x", + "/usr/share/man/my_MM/man2", + "/usr/share/man/my_MM/man2x", + "/usr/share/man/my_MM/man3", + "/usr/share/man/my_MM/man3p", + "/usr/share/man/my_MM/man3x", + "/usr/share/man/my_MM/man4", + "/usr/share/man/my_MM/man4x", + "/usr/share/man/my_MM/man5", + "/usr/share/man/my_MM/man5x", + "/usr/share/man/my_MM/man6", + "/usr/share/man/my_MM/man6x", + "/usr/share/man/my_MM/man7", + "/usr/share/man/my_MM/man7x", + "/usr/share/man/my_MM/man8", + "/usr/share/man/my_MM/man8x", + "/usr/share/man/my_MM/man9", + "/usr/share/man/my_MM/man9x", + "/usr/share/man/my_MM/mann", + "/usr/share/man/myn", + "/usr/share/man/myn/man0p", + "/usr/share/man/myn/man1", + "/usr/share/man/myn/man1p", + "/usr/share/man/myn/man1x", + "/usr/share/man/myn/man2", + "/usr/share/man/myn/man2x", + "/usr/share/man/myn/man3", + "/usr/share/man/myn/man3p", + "/usr/share/man/myn/man3x", + "/usr/share/man/myn/man4", + "/usr/share/man/myn/man4x", + "/usr/share/man/myn/man5", + "/usr/share/man/myn/man5x", + "/usr/share/man/myn/man6", + "/usr/share/man/myn/man6x", + "/usr/share/man/myn/man7", + "/usr/share/man/myn/man7x", + "/usr/share/man/myn/man8", + "/usr/share/man/myn/man8x", + "/usr/share/man/myn/man9", + "/usr/share/man/myn/man9x", + "/usr/share/man/myn/mann", + "/usr/share/man/myv", + "/usr/share/man/myv/man0p", + "/usr/share/man/myv/man1", + "/usr/share/man/myv/man1p", + "/usr/share/man/myv/man1x", + "/usr/share/man/myv/man2", + "/usr/share/man/myv/man2x", + "/usr/share/man/myv/man3", + "/usr/share/man/myv/man3p", + "/usr/share/man/myv/man3x", + "/usr/share/man/myv/man4", + "/usr/share/man/myv/man4x", + "/usr/share/man/myv/man5", + "/usr/share/man/myv/man5x", + "/usr/share/man/myv/man6", + "/usr/share/man/myv/man6x", + "/usr/share/man/myv/man7", + "/usr/share/man/myv/man7x", + "/usr/share/man/myv/man8", + "/usr/share/man/myv/man8x", + "/usr/share/man/myv/man9", + "/usr/share/man/myv/man9x", + "/usr/share/man/myv/mann", + "/usr/share/man/na", + "/usr/share/man/na/man0p", + "/usr/share/man/na/man1", + "/usr/share/man/na/man1p", + "/usr/share/man/na/man1x", + "/usr/share/man/na/man2", + "/usr/share/man/na/man2x", + "/usr/share/man/na/man3", + "/usr/share/man/na/man3p", + "/usr/share/man/na/man3x", + "/usr/share/man/na/man4", + "/usr/share/man/na/man4x", + "/usr/share/man/na/man5", + "/usr/share/man/na/man5x", + "/usr/share/man/na/man6", + "/usr/share/man/na/man6x", + "/usr/share/man/na/man7", + "/usr/share/man/na/man7x", + "/usr/share/man/na/man8", + "/usr/share/man/na/man8x", + "/usr/share/man/na/man9", + "/usr/share/man/na/man9x", + "/usr/share/man/na/mann", + "/usr/share/man/nah", + "/usr/share/man/nah/man0p", + "/usr/share/man/nah/man1", + "/usr/share/man/nah/man1p", + "/usr/share/man/nah/man1x", + "/usr/share/man/nah/man2", + "/usr/share/man/nah/man2x", + "/usr/share/man/nah/man3", + "/usr/share/man/nah/man3p", + "/usr/share/man/nah/man3x", + "/usr/share/man/nah/man4", + "/usr/share/man/nah/man4x", + "/usr/share/man/nah/man5", + "/usr/share/man/nah/man5x", + "/usr/share/man/nah/man6", + "/usr/share/man/nah/man6x", + "/usr/share/man/nah/man7", + "/usr/share/man/nah/man7x", + "/usr/share/man/nah/man8", + "/usr/share/man/nah/man8x", + "/usr/share/man/nah/man9", + "/usr/share/man/nah/man9x", + "/usr/share/man/nah/mann", + "/usr/share/man/nai", + "/usr/share/man/nai/man0p", + "/usr/share/man/nai/man1", + "/usr/share/man/nai/man1p", + "/usr/share/man/nai/man1x", + "/usr/share/man/nai/man2", + "/usr/share/man/nai/man2x", + "/usr/share/man/nai/man3", + "/usr/share/man/nai/man3p", + "/usr/share/man/nai/man3x", + "/usr/share/man/nai/man4", + "/usr/share/man/nai/man4x", + "/usr/share/man/nai/man5", + "/usr/share/man/nai/man5x", + "/usr/share/man/nai/man6", + "/usr/share/man/nai/man6x", + "/usr/share/man/nai/man7", + "/usr/share/man/nai/man7x", + "/usr/share/man/nai/man8", + "/usr/share/man/nai/man8x", + "/usr/share/man/nai/man9", + "/usr/share/man/nai/man9x", + "/usr/share/man/nai/mann", + "/usr/share/man/nan", + "/usr/share/man/nan/man0p", + "/usr/share/man/nan/man1", + "/usr/share/man/nan/man1p", + "/usr/share/man/nan/man1x", + "/usr/share/man/nan/man2", + "/usr/share/man/nan/man2x", + "/usr/share/man/nan/man3", + "/usr/share/man/nan/man3p", + "/usr/share/man/nan/man3x", + "/usr/share/man/nan/man4", + "/usr/share/man/nan/man4x", + "/usr/share/man/nan/man5", + "/usr/share/man/nan/man5x", + "/usr/share/man/nan/man6", + "/usr/share/man/nan/man6x", + "/usr/share/man/nan/man7", + "/usr/share/man/nan/man7x", + "/usr/share/man/nan/man8", + "/usr/share/man/nan/man8x", + "/usr/share/man/nan/man9", + "/usr/share/man/nan/man9x", + "/usr/share/man/nan/mann", + "/usr/share/man/nap", + "/usr/share/man/nap/man0p", + "/usr/share/man/nap/man1", + "/usr/share/man/nap/man1p", + "/usr/share/man/nap/man1x", + "/usr/share/man/nap/man2", + "/usr/share/man/nap/man2x", + "/usr/share/man/nap/man3", + "/usr/share/man/nap/man3p", + "/usr/share/man/nap/man3x", + "/usr/share/man/nap/man4", + "/usr/share/man/nap/man4x", + "/usr/share/man/nap/man5", + "/usr/share/man/nap/man5x", + "/usr/share/man/nap/man6", + "/usr/share/man/nap/man6x", + "/usr/share/man/nap/man7", + "/usr/share/man/nap/man7x", + "/usr/share/man/nap/man8", + "/usr/share/man/nap/man8x", + "/usr/share/man/nap/man9", + "/usr/share/man/nap/man9x", + "/usr/share/man/nap/mann", + "/usr/share/man/nb", + "/usr/share/man/nb/man0p", + "/usr/share/man/nb/man1", + "/usr/share/man/nb/man1p", + "/usr/share/man/nb/man1x", + "/usr/share/man/nb/man2", + "/usr/share/man/nb/man2x", + "/usr/share/man/nb/man3", + "/usr/share/man/nb/man3p", + "/usr/share/man/nb/man3x", + "/usr/share/man/nb/man4", + "/usr/share/man/nb/man4x", + "/usr/share/man/nb/man5", + "/usr/share/man/nb/man5x", + "/usr/share/man/nb/man6", + "/usr/share/man/nb/man6x", + "/usr/share/man/nb/man7", + "/usr/share/man/nb/man7x", + "/usr/share/man/nb/man8", + "/usr/share/man/nb/man8x", + "/usr/share/man/nb/man9", + "/usr/share/man/nb/man9x", + "/usr/share/man/nb/mann", + "/usr/share/man/nb_NO", + "/usr/share/man/nb_NO/man0p", + "/usr/share/man/nb_NO/man1", + "/usr/share/man/nb_NO/man1p", + "/usr/share/man/nb_NO/man1x", + "/usr/share/man/nb_NO/man2", + "/usr/share/man/nb_NO/man2x", + "/usr/share/man/nb_NO/man3", + "/usr/share/man/nb_NO/man3p", + "/usr/share/man/nb_NO/man3x", + "/usr/share/man/nb_NO/man4", + "/usr/share/man/nb_NO/man4x", + "/usr/share/man/nb_NO/man5", + "/usr/share/man/nb_NO/man5x", + "/usr/share/man/nb_NO/man6", + "/usr/share/man/nb_NO/man6x", + "/usr/share/man/nb_NO/man7", + "/usr/share/man/nb_NO/man7x", + "/usr/share/man/nb_NO/man8", + "/usr/share/man/nb_NO/man8x", + "/usr/share/man/nb_NO/man9", + "/usr/share/man/nb_NO/man9x", + "/usr/share/man/nb_NO/mann", + "/usr/share/man/nd", + "/usr/share/man/nd/man0p", + "/usr/share/man/nd/man1", + "/usr/share/man/nd/man1p", + "/usr/share/man/nd/man1x", + "/usr/share/man/nd/man2", + "/usr/share/man/nd/man2x", + "/usr/share/man/nd/man3", + "/usr/share/man/nd/man3p", + "/usr/share/man/nd/man3x", + "/usr/share/man/nd/man4", + "/usr/share/man/nd/man4x", + "/usr/share/man/nd/man5", + "/usr/share/man/nd/man5x", + "/usr/share/man/nd/man6", + "/usr/share/man/nd/man6x", + "/usr/share/man/nd/man7", + "/usr/share/man/nd/man7x", + "/usr/share/man/nd/man8", + "/usr/share/man/nd/man8x", + "/usr/share/man/nd/man9", + "/usr/share/man/nd/man9x", + "/usr/share/man/nd/mann", + "/usr/share/man/nds", + "/usr/share/man/nds/man0p", + "/usr/share/man/nds/man1", + "/usr/share/man/nds/man1p", + "/usr/share/man/nds/man1x", + "/usr/share/man/nds/man2", + "/usr/share/man/nds/man2x", + "/usr/share/man/nds/man3", + "/usr/share/man/nds/man3p", + "/usr/share/man/nds/man3x", + "/usr/share/man/nds/man4", + "/usr/share/man/nds/man4x", + "/usr/share/man/nds/man5", + "/usr/share/man/nds/man5x", + "/usr/share/man/nds/man6", + "/usr/share/man/nds/man6x", + "/usr/share/man/nds/man7", + "/usr/share/man/nds/man7x", + "/usr/share/man/nds/man8", + "/usr/share/man/nds/man8x", + "/usr/share/man/nds/man9", + "/usr/share/man/nds/man9x", + "/usr/share/man/nds/mann", + "/usr/share/man/ne", + "/usr/share/man/ne/man0p", + "/usr/share/man/ne/man1", + "/usr/share/man/ne/man1p", + "/usr/share/man/ne/man1x", + "/usr/share/man/ne/man2", + "/usr/share/man/ne/man2x", + "/usr/share/man/ne/man3", + "/usr/share/man/ne/man3p", + "/usr/share/man/ne/man3x", + "/usr/share/man/ne/man4", + "/usr/share/man/ne/man4x", + "/usr/share/man/ne/man5", + "/usr/share/man/ne/man5x", + "/usr/share/man/ne/man6", + "/usr/share/man/ne/man6x", + "/usr/share/man/ne/man7", + "/usr/share/man/ne/man7x", + "/usr/share/man/ne/man8", + "/usr/share/man/ne/man8x", + "/usr/share/man/ne/man9", + "/usr/share/man/ne/man9x", + "/usr/share/man/ne/mann", + "/usr/share/man/new", + "/usr/share/man/new/man0p", + "/usr/share/man/new/man1", + "/usr/share/man/new/man1p", + "/usr/share/man/new/man1x", + "/usr/share/man/new/man2", + "/usr/share/man/new/man2x", + "/usr/share/man/new/man3", + "/usr/share/man/new/man3p", + "/usr/share/man/new/man3x", + "/usr/share/man/new/man4", + "/usr/share/man/new/man4x", + "/usr/share/man/new/man5", + "/usr/share/man/new/man5x", + "/usr/share/man/new/man6", + "/usr/share/man/new/man6x", + "/usr/share/man/new/man7", + "/usr/share/man/new/man7x", + "/usr/share/man/new/man8", + "/usr/share/man/new/man8x", + "/usr/share/man/new/man9", + "/usr/share/man/new/man9x", + "/usr/share/man/new/mann", + "/usr/share/man/ng", + "/usr/share/man/ng/man0p", + "/usr/share/man/ng/man1", + "/usr/share/man/ng/man1p", + "/usr/share/man/ng/man1x", + "/usr/share/man/ng/man2", + "/usr/share/man/ng/man2x", + "/usr/share/man/ng/man3", + "/usr/share/man/ng/man3p", + "/usr/share/man/ng/man3x", + "/usr/share/man/ng/man4", + "/usr/share/man/ng/man4x", + "/usr/share/man/ng/man5", + "/usr/share/man/ng/man5x", + "/usr/share/man/ng/man6", + "/usr/share/man/ng/man6x", + "/usr/share/man/ng/man7", + "/usr/share/man/ng/man7x", + "/usr/share/man/ng/man8", + "/usr/share/man/ng/man8x", + "/usr/share/man/ng/man9", + "/usr/share/man/ng/man9x", + "/usr/share/man/ng/mann", + "/usr/share/man/nia", + "/usr/share/man/nia/man0p", + "/usr/share/man/nia/man1", + "/usr/share/man/nia/man1p", + "/usr/share/man/nia/man1x", + "/usr/share/man/nia/man2", + "/usr/share/man/nia/man2x", + "/usr/share/man/nia/man3", + "/usr/share/man/nia/man3p", + "/usr/share/man/nia/man3x", + "/usr/share/man/nia/man4", + "/usr/share/man/nia/man4x", + "/usr/share/man/nia/man5", + "/usr/share/man/nia/man5x", + "/usr/share/man/nia/man6", + "/usr/share/man/nia/man6x", + "/usr/share/man/nia/man7", + "/usr/share/man/nia/man7x", + "/usr/share/man/nia/man8", + "/usr/share/man/nia/man8x", + "/usr/share/man/nia/man9", + "/usr/share/man/nia/man9x", + "/usr/share/man/nia/mann", + "/usr/share/man/nic", + "/usr/share/man/nic/man0p", + "/usr/share/man/nic/man1", + "/usr/share/man/nic/man1p", + "/usr/share/man/nic/man1x", + "/usr/share/man/nic/man2", + "/usr/share/man/nic/man2x", + "/usr/share/man/nic/man3", + "/usr/share/man/nic/man3p", + "/usr/share/man/nic/man3x", + "/usr/share/man/nic/man4", + "/usr/share/man/nic/man4x", + "/usr/share/man/nic/man5", + "/usr/share/man/nic/man5x", + "/usr/share/man/nic/man6", + "/usr/share/man/nic/man6x", + "/usr/share/man/nic/man7", + "/usr/share/man/nic/man7x", + "/usr/share/man/nic/man8", + "/usr/share/man/nic/man8x", + "/usr/share/man/nic/man9", + "/usr/share/man/nic/man9x", + "/usr/share/man/nic/mann", + "/usr/share/man/niu", + "/usr/share/man/niu/man0p", + "/usr/share/man/niu/man1", + "/usr/share/man/niu/man1p", + "/usr/share/man/niu/man1x", + "/usr/share/man/niu/man2", + "/usr/share/man/niu/man2x", + "/usr/share/man/niu/man3", + "/usr/share/man/niu/man3p", + "/usr/share/man/niu/man3x", + "/usr/share/man/niu/man4", + "/usr/share/man/niu/man4x", + "/usr/share/man/niu/man5", + "/usr/share/man/niu/man5x", + "/usr/share/man/niu/man6", + "/usr/share/man/niu/man6x", + "/usr/share/man/niu/man7", + "/usr/share/man/niu/man7x", + "/usr/share/man/niu/man8", + "/usr/share/man/niu/man8x", + "/usr/share/man/niu/man9", + "/usr/share/man/niu/man9x", + "/usr/share/man/niu/mann", + "/usr/share/man/nl", + "/usr/share/man/nl.us-ascii", + "/usr/share/man/nl.us-ascii/man0p", + "/usr/share/man/nl.us-ascii/man1", + "/usr/share/man/nl.us-ascii/man1p", + "/usr/share/man/nl.us-ascii/man1x", + "/usr/share/man/nl.us-ascii/man2", + "/usr/share/man/nl.us-ascii/man2x", + "/usr/share/man/nl.us-ascii/man3", + "/usr/share/man/nl.us-ascii/man3p", + "/usr/share/man/nl.us-ascii/man3x", + "/usr/share/man/nl.us-ascii/man4", + "/usr/share/man/nl.us-ascii/man4x", + "/usr/share/man/nl.us-ascii/man5", + "/usr/share/man/nl.us-ascii/man5x", + "/usr/share/man/nl.us-ascii/man6", + "/usr/share/man/nl.us-ascii/man6x", + "/usr/share/man/nl.us-ascii/man7", + "/usr/share/man/nl.us-ascii/man7x", + "/usr/share/man/nl.us-ascii/man8", + "/usr/share/man/nl.us-ascii/man8x", + "/usr/share/man/nl.us-ascii/man9", + "/usr/share/man/nl.us-ascii/man9x", + "/usr/share/man/nl.us-ascii/mann", + "/usr/share/man/nl/man0p", + "/usr/share/man/nl/man1", + "/usr/share/man/nl/man1p", + "/usr/share/man/nl/man1x", + "/usr/share/man/nl/man2", + "/usr/share/man/nl/man2x", + "/usr/share/man/nl/man3", + "/usr/share/man/nl/man3p", + "/usr/share/man/nl/man3x", + "/usr/share/man/nl/man4", + "/usr/share/man/nl/man4x", + "/usr/share/man/nl/man5", + "/usr/share/man/nl/man5x", + "/usr/share/man/nl/man6", + "/usr/share/man/nl/man6x", + "/usr/share/man/nl/man7", + "/usr/share/man/nl/man7x", + "/usr/share/man/nl/man8", + "/usr/share/man/nl/man8x", + "/usr/share/man/nl/man9", + "/usr/share/man/nl/man9x", + "/usr/share/man/nl/mann", + "/usr/share/man/nl_BE", + "/usr/share/man/nl_BE/man0p", + "/usr/share/man/nl_BE/man1", + "/usr/share/man/nl_BE/man1p", + "/usr/share/man/nl_BE/man1x", + "/usr/share/man/nl_BE/man2", + "/usr/share/man/nl_BE/man2x", + "/usr/share/man/nl_BE/man3", + "/usr/share/man/nl_BE/man3p", + "/usr/share/man/nl_BE/man3x", + "/usr/share/man/nl_BE/man4", + "/usr/share/man/nl_BE/man4x", + "/usr/share/man/nl_BE/man5", + "/usr/share/man/nl_BE/man5x", + "/usr/share/man/nl_BE/man6", + "/usr/share/man/nl_BE/man6x", + "/usr/share/man/nl_BE/man7", + "/usr/share/man/nl_BE/man7x", + "/usr/share/man/nl_BE/man8", + "/usr/share/man/nl_BE/man8x", + "/usr/share/man/nl_BE/man9", + "/usr/share/man/nl_BE/man9x", + "/usr/share/man/nl_BE/mann", + "/usr/share/man/nl_NL", + "/usr/share/man/nl_NL/man0p", + "/usr/share/man/nl_NL/man1", + "/usr/share/man/nl_NL/man1p", + "/usr/share/man/nl_NL/man1x", + "/usr/share/man/nl_NL/man2", + "/usr/share/man/nl_NL/man2x", + "/usr/share/man/nl_NL/man3", + "/usr/share/man/nl_NL/man3p", + "/usr/share/man/nl_NL/man3x", + "/usr/share/man/nl_NL/man4", + "/usr/share/man/nl_NL/man4x", + "/usr/share/man/nl_NL/man5", + "/usr/share/man/nl_NL/man5x", + "/usr/share/man/nl_NL/man6", + "/usr/share/man/nl_NL/man6x", + "/usr/share/man/nl_NL/man7", + "/usr/share/man/nl_NL/man7x", + "/usr/share/man/nl_NL/man8", + "/usr/share/man/nl_NL/man8x", + "/usr/share/man/nl_NL/man9", + "/usr/share/man/nl_NL/man9x", + "/usr/share/man/nl_NL/mann", + "/usr/share/man/nn", + "/usr/share/man/nn/man0p", + "/usr/share/man/nn/man1", + "/usr/share/man/nn/man1p", + "/usr/share/man/nn/man1x", + "/usr/share/man/nn/man2", + "/usr/share/man/nn/man2x", + "/usr/share/man/nn/man3", + "/usr/share/man/nn/man3p", + "/usr/share/man/nn/man3x", + "/usr/share/man/nn/man4", + "/usr/share/man/nn/man4x", + "/usr/share/man/nn/man5", + "/usr/share/man/nn/man5x", + "/usr/share/man/nn/man6", + "/usr/share/man/nn/man6x", + "/usr/share/man/nn/man7", + "/usr/share/man/nn/man7x", + "/usr/share/man/nn/man8", + "/usr/share/man/nn/man8x", + "/usr/share/man/nn/man9", + "/usr/share/man/nn/man9x", + "/usr/share/man/nn/mann", + "/usr/share/man/nn_NO", + "/usr/share/man/nn_NO/man0p", + "/usr/share/man/nn_NO/man1", + "/usr/share/man/nn_NO/man1p", + "/usr/share/man/nn_NO/man1x", + "/usr/share/man/nn_NO/man2", + "/usr/share/man/nn_NO/man2x", + "/usr/share/man/nn_NO/man3", + "/usr/share/man/nn_NO/man3p", + "/usr/share/man/nn_NO/man3x", + "/usr/share/man/nn_NO/man4", + "/usr/share/man/nn_NO/man4x", + "/usr/share/man/nn_NO/man5", + "/usr/share/man/nn_NO/man5x", + "/usr/share/man/nn_NO/man6", + "/usr/share/man/nn_NO/man6x", + "/usr/share/man/nn_NO/man7", + "/usr/share/man/nn_NO/man7x", + "/usr/share/man/nn_NO/man8", + "/usr/share/man/nn_NO/man8x", + "/usr/share/man/nn_NO/man9", + "/usr/share/man/nn_NO/man9x", + "/usr/share/man/nn_NO/mann", + "/usr/share/man/no", + "/usr/share/man/no.us-ascii", + "/usr/share/man/no.us-ascii/man0p", + "/usr/share/man/no.us-ascii/man1", + "/usr/share/man/no.us-ascii/man1p", + "/usr/share/man/no.us-ascii/man1x", + "/usr/share/man/no.us-ascii/man2", + "/usr/share/man/no.us-ascii/man2x", + "/usr/share/man/no.us-ascii/man3", + "/usr/share/man/no.us-ascii/man3p", + "/usr/share/man/no.us-ascii/man3x", + "/usr/share/man/no.us-ascii/man4", + "/usr/share/man/no.us-ascii/man4x", + "/usr/share/man/no.us-ascii/man5", + "/usr/share/man/no.us-ascii/man5x", + "/usr/share/man/no.us-ascii/man6", + "/usr/share/man/no.us-ascii/man6x", + "/usr/share/man/no.us-ascii/man7", + "/usr/share/man/no.us-ascii/man7x", + "/usr/share/man/no.us-ascii/man8", + "/usr/share/man/no.us-ascii/man8x", + "/usr/share/man/no.us-ascii/man9", + "/usr/share/man/no.us-ascii/man9x", + "/usr/share/man/no.us-ascii/mann", + "/usr/share/man/no/man0p", + "/usr/share/man/no/man1", + "/usr/share/man/no/man1p", + "/usr/share/man/no/man1x", + "/usr/share/man/no/man2", + "/usr/share/man/no/man2x", + "/usr/share/man/no/man3", + "/usr/share/man/no/man3p", + "/usr/share/man/no/man3x", + "/usr/share/man/no/man4", + "/usr/share/man/no/man4x", + "/usr/share/man/no/man5", + "/usr/share/man/no/man5x", + "/usr/share/man/no/man6", + "/usr/share/man/no/man6x", + "/usr/share/man/no/man7", + "/usr/share/man/no/man7x", + "/usr/share/man/no/man8", + "/usr/share/man/no/man8x", + "/usr/share/man/no/man9", + "/usr/share/man/no/man9x", + "/usr/share/man/no/mann", + "/usr/share/man/no_NO", + "/usr/share/man/no_NO/man0p", + "/usr/share/man/no_NO/man1", + "/usr/share/man/no_NO/man1p", + "/usr/share/man/no_NO/man1x", + "/usr/share/man/no_NO/man2", + "/usr/share/man/no_NO/man2x", + "/usr/share/man/no_NO/man3", + "/usr/share/man/no_NO/man3p", + "/usr/share/man/no_NO/man3x", + "/usr/share/man/no_NO/man4", + "/usr/share/man/no_NO/man4x", + "/usr/share/man/no_NO/man5", + "/usr/share/man/no_NO/man5x", + "/usr/share/man/no_NO/man6", + "/usr/share/man/no_NO/man6x", + "/usr/share/man/no_NO/man7", + "/usr/share/man/no_NO/man7x", + "/usr/share/man/no_NO/man8", + "/usr/share/man/no_NO/man8x", + "/usr/share/man/no_NO/man9", + "/usr/share/man/no_NO/man9x", + "/usr/share/man/no_NO/mann", + "/usr/share/man/nog", + "/usr/share/man/nog/man0p", + "/usr/share/man/nog/man1", + "/usr/share/man/nog/man1p", + "/usr/share/man/nog/man1x", + "/usr/share/man/nog/man2", + "/usr/share/man/nog/man2x", + "/usr/share/man/nog/man3", + "/usr/share/man/nog/man3p", + "/usr/share/man/nog/man3x", + "/usr/share/man/nog/man4", + "/usr/share/man/nog/man4x", + "/usr/share/man/nog/man5", + "/usr/share/man/nog/man5x", + "/usr/share/man/nog/man6", + "/usr/share/man/nog/man6x", + "/usr/share/man/nog/man7", + "/usr/share/man/nog/man7x", + "/usr/share/man/nog/man8", + "/usr/share/man/nog/man8x", + "/usr/share/man/nog/man9", + "/usr/share/man/nog/man9x", + "/usr/share/man/nog/mann", + "/usr/share/man/non", + "/usr/share/man/non/man0p", + "/usr/share/man/non/man1", + "/usr/share/man/non/man1p", + "/usr/share/man/non/man1x", + "/usr/share/man/non/man2", + "/usr/share/man/non/man2x", + "/usr/share/man/non/man3", + "/usr/share/man/non/man3p", + "/usr/share/man/non/man3x", + "/usr/share/man/non/man4", + "/usr/share/man/non/man4x", + "/usr/share/man/non/man5", + "/usr/share/man/non/man5x", + "/usr/share/man/non/man6", + "/usr/share/man/non/man6x", + "/usr/share/man/non/man7", + "/usr/share/man/non/man7x", + "/usr/share/man/non/man8", + "/usr/share/man/non/man8x", + "/usr/share/man/non/man9", + "/usr/share/man/non/man9x", + "/usr/share/man/non/mann", + "/usr/share/man/nqo", + "/usr/share/man/nqo/man0p", + "/usr/share/man/nqo/man1", + "/usr/share/man/nqo/man1p", + "/usr/share/man/nqo/man1x", + "/usr/share/man/nqo/man2", + "/usr/share/man/nqo/man2x", + "/usr/share/man/nqo/man3", + "/usr/share/man/nqo/man3p", + "/usr/share/man/nqo/man3x", + "/usr/share/man/nqo/man4", + "/usr/share/man/nqo/man4x", + "/usr/share/man/nqo/man5", + "/usr/share/man/nqo/man5x", + "/usr/share/man/nqo/man6", + "/usr/share/man/nqo/man6x", + "/usr/share/man/nqo/man7", + "/usr/share/man/nqo/man7x", + "/usr/share/man/nqo/man8", + "/usr/share/man/nqo/man8x", + "/usr/share/man/nqo/man9", + "/usr/share/man/nqo/man9x", + "/usr/share/man/nqo/mann", + "/usr/share/man/nr", + "/usr/share/man/nr/man0p", + "/usr/share/man/nr/man1", + "/usr/share/man/nr/man1p", + "/usr/share/man/nr/man1x", + "/usr/share/man/nr/man2", + "/usr/share/man/nr/man2x", + "/usr/share/man/nr/man3", + "/usr/share/man/nr/man3p", + "/usr/share/man/nr/man3x", + "/usr/share/man/nr/man4", + "/usr/share/man/nr/man4x", + "/usr/share/man/nr/man5", + "/usr/share/man/nr/man5x", + "/usr/share/man/nr/man6", + "/usr/share/man/nr/man6x", + "/usr/share/man/nr/man7", + "/usr/share/man/nr/man7x", + "/usr/share/man/nr/man8", + "/usr/share/man/nr/man8x", + "/usr/share/man/nr/man9", + "/usr/share/man/nr/man9x", + "/usr/share/man/nr/mann", + "/usr/share/man/nso", + "/usr/share/man/nso/man0p", + "/usr/share/man/nso/man1", + "/usr/share/man/nso/man1p", + "/usr/share/man/nso/man1x", + "/usr/share/man/nso/man2", + "/usr/share/man/nso/man2x", + "/usr/share/man/nso/man3", + "/usr/share/man/nso/man3p", + "/usr/share/man/nso/man3x", + "/usr/share/man/nso/man4", + "/usr/share/man/nso/man4x", + "/usr/share/man/nso/man5", + "/usr/share/man/nso/man5x", + "/usr/share/man/nso/man6", + "/usr/share/man/nso/man6x", + "/usr/share/man/nso/man7", + "/usr/share/man/nso/man7x", + "/usr/share/man/nso/man8", + "/usr/share/man/nso/man8x", + "/usr/share/man/nso/man9", + "/usr/share/man/nso/man9x", + "/usr/share/man/nso/mann", + "/usr/share/man/nub", + "/usr/share/man/nub/man0p", + "/usr/share/man/nub/man1", + "/usr/share/man/nub/man1p", + "/usr/share/man/nub/man1x", + "/usr/share/man/nub/man2", + "/usr/share/man/nub/man2x", + "/usr/share/man/nub/man3", + "/usr/share/man/nub/man3p", + "/usr/share/man/nub/man3x", + "/usr/share/man/nub/man4", + "/usr/share/man/nub/man4x", + "/usr/share/man/nub/man5", + "/usr/share/man/nub/man5x", + "/usr/share/man/nub/man6", + "/usr/share/man/nub/man6x", + "/usr/share/man/nub/man7", + "/usr/share/man/nub/man7x", + "/usr/share/man/nub/man8", + "/usr/share/man/nub/man8x", + "/usr/share/man/nub/man9", + "/usr/share/man/nub/man9x", + "/usr/share/man/nub/mann", + "/usr/share/man/nv", + "/usr/share/man/nv/man0p", + "/usr/share/man/nv/man1", + "/usr/share/man/nv/man1p", + "/usr/share/man/nv/man1x", + "/usr/share/man/nv/man2", + "/usr/share/man/nv/man2x", + "/usr/share/man/nv/man3", + "/usr/share/man/nv/man3p", + "/usr/share/man/nv/man3x", + "/usr/share/man/nv/man4", + "/usr/share/man/nv/man4x", + "/usr/share/man/nv/man5", + "/usr/share/man/nv/man5x", + "/usr/share/man/nv/man6", + "/usr/share/man/nv/man6x", + "/usr/share/man/nv/man7", + "/usr/share/man/nv/man7x", + "/usr/share/man/nv/man8", + "/usr/share/man/nv/man8x", + "/usr/share/man/nv/man9", + "/usr/share/man/nv/man9x", + "/usr/share/man/nv/mann", + "/usr/share/man/nwc", + "/usr/share/man/nwc/man0p", + "/usr/share/man/nwc/man1", + "/usr/share/man/nwc/man1p", + "/usr/share/man/nwc/man1x", + "/usr/share/man/nwc/man2", + "/usr/share/man/nwc/man2x", + "/usr/share/man/nwc/man3", + "/usr/share/man/nwc/man3p", + "/usr/share/man/nwc/man3x", + "/usr/share/man/nwc/man4", + "/usr/share/man/nwc/man4x", + "/usr/share/man/nwc/man5", + "/usr/share/man/nwc/man5x", + "/usr/share/man/nwc/man6", + "/usr/share/man/nwc/man6x", + "/usr/share/man/nwc/man7", + "/usr/share/man/nwc/man7x", + "/usr/share/man/nwc/man8", + "/usr/share/man/nwc/man8x", + "/usr/share/man/nwc/man9", + "/usr/share/man/nwc/man9x", + "/usr/share/man/nwc/mann", + "/usr/share/man/ny", + "/usr/share/man/ny/man0p", + "/usr/share/man/ny/man1", + "/usr/share/man/ny/man1p", + "/usr/share/man/ny/man1x", + "/usr/share/man/ny/man2", + "/usr/share/man/ny/man2x", + "/usr/share/man/ny/man3", + "/usr/share/man/ny/man3p", + "/usr/share/man/ny/man3x", + "/usr/share/man/ny/man4", + "/usr/share/man/ny/man4x", + "/usr/share/man/ny/man5", + "/usr/share/man/ny/man5x", + "/usr/share/man/ny/man6", + "/usr/share/man/ny/man6x", + "/usr/share/man/ny/man7", + "/usr/share/man/ny/man7x", + "/usr/share/man/ny/man8", + "/usr/share/man/ny/man8x", + "/usr/share/man/ny/man9", + "/usr/share/man/ny/man9x", + "/usr/share/man/ny/mann", + "/usr/share/man/nym", + "/usr/share/man/nym/man0p", + "/usr/share/man/nym/man1", + "/usr/share/man/nym/man1p", + "/usr/share/man/nym/man1x", + "/usr/share/man/nym/man2", + "/usr/share/man/nym/man2x", + "/usr/share/man/nym/man3", + "/usr/share/man/nym/man3p", + "/usr/share/man/nym/man3x", + "/usr/share/man/nym/man4", + "/usr/share/man/nym/man4x", + "/usr/share/man/nym/man5", + "/usr/share/man/nym/man5x", + "/usr/share/man/nym/man6", + "/usr/share/man/nym/man6x", + "/usr/share/man/nym/man7", + "/usr/share/man/nym/man7x", + "/usr/share/man/nym/man8", + "/usr/share/man/nym/man8x", + "/usr/share/man/nym/man9", + "/usr/share/man/nym/man9x", + "/usr/share/man/nym/mann", + "/usr/share/man/nyn", + "/usr/share/man/nyn/man0p", + "/usr/share/man/nyn/man1", + "/usr/share/man/nyn/man1p", + "/usr/share/man/nyn/man1x", + "/usr/share/man/nyn/man2", + "/usr/share/man/nyn/man2x", + "/usr/share/man/nyn/man3", + "/usr/share/man/nyn/man3p", + "/usr/share/man/nyn/man3x", + "/usr/share/man/nyn/man4", + "/usr/share/man/nyn/man4x", + "/usr/share/man/nyn/man5", + "/usr/share/man/nyn/man5x", + "/usr/share/man/nyn/man6", + "/usr/share/man/nyn/man6x", + "/usr/share/man/nyn/man7", + "/usr/share/man/nyn/man7x", + "/usr/share/man/nyn/man8", + "/usr/share/man/nyn/man8x", + "/usr/share/man/nyn/man9", + "/usr/share/man/nyn/man9x", + "/usr/share/man/nyn/mann", + "/usr/share/man/nyo", + "/usr/share/man/nyo/man0p", + "/usr/share/man/nyo/man1", + "/usr/share/man/nyo/man1p", + "/usr/share/man/nyo/man1x", + "/usr/share/man/nyo/man2", + "/usr/share/man/nyo/man2x", + "/usr/share/man/nyo/man3", + "/usr/share/man/nyo/man3p", + "/usr/share/man/nyo/man3x", + "/usr/share/man/nyo/man4", + "/usr/share/man/nyo/man4x", + "/usr/share/man/nyo/man5", + "/usr/share/man/nyo/man5x", + "/usr/share/man/nyo/man6", + "/usr/share/man/nyo/man6x", + "/usr/share/man/nyo/man7", + "/usr/share/man/nyo/man7x", + "/usr/share/man/nyo/man8", + "/usr/share/man/nyo/man8x", + "/usr/share/man/nyo/man9", + "/usr/share/man/nyo/man9x", + "/usr/share/man/nyo/mann", + "/usr/share/man/nzi", + "/usr/share/man/nzi/man0p", + "/usr/share/man/nzi/man1", + "/usr/share/man/nzi/man1p", + "/usr/share/man/nzi/man1x", + "/usr/share/man/nzi/man2", + "/usr/share/man/nzi/man2x", + "/usr/share/man/nzi/man3", + "/usr/share/man/nzi/man3p", + "/usr/share/man/nzi/man3x", + "/usr/share/man/nzi/man4", + "/usr/share/man/nzi/man4x", + "/usr/share/man/nzi/man5", + "/usr/share/man/nzi/man5x", + "/usr/share/man/nzi/man6", + "/usr/share/man/nzi/man6x", + "/usr/share/man/nzi/man7", + "/usr/share/man/nzi/man7x", + "/usr/share/man/nzi/man8", + "/usr/share/man/nzi/man8x", + "/usr/share/man/nzi/man9", + "/usr/share/man/nzi/man9x", + "/usr/share/man/nzi/mann", + "/usr/share/man/oc", + "/usr/share/man/oc/man0p", + "/usr/share/man/oc/man1", + "/usr/share/man/oc/man1p", + "/usr/share/man/oc/man1x", + "/usr/share/man/oc/man2", + "/usr/share/man/oc/man2x", + "/usr/share/man/oc/man3", + "/usr/share/man/oc/man3p", + "/usr/share/man/oc/man3x", + "/usr/share/man/oc/man4", + "/usr/share/man/oc/man4x", + "/usr/share/man/oc/man5", + "/usr/share/man/oc/man5x", + "/usr/share/man/oc/man6", + "/usr/share/man/oc/man6x", + "/usr/share/man/oc/man7", + "/usr/share/man/oc/man7x", + "/usr/share/man/oc/man8", + "/usr/share/man/oc/man8x", + "/usr/share/man/oc/man9", + "/usr/share/man/oc/man9x", + "/usr/share/man/oc/mann", + "/usr/share/man/oj", + "/usr/share/man/oj/man0p", + "/usr/share/man/oj/man1", + "/usr/share/man/oj/man1p", + "/usr/share/man/oj/man1x", + "/usr/share/man/oj/man2", + "/usr/share/man/oj/man2x", + "/usr/share/man/oj/man3", + "/usr/share/man/oj/man3p", + "/usr/share/man/oj/man3x", + "/usr/share/man/oj/man4", + "/usr/share/man/oj/man4x", + "/usr/share/man/oj/man5", + "/usr/share/man/oj/man5x", + "/usr/share/man/oj/man6", + "/usr/share/man/oj/man6x", + "/usr/share/man/oj/man7", + "/usr/share/man/oj/man7x", + "/usr/share/man/oj/man8", + "/usr/share/man/oj/man8x", + "/usr/share/man/oj/man9", + "/usr/share/man/oj/man9x", + "/usr/share/man/oj/mann", + "/usr/share/man/om", + "/usr/share/man/om/man0p", + "/usr/share/man/om/man1", + "/usr/share/man/om/man1p", + "/usr/share/man/om/man1x", + "/usr/share/man/om/man2", + "/usr/share/man/om/man2x", + "/usr/share/man/om/man3", + "/usr/share/man/om/man3p", + "/usr/share/man/om/man3x", + "/usr/share/man/om/man4", + "/usr/share/man/om/man4x", + "/usr/share/man/om/man5", + "/usr/share/man/om/man5x", + "/usr/share/man/om/man6", + "/usr/share/man/om/man6x", + "/usr/share/man/om/man7", + "/usr/share/man/om/man7x", + "/usr/share/man/om/man8", + "/usr/share/man/om/man8x", + "/usr/share/man/om/man9", + "/usr/share/man/om/man9x", + "/usr/share/man/om/mann", + "/usr/share/man/or", + "/usr/share/man/or/man0p", + "/usr/share/man/or/man1", + "/usr/share/man/or/man1p", + "/usr/share/man/or/man1x", + "/usr/share/man/or/man2", + "/usr/share/man/or/man2x", + "/usr/share/man/or/man3", + "/usr/share/man/or/man3p", + "/usr/share/man/or/man3x", + "/usr/share/man/or/man4", + "/usr/share/man/or/man4x", + "/usr/share/man/or/man5", + "/usr/share/man/or/man5x", + "/usr/share/man/or/man6", + "/usr/share/man/or/man6x", + "/usr/share/man/or/man7", + "/usr/share/man/or/man7x", + "/usr/share/man/or/man8", + "/usr/share/man/or/man8x", + "/usr/share/man/or/man9", + "/usr/share/man/or/man9x", + "/usr/share/man/or/mann", + "/usr/share/man/or_IN", + "/usr/share/man/or_IN/man0p", + "/usr/share/man/or_IN/man1", + "/usr/share/man/or_IN/man1p", + "/usr/share/man/or_IN/man1x", + "/usr/share/man/or_IN/man2", + "/usr/share/man/or_IN/man2x", + "/usr/share/man/or_IN/man3", + "/usr/share/man/or_IN/man3p", + "/usr/share/man/or_IN/man3x", + "/usr/share/man/or_IN/man4", + "/usr/share/man/or_IN/man4x", + "/usr/share/man/or_IN/man5", + "/usr/share/man/or_IN/man5x", + "/usr/share/man/or_IN/man6", + "/usr/share/man/or_IN/man6x", + "/usr/share/man/or_IN/man7", + "/usr/share/man/or_IN/man7x", + "/usr/share/man/or_IN/man8", + "/usr/share/man/or_IN/man8x", + "/usr/share/man/or_IN/man9", + "/usr/share/man/or_IN/man9x", + "/usr/share/man/or_IN/mann", + "/usr/share/man/os", + "/usr/share/man/os/man0p", + "/usr/share/man/os/man1", + "/usr/share/man/os/man1p", + "/usr/share/man/os/man1x", + "/usr/share/man/os/man2", + "/usr/share/man/os/man2x", + "/usr/share/man/os/man3", + "/usr/share/man/os/man3p", + "/usr/share/man/os/man3x", + "/usr/share/man/os/man4", + "/usr/share/man/os/man4x", + "/usr/share/man/os/man5", + "/usr/share/man/os/man5x", + "/usr/share/man/os/man6", + "/usr/share/man/os/man6x", + "/usr/share/man/os/man7", + "/usr/share/man/os/man7x", + "/usr/share/man/os/man8", + "/usr/share/man/os/man8x", + "/usr/share/man/os/man9", + "/usr/share/man/os/man9x", + "/usr/share/man/os/mann", + "/usr/share/man/osa", + "/usr/share/man/osa/man0p", + "/usr/share/man/osa/man1", + "/usr/share/man/osa/man1p", + "/usr/share/man/osa/man1x", + "/usr/share/man/osa/man2", + "/usr/share/man/osa/man2x", + "/usr/share/man/osa/man3", + "/usr/share/man/osa/man3p", + "/usr/share/man/osa/man3x", + "/usr/share/man/osa/man4", + "/usr/share/man/osa/man4x", + "/usr/share/man/osa/man5", + "/usr/share/man/osa/man5x", + "/usr/share/man/osa/man6", + "/usr/share/man/osa/man6x", + "/usr/share/man/osa/man7", + "/usr/share/man/osa/man7x", + "/usr/share/man/osa/man8", + "/usr/share/man/osa/man8x", + "/usr/share/man/osa/man9", + "/usr/share/man/osa/man9x", + "/usr/share/man/osa/mann", + "/usr/share/man/ota", + "/usr/share/man/ota/man0p", + "/usr/share/man/ota/man1", + "/usr/share/man/ota/man1p", + "/usr/share/man/ota/man1x", + "/usr/share/man/ota/man2", + "/usr/share/man/ota/man2x", + "/usr/share/man/ota/man3", + "/usr/share/man/ota/man3p", + "/usr/share/man/ota/man3x", + "/usr/share/man/ota/man4", + "/usr/share/man/ota/man4x", + "/usr/share/man/ota/man5", + "/usr/share/man/ota/man5x", + "/usr/share/man/ota/man6", + "/usr/share/man/ota/man6x", + "/usr/share/man/ota/man7", + "/usr/share/man/ota/man7x", + "/usr/share/man/ota/man8", + "/usr/share/man/ota/man8x", + "/usr/share/man/ota/man9", + "/usr/share/man/ota/man9x", + "/usr/share/man/ota/mann", + "/usr/share/man/oto", + "/usr/share/man/oto/man0p", + "/usr/share/man/oto/man1", + "/usr/share/man/oto/man1p", + "/usr/share/man/oto/man1x", + "/usr/share/man/oto/man2", + "/usr/share/man/oto/man2x", + "/usr/share/man/oto/man3", + "/usr/share/man/oto/man3p", + "/usr/share/man/oto/man3x", + "/usr/share/man/oto/man4", + "/usr/share/man/oto/man4x", + "/usr/share/man/oto/man5", + "/usr/share/man/oto/man5x", + "/usr/share/man/oto/man6", + "/usr/share/man/oto/man6x", + "/usr/share/man/oto/man7", + "/usr/share/man/oto/man7x", + "/usr/share/man/oto/man8", + "/usr/share/man/oto/man8x", + "/usr/share/man/oto/man9", + "/usr/share/man/oto/man9x", + "/usr/share/man/oto/mann", + "/usr/share/man/pa", + "/usr/share/man/pa/man0p", + "/usr/share/man/pa/man1", + "/usr/share/man/pa/man1p", + "/usr/share/man/pa/man1x", + "/usr/share/man/pa/man2", + "/usr/share/man/pa/man2x", + "/usr/share/man/pa/man3", + "/usr/share/man/pa/man3p", + "/usr/share/man/pa/man3x", + "/usr/share/man/pa/man4", + "/usr/share/man/pa/man4x", + "/usr/share/man/pa/man5", + "/usr/share/man/pa/man5x", + "/usr/share/man/pa/man6", + "/usr/share/man/pa/man6x", + "/usr/share/man/pa/man7", + "/usr/share/man/pa/man7x", + "/usr/share/man/pa/man8", + "/usr/share/man/pa/man8x", + "/usr/share/man/pa/man9", + "/usr/share/man/pa/man9x", + "/usr/share/man/pa/mann", + "/usr/share/man/paa", + "/usr/share/man/paa/man0p", + "/usr/share/man/paa/man1", + "/usr/share/man/paa/man1p", + "/usr/share/man/paa/man1x", + "/usr/share/man/paa/man2", + "/usr/share/man/paa/man2x", + "/usr/share/man/paa/man3", + "/usr/share/man/paa/man3p", + "/usr/share/man/paa/man3x", + "/usr/share/man/paa/man4", + "/usr/share/man/paa/man4x", + "/usr/share/man/paa/man5", + "/usr/share/man/paa/man5x", + "/usr/share/man/paa/man6", + "/usr/share/man/paa/man6x", + "/usr/share/man/paa/man7", + "/usr/share/man/paa/man7x", + "/usr/share/man/paa/man8", + "/usr/share/man/paa/man8x", + "/usr/share/man/paa/man9", + "/usr/share/man/paa/man9x", + "/usr/share/man/paa/mann", + "/usr/share/man/pag", + "/usr/share/man/pag/man0p", + "/usr/share/man/pag/man1", + "/usr/share/man/pag/man1p", + "/usr/share/man/pag/man1x", + "/usr/share/man/pag/man2", + "/usr/share/man/pag/man2x", + "/usr/share/man/pag/man3", + "/usr/share/man/pag/man3p", + "/usr/share/man/pag/man3x", + "/usr/share/man/pag/man4", + "/usr/share/man/pag/man4x", + "/usr/share/man/pag/man5", + "/usr/share/man/pag/man5x", + "/usr/share/man/pag/man6", + "/usr/share/man/pag/man6x", + "/usr/share/man/pag/man7", + "/usr/share/man/pag/man7x", + "/usr/share/man/pag/man8", + "/usr/share/man/pag/man8x", + "/usr/share/man/pag/man9", + "/usr/share/man/pag/man9x", + "/usr/share/man/pag/mann", + "/usr/share/man/pal", + "/usr/share/man/pal/man0p", + "/usr/share/man/pal/man1", + "/usr/share/man/pal/man1p", + "/usr/share/man/pal/man1x", + "/usr/share/man/pal/man2", + "/usr/share/man/pal/man2x", + "/usr/share/man/pal/man3", + "/usr/share/man/pal/man3p", + "/usr/share/man/pal/man3x", + "/usr/share/man/pal/man4", + "/usr/share/man/pal/man4x", + "/usr/share/man/pal/man5", + "/usr/share/man/pal/man5x", + "/usr/share/man/pal/man6", + "/usr/share/man/pal/man6x", + "/usr/share/man/pal/man7", + "/usr/share/man/pal/man7x", + "/usr/share/man/pal/man8", + "/usr/share/man/pal/man8x", + "/usr/share/man/pal/man9", + "/usr/share/man/pal/man9x", + "/usr/share/man/pal/mann", + "/usr/share/man/pam", + "/usr/share/man/pam/man0p", + "/usr/share/man/pam/man1", + "/usr/share/man/pam/man1p", + "/usr/share/man/pam/man1x", + "/usr/share/man/pam/man2", + "/usr/share/man/pam/man2x", + "/usr/share/man/pam/man3", + "/usr/share/man/pam/man3p", + "/usr/share/man/pam/man3x", + "/usr/share/man/pam/man4", + "/usr/share/man/pam/man4x", + "/usr/share/man/pam/man5", + "/usr/share/man/pam/man5x", + "/usr/share/man/pam/man6", + "/usr/share/man/pam/man6x", + "/usr/share/man/pam/man7", + "/usr/share/man/pam/man7x", + "/usr/share/man/pam/man8", + "/usr/share/man/pam/man8x", + "/usr/share/man/pam/man9", + "/usr/share/man/pam/man9x", + "/usr/share/man/pam/mann", + "/usr/share/man/pap", + "/usr/share/man/pap/man0p", + "/usr/share/man/pap/man1", + "/usr/share/man/pap/man1p", + "/usr/share/man/pap/man1x", + "/usr/share/man/pap/man2", + "/usr/share/man/pap/man2x", + "/usr/share/man/pap/man3", + "/usr/share/man/pap/man3p", + "/usr/share/man/pap/man3x", + "/usr/share/man/pap/man4", + "/usr/share/man/pap/man4x", + "/usr/share/man/pap/man5", + "/usr/share/man/pap/man5x", + "/usr/share/man/pap/man6", + "/usr/share/man/pap/man6x", + "/usr/share/man/pap/man7", + "/usr/share/man/pap/man7x", + "/usr/share/man/pap/man8", + "/usr/share/man/pap/man8x", + "/usr/share/man/pap/man9", + "/usr/share/man/pap/man9x", + "/usr/share/man/pap/mann", + "/usr/share/man/pau", + "/usr/share/man/pau/man0p", + "/usr/share/man/pau/man1", + "/usr/share/man/pau/man1p", + "/usr/share/man/pau/man1x", + "/usr/share/man/pau/man2", + "/usr/share/man/pau/man2x", + "/usr/share/man/pau/man3", + "/usr/share/man/pau/man3p", + "/usr/share/man/pau/man3x", + "/usr/share/man/pau/man4", + "/usr/share/man/pau/man4x", + "/usr/share/man/pau/man5", + "/usr/share/man/pau/man5x", + "/usr/share/man/pau/man6", + "/usr/share/man/pau/man6x", + "/usr/share/man/pau/man7", + "/usr/share/man/pau/man7x", + "/usr/share/man/pau/man8", + "/usr/share/man/pau/man8x", + "/usr/share/man/pau/man9", + "/usr/share/man/pau/man9x", + "/usr/share/man/pau/mann", + "/usr/share/man/pbs", + "/usr/share/man/pbs/man0p", + "/usr/share/man/pbs/man1", + "/usr/share/man/pbs/man1p", + "/usr/share/man/pbs/man1x", + "/usr/share/man/pbs/man2", + "/usr/share/man/pbs/man2x", + "/usr/share/man/pbs/man3", + "/usr/share/man/pbs/man3p", + "/usr/share/man/pbs/man3x", + "/usr/share/man/pbs/man4", + "/usr/share/man/pbs/man4x", + "/usr/share/man/pbs/man5", + "/usr/share/man/pbs/man5x", + "/usr/share/man/pbs/man6", + "/usr/share/man/pbs/man6x", + "/usr/share/man/pbs/man7", + "/usr/share/man/pbs/man7x", + "/usr/share/man/pbs/man8", + "/usr/share/man/pbs/man8x", + "/usr/share/man/pbs/man9", + "/usr/share/man/pbs/man9x", + "/usr/share/man/pbs/mann", + "/usr/share/man/peo", + "/usr/share/man/peo/man0p", + "/usr/share/man/peo/man1", + "/usr/share/man/peo/man1p", + "/usr/share/man/peo/man1x", + "/usr/share/man/peo/man2", + "/usr/share/man/peo/man2x", + "/usr/share/man/peo/man3", + "/usr/share/man/peo/man3p", + "/usr/share/man/peo/man3x", + "/usr/share/man/peo/man4", + "/usr/share/man/peo/man4x", + "/usr/share/man/peo/man5", + "/usr/share/man/peo/man5x", + "/usr/share/man/peo/man6", + "/usr/share/man/peo/man6x", + "/usr/share/man/peo/man7", + "/usr/share/man/peo/man7x", + "/usr/share/man/peo/man8", + "/usr/share/man/peo/man8x", + "/usr/share/man/peo/man9", + "/usr/share/man/peo/man9x", + "/usr/share/man/peo/mann", + "/usr/share/man/phi", + "/usr/share/man/phi/man0p", + "/usr/share/man/phi/man1", + "/usr/share/man/phi/man1p", + "/usr/share/man/phi/man1x", + "/usr/share/man/phi/man2", + "/usr/share/man/phi/man2x", + "/usr/share/man/phi/man3", + "/usr/share/man/phi/man3p", + "/usr/share/man/phi/man3x", + "/usr/share/man/phi/man4", + "/usr/share/man/phi/man4x", + "/usr/share/man/phi/man5", + "/usr/share/man/phi/man5x", + "/usr/share/man/phi/man6", + "/usr/share/man/phi/man6x", + "/usr/share/man/phi/man7", + "/usr/share/man/phi/man7x", + "/usr/share/man/phi/man8", + "/usr/share/man/phi/man8x", + "/usr/share/man/phi/man9", + "/usr/share/man/phi/man9x", + "/usr/share/man/phi/mann", + "/usr/share/man/phn", + "/usr/share/man/phn/man0p", + "/usr/share/man/phn/man1", + "/usr/share/man/phn/man1p", + "/usr/share/man/phn/man1x", + "/usr/share/man/phn/man2", + "/usr/share/man/phn/man2x", + "/usr/share/man/phn/man3", + "/usr/share/man/phn/man3p", + "/usr/share/man/phn/man3x", + "/usr/share/man/phn/man4", + "/usr/share/man/phn/man4x", + "/usr/share/man/phn/man5", + "/usr/share/man/phn/man5x", + "/usr/share/man/phn/man6", + "/usr/share/man/phn/man6x", + "/usr/share/man/phn/man7", + "/usr/share/man/phn/man7x", + "/usr/share/man/phn/man8", + "/usr/share/man/phn/man8x", + "/usr/share/man/phn/man9", + "/usr/share/man/phn/man9x", + "/usr/share/man/phn/mann", + "/usr/share/man/pi", + "/usr/share/man/pi/man0p", + "/usr/share/man/pi/man1", + "/usr/share/man/pi/man1p", + "/usr/share/man/pi/man1x", + "/usr/share/man/pi/man2", + "/usr/share/man/pi/man2x", + "/usr/share/man/pi/man3", + "/usr/share/man/pi/man3p", + "/usr/share/man/pi/man3x", + "/usr/share/man/pi/man4", + "/usr/share/man/pi/man4x", + "/usr/share/man/pi/man5", + "/usr/share/man/pi/man5x", + "/usr/share/man/pi/man6", + "/usr/share/man/pi/man6x", + "/usr/share/man/pi/man7", + "/usr/share/man/pi/man7x", + "/usr/share/man/pi/man8", + "/usr/share/man/pi/man8x", + "/usr/share/man/pi/man9", + "/usr/share/man/pi/man9x", + "/usr/share/man/pi/mann", + "/usr/share/man/pis", + "/usr/share/man/pis/man0p", + "/usr/share/man/pis/man1", + "/usr/share/man/pis/man1p", + "/usr/share/man/pis/man1x", + "/usr/share/man/pis/man2", + "/usr/share/man/pis/man2x", + "/usr/share/man/pis/man3", + "/usr/share/man/pis/man3p", + "/usr/share/man/pis/man3x", + "/usr/share/man/pis/man4", + "/usr/share/man/pis/man4x", + "/usr/share/man/pis/man5", + "/usr/share/man/pis/man5x", + "/usr/share/man/pis/man6", + "/usr/share/man/pis/man6x", + "/usr/share/man/pis/man7", + "/usr/share/man/pis/man7x", + "/usr/share/man/pis/man8", + "/usr/share/man/pis/man8x", + "/usr/share/man/pis/man9", + "/usr/share/man/pis/man9x", + "/usr/share/man/pis/mann", + "/usr/share/man/pl", + "/usr/share/man/pl/man0p", + "/usr/share/man/pl/man1", + "/usr/share/man/pl/man1p", + "/usr/share/man/pl/man1x", + "/usr/share/man/pl/man2", + "/usr/share/man/pl/man2x", + "/usr/share/man/pl/man3", + "/usr/share/man/pl/man3p", + "/usr/share/man/pl/man3x", + "/usr/share/man/pl/man4", + "/usr/share/man/pl/man4x", + "/usr/share/man/pl/man5", + "/usr/share/man/pl/man5x", + "/usr/share/man/pl/man6", + "/usr/share/man/pl/man6x", + "/usr/share/man/pl/man7", + "/usr/share/man/pl/man7x", + "/usr/share/man/pl/man8", + "/usr/share/man/pl/man8x", + "/usr/share/man/pl/man9", + "/usr/share/man/pl/man9x", + "/usr/share/man/pl/mann", + "/usr/share/man/pl_PL", + "/usr/share/man/pl_PL/man0p", + "/usr/share/man/pl_PL/man1", + "/usr/share/man/pl_PL/man1p", + "/usr/share/man/pl_PL/man1x", + "/usr/share/man/pl_PL/man2", + "/usr/share/man/pl_PL/man2x", + "/usr/share/man/pl_PL/man3", + "/usr/share/man/pl_PL/man3p", + "/usr/share/man/pl_PL/man3x", + "/usr/share/man/pl_PL/man4", + "/usr/share/man/pl_PL/man4x", + "/usr/share/man/pl_PL/man5", + "/usr/share/man/pl_PL/man5x", + "/usr/share/man/pl_PL/man6", + "/usr/share/man/pl_PL/man6x", + "/usr/share/man/pl_PL/man7", + "/usr/share/man/pl_PL/man7x", + "/usr/share/man/pl_PL/man8", + "/usr/share/man/pl_PL/man8x", + "/usr/share/man/pl_PL/man9", + "/usr/share/man/pl_PL/man9x", + "/usr/share/man/pl_PL/mann", + "/usr/share/man/pms", + "/usr/share/man/pms/man0p", + "/usr/share/man/pms/man1", + "/usr/share/man/pms/man1p", + "/usr/share/man/pms/man1x", + "/usr/share/man/pms/man2", + "/usr/share/man/pms/man2x", + "/usr/share/man/pms/man3", + "/usr/share/man/pms/man3p", + "/usr/share/man/pms/man3x", + "/usr/share/man/pms/man4", + "/usr/share/man/pms/man4x", + "/usr/share/man/pms/man5", + "/usr/share/man/pms/man5x", + "/usr/share/man/pms/man6", + "/usr/share/man/pms/man6x", + "/usr/share/man/pms/man7", + "/usr/share/man/pms/man7x", + "/usr/share/man/pms/man8", + "/usr/share/man/pms/man8x", + "/usr/share/man/pms/man9", + "/usr/share/man/pms/man9x", + "/usr/share/man/pms/mann", + "/usr/share/man/pon", + "/usr/share/man/pon/man0p", + "/usr/share/man/pon/man1", + "/usr/share/man/pon/man1p", + "/usr/share/man/pon/man1x", + "/usr/share/man/pon/man2", + "/usr/share/man/pon/man2x", + "/usr/share/man/pon/man3", + "/usr/share/man/pon/man3p", + "/usr/share/man/pon/man3x", + "/usr/share/man/pon/man4", + "/usr/share/man/pon/man4x", + "/usr/share/man/pon/man5", + "/usr/share/man/pon/man5x", + "/usr/share/man/pon/man6", + "/usr/share/man/pon/man6x", + "/usr/share/man/pon/man7", + "/usr/share/man/pon/man7x", + "/usr/share/man/pon/man8", + "/usr/share/man/pon/man8x", + "/usr/share/man/pon/man9", + "/usr/share/man/pon/man9x", + "/usr/share/man/pon/mann", + "/usr/share/man/pra", + "/usr/share/man/pra/man0p", + "/usr/share/man/pra/man1", + "/usr/share/man/pra/man1p", + "/usr/share/man/pra/man1x", + "/usr/share/man/pra/man2", + "/usr/share/man/pra/man2x", + "/usr/share/man/pra/man3", + "/usr/share/man/pra/man3p", + "/usr/share/man/pra/man3x", + "/usr/share/man/pra/man4", + "/usr/share/man/pra/man4x", + "/usr/share/man/pra/man5", + "/usr/share/man/pra/man5x", + "/usr/share/man/pra/man6", + "/usr/share/man/pra/man6x", + "/usr/share/man/pra/man7", + "/usr/share/man/pra/man7x", + "/usr/share/man/pra/man8", + "/usr/share/man/pra/man8x", + "/usr/share/man/pra/man9", + "/usr/share/man/pra/man9x", + "/usr/share/man/pra/mann", + "/usr/share/man/pro", + "/usr/share/man/pro/man0p", + "/usr/share/man/pro/man1", + "/usr/share/man/pro/man1p", + "/usr/share/man/pro/man1x", + "/usr/share/man/pro/man2", + "/usr/share/man/pro/man2x", + "/usr/share/man/pro/man3", + "/usr/share/man/pro/man3p", + "/usr/share/man/pro/man3x", + "/usr/share/man/pro/man4", + "/usr/share/man/pro/man4x", + "/usr/share/man/pro/man5", + "/usr/share/man/pro/man5x", + "/usr/share/man/pro/man6", + "/usr/share/man/pro/man6x", + "/usr/share/man/pro/man7", + "/usr/share/man/pro/man7x", + "/usr/share/man/pro/man8", + "/usr/share/man/pro/man8x", + "/usr/share/man/pro/man9", + "/usr/share/man/pro/man9x", + "/usr/share/man/pro/mann", + "/usr/share/man/ps", + "/usr/share/man/ps/man0p", + "/usr/share/man/ps/man1", + "/usr/share/man/ps/man1p", + "/usr/share/man/ps/man1x", + "/usr/share/man/ps/man2", + "/usr/share/man/ps/man2x", + "/usr/share/man/ps/man3", + "/usr/share/man/ps/man3p", + "/usr/share/man/ps/man3x", + "/usr/share/man/ps/man4", + "/usr/share/man/ps/man4x", + "/usr/share/man/ps/man5", + "/usr/share/man/ps/man5x", + "/usr/share/man/ps/man6", + "/usr/share/man/ps/man6x", + "/usr/share/man/ps/man7", + "/usr/share/man/ps/man7x", + "/usr/share/man/ps/man8", + "/usr/share/man/ps/man8x", + "/usr/share/man/ps/man9", + "/usr/share/man/ps/man9x", + "/usr/share/man/ps/mann", + "/usr/share/man/pt", + "/usr/share/man/pt.us-ascii", + "/usr/share/man/pt.us-ascii/man0p", + "/usr/share/man/pt.us-ascii/man1", + "/usr/share/man/pt.us-ascii/man1p", + "/usr/share/man/pt.us-ascii/man1x", + "/usr/share/man/pt.us-ascii/man2", + "/usr/share/man/pt.us-ascii/man2x", + "/usr/share/man/pt.us-ascii/man3", + "/usr/share/man/pt.us-ascii/man3p", + "/usr/share/man/pt.us-ascii/man3x", + "/usr/share/man/pt.us-ascii/man4", + "/usr/share/man/pt.us-ascii/man4x", + "/usr/share/man/pt.us-ascii/man5", + "/usr/share/man/pt.us-ascii/man5x", + "/usr/share/man/pt.us-ascii/man6", + "/usr/share/man/pt.us-ascii/man6x", + "/usr/share/man/pt.us-ascii/man7", + "/usr/share/man/pt.us-ascii/man7x", + "/usr/share/man/pt.us-ascii/man8", + "/usr/share/man/pt.us-ascii/man8x", + "/usr/share/man/pt.us-ascii/man9", + "/usr/share/man/pt.us-ascii/man9x", + "/usr/share/man/pt.us-ascii/mann", + "/usr/share/man/pt/man0p", + "/usr/share/man/pt/man1", + "/usr/share/man/pt/man1p", + "/usr/share/man/pt/man1x", + "/usr/share/man/pt/man2", + "/usr/share/man/pt/man2x", + "/usr/share/man/pt/man3", + "/usr/share/man/pt/man3p", + "/usr/share/man/pt/man3x", + "/usr/share/man/pt/man4", + "/usr/share/man/pt/man4x", + "/usr/share/man/pt/man5", + "/usr/share/man/pt/man5x", + "/usr/share/man/pt/man6", + "/usr/share/man/pt/man6x", + "/usr/share/man/pt/man7", + "/usr/share/man/pt/man7x", + "/usr/share/man/pt/man8", + "/usr/share/man/pt/man8x", + "/usr/share/man/pt/man9", + "/usr/share/man/pt/man9x", + "/usr/share/man/pt/mann", + "/usr/share/man/pt_BR", + "/usr/share/man/pt_BR.us-ascii", + "/usr/share/man/pt_BR.us-ascii/man0p", + "/usr/share/man/pt_BR.us-ascii/man1", + "/usr/share/man/pt_BR.us-ascii/man1p", + "/usr/share/man/pt_BR.us-ascii/man1x", + "/usr/share/man/pt_BR.us-ascii/man2", + "/usr/share/man/pt_BR.us-ascii/man2x", + "/usr/share/man/pt_BR.us-ascii/man3", + "/usr/share/man/pt_BR.us-ascii/man3p", + "/usr/share/man/pt_BR.us-ascii/man3x", + "/usr/share/man/pt_BR.us-ascii/man4", + "/usr/share/man/pt_BR.us-ascii/man4x", + "/usr/share/man/pt_BR.us-ascii/man5", + "/usr/share/man/pt_BR.us-ascii/man5x", + "/usr/share/man/pt_BR.us-ascii/man6", + "/usr/share/man/pt_BR.us-ascii/man6x", + "/usr/share/man/pt_BR.us-ascii/man7", + "/usr/share/man/pt_BR.us-ascii/man7x", + "/usr/share/man/pt_BR.us-ascii/man8", + "/usr/share/man/pt_BR.us-ascii/man8x", + "/usr/share/man/pt_BR.us-ascii/man9", + "/usr/share/man/pt_BR.us-ascii/man9x", + "/usr/share/man/pt_BR.us-ascii/mann", + "/usr/share/man/pt_BR/man0p", + "/usr/share/man/pt_BR/man1", + "/usr/share/man/pt_BR/man1p", + "/usr/share/man/pt_BR/man1x", + "/usr/share/man/pt_BR/man2", + "/usr/share/man/pt_BR/man2x", + "/usr/share/man/pt_BR/man3", + "/usr/share/man/pt_BR/man3p", + "/usr/share/man/pt_BR/man3x", + "/usr/share/man/pt_BR/man4", + "/usr/share/man/pt_BR/man4x", + "/usr/share/man/pt_BR/man5", + "/usr/share/man/pt_BR/man5x", + "/usr/share/man/pt_BR/man6", + "/usr/share/man/pt_BR/man6x", + "/usr/share/man/pt_BR/man7", + "/usr/share/man/pt_BR/man7x", + "/usr/share/man/pt_BR/man8", + "/usr/share/man/pt_BR/man8x", + "/usr/share/man/pt_BR/man9", + "/usr/share/man/pt_BR/man9x", + "/usr/share/man/pt_BR/mann", + "/usr/share/man/pt_PT", + "/usr/share/man/pt_PT/man0p", + "/usr/share/man/pt_PT/man1", + "/usr/share/man/pt_PT/man1p", + "/usr/share/man/pt_PT/man1x", + "/usr/share/man/pt_PT/man2", + "/usr/share/man/pt_PT/man2x", + "/usr/share/man/pt_PT/man3", + "/usr/share/man/pt_PT/man3p", + "/usr/share/man/pt_PT/man3x", + "/usr/share/man/pt_PT/man4", + "/usr/share/man/pt_PT/man4x", + "/usr/share/man/pt_PT/man5", + "/usr/share/man/pt_PT/man5x", + "/usr/share/man/pt_PT/man6", + "/usr/share/man/pt_PT/man6x", + "/usr/share/man/pt_PT/man7", + "/usr/share/man/pt_PT/man7x", + "/usr/share/man/pt_PT/man8", + "/usr/share/man/pt_PT/man8x", + "/usr/share/man/pt_PT/man9", + "/usr/share/man/pt_PT/man9x", + "/usr/share/man/pt_PT/mann", + "/usr/share/man/qaa-qtz", + "/usr/share/man/qaa-qtz/man0p", + "/usr/share/man/qaa-qtz/man1", + "/usr/share/man/qaa-qtz/man1p", + "/usr/share/man/qaa-qtz/man1x", + "/usr/share/man/qaa-qtz/man2", + "/usr/share/man/qaa-qtz/man2x", + "/usr/share/man/qaa-qtz/man3", + "/usr/share/man/qaa-qtz/man3p", + "/usr/share/man/qaa-qtz/man3x", + "/usr/share/man/qaa-qtz/man4", + "/usr/share/man/qaa-qtz/man4x", + "/usr/share/man/qaa-qtz/man5", + "/usr/share/man/qaa-qtz/man5x", + "/usr/share/man/qaa-qtz/man6", + "/usr/share/man/qaa-qtz/man6x", + "/usr/share/man/qaa-qtz/man7", + "/usr/share/man/qaa-qtz/man7x", + "/usr/share/man/qaa-qtz/man8", + "/usr/share/man/qaa-qtz/man8x", + "/usr/share/man/qaa-qtz/man9", + "/usr/share/man/qaa-qtz/man9x", + "/usr/share/man/qaa-qtz/mann", + "/usr/share/man/qu", + "/usr/share/man/qu/man0p", + "/usr/share/man/qu/man1", + "/usr/share/man/qu/man1p", + "/usr/share/man/qu/man1x", + "/usr/share/man/qu/man2", + "/usr/share/man/qu/man2x", + "/usr/share/man/qu/man3", + "/usr/share/man/qu/man3p", + "/usr/share/man/qu/man3x", + "/usr/share/man/qu/man4", + "/usr/share/man/qu/man4x", + "/usr/share/man/qu/man5", + "/usr/share/man/qu/man5x", + "/usr/share/man/qu/man6", + "/usr/share/man/qu/man6x", + "/usr/share/man/qu/man7", + "/usr/share/man/qu/man7x", + "/usr/share/man/qu/man8", + "/usr/share/man/qu/man8x", + "/usr/share/man/qu/man9", + "/usr/share/man/qu/man9x", + "/usr/share/man/qu/mann", + "/usr/share/man/quy", + "/usr/share/man/quy/man0p", + "/usr/share/man/quy/man1", + "/usr/share/man/quy/man1p", + "/usr/share/man/quy/man1x", + "/usr/share/man/quy/man2", + "/usr/share/man/quy/man2x", + "/usr/share/man/quy/man3", + "/usr/share/man/quy/man3p", + "/usr/share/man/quy/man3x", + "/usr/share/man/quy/man4", + "/usr/share/man/quy/man4x", + "/usr/share/man/quy/man5", + "/usr/share/man/quy/man5x", + "/usr/share/man/quy/man6", + "/usr/share/man/quy/man6x", + "/usr/share/man/quy/man7", + "/usr/share/man/quy/man7x", + "/usr/share/man/quy/man8", + "/usr/share/man/quy/man8x", + "/usr/share/man/quy/man9", + "/usr/share/man/quy/man9x", + "/usr/share/man/quy/mann", + "/usr/share/man/quz", + "/usr/share/man/quz/man0p", + "/usr/share/man/quz/man1", + "/usr/share/man/quz/man1p", + "/usr/share/man/quz/man1x", + "/usr/share/man/quz/man2", + "/usr/share/man/quz/man2x", + "/usr/share/man/quz/man3", + "/usr/share/man/quz/man3p", + "/usr/share/man/quz/man3x", + "/usr/share/man/quz/man4", + "/usr/share/man/quz/man4x", + "/usr/share/man/quz/man5", + "/usr/share/man/quz/man5x", + "/usr/share/man/quz/man6", + "/usr/share/man/quz/man6x", + "/usr/share/man/quz/man7", + "/usr/share/man/quz/man7x", + "/usr/share/man/quz/man8", + "/usr/share/man/quz/man8x", + "/usr/share/man/quz/man9", + "/usr/share/man/quz/man9x", + "/usr/share/man/quz/mann", + "/usr/share/man/raj", + "/usr/share/man/raj/man0p", + "/usr/share/man/raj/man1", + "/usr/share/man/raj/man1p", + "/usr/share/man/raj/man1x", + "/usr/share/man/raj/man2", + "/usr/share/man/raj/man2x", + "/usr/share/man/raj/man3", + "/usr/share/man/raj/man3p", + "/usr/share/man/raj/man3x", + "/usr/share/man/raj/man4", + "/usr/share/man/raj/man4x", + "/usr/share/man/raj/man5", + "/usr/share/man/raj/man5x", + "/usr/share/man/raj/man6", + "/usr/share/man/raj/man6x", + "/usr/share/man/raj/man7", + "/usr/share/man/raj/man7x", + "/usr/share/man/raj/man8", + "/usr/share/man/raj/man8x", + "/usr/share/man/raj/man9", + "/usr/share/man/raj/man9x", + "/usr/share/man/raj/mann", + "/usr/share/man/rap", + "/usr/share/man/rap/man0p", + "/usr/share/man/rap/man1", + "/usr/share/man/rap/man1p", + "/usr/share/man/rap/man1x", + "/usr/share/man/rap/man2", + "/usr/share/man/rap/man2x", + "/usr/share/man/rap/man3", + "/usr/share/man/rap/man3p", + "/usr/share/man/rap/man3x", + "/usr/share/man/rap/man4", + "/usr/share/man/rap/man4x", + "/usr/share/man/rap/man5", + "/usr/share/man/rap/man5x", + "/usr/share/man/rap/man6", + "/usr/share/man/rap/man6x", + "/usr/share/man/rap/man7", + "/usr/share/man/rap/man7x", + "/usr/share/man/rap/man8", + "/usr/share/man/rap/man8x", + "/usr/share/man/rap/man9", + "/usr/share/man/rap/man9x", + "/usr/share/man/rap/mann", + "/usr/share/man/rar", + "/usr/share/man/rar/man0p", + "/usr/share/man/rar/man1", + "/usr/share/man/rar/man1p", + "/usr/share/man/rar/man1x", + "/usr/share/man/rar/man2", + "/usr/share/man/rar/man2x", + "/usr/share/man/rar/man3", + "/usr/share/man/rar/man3p", + "/usr/share/man/rar/man3x", + "/usr/share/man/rar/man4", + "/usr/share/man/rar/man4x", + "/usr/share/man/rar/man5", + "/usr/share/man/rar/man5x", + "/usr/share/man/rar/man6", + "/usr/share/man/rar/man6x", + "/usr/share/man/rar/man7", + "/usr/share/man/rar/man7x", + "/usr/share/man/rar/man8", + "/usr/share/man/rar/man8x", + "/usr/share/man/rar/man9", + "/usr/share/man/rar/man9x", + "/usr/share/man/rar/mann", + "/usr/share/man/rm", + "/usr/share/man/rm/man0p", + "/usr/share/man/rm/man1", + "/usr/share/man/rm/man1p", + "/usr/share/man/rm/man1x", + "/usr/share/man/rm/man2", + "/usr/share/man/rm/man2x", + "/usr/share/man/rm/man3", + "/usr/share/man/rm/man3p", + "/usr/share/man/rm/man3x", + "/usr/share/man/rm/man4", + "/usr/share/man/rm/man4x", + "/usr/share/man/rm/man5", + "/usr/share/man/rm/man5x", + "/usr/share/man/rm/man6", + "/usr/share/man/rm/man6x", + "/usr/share/man/rm/man7", + "/usr/share/man/rm/man7x", + "/usr/share/man/rm/man8", + "/usr/share/man/rm/man8x", + "/usr/share/man/rm/man9", + "/usr/share/man/rm/man9x", + "/usr/share/man/rm/mann", + "/usr/share/man/rn", + "/usr/share/man/rn/man0p", + "/usr/share/man/rn/man1", + "/usr/share/man/rn/man1p", + "/usr/share/man/rn/man1x", + "/usr/share/man/rn/man2", + "/usr/share/man/rn/man2x", + "/usr/share/man/rn/man3", + "/usr/share/man/rn/man3p", + "/usr/share/man/rn/man3x", + "/usr/share/man/rn/man4", + "/usr/share/man/rn/man4x", + "/usr/share/man/rn/man5", + "/usr/share/man/rn/man5x", + "/usr/share/man/rn/man6", + "/usr/share/man/rn/man6x", + "/usr/share/man/rn/man7", + "/usr/share/man/rn/man7x", + "/usr/share/man/rn/man8", + "/usr/share/man/rn/man8x", + "/usr/share/man/rn/man9", + "/usr/share/man/rn/man9x", + "/usr/share/man/rn/mann", + "/usr/share/man/ro", + "/usr/share/man/ro/man0p", + "/usr/share/man/ro/man1", + "/usr/share/man/ro/man1p", + "/usr/share/man/ro/man1x", + "/usr/share/man/ro/man2", + "/usr/share/man/ro/man2x", + "/usr/share/man/ro/man3", + "/usr/share/man/ro/man3p", + "/usr/share/man/ro/man3x", + "/usr/share/man/ro/man4", + "/usr/share/man/ro/man4x", + "/usr/share/man/ro/man5", + "/usr/share/man/ro/man5x", + "/usr/share/man/ro/man6", + "/usr/share/man/ro/man6x", + "/usr/share/man/ro/man7", + "/usr/share/man/ro/man7x", + "/usr/share/man/ro/man8", + "/usr/share/man/ro/man8x", + "/usr/share/man/ro/man9", + "/usr/share/man/ro/man9x", + "/usr/share/man/ro/mann", + "/usr/share/man/ro_RO", + "/usr/share/man/ro_RO/man0p", + "/usr/share/man/ro_RO/man1", + "/usr/share/man/ro_RO/man1p", + "/usr/share/man/ro_RO/man1x", + "/usr/share/man/ro_RO/man2", + "/usr/share/man/ro_RO/man2x", + "/usr/share/man/ro_RO/man3", + "/usr/share/man/ro_RO/man3p", + "/usr/share/man/ro_RO/man3x", + "/usr/share/man/ro_RO/man4", + "/usr/share/man/ro_RO/man4x", + "/usr/share/man/ro_RO/man5", + "/usr/share/man/ro_RO/man5x", + "/usr/share/man/ro_RO/man6", + "/usr/share/man/ro_RO/man6x", + "/usr/share/man/ro_RO/man7", + "/usr/share/man/ro_RO/man7x", + "/usr/share/man/ro_RO/man8", + "/usr/share/man/ro_RO/man8x", + "/usr/share/man/ro_RO/man9", + "/usr/share/man/ro_RO/man9x", + "/usr/share/man/ro_RO/mann", + "/usr/share/man/roa", + "/usr/share/man/roa/man0p", + "/usr/share/man/roa/man1", + "/usr/share/man/roa/man1p", + "/usr/share/man/roa/man1x", + "/usr/share/man/roa/man2", + "/usr/share/man/roa/man2x", + "/usr/share/man/roa/man3", + "/usr/share/man/roa/man3p", + "/usr/share/man/roa/man3x", + "/usr/share/man/roa/man4", + "/usr/share/man/roa/man4x", + "/usr/share/man/roa/man5", + "/usr/share/man/roa/man5x", + "/usr/share/man/roa/man6", + "/usr/share/man/roa/man6x", + "/usr/share/man/roa/man7", + "/usr/share/man/roa/man7x", + "/usr/share/man/roa/man8", + "/usr/share/man/roa/man8x", + "/usr/share/man/roa/man9", + "/usr/share/man/roa/man9x", + "/usr/share/man/roa/mann", + "/usr/share/man/rom", + "/usr/share/man/rom/man0p", + "/usr/share/man/rom/man1", + "/usr/share/man/rom/man1p", + "/usr/share/man/rom/man1x", + "/usr/share/man/rom/man2", + "/usr/share/man/rom/man2x", + "/usr/share/man/rom/man3", + "/usr/share/man/rom/man3p", + "/usr/share/man/rom/man3x", + "/usr/share/man/rom/man4", + "/usr/share/man/rom/man4x", + "/usr/share/man/rom/man5", + "/usr/share/man/rom/man5x", + "/usr/share/man/rom/man6", + "/usr/share/man/rom/man6x", + "/usr/share/man/rom/man7", + "/usr/share/man/rom/man7x", + "/usr/share/man/rom/man8", + "/usr/share/man/rom/man8x", + "/usr/share/man/rom/man9", + "/usr/share/man/rom/man9x", + "/usr/share/man/rom/mann", + "/usr/share/man/ru", + "/usr/share/man/ru/man0p", + "/usr/share/man/ru/man1", + "/usr/share/man/ru/man1p", + "/usr/share/man/ru/man1x", + "/usr/share/man/ru/man2", + "/usr/share/man/ru/man2x", + "/usr/share/man/ru/man3", + "/usr/share/man/ru/man3p", + "/usr/share/man/ru/man3x", + "/usr/share/man/ru/man4", + "/usr/share/man/ru/man4x", + "/usr/share/man/ru/man5", + "/usr/share/man/ru/man5x", + "/usr/share/man/ru/man6", + "/usr/share/man/ru/man6x", + "/usr/share/man/ru/man7", + "/usr/share/man/ru/man7x", + "/usr/share/man/ru/man8", + "/usr/share/man/ru/man8x", + "/usr/share/man/ru/man9", + "/usr/share/man/ru/man9x", + "/usr/share/man/ru/mann", + "/usr/share/man/ru_RU", + "/usr/share/man/ru_RU.KOI8-R", + "/usr/share/man/ru_RU.KOI8-R/man0p", + "/usr/share/man/ru_RU.KOI8-R/man1", + "/usr/share/man/ru_RU.KOI8-R/man1p", + "/usr/share/man/ru_RU.KOI8-R/man1x", + "/usr/share/man/ru_RU.KOI8-R/man2", + "/usr/share/man/ru_RU.KOI8-R/man2x", + "/usr/share/man/ru_RU.KOI8-R/man3", + "/usr/share/man/ru_RU.KOI8-R/man3p", + "/usr/share/man/ru_RU.KOI8-R/man3x", + "/usr/share/man/ru_RU.KOI8-R/man4", + "/usr/share/man/ru_RU.KOI8-R/man4x", + "/usr/share/man/ru_RU.KOI8-R/man5", + "/usr/share/man/ru_RU.KOI8-R/man5x", + "/usr/share/man/ru_RU.KOI8-R/man6", + "/usr/share/man/ru_RU.KOI8-R/man6x", + "/usr/share/man/ru_RU.KOI8-R/man7", + "/usr/share/man/ru_RU.KOI8-R/man7x", + "/usr/share/man/ru_RU.KOI8-R/man8", + "/usr/share/man/ru_RU.KOI8-R/man8x", + "/usr/share/man/ru_RU.KOI8-R/man9", + "/usr/share/man/ru_RU.KOI8-R/man9x", + "/usr/share/man/ru_RU.KOI8-R/mann", + "/usr/share/man/ru_RU/man0p", + "/usr/share/man/ru_RU/man1", + "/usr/share/man/ru_RU/man1p", + "/usr/share/man/ru_RU/man1x", + "/usr/share/man/ru_RU/man2", + "/usr/share/man/ru_RU/man2x", + "/usr/share/man/ru_RU/man3", + "/usr/share/man/ru_RU/man3p", + "/usr/share/man/ru_RU/man3x", + "/usr/share/man/ru_RU/man4", + "/usr/share/man/ru_RU/man4x", + "/usr/share/man/ru_RU/man5", + "/usr/share/man/ru_RU/man5x", + "/usr/share/man/ru_RU/man6", + "/usr/share/man/ru_RU/man6x", + "/usr/share/man/ru_RU/man7", + "/usr/share/man/ru_RU/man7x", + "/usr/share/man/ru_RU/man8", + "/usr/share/man/ru_RU/man8x", + "/usr/share/man/ru_RU/man9", + "/usr/share/man/ru_RU/man9x", + "/usr/share/man/ru_RU/mann", + "/usr/share/man/rue", + "/usr/share/man/rue/man0p", + "/usr/share/man/rue/man1", + "/usr/share/man/rue/man1p", + "/usr/share/man/rue/man1x", + "/usr/share/man/rue/man2", + "/usr/share/man/rue/man2x", + "/usr/share/man/rue/man3", + "/usr/share/man/rue/man3p", + "/usr/share/man/rue/man3x", + "/usr/share/man/rue/man4", + "/usr/share/man/rue/man4x", + "/usr/share/man/rue/man5", + "/usr/share/man/rue/man5x", + "/usr/share/man/rue/man6", + "/usr/share/man/rue/man6x", + "/usr/share/man/rue/man7", + "/usr/share/man/rue/man7x", + "/usr/share/man/rue/man8", + "/usr/share/man/rue/man8x", + "/usr/share/man/rue/man9", + "/usr/share/man/rue/man9x", + "/usr/share/man/rue/mann", + "/usr/share/man/rup", + "/usr/share/man/rup/man0p", + "/usr/share/man/rup/man1", + "/usr/share/man/rup/man1p", + "/usr/share/man/rup/man1x", + "/usr/share/man/rup/man2", + "/usr/share/man/rup/man2x", + "/usr/share/man/rup/man3", + "/usr/share/man/rup/man3p", + "/usr/share/man/rup/man3x", + "/usr/share/man/rup/man4", + "/usr/share/man/rup/man4x", + "/usr/share/man/rup/man5", + "/usr/share/man/rup/man5x", + "/usr/share/man/rup/man6", + "/usr/share/man/rup/man6x", + "/usr/share/man/rup/man7", + "/usr/share/man/rup/man7x", + "/usr/share/man/rup/man8", + "/usr/share/man/rup/man8x", + "/usr/share/man/rup/man9", + "/usr/share/man/rup/man9x", + "/usr/share/man/rup/mann", + "/usr/share/man/rw", + "/usr/share/man/rw/man0p", + "/usr/share/man/rw/man1", + "/usr/share/man/rw/man1p", + "/usr/share/man/rw/man1x", + "/usr/share/man/rw/man2", + "/usr/share/man/rw/man2x", + "/usr/share/man/rw/man3", + "/usr/share/man/rw/man3p", + "/usr/share/man/rw/man3x", + "/usr/share/man/rw/man4", + "/usr/share/man/rw/man4x", + "/usr/share/man/rw/man5", + "/usr/share/man/rw/man5x", + "/usr/share/man/rw/man6", + "/usr/share/man/rw/man6x", + "/usr/share/man/rw/man7", + "/usr/share/man/rw/man7x", + "/usr/share/man/rw/man8", + "/usr/share/man/rw/man8x", + "/usr/share/man/rw/man9", + "/usr/share/man/rw/man9x", + "/usr/share/man/rw/mann", + "/usr/share/man/sa", + "/usr/share/man/sa/man0p", + "/usr/share/man/sa/man1", + "/usr/share/man/sa/man1p", + "/usr/share/man/sa/man1x", + "/usr/share/man/sa/man2", + "/usr/share/man/sa/man2x", + "/usr/share/man/sa/man3", + "/usr/share/man/sa/man3p", + "/usr/share/man/sa/man3x", + "/usr/share/man/sa/man4", + "/usr/share/man/sa/man4x", + "/usr/share/man/sa/man5", + "/usr/share/man/sa/man5x", + "/usr/share/man/sa/man6", + "/usr/share/man/sa/man6x", + "/usr/share/man/sa/man7", + "/usr/share/man/sa/man7x", + "/usr/share/man/sa/man8", + "/usr/share/man/sa/man8x", + "/usr/share/man/sa/man9", + "/usr/share/man/sa/man9x", + "/usr/share/man/sa/mann", + "/usr/share/man/sad", + "/usr/share/man/sad/man0p", + "/usr/share/man/sad/man1", + "/usr/share/man/sad/man1p", + "/usr/share/man/sad/man1x", + "/usr/share/man/sad/man2", + "/usr/share/man/sad/man2x", + "/usr/share/man/sad/man3", + "/usr/share/man/sad/man3p", + "/usr/share/man/sad/man3x", + "/usr/share/man/sad/man4", + "/usr/share/man/sad/man4x", + "/usr/share/man/sad/man5", + "/usr/share/man/sad/man5x", + "/usr/share/man/sad/man6", + "/usr/share/man/sad/man6x", + "/usr/share/man/sad/man7", + "/usr/share/man/sad/man7x", + "/usr/share/man/sad/man8", + "/usr/share/man/sad/man8x", + "/usr/share/man/sad/man9", + "/usr/share/man/sad/man9x", + "/usr/share/man/sad/mann", + "/usr/share/man/sah", + "/usr/share/man/sah/man0p", + "/usr/share/man/sah/man1", + "/usr/share/man/sah/man1p", + "/usr/share/man/sah/man1x", + "/usr/share/man/sah/man2", + "/usr/share/man/sah/man2x", + "/usr/share/man/sah/man3", + "/usr/share/man/sah/man3p", + "/usr/share/man/sah/man3x", + "/usr/share/man/sah/man4", + "/usr/share/man/sah/man4x", + "/usr/share/man/sah/man5", + "/usr/share/man/sah/man5x", + "/usr/share/man/sah/man6", + "/usr/share/man/sah/man6x", + "/usr/share/man/sah/man7", + "/usr/share/man/sah/man7x", + "/usr/share/man/sah/man8", + "/usr/share/man/sah/man8x", + "/usr/share/man/sah/man9", + "/usr/share/man/sah/man9x", + "/usr/share/man/sah/mann", + "/usr/share/man/sai", + "/usr/share/man/sai/man0p", + "/usr/share/man/sai/man1", + "/usr/share/man/sai/man1p", + "/usr/share/man/sai/man1x", + "/usr/share/man/sai/man2", + "/usr/share/man/sai/man2x", + "/usr/share/man/sai/man3", + "/usr/share/man/sai/man3p", + "/usr/share/man/sai/man3x", + "/usr/share/man/sai/man4", + "/usr/share/man/sai/man4x", + "/usr/share/man/sai/man5", + "/usr/share/man/sai/man5x", + "/usr/share/man/sai/man6", + "/usr/share/man/sai/man6x", + "/usr/share/man/sai/man7", + "/usr/share/man/sai/man7x", + "/usr/share/man/sai/man8", + "/usr/share/man/sai/man8x", + "/usr/share/man/sai/man9", + "/usr/share/man/sai/man9x", + "/usr/share/man/sai/mann", + "/usr/share/man/sal", + "/usr/share/man/sal/man0p", + "/usr/share/man/sal/man1", + "/usr/share/man/sal/man1p", + "/usr/share/man/sal/man1x", + "/usr/share/man/sal/man2", + "/usr/share/man/sal/man2x", + "/usr/share/man/sal/man3", + "/usr/share/man/sal/man3p", + "/usr/share/man/sal/man3x", + "/usr/share/man/sal/man4", + "/usr/share/man/sal/man4x", + "/usr/share/man/sal/man5", + "/usr/share/man/sal/man5x", + "/usr/share/man/sal/man6", + "/usr/share/man/sal/man6x", + "/usr/share/man/sal/man7", + "/usr/share/man/sal/man7x", + "/usr/share/man/sal/man8", + "/usr/share/man/sal/man8x", + "/usr/share/man/sal/man9", + "/usr/share/man/sal/man9x", + "/usr/share/man/sal/mann", + "/usr/share/man/sam", + "/usr/share/man/sam/man0p", + "/usr/share/man/sam/man1", + "/usr/share/man/sam/man1p", + "/usr/share/man/sam/man1x", + "/usr/share/man/sam/man2", + "/usr/share/man/sam/man2x", + "/usr/share/man/sam/man3", + "/usr/share/man/sam/man3p", + "/usr/share/man/sam/man3x", + "/usr/share/man/sam/man4", + "/usr/share/man/sam/man4x", + "/usr/share/man/sam/man5", + "/usr/share/man/sam/man5x", + "/usr/share/man/sam/man6", + "/usr/share/man/sam/man6x", + "/usr/share/man/sam/man7", + "/usr/share/man/sam/man7x", + "/usr/share/man/sam/man8", + "/usr/share/man/sam/man8x", + "/usr/share/man/sam/man9", + "/usr/share/man/sam/man9x", + "/usr/share/man/sam/mann", + "/usr/share/man/sas", + "/usr/share/man/sas/man0p", + "/usr/share/man/sas/man1", + "/usr/share/man/sas/man1p", + "/usr/share/man/sas/man1x", + "/usr/share/man/sas/man2", + "/usr/share/man/sas/man2x", + "/usr/share/man/sas/man3", + "/usr/share/man/sas/man3p", + "/usr/share/man/sas/man3x", + "/usr/share/man/sas/man4", + "/usr/share/man/sas/man4x", + "/usr/share/man/sas/man5", + "/usr/share/man/sas/man5x", + "/usr/share/man/sas/man6", + "/usr/share/man/sas/man6x", + "/usr/share/man/sas/man7", + "/usr/share/man/sas/man7x", + "/usr/share/man/sas/man8", + "/usr/share/man/sas/man8x", + "/usr/share/man/sas/man9", + "/usr/share/man/sas/man9x", + "/usr/share/man/sas/mann", + "/usr/share/man/sat", + "/usr/share/man/sat/man0p", + "/usr/share/man/sat/man1", + "/usr/share/man/sat/man1p", + "/usr/share/man/sat/man1x", + "/usr/share/man/sat/man2", + "/usr/share/man/sat/man2x", + "/usr/share/man/sat/man3", + "/usr/share/man/sat/man3p", + "/usr/share/man/sat/man3x", + "/usr/share/man/sat/man4", + "/usr/share/man/sat/man4x", + "/usr/share/man/sat/man5", + "/usr/share/man/sat/man5x", + "/usr/share/man/sat/man6", + "/usr/share/man/sat/man6x", + "/usr/share/man/sat/man7", + "/usr/share/man/sat/man7x", + "/usr/share/man/sat/man8", + "/usr/share/man/sat/man8x", + "/usr/share/man/sat/man9", + "/usr/share/man/sat/man9x", + "/usr/share/man/sat/mann", + "/usr/share/man/sat@deva", + "/usr/share/man/sat@deva/man0p", + "/usr/share/man/sat@deva/man1", + "/usr/share/man/sat@deva/man1p", + "/usr/share/man/sat@deva/man1x", + "/usr/share/man/sat@deva/man2", + "/usr/share/man/sat@deva/man2x", + "/usr/share/man/sat@deva/man3", + "/usr/share/man/sat@deva/man3p", + "/usr/share/man/sat@deva/man3x", + "/usr/share/man/sat@deva/man4", + "/usr/share/man/sat@deva/man4x", + "/usr/share/man/sat@deva/man5", + "/usr/share/man/sat@deva/man5x", + "/usr/share/man/sat@deva/man6", + "/usr/share/man/sat@deva/man6x", + "/usr/share/man/sat@deva/man7", + "/usr/share/man/sat@deva/man7x", + "/usr/share/man/sat@deva/man8", + "/usr/share/man/sat@deva/man8x", + "/usr/share/man/sat@deva/man9", + "/usr/share/man/sat@deva/man9x", + "/usr/share/man/sat@deva/mann", + "/usr/share/man/sat@olchiki", + "/usr/share/man/sat@olchiki/man0p", + "/usr/share/man/sat@olchiki/man1", + "/usr/share/man/sat@olchiki/man1p", + "/usr/share/man/sat@olchiki/man1x", + "/usr/share/man/sat@olchiki/man2", + "/usr/share/man/sat@olchiki/man2x", + "/usr/share/man/sat@olchiki/man3", + "/usr/share/man/sat@olchiki/man3p", + "/usr/share/man/sat@olchiki/man3x", + "/usr/share/man/sat@olchiki/man4", + "/usr/share/man/sat@olchiki/man4x", + "/usr/share/man/sat@olchiki/man5", + "/usr/share/man/sat@olchiki/man5x", + "/usr/share/man/sat@olchiki/man6", + "/usr/share/man/sat@olchiki/man6x", + "/usr/share/man/sat@olchiki/man7", + "/usr/share/man/sat@olchiki/man7x", + "/usr/share/man/sat@olchiki/man8", + "/usr/share/man/sat@olchiki/man8x", + "/usr/share/man/sat@olchiki/man9", + "/usr/share/man/sat@olchiki/man9x", + "/usr/share/man/sat@olchiki/mann", + "/usr/share/man/sc", + "/usr/share/man/sc/man0p", + "/usr/share/man/sc/man1", + "/usr/share/man/sc/man1p", + "/usr/share/man/sc/man1x", + "/usr/share/man/sc/man2", + "/usr/share/man/sc/man2x", + "/usr/share/man/sc/man3", + "/usr/share/man/sc/man3p", + "/usr/share/man/sc/man3x", + "/usr/share/man/sc/man4", + "/usr/share/man/sc/man4x", + "/usr/share/man/sc/man5", + "/usr/share/man/sc/man5x", + "/usr/share/man/sc/man6", + "/usr/share/man/sc/man6x", + "/usr/share/man/sc/man7", + "/usr/share/man/sc/man7x", + "/usr/share/man/sc/man8", + "/usr/share/man/sc/man8x", + "/usr/share/man/sc/man9", + "/usr/share/man/sc/man9x", + "/usr/share/man/sc/mann", + "/usr/share/man/scn", + "/usr/share/man/scn/man0p", + "/usr/share/man/scn/man1", + "/usr/share/man/scn/man1p", + "/usr/share/man/scn/man1x", + "/usr/share/man/scn/man2", + "/usr/share/man/scn/man2x", + "/usr/share/man/scn/man3", + "/usr/share/man/scn/man3p", + "/usr/share/man/scn/man3x", + "/usr/share/man/scn/man4", + "/usr/share/man/scn/man4x", + "/usr/share/man/scn/man5", + "/usr/share/man/scn/man5x", + "/usr/share/man/scn/man6", + "/usr/share/man/scn/man6x", + "/usr/share/man/scn/man7", + "/usr/share/man/scn/man7x", + "/usr/share/man/scn/man8", + "/usr/share/man/scn/man8x", + "/usr/share/man/scn/man9", + "/usr/share/man/scn/man9x", + "/usr/share/man/scn/mann", + "/usr/share/man/sco", + "/usr/share/man/sco/man0p", + "/usr/share/man/sco/man1", + "/usr/share/man/sco/man1p", + "/usr/share/man/sco/man1x", + "/usr/share/man/sco/man2", + "/usr/share/man/sco/man2x", + "/usr/share/man/sco/man3", + "/usr/share/man/sco/man3p", + "/usr/share/man/sco/man3x", + "/usr/share/man/sco/man4", + "/usr/share/man/sco/man4x", + "/usr/share/man/sco/man5", + "/usr/share/man/sco/man5x", + "/usr/share/man/sco/man6", + "/usr/share/man/sco/man6x", + "/usr/share/man/sco/man7", + "/usr/share/man/sco/man7x", + "/usr/share/man/sco/man8", + "/usr/share/man/sco/man8x", + "/usr/share/man/sco/man9", + "/usr/share/man/sco/man9x", + "/usr/share/man/sco/mann", + "/usr/share/man/sd", + "/usr/share/man/sd/man0p", + "/usr/share/man/sd/man1", + "/usr/share/man/sd/man1p", + "/usr/share/man/sd/man1x", + "/usr/share/man/sd/man2", + "/usr/share/man/sd/man2x", + "/usr/share/man/sd/man3", + "/usr/share/man/sd/man3p", + "/usr/share/man/sd/man3x", + "/usr/share/man/sd/man4", + "/usr/share/man/sd/man4x", + "/usr/share/man/sd/man5", + "/usr/share/man/sd/man5x", + "/usr/share/man/sd/man6", + "/usr/share/man/sd/man6x", + "/usr/share/man/sd/man7", + "/usr/share/man/sd/man7x", + "/usr/share/man/sd/man8", + "/usr/share/man/sd/man8x", + "/usr/share/man/sd/man9", + "/usr/share/man/sd/man9x", + "/usr/share/man/sd/mann", + "/usr/share/man/sd@deva", + "/usr/share/man/sd@deva/man0p", + "/usr/share/man/sd@deva/man1", + "/usr/share/man/sd@deva/man1p", + "/usr/share/man/sd@deva/man1x", + "/usr/share/man/sd@deva/man2", + "/usr/share/man/sd@deva/man2x", + "/usr/share/man/sd@deva/man3", + "/usr/share/man/sd@deva/man3p", + "/usr/share/man/sd@deva/man3x", + "/usr/share/man/sd@deva/man4", + "/usr/share/man/sd@deva/man4x", + "/usr/share/man/sd@deva/man5", + "/usr/share/man/sd@deva/man5x", + "/usr/share/man/sd@deva/man6", + "/usr/share/man/sd@deva/man6x", + "/usr/share/man/sd@deva/man7", + "/usr/share/man/sd@deva/man7x", + "/usr/share/man/sd@deva/man8", + "/usr/share/man/sd@deva/man8x", + "/usr/share/man/sd@deva/man9", + "/usr/share/man/sd@deva/man9x", + "/usr/share/man/sd@deva/mann", + "/usr/share/man/se", + "/usr/share/man/se/man0p", + "/usr/share/man/se/man1", + "/usr/share/man/se/man1p", + "/usr/share/man/se/man1x", + "/usr/share/man/se/man2", + "/usr/share/man/se/man2x", + "/usr/share/man/se/man3", + "/usr/share/man/se/man3p", + "/usr/share/man/se/man3x", + "/usr/share/man/se/man4", + "/usr/share/man/se/man4x", + "/usr/share/man/se/man5", + "/usr/share/man/se/man5x", + "/usr/share/man/se/man6", + "/usr/share/man/se/man6x", + "/usr/share/man/se/man7", + "/usr/share/man/se/man7x", + "/usr/share/man/se/man8", + "/usr/share/man/se/man8x", + "/usr/share/man/se/man9", + "/usr/share/man/se/man9x", + "/usr/share/man/se/mann", + "/usr/share/man/sel", + "/usr/share/man/sel/man0p", + "/usr/share/man/sel/man1", + "/usr/share/man/sel/man1p", + "/usr/share/man/sel/man1x", + "/usr/share/man/sel/man2", + "/usr/share/man/sel/man2x", + "/usr/share/man/sel/man3", + "/usr/share/man/sel/man3p", + "/usr/share/man/sel/man3x", + "/usr/share/man/sel/man4", + "/usr/share/man/sel/man4x", + "/usr/share/man/sel/man5", + "/usr/share/man/sel/man5x", + "/usr/share/man/sel/man6", + "/usr/share/man/sel/man6x", + "/usr/share/man/sel/man7", + "/usr/share/man/sel/man7x", + "/usr/share/man/sel/man8", + "/usr/share/man/sel/man8x", + "/usr/share/man/sel/man9", + "/usr/share/man/sel/man9x", + "/usr/share/man/sel/mann", + "/usr/share/man/sem", + "/usr/share/man/sem/man0p", + "/usr/share/man/sem/man1", + "/usr/share/man/sem/man1p", + "/usr/share/man/sem/man1x", + "/usr/share/man/sem/man2", + "/usr/share/man/sem/man2x", + "/usr/share/man/sem/man3", + "/usr/share/man/sem/man3p", + "/usr/share/man/sem/man3x", + "/usr/share/man/sem/man4", + "/usr/share/man/sem/man4x", + "/usr/share/man/sem/man5", + "/usr/share/man/sem/man5x", + "/usr/share/man/sem/man6", + "/usr/share/man/sem/man6x", + "/usr/share/man/sem/man7", + "/usr/share/man/sem/man7x", + "/usr/share/man/sem/man8", + "/usr/share/man/sem/man8x", + "/usr/share/man/sem/man9", + "/usr/share/man/sem/man9x", + "/usr/share/man/sem/mann", + "/usr/share/man/sg", + "/usr/share/man/sg/man0p", + "/usr/share/man/sg/man1", + "/usr/share/man/sg/man1p", + "/usr/share/man/sg/man1x", + "/usr/share/man/sg/man2", + "/usr/share/man/sg/man2x", + "/usr/share/man/sg/man3", + "/usr/share/man/sg/man3p", + "/usr/share/man/sg/man3x", + "/usr/share/man/sg/man4", + "/usr/share/man/sg/man4x", + "/usr/share/man/sg/man5", + "/usr/share/man/sg/man5x", + "/usr/share/man/sg/man6", + "/usr/share/man/sg/man6x", + "/usr/share/man/sg/man7", + "/usr/share/man/sg/man7x", + "/usr/share/man/sg/man8", + "/usr/share/man/sg/man8x", + "/usr/share/man/sg/man9", + "/usr/share/man/sg/man9x", + "/usr/share/man/sg/mann", + "/usr/share/man/sga", + "/usr/share/man/sga/man0p", + "/usr/share/man/sga/man1", + "/usr/share/man/sga/man1p", + "/usr/share/man/sga/man1x", + "/usr/share/man/sga/man2", + "/usr/share/man/sga/man2x", + "/usr/share/man/sga/man3", + "/usr/share/man/sga/man3p", + "/usr/share/man/sga/man3x", + "/usr/share/man/sga/man4", + "/usr/share/man/sga/man4x", + "/usr/share/man/sga/man5", + "/usr/share/man/sga/man5x", + "/usr/share/man/sga/man6", + "/usr/share/man/sga/man6x", + "/usr/share/man/sga/man7", + "/usr/share/man/sga/man7x", + "/usr/share/man/sga/man8", + "/usr/share/man/sga/man8x", + "/usr/share/man/sga/man9", + "/usr/share/man/sga/man9x", + "/usr/share/man/sga/mann", + "/usr/share/man/sgn", + "/usr/share/man/sgn/man0p", + "/usr/share/man/sgn/man1", + "/usr/share/man/sgn/man1p", + "/usr/share/man/sgn/man1x", + "/usr/share/man/sgn/man2", + "/usr/share/man/sgn/man2x", + "/usr/share/man/sgn/man3", + "/usr/share/man/sgn/man3p", + "/usr/share/man/sgn/man3x", + "/usr/share/man/sgn/man4", + "/usr/share/man/sgn/man4x", + "/usr/share/man/sgn/man5", + "/usr/share/man/sgn/man5x", + "/usr/share/man/sgn/man6", + "/usr/share/man/sgn/man6x", + "/usr/share/man/sgn/man7", + "/usr/share/man/sgn/man7x", + "/usr/share/man/sgn/man8", + "/usr/share/man/sgn/man8x", + "/usr/share/man/sgn/man9", + "/usr/share/man/sgn/man9x", + "/usr/share/man/sgn/mann", + "/usr/share/man/shn", + "/usr/share/man/shn/man0p", + "/usr/share/man/shn/man1", + "/usr/share/man/shn/man1p", + "/usr/share/man/shn/man1x", + "/usr/share/man/shn/man2", + "/usr/share/man/shn/man2x", + "/usr/share/man/shn/man3", + "/usr/share/man/shn/man3p", + "/usr/share/man/shn/man3x", + "/usr/share/man/shn/man4", + "/usr/share/man/shn/man4x", + "/usr/share/man/shn/man5", + "/usr/share/man/shn/man5x", + "/usr/share/man/shn/man6", + "/usr/share/man/shn/man6x", + "/usr/share/man/shn/man7", + "/usr/share/man/shn/man7x", + "/usr/share/man/shn/man8", + "/usr/share/man/shn/man8x", + "/usr/share/man/shn/man9", + "/usr/share/man/shn/man9x", + "/usr/share/man/shn/mann", + "/usr/share/man/shs", + "/usr/share/man/shs/man0p", + "/usr/share/man/shs/man1", + "/usr/share/man/shs/man1p", + "/usr/share/man/shs/man1x", + "/usr/share/man/shs/man2", + "/usr/share/man/shs/man2x", + "/usr/share/man/shs/man3", + "/usr/share/man/shs/man3p", + "/usr/share/man/shs/man3x", + "/usr/share/man/shs/man4", + "/usr/share/man/shs/man4x", + "/usr/share/man/shs/man5", + "/usr/share/man/shs/man5x", + "/usr/share/man/shs/man6", + "/usr/share/man/shs/man6x", + "/usr/share/man/shs/man7", + "/usr/share/man/shs/man7x", + "/usr/share/man/shs/man8", + "/usr/share/man/shs/man8x", + "/usr/share/man/shs/man9", + "/usr/share/man/shs/man9x", + "/usr/share/man/shs/mann", + "/usr/share/man/si", + "/usr/share/man/si/man0p", + "/usr/share/man/si/man1", + "/usr/share/man/si/man1p", + "/usr/share/man/si/man1x", + "/usr/share/man/si/man2", + "/usr/share/man/si/man2x", + "/usr/share/man/si/man3", + "/usr/share/man/si/man3p", + "/usr/share/man/si/man3x", + "/usr/share/man/si/man4", + "/usr/share/man/si/man4x", + "/usr/share/man/si/man5", + "/usr/share/man/si/man5x", + "/usr/share/man/si/man6", + "/usr/share/man/si/man6x", + "/usr/share/man/si/man7", + "/usr/share/man/si/man7x", + "/usr/share/man/si/man8", + "/usr/share/man/si/man8x", + "/usr/share/man/si/man9", + "/usr/share/man/si/man9x", + "/usr/share/man/si/mann", + "/usr/share/man/si_LK", + "/usr/share/man/si_LK/man0p", + "/usr/share/man/si_LK/man1", + "/usr/share/man/si_LK/man1p", + "/usr/share/man/si_LK/man1x", + "/usr/share/man/si_LK/man2", + "/usr/share/man/si_LK/man2x", + "/usr/share/man/si_LK/man3", + "/usr/share/man/si_LK/man3p", + "/usr/share/man/si_LK/man3x", + "/usr/share/man/si_LK/man4", + "/usr/share/man/si_LK/man4x", + "/usr/share/man/si_LK/man5", + "/usr/share/man/si_LK/man5x", + "/usr/share/man/si_LK/man6", + "/usr/share/man/si_LK/man6x", + "/usr/share/man/si_LK/man7", + "/usr/share/man/si_LK/man7x", + "/usr/share/man/si_LK/man8", + "/usr/share/man/si_LK/man8x", + "/usr/share/man/si_LK/man9", + "/usr/share/man/si_LK/man9x", + "/usr/share/man/si_LK/mann", + "/usr/share/man/sid", + "/usr/share/man/sid/man0p", + "/usr/share/man/sid/man1", + "/usr/share/man/sid/man1p", + "/usr/share/man/sid/man1x", + "/usr/share/man/sid/man2", + "/usr/share/man/sid/man2x", + "/usr/share/man/sid/man3", + "/usr/share/man/sid/man3p", + "/usr/share/man/sid/man3x", + "/usr/share/man/sid/man4", + "/usr/share/man/sid/man4x", + "/usr/share/man/sid/man5", + "/usr/share/man/sid/man5x", + "/usr/share/man/sid/man6", + "/usr/share/man/sid/man6x", + "/usr/share/man/sid/man7", + "/usr/share/man/sid/man7x", + "/usr/share/man/sid/man8", + "/usr/share/man/sid/man8x", + "/usr/share/man/sid/man9", + "/usr/share/man/sid/man9x", + "/usr/share/man/sid/mann", + "/usr/share/man/sio", + "/usr/share/man/sio/man0p", + "/usr/share/man/sio/man1", + "/usr/share/man/sio/man1p", + "/usr/share/man/sio/man1x", + "/usr/share/man/sio/man2", + "/usr/share/man/sio/man2x", + "/usr/share/man/sio/man3", + "/usr/share/man/sio/man3p", + "/usr/share/man/sio/man3x", + "/usr/share/man/sio/man4", + "/usr/share/man/sio/man4x", + "/usr/share/man/sio/man5", + "/usr/share/man/sio/man5x", + "/usr/share/man/sio/man6", + "/usr/share/man/sio/man6x", + "/usr/share/man/sio/man7", + "/usr/share/man/sio/man7x", + "/usr/share/man/sio/man8", + "/usr/share/man/sio/man8x", + "/usr/share/man/sio/man9", + "/usr/share/man/sio/man9x", + "/usr/share/man/sio/mann", + "/usr/share/man/sit", + "/usr/share/man/sit/man0p", + "/usr/share/man/sit/man1", + "/usr/share/man/sit/man1p", + "/usr/share/man/sit/man1x", + "/usr/share/man/sit/man2", + "/usr/share/man/sit/man2x", + "/usr/share/man/sit/man3", + "/usr/share/man/sit/man3p", + "/usr/share/man/sit/man3x", + "/usr/share/man/sit/man4", + "/usr/share/man/sit/man4x", + "/usr/share/man/sit/man5", + "/usr/share/man/sit/man5x", + "/usr/share/man/sit/man6", + "/usr/share/man/sit/man6x", + "/usr/share/man/sit/man7", + "/usr/share/man/sit/man7x", + "/usr/share/man/sit/man8", + "/usr/share/man/sit/man8x", + "/usr/share/man/sit/man9", + "/usr/share/man/sit/man9x", + "/usr/share/man/sit/mann", + "/usr/share/man/sk", + "/usr/share/man/sk.cp1250", + "/usr/share/man/sk.cp1250/man0p", + "/usr/share/man/sk.cp1250/man1", + "/usr/share/man/sk.cp1250/man1p", + "/usr/share/man/sk.cp1250/man1x", + "/usr/share/man/sk.cp1250/man2", + "/usr/share/man/sk.cp1250/man2x", + "/usr/share/man/sk.cp1250/man3", + "/usr/share/man/sk.cp1250/man3p", + "/usr/share/man/sk.cp1250/man3x", + "/usr/share/man/sk.cp1250/man4", + "/usr/share/man/sk.cp1250/man4x", + "/usr/share/man/sk.cp1250/man5", + "/usr/share/man/sk.cp1250/man5x", + "/usr/share/man/sk.cp1250/man6", + "/usr/share/man/sk.cp1250/man6x", + "/usr/share/man/sk.cp1250/man7", + "/usr/share/man/sk.cp1250/man7x", + "/usr/share/man/sk.cp1250/man8", + "/usr/share/man/sk.cp1250/man8x", + "/usr/share/man/sk.cp1250/man9", + "/usr/share/man/sk.cp1250/man9x", + "/usr/share/man/sk.cp1250/mann", + "/usr/share/man/sk/man0p", + "/usr/share/man/sk/man1", + "/usr/share/man/sk/man1p", + "/usr/share/man/sk/man1x", + "/usr/share/man/sk/man2", + "/usr/share/man/sk/man2x", + "/usr/share/man/sk/man3", + "/usr/share/man/sk/man3p", + "/usr/share/man/sk/man3x", + "/usr/share/man/sk/man4", + "/usr/share/man/sk/man4x", + "/usr/share/man/sk/man5", + "/usr/share/man/sk/man5x", + "/usr/share/man/sk/man6", + "/usr/share/man/sk/man6x", + "/usr/share/man/sk/man7", + "/usr/share/man/sk/man7x", + "/usr/share/man/sk/man8", + "/usr/share/man/sk/man8x", + "/usr/share/man/sk/man9", + "/usr/share/man/sk/man9x", + "/usr/share/man/sk/mann", + "/usr/share/man/sk_SK", + "/usr/share/man/sk_SK/man0p", + "/usr/share/man/sk_SK/man1", + "/usr/share/man/sk_SK/man1p", + "/usr/share/man/sk_SK/man1x", + "/usr/share/man/sk_SK/man2", + "/usr/share/man/sk_SK/man2x", + "/usr/share/man/sk_SK/man3", + "/usr/share/man/sk_SK/man3p", + "/usr/share/man/sk_SK/man3x", + "/usr/share/man/sk_SK/man4", + "/usr/share/man/sk_SK/man4x", + "/usr/share/man/sk_SK/man5", + "/usr/share/man/sk_SK/man5x", + "/usr/share/man/sk_SK/man6", + "/usr/share/man/sk_SK/man6x", + "/usr/share/man/sk_SK/man7", + "/usr/share/man/sk_SK/man7x", + "/usr/share/man/sk_SK/man8", + "/usr/share/man/sk_SK/man8x", + "/usr/share/man/sk_SK/man9", + "/usr/share/man/sk_SK/man9x", + "/usr/share/man/sk_SK/mann", + "/usr/share/man/sl", + "/usr/share/man/sl/man0p", + "/usr/share/man/sl/man1", + "/usr/share/man/sl/man1p", + "/usr/share/man/sl/man1x", + "/usr/share/man/sl/man2", + "/usr/share/man/sl/man2x", + "/usr/share/man/sl/man3", + "/usr/share/man/sl/man3p", + "/usr/share/man/sl/man3x", + "/usr/share/man/sl/man4", + "/usr/share/man/sl/man4x", + "/usr/share/man/sl/man5", + "/usr/share/man/sl/man5x", + "/usr/share/man/sl/man6", + "/usr/share/man/sl/man6x", + "/usr/share/man/sl/man7", + "/usr/share/man/sl/man7x", + "/usr/share/man/sl/man8", + "/usr/share/man/sl/man8x", + "/usr/share/man/sl/man9", + "/usr/share/man/sl/man9x", + "/usr/share/man/sl/mann", + "/usr/share/man/sl_SI", + "/usr/share/man/sl_SI/man0p", + "/usr/share/man/sl_SI/man1", + "/usr/share/man/sl_SI/man1p", + "/usr/share/man/sl_SI/man1x", + "/usr/share/man/sl_SI/man2", + "/usr/share/man/sl_SI/man2x", + "/usr/share/man/sl_SI/man3", + "/usr/share/man/sl_SI/man3p", + "/usr/share/man/sl_SI/man3x", + "/usr/share/man/sl_SI/man4", + "/usr/share/man/sl_SI/man4x", + "/usr/share/man/sl_SI/man5", + "/usr/share/man/sl_SI/man5x", + "/usr/share/man/sl_SI/man6", + "/usr/share/man/sl_SI/man6x", + "/usr/share/man/sl_SI/man7", + "/usr/share/man/sl_SI/man7x", + "/usr/share/man/sl_SI/man8", + "/usr/share/man/sl_SI/man8x", + "/usr/share/man/sl_SI/man9", + "/usr/share/man/sl_SI/man9x", + "/usr/share/man/sl_SI/mann", + "/usr/share/man/sla", + "/usr/share/man/sla/man0p", + "/usr/share/man/sla/man1", + "/usr/share/man/sla/man1p", + "/usr/share/man/sla/man1x", + "/usr/share/man/sla/man2", + "/usr/share/man/sla/man2x", + "/usr/share/man/sla/man3", + "/usr/share/man/sla/man3p", + "/usr/share/man/sla/man3x", + "/usr/share/man/sla/man4", + "/usr/share/man/sla/man4x", + "/usr/share/man/sla/man5", + "/usr/share/man/sla/man5x", + "/usr/share/man/sla/man6", + "/usr/share/man/sla/man6x", + "/usr/share/man/sla/man7", + "/usr/share/man/sla/man7x", + "/usr/share/man/sla/man8", + "/usr/share/man/sla/man8x", + "/usr/share/man/sla/man9", + "/usr/share/man/sla/man9x", + "/usr/share/man/sla/mann", + "/usr/share/man/sm", + "/usr/share/man/sm/man0p", + "/usr/share/man/sm/man1", + "/usr/share/man/sm/man1p", + "/usr/share/man/sm/man1x", + "/usr/share/man/sm/man2", + "/usr/share/man/sm/man2x", + "/usr/share/man/sm/man3", + "/usr/share/man/sm/man3p", + "/usr/share/man/sm/man3x", + "/usr/share/man/sm/man4", + "/usr/share/man/sm/man4x", + "/usr/share/man/sm/man5", + "/usr/share/man/sm/man5x", + "/usr/share/man/sm/man6", + "/usr/share/man/sm/man6x", + "/usr/share/man/sm/man7", + "/usr/share/man/sm/man7x", + "/usr/share/man/sm/man8", + "/usr/share/man/sm/man8x", + "/usr/share/man/sm/man9", + "/usr/share/man/sm/man9x", + "/usr/share/man/sm/mann", + "/usr/share/man/sma", + "/usr/share/man/sma/man0p", + "/usr/share/man/sma/man1", + "/usr/share/man/sma/man1p", + "/usr/share/man/sma/man1x", + "/usr/share/man/sma/man2", + "/usr/share/man/sma/man2x", + "/usr/share/man/sma/man3", + "/usr/share/man/sma/man3p", + "/usr/share/man/sma/man3x", + "/usr/share/man/sma/man4", + "/usr/share/man/sma/man4x", + "/usr/share/man/sma/man5", + "/usr/share/man/sma/man5x", + "/usr/share/man/sma/man6", + "/usr/share/man/sma/man6x", + "/usr/share/man/sma/man7", + "/usr/share/man/sma/man7x", + "/usr/share/man/sma/man8", + "/usr/share/man/sma/man8x", + "/usr/share/man/sma/man9", + "/usr/share/man/sma/man9x", + "/usr/share/man/sma/mann", + "/usr/share/man/smi", + "/usr/share/man/smi/man0p", + "/usr/share/man/smi/man1", + "/usr/share/man/smi/man1p", + "/usr/share/man/smi/man1x", + "/usr/share/man/smi/man2", + "/usr/share/man/smi/man2x", + "/usr/share/man/smi/man3", + "/usr/share/man/smi/man3p", + "/usr/share/man/smi/man3x", + "/usr/share/man/smi/man4", + "/usr/share/man/smi/man4x", + "/usr/share/man/smi/man5", + "/usr/share/man/smi/man5x", + "/usr/share/man/smi/man6", + "/usr/share/man/smi/man6x", + "/usr/share/man/smi/man7", + "/usr/share/man/smi/man7x", + "/usr/share/man/smi/man8", + "/usr/share/man/smi/man8x", + "/usr/share/man/smi/man9", + "/usr/share/man/smi/man9x", + "/usr/share/man/smi/mann", + "/usr/share/man/smj", + "/usr/share/man/smj/man0p", + "/usr/share/man/smj/man1", + "/usr/share/man/smj/man1p", + "/usr/share/man/smj/man1x", + "/usr/share/man/smj/man2", + "/usr/share/man/smj/man2x", + "/usr/share/man/smj/man3", + "/usr/share/man/smj/man3p", + "/usr/share/man/smj/man3x", + "/usr/share/man/smj/man4", + "/usr/share/man/smj/man4x", + "/usr/share/man/smj/man5", + "/usr/share/man/smj/man5x", + "/usr/share/man/smj/man6", + "/usr/share/man/smj/man6x", + "/usr/share/man/smj/man7", + "/usr/share/man/smj/man7x", + "/usr/share/man/smj/man8", + "/usr/share/man/smj/man8x", + "/usr/share/man/smj/man9", + "/usr/share/man/smj/man9x", + "/usr/share/man/smj/mann", + "/usr/share/man/smn", + "/usr/share/man/smn/man0p", + "/usr/share/man/smn/man1", + "/usr/share/man/smn/man1p", + "/usr/share/man/smn/man1x", + "/usr/share/man/smn/man2", + "/usr/share/man/smn/man2x", + "/usr/share/man/smn/man3", + "/usr/share/man/smn/man3p", + "/usr/share/man/smn/man3x", + "/usr/share/man/smn/man4", + "/usr/share/man/smn/man4x", + "/usr/share/man/smn/man5", + "/usr/share/man/smn/man5x", + "/usr/share/man/smn/man6", + "/usr/share/man/smn/man6x", + "/usr/share/man/smn/man7", + "/usr/share/man/smn/man7x", + "/usr/share/man/smn/man8", + "/usr/share/man/smn/man8x", + "/usr/share/man/smn/man9", + "/usr/share/man/smn/man9x", + "/usr/share/man/smn/mann", + "/usr/share/man/sms", + "/usr/share/man/sms/man0p", + "/usr/share/man/sms/man1", + "/usr/share/man/sms/man1p", + "/usr/share/man/sms/man1x", + "/usr/share/man/sms/man2", + "/usr/share/man/sms/man2x", + "/usr/share/man/sms/man3", + "/usr/share/man/sms/man3p", + "/usr/share/man/sms/man3x", + "/usr/share/man/sms/man4", + "/usr/share/man/sms/man4x", + "/usr/share/man/sms/man5", + "/usr/share/man/sms/man5x", + "/usr/share/man/sms/man6", + "/usr/share/man/sms/man6x", + "/usr/share/man/sms/man7", + "/usr/share/man/sms/man7x", + "/usr/share/man/sms/man8", + "/usr/share/man/sms/man8x", + "/usr/share/man/sms/man9", + "/usr/share/man/sms/man9x", + "/usr/share/man/sms/mann", + "/usr/share/man/sn", + "/usr/share/man/sn/man0p", + "/usr/share/man/sn/man1", + "/usr/share/man/sn/man1p", + "/usr/share/man/sn/man1x", + "/usr/share/man/sn/man2", + "/usr/share/man/sn/man2x", + "/usr/share/man/sn/man3", + "/usr/share/man/sn/man3p", + "/usr/share/man/sn/man3x", + "/usr/share/man/sn/man4", + "/usr/share/man/sn/man4x", + "/usr/share/man/sn/man5", + "/usr/share/man/sn/man5x", + "/usr/share/man/sn/man6", + "/usr/share/man/sn/man6x", + "/usr/share/man/sn/man7", + "/usr/share/man/sn/man7x", + "/usr/share/man/sn/man8", + "/usr/share/man/sn/man8x", + "/usr/share/man/sn/man9", + "/usr/share/man/sn/man9x", + "/usr/share/man/sn/mann", + "/usr/share/man/snk", + "/usr/share/man/snk/man0p", + "/usr/share/man/snk/man1", + "/usr/share/man/snk/man1p", + "/usr/share/man/snk/man1x", + "/usr/share/man/snk/man2", + "/usr/share/man/snk/man2x", + "/usr/share/man/snk/man3", + "/usr/share/man/snk/man3p", + "/usr/share/man/snk/man3x", + "/usr/share/man/snk/man4", + "/usr/share/man/snk/man4x", + "/usr/share/man/snk/man5", + "/usr/share/man/snk/man5x", + "/usr/share/man/snk/man6", + "/usr/share/man/snk/man6x", + "/usr/share/man/snk/man7", + "/usr/share/man/snk/man7x", + "/usr/share/man/snk/man8", + "/usr/share/man/snk/man8x", + "/usr/share/man/snk/man9", + "/usr/share/man/snk/man9x", + "/usr/share/man/snk/mann", + "/usr/share/man/so", + "/usr/share/man/so/man0p", + "/usr/share/man/so/man1", + "/usr/share/man/so/man1p", + "/usr/share/man/so/man1x", + "/usr/share/man/so/man2", + "/usr/share/man/so/man2x", + "/usr/share/man/so/man3", + "/usr/share/man/so/man3p", + "/usr/share/man/so/man3x", + "/usr/share/man/so/man4", + "/usr/share/man/so/man4x", + "/usr/share/man/so/man5", + "/usr/share/man/so/man5x", + "/usr/share/man/so/man6", + "/usr/share/man/so/man6x", + "/usr/share/man/so/man7", + "/usr/share/man/so/man7x", + "/usr/share/man/so/man8", + "/usr/share/man/so/man8x", + "/usr/share/man/so/man9", + "/usr/share/man/so/man9x", + "/usr/share/man/so/mann", + "/usr/share/man/sog", + "/usr/share/man/sog/man0p", + "/usr/share/man/sog/man1", + "/usr/share/man/sog/man1p", + "/usr/share/man/sog/man1x", + "/usr/share/man/sog/man2", + "/usr/share/man/sog/man2x", + "/usr/share/man/sog/man3", + "/usr/share/man/sog/man3p", + "/usr/share/man/sog/man3x", + "/usr/share/man/sog/man4", + "/usr/share/man/sog/man4x", + "/usr/share/man/sog/man5", + "/usr/share/man/sog/man5x", + "/usr/share/man/sog/man6", + "/usr/share/man/sog/man6x", + "/usr/share/man/sog/man7", + "/usr/share/man/sog/man7x", + "/usr/share/man/sog/man8", + "/usr/share/man/sog/man8x", + "/usr/share/man/sog/man9", + "/usr/share/man/sog/man9x", + "/usr/share/man/sog/mann", + "/usr/share/man/son", + "/usr/share/man/son/man0p", + "/usr/share/man/son/man1", + "/usr/share/man/son/man1p", + "/usr/share/man/son/man1x", + "/usr/share/man/son/man2", + "/usr/share/man/son/man2x", + "/usr/share/man/son/man3", + "/usr/share/man/son/man3p", + "/usr/share/man/son/man3x", + "/usr/share/man/son/man4", + "/usr/share/man/son/man4x", + "/usr/share/man/son/man5", + "/usr/share/man/son/man5x", + "/usr/share/man/son/man6", + "/usr/share/man/son/man6x", + "/usr/share/man/son/man7", + "/usr/share/man/son/man7x", + "/usr/share/man/son/man8", + "/usr/share/man/son/man8x", + "/usr/share/man/son/man9", + "/usr/share/man/son/man9x", + "/usr/share/man/son/mann", + "/usr/share/man/sp", + "/usr/share/man/sp/man0p", + "/usr/share/man/sp/man1", + "/usr/share/man/sp/man1p", + "/usr/share/man/sp/man1x", + "/usr/share/man/sp/man2", + "/usr/share/man/sp/man2x", + "/usr/share/man/sp/man3", + "/usr/share/man/sp/man3p", + "/usr/share/man/sp/man3x", + "/usr/share/man/sp/man4", + "/usr/share/man/sp/man4x", + "/usr/share/man/sp/man5", + "/usr/share/man/sp/man5x", + "/usr/share/man/sp/man6", + "/usr/share/man/sp/man6x", + "/usr/share/man/sp/man7", + "/usr/share/man/sp/man7x", + "/usr/share/man/sp/man8", + "/usr/share/man/sp/man8x", + "/usr/share/man/sp/man9", + "/usr/share/man/sp/man9x", + "/usr/share/man/sp/mann", + "/usr/share/man/sq", + "/usr/share/man/sq/man0p", + "/usr/share/man/sq/man1", + "/usr/share/man/sq/man1p", + "/usr/share/man/sq/man1x", + "/usr/share/man/sq/man2", + "/usr/share/man/sq/man2x", + "/usr/share/man/sq/man3", + "/usr/share/man/sq/man3p", + "/usr/share/man/sq/man3x", + "/usr/share/man/sq/man4", + "/usr/share/man/sq/man4x", + "/usr/share/man/sq/man5", + "/usr/share/man/sq/man5x", + "/usr/share/man/sq/man6", + "/usr/share/man/sq/man6x", + "/usr/share/man/sq/man7", + "/usr/share/man/sq/man7x", + "/usr/share/man/sq/man8", + "/usr/share/man/sq/man8x", + "/usr/share/man/sq/man9", + "/usr/share/man/sq/man9x", + "/usr/share/man/sq/mann", + "/usr/share/man/sq_AL", + "/usr/share/man/sq_AL/man0p", + "/usr/share/man/sq_AL/man1", + "/usr/share/man/sq_AL/man1p", + "/usr/share/man/sq_AL/man1x", + "/usr/share/man/sq_AL/man2", + "/usr/share/man/sq_AL/man2x", + "/usr/share/man/sq_AL/man3", + "/usr/share/man/sq_AL/man3p", + "/usr/share/man/sq_AL/man3x", + "/usr/share/man/sq_AL/man4", + "/usr/share/man/sq_AL/man4x", + "/usr/share/man/sq_AL/man5", + "/usr/share/man/sq_AL/man5x", + "/usr/share/man/sq_AL/man6", + "/usr/share/man/sq_AL/man6x", + "/usr/share/man/sq_AL/man7", + "/usr/share/man/sq_AL/man7x", + "/usr/share/man/sq_AL/man8", + "/usr/share/man/sq_AL/man8x", + "/usr/share/man/sq_AL/man9", + "/usr/share/man/sq_AL/man9x", + "/usr/share/man/sq_AL/mann", + "/usr/share/man/sr", + "/usr/share/man/sr/man0p", + "/usr/share/man/sr/man1", + "/usr/share/man/sr/man1p", + "/usr/share/man/sr/man1x", + "/usr/share/man/sr/man2", + "/usr/share/man/sr/man2x", + "/usr/share/man/sr/man3", + "/usr/share/man/sr/man3p", + "/usr/share/man/sr/man3x", + "/usr/share/man/sr/man4", + "/usr/share/man/sr/man4x", + "/usr/share/man/sr/man5", + "/usr/share/man/sr/man5x", + "/usr/share/man/sr/man6", + "/usr/share/man/sr/man6x", + "/usr/share/man/sr/man7", + "/usr/share/man/sr/man7x", + "/usr/share/man/sr/man8", + "/usr/share/man/sr/man8x", + "/usr/share/man/sr/man9", + "/usr/share/man/sr/man9x", + "/usr/share/man/sr/mann", + "/usr/share/man/sr@Latn", + "/usr/share/man/sr@Latn/man0p", + "/usr/share/man/sr@Latn/man1", + "/usr/share/man/sr@Latn/man1p", + "/usr/share/man/sr@Latn/man1x", + "/usr/share/man/sr@Latn/man2", + "/usr/share/man/sr@Latn/man2x", + "/usr/share/man/sr@Latn/man3", + "/usr/share/man/sr@Latn/man3p", + "/usr/share/man/sr@Latn/man3x", + "/usr/share/man/sr@Latn/man4", + "/usr/share/man/sr@Latn/man4x", + "/usr/share/man/sr@Latn/man5", + "/usr/share/man/sr@Latn/man5x", + "/usr/share/man/sr@Latn/man6", + "/usr/share/man/sr@Latn/man6x", + "/usr/share/man/sr@Latn/man7", + "/usr/share/man/sr@Latn/man7x", + "/usr/share/man/sr@Latn/man8", + "/usr/share/man/sr@Latn/man8x", + "/usr/share/man/sr@Latn/man9", + "/usr/share/man/sr@Latn/man9x", + "/usr/share/man/sr@Latn/mann", + "/usr/share/man/sr@ije", + "/usr/share/man/sr@ije/man0p", + "/usr/share/man/sr@ije/man1", + "/usr/share/man/sr@ije/man1p", + "/usr/share/man/sr@ije/man1x", + "/usr/share/man/sr@ije/man2", + "/usr/share/man/sr@ije/man2x", + "/usr/share/man/sr@ije/man3", + "/usr/share/man/sr@ije/man3p", + "/usr/share/man/sr@ije/man3x", + "/usr/share/man/sr@ije/man4", + "/usr/share/man/sr@ije/man4x", + "/usr/share/man/sr@ije/man5", + "/usr/share/man/sr@ije/man5x", + "/usr/share/man/sr@ije/man6", + "/usr/share/man/sr@ije/man6x", + "/usr/share/man/sr@ije/man7", + "/usr/share/man/sr@ije/man7x", + "/usr/share/man/sr@ije/man8", + "/usr/share/man/sr@ije/man8x", + "/usr/share/man/sr@ije/man9", + "/usr/share/man/sr@ije/man9x", + "/usr/share/man/sr@ije/mann", + "/usr/share/man/sr@ijekavian", + "/usr/share/man/sr@ijekavian/man0p", + "/usr/share/man/sr@ijekavian/man1", + "/usr/share/man/sr@ijekavian/man1p", + "/usr/share/man/sr@ijekavian/man1x", + "/usr/share/man/sr@ijekavian/man2", + "/usr/share/man/sr@ijekavian/man2x", + "/usr/share/man/sr@ijekavian/man3", + "/usr/share/man/sr@ijekavian/man3p", + "/usr/share/man/sr@ijekavian/man3x", + "/usr/share/man/sr@ijekavian/man4", + "/usr/share/man/sr@ijekavian/man4x", + "/usr/share/man/sr@ijekavian/man5", + "/usr/share/man/sr@ijekavian/man5x", + "/usr/share/man/sr@ijekavian/man6", + "/usr/share/man/sr@ijekavian/man6x", + "/usr/share/man/sr@ijekavian/man7", + "/usr/share/man/sr@ijekavian/man7x", + "/usr/share/man/sr@ijekavian/man8", + "/usr/share/man/sr@ijekavian/man8x", + "/usr/share/man/sr@ijekavian/man9", + "/usr/share/man/sr@ijekavian/man9x", + "/usr/share/man/sr@ijekavian/mann", + "/usr/share/man/sr@ijekavianlatin", + "/usr/share/man/sr@ijekavianlatin/man0p", + "/usr/share/man/sr@ijekavianlatin/man1", + "/usr/share/man/sr@ijekavianlatin/man1p", + "/usr/share/man/sr@ijekavianlatin/man1x", + "/usr/share/man/sr@ijekavianlatin/man2", + "/usr/share/man/sr@ijekavianlatin/man2x", + "/usr/share/man/sr@ijekavianlatin/man3", + "/usr/share/man/sr@ijekavianlatin/man3p", + "/usr/share/man/sr@ijekavianlatin/man3x", + "/usr/share/man/sr@ijekavianlatin/man4", + "/usr/share/man/sr@ijekavianlatin/man4x", + "/usr/share/man/sr@ijekavianlatin/man5", + "/usr/share/man/sr@ijekavianlatin/man5x", + "/usr/share/man/sr@ijekavianlatin/man6", + "/usr/share/man/sr@ijekavianlatin/man6x", + "/usr/share/man/sr@ijekavianlatin/man7", + "/usr/share/man/sr@ijekavianlatin/man7x", + "/usr/share/man/sr@ijekavianlatin/man8", + "/usr/share/man/sr@ijekavianlatin/man8x", + "/usr/share/man/sr@ijekavianlatin/man9", + "/usr/share/man/sr@ijekavianlatin/man9x", + "/usr/share/man/sr@ijekavianlatin/mann", + "/usr/share/man/sr@latin", + "/usr/share/man/sr@latin/man0p", + "/usr/share/man/sr@latin/man1", + "/usr/share/man/sr@latin/man1p", + "/usr/share/man/sr@latin/man1x", + "/usr/share/man/sr@latin/man2", + "/usr/share/man/sr@latin/man2x", + "/usr/share/man/sr@latin/man3", + "/usr/share/man/sr@latin/man3p", + "/usr/share/man/sr@latin/man3x", + "/usr/share/man/sr@latin/man4", + "/usr/share/man/sr@latin/man4x", + "/usr/share/man/sr@latin/man5", + "/usr/share/man/sr@latin/man5x", + "/usr/share/man/sr@latin/man6", + "/usr/share/man/sr@latin/man6x", + "/usr/share/man/sr@latin/man7", + "/usr/share/man/sr@latin/man7x", + "/usr/share/man/sr@latin/man8", + "/usr/share/man/sr@latin/man8x", + "/usr/share/man/sr@latin/man9", + "/usr/share/man/sr@latin/man9x", + "/usr/share/man/sr@latin/mann", + "/usr/share/man/sr_ME", + "/usr/share/man/sr_ME/man0p", + "/usr/share/man/sr_ME/man1", + "/usr/share/man/sr_ME/man1p", + "/usr/share/man/sr_ME/man1x", + "/usr/share/man/sr_ME/man2", + "/usr/share/man/sr_ME/man2x", + "/usr/share/man/sr_ME/man3", + "/usr/share/man/sr_ME/man3p", + "/usr/share/man/sr_ME/man3x", + "/usr/share/man/sr_ME/man4", + "/usr/share/man/sr_ME/man4x", + "/usr/share/man/sr_ME/man5", + "/usr/share/man/sr_ME/man5x", + "/usr/share/man/sr_ME/man6", + "/usr/share/man/sr_ME/man6x", + "/usr/share/man/sr_ME/man7", + "/usr/share/man/sr_ME/man7x", + "/usr/share/man/sr_ME/man8", + "/usr/share/man/sr_ME/man8x", + "/usr/share/man/sr_ME/man9", + "/usr/share/man/sr_ME/man9x", + "/usr/share/man/sr_ME/mann", + "/usr/share/man/sr_RS", + "/usr/share/man/sr_RS/man0p", + "/usr/share/man/sr_RS/man1", + "/usr/share/man/sr_RS/man1p", + "/usr/share/man/sr_RS/man1x", + "/usr/share/man/sr_RS/man2", + "/usr/share/man/sr_RS/man2x", + "/usr/share/man/sr_RS/man3", + "/usr/share/man/sr_RS/man3p", + "/usr/share/man/sr_RS/man3x", + "/usr/share/man/sr_RS/man4", + "/usr/share/man/sr_RS/man4x", + "/usr/share/man/sr_RS/man5", + "/usr/share/man/sr_RS/man5x", + "/usr/share/man/sr_RS/man6", + "/usr/share/man/sr_RS/man6x", + "/usr/share/man/sr_RS/man7", + "/usr/share/man/sr_RS/man7x", + "/usr/share/man/sr_RS/man8", + "/usr/share/man/sr_RS/man8x", + "/usr/share/man/sr_RS/man9", + "/usr/share/man/sr_RS/man9x", + "/usr/share/man/sr_RS/mann", + "/usr/share/man/sr_RS@latin", + "/usr/share/man/sr_RS@latin/man0p", + "/usr/share/man/sr_RS@latin/man1", + "/usr/share/man/sr_RS@latin/man1p", + "/usr/share/man/sr_RS@latin/man1x", + "/usr/share/man/sr_RS@latin/man2", + "/usr/share/man/sr_RS@latin/man2x", + "/usr/share/man/sr_RS@latin/man3", + "/usr/share/man/sr_RS@latin/man3p", + "/usr/share/man/sr_RS@latin/man3x", + "/usr/share/man/sr_RS@latin/man4", + "/usr/share/man/sr_RS@latin/man4x", + "/usr/share/man/sr_RS@latin/man5", + "/usr/share/man/sr_RS@latin/man5x", + "/usr/share/man/sr_RS@latin/man6", + "/usr/share/man/sr_RS@latin/man6x", + "/usr/share/man/sr_RS@latin/man7", + "/usr/share/man/sr_RS@latin/man7x", + "/usr/share/man/sr_RS@latin/man8", + "/usr/share/man/sr_RS@latin/man8x", + "/usr/share/man/sr_RS@latin/man9", + "/usr/share/man/sr_RS@latin/man9x", + "/usr/share/man/sr_RS@latin/mann", + "/usr/share/man/srd", + "/usr/share/man/srd/man0p", + "/usr/share/man/srd/man1", + "/usr/share/man/srd/man1p", + "/usr/share/man/srd/man1x", + "/usr/share/man/srd/man2", + "/usr/share/man/srd/man2x", + "/usr/share/man/srd/man3", + "/usr/share/man/srd/man3p", + "/usr/share/man/srd/man3x", + "/usr/share/man/srd/man4", + "/usr/share/man/srd/man4x", + "/usr/share/man/srd/man5", + "/usr/share/man/srd/man5x", + "/usr/share/man/srd/man6", + "/usr/share/man/srd/man6x", + "/usr/share/man/srd/man7", + "/usr/share/man/srd/man7x", + "/usr/share/man/srd/man8", + "/usr/share/man/srd/man8x", + "/usr/share/man/srd/man9", + "/usr/share/man/srd/man9x", + "/usr/share/man/srd/mann", + "/usr/share/man/srn", + "/usr/share/man/srn/man0p", + "/usr/share/man/srn/man1", + "/usr/share/man/srn/man1p", + "/usr/share/man/srn/man1x", + "/usr/share/man/srn/man2", + "/usr/share/man/srn/man2x", + "/usr/share/man/srn/man3", + "/usr/share/man/srn/man3p", + "/usr/share/man/srn/man3x", + "/usr/share/man/srn/man4", + "/usr/share/man/srn/man4x", + "/usr/share/man/srn/man5", + "/usr/share/man/srn/man5x", + "/usr/share/man/srn/man6", + "/usr/share/man/srn/man6x", + "/usr/share/man/srn/man7", + "/usr/share/man/srn/man7x", + "/usr/share/man/srn/man8", + "/usr/share/man/srn/man8x", + "/usr/share/man/srn/man9", + "/usr/share/man/srn/man9x", + "/usr/share/man/srn/mann", + "/usr/share/man/srr", + "/usr/share/man/srr/man0p", + "/usr/share/man/srr/man1", + "/usr/share/man/srr/man1p", + "/usr/share/man/srr/man1x", + "/usr/share/man/srr/man2", + "/usr/share/man/srr/man2x", + "/usr/share/man/srr/man3", + "/usr/share/man/srr/man3p", + "/usr/share/man/srr/man3x", + "/usr/share/man/srr/man4", + "/usr/share/man/srr/man4x", + "/usr/share/man/srr/man5", + "/usr/share/man/srr/man5x", + "/usr/share/man/srr/man6", + "/usr/share/man/srr/man6x", + "/usr/share/man/srr/man7", + "/usr/share/man/srr/man7x", + "/usr/share/man/srr/man8", + "/usr/share/man/srr/man8x", + "/usr/share/man/srr/man9", + "/usr/share/man/srr/man9x", + "/usr/share/man/srr/mann", + "/usr/share/man/ss", + "/usr/share/man/ss/man0p", + "/usr/share/man/ss/man1", + "/usr/share/man/ss/man1p", + "/usr/share/man/ss/man1x", + "/usr/share/man/ss/man2", + "/usr/share/man/ss/man2x", + "/usr/share/man/ss/man3", + "/usr/share/man/ss/man3p", + "/usr/share/man/ss/man3x", + "/usr/share/man/ss/man4", + "/usr/share/man/ss/man4x", + "/usr/share/man/ss/man5", + "/usr/share/man/ss/man5x", + "/usr/share/man/ss/man6", + "/usr/share/man/ss/man6x", + "/usr/share/man/ss/man7", + "/usr/share/man/ss/man7x", + "/usr/share/man/ss/man8", + "/usr/share/man/ss/man8x", + "/usr/share/man/ss/man9", + "/usr/share/man/ss/man9x", + "/usr/share/man/ss/mann", + "/usr/share/man/ssa", + "/usr/share/man/ssa/man0p", + "/usr/share/man/ssa/man1", + "/usr/share/man/ssa/man1p", + "/usr/share/man/ssa/man1x", + "/usr/share/man/ssa/man2", + "/usr/share/man/ssa/man2x", + "/usr/share/man/ssa/man3", + "/usr/share/man/ssa/man3p", + "/usr/share/man/ssa/man3x", + "/usr/share/man/ssa/man4", + "/usr/share/man/ssa/man4x", + "/usr/share/man/ssa/man5", + "/usr/share/man/ssa/man5x", + "/usr/share/man/ssa/man6", + "/usr/share/man/ssa/man6x", + "/usr/share/man/ssa/man7", + "/usr/share/man/ssa/man7x", + "/usr/share/man/ssa/man8", + "/usr/share/man/ssa/man8x", + "/usr/share/man/ssa/man9", + "/usr/share/man/ssa/man9x", + "/usr/share/man/ssa/mann", + "/usr/share/man/st", + "/usr/share/man/st/man0p", + "/usr/share/man/st/man1", + "/usr/share/man/st/man1p", + "/usr/share/man/st/man1x", + "/usr/share/man/st/man2", + "/usr/share/man/st/man2x", + "/usr/share/man/st/man3", + "/usr/share/man/st/man3p", + "/usr/share/man/st/man3x", + "/usr/share/man/st/man4", + "/usr/share/man/st/man4x", + "/usr/share/man/st/man5", + "/usr/share/man/st/man5x", + "/usr/share/man/st/man6", + "/usr/share/man/st/man6x", + "/usr/share/man/st/man7", + "/usr/share/man/st/man7x", + "/usr/share/man/st/man8", + "/usr/share/man/st/man8x", + "/usr/share/man/st/man9", + "/usr/share/man/st/man9x", + "/usr/share/man/st/mann", + "/usr/share/man/su", + "/usr/share/man/su/man0p", + "/usr/share/man/su/man1", + "/usr/share/man/su/man1p", + "/usr/share/man/su/man1x", + "/usr/share/man/su/man2", + "/usr/share/man/su/man2x", + "/usr/share/man/su/man3", + "/usr/share/man/su/man3p", + "/usr/share/man/su/man3x", + "/usr/share/man/su/man4", + "/usr/share/man/su/man4x", + "/usr/share/man/su/man5", + "/usr/share/man/su/man5x", + "/usr/share/man/su/man6", + "/usr/share/man/su/man6x", + "/usr/share/man/su/man7", + "/usr/share/man/su/man7x", + "/usr/share/man/su/man8", + "/usr/share/man/su/man8x", + "/usr/share/man/su/man9", + "/usr/share/man/su/man9x", + "/usr/share/man/su/mann", + "/usr/share/man/suk", + "/usr/share/man/suk/man0p", + "/usr/share/man/suk/man1", + "/usr/share/man/suk/man1p", + "/usr/share/man/suk/man1x", + "/usr/share/man/suk/man2", + "/usr/share/man/suk/man2x", + "/usr/share/man/suk/man3", + "/usr/share/man/suk/man3p", + "/usr/share/man/suk/man3x", + "/usr/share/man/suk/man4", + "/usr/share/man/suk/man4x", + "/usr/share/man/suk/man5", + "/usr/share/man/suk/man5x", + "/usr/share/man/suk/man6", + "/usr/share/man/suk/man6x", + "/usr/share/man/suk/man7", + "/usr/share/man/suk/man7x", + "/usr/share/man/suk/man8", + "/usr/share/man/suk/man8x", + "/usr/share/man/suk/man9", + "/usr/share/man/suk/man9x", + "/usr/share/man/suk/mann", + "/usr/share/man/sus", + "/usr/share/man/sus/man0p", + "/usr/share/man/sus/man1", + "/usr/share/man/sus/man1p", + "/usr/share/man/sus/man1x", + "/usr/share/man/sus/man2", + "/usr/share/man/sus/man2x", + "/usr/share/man/sus/man3", + "/usr/share/man/sus/man3p", + "/usr/share/man/sus/man3x", + "/usr/share/man/sus/man4", + "/usr/share/man/sus/man4x", + "/usr/share/man/sus/man5", + "/usr/share/man/sus/man5x", + "/usr/share/man/sus/man6", + "/usr/share/man/sus/man6x", + "/usr/share/man/sus/man7", + "/usr/share/man/sus/man7x", + "/usr/share/man/sus/man8", + "/usr/share/man/sus/man8x", + "/usr/share/man/sus/man9", + "/usr/share/man/sus/man9x", + "/usr/share/man/sus/mann", + "/usr/share/man/sux", + "/usr/share/man/sux/man0p", + "/usr/share/man/sux/man1", + "/usr/share/man/sux/man1p", + "/usr/share/man/sux/man1x", + "/usr/share/man/sux/man2", + "/usr/share/man/sux/man2x", + "/usr/share/man/sux/man3", + "/usr/share/man/sux/man3p", + "/usr/share/man/sux/man3x", + "/usr/share/man/sux/man4", + "/usr/share/man/sux/man4x", + "/usr/share/man/sux/man5", + "/usr/share/man/sux/man5x", + "/usr/share/man/sux/man6", + "/usr/share/man/sux/man6x", + "/usr/share/man/sux/man7", + "/usr/share/man/sux/man7x", + "/usr/share/man/sux/man8", + "/usr/share/man/sux/man8x", + "/usr/share/man/sux/man9", + "/usr/share/man/sux/man9x", + "/usr/share/man/sux/mann", + "/usr/share/man/sv", + "/usr/share/man/sv/man0p", + "/usr/share/man/sv/man1", + "/usr/share/man/sv/man1p", + "/usr/share/man/sv/man1x", + "/usr/share/man/sv/man2", + "/usr/share/man/sv/man2x", + "/usr/share/man/sv/man3", + "/usr/share/man/sv/man3p", + "/usr/share/man/sv/man3x", + "/usr/share/man/sv/man4", + "/usr/share/man/sv/man4x", + "/usr/share/man/sv/man5", + "/usr/share/man/sv/man5x", + "/usr/share/man/sv/man6", + "/usr/share/man/sv/man6x", + "/usr/share/man/sv/man7", + "/usr/share/man/sv/man7x", + "/usr/share/man/sv/man8", + "/usr/share/man/sv/man8x", + "/usr/share/man/sv/man9", + "/usr/share/man/sv/man9x", + "/usr/share/man/sv/mann", + "/usr/share/man/sv_SE", + "/usr/share/man/sv_SE/man0p", + "/usr/share/man/sv_SE/man1", + "/usr/share/man/sv_SE/man1p", + "/usr/share/man/sv_SE/man1x", + "/usr/share/man/sv_SE/man2", + "/usr/share/man/sv_SE/man2x", + "/usr/share/man/sv_SE/man3", + "/usr/share/man/sv_SE/man3p", + "/usr/share/man/sv_SE/man3x", + "/usr/share/man/sv_SE/man4", + "/usr/share/man/sv_SE/man4x", + "/usr/share/man/sv_SE/man5", + "/usr/share/man/sv_SE/man5x", + "/usr/share/man/sv_SE/man6", + "/usr/share/man/sv_SE/man6x", + "/usr/share/man/sv_SE/man7", + "/usr/share/man/sv_SE/man7x", + "/usr/share/man/sv_SE/man8", + "/usr/share/man/sv_SE/man8x", + "/usr/share/man/sv_SE/man9", + "/usr/share/man/sv_SE/man9x", + "/usr/share/man/sv_SE/mann", + "/usr/share/man/sw", + "/usr/share/man/sw/man0p", + "/usr/share/man/sw/man1", + "/usr/share/man/sw/man1p", + "/usr/share/man/sw/man1x", + "/usr/share/man/sw/man2", + "/usr/share/man/sw/man2x", + "/usr/share/man/sw/man3", + "/usr/share/man/sw/man3p", + "/usr/share/man/sw/man3x", + "/usr/share/man/sw/man4", + "/usr/share/man/sw/man4x", + "/usr/share/man/sw/man5", + "/usr/share/man/sw/man5x", + "/usr/share/man/sw/man6", + "/usr/share/man/sw/man6x", + "/usr/share/man/sw/man7", + "/usr/share/man/sw/man7x", + "/usr/share/man/sw/man8", + "/usr/share/man/sw/man8x", + "/usr/share/man/sw/man9", + "/usr/share/man/sw/man9x", + "/usr/share/man/sw/mann", + "/usr/share/man/syc", + "/usr/share/man/syc/man0p", + "/usr/share/man/syc/man1", + "/usr/share/man/syc/man1p", + "/usr/share/man/syc/man1x", + "/usr/share/man/syc/man2", + "/usr/share/man/syc/man2x", + "/usr/share/man/syc/man3", + "/usr/share/man/syc/man3p", + "/usr/share/man/syc/man3x", + "/usr/share/man/syc/man4", + "/usr/share/man/syc/man4x", + "/usr/share/man/syc/man5", + "/usr/share/man/syc/man5x", + "/usr/share/man/syc/man6", + "/usr/share/man/syc/man6x", + "/usr/share/man/syc/man7", + "/usr/share/man/syc/man7x", + "/usr/share/man/syc/man8", + "/usr/share/man/syc/man8x", + "/usr/share/man/syc/man9", + "/usr/share/man/syc/man9x", + "/usr/share/man/syc/mann", + "/usr/share/man/syr", + "/usr/share/man/syr/man0p", + "/usr/share/man/syr/man1", + "/usr/share/man/syr/man1p", + "/usr/share/man/syr/man1x", + "/usr/share/man/syr/man2", + "/usr/share/man/syr/man2x", + "/usr/share/man/syr/man3", + "/usr/share/man/syr/man3p", + "/usr/share/man/syr/man3x", + "/usr/share/man/syr/man4", + "/usr/share/man/syr/man4x", + "/usr/share/man/syr/man5", + "/usr/share/man/syr/man5x", + "/usr/share/man/syr/man6", + "/usr/share/man/syr/man6x", + "/usr/share/man/syr/man7", + "/usr/share/man/syr/man7x", + "/usr/share/man/syr/man8", + "/usr/share/man/syr/man8x", + "/usr/share/man/syr/man9", + "/usr/share/man/syr/man9x", + "/usr/share/man/syr/mann", + "/usr/share/man/szl", + "/usr/share/man/szl/man0p", + "/usr/share/man/szl/man1", + "/usr/share/man/szl/man1p", + "/usr/share/man/szl/man1x", + "/usr/share/man/szl/man2", + "/usr/share/man/szl/man2x", + "/usr/share/man/szl/man3", + "/usr/share/man/szl/man3p", + "/usr/share/man/szl/man3x", + "/usr/share/man/szl/man4", + "/usr/share/man/szl/man4x", + "/usr/share/man/szl/man5", + "/usr/share/man/szl/man5x", + "/usr/share/man/szl/man6", + "/usr/share/man/szl/man6x", + "/usr/share/man/szl/man7", + "/usr/share/man/szl/man7x", + "/usr/share/man/szl/man8", + "/usr/share/man/szl/man8x", + "/usr/share/man/szl/man9", + "/usr/share/man/szl/man9x", + "/usr/share/man/szl/mann", + "/usr/share/man/ta", + "/usr/share/man/ta/man0p", + "/usr/share/man/ta/man1", + "/usr/share/man/ta/man1p", + "/usr/share/man/ta/man1x", + "/usr/share/man/ta/man2", + "/usr/share/man/ta/man2x", + "/usr/share/man/ta/man3", + "/usr/share/man/ta/man3p", + "/usr/share/man/ta/man3x", + "/usr/share/man/ta/man4", + "/usr/share/man/ta/man4x", + "/usr/share/man/ta/man5", + "/usr/share/man/ta/man5x", + "/usr/share/man/ta/man6", + "/usr/share/man/ta/man6x", + "/usr/share/man/ta/man7", + "/usr/share/man/ta/man7x", + "/usr/share/man/ta/man8", + "/usr/share/man/ta/man8x", + "/usr/share/man/ta/man9", + "/usr/share/man/ta/man9x", + "/usr/share/man/ta/mann", + "/usr/share/man/ta_IN", + "/usr/share/man/ta_IN/man0p", + "/usr/share/man/ta_IN/man1", + "/usr/share/man/ta_IN/man1p", + "/usr/share/man/ta_IN/man1x", + "/usr/share/man/ta_IN/man2", + "/usr/share/man/ta_IN/man2x", + "/usr/share/man/ta_IN/man3", + "/usr/share/man/ta_IN/man3p", + "/usr/share/man/ta_IN/man3x", + "/usr/share/man/ta_IN/man4", + "/usr/share/man/ta_IN/man4x", + "/usr/share/man/ta_IN/man5", + "/usr/share/man/ta_IN/man5x", + "/usr/share/man/ta_IN/man6", + "/usr/share/man/ta_IN/man6x", + "/usr/share/man/ta_IN/man7", + "/usr/share/man/ta_IN/man7x", + "/usr/share/man/ta_IN/man8", + "/usr/share/man/ta_IN/man8x", + "/usr/share/man/ta_IN/man9", + "/usr/share/man/ta_IN/man9x", + "/usr/share/man/ta_IN/mann", + "/usr/share/man/ta_LK", + "/usr/share/man/ta_LK/man0p", + "/usr/share/man/ta_LK/man1", + "/usr/share/man/ta_LK/man1p", + "/usr/share/man/ta_LK/man1x", + "/usr/share/man/ta_LK/man2", + "/usr/share/man/ta_LK/man2x", + "/usr/share/man/ta_LK/man3", + "/usr/share/man/ta_LK/man3p", + "/usr/share/man/ta_LK/man3x", + "/usr/share/man/ta_LK/man4", + "/usr/share/man/ta_LK/man4x", + "/usr/share/man/ta_LK/man5", + "/usr/share/man/ta_LK/man5x", + "/usr/share/man/ta_LK/man6", + "/usr/share/man/ta_LK/man6x", + "/usr/share/man/ta_LK/man7", + "/usr/share/man/ta_LK/man7x", + "/usr/share/man/ta_LK/man8", + "/usr/share/man/ta_LK/man8x", + "/usr/share/man/ta_LK/man9", + "/usr/share/man/ta_LK/man9x", + "/usr/share/man/ta_LK/mann", + "/usr/share/man/tai", + "/usr/share/man/tai/man0p", + "/usr/share/man/tai/man1", + "/usr/share/man/tai/man1p", + "/usr/share/man/tai/man1x", + "/usr/share/man/tai/man2", + "/usr/share/man/tai/man2x", + "/usr/share/man/tai/man3", + "/usr/share/man/tai/man3p", + "/usr/share/man/tai/man3x", + "/usr/share/man/tai/man4", + "/usr/share/man/tai/man4x", + "/usr/share/man/tai/man5", + "/usr/share/man/tai/man5x", + "/usr/share/man/tai/man6", + "/usr/share/man/tai/man6x", + "/usr/share/man/tai/man7", + "/usr/share/man/tai/man7x", + "/usr/share/man/tai/man8", + "/usr/share/man/tai/man8x", + "/usr/share/man/tai/man9", + "/usr/share/man/tai/man9x", + "/usr/share/man/tai/mann", + "/usr/share/man/te", + "/usr/share/man/te/man0p", + "/usr/share/man/te/man1", + "/usr/share/man/te/man1p", + "/usr/share/man/te/man1x", + "/usr/share/man/te/man2", + "/usr/share/man/te/man2x", + "/usr/share/man/te/man3", + "/usr/share/man/te/man3p", + "/usr/share/man/te/man3x", + "/usr/share/man/te/man4", + "/usr/share/man/te/man4x", + "/usr/share/man/te/man5", + "/usr/share/man/te/man5x", + "/usr/share/man/te/man6", + "/usr/share/man/te/man6x", + "/usr/share/man/te/man7", + "/usr/share/man/te/man7x", + "/usr/share/man/te/man8", + "/usr/share/man/te/man8x", + "/usr/share/man/te/man9", + "/usr/share/man/te/man9x", + "/usr/share/man/te/mann", + "/usr/share/man/tem", + "/usr/share/man/tem/man0p", + "/usr/share/man/tem/man1", + "/usr/share/man/tem/man1p", + "/usr/share/man/tem/man1x", + "/usr/share/man/tem/man2", + "/usr/share/man/tem/man2x", + "/usr/share/man/tem/man3", + "/usr/share/man/tem/man3p", + "/usr/share/man/tem/man3x", + "/usr/share/man/tem/man4", + "/usr/share/man/tem/man4x", + "/usr/share/man/tem/man5", + "/usr/share/man/tem/man5x", + "/usr/share/man/tem/man6", + "/usr/share/man/tem/man6x", + "/usr/share/man/tem/man7", + "/usr/share/man/tem/man7x", + "/usr/share/man/tem/man8", + "/usr/share/man/tem/man8x", + "/usr/share/man/tem/man9", + "/usr/share/man/tem/man9x", + "/usr/share/man/tem/mann", + "/usr/share/man/ter", + "/usr/share/man/ter/man0p", + "/usr/share/man/ter/man1", + "/usr/share/man/ter/man1p", + "/usr/share/man/ter/man1x", + "/usr/share/man/ter/man2", + "/usr/share/man/ter/man2x", + "/usr/share/man/ter/man3", + "/usr/share/man/ter/man3p", + "/usr/share/man/ter/man3x", + "/usr/share/man/ter/man4", + "/usr/share/man/ter/man4x", + "/usr/share/man/ter/man5", + "/usr/share/man/ter/man5x", + "/usr/share/man/ter/man6", + "/usr/share/man/ter/man6x", + "/usr/share/man/ter/man7", + "/usr/share/man/ter/man7x", + "/usr/share/man/ter/man8", + "/usr/share/man/ter/man8x", + "/usr/share/man/ter/man9", + "/usr/share/man/ter/man9x", + "/usr/share/man/ter/mann", + "/usr/share/man/tet", + "/usr/share/man/tet/man0p", + "/usr/share/man/tet/man1", + "/usr/share/man/tet/man1p", + "/usr/share/man/tet/man1x", + "/usr/share/man/tet/man2", + "/usr/share/man/tet/man2x", + "/usr/share/man/tet/man3", + "/usr/share/man/tet/man3p", + "/usr/share/man/tet/man3x", + "/usr/share/man/tet/man4", + "/usr/share/man/tet/man4x", + "/usr/share/man/tet/man5", + "/usr/share/man/tet/man5x", + "/usr/share/man/tet/man6", + "/usr/share/man/tet/man6x", + "/usr/share/man/tet/man7", + "/usr/share/man/tet/man7x", + "/usr/share/man/tet/man8", + "/usr/share/man/tet/man8x", + "/usr/share/man/tet/man9", + "/usr/share/man/tet/man9x", + "/usr/share/man/tet/mann", + "/usr/share/man/tg", + "/usr/share/man/tg/man0p", + "/usr/share/man/tg/man1", + "/usr/share/man/tg/man1p", + "/usr/share/man/tg/man1x", + "/usr/share/man/tg/man2", + "/usr/share/man/tg/man2x", + "/usr/share/man/tg/man3", + "/usr/share/man/tg/man3p", + "/usr/share/man/tg/man3x", + "/usr/share/man/tg/man4", + "/usr/share/man/tg/man4x", + "/usr/share/man/tg/man5", + "/usr/share/man/tg/man5x", + "/usr/share/man/tg/man6", + "/usr/share/man/tg/man6x", + "/usr/share/man/tg/man7", + "/usr/share/man/tg/man7x", + "/usr/share/man/tg/man8", + "/usr/share/man/tg/man8x", + "/usr/share/man/tg/man9", + "/usr/share/man/tg/man9x", + "/usr/share/man/tg/mann", + "/usr/share/man/th", + "/usr/share/man/th/man0p", + "/usr/share/man/th/man1", + "/usr/share/man/th/man1p", + "/usr/share/man/th/man1x", + "/usr/share/man/th/man2", + "/usr/share/man/th/man2x", + "/usr/share/man/th/man3", + "/usr/share/man/th/man3p", + "/usr/share/man/th/man3x", + "/usr/share/man/th/man4", + "/usr/share/man/th/man4x", + "/usr/share/man/th/man5", + "/usr/share/man/th/man5x", + "/usr/share/man/th/man6", + "/usr/share/man/th/man6x", + "/usr/share/man/th/man7", + "/usr/share/man/th/man7x", + "/usr/share/man/th/man8", + "/usr/share/man/th/man8x", + "/usr/share/man/th/man9", + "/usr/share/man/th/man9x", + "/usr/share/man/th/mann", + "/usr/share/man/th_TH", + "/usr/share/man/th_TH/man0p", + "/usr/share/man/th_TH/man1", + "/usr/share/man/th_TH/man1p", + "/usr/share/man/th_TH/man1x", + "/usr/share/man/th_TH/man2", + "/usr/share/man/th_TH/man2x", + "/usr/share/man/th_TH/man3", + "/usr/share/man/th_TH/man3p", + "/usr/share/man/th_TH/man3x", + "/usr/share/man/th_TH/man4", + "/usr/share/man/th_TH/man4x", + "/usr/share/man/th_TH/man5", + "/usr/share/man/th_TH/man5x", + "/usr/share/man/th_TH/man6", + "/usr/share/man/th_TH/man6x", + "/usr/share/man/th_TH/man7", + "/usr/share/man/th_TH/man7x", + "/usr/share/man/th_TH/man8", + "/usr/share/man/th_TH/man8x", + "/usr/share/man/th_TH/man9", + "/usr/share/man/th_TH/man9x", + "/usr/share/man/th_TH/mann", + "/usr/share/man/ti", + "/usr/share/man/ti/man0p", + "/usr/share/man/ti/man1", + "/usr/share/man/ti/man1p", + "/usr/share/man/ti/man1x", + "/usr/share/man/ti/man2", + "/usr/share/man/ti/man2x", + "/usr/share/man/ti/man3", + "/usr/share/man/ti/man3p", + "/usr/share/man/ti/man3x", + "/usr/share/man/ti/man4", + "/usr/share/man/ti/man4x", + "/usr/share/man/ti/man5", + "/usr/share/man/ti/man5x", + "/usr/share/man/ti/man6", + "/usr/share/man/ti/man6x", + "/usr/share/man/ti/man7", + "/usr/share/man/ti/man7x", + "/usr/share/man/ti/man8", + "/usr/share/man/ti/man8x", + "/usr/share/man/ti/man9", + "/usr/share/man/ti/man9x", + "/usr/share/man/ti/mann", + "/usr/share/man/tig", + "/usr/share/man/tig/man0p", + "/usr/share/man/tig/man1", + "/usr/share/man/tig/man1p", + "/usr/share/man/tig/man1x", + "/usr/share/man/tig/man2", + "/usr/share/man/tig/man2x", + "/usr/share/man/tig/man3", + "/usr/share/man/tig/man3p", + "/usr/share/man/tig/man3x", + "/usr/share/man/tig/man4", + "/usr/share/man/tig/man4x", + "/usr/share/man/tig/man5", + "/usr/share/man/tig/man5x", + "/usr/share/man/tig/man6", + "/usr/share/man/tig/man6x", + "/usr/share/man/tig/man7", + "/usr/share/man/tig/man7x", + "/usr/share/man/tig/man8", + "/usr/share/man/tig/man8x", + "/usr/share/man/tig/man9", + "/usr/share/man/tig/man9x", + "/usr/share/man/tig/mann", + "/usr/share/man/tiv", + "/usr/share/man/tiv/man0p", + "/usr/share/man/tiv/man1", + "/usr/share/man/tiv/man1p", + "/usr/share/man/tiv/man1x", + "/usr/share/man/tiv/man2", + "/usr/share/man/tiv/man2x", + "/usr/share/man/tiv/man3", + "/usr/share/man/tiv/man3p", + "/usr/share/man/tiv/man3x", + "/usr/share/man/tiv/man4", + "/usr/share/man/tiv/man4x", + "/usr/share/man/tiv/man5", + "/usr/share/man/tiv/man5x", + "/usr/share/man/tiv/man6", + "/usr/share/man/tiv/man6x", + "/usr/share/man/tiv/man7", + "/usr/share/man/tiv/man7x", + "/usr/share/man/tiv/man8", + "/usr/share/man/tiv/man8x", + "/usr/share/man/tiv/man9", + "/usr/share/man/tiv/man9x", + "/usr/share/man/tiv/mann", + "/usr/share/man/tk", + "/usr/share/man/tk/man0p", + "/usr/share/man/tk/man1", + "/usr/share/man/tk/man1p", + "/usr/share/man/tk/man1x", + "/usr/share/man/tk/man2", + "/usr/share/man/tk/man2x", + "/usr/share/man/tk/man3", + "/usr/share/man/tk/man3p", + "/usr/share/man/tk/man3x", + "/usr/share/man/tk/man4", + "/usr/share/man/tk/man4x", + "/usr/share/man/tk/man5", + "/usr/share/man/tk/man5x", + "/usr/share/man/tk/man6", + "/usr/share/man/tk/man6x", + "/usr/share/man/tk/man7", + "/usr/share/man/tk/man7x", + "/usr/share/man/tk/man8", + "/usr/share/man/tk/man8x", + "/usr/share/man/tk/man9", + "/usr/share/man/tk/man9x", + "/usr/share/man/tk/mann", + "/usr/share/man/tkl", + "/usr/share/man/tkl/man0p", + "/usr/share/man/tkl/man1", + "/usr/share/man/tkl/man1p", + "/usr/share/man/tkl/man1x", + "/usr/share/man/tkl/man2", + "/usr/share/man/tkl/man2x", + "/usr/share/man/tkl/man3", + "/usr/share/man/tkl/man3p", + "/usr/share/man/tkl/man3x", + "/usr/share/man/tkl/man4", + "/usr/share/man/tkl/man4x", + "/usr/share/man/tkl/man5", + "/usr/share/man/tkl/man5x", + "/usr/share/man/tkl/man6", + "/usr/share/man/tkl/man6x", + "/usr/share/man/tkl/man7", + "/usr/share/man/tkl/man7x", + "/usr/share/man/tkl/man8", + "/usr/share/man/tkl/man8x", + "/usr/share/man/tkl/man9", + "/usr/share/man/tkl/man9x", + "/usr/share/man/tkl/mann", + "/usr/share/man/tl", + "/usr/share/man/tl/man0p", + "/usr/share/man/tl/man1", + "/usr/share/man/tl/man1p", + "/usr/share/man/tl/man1x", + "/usr/share/man/tl/man2", + "/usr/share/man/tl/man2x", + "/usr/share/man/tl/man3", + "/usr/share/man/tl/man3p", + "/usr/share/man/tl/man3x", + "/usr/share/man/tl/man4", + "/usr/share/man/tl/man4x", + "/usr/share/man/tl/man5", + "/usr/share/man/tl/man5x", + "/usr/share/man/tl/man6", + "/usr/share/man/tl/man6x", + "/usr/share/man/tl/man7", + "/usr/share/man/tl/man7x", + "/usr/share/man/tl/man8", + "/usr/share/man/tl/man8x", + "/usr/share/man/tl/man9", + "/usr/share/man/tl/man9x", + "/usr/share/man/tl/mann", + "/usr/share/man/tl_PH", + "/usr/share/man/tl_PH/man0p", + "/usr/share/man/tl_PH/man1", + "/usr/share/man/tl_PH/man1p", + "/usr/share/man/tl_PH/man1x", + "/usr/share/man/tl_PH/man2", + "/usr/share/man/tl_PH/man2x", + "/usr/share/man/tl_PH/man3", + "/usr/share/man/tl_PH/man3p", + "/usr/share/man/tl_PH/man3x", + "/usr/share/man/tl_PH/man4", + "/usr/share/man/tl_PH/man4x", + "/usr/share/man/tl_PH/man5", + "/usr/share/man/tl_PH/man5x", + "/usr/share/man/tl_PH/man6", + "/usr/share/man/tl_PH/man6x", + "/usr/share/man/tl_PH/man7", + "/usr/share/man/tl_PH/man7x", + "/usr/share/man/tl_PH/man8", + "/usr/share/man/tl_PH/man8x", + "/usr/share/man/tl_PH/man9", + "/usr/share/man/tl_PH/man9x", + "/usr/share/man/tl_PH/mann", + "/usr/share/man/tlh", + "/usr/share/man/tlh/man0p", + "/usr/share/man/tlh/man1", + "/usr/share/man/tlh/man1p", + "/usr/share/man/tlh/man1x", + "/usr/share/man/tlh/man2", + "/usr/share/man/tlh/man2x", + "/usr/share/man/tlh/man3", + "/usr/share/man/tlh/man3p", + "/usr/share/man/tlh/man3x", + "/usr/share/man/tlh/man4", + "/usr/share/man/tlh/man4x", + "/usr/share/man/tlh/man5", + "/usr/share/man/tlh/man5x", + "/usr/share/man/tlh/man6", + "/usr/share/man/tlh/man6x", + "/usr/share/man/tlh/man7", + "/usr/share/man/tlh/man7x", + "/usr/share/man/tlh/man8", + "/usr/share/man/tlh/man8x", + "/usr/share/man/tlh/man9", + "/usr/share/man/tlh/man9x", + "/usr/share/man/tlh/mann", + "/usr/share/man/tli", + "/usr/share/man/tli/man0p", + "/usr/share/man/tli/man1", + "/usr/share/man/tli/man1p", + "/usr/share/man/tli/man1x", + "/usr/share/man/tli/man2", + "/usr/share/man/tli/man2x", + "/usr/share/man/tli/man3", + "/usr/share/man/tli/man3p", + "/usr/share/man/tli/man3x", + "/usr/share/man/tli/man4", + "/usr/share/man/tli/man4x", + "/usr/share/man/tli/man5", + "/usr/share/man/tli/man5x", + "/usr/share/man/tli/man6", + "/usr/share/man/tli/man6x", + "/usr/share/man/tli/man7", + "/usr/share/man/tli/man7x", + "/usr/share/man/tli/man8", + "/usr/share/man/tli/man8x", + "/usr/share/man/tli/man9", + "/usr/share/man/tli/man9x", + "/usr/share/man/tli/mann", + "/usr/share/man/tmh", + "/usr/share/man/tmh/man0p", + "/usr/share/man/tmh/man1", + "/usr/share/man/tmh/man1p", + "/usr/share/man/tmh/man1x", + "/usr/share/man/tmh/man2", + "/usr/share/man/tmh/man2x", + "/usr/share/man/tmh/man3", + "/usr/share/man/tmh/man3p", + "/usr/share/man/tmh/man3x", + "/usr/share/man/tmh/man4", + "/usr/share/man/tmh/man4x", + "/usr/share/man/tmh/man5", + "/usr/share/man/tmh/man5x", + "/usr/share/man/tmh/man6", + "/usr/share/man/tmh/man6x", + "/usr/share/man/tmh/man7", + "/usr/share/man/tmh/man7x", + "/usr/share/man/tmh/man8", + "/usr/share/man/tmh/man8x", + "/usr/share/man/tmh/man9", + "/usr/share/man/tmh/man9x", + "/usr/share/man/tmh/mann", + "/usr/share/man/tn", + "/usr/share/man/tn/man0p", + "/usr/share/man/tn/man1", + "/usr/share/man/tn/man1p", + "/usr/share/man/tn/man1x", + "/usr/share/man/tn/man2", + "/usr/share/man/tn/man2x", + "/usr/share/man/tn/man3", + "/usr/share/man/tn/man3p", + "/usr/share/man/tn/man3x", + "/usr/share/man/tn/man4", + "/usr/share/man/tn/man4x", + "/usr/share/man/tn/man5", + "/usr/share/man/tn/man5x", + "/usr/share/man/tn/man6", + "/usr/share/man/tn/man6x", + "/usr/share/man/tn/man7", + "/usr/share/man/tn/man7x", + "/usr/share/man/tn/man8", + "/usr/share/man/tn/man8x", + "/usr/share/man/tn/man9", + "/usr/share/man/tn/man9x", + "/usr/share/man/tn/mann", + "/usr/share/man/to", + "/usr/share/man/to/man0p", + "/usr/share/man/to/man1", + "/usr/share/man/to/man1p", + "/usr/share/man/to/man1x", + "/usr/share/man/to/man2", + "/usr/share/man/to/man2x", + "/usr/share/man/to/man3", + "/usr/share/man/to/man3p", + "/usr/share/man/to/man3x", + "/usr/share/man/to/man4", + "/usr/share/man/to/man4x", + "/usr/share/man/to/man5", + "/usr/share/man/to/man5x", + "/usr/share/man/to/man6", + "/usr/share/man/to/man6x", + "/usr/share/man/to/man7", + "/usr/share/man/to/man7x", + "/usr/share/man/to/man8", + "/usr/share/man/to/man8x", + "/usr/share/man/to/man9", + "/usr/share/man/to/man9x", + "/usr/share/man/to/mann", + "/usr/share/man/tog", + "/usr/share/man/tog/man0p", + "/usr/share/man/tog/man1", + "/usr/share/man/tog/man1p", + "/usr/share/man/tog/man1x", + "/usr/share/man/tog/man2", + "/usr/share/man/tog/man2x", + "/usr/share/man/tog/man3", + "/usr/share/man/tog/man3p", + "/usr/share/man/tog/man3x", + "/usr/share/man/tog/man4", + "/usr/share/man/tog/man4x", + "/usr/share/man/tog/man5", + "/usr/share/man/tog/man5x", + "/usr/share/man/tog/man6", + "/usr/share/man/tog/man6x", + "/usr/share/man/tog/man7", + "/usr/share/man/tog/man7x", + "/usr/share/man/tog/man8", + "/usr/share/man/tog/man8x", + "/usr/share/man/tog/man9", + "/usr/share/man/tog/man9x", + "/usr/share/man/tog/mann", + "/usr/share/man/ton", + "/usr/share/man/ton/man0p", + "/usr/share/man/ton/man1", + "/usr/share/man/ton/man1p", + "/usr/share/man/ton/man1x", + "/usr/share/man/ton/man2", + "/usr/share/man/ton/man2x", + "/usr/share/man/ton/man3", + "/usr/share/man/ton/man3p", + "/usr/share/man/ton/man3x", + "/usr/share/man/ton/man4", + "/usr/share/man/ton/man4x", + "/usr/share/man/ton/man5", + "/usr/share/man/ton/man5x", + "/usr/share/man/ton/man6", + "/usr/share/man/ton/man6x", + "/usr/share/man/ton/man7", + "/usr/share/man/ton/man7x", + "/usr/share/man/ton/man8", + "/usr/share/man/ton/man8x", + "/usr/share/man/ton/man9", + "/usr/share/man/ton/man9x", + "/usr/share/man/ton/mann", + "/usr/share/man/tpi", + "/usr/share/man/tpi/man0p", + "/usr/share/man/tpi/man1", + "/usr/share/man/tpi/man1p", + "/usr/share/man/tpi/man1x", + "/usr/share/man/tpi/man2", + "/usr/share/man/tpi/man2x", + "/usr/share/man/tpi/man3", + "/usr/share/man/tpi/man3p", + "/usr/share/man/tpi/man3x", + "/usr/share/man/tpi/man4", + "/usr/share/man/tpi/man4x", + "/usr/share/man/tpi/man5", + "/usr/share/man/tpi/man5x", + "/usr/share/man/tpi/man6", + "/usr/share/man/tpi/man6x", + "/usr/share/man/tpi/man7", + "/usr/share/man/tpi/man7x", + "/usr/share/man/tpi/man8", + "/usr/share/man/tpi/man8x", + "/usr/share/man/tpi/man9", + "/usr/share/man/tpi/man9x", + "/usr/share/man/tpi/mann", + "/usr/share/man/tr", + "/usr/share/man/tr/man0p", + "/usr/share/man/tr/man1", + "/usr/share/man/tr/man1p", + "/usr/share/man/tr/man1x", + "/usr/share/man/tr/man2", + "/usr/share/man/tr/man2x", + "/usr/share/man/tr/man3", + "/usr/share/man/tr/man3p", + "/usr/share/man/tr/man3x", + "/usr/share/man/tr/man4", + "/usr/share/man/tr/man4x", + "/usr/share/man/tr/man5", + "/usr/share/man/tr/man5x", + "/usr/share/man/tr/man6", + "/usr/share/man/tr/man6x", + "/usr/share/man/tr/man7", + "/usr/share/man/tr/man7x", + "/usr/share/man/tr/man8", + "/usr/share/man/tr/man8x", + "/usr/share/man/tr/man9", + "/usr/share/man/tr/man9x", + "/usr/share/man/tr/mann", + "/usr/share/man/tr_TR", + "/usr/share/man/tr_TR/man0p", + "/usr/share/man/tr_TR/man1", + "/usr/share/man/tr_TR/man1p", + "/usr/share/man/tr_TR/man1x", + "/usr/share/man/tr_TR/man2", + "/usr/share/man/tr_TR/man2x", + "/usr/share/man/tr_TR/man3", + "/usr/share/man/tr_TR/man3p", + "/usr/share/man/tr_TR/man3x", + "/usr/share/man/tr_TR/man4", + "/usr/share/man/tr_TR/man4x", + "/usr/share/man/tr_TR/man5", + "/usr/share/man/tr_TR/man5x", + "/usr/share/man/tr_TR/man6", + "/usr/share/man/tr_TR/man6x", + "/usr/share/man/tr_TR/man7", + "/usr/share/man/tr_TR/man7x", + "/usr/share/man/tr_TR/man8", + "/usr/share/man/tr_TR/man8x", + "/usr/share/man/tr_TR/man9", + "/usr/share/man/tr_TR/man9x", + "/usr/share/man/tr_TR/mann", + "/usr/share/man/ts", + "/usr/share/man/ts/man0p", + "/usr/share/man/ts/man1", + "/usr/share/man/ts/man1p", + "/usr/share/man/ts/man1x", + "/usr/share/man/ts/man2", + "/usr/share/man/ts/man2x", + "/usr/share/man/ts/man3", + "/usr/share/man/ts/man3p", + "/usr/share/man/ts/man3x", + "/usr/share/man/ts/man4", + "/usr/share/man/ts/man4x", + "/usr/share/man/ts/man5", + "/usr/share/man/ts/man5x", + "/usr/share/man/ts/man6", + "/usr/share/man/ts/man6x", + "/usr/share/man/ts/man7", + "/usr/share/man/ts/man7x", + "/usr/share/man/ts/man8", + "/usr/share/man/ts/man8x", + "/usr/share/man/ts/man9", + "/usr/share/man/ts/man9x", + "/usr/share/man/ts/mann", + "/usr/share/man/tsi", + "/usr/share/man/tsi/man0p", + "/usr/share/man/tsi/man1", + "/usr/share/man/tsi/man1p", + "/usr/share/man/tsi/man1x", + "/usr/share/man/tsi/man2", + "/usr/share/man/tsi/man2x", + "/usr/share/man/tsi/man3", + "/usr/share/man/tsi/man3p", + "/usr/share/man/tsi/man3x", + "/usr/share/man/tsi/man4", + "/usr/share/man/tsi/man4x", + "/usr/share/man/tsi/man5", + "/usr/share/man/tsi/man5x", + "/usr/share/man/tsi/man6", + "/usr/share/man/tsi/man6x", + "/usr/share/man/tsi/man7", + "/usr/share/man/tsi/man7x", + "/usr/share/man/tsi/man8", + "/usr/share/man/tsi/man8x", + "/usr/share/man/tsi/man9", + "/usr/share/man/tsi/man9x", + "/usr/share/man/tsi/mann", + "/usr/share/man/tt", + "/usr/share/man/tt/man0p", + "/usr/share/man/tt/man1", + "/usr/share/man/tt/man1p", + "/usr/share/man/tt/man1x", + "/usr/share/man/tt/man2", + "/usr/share/man/tt/man2x", + "/usr/share/man/tt/man3", + "/usr/share/man/tt/man3p", + "/usr/share/man/tt/man3x", + "/usr/share/man/tt/man4", + "/usr/share/man/tt/man4x", + "/usr/share/man/tt/man5", + "/usr/share/man/tt/man5x", + "/usr/share/man/tt/man6", + "/usr/share/man/tt/man6x", + "/usr/share/man/tt/man7", + "/usr/share/man/tt/man7x", + "/usr/share/man/tt/man8", + "/usr/share/man/tt/man8x", + "/usr/share/man/tt/man9", + "/usr/share/man/tt/man9x", + "/usr/share/man/tt/mann", + "/usr/share/man/tt@iqtelif", + "/usr/share/man/tt@iqtelif/man0p", + "/usr/share/man/tt@iqtelif/man1", + "/usr/share/man/tt@iqtelif/man1p", + "/usr/share/man/tt@iqtelif/man1x", + "/usr/share/man/tt@iqtelif/man2", + "/usr/share/man/tt@iqtelif/man2x", + "/usr/share/man/tt@iqtelif/man3", + "/usr/share/man/tt@iqtelif/man3p", + "/usr/share/man/tt@iqtelif/man3x", + "/usr/share/man/tt@iqtelif/man4", + "/usr/share/man/tt@iqtelif/man4x", + "/usr/share/man/tt@iqtelif/man5", + "/usr/share/man/tt@iqtelif/man5x", + "/usr/share/man/tt@iqtelif/man6", + "/usr/share/man/tt@iqtelif/man6x", + "/usr/share/man/tt@iqtelif/man7", + "/usr/share/man/tt@iqtelif/man7x", + "/usr/share/man/tt@iqtelif/man8", + "/usr/share/man/tt@iqtelif/man8x", + "/usr/share/man/tt@iqtelif/man9", + "/usr/share/man/tt@iqtelif/man9x", + "/usr/share/man/tt@iqtelif/mann", + "/usr/share/man/tt_RU", + "/usr/share/man/tt_RU/man0p", + "/usr/share/man/tt_RU/man1", + "/usr/share/man/tt_RU/man1p", + "/usr/share/man/tt_RU/man1x", + "/usr/share/man/tt_RU/man2", + "/usr/share/man/tt_RU/man2x", + "/usr/share/man/tt_RU/man3", + "/usr/share/man/tt_RU/man3p", + "/usr/share/man/tt_RU/man3x", + "/usr/share/man/tt_RU/man4", + "/usr/share/man/tt_RU/man4x", + "/usr/share/man/tt_RU/man5", + "/usr/share/man/tt_RU/man5x", + "/usr/share/man/tt_RU/man6", + "/usr/share/man/tt_RU/man6x", + "/usr/share/man/tt_RU/man7", + "/usr/share/man/tt_RU/man7x", + "/usr/share/man/tt_RU/man8", + "/usr/share/man/tt_RU/man8x", + "/usr/share/man/tt_RU/man9", + "/usr/share/man/tt_RU/man9x", + "/usr/share/man/tt_RU/mann", + "/usr/share/man/tum", + "/usr/share/man/tum/man0p", + "/usr/share/man/tum/man1", + "/usr/share/man/tum/man1p", + "/usr/share/man/tum/man1x", + "/usr/share/man/tum/man2", + "/usr/share/man/tum/man2x", + "/usr/share/man/tum/man3", + "/usr/share/man/tum/man3p", + "/usr/share/man/tum/man3x", + "/usr/share/man/tum/man4", + "/usr/share/man/tum/man4x", + "/usr/share/man/tum/man5", + "/usr/share/man/tum/man5x", + "/usr/share/man/tum/man6", + "/usr/share/man/tum/man6x", + "/usr/share/man/tum/man7", + "/usr/share/man/tum/man7x", + "/usr/share/man/tum/man8", + "/usr/share/man/tum/man8x", + "/usr/share/man/tum/man9", + "/usr/share/man/tum/man9x", + "/usr/share/man/tum/mann", + "/usr/share/man/tup", + "/usr/share/man/tup/man0p", + "/usr/share/man/tup/man1", + "/usr/share/man/tup/man1p", + "/usr/share/man/tup/man1x", + "/usr/share/man/tup/man2", + "/usr/share/man/tup/man2x", + "/usr/share/man/tup/man3", + "/usr/share/man/tup/man3p", + "/usr/share/man/tup/man3x", + "/usr/share/man/tup/man4", + "/usr/share/man/tup/man4x", + "/usr/share/man/tup/man5", + "/usr/share/man/tup/man5x", + "/usr/share/man/tup/man6", + "/usr/share/man/tup/man6x", + "/usr/share/man/tup/man7", + "/usr/share/man/tup/man7x", + "/usr/share/man/tup/man8", + "/usr/share/man/tup/man8x", + "/usr/share/man/tup/man9", + "/usr/share/man/tup/man9x", + "/usr/share/man/tup/mann", + "/usr/share/man/tut", + "/usr/share/man/tut/man0p", + "/usr/share/man/tut/man1", + "/usr/share/man/tut/man1p", + "/usr/share/man/tut/man1x", + "/usr/share/man/tut/man2", + "/usr/share/man/tut/man2x", + "/usr/share/man/tut/man3", + "/usr/share/man/tut/man3p", + "/usr/share/man/tut/man3x", + "/usr/share/man/tut/man4", + "/usr/share/man/tut/man4x", + "/usr/share/man/tut/man5", + "/usr/share/man/tut/man5x", + "/usr/share/man/tut/man6", + "/usr/share/man/tut/man6x", + "/usr/share/man/tut/man7", + "/usr/share/man/tut/man7x", + "/usr/share/man/tut/man8", + "/usr/share/man/tut/man8x", + "/usr/share/man/tut/man9", + "/usr/share/man/tut/man9x", + "/usr/share/man/tut/mann", + "/usr/share/man/tvl", + "/usr/share/man/tvl/man0p", + "/usr/share/man/tvl/man1", + "/usr/share/man/tvl/man1p", + "/usr/share/man/tvl/man1x", + "/usr/share/man/tvl/man2", + "/usr/share/man/tvl/man2x", + "/usr/share/man/tvl/man3", + "/usr/share/man/tvl/man3p", + "/usr/share/man/tvl/man3x", + "/usr/share/man/tvl/man4", + "/usr/share/man/tvl/man4x", + "/usr/share/man/tvl/man5", + "/usr/share/man/tvl/man5x", + "/usr/share/man/tvl/man6", + "/usr/share/man/tvl/man6x", + "/usr/share/man/tvl/man7", + "/usr/share/man/tvl/man7x", + "/usr/share/man/tvl/man8", + "/usr/share/man/tvl/man8x", + "/usr/share/man/tvl/man9", + "/usr/share/man/tvl/man9x", + "/usr/share/man/tvl/mann", + "/usr/share/man/tw", + "/usr/share/man/tw/man0p", + "/usr/share/man/tw/man1", + "/usr/share/man/tw/man1p", + "/usr/share/man/tw/man1x", + "/usr/share/man/tw/man2", + "/usr/share/man/tw/man2x", + "/usr/share/man/tw/man3", + "/usr/share/man/tw/man3p", + "/usr/share/man/tw/man3x", + "/usr/share/man/tw/man4", + "/usr/share/man/tw/man4x", + "/usr/share/man/tw/man5", + "/usr/share/man/tw/man5x", + "/usr/share/man/tw/man6", + "/usr/share/man/tw/man6x", + "/usr/share/man/tw/man7", + "/usr/share/man/tw/man7x", + "/usr/share/man/tw/man8", + "/usr/share/man/tw/man8x", + "/usr/share/man/tw/man9", + "/usr/share/man/tw/man9x", + "/usr/share/man/tw/mann", + "/usr/share/man/ty", + "/usr/share/man/ty/man0p", + "/usr/share/man/ty/man1", + "/usr/share/man/ty/man1p", + "/usr/share/man/ty/man1x", + "/usr/share/man/ty/man2", + "/usr/share/man/ty/man2x", + "/usr/share/man/ty/man3", + "/usr/share/man/ty/man3p", + "/usr/share/man/ty/man3x", + "/usr/share/man/ty/man4", + "/usr/share/man/ty/man4x", + "/usr/share/man/ty/man5", + "/usr/share/man/ty/man5x", + "/usr/share/man/ty/man6", + "/usr/share/man/ty/man6x", + "/usr/share/man/ty/man7", + "/usr/share/man/ty/man7x", + "/usr/share/man/ty/man8", + "/usr/share/man/ty/man8x", + "/usr/share/man/ty/man9", + "/usr/share/man/ty/man9x", + "/usr/share/man/ty/mann", + "/usr/share/man/tyv", + "/usr/share/man/tyv/man0p", + "/usr/share/man/tyv/man1", + "/usr/share/man/tyv/man1p", + "/usr/share/man/tyv/man1x", + "/usr/share/man/tyv/man2", + "/usr/share/man/tyv/man2x", + "/usr/share/man/tyv/man3", + "/usr/share/man/tyv/man3p", + "/usr/share/man/tyv/man3x", + "/usr/share/man/tyv/man4", + "/usr/share/man/tyv/man4x", + "/usr/share/man/tyv/man5", + "/usr/share/man/tyv/man5x", + "/usr/share/man/tyv/man6", + "/usr/share/man/tyv/man6x", + "/usr/share/man/tyv/man7", + "/usr/share/man/tyv/man7x", + "/usr/share/man/tyv/man8", + "/usr/share/man/tyv/man8x", + "/usr/share/man/tyv/man9", + "/usr/share/man/tyv/man9x", + "/usr/share/man/tyv/mann", + "/usr/share/man/tzm", + "/usr/share/man/tzm/man0p", + "/usr/share/man/tzm/man1", + "/usr/share/man/tzm/man1p", + "/usr/share/man/tzm/man1x", + "/usr/share/man/tzm/man2", + "/usr/share/man/tzm/man2x", + "/usr/share/man/tzm/man3", + "/usr/share/man/tzm/man3p", + "/usr/share/man/tzm/man3x", + "/usr/share/man/tzm/man4", + "/usr/share/man/tzm/man4x", + "/usr/share/man/tzm/man5", + "/usr/share/man/tzm/man5x", + "/usr/share/man/tzm/man6", + "/usr/share/man/tzm/man6x", + "/usr/share/man/tzm/man7", + "/usr/share/man/tzm/man7x", + "/usr/share/man/tzm/man8", + "/usr/share/man/tzm/man8x", + "/usr/share/man/tzm/man9", + "/usr/share/man/tzm/man9x", + "/usr/share/man/tzm/mann", + "/usr/share/man/tzo", + "/usr/share/man/tzo/man0p", + "/usr/share/man/tzo/man1", + "/usr/share/man/tzo/man1p", + "/usr/share/man/tzo/man1x", + "/usr/share/man/tzo/man2", + "/usr/share/man/tzo/man2x", + "/usr/share/man/tzo/man3", + "/usr/share/man/tzo/man3p", + "/usr/share/man/tzo/man3x", + "/usr/share/man/tzo/man4", + "/usr/share/man/tzo/man4x", + "/usr/share/man/tzo/man5", + "/usr/share/man/tzo/man5x", + "/usr/share/man/tzo/man6", + "/usr/share/man/tzo/man6x", + "/usr/share/man/tzo/man7", + "/usr/share/man/tzo/man7x", + "/usr/share/man/tzo/man8", + "/usr/share/man/tzo/man8x", + "/usr/share/man/tzo/man9", + "/usr/share/man/tzo/man9x", + "/usr/share/man/tzo/mann", + "/usr/share/man/ua", + "/usr/share/man/ua/man0p", + "/usr/share/man/ua/man1", + "/usr/share/man/ua/man1p", + "/usr/share/man/ua/man1x", + "/usr/share/man/ua/man2", + "/usr/share/man/ua/man2x", + "/usr/share/man/ua/man3", + "/usr/share/man/ua/man3p", + "/usr/share/man/ua/man3x", + "/usr/share/man/ua/man4", + "/usr/share/man/ua/man4x", + "/usr/share/man/ua/man5", + "/usr/share/man/ua/man5x", + "/usr/share/man/ua/man6", + "/usr/share/man/ua/man6x", + "/usr/share/man/ua/man7", + "/usr/share/man/ua/man7x", + "/usr/share/man/ua/man8", + "/usr/share/man/ua/man8x", + "/usr/share/man/ua/man9", + "/usr/share/man/ua/man9x", + "/usr/share/man/ua/mann", + "/usr/share/man/udm", + "/usr/share/man/udm/man0p", + "/usr/share/man/udm/man1", + "/usr/share/man/udm/man1p", + "/usr/share/man/udm/man1x", + "/usr/share/man/udm/man2", + "/usr/share/man/udm/man2x", + "/usr/share/man/udm/man3", + "/usr/share/man/udm/man3p", + "/usr/share/man/udm/man3x", + "/usr/share/man/udm/man4", + "/usr/share/man/udm/man4x", + "/usr/share/man/udm/man5", + "/usr/share/man/udm/man5x", + "/usr/share/man/udm/man6", + "/usr/share/man/udm/man6x", + "/usr/share/man/udm/man7", + "/usr/share/man/udm/man7x", + "/usr/share/man/udm/man8", + "/usr/share/man/udm/man8x", + "/usr/share/man/udm/man9", + "/usr/share/man/udm/man9x", + "/usr/share/man/udm/mann", + "/usr/share/man/ug", + "/usr/share/man/ug/man0p", + "/usr/share/man/ug/man1", + "/usr/share/man/ug/man1p", + "/usr/share/man/ug/man1x", + "/usr/share/man/ug/man2", + "/usr/share/man/ug/man2x", + "/usr/share/man/ug/man3", + "/usr/share/man/ug/man3p", + "/usr/share/man/ug/man3x", + "/usr/share/man/ug/man4", + "/usr/share/man/ug/man4x", + "/usr/share/man/ug/man5", + "/usr/share/man/ug/man5x", + "/usr/share/man/ug/man6", + "/usr/share/man/ug/man6x", + "/usr/share/man/ug/man7", + "/usr/share/man/ug/man7x", + "/usr/share/man/ug/man8", + "/usr/share/man/ug/man8x", + "/usr/share/man/ug/man9", + "/usr/share/man/ug/man9x", + "/usr/share/man/ug/mann", + "/usr/share/man/uga", + "/usr/share/man/uga/man0p", + "/usr/share/man/uga/man1", + "/usr/share/man/uga/man1p", + "/usr/share/man/uga/man1x", + "/usr/share/man/uga/man2", + "/usr/share/man/uga/man2x", + "/usr/share/man/uga/man3", + "/usr/share/man/uga/man3p", + "/usr/share/man/uga/man3x", + "/usr/share/man/uga/man4", + "/usr/share/man/uga/man4x", + "/usr/share/man/uga/man5", + "/usr/share/man/uga/man5x", + "/usr/share/man/uga/man6", + "/usr/share/man/uga/man6x", + "/usr/share/man/uga/man7", + "/usr/share/man/uga/man7x", + "/usr/share/man/uga/man8", + "/usr/share/man/uga/man8x", + "/usr/share/man/uga/man9", + "/usr/share/man/uga/man9x", + "/usr/share/man/uga/mann", + "/usr/share/man/uk", + "/usr/share/man/uk/man0p", + "/usr/share/man/uk/man1", + "/usr/share/man/uk/man1p", + "/usr/share/man/uk/man1x", + "/usr/share/man/uk/man2", + "/usr/share/man/uk/man2x", + "/usr/share/man/uk/man3", + "/usr/share/man/uk/man3p", + "/usr/share/man/uk/man3x", + "/usr/share/man/uk/man4", + "/usr/share/man/uk/man4x", + "/usr/share/man/uk/man5", + "/usr/share/man/uk/man5x", + "/usr/share/man/uk/man6", + "/usr/share/man/uk/man6x", + "/usr/share/man/uk/man7", + "/usr/share/man/uk/man7x", + "/usr/share/man/uk/man8", + "/usr/share/man/uk/man8x", + "/usr/share/man/uk/man9", + "/usr/share/man/uk/man9x", + "/usr/share/man/uk/mann", + "/usr/share/man/uk_UA", + "/usr/share/man/uk_UA/man0p", + "/usr/share/man/uk_UA/man1", + "/usr/share/man/uk_UA/man1p", + "/usr/share/man/uk_UA/man1x", + "/usr/share/man/uk_UA/man2", + "/usr/share/man/uk_UA/man2x", + "/usr/share/man/uk_UA/man3", + "/usr/share/man/uk_UA/man3p", + "/usr/share/man/uk_UA/man3x", + "/usr/share/man/uk_UA/man4", + "/usr/share/man/uk_UA/man4x", + "/usr/share/man/uk_UA/man5", + "/usr/share/man/uk_UA/man5x", + "/usr/share/man/uk_UA/man6", + "/usr/share/man/uk_UA/man6x", + "/usr/share/man/uk_UA/man7", + "/usr/share/man/uk_UA/man7x", + "/usr/share/man/uk_UA/man8", + "/usr/share/man/uk_UA/man8x", + "/usr/share/man/uk_UA/man9", + "/usr/share/man/uk_UA/man9x", + "/usr/share/man/uk_UA/mann", + "/usr/share/man/umb", + "/usr/share/man/umb/man0p", + "/usr/share/man/umb/man1", + "/usr/share/man/umb/man1p", + "/usr/share/man/umb/man1x", + "/usr/share/man/umb/man2", + "/usr/share/man/umb/man2x", + "/usr/share/man/umb/man3", + "/usr/share/man/umb/man3p", + "/usr/share/man/umb/man3x", + "/usr/share/man/umb/man4", + "/usr/share/man/umb/man4x", + "/usr/share/man/umb/man5", + "/usr/share/man/umb/man5x", + "/usr/share/man/umb/man6", + "/usr/share/man/umb/man6x", + "/usr/share/man/umb/man7", + "/usr/share/man/umb/man7x", + "/usr/share/man/umb/man8", + "/usr/share/man/umb/man8x", + "/usr/share/man/umb/man9", + "/usr/share/man/umb/man9x", + "/usr/share/man/umb/mann", + "/usr/share/man/und", + "/usr/share/man/und/man0p", + "/usr/share/man/und/man1", + "/usr/share/man/und/man1p", + "/usr/share/man/und/man1x", + "/usr/share/man/und/man2", + "/usr/share/man/und/man2x", + "/usr/share/man/und/man3", + "/usr/share/man/und/man3p", + "/usr/share/man/und/man3x", + "/usr/share/man/und/man4", + "/usr/share/man/und/man4x", + "/usr/share/man/und/man5", + "/usr/share/man/und/man5x", + "/usr/share/man/und/man6", + "/usr/share/man/und/man6x", + "/usr/share/man/und/man7", + "/usr/share/man/und/man7x", + "/usr/share/man/und/man8", + "/usr/share/man/und/man8x", + "/usr/share/man/und/man9", + "/usr/share/man/und/man9x", + "/usr/share/man/und/mann", + "/usr/share/man/ur", + "/usr/share/man/ur/man0p", + "/usr/share/man/ur/man1", + "/usr/share/man/ur/man1p", + "/usr/share/man/ur/man1x", + "/usr/share/man/ur/man2", + "/usr/share/man/ur/man2x", + "/usr/share/man/ur/man3", + "/usr/share/man/ur/man3p", + "/usr/share/man/ur/man3x", + "/usr/share/man/ur/man4", + "/usr/share/man/ur/man4x", + "/usr/share/man/ur/man5", + "/usr/share/man/ur/man5x", + "/usr/share/man/ur/man6", + "/usr/share/man/ur/man6x", + "/usr/share/man/ur/man7", + "/usr/share/man/ur/man7x", + "/usr/share/man/ur/man8", + "/usr/share/man/ur/man8x", + "/usr/share/man/ur/man9", + "/usr/share/man/ur/man9x", + "/usr/share/man/ur/mann", + "/usr/share/man/ur_PK", + "/usr/share/man/ur_PK/man0p", + "/usr/share/man/ur_PK/man1", + "/usr/share/man/ur_PK/man1p", + "/usr/share/man/ur_PK/man1x", + "/usr/share/man/ur_PK/man2", + "/usr/share/man/ur_PK/man2x", + "/usr/share/man/ur_PK/man3", + "/usr/share/man/ur_PK/man3p", + "/usr/share/man/ur_PK/man3x", + "/usr/share/man/ur_PK/man4", + "/usr/share/man/ur_PK/man4x", + "/usr/share/man/ur_PK/man5", + "/usr/share/man/ur_PK/man5x", + "/usr/share/man/ur_PK/man6", + "/usr/share/man/ur_PK/man6x", + "/usr/share/man/ur_PK/man7", + "/usr/share/man/ur_PK/man7x", + "/usr/share/man/ur_PK/man8", + "/usr/share/man/ur_PK/man8x", + "/usr/share/man/ur_PK/man9", + "/usr/share/man/ur_PK/man9x", + "/usr/share/man/ur_PK/mann", + "/usr/share/man/uz", + "/usr/share/man/uz/man0p", + "/usr/share/man/uz/man1", + "/usr/share/man/uz/man1p", + "/usr/share/man/uz/man1x", + "/usr/share/man/uz/man2", + "/usr/share/man/uz/man2x", + "/usr/share/man/uz/man3", + "/usr/share/man/uz/man3p", + "/usr/share/man/uz/man3x", + "/usr/share/man/uz/man4", + "/usr/share/man/uz/man4x", + "/usr/share/man/uz/man5", + "/usr/share/man/uz/man5x", + "/usr/share/man/uz/man6", + "/usr/share/man/uz/man6x", + "/usr/share/man/uz/man7", + "/usr/share/man/uz/man7x", + "/usr/share/man/uz/man8", + "/usr/share/man/uz/man8x", + "/usr/share/man/uz/man9", + "/usr/share/man/uz/man9x", + "/usr/share/man/uz/mann", + "/usr/share/man/uz@Cyrl", + "/usr/share/man/uz@Cyrl/man0p", + "/usr/share/man/uz@Cyrl/man1", + "/usr/share/man/uz@Cyrl/man1p", + "/usr/share/man/uz@Cyrl/man1x", + "/usr/share/man/uz@Cyrl/man2", + "/usr/share/man/uz@Cyrl/man2x", + "/usr/share/man/uz@Cyrl/man3", + "/usr/share/man/uz@Cyrl/man3p", + "/usr/share/man/uz@Cyrl/man3x", + "/usr/share/man/uz@Cyrl/man4", + "/usr/share/man/uz@Cyrl/man4x", + "/usr/share/man/uz@Cyrl/man5", + "/usr/share/man/uz@Cyrl/man5x", + "/usr/share/man/uz@Cyrl/man6", + "/usr/share/man/uz@Cyrl/man6x", + "/usr/share/man/uz@Cyrl/man7", + "/usr/share/man/uz@Cyrl/man7x", + "/usr/share/man/uz@Cyrl/man8", + "/usr/share/man/uz@Cyrl/man8x", + "/usr/share/man/uz@Cyrl/man9", + "/usr/share/man/uz@Cyrl/man9x", + "/usr/share/man/uz@Cyrl/mann", + "/usr/share/man/uz@Latn", + "/usr/share/man/uz@Latn/man0p", + "/usr/share/man/uz@Latn/man1", + "/usr/share/man/uz@Latn/man1p", + "/usr/share/man/uz@Latn/man1x", + "/usr/share/man/uz@Latn/man2", + "/usr/share/man/uz@Latn/man2x", + "/usr/share/man/uz@Latn/man3", + "/usr/share/man/uz@Latn/man3p", + "/usr/share/man/uz@Latn/man3x", + "/usr/share/man/uz@Latn/man4", + "/usr/share/man/uz@Latn/man4x", + "/usr/share/man/uz@Latn/man5", + "/usr/share/man/uz@Latn/man5x", + "/usr/share/man/uz@Latn/man6", + "/usr/share/man/uz@Latn/man6x", + "/usr/share/man/uz@Latn/man7", + "/usr/share/man/uz@Latn/man7x", + "/usr/share/man/uz@Latn/man8", + "/usr/share/man/uz@Latn/man8x", + "/usr/share/man/uz@Latn/man9", + "/usr/share/man/uz@Latn/man9x", + "/usr/share/man/uz@Latn/mann", + "/usr/share/man/uz@cyrillic", + "/usr/share/man/uz@cyrillic/man0p", + "/usr/share/man/uz@cyrillic/man1", + "/usr/share/man/uz@cyrillic/man1p", + "/usr/share/man/uz@cyrillic/man1x", + "/usr/share/man/uz@cyrillic/man2", + "/usr/share/man/uz@cyrillic/man2x", + "/usr/share/man/uz@cyrillic/man3", + "/usr/share/man/uz@cyrillic/man3p", + "/usr/share/man/uz@cyrillic/man3x", + "/usr/share/man/uz@cyrillic/man4", + "/usr/share/man/uz@cyrillic/man4x", + "/usr/share/man/uz@cyrillic/man5", + "/usr/share/man/uz@cyrillic/man5x", + "/usr/share/man/uz@cyrillic/man6", + "/usr/share/man/uz@cyrillic/man6x", + "/usr/share/man/uz@cyrillic/man7", + "/usr/share/man/uz@cyrillic/man7x", + "/usr/share/man/uz@cyrillic/man8", + "/usr/share/man/uz@cyrillic/man8x", + "/usr/share/man/uz@cyrillic/man9", + "/usr/share/man/uz@cyrillic/man9x", + "/usr/share/man/uz@cyrillic/mann", + "/usr/share/man/vai", + "/usr/share/man/vai/man0p", + "/usr/share/man/vai/man1", + "/usr/share/man/vai/man1p", + "/usr/share/man/vai/man1x", + "/usr/share/man/vai/man2", + "/usr/share/man/vai/man2x", + "/usr/share/man/vai/man3", + "/usr/share/man/vai/man3p", + "/usr/share/man/vai/man3x", + "/usr/share/man/vai/man4", + "/usr/share/man/vai/man4x", + "/usr/share/man/vai/man5", + "/usr/share/man/vai/man5x", + "/usr/share/man/vai/man6", + "/usr/share/man/vai/man6x", + "/usr/share/man/vai/man7", + "/usr/share/man/vai/man7x", + "/usr/share/man/vai/man8", + "/usr/share/man/vai/man8x", + "/usr/share/man/vai/man9", + "/usr/share/man/vai/man9x", + "/usr/share/man/vai/mann", + "/usr/share/man/ve", + "/usr/share/man/ve/man0p", + "/usr/share/man/ve/man1", + "/usr/share/man/ve/man1p", + "/usr/share/man/ve/man1x", + "/usr/share/man/ve/man2", + "/usr/share/man/ve/man2x", + "/usr/share/man/ve/man3", + "/usr/share/man/ve/man3p", + "/usr/share/man/ve/man3x", + "/usr/share/man/ve/man4", + "/usr/share/man/ve/man4x", + "/usr/share/man/ve/man5", + "/usr/share/man/ve/man5x", + "/usr/share/man/ve/man6", + "/usr/share/man/ve/man6x", + "/usr/share/man/ve/man7", + "/usr/share/man/ve/man7x", + "/usr/share/man/ve/man8", + "/usr/share/man/ve/man8x", + "/usr/share/man/ve/man9", + "/usr/share/man/ve/man9x", + "/usr/share/man/ve/mann", + "/usr/share/man/vec", + "/usr/share/man/vec/man0p", + "/usr/share/man/vec/man1", + "/usr/share/man/vec/man1p", + "/usr/share/man/vec/man1x", + "/usr/share/man/vec/man2", + "/usr/share/man/vec/man2x", + "/usr/share/man/vec/man3", + "/usr/share/man/vec/man3p", + "/usr/share/man/vec/man3x", + "/usr/share/man/vec/man4", + "/usr/share/man/vec/man4x", + "/usr/share/man/vec/man5", + "/usr/share/man/vec/man5x", + "/usr/share/man/vec/man6", + "/usr/share/man/vec/man6x", + "/usr/share/man/vec/man7", + "/usr/share/man/vec/man7x", + "/usr/share/man/vec/man8", + "/usr/share/man/vec/man8x", + "/usr/share/man/vec/man9", + "/usr/share/man/vec/man9x", + "/usr/share/man/vec/mann", + "/usr/share/man/ven", + "/usr/share/man/ven/man0p", + "/usr/share/man/ven/man1", + "/usr/share/man/ven/man1p", + "/usr/share/man/ven/man1x", + "/usr/share/man/ven/man2", + "/usr/share/man/ven/man2x", + "/usr/share/man/ven/man3", + "/usr/share/man/ven/man3p", + "/usr/share/man/ven/man3x", + "/usr/share/man/ven/man4", + "/usr/share/man/ven/man4x", + "/usr/share/man/ven/man5", + "/usr/share/man/ven/man5x", + "/usr/share/man/ven/man6", + "/usr/share/man/ven/man6x", + "/usr/share/man/ven/man7", + "/usr/share/man/ven/man7x", + "/usr/share/man/ven/man8", + "/usr/share/man/ven/man8x", + "/usr/share/man/ven/man9", + "/usr/share/man/ven/man9x", + "/usr/share/man/ven/mann", + "/usr/share/man/vi", + "/usr/share/man/vi/man0p", + "/usr/share/man/vi/man1", + "/usr/share/man/vi/man1p", + "/usr/share/man/vi/man1x", + "/usr/share/man/vi/man2", + "/usr/share/man/vi/man2x", + "/usr/share/man/vi/man3", + "/usr/share/man/vi/man3p", + "/usr/share/man/vi/man3x", + "/usr/share/man/vi/man4", + "/usr/share/man/vi/man4x", + "/usr/share/man/vi/man5", + "/usr/share/man/vi/man5x", + "/usr/share/man/vi/man6", + "/usr/share/man/vi/man6x", + "/usr/share/man/vi/man7", + "/usr/share/man/vi/man7x", + "/usr/share/man/vi/man8", + "/usr/share/man/vi/man8x", + "/usr/share/man/vi/man9", + "/usr/share/man/vi/man9x", + "/usr/share/man/vi/mann", + "/usr/share/man/vi_VN", + "/usr/share/man/vi_VN/man0p", + "/usr/share/man/vi_VN/man1", + "/usr/share/man/vi_VN/man1p", + "/usr/share/man/vi_VN/man1x", + "/usr/share/man/vi_VN/man2", + "/usr/share/man/vi_VN/man2x", + "/usr/share/man/vi_VN/man3", + "/usr/share/man/vi_VN/man3p", + "/usr/share/man/vi_VN/man3x", + "/usr/share/man/vi_VN/man4", + "/usr/share/man/vi_VN/man4x", + "/usr/share/man/vi_VN/man5", + "/usr/share/man/vi_VN/man5x", + "/usr/share/man/vi_VN/man6", + "/usr/share/man/vi_VN/man6x", + "/usr/share/man/vi_VN/man7", + "/usr/share/man/vi_VN/man7x", + "/usr/share/man/vi_VN/man8", + "/usr/share/man/vi_VN/man8x", + "/usr/share/man/vi_VN/man9", + "/usr/share/man/vi_VN/man9x", + "/usr/share/man/vi_VN/mann", + "/usr/share/man/vo", + "/usr/share/man/vo/man0p", + "/usr/share/man/vo/man1", + "/usr/share/man/vo/man1p", + "/usr/share/man/vo/man1x", + "/usr/share/man/vo/man2", + "/usr/share/man/vo/man2x", + "/usr/share/man/vo/man3", + "/usr/share/man/vo/man3p", + "/usr/share/man/vo/man3x", + "/usr/share/man/vo/man4", + "/usr/share/man/vo/man4x", + "/usr/share/man/vo/man5", + "/usr/share/man/vo/man5x", + "/usr/share/man/vo/man6", + "/usr/share/man/vo/man6x", + "/usr/share/man/vo/man7", + "/usr/share/man/vo/man7x", + "/usr/share/man/vo/man8", + "/usr/share/man/vo/man8x", + "/usr/share/man/vo/man9", + "/usr/share/man/vo/man9x", + "/usr/share/man/vo/mann", + "/usr/share/man/vot", + "/usr/share/man/vot/man0p", + "/usr/share/man/vot/man1", + "/usr/share/man/vot/man1p", + "/usr/share/man/vot/man1x", + "/usr/share/man/vot/man2", + "/usr/share/man/vot/man2x", + "/usr/share/man/vot/man3", + "/usr/share/man/vot/man3p", + "/usr/share/man/vot/man3x", + "/usr/share/man/vot/man4", + "/usr/share/man/vot/man4x", + "/usr/share/man/vot/man5", + "/usr/share/man/vot/man5x", + "/usr/share/man/vot/man6", + "/usr/share/man/vot/man6x", + "/usr/share/man/vot/man7", + "/usr/share/man/vot/man7x", + "/usr/share/man/vot/man8", + "/usr/share/man/vot/man8x", + "/usr/share/man/vot/man9", + "/usr/share/man/vot/man9x", + "/usr/share/man/vot/mann", + "/usr/share/man/wa", + "/usr/share/man/wa/man0p", + "/usr/share/man/wa/man1", + "/usr/share/man/wa/man1p", + "/usr/share/man/wa/man1x", + "/usr/share/man/wa/man2", + "/usr/share/man/wa/man2x", + "/usr/share/man/wa/man3", + "/usr/share/man/wa/man3p", + "/usr/share/man/wa/man3x", + "/usr/share/man/wa/man4", + "/usr/share/man/wa/man4x", + "/usr/share/man/wa/man5", + "/usr/share/man/wa/man5x", + "/usr/share/man/wa/man6", + "/usr/share/man/wa/man6x", + "/usr/share/man/wa/man7", + "/usr/share/man/wa/man7x", + "/usr/share/man/wa/man8", + "/usr/share/man/wa/man8x", + "/usr/share/man/wa/man9", + "/usr/share/man/wa/man9x", + "/usr/share/man/wa/mann", + "/usr/share/man/wae", + "/usr/share/man/wae/man0p", + "/usr/share/man/wae/man1", + "/usr/share/man/wae/man1p", + "/usr/share/man/wae/man1x", + "/usr/share/man/wae/man2", + "/usr/share/man/wae/man2x", + "/usr/share/man/wae/man3", + "/usr/share/man/wae/man3p", + "/usr/share/man/wae/man3x", + "/usr/share/man/wae/man4", + "/usr/share/man/wae/man4x", + "/usr/share/man/wae/man5", + "/usr/share/man/wae/man5x", + "/usr/share/man/wae/man6", + "/usr/share/man/wae/man6x", + "/usr/share/man/wae/man7", + "/usr/share/man/wae/man7x", + "/usr/share/man/wae/man8", + "/usr/share/man/wae/man8x", + "/usr/share/man/wae/man9", + "/usr/share/man/wae/man9x", + "/usr/share/man/wae/mann", + "/usr/share/man/wak", + "/usr/share/man/wak/man0p", + "/usr/share/man/wak/man1", + "/usr/share/man/wak/man1p", + "/usr/share/man/wak/man1x", + "/usr/share/man/wak/man2", + "/usr/share/man/wak/man2x", + "/usr/share/man/wak/man3", + "/usr/share/man/wak/man3p", + "/usr/share/man/wak/man3x", + "/usr/share/man/wak/man4", + "/usr/share/man/wak/man4x", + "/usr/share/man/wak/man5", + "/usr/share/man/wak/man5x", + "/usr/share/man/wak/man6", + "/usr/share/man/wak/man6x", + "/usr/share/man/wak/man7", + "/usr/share/man/wak/man7x", + "/usr/share/man/wak/man8", + "/usr/share/man/wak/man8x", + "/usr/share/man/wak/man9", + "/usr/share/man/wak/man9x", + "/usr/share/man/wak/mann", + "/usr/share/man/wal", + "/usr/share/man/wal/man0p", + "/usr/share/man/wal/man1", + "/usr/share/man/wal/man1p", + "/usr/share/man/wal/man1x", + "/usr/share/man/wal/man2", + "/usr/share/man/wal/man2x", + "/usr/share/man/wal/man3", + "/usr/share/man/wal/man3p", + "/usr/share/man/wal/man3x", + "/usr/share/man/wal/man4", + "/usr/share/man/wal/man4x", + "/usr/share/man/wal/man5", + "/usr/share/man/wal/man5x", + "/usr/share/man/wal/man6", + "/usr/share/man/wal/man6x", + "/usr/share/man/wal/man7", + "/usr/share/man/wal/man7x", + "/usr/share/man/wal/man8", + "/usr/share/man/wal/man8x", + "/usr/share/man/wal/man9", + "/usr/share/man/wal/man9x", + "/usr/share/man/wal/mann", + "/usr/share/man/war", + "/usr/share/man/war/man0p", + "/usr/share/man/war/man1", + "/usr/share/man/war/man1p", + "/usr/share/man/war/man1x", + "/usr/share/man/war/man2", + "/usr/share/man/war/man2x", + "/usr/share/man/war/man3", + "/usr/share/man/war/man3p", + "/usr/share/man/war/man3x", + "/usr/share/man/war/man4", + "/usr/share/man/war/man4x", + "/usr/share/man/war/man5", + "/usr/share/man/war/man5x", + "/usr/share/man/war/man6", + "/usr/share/man/war/man6x", + "/usr/share/man/war/man7", + "/usr/share/man/war/man7x", + "/usr/share/man/war/man8", + "/usr/share/man/war/man8x", + "/usr/share/man/war/man9", + "/usr/share/man/war/man9x", + "/usr/share/man/war/mann", + "/usr/share/man/was", + "/usr/share/man/was/man0p", + "/usr/share/man/was/man1", + "/usr/share/man/was/man1p", + "/usr/share/man/was/man1x", + "/usr/share/man/was/man2", + "/usr/share/man/was/man2x", + "/usr/share/man/was/man3", + "/usr/share/man/was/man3p", + "/usr/share/man/was/man3x", + "/usr/share/man/was/man4", + "/usr/share/man/was/man4x", + "/usr/share/man/was/man5", + "/usr/share/man/was/man5x", + "/usr/share/man/was/man6", + "/usr/share/man/was/man6x", + "/usr/share/man/was/man7", + "/usr/share/man/was/man7x", + "/usr/share/man/was/man8", + "/usr/share/man/was/man8x", + "/usr/share/man/was/man9", + "/usr/share/man/was/man9x", + "/usr/share/man/was/mann", + "/usr/share/man/wba", + "/usr/share/man/wba/man0p", + "/usr/share/man/wba/man1", + "/usr/share/man/wba/man1p", + "/usr/share/man/wba/man1x", + "/usr/share/man/wba/man2", + "/usr/share/man/wba/man2x", + "/usr/share/man/wba/man3", + "/usr/share/man/wba/man3p", + "/usr/share/man/wba/man3x", + "/usr/share/man/wba/man4", + "/usr/share/man/wba/man4x", + "/usr/share/man/wba/man5", + "/usr/share/man/wba/man5x", + "/usr/share/man/wba/man6", + "/usr/share/man/wba/man6x", + "/usr/share/man/wba/man7", + "/usr/share/man/wba/man7x", + "/usr/share/man/wba/man8", + "/usr/share/man/wba/man8x", + "/usr/share/man/wba/man9", + "/usr/share/man/wba/man9x", + "/usr/share/man/wba/mann", + "/usr/share/man/wen", + "/usr/share/man/wen/man0p", + "/usr/share/man/wen/man1", + "/usr/share/man/wen/man1p", + "/usr/share/man/wen/man1x", + "/usr/share/man/wen/man2", + "/usr/share/man/wen/man2x", + "/usr/share/man/wen/man3", + "/usr/share/man/wen/man3p", + "/usr/share/man/wen/man3x", + "/usr/share/man/wen/man4", + "/usr/share/man/wen/man4x", + "/usr/share/man/wen/man5", + "/usr/share/man/wen/man5x", + "/usr/share/man/wen/man6", + "/usr/share/man/wen/man6x", + "/usr/share/man/wen/man7", + "/usr/share/man/wen/man7x", + "/usr/share/man/wen/man8", + "/usr/share/man/wen/man8x", + "/usr/share/man/wen/man9", + "/usr/share/man/wen/man9x", + "/usr/share/man/wen/mann", + "/usr/share/man/wo", + "/usr/share/man/wo/man0p", + "/usr/share/man/wo/man1", + "/usr/share/man/wo/man1p", + "/usr/share/man/wo/man1x", + "/usr/share/man/wo/man2", + "/usr/share/man/wo/man2x", + "/usr/share/man/wo/man3", + "/usr/share/man/wo/man3p", + "/usr/share/man/wo/man3x", + "/usr/share/man/wo/man4", + "/usr/share/man/wo/man4x", + "/usr/share/man/wo/man5", + "/usr/share/man/wo/man5x", + "/usr/share/man/wo/man6", + "/usr/share/man/wo/man6x", + "/usr/share/man/wo/man7", + "/usr/share/man/wo/man7x", + "/usr/share/man/wo/man8", + "/usr/share/man/wo/man8x", + "/usr/share/man/wo/man9", + "/usr/share/man/wo/man9x", + "/usr/share/man/wo/mann", + "/usr/share/man/xal", + "/usr/share/man/xal/man0p", + "/usr/share/man/xal/man1", + "/usr/share/man/xal/man1p", + "/usr/share/man/xal/man1x", + "/usr/share/man/xal/man2", + "/usr/share/man/xal/man2x", + "/usr/share/man/xal/man3", + "/usr/share/man/xal/man3p", + "/usr/share/man/xal/man3x", + "/usr/share/man/xal/man4", + "/usr/share/man/xal/man4x", + "/usr/share/man/xal/man5", + "/usr/share/man/xal/man5x", + "/usr/share/man/xal/man6", + "/usr/share/man/xal/man6x", + "/usr/share/man/xal/man7", + "/usr/share/man/xal/man7x", + "/usr/share/man/xal/man8", + "/usr/share/man/xal/man8x", + "/usr/share/man/xal/man9", + "/usr/share/man/xal/man9x", + "/usr/share/man/xal/mann", + "/usr/share/man/xh", + "/usr/share/man/xh/man0p", + "/usr/share/man/xh/man1", + "/usr/share/man/xh/man1p", + "/usr/share/man/xh/man1x", + "/usr/share/man/xh/man2", + "/usr/share/man/xh/man2x", + "/usr/share/man/xh/man3", + "/usr/share/man/xh/man3p", + "/usr/share/man/xh/man3x", + "/usr/share/man/xh/man4", + "/usr/share/man/xh/man4x", + "/usr/share/man/xh/man5", + "/usr/share/man/xh/man5x", + "/usr/share/man/xh/man6", + "/usr/share/man/xh/man6x", + "/usr/share/man/xh/man7", + "/usr/share/man/xh/man7x", + "/usr/share/man/xh/man8", + "/usr/share/man/xh/man8x", + "/usr/share/man/xh/man9", + "/usr/share/man/xh/man9x", + "/usr/share/man/xh/mann", + "/usr/share/man/yao", + "/usr/share/man/yao/man0p", + "/usr/share/man/yao/man1", + "/usr/share/man/yao/man1p", + "/usr/share/man/yao/man1x", + "/usr/share/man/yao/man2", + "/usr/share/man/yao/man2x", + "/usr/share/man/yao/man3", + "/usr/share/man/yao/man3p", + "/usr/share/man/yao/man3x", + "/usr/share/man/yao/man4", + "/usr/share/man/yao/man4x", + "/usr/share/man/yao/man5", + "/usr/share/man/yao/man5x", + "/usr/share/man/yao/man6", + "/usr/share/man/yao/man6x", + "/usr/share/man/yao/man7", + "/usr/share/man/yao/man7x", + "/usr/share/man/yao/man8", + "/usr/share/man/yao/man8x", + "/usr/share/man/yao/man9", + "/usr/share/man/yao/man9x", + "/usr/share/man/yao/mann", + "/usr/share/man/yap", + "/usr/share/man/yap/man0p", + "/usr/share/man/yap/man1", + "/usr/share/man/yap/man1p", + "/usr/share/man/yap/man1x", + "/usr/share/man/yap/man2", + "/usr/share/man/yap/man2x", + "/usr/share/man/yap/man3", + "/usr/share/man/yap/man3p", + "/usr/share/man/yap/man3x", + "/usr/share/man/yap/man4", + "/usr/share/man/yap/man4x", + "/usr/share/man/yap/man5", + "/usr/share/man/yap/man5x", + "/usr/share/man/yap/man6", + "/usr/share/man/yap/man6x", + "/usr/share/man/yap/man7", + "/usr/share/man/yap/man7x", + "/usr/share/man/yap/man8", + "/usr/share/man/yap/man8x", + "/usr/share/man/yap/man9", + "/usr/share/man/yap/man9x", + "/usr/share/man/yap/mann", + "/usr/share/man/yi", + "/usr/share/man/yi/man0p", + "/usr/share/man/yi/man1", + "/usr/share/man/yi/man1p", + "/usr/share/man/yi/man1x", + "/usr/share/man/yi/man2", + "/usr/share/man/yi/man2x", + "/usr/share/man/yi/man3", + "/usr/share/man/yi/man3p", + "/usr/share/man/yi/man3x", + "/usr/share/man/yi/man4", + "/usr/share/man/yi/man4x", + "/usr/share/man/yi/man5", + "/usr/share/man/yi/man5x", + "/usr/share/man/yi/man6", + "/usr/share/man/yi/man6x", + "/usr/share/man/yi/man7", + "/usr/share/man/yi/man7x", + "/usr/share/man/yi/man8", + "/usr/share/man/yi/man8x", + "/usr/share/man/yi/man9", + "/usr/share/man/yi/man9x", + "/usr/share/man/yi/mann", + "/usr/share/man/yo", + "/usr/share/man/yo/man0p", + "/usr/share/man/yo/man1", + "/usr/share/man/yo/man1p", + "/usr/share/man/yo/man1x", + "/usr/share/man/yo/man2", + "/usr/share/man/yo/man2x", + "/usr/share/man/yo/man3", + "/usr/share/man/yo/man3p", + "/usr/share/man/yo/man3x", + "/usr/share/man/yo/man4", + "/usr/share/man/yo/man4x", + "/usr/share/man/yo/man5", + "/usr/share/man/yo/man5x", + "/usr/share/man/yo/man6", + "/usr/share/man/yo/man6x", + "/usr/share/man/yo/man7", + "/usr/share/man/yo/man7x", + "/usr/share/man/yo/man8", + "/usr/share/man/yo/man8x", + "/usr/share/man/yo/man9", + "/usr/share/man/yo/man9x", + "/usr/share/man/yo/mann", + "/usr/share/man/ypk", + "/usr/share/man/ypk/man0p", + "/usr/share/man/ypk/man1", + "/usr/share/man/ypk/man1p", + "/usr/share/man/ypk/man1x", + "/usr/share/man/ypk/man2", + "/usr/share/man/ypk/man2x", + "/usr/share/man/ypk/man3", + "/usr/share/man/ypk/man3p", + "/usr/share/man/ypk/man3x", + "/usr/share/man/ypk/man4", + "/usr/share/man/ypk/man4x", + "/usr/share/man/ypk/man5", + "/usr/share/man/ypk/man5x", + "/usr/share/man/ypk/man6", + "/usr/share/man/ypk/man6x", + "/usr/share/man/ypk/man7", + "/usr/share/man/ypk/man7x", + "/usr/share/man/ypk/man8", + "/usr/share/man/ypk/man8x", + "/usr/share/man/ypk/man9", + "/usr/share/man/ypk/man9x", + "/usr/share/man/ypk/mann", + "/usr/share/man/za", + "/usr/share/man/za/man0p", + "/usr/share/man/za/man1", + "/usr/share/man/za/man1p", + "/usr/share/man/za/man1x", + "/usr/share/man/za/man2", + "/usr/share/man/za/man2x", + "/usr/share/man/za/man3", + "/usr/share/man/za/man3p", + "/usr/share/man/za/man3x", + "/usr/share/man/za/man4", + "/usr/share/man/za/man4x", + "/usr/share/man/za/man5", + "/usr/share/man/za/man5x", + "/usr/share/man/za/man6", + "/usr/share/man/za/man6x", + "/usr/share/man/za/man7", + "/usr/share/man/za/man7x", + "/usr/share/man/za/man8", + "/usr/share/man/za/man8x", + "/usr/share/man/za/man9", + "/usr/share/man/za/man9x", + "/usr/share/man/za/mann", + "/usr/share/man/zam", + "/usr/share/man/zam/man0p", + "/usr/share/man/zam/man1", + "/usr/share/man/zam/man1p", + "/usr/share/man/zam/man1x", + "/usr/share/man/zam/man2", + "/usr/share/man/zam/man2x", + "/usr/share/man/zam/man3", + "/usr/share/man/zam/man3p", + "/usr/share/man/zam/man3x", + "/usr/share/man/zam/man4", + "/usr/share/man/zam/man4x", + "/usr/share/man/zam/man5", + "/usr/share/man/zam/man5x", + "/usr/share/man/zam/man6", + "/usr/share/man/zam/man6x", + "/usr/share/man/zam/man7", + "/usr/share/man/zam/man7x", + "/usr/share/man/zam/man8", + "/usr/share/man/zam/man8x", + "/usr/share/man/zam/man9", + "/usr/share/man/zam/man9x", + "/usr/share/man/zam/mann", + "/usr/share/man/zap", + "/usr/share/man/zap/man0p", + "/usr/share/man/zap/man1", + "/usr/share/man/zap/man1p", + "/usr/share/man/zap/man1x", + "/usr/share/man/zap/man2", + "/usr/share/man/zap/man2x", + "/usr/share/man/zap/man3", + "/usr/share/man/zap/man3p", + "/usr/share/man/zap/man3x", + "/usr/share/man/zap/man4", + "/usr/share/man/zap/man4x", + "/usr/share/man/zap/man5", + "/usr/share/man/zap/man5x", + "/usr/share/man/zap/man6", + "/usr/share/man/zap/man6x", + "/usr/share/man/zap/man7", + "/usr/share/man/zap/man7x", + "/usr/share/man/zap/man8", + "/usr/share/man/zap/man8x", + "/usr/share/man/zap/man9", + "/usr/share/man/zap/man9x", + "/usr/share/man/zap/mann", + "/usr/share/man/zbl", + "/usr/share/man/zbl/man0p", + "/usr/share/man/zbl/man1", + "/usr/share/man/zbl/man1p", + "/usr/share/man/zbl/man1x", + "/usr/share/man/zbl/man2", + "/usr/share/man/zbl/man2x", + "/usr/share/man/zbl/man3", + "/usr/share/man/zbl/man3p", + "/usr/share/man/zbl/man3x", + "/usr/share/man/zbl/man4", + "/usr/share/man/zbl/man4x", + "/usr/share/man/zbl/man5", + "/usr/share/man/zbl/man5x", + "/usr/share/man/zbl/man6", + "/usr/share/man/zbl/man6x", + "/usr/share/man/zbl/man7", + "/usr/share/man/zbl/man7x", + "/usr/share/man/zbl/man8", + "/usr/share/man/zbl/man8x", + "/usr/share/man/zbl/man9", + "/usr/share/man/zbl/man9x", + "/usr/share/man/zbl/mann", + "/usr/share/man/zen", + "/usr/share/man/zen/man0p", + "/usr/share/man/zen/man1", + "/usr/share/man/zen/man1p", + "/usr/share/man/zen/man1x", + "/usr/share/man/zen/man2", + "/usr/share/man/zen/man2x", + "/usr/share/man/zen/man3", + "/usr/share/man/zen/man3p", + "/usr/share/man/zen/man3x", + "/usr/share/man/zen/man4", + "/usr/share/man/zen/man4x", + "/usr/share/man/zen/man5", + "/usr/share/man/zen/man5x", + "/usr/share/man/zen/man6", + "/usr/share/man/zen/man6x", + "/usr/share/man/zen/man7", + "/usr/share/man/zen/man7x", + "/usr/share/man/zen/man8", + "/usr/share/man/zen/man8x", + "/usr/share/man/zen/man9", + "/usr/share/man/zen/man9x", + "/usr/share/man/zen/mann", + "/usr/share/man/zgh", + "/usr/share/man/zgh/man0p", + "/usr/share/man/zgh/man1", + "/usr/share/man/zgh/man1p", + "/usr/share/man/zgh/man1x", + "/usr/share/man/zgh/man2", + "/usr/share/man/zgh/man2x", + "/usr/share/man/zgh/man3", + "/usr/share/man/zgh/man3p", + "/usr/share/man/zgh/man3x", + "/usr/share/man/zgh/man4", + "/usr/share/man/zgh/man4x", + "/usr/share/man/zgh/man5", + "/usr/share/man/zgh/man5x", + "/usr/share/man/zgh/man6", + "/usr/share/man/zgh/man6x", + "/usr/share/man/zgh/man7", + "/usr/share/man/zgh/man7x", + "/usr/share/man/zgh/man8", + "/usr/share/man/zgh/man8x", + "/usr/share/man/zgh/man9", + "/usr/share/man/zgh/man9x", + "/usr/share/man/zgh/mann", + "/usr/share/man/zh", + "/usr/share/man/zh-Hans", + "/usr/share/man/zh-Hans/man0p", + "/usr/share/man/zh-Hans/man1", + "/usr/share/man/zh-Hans/man1p", + "/usr/share/man/zh-Hans/man1x", + "/usr/share/man/zh-Hans/man2", + "/usr/share/man/zh-Hans/man2x", + "/usr/share/man/zh-Hans/man3", + "/usr/share/man/zh-Hans/man3p", + "/usr/share/man/zh-Hans/man3x", + "/usr/share/man/zh-Hans/man4", + "/usr/share/man/zh-Hans/man4x", + "/usr/share/man/zh-Hans/man5", + "/usr/share/man/zh-Hans/man5x", + "/usr/share/man/zh-Hans/man6", + "/usr/share/man/zh-Hans/man6x", + "/usr/share/man/zh-Hans/man7", + "/usr/share/man/zh-Hans/man7x", + "/usr/share/man/zh-Hans/man8", + "/usr/share/man/zh-Hans/man8x", + "/usr/share/man/zh-Hans/man9", + "/usr/share/man/zh-Hans/man9x", + "/usr/share/man/zh-Hans/mann", + "/usr/share/man/zh-Hant", + "/usr/share/man/zh-Hant/man0p", + "/usr/share/man/zh-Hant/man1", + "/usr/share/man/zh-Hant/man1p", + "/usr/share/man/zh-Hant/man1x", + "/usr/share/man/zh-Hant/man2", + "/usr/share/man/zh-Hant/man2x", + "/usr/share/man/zh-Hant/man3", + "/usr/share/man/zh-Hant/man3p", + "/usr/share/man/zh-Hant/man3x", + "/usr/share/man/zh-Hant/man4", + "/usr/share/man/zh-Hant/man4x", + "/usr/share/man/zh-Hant/man5", + "/usr/share/man/zh-Hant/man5x", + "/usr/share/man/zh-Hant/man6", + "/usr/share/man/zh-Hant/man6x", + "/usr/share/man/zh-Hant/man7", + "/usr/share/man/zh-Hant/man7x", + "/usr/share/man/zh-Hant/man8", + "/usr/share/man/zh-Hant/man8x", + "/usr/share/man/zh-Hant/man9", + "/usr/share/man/zh-Hant/man9x", + "/usr/share/man/zh-Hant/mann", + "/usr/share/man/zh/man0p", + "/usr/share/man/zh/man1", + "/usr/share/man/zh/man1p", + "/usr/share/man/zh/man1x", + "/usr/share/man/zh/man2", + "/usr/share/man/zh/man2x", + "/usr/share/man/zh/man3", + "/usr/share/man/zh/man3p", + "/usr/share/man/zh/man3x", + "/usr/share/man/zh/man4", + "/usr/share/man/zh/man4x", + "/usr/share/man/zh/man5", + "/usr/share/man/zh/man5x", + "/usr/share/man/zh/man6", + "/usr/share/man/zh/man6x", + "/usr/share/man/zh/man7", + "/usr/share/man/zh/man7x", + "/usr/share/man/zh/man8", + "/usr/share/man/zh/man8x", + "/usr/share/man/zh/man9", + "/usr/share/man/zh/man9x", + "/usr/share/man/zh/mann", + "/usr/share/man/zh_CN", + "/usr/share/man/zh_CN.GB2312", + "/usr/share/man/zh_CN.GB2312/man0p", + "/usr/share/man/zh_CN.GB2312/man1", + "/usr/share/man/zh_CN.GB2312/man1p", + "/usr/share/man/zh_CN.GB2312/man1x", + "/usr/share/man/zh_CN.GB2312/man2", + "/usr/share/man/zh_CN.GB2312/man2x", + "/usr/share/man/zh_CN.GB2312/man3", + "/usr/share/man/zh_CN.GB2312/man3p", + "/usr/share/man/zh_CN.GB2312/man3x", + "/usr/share/man/zh_CN.GB2312/man4", + "/usr/share/man/zh_CN.GB2312/man4x", + "/usr/share/man/zh_CN.GB2312/man5", + "/usr/share/man/zh_CN.GB2312/man5x", + "/usr/share/man/zh_CN.GB2312/man6", + "/usr/share/man/zh_CN.GB2312/man6x", + "/usr/share/man/zh_CN.GB2312/man7", + "/usr/share/man/zh_CN.GB2312/man7x", + "/usr/share/man/zh_CN.GB2312/man8", + "/usr/share/man/zh_CN.GB2312/man8x", + "/usr/share/man/zh_CN.GB2312/man9", + "/usr/share/man/zh_CN.GB2312/man9x", + "/usr/share/man/zh_CN.GB2312/mann", + "/usr/share/man/zh_CN/man0p", + "/usr/share/man/zh_CN/man1", + "/usr/share/man/zh_CN/man1p", + "/usr/share/man/zh_CN/man1x", + "/usr/share/man/zh_CN/man2", + "/usr/share/man/zh_CN/man2x", + "/usr/share/man/zh_CN/man3", + "/usr/share/man/zh_CN/man3p", + "/usr/share/man/zh_CN/man3x", + "/usr/share/man/zh_CN/man4", + "/usr/share/man/zh_CN/man4x", + "/usr/share/man/zh_CN/man5", + "/usr/share/man/zh_CN/man5x", + "/usr/share/man/zh_CN/man6", + "/usr/share/man/zh_CN/man6x", + "/usr/share/man/zh_CN/man7", + "/usr/share/man/zh_CN/man7x", + "/usr/share/man/zh_CN/man8", + "/usr/share/man/zh_CN/man8x", + "/usr/share/man/zh_CN/man9", + "/usr/share/man/zh_CN/man9x", + "/usr/share/man/zh_CN/mann", + "/usr/share/man/zh_HK", + "/usr/share/man/zh_HK/man0p", + "/usr/share/man/zh_HK/man1", + "/usr/share/man/zh_HK/man1p", + "/usr/share/man/zh_HK/man1x", + "/usr/share/man/zh_HK/man2", + "/usr/share/man/zh_HK/man2x", + "/usr/share/man/zh_HK/man3", + "/usr/share/man/zh_HK/man3p", + "/usr/share/man/zh_HK/man3x", + "/usr/share/man/zh_HK/man4", + "/usr/share/man/zh_HK/man4x", + "/usr/share/man/zh_HK/man5", + "/usr/share/man/zh_HK/man5x", + "/usr/share/man/zh_HK/man6", + "/usr/share/man/zh_HK/man6x", + "/usr/share/man/zh_HK/man7", + "/usr/share/man/zh_HK/man7x", + "/usr/share/man/zh_HK/man8", + "/usr/share/man/zh_HK/man8x", + "/usr/share/man/zh_HK/man9", + "/usr/share/man/zh_HK/man9x", + "/usr/share/man/zh_HK/mann", + "/usr/share/man/zh_TW", + "/usr/share/man/zh_TW.Big5", + "/usr/share/man/zh_TW.Big5/man0p", + "/usr/share/man/zh_TW.Big5/man1", + "/usr/share/man/zh_TW.Big5/man1p", + "/usr/share/man/zh_TW.Big5/man1x", + "/usr/share/man/zh_TW.Big5/man2", + "/usr/share/man/zh_TW.Big5/man2x", + "/usr/share/man/zh_TW.Big5/man3", + "/usr/share/man/zh_TW.Big5/man3p", + "/usr/share/man/zh_TW.Big5/man3x", + "/usr/share/man/zh_TW.Big5/man4", + "/usr/share/man/zh_TW.Big5/man4x", + "/usr/share/man/zh_TW.Big5/man5", + "/usr/share/man/zh_TW.Big5/man5x", + "/usr/share/man/zh_TW.Big5/man6", + "/usr/share/man/zh_TW.Big5/man6x", + "/usr/share/man/zh_TW.Big5/man7", + "/usr/share/man/zh_TW.Big5/man7x", + "/usr/share/man/zh_TW.Big5/man8", + "/usr/share/man/zh_TW.Big5/man8x", + "/usr/share/man/zh_TW.Big5/man9", + "/usr/share/man/zh_TW.Big5/man9x", + "/usr/share/man/zh_TW.Big5/mann", + "/usr/share/man/zh_TW/man0p", + "/usr/share/man/zh_TW/man1", + "/usr/share/man/zh_TW/man1p", + "/usr/share/man/zh_TW/man1x", + "/usr/share/man/zh_TW/man2", + "/usr/share/man/zh_TW/man2x", + "/usr/share/man/zh_TW/man3", + "/usr/share/man/zh_TW/man3p", + "/usr/share/man/zh_TW/man3x", + "/usr/share/man/zh_TW/man4", + "/usr/share/man/zh_TW/man4x", + "/usr/share/man/zh_TW/man5", + "/usr/share/man/zh_TW/man5x", + "/usr/share/man/zh_TW/man6", + "/usr/share/man/zh_TW/man6x", + "/usr/share/man/zh_TW/man7", + "/usr/share/man/zh_TW/man7x", + "/usr/share/man/zh_TW/man8", + "/usr/share/man/zh_TW/man8x", + "/usr/share/man/zh_TW/man9", + "/usr/share/man/zh_TW/man9x", + "/usr/share/man/zh_TW/mann", + "/usr/share/man/znd", + "/usr/share/man/znd/man0p", + "/usr/share/man/znd/man1", + "/usr/share/man/znd/man1p", + "/usr/share/man/znd/man1x", + "/usr/share/man/znd/man2", + "/usr/share/man/znd/man2x", + "/usr/share/man/znd/man3", + "/usr/share/man/znd/man3p", + "/usr/share/man/znd/man3x", + "/usr/share/man/znd/man4", + "/usr/share/man/znd/man4x", + "/usr/share/man/znd/man5", + "/usr/share/man/znd/man5x", + "/usr/share/man/znd/man6", + "/usr/share/man/znd/man6x", + "/usr/share/man/znd/man7", + "/usr/share/man/znd/man7x", + "/usr/share/man/znd/man8", + "/usr/share/man/znd/man8x", + "/usr/share/man/znd/man9", + "/usr/share/man/znd/man9x", + "/usr/share/man/znd/mann", + "/usr/share/man/zu", + "/usr/share/man/zu/man0p", + "/usr/share/man/zu/man1", + "/usr/share/man/zu/man1p", + "/usr/share/man/zu/man1x", + "/usr/share/man/zu/man2", + "/usr/share/man/zu/man2x", + "/usr/share/man/zu/man3", + "/usr/share/man/zu/man3p", + "/usr/share/man/zu/man3x", + "/usr/share/man/zu/man4", + "/usr/share/man/zu/man4x", + "/usr/share/man/zu/man5", + "/usr/share/man/zu/man5x", + "/usr/share/man/zu/man6", + "/usr/share/man/zu/man6x", + "/usr/share/man/zu/man7", + "/usr/share/man/zu/man7x", + "/usr/share/man/zu/man8", + "/usr/share/man/zu/man8x", + "/usr/share/man/zu/man9", + "/usr/share/man/zu/man9x", + "/usr/share/man/zu/mann", + "/usr/share/man/zun", + "/usr/share/man/zun/man0p", + "/usr/share/man/zun/man1", + "/usr/share/man/zun/man1p", + "/usr/share/man/zun/man1x", + "/usr/share/man/zun/man2", + "/usr/share/man/zun/man2x", + "/usr/share/man/zun/man3", + "/usr/share/man/zun/man3p", + "/usr/share/man/zun/man3x", + "/usr/share/man/zun/man4", + "/usr/share/man/zun/man4x", + "/usr/share/man/zun/man5", + "/usr/share/man/zun/man5x", + "/usr/share/man/zun/man6", + "/usr/share/man/zun/man6x", + "/usr/share/man/zun/man7", + "/usr/share/man/zun/man7x", + "/usr/share/man/zun/man8", + "/usr/share/man/zun/man8x", + "/usr/share/man/zun/man9", + "/usr/share/man/zun/man9x", + "/usr/share/man/zun/mann", + "/usr/share/man/zxx", + "/usr/share/man/zxx/man0p", + "/usr/share/man/zxx/man1", + "/usr/share/man/zxx/man1p", + "/usr/share/man/zxx/man1x", + "/usr/share/man/zxx/man2", + "/usr/share/man/zxx/man2x", + "/usr/share/man/zxx/man3", + "/usr/share/man/zxx/man3p", + "/usr/share/man/zxx/man3x", + "/usr/share/man/zxx/man4", + "/usr/share/man/zxx/man4x", + "/usr/share/man/zxx/man5", + "/usr/share/man/zxx/man5x", + "/usr/share/man/zxx/man6", + "/usr/share/man/zxx/man6x", + "/usr/share/man/zxx/man7", + "/usr/share/man/zxx/man7x", + "/usr/share/man/zxx/man8", + "/usr/share/man/zxx/man8x", + "/usr/share/man/zxx/man9", + "/usr/share/man/zxx/man9x", + "/usr/share/man/zxx/mann", + "/usr/share/man/zza", + "/usr/share/man/zza/man0p", + "/usr/share/man/zza/man1", + "/usr/share/man/zza/man1p", + "/usr/share/man/zza/man1x", + "/usr/share/man/zza/man2", + "/usr/share/man/zza/man2x", + "/usr/share/man/zza/man3", + "/usr/share/man/zza/man3p", + "/usr/share/man/zza/man3x", + "/usr/share/man/zza/man4", + "/usr/share/man/zza/man4x", + "/usr/share/man/zza/man5", + "/usr/share/man/zza/man5x", + "/usr/share/man/zza/man6", + "/usr/share/man/zza/man6x", + "/usr/share/man/zza/man7", + "/usr/share/man/zza/man7x", + "/usr/share/man/zza/man8", + "/usr/share/man/zza/man8x", + "/usr/share/man/zza/man9", + "/usr/share/man/zza/man9x", + "/usr/share/man/zza/mann", + "/usr/share/metainfo", + "/usr/share/mime-info", + "/usr/share/misc", + "/usr/share/omf", + "/usr/share/pixmaps", + "/usr/share/sounds", + "/usr/share/themes", + "/usr/share/wayland-sessions", + "/usr/share/xsessions", + "/usr/share/zsh", + "/usr/share/zsh/site-functions", + "/usr/src", + "/usr/src/debug", + "/usr/src/kernels", + "/usr/tmp", + "/var", + "/var/adm", + "/var/cache", + "/var/cache/bpf", + "/var/db", + "/var/empty", + "/var/ftp", + "/var/games", + "/var/lib", + "/var/lib/games", + "/var/lib/misc", + "/var/lib/rpm-state", + "/var/local", + "/var/lock", + "/var/log", + "/var/mail", + "/var/nis", + "/var/opt", + "/var/preserve", + "/var/run", + "/var/spool", + "/var/spool/lpd", + "/var/spool/mail", + "/var/tmp", + "/var/yp" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "glibc@2.34-125.el9_5.3.x86_64", + "Name": "glibc", + "Identifier": { + "PURL": "pkg:rpm/redhat/glibc@2.34-125.el9_5.3?arch=x86_64\u0026distro=redhat-9.5", + "UID": "6af75572d26dfeb6" + }, + "Version": "2.34", + "Release": "125.el9_5.3", + "Arch": "x86_64", + "SrcName": "glibc", + "SrcVersion": "2.34", + "SrcRelease": "125.el9_5.3", + "Licenses": [ + "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "basesystem@11-13.el9.noarch", + "glibc-common@2.34-125.el9_5.3.x86_64", + "glibc-minimal-langpack@2.34-125.el9_5.3.x86_64", + "libgcc@11.5.0-5.el9_5.x86_64" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:3e1ce35077963fc222236de3c47db893", + "InstalledFiles": [ + "/etc/gai.conf", + "/etc/ld.so.cache", + "/etc/ld.so.conf", + "/etc/ld.so.conf.d", + "/etc/nsswitch.conf", + "/etc/rpc", + "/lib64/ld-linux-x86-64.so.2", + "/lib64/libBrokenLocale.so.1", + "/lib64/libSegFault.so", + "/lib64/libanl.so.1", + "/lib64/libc.so.6", + "/lib64/libc_malloc_debug.so.0", + "/lib64/libdl.so.2", + "/lib64/libm.so.6", + "/lib64/libmvec.so.1", + "/lib64/libnss_compat.so.2", + "/lib64/libnss_dns.so.2", + "/lib64/libnss_files.so.2", + "/lib64/libpthread.so.0", + "/lib64/libresolv.so.2", + "/lib64/librt.so.1", + "/lib64/libthread_db.so.1", + "/lib64/libutil.so.1", + "/sbin/ldconfig", + "/usr/lib/.build-id", + "/usr/lib/.build-id/01", + "/usr/lib/.build-id/01/c819b24acb0c795efbcc374317234409ee0dc7", + "/usr/lib/.build-id/04", + "/usr/lib/.build-id/04/2b1f691362ff98b5818677d6016fdf2bcd3bcf", + "/usr/lib/.build-id/07", + "/usr/lib/.build-id/07/68bc1584135c16b88c585ab0104ee0eefcee18", + "/usr/lib/.build-id/07/c6dc4a8e90f5cff4f78c4b36b6dfbda1ed6681", + "/usr/lib/.build-id/10", + "/usr/lib/.build-id/10/d40b75d0bae460ec3a4144682e8e73251cf6b0", + "/usr/lib/.build-id/10/ee1ae223d6ba56abfbc3e4f7e432f42584aae7", + "/usr/lib/.build-id/2b", + "/usr/lib/.build-id/2b/3db11dedcc37e9df3d315d1b1dbd4e929ef958", + "/usr/lib/.build-id/32", + "/usr/lib/.build-id/32/a6e8ea3e731bda513ef815e59500d6c3e744b6", + "/usr/lib/.build-id/35", + "/usr/lib/.build-id/35/116f61304bea9e531ec17eaec8fc84260abe59", + "/usr/lib/.build-id/36", + "/usr/lib/.build-id/36/644bbc91b17b3a87ce54b19ec8821a884e85b0", + "/usr/lib/.build-id/3e", + "/usr/lib/.build-id/3e/68016018aa61ff89e701d3af6f9bdd8658a1f1", + "/usr/lib/.build-id/3f", + "/usr/lib/.build-id/3f/1be926cd6a1491a88d1d78715d169ee7d5708a", + "/usr/lib/.build-id/61", + "/usr/lib/.build-id/61/5329eb295112871fe565ddd20b1ac4b644bb67", + "/usr/lib/.build-id/7a", + "/usr/lib/.build-id/7a/40a22c9a82854f3d66767232ae364a99174860", + "/usr/lib/.build-id/7a/8e602a791b906aa4fc16c0adc6ccbd3839ccb5", + "/usr/lib/.build-id/7a/8e602a791b906aa4fc16c0adc6ccbd3839ccb5.1", + "/usr/lib/.build-id/7a/8e602a791b906aa4fc16c0adc6ccbd3839ccb5.2", + "/usr/lib/.build-id/83", + "/usr/lib/.build-id/83/f6b1bf683edcfdfa9e2e326f213ce903cb8f99", + "/usr/lib/.build-id/89", + "/usr/lib/.build-id/89/1ea8e785d2c39325201bf8bbd17da34cc78c9a", + "/usr/lib/.build-id/8a", + "/usr/lib/.build-id/8a/df32dc7b70cf48a481cd6899bf3dd683fdaa55", + "/usr/lib/.build-id/92", + "/usr/lib/.build-id/92/d295538fb48f417e5e9c43108e17357adc2be2", + "/usr/lib/.build-id/99", + "/usr/lib/.build-id/99/9aab3ffdd44d4f2ffe6abd6c6d36ccebadf3b3", + "/usr/lib/.build-id/a8", + "/usr/lib/.build-id/a8/0f978205f9e5a0eb61c50396f02f93c3953c59", + "/usr/lib/.build-id/b3", + "/usr/lib/.build-id/b3/e9965a54bf80257a4e38422f8a461163dde085", + "/usr/lib/.build-id/bd", + "/usr/lib/.build-id/bd/25a0b81351901d6b2429d36d8b58a2170be86b", + "/usr/lib/.build-id/cc", + "/usr/lib/.build-id/cc/302bb94fb8438236b69d0c16767dce981698d3", + "/usr/lib/.build-id/cc/fa188d19f45e944a8c7cc370de2c3d201768cb", + "/usr/lib/.build-id/d0", + "/usr/lib/.build-id/d0/8b6603a1139eb36cd40c58582e8f773482e6fc", + "/usr/lib/.build-id/d2", + "/usr/lib/.build-id/d2/bf0b656d5a9d43c085356d918a09183ae4c344", + "/usr/lib/.build-id/d9", + "/usr/lib/.build-id/d9/1e944525bec1663885f4173f2a3d43feb9c136", + "/usr/lib/.build-id/dd", + "/usr/lib/.build-id/dd/dcb75f411654391e1736b77e826017deb082e2", + "/usr/lib/.build-id/f0", + "/usr/lib/.build-id/f0/df5276edb5dff6db8ada22d686583dec4f85b7", + "/usr/lib/.build-id/f8", + "/usr/lib/.build-id/f8/544ad90e1187bfefe756af2e1d3caf9d0d52a5", + "/usr/lib64/audit", + "/usr/lib64/audit/sotruss-lib.so", + "/usr/lib64/gconv", + "/usr/lib64/gconv/ANSI_X3.110.so", + "/usr/lib64/gconv/CP1252.so", + "/usr/lib64/gconv/ISO8859-1.so", + "/usr/lib64/gconv/ISO8859-15.so", + "/usr/lib64/gconv/UNICODE.so", + "/usr/lib64/gconv/UTF-16.so", + "/usr/lib64/gconv/UTF-32.so", + "/usr/lib64/gconv/UTF-7.so", + "/usr/lib64/gconv/gconv-modules", + "/usr/lib64/gconv/gconv-modules.cache", + "/usr/lib64/gconv/gconv-modules.d", + "/usr/lib64/libmemusage.so", + "/usr/lib64/libpcprofile.so", + "/usr/libexec/getconf", + "/usr/libexec/getconf/POSIX_V6_LP64_OFF64", + "/usr/libexec/getconf/POSIX_V7_LP64_OFF64", + "/usr/libexec/getconf/XBS5_LP64_OFF64", + "/usr/sbin/iconvconfig", + "/usr/share/licenses/glibc", + "/usr/share/licenses/glibc/COPYING", + "/usr/share/licenses/glibc/COPYING.LIB", + "/usr/share/licenses/glibc/LICENSES", + "/var/cache/ldconfig", + "/var/cache/ldconfig/aux-cache" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "glibc-common@2.34-125.el9_5.3.x86_64", + "Name": "glibc-common", + "Identifier": { + "PURL": "pkg:rpm/redhat/glibc-common@2.34-125.el9_5.3?arch=x86_64\u0026distro=redhat-9.5", + "UID": "f925f99e041ddc4d" + }, + "Version": "2.34", + "Release": "125.el9_5.3", + "Arch": "x86_64", + "SrcName": "glibc", + "SrcVersion": "2.34", + "SrcRelease": "125.el9_5.3", + "Licenses": [ + "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "bash@5.1.8-9.el9.x86_64", + "glibc@2.34-125.el9_5.3.x86_64", + "tzdata@2025b-1.el9.noarch" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:151da884198691f581cf0d341a926b55", + "InstalledFiles": [ + "/usr/bin/catchsegv", + "/usr/bin/gencat", + "/usr/bin/getconf", + "/usr/bin/getent", + "/usr/bin/iconv", + "/usr/bin/ld.so", + "/usr/bin/ldd", + "/usr/bin/locale", + "/usr/bin/localedef", + "/usr/bin/pldd", + "/usr/bin/sotruss", + "/usr/bin/sprof", + "/usr/bin/tzselect", + "/usr/bin/zdump", + "/usr/lib/.build-id", + "/usr/lib/.build-id/0f", + "/usr/lib/.build-id/0f/6d02f9f5503a61fd79b174d895522e6790d8fb", + "/usr/lib/.build-id/2c", + "/usr/lib/.build-id/2c/8435a204247cda840dcfed0ef2407deb3a9c7d", + "/usr/lib/.build-id/40", + "/usr/lib/.build-id/40/55202cdf140017f178277f0e4786a0ef2b0dea", + "/usr/lib/.build-id/77", + "/usr/lib/.build-id/77/49a00497d94bb068a0818bd13fff5bb8402291", + "/usr/lib/.build-id/7a/8e602a791b906aa4fc16c0adc6ccbd3839ccb5.3", + "/usr/lib/.build-id/7e", + "/usr/lib/.build-id/7e/87379290424a4ffb80627e7eeb266b48fc5214", + "/usr/lib/.build-id/b1", + "/usr/lib/.build-id/b1/6a185b85d2d2c1c0089d784699cb9cd21e0747", + "/usr/lib/.build-id/db", + "/usr/lib/.build-id/db/5bb78fdbefc39214f9570a283db17dce1efb73", + "/usr/lib/.build-id/e7", + "/usr/lib/.build-id/e7/ff95e455e52bdfcc2f9853c88e0402aab7e16c", + "/usr/lib/.build-id/fc", + "/usr/lib/.build-id/fc/dd2d59bc1e0fb5fe51f6fb64de80365fe441db", + "/usr/lib/locale", + "/usr/lib/locale/C.utf8", + "/usr/lib/locale/C.utf8/LC_ADDRESS", + "/usr/lib/locale/C.utf8/LC_COLLATE", + "/usr/lib/locale/C.utf8/LC_CTYPE", + "/usr/lib/locale/C.utf8/LC_IDENTIFICATION", + "/usr/lib/locale/C.utf8/LC_MEASUREMENT", + "/usr/lib/locale/C.utf8/LC_MESSAGES", + "/usr/lib/locale/C.utf8/LC_MESSAGES/SYS_LC_MESSAGES", + "/usr/lib/locale/C.utf8/LC_MONETARY", + "/usr/lib/locale/C.utf8/LC_NAME", + "/usr/lib/locale/C.utf8/LC_NUMERIC", + "/usr/lib/locale/C.utf8/LC_PAPER", + "/usr/lib/locale/C.utf8/LC_TELEPHONE", + "/usr/lib/locale/C.utf8/LC_TIME", + "/usr/sbin/zic", + "/usr/share/i18n", + "/usr/share/i18n/charmaps", + "/usr/share/i18n/locales", + "/usr/share/locale/locale.alias" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "glibc-minimal-langpack@2.34-125.el9_5.3.x86_64", + "Name": "glibc-minimal-langpack", + "Identifier": { + "PURL": "pkg:rpm/redhat/glibc-minimal-langpack@2.34-125.el9_5.3?arch=x86_64\u0026distro=redhat-9.5", + "UID": "2c5d1670af8a542d" + }, + "Version": "2.34", + "Release": "125.el9_5.3", + "Arch": "x86_64", + "SrcName": "glibc", + "SrcVersion": "2.34", + "SrcRelease": "125.el9_5.3", + "Licenses": [ + "LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "glibc-common@2.34-125.el9_5.3.x86_64", + "glibc@2.34-125.el9_5.3.x86_64" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:a6fb3c3d2652eacfb7088e2d477e3712", + "AnalyzedBy": "rpm" + }, + { + "ID": "gpg-pubkey@5a6340b3-6229229e.", + "Name": "gpg-pubkey", + "Identifier": { + "PURL": "pkg:rpm/redhat/gpg-pubkey@5a6340b3-6229229e?arch=None\u0026distro=redhat-9.5", + "UID": "5d6580c0b4c1caa3" + }, + "Version": "5a6340b3", + "Release": "6229229e", + "Arch": "None", + "Licenses": [ + "pubkey" + ], + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "third-party" + }, + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "AnalyzedBy": "rpm" + }, + { + "ID": "gpg-pubkey@fd431d51-4ae0493b.", + "Name": "gpg-pubkey", + "Identifier": { + "PURL": "pkg:rpm/redhat/gpg-pubkey@fd431d51-4ae0493b?arch=None\u0026distro=redhat-9.5", + "UID": "4042de3b4b0669a1" + }, + "Version": "fd431d51", + "Release": "4ae0493b", + "Arch": "None", + "Licenses": [ + "pubkey" + ], + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "third-party" + }, + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "AnalyzedBy": "rpm" + }, + { + "ID": "libacl@2.3.1-4.el9.x86_64", + "Name": "libacl", + "Identifier": { + "PURL": "pkg:rpm/redhat/libacl@2.3.1-4.el9?arch=x86_64\u0026distro=redhat-9.5", + "UID": "55f4580a7b246b8d" + }, + "Version": "2.3.1", + "Release": "4.el9", + "Arch": "x86_64", + "SrcName": "acl", + "SrcVersion": "2.3.1", + "SrcRelease": "4.el9", + "Licenses": [ + "LGPLv2+" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "glibc@2.34-125.el9_5.3.x86_64", + "libattr@2.5.1-3.el9.x86_64" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:60e0fde3f7771c02903da07a53be36fd", + "InstalledFiles": [ + "/usr/lib/.build-id", + "/usr/lib/.build-id/8f", + "/usr/lib/.build-id/8f/9fad14a09c1b986a33688357d1513656346734", + "/usr/lib64/libacl.so.1", + "/usr/lib64/libacl.so.1.1.2301" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "libattr@2.5.1-3.el9.x86_64", + "Name": "libattr", + "Identifier": { + "PURL": "pkg:rpm/redhat/libattr@2.5.1-3.el9?arch=x86_64\u0026distro=redhat-9.5", + "UID": "b824a576a724ccdc" + }, + "Version": "2.5.1", + "Release": "3.el9", + "Arch": "x86_64", + "SrcName": "attr", + "SrcVersion": "2.5.1", + "SrcRelease": "3.el9", + "Licenses": [ + "LGPLv2+" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "glibc@2.34-125.el9_5.3.x86_64" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:52ccab71d2ac43945dc5d604e96548c4", + "InstalledFiles": [ + "/etc/xattr.conf", + "/usr/lib/.build-id", + "/usr/lib/.build-id/e6", + "/usr/lib/.build-id/e6/7f1fc89e8ac6a35f6fda914bcf6144b9ccb99c", + "/usr/lib64/libattr.so.1", + "/usr/lib64/libattr.so.1.1.2501" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "libcap@2.48-9.el9_2.x86_64", + "Name": "libcap", + "Identifier": { + "PURL": "pkg:rpm/redhat/libcap@2.48-9.el9_2?arch=x86_64\u0026distro=redhat-9.5", + "UID": "7826b36bb6020fd3" + }, + "Version": "2.48", + "Release": "9.el9_2", + "Arch": "x86_64", + "SrcName": "libcap", + "SrcVersion": "2.48", + "SrcRelease": "9.el9_2", + "Licenses": [ + "BSD or GPLv2" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "glibc@2.34-125.el9_5.3.x86_64", + "libgcc@11.5.0-5.el9_5.x86_64" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:eb03b19ffc61a35455408b0b8dbe6770", + "InstalledFiles": [ + "/usr/lib/.build-id", + "/usr/lib/.build-id/04", + "/usr/lib/.build-id/04/d463d3a6f0683b47e218e7510f40719647d3aa", + "/usr/lib/.build-id/7d", + "/usr/lib/.build-id/7d/6a98b4f53ce9e26432c74f23019917a8fe21b1", + "/usr/lib/.build-id/86", + "/usr/lib/.build-id/86/91d08fef3d9f042028d462e5b4e17b78332215", + "/usr/lib/.build-id/9d", + "/usr/lib/.build-id/9d/7457bcb82b3ca773a040754c73f41e6d405c49", + "/usr/lib/.build-id/a6", + "/usr/lib/.build-id/a6/d10687dc0f44bce6d5ebea74cbbefd77a3535b", + "/usr/lib/.build-id/b2", + "/usr/lib/.build-id/b2/213d6e1ca5ee952158c94f8221d5c9afa230ce", + "/usr/lib/.build-id/d0", + "/usr/lib/.build-id/d0/43a7b3e7c8ec366bfa066b4c91be8ff25f1497", + "/usr/lib64/libcap.so.2", + "/usr/lib64/libcap.so.2.48", + "/usr/lib64/libpsx.so.2", + "/usr/lib64/libpsx.so.2.48", + "/usr/lib64/security/pam_cap.so", + "/usr/sbin/capsh", + "/usr/sbin/getcap", + "/usr/sbin/getpcaps", + "/usr/sbin/setcap", + "/usr/share/doc/libcap", + "/usr/share/doc/libcap/capability.notes", + "/usr/share/licenses/libcap", + "/usr/share/licenses/libcap/License", + "/usr/share/man/man1/capsh.1.gz", + "/usr/share/man/man8/getcap.8.gz", + "/usr/share/man/man8/getpcaps.8.gz", + "/usr/share/man/man8/setcap.8.gz" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "libgcc@11.5.0-5.el9_5.x86_64", + "Name": "libgcc", + "Identifier": { + "PURL": "pkg:rpm/redhat/libgcc@11.5.0-5.el9_5?arch=x86_64\u0026distro=redhat-9.5", + "UID": "8bbc938e43f85e9c" + }, + "Version": "11.5.0", + "Release": "5.el9_5", + "Arch": "x86_64", + "SrcName": "gcc", + "SrcVersion": "11.5.0", + "SrcRelease": "5.el9_5", + "Licenses": [ + "GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:e94be5082e728daef320941c06d23cdb", + "InstalledFiles": [ + "/lib64/libgcc_s-11-20240719.so.1", + "/lib64/libgcc_s.so.1", + "/usr/lib/.build-id", + "/usr/lib/.build-id/fe", + "/usr/lib/.build-id/fe/8903ee76261ccca26c0f75daa1da637a93f37b", + "/usr/share/licenses/libgcc", + "/usr/share/licenses/libgcc/COPYING", + "/usr/share/licenses/libgcc/COPYING.LIB", + "/usr/share/licenses/libgcc/COPYING.RUNTIME", + "/usr/share/licenses/libgcc/COPYING3", + "/usr/share/licenses/libgcc/COPYING3.LIB" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "libselinux@3.6-1.el9.x86_64", + "Name": "libselinux", + "Identifier": { + "PURL": "pkg:rpm/redhat/libselinux@3.6-1.el9?arch=x86_64\u0026distro=redhat-9.5", + "UID": "ddf03a067a4c2534" + }, + "Version": "3.6", + "Release": "1.el9", + "Arch": "x86_64", + "SrcName": "libselinux", + "SrcVersion": "3.6", + "SrcRelease": "1.el9", + "Licenses": [ + "Public Domain" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "glibc@2.34-125.el9_5.3.x86_64", + "libsepol@3.6-1.el9.x86_64", + "pcre2@10.40-6.el9.x86_64" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:7b41929011fd9a579c33a74b7d8c2b1d", + "InstalledFiles": [ + "/run/setrans", + "/usr/lib/.build-id", + "/usr/lib/.build-id/bd", + "/usr/lib/.build-id/bd/c4adbb0901b548f448d6f0d92b49c352e3b9f6", + "/usr/lib/tmpfiles.d/libselinux.conf", + "/usr/lib64/libselinux.so.1", + "/usr/share/licenses/libselinux", + "/usr/share/licenses/libselinux/LICENSE" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "libsepol@3.6-1.el9.x86_64", + "Name": "libsepol", + "Identifier": { + "PURL": "pkg:rpm/redhat/libsepol@3.6-1.el9?arch=x86_64\u0026distro=redhat-9.5", + "UID": "9e678c0cb046de43" + }, + "Version": "3.6", + "Release": "1.el9", + "Arch": "x86_64", + "SrcName": "libsepol", + "SrcVersion": "3.6", + "SrcRelease": "1.el9", + "Licenses": [ + "LGPLv2+" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "glibc@2.34-125.el9_5.3.x86_64" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:ff8350b3eb68846cf33f797a65e6ed48", + "InstalledFiles": [ + "/usr/lib/.build-id", + "/usr/lib/.build-id/a3", + "/usr/lib/.build-id/a3/d34474eed0b870f4ef7a8baa9ef38958db8e07", + "/usr/lib64/libsepol.so.2", + "/usr/share/licenses/libsepol", + "/usr/share/licenses/libsepol/LICENSE" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "ncurses-base@6.2-10.20210508.el9.noarch", + "Name": "ncurses-base", + "Identifier": { + "PURL": "pkg:rpm/redhat/ncurses-base@6.2-10.20210508.el9?arch=noarch\u0026distro=redhat-9.5", + "UID": "d3fc90b0426bd4ac" + }, + "Version": "6.2", + "Release": "10.20210508.el9", + "Arch": "noarch", + "SrcName": "ncurses", + "SrcVersion": "6.2", + "SrcRelease": "10.20210508.el9", + "Licenses": [ + "MIT" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:9144b9cab47e7f1b2847d9034345dffb", + "InstalledFiles": [ + "/etc/terminfo", + "/usr/share/doc/ncurses-base", + "/usr/share/doc/ncurses-base/README", + "/usr/share/licenses/ncurses-base", + "/usr/share/licenses/ncurses-base/COPYING", + "/usr/share/tabset", + "/usr/share/tabset/std", + "/usr/share/tabset/stdcrt", + "/usr/share/tabset/vt100", + "/usr/share/tabset/vt300", + "/usr/share/terminfo", + "/usr/share/terminfo/A", + "/usr/share/terminfo/A/Apple_Terminal", + "/usr/share/terminfo/E", + "/usr/share/terminfo/E/Eterm", + "/usr/share/terminfo/E/Eterm-256color", + "/usr/share/terminfo/E/Eterm-88color", + "/usr/share/terminfo/E/Eterm-color", + "/usr/share/terminfo/a", + "/usr/share/terminfo/a/alacritty", + "/usr/share/terminfo/a/ansi", + "/usr/share/terminfo/a/ansi80x25", + "/usr/share/terminfo/a/ansis", + "/usr/share/terminfo/a/aterm", + "/usr/share/terminfo/b", + "/usr/share/terminfo/b/bterm", + "/usr/share/terminfo/c", + "/usr/share/terminfo/c/cons25", + "/usr/share/terminfo/c/cygwin", + "/usr/share/terminfo/d", + "/usr/share/terminfo/d/dumb", + "/usr/share/terminfo/e", + "/usr/share/terminfo/e/eterm", + "/usr/share/terminfo/e/eterm-color", + "/usr/share/terminfo/g", + "/usr/share/terminfo/g/gnome", + "/usr/share/terminfo/g/gnome-256color", + "/usr/share/terminfo/h", + "/usr/share/terminfo/h/hurd", + "/usr/share/terminfo/j", + "/usr/share/terminfo/j/jfbterm", + "/usr/share/terminfo/k", + "/usr/share/terminfo/k/kitty", + "/usr/share/terminfo/k/kon", + "/usr/share/terminfo/k/kon2", + "/usr/share/terminfo/k/konsole", + "/usr/share/terminfo/k/konsole-256color", + "/usr/share/terminfo/l", + "/usr/share/terminfo/l/linux", + "/usr/share/terminfo/m", + "/usr/share/terminfo/m/mach", + "/usr/share/terminfo/m/mach-bold", + "/usr/share/terminfo/m/mach-color", + "/usr/share/terminfo/m/mach-gnu", + "/usr/share/terminfo/m/mach-gnu-color", + "/usr/share/terminfo/m/mlterm", + "/usr/share/terminfo/m/mrxvt", + "/usr/share/terminfo/n", + "/usr/share/terminfo/n/nsterm", + "/usr/share/terminfo/n/nsterm-256color", + "/usr/share/terminfo/n/nxterm", + "/usr/share/terminfo/p", + "/usr/share/terminfo/p/pcansi", + "/usr/share/terminfo/p/putty", + "/usr/share/terminfo/p/putty-256color", + "/usr/share/terminfo/r", + "/usr/share/terminfo/r/rxvt", + "/usr/share/terminfo/r/rxvt-16color", + "/usr/share/terminfo/r/rxvt-256color", + "/usr/share/terminfo/r/rxvt-88color", + "/usr/share/terminfo/r/rxvt-basic", + "/usr/share/terminfo/r/rxvt-color", + "/usr/share/terminfo/r/rxvt-cygwin", + "/usr/share/terminfo/r/rxvt-cygwin-native", + "/usr/share/terminfo/r/rxvt-unicode", + "/usr/share/terminfo/r/rxvt-unicode-256color", + "/usr/share/terminfo/r/rxvt-xpm", + "/usr/share/terminfo/s", + "/usr/share/terminfo/s/screen", + "/usr/share/terminfo/s/screen-16color", + "/usr/share/terminfo/s/screen-256color", + "/usr/share/terminfo/s/screen.Eterm", + "/usr/share/terminfo/s/screen.gnome", + "/usr/share/terminfo/s/screen.konsole", + "/usr/share/terminfo/s/screen.konsole-256color", + "/usr/share/terminfo/s/screen.linux", + "/usr/share/terminfo/s/screen.linux-s", + "/usr/share/terminfo/s/screen.mlterm", + "/usr/share/terminfo/s/screen.mlterm-256color", + "/usr/share/terminfo/s/screen.mrxvt", + "/usr/share/terminfo/s/screen.putty", + "/usr/share/terminfo/s/screen.putty-256color", + "/usr/share/terminfo/s/screen.rxvt", + "/usr/share/terminfo/s/screen.teraterm", + "/usr/share/terminfo/s/screen.vte", + "/usr/share/terminfo/s/screen.vte-256color", + "/usr/share/terminfo/s/screen.xterm-256color", + "/usr/share/terminfo/s/screen.xterm-new", + "/usr/share/terminfo/s/screen.xterm-r6", + "/usr/share/terminfo/s/screen.xterm-xfree86", + "/usr/share/terminfo/s/st", + "/usr/share/terminfo/s/st-16color", + "/usr/share/terminfo/s/st-256color", + "/usr/share/terminfo/s/stterm", + "/usr/share/terminfo/s/stterm-16color", + "/usr/share/terminfo/s/stterm-256color", + "/usr/share/terminfo/s/sun", + "/usr/share/terminfo/s/sun1", + "/usr/share/terminfo/s/sun2", + "/usr/share/terminfo/t", + "/usr/share/terminfo/t/teraterm", + "/usr/share/terminfo/t/teraterm2.3", + "/usr/share/terminfo/t/tmux", + "/usr/share/terminfo/t/tmux-256color", + "/usr/share/terminfo/t/tmux-direct", + "/usr/share/terminfo/v", + "/usr/share/terminfo/v/vs100", + "/usr/share/terminfo/v/vt100", + "/usr/share/terminfo/v/vt100-am", + "/usr/share/terminfo/v/vt100-nav", + "/usr/share/terminfo/v/vt102", + "/usr/share/terminfo/v/vt200", + "/usr/share/terminfo/v/vt220", + "/usr/share/terminfo/v/vt52", + "/usr/share/terminfo/v/vte", + "/usr/share/terminfo/v/vte-256color", + "/usr/share/terminfo/v/vwmterm", + "/usr/share/terminfo/w", + "/usr/share/terminfo/w/wsvt25", + "/usr/share/terminfo/w/wsvt25m", + "/usr/share/terminfo/x", + "/usr/share/terminfo/x/xfce", + "/usr/share/terminfo/x/xterm", + "/usr/share/terminfo/x/xterm-1002", + "/usr/share/terminfo/x/xterm-1003", + "/usr/share/terminfo/x/xterm-1005", + "/usr/share/terminfo/x/xterm-1006", + "/usr/share/terminfo/x/xterm-16color", + "/usr/share/terminfo/x/xterm-24", + "/usr/share/terminfo/x/xterm-256color", + "/usr/share/terminfo/x/xterm-88color", + "/usr/share/terminfo/x/xterm-8bit", + "/usr/share/terminfo/x/xterm-basic", + "/usr/share/terminfo/x/xterm-bold", + "/usr/share/terminfo/x/xterm-color", + "/usr/share/terminfo/x/xterm-direct", + "/usr/share/terminfo/x/xterm-direct16", + "/usr/share/terminfo/x/xterm-direct2", + "/usr/share/terminfo/x/xterm-direct256", + "/usr/share/terminfo/x/xterm-hp", + "/usr/share/terminfo/x/xterm-mono", + "/usr/share/terminfo/x/xterm-new", + "/usr/share/terminfo/x/xterm-nic", + "/usr/share/terminfo/x/xterm-noapp", + "/usr/share/terminfo/x/xterm-old", + "/usr/share/terminfo/x/xterm-pcolor", + "/usr/share/terminfo/x/xterm-r5", + "/usr/share/terminfo/x/xterm-r6", + "/usr/share/terminfo/x/xterm-sco", + "/usr/share/terminfo/x/xterm-sun", + "/usr/share/terminfo/x/xterm-utf8", + "/usr/share/terminfo/x/xterm-vt220", + "/usr/share/terminfo/x/xterm-vt52", + "/usr/share/terminfo/x/xterm-x10mouse", + "/usr/share/terminfo/x/xterm-x11hilite", + "/usr/share/terminfo/x/xterm-x11mouse", + "/usr/share/terminfo/x/xterm-xf86-v32", + "/usr/share/terminfo/x/xterm-xf86-v33", + "/usr/share/terminfo/x/xterm-xf86-v333", + "/usr/share/terminfo/x/xterm-xf86-v40", + "/usr/share/terminfo/x/xterm-xf86-v43", + "/usr/share/terminfo/x/xterm-xf86-v44", + "/usr/share/terminfo/x/xterm-xfree86", + "/usr/share/terminfo/x/xterm-xi", + "/usr/share/terminfo/x/xterms" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "ncurses-libs@6.2-10.20210508.el9.x86_64", + "Name": "ncurses-libs", + "Identifier": { + "PURL": "pkg:rpm/redhat/ncurses-libs@6.2-10.20210508.el9?arch=x86_64\u0026distro=redhat-9.5", + "UID": "dcb636b29f1f0b0c" + }, + "Version": "6.2", + "Release": "10.20210508.el9", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.2", + "SrcRelease": "10.20210508.el9", + "Licenses": [ + "MIT" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "glibc@2.34-125.el9_5.3.x86_64", + "ncurses-base@6.2-10.20210508.el9.noarch" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:9b5398bcc39bef4de11d308e38f0128c", + "InstalledFiles": [ + "/usr/lib/.build-id", + "/usr/lib/.build-id/0e", + "/usr/lib/.build-id/0e/89a06044dfd4158900fcedd26b84e5540a1e2a", + "/usr/lib/.build-id/14", + "/usr/lib/.build-id/14/0fb74f32b9188f27050f8cdbe86184694a58dd", + "/usr/lib/.build-id/2e", + "/usr/lib/.build-id/2e/6fd6ae977c8c27e03375ffe6638a1825bc2542", + "/usr/lib/.build-id/34", + "/usr/lib/.build-id/34/6efe66eb00eb12fbaf7ba111da2d689000a9c1", + "/usr/lib/.build-id/47", + "/usr/lib/.build-id/47/490575bc7240e3e1a5053a3c0076740e3a8608", + "/usr/lib/.build-id/5c", + "/usr/lib/.build-id/5c/86b5969a136571ff7fc933596f356ba8e7ce73", + "/usr/lib/.build-id/6e", + "/usr/lib/.build-id/6e/8a87d950fa40eac47fa823c5d047e9f3cba697", + "/usr/lib/.build-id/ac", + "/usr/lib/.build-id/ac/160a3352da4bd2df74276f92f6ecf973101a71", + "/usr/lib/.build-id/b6", + "/usr/lib/.build-id/b6/ba7a16b5de3deeb8e975c07947b3458c56b241", + "/usr/lib/.build-id/cb", + "/usr/lib/.build-id/cb/f9f6b7d46b0f9841c39a007c72f1e3b142eb86", + "/usr/lib/.build-id/fe", + "/usr/lib/.build-id/fe/025c316edd4d4e78b166a1acad4cc582c92d01", + "/usr/lib/.build-id/fe/bdf0a8662671bc7387e69902b7c8c424de5c01", + "/usr/lib64/libform.so.6", + "/usr/lib64/libform.so.6.2", + "/usr/lib64/libformw.so.6", + "/usr/lib64/libformw.so.6.2", + "/usr/lib64/libmenu.so.6", + "/usr/lib64/libmenu.so.6.2", + "/usr/lib64/libmenuw.so.6", + "/usr/lib64/libmenuw.so.6.2", + "/usr/lib64/libncurses.so.6", + "/usr/lib64/libncurses.so.6.2", + "/usr/lib64/libncursesw.so.6", + "/usr/lib64/libncursesw.so.6.2", + "/usr/lib64/libpanel.so.6", + "/usr/lib64/libpanel.so.6.2", + "/usr/lib64/libpanelw.so.6", + "/usr/lib64/libpanelw.so.6.2", + "/usr/lib64/libtic.so.6", + "/usr/lib64/libtic.so.6.2", + "/usr/lib64/libtinfo.so.6", + "/usr/lib64/libtinfo.so.6.2" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "pcre2@10.40-6.el9.x86_64", + "Name": "pcre2", + "Identifier": { + "PURL": "pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64\u0026distro=redhat-9.5", + "UID": "9abd5a4065ab896c" + }, + "Version": "10.40", + "Release": "6.el9", + "Arch": "x86_64", + "SrcName": "pcre2", + "SrcVersion": "10.40", + "SrcRelease": "6.el9", + "Licenses": [ + "BSD" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "glibc@2.34-125.el9_5.3.x86_64", + "pcre2-syntax@10.40-6.el9.noarch" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:6bad562d1fe17248c677891016d5c18e", + "InstalledFiles": [ + "/usr/lib/.build-id", + "/usr/lib/.build-id/48", + "/usr/lib/.build-id/48/1282542036ac05da5dbbe987bb1feae7f7eb4a", + "/usr/lib/.build-id/76", + "/usr/lib/.build-id/76/2e199f8f08725f767cb3c3167faae14327659f", + "/usr/lib64/libpcre2-8.so.0", + "/usr/lib64/libpcre2-8.so.0.11.0", + "/usr/lib64/libpcre2-posix.so.3", + "/usr/lib64/libpcre2-posix.so.3.0.2" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "pcre2-syntax@10.40-6.el9.noarch", + "Name": "pcre2-syntax", + "Identifier": { + "PURL": "pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch\u0026distro=redhat-9.5", + "UID": "459af584b3a3a6aa" + }, + "Version": "10.40", + "Release": "6.el9", + "Arch": "noarch", + "SrcName": "pcre2", + "SrcVersion": "10.40", + "SrcRelease": "6.el9", + "Licenses": [ + "BSD" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:e16f2b328f130d319f08c995f4d3315b", + "InstalledFiles": [ + "/usr/share/doc/pcre2-syntax", + "/usr/share/doc/pcre2-syntax/AUTHORS", + "/usr/share/doc/pcre2-syntax/ChangeLog", + "/usr/share/doc/pcre2-syntax/NEWS", + "/usr/share/licenses/pcre2-syntax", + "/usr/share/licenses/pcre2-syntax/COPYING", + "/usr/share/licenses/pcre2-syntax/LICENCE", + "/usr/share/man/man3/pcre2.3.gz", + "/usr/share/man/man3/pcre2compat.3.gz", + "/usr/share/man/man3/pcre2limits.3.gz", + "/usr/share/man/man3/pcre2matching.3.gz", + "/usr/share/man/man3/pcre2partial.3.gz", + "/usr/share/man/man3/pcre2pattern.3.gz", + "/usr/share/man/man3/pcre2perform.3.gz", + "/usr/share/man/man3/pcre2syntax.3.gz", + "/usr/share/man/man3/pcre2unicode.3.gz" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "redhat-release@9.5-0.6.el9.x86_64", + "Name": "redhat-release", + "Identifier": { + "PURL": "pkg:rpm/redhat/redhat-release@9.5-0.6.el9?arch=x86_64\u0026distro=redhat-9.5", + "UID": "9b68521dba997804" + }, + "Version": "9.5", + "Release": "0.6.el9", + "Arch": "x86_64", + "SrcName": "redhat-release", + "SrcVersion": "9.5", + "SrcRelease": "0.6.el9", + "Licenses": [ + "GPLv2" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:2250d9cd0d4568420047643254adbf41", + "InstalledFiles": [ + "/etc/dnf/protected.d/redhat-release.conf", + "/etc/issue", + "/etc/issue.d", + "/etc/issue.net", + "/etc/os-release", + "/etc/pki/product-default", + "/etc/pki/product-default/479.pem", + "/etc/pki/rpm-gpg", + "/etc/pki/rpm-gpg/ISV-Container-signing-key", + "/etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-beta", + "/etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release", + "/etc/pki/swid/CA/redhat.com", + "/etc/pki/swid/CA/redhat.com/redhatcodesignca.cert", + "/etc/redhat-release", + "/etc/swid/swidtags.d", + "/etc/swid/swidtags.d/redhat.com", + "/etc/system-release", + "/etc/system-release-cpe", + "/etc/yum.repos.d", + "/usr/lib/os-release", + "/usr/lib/rpm/macros.d/macros.dist", + "/usr/lib/swidtag/redhat.com", + "/usr/lib/swidtag/redhat.com/com.redhat.RHEL-9-x86_64.swidtag", + "/usr/lib/swidtag/redhat.com/com.redhat.RHEL-9.5-x86_64.swidtag", + "/usr/lib/sysctl.d/50-redhat.conf", + "/usr/lib/systemd/system-preset/85-display-manager.preset", + "/usr/lib/systemd/system-preset/90-default.preset", + "/usr/lib/systemd/system-preset/99-default-disable.preset", + "/usr/lib/systemd/user-preset/90-default-user.preset", + "/usr/lib/systemd/user-preset/99-default-disable.preset", + "/usr/share/doc/redhat-release/GPL", + "/usr/share/doc/redhat-release/GPL-source-offer" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "setup@2.13.7-10.el9.noarch", + "Name": "setup", + "Identifier": { + "PURL": "pkg:rpm/redhat/setup@2.13.7-10.el9?arch=noarch\u0026distro=redhat-9.5", + "UID": "aac6dcf91606c10e" + }, + "Version": "2.13.7", + "Release": "10.el9", + "Arch": "noarch", + "SrcName": "setup", + "SrcVersion": "2.13.7", + "SrcRelease": "10.el9", + "Licenses": [ + "Public Domain" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "redhat-release@9.5-0.6.el9.x86_64" + ], + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:b7e2acce809a4d9403ae8499e929ad53", + "InstalledFiles": [ + "/etc/aliases", + "/etc/bashrc", + "/etc/csh.cshrc", + "/etc/csh.login", + "/etc/dnf/protected.d/setup.conf", + "/etc/environment", + "/etc/ethertypes", + "/etc/exports", + "/etc/filesystems", + "/etc/fstab", + "/etc/group", + "/etc/gshadow", + "/etc/host.conf", + "/etc/hosts", + "/etc/inputrc", + "/etc/motd", + "/etc/motd.d", + "/etc/networks", + "/etc/passwd", + "/etc/printcap", + "/etc/profile", + "/etc/profile.d", + "/etc/profile.d/csh.local", + "/etc/profile.d/lang.csh", + "/etc/profile.d/lang.sh", + "/etc/profile.d/sh.local", + "/etc/protocols", + "/etc/services", + "/etc/shadow", + "/etc/shells", + "/etc/subgid", + "/etc/subuid", + "/run/motd", + "/run/motd.d", + "/usr/lib/motd", + "/usr/lib/motd.d", + "/usr/lib/tmpfiles.d/setup.conf", + "/usr/share/doc/setup", + "/usr/share/doc/setup/uidgid", + "/usr/share/licenses/setup", + "/usr/share/licenses/setup/COPYING" + ], + "AnalyzedBy": "rpm" + }, + { + "ID": "tzdata@2025b-1.el9.noarch", + "Name": "tzdata", + "Identifier": { + "PURL": "pkg:rpm/redhat/tzdata@2025b-1.el9?arch=noarch\u0026distro=redhat-9.5", + "UID": "661b8b1958dd38ab" + }, + "Version": "2025b", + "Release": "1.el9", + "Arch": "noarch", + "SrcName": "tzdata", + "SrcVersion": "2025b", + "SrcRelease": "1.el9", + "Licenses": [ + "Public Domain" + ], + "Maintainer": "Red Hat, Inc.", + "BuildInfo": { + "ContentSets": [ + "rhel-9-for-aarch64-baseos-rpms", + "rhel-9-for-aarch64-baseos-source-rpms", + "rhel-9-for-ppc64le-baseos-rpms", + "rhel-9-for-ppc64le-baseos-source-rpms", + "rhel-9-for-s390x-baseos-rpms", + "rhel-9-for-s390x-baseos-source-rpms", + "rhel-9-for-x86_64-baseos-rpms", + "rhel-9-for-x86_64-baseos-source-rpms" + ] + }, + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "Digest": "md5:d7fd195490791e657d509ab1594ff2f6", + "InstalledFiles": [ + "/usr/share/doc/tzdata", + "/usr/share/doc/tzdata/README", + "/usr/share/doc/tzdata/theory.html", + "/usr/share/doc/tzdata/tz-art.html", + "/usr/share/doc/tzdata/tz-link.html", + "/usr/share/licenses/tzdata", + "/usr/share/licenses/tzdata/LICENSE", + "/usr/share/zoneinfo", + "/usr/share/zoneinfo/Africa", + "/usr/share/zoneinfo/Africa/Abidjan", + "/usr/share/zoneinfo/Africa/Accra", + "/usr/share/zoneinfo/Africa/Addis_Ababa", + "/usr/share/zoneinfo/Africa/Algiers", + "/usr/share/zoneinfo/Africa/Asmara", + "/usr/share/zoneinfo/Africa/Asmera", + "/usr/share/zoneinfo/Africa/Bamako", + "/usr/share/zoneinfo/Africa/Bangui", + "/usr/share/zoneinfo/Africa/Banjul", + "/usr/share/zoneinfo/Africa/Bissau", + "/usr/share/zoneinfo/Africa/Blantyre", + "/usr/share/zoneinfo/Africa/Brazzaville", + "/usr/share/zoneinfo/Africa/Bujumbura", + "/usr/share/zoneinfo/Africa/Cairo", + "/usr/share/zoneinfo/Africa/Casablanca", + "/usr/share/zoneinfo/Africa/Ceuta", + "/usr/share/zoneinfo/Africa/Conakry", + "/usr/share/zoneinfo/Africa/Dakar", + "/usr/share/zoneinfo/Africa/Dar_es_Salaam", + "/usr/share/zoneinfo/Africa/Djibouti", + "/usr/share/zoneinfo/Africa/Douala", + "/usr/share/zoneinfo/Africa/El_Aaiun", + "/usr/share/zoneinfo/Africa/Freetown", + "/usr/share/zoneinfo/Africa/Gaborone", + "/usr/share/zoneinfo/Africa/Harare", + "/usr/share/zoneinfo/Africa/Johannesburg", + "/usr/share/zoneinfo/Africa/Juba", + "/usr/share/zoneinfo/Africa/Kampala", + "/usr/share/zoneinfo/Africa/Khartoum", + "/usr/share/zoneinfo/Africa/Kigali", + "/usr/share/zoneinfo/Africa/Kinshasa", + "/usr/share/zoneinfo/Africa/Lagos", + "/usr/share/zoneinfo/Africa/Libreville", + "/usr/share/zoneinfo/Africa/Lome", + "/usr/share/zoneinfo/Africa/Luanda", + "/usr/share/zoneinfo/Africa/Lubumbashi", + "/usr/share/zoneinfo/Africa/Lusaka", + "/usr/share/zoneinfo/Africa/Malabo", + "/usr/share/zoneinfo/Africa/Maputo", + "/usr/share/zoneinfo/Africa/Maseru", + "/usr/share/zoneinfo/Africa/Mbabane", + "/usr/share/zoneinfo/Africa/Mogadishu", + "/usr/share/zoneinfo/Africa/Monrovia", + "/usr/share/zoneinfo/Africa/Nairobi", + "/usr/share/zoneinfo/Africa/Ndjamena", + "/usr/share/zoneinfo/Africa/Niamey", + "/usr/share/zoneinfo/Africa/Nouakchott", + "/usr/share/zoneinfo/Africa/Ouagadougou", + "/usr/share/zoneinfo/Africa/Porto-Novo", + "/usr/share/zoneinfo/Africa/Sao_Tome", + "/usr/share/zoneinfo/Africa/Timbuktu", + "/usr/share/zoneinfo/Africa/Tripoli", + "/usr/share/zoneinfo/Africa/Tunis", + "/usr/share/zoneinfo/Africa/Windhoek", + "/usr/share/zoneinfo/America", + "/usr/share/zoneinfo/America/Adak", + "/usr/share/zoneinfo/America/Anchorage", + "/usr/share/zoneinfo/America/Anguilla", + "/usr/share/zoneinfo/America/Antigua", + "/usr/share/zoneinfo/America/Araguaina", + "/usr/share/zoneinfo/America/Argentina", + "/usr/share/zoneinfo/America/Argentina/Buenos_Aires", + "/usr/share/zoneinfo/America/Argentina/Catamarca", + "/usr/share/zoneinfo/America/Argentina/ComodRivadavia", + "/usr/share/zoneinfo/America/Argentina/Cordoba", + "/usr/share/zoneinfo/America/Argentina/Jujuy", + "/usr/share/zoneinfo/America/Argentina/La_Rioja", + "/usr/share/zoneinfo/America/Argentina/Mendoza", + "/usr/share/zoneinfo/America/Argentina/Rio_Gallegos", + "/usr/share/zoneinfo/America/Argentina/Salta", + "/usr/share/zoneinfo/America/Argentina/San_Juan", + "/usr/share/zoneinfo/America/Argentina/San_Luis", + "/usr/share/zoneinfo/America/Argentina/Tucuman", + "/usr/share/zoneinfo/America/Argentina/Ushuaia", + "/usr/share/zoneinfo/America/Aruba", + "/usr/share/zoneinfo/America/Asuncion", + "/usr/share/zoneinfo/America/Atikokan", + "/usr/share/zoneinfo/America/Atka", + "/usr/share/zoneinfo/America/Bahia", + "/usr/share/zoneinfo/America/Bahia_Banderas", + "/usr/share/zoneinfo/America/Barbados", + "/usr/share/zoneinfo/America/Belem", + "/usr/share/zoneinfo/America/Belize", + "/usr/share/zoneinfo/America/Blanc-Sablon", + "/usr/share/zoneinfo/America/Boa_Vista", + "/usr/share/zoneinfo/America/Bogota", + "/usr/share/zoneinfo/America/Boise", + "/usr/share/zoneinfo/America/Buenos_Aires", + "/usr/share/zoneinfo/America/Cambridge_Bay", + "/usr/share/zoneinfo/America/Campo_Grande", + "/usr/share/zoneinfo/America/Cancun", + "/usr/share/zoneinfo/America/Caracas", + "/usr/share/zoneinfo/America/Catamarca", + "/usr/share/zoneinfo/America/Cayenne", + "/usr/share/zoneinfo/America/Cayman", + "/usr/share/zoneinfo/America/Chicago", + "/usr/share/zoneinfo/America/Chihuahua", + "/usr/share/zoneinfo/America/Ciudad_Juarez", + "/usr/share/zoneinfo/America/Coral_Harbour", + "/usr/share/zoneinfo/America/Cordoba", + "/usr/share/zoneinfo/America/Costa_Rica", + "/usr/share/zoneinfo/America/Coyhaique", + "/usr/share/zoneinfo/America/Creston", + "/usr/share/zoneinfo/America/Cuiaba", + "/usr/share/zoneinfo/America/Curacao", + "/usr/share/zoneinfo/America/Danmarkshavn", + "/usr/share/zoneinfo/America/Dawson", + "/usr/share/zoneinfo/America/Dawson_Creek", + "/usr/share/zoneinfo/America/Denver", + "/usr/share/zoneinfo/America/Detroit", + "/usr/share/zoneinfo/America/Dominica", + "/usr/share/zoneinfo/America/Edmonton", + "/usr/share/zoneinfo/America/Eirunepe", + "/usr/share/zoneinfo/America/El_Salvador", + "/usr/share/zoneinfo/America/Ensenada", + "/usr/share/zoneinfo/America/Fort_Nelson", + "/usr/share/zoneinfo/America/Fort_Wayne", + "/usr/share/zoneinfo/America/Fortaleza", + "/usr/share/zoneinfo/America/Glace_Bay", + "/usr/share/zoneinfo/America/Godthab", + "/usr/share/zoneinfo/America/Goose_Bay", + "/usr/share/zoneinfo/America/Grand_Turk", + "/usr/share/zoneinfo/America/Grenada", + "/usr/share/zoneinfo/America/Guadeloupe", + "/usr/share/zoneinfo/America/Guatemala", + "/usr/share/zoneinfo/America/Guayaquil", + "/usr/share/zoneinfo/America/Guyana", + "/usr/share/zoneinfo/America/Halifax", + "/usr/share/zoneinfo/America/Havana", + "/usr/share/zoneinfo/America/Hermosillo", + "/usr/share/zoneinfo/America/Indiana", + "/usr/share/zoneinfo/America/Indiana/Indianapolis", + "/usr/share/zoneinfo/America/Indiana/Knox", + "/usr/share/zoneinfo/America/Indiana/Marengo", + "/usr/share/zoneinfo/America/Indiana/Petersburg", + "/usr/share/zoneinfo/America/Indiana/Tell_City", + "/usr/share/zoneinfo/America/Indiana/Vevay", + "/usr/share/zoneinfo/America/Indiana/Vincennes", + "/usr/share/zoneinfo/America/Indiana/Winamac", + "/usr/share/zoneinfo/America/Indianapolis", + "/usr/share/zoneinfo/America/Inuvik", + "/usr/share/zoneinfo/America/Iqaluit", + "/usr/share/zoneinfo/America/Jamaica", + "/usr/share/zoneinfo/America/Jujuy", + "/usr/share/zoneinfo/America/Juneau", + "/usr/share/zoneinfo/America/Kentucky", + "/usr/share/zoneinfo/America/Kentucky/Louisville", + "/usr/share/zoneinfo/America/Kentucky/Monticello", + "/usr/share/zoneinfo/America/Knox_IN", + "/usr/share/zoneinfo/America/Kralendijk", + "/usr/share/zoneinfo/America/La_Paz", + "/usr/share/zoneinfo/America/Lima", + "/usr/share/zoneinfo/America/Los_Angeles", + "/usr/share/zoneinfo/America/Louisville", + "/usr/share/zoneinfo/America/Lower_Princes", + "/usr/share/zoneinfo/America/Maceio", + "/usr/share/zoneinfo/America/Managua", + "/usr/share/zoneinfo/America/Manaus", + "/usr/share/zoneinfo/America/Marigot", + "/usr/share/zoneinfo/America/Martinique", + "/usr/share/zoneinfo/America/Matamoros", + "/usr/share/zoneinfo/America/Mazatlan", + "/usr/share/zoneinfo/America/Mendoza", + "/usr/share/zoneinfo/America/Menominee", + "/usr/share/zoneinfo/America/Merida", + "/usr/share/zoneinfo/America/Metlakatla", + "/usr/share/zoneinfo/America/Mexico_City", + "/usr/share/zoneinfo/America/Miquelon", + "/usr/share/zoneinfo/America/Moncton", + "/usr/share/zoneinfo/America/Monterrey", + "/usr/share/zoneinfo/America/Montevideo", + "/usr/share/zoneinfo/America/Montreal", + "/usr/share/zoneinfo/America/Montserrat", + "/usr/share/zoneinfo/America/Nassau", + "/usr/share/zoneinfo/America/New_York", + "/usr/share/zoneinfo/America/Nipigon", + "/usr/share/zoneinfo/America/Nome", + "/usr/share/zoneinfo/America/Noronha", + "/usr/share/zoneinfo/America/North_Dakota", + "/usr/share/zoneinfo/America/North_Dakota/Beulah", + "/usr/share/zoneinfo/America/North_Dakota/Center", + "/usr/share/zoneinfo/America/North_Dakota/New_Salem", + "/usr/share/zoneinfo/America/Nuuk", + "/usr/share/zoneinfo/America/Ojinaga", + "/usr/share/zoneinfo/America/Panama", + "/usr/share/zoneinfo/America/Pangnirtung", + "/usr/share/zoneinfo/America/Paramaribo", + "/usr/share/zoneinfo/America/Phoenix", + "/usr/share/zoneinfo/America/Port-au-Prince", + "/usr/share/zoneinfo/America/Port_of_Spain", + "/usr/share/zoneinfo/America/Porto_Acre", + "/usr/share/zoneinfo/America/Porto_Velho", + "/usr/share/zoneinfo/America/Puerto_Rico", + "/usr/share/zoneinfo/America/Punta_Arenas", + "/usr/share/zoneinfo/America/Rainy_River", + "/usr/share/zoneinfo/America/Rankin_Inlet", + "/usr/share/zoneinfo/America/Recife", + "/usr/share/zoneinfo/America/Regina", + "/usr/share/zoneinfo/America/Resolute", + "/usr/share/zoneinfo/America/Rio_Branco", + "/usr/share/zoneinfo/America/Rosario", + "/usr/share/zoneinfo/America/Santa_Isabel", + "/usr/share/zoneinfo/America/Santarem", + "/usr/share/zoneinfo/America/Santiago", + "/usr/share/zoneinfo/America/Santo_Domingo", + "/usr/share/zoneinfo/America/Sao_Paulo", + "/usr/share/zoneinfo/America/Scoresbysund", + "/usr/share/zoneinfo/America/Shiprock", + "/usr/share/zoneinfo/America/Sitka", + "/usr/share/zoneinfo/America/St_Barthelemy", + "/usr/share/zoneinfo/America/St_Johns", + "/usr/share/zoneinfo/America/St_Kitts", + "/usr/share/zoneinfo/America/St_Lucia", + "/usr/share/zoneinfo/America/St_Thomas", + "/usr/share/zoneinfo/America/St_Vincent", + "/usr/share/zoneinfo/America/Swift_Current", + "/usr/share/zoneinfo/America/Tegucigalpa", + "/usr/share/zoneinfo/America/Thule", + "/usr/share/zoneinfo/America/Thunder_Bay", + "/usr/share/zoneinfo/America/Tijuana", + "/usr/share/zoneinfo/America/Toronto", + "/usr/share/zoneinfo/America/Tortola", + "/usr/share/zoneinfo/America/Vancouver", + "/usr/share/zoneinfo/America/Virgin", + "/usr/share/zoneinfo/America/Whitehorse", + "/usr/share/zoneinfo/America/Winnipeg", + "/usr/share/zoneinfo/America/Yakutat", + "/usr/share/zoneinfo/America/Yellowknife", + "/usr/share/zoneinfo/Antarctica", + "/usr/share/zoneinfo/Antarctica/Casey", + "/usr/share/zoneinfo/Antarctica/Davis", + "/usr/share/zoneinfo/Antarctica/DumontDUrville", + "/usr/share/zoneinfo/Antarctica/Macquarie", + "/usr/share/zoneinfo/Antarctica/Mawson", + "/usr/share/zoneinfo/Antarctica/McMurdo", + "/usr/share/zoneinfo/Antarctica/Palmer", + "/usr/share/zoneinfo/Antarctica/Rothera", + "/usr/share/zoneinfo/Antarctica/South_Pole", + "/usr/share/zoneinfo/Antarctica/Syowa", + "/usr/share/zoneinfo/Antarctica/Troll", + "/usr/share/zoneinfo/Antarctica/Vostok", + "/usr/share/zoneinfo/Arctic", + "/usr/share/zoneinfo/Arctic/Longyearbyen", + "/usr/share/zoneinfo/Asia", + "/usr/share/zoneinfo/Asia/Aden", + "/usr/share/zoneinfo/Asia/Almaty", + "/usr/share/zoneinfo/Asia/Amman", + "/usr/share/zoneinfo/Asia/Anadyr", + "/usr/share/zoneinfo/Asia/Aqtau", + "/usr/share/zoneinfo/Asia/Aqtobe", + "/usr/share/zoneinfo/Asia/Ashgabat", + "/usr/share/zoneinfo/Asia/Ashkhabad", + "/usr/share/zoneinfo/Asia/Atyrau", + "/usr/share/zoneinfo/Asia/Baghdad", + "/usr/share/zoneinfo/Asia/Bahrain", + "/usr/share/zoneinfo/Asia/Baku", + "/usr/share/zoneinfo/Asia/Bangkok", + "/usr/share/zoneinfo/Asia/Barnaul", + "/usr/share/zoneinfo/Asia/Beirut", + "/usr/share/zoneinfo/Asia/Bishkek", + "/usr/share/zoneinfo/Asia/Brunei", + "/usr/share/zoneinfo/Asia/Calcutta", + "/usr/share/zoneinfo/Asia/Chita", + "/usr/share/zoneinfo/Asia/Choibalsan", + "/usr/share/zoneinfo/Asia/Chongqing", + "/usr/share/zoneinfo/Asia/Chungking", + "/usr/share/zoneinfo/Asia/Colombo", + "/usr/share/zoneinfo/Asia/Dacca", + "/usr/share/zoneinfo/Asia/Damascus", + "/usr/share/zoneinfo/Asia/Dhaka", + "/usr/share/zoneinfo/Asia/Dili", + "/usr/share/zoneinfo/Asia/Dubai", + "/usr/share/zoneinfo/Asia/Dushanbe", + "/usr/share/zoneinfo/Asia/Famagusta", + "/usr/share/zoneinfo/Asia/Gaza", + "/usr/share/zoneinfo/Asia/Harbin", + "/usr/share/zoneinfo/Asia/Hebron", + "/usr/share/zoneinfo/Asia/Ho_Chi_Minh", + "/usr/share/zoneinfo/Asia/Hong_Kong", + "/usr/share/zoneinfo/Asia/Hovd", + "/usr/share/zoneinfo/Asia/Irkutsk", + "/usr/share/zoneinfo/Asia/Istanbul", + "/usr/share/zoneinfo/Asia/Jakarta", + "/usr/share/zoneinfo/Asia/Jayapura", + "/usr/share/zoneinfo/Asia/Jerusalem", + "/usr/share/zoneinfo/Asia/Kabul", + "/usr/share/zoneinfo/Asia/Kamchatka", + "/usr/share/zoneinfo/Asia/Karachi", + "/usr/share/zoneinfo/Asia/Kashgar", + "/usr/share/zoneinfo/Asia/Kathmandu", + "/usr/share/zoneinfo/Asia/Katmandu", + "/usr/share/zoneinfo/Asia/Khandyga", + "/usr/share/zoneinfo/Asia/Kolkata", + "/usr/share/zoneinfo/Asia/Krasnoyarsk", + "/usr/share/zoneinfo/Asia/Kuala_Lumpur", + "/usr/share/zoneinfo/Asia/Kuching", + "/usr/share/zoneinfo/Asia/Kuwait", + "/usr/share/zoneinfo/Asia/Macao", + "/usr/share/zoneinfo/Asia/Macau", + "/usr/share/zoneinfo/Asia/Magadan", + "/usr/share/zoneinfo/Asia/Makassar", + "/usr/share/zoneinfo/Asia/Manila", + "/usr/share/zoneinfo/Asia/Muscat", + "/usr/share/zoneinfo/Asia/Nicosia", + "/usr/share/zoneinfo/Asia/Novokuznetsk", + "/usr/share/zoneinfo/Asia/Novosibirsk", + "/usr/share/zoneinfo/Asia/Omsk", + "/usr/share/zoneinfo/Asia/Oral", + "/usr/share/zoneinfo/Asia/Phnom_Penh", + "/usr/share/zoneinfo/Asia/Pontianak", + "/usr/share/zoneinfo/Asia/Pyongyang", + "/usr/share/zoneinfo/Asia/Qatar", + "/usr/share/zoneinfo/Asia/Qostanay", + "/usr/share/zoneinfo/Asia/Qyzylorda", + "/usr/share/zoneinfo/Asia/Rangoon", + "/usr/share/zoneinfo/Asia/Riyadh", + "/usr/share/zoneinfo/Asia/Saigon", + "/usr/share/zoneinfo/Asia/Sakhalin", + "/usr/share/zoneinfo/Asia/Samarkand", + "/usr/share/zoneinfo/Asia/Seoul", + "/usr/share/zoneinfo/Asia/Shanghai", + "/usr/share/zoneinfo/Asia/Singapore", + "/usr/share/zoneinfo/Asia/Srednekolymsk", + "/usr/share/zoneinfo/Asia/Taipei", + "/usr/share/zoneinfo/Asia/Tashkent", + "/usr/share/zoneinfo/Asia/Tbilisi", + "/usr/share/zoneinfo/Asia/Tehran", + "/usr/share/zoneinfo/Asia/Tel_Aviv", + "/usr/share/zoneinfo/Asia/Thimbu", + "/usr/share/zoneinfo/Asia/Thimphu", + "/usr/share/zoneinfo/Asia/Tokyo", + "/usr/share/zoneinfo/Asia/Tomsk", + "/usr/share/zoneinfo/Asia/Ujung_Pandang", + "/usr/share/zoneinfo/Asia/Ulaanbaatar", + "/usr/share/zoneinfo/Asia/Ulan_Bator", + "/usr/share/zoneinfo/Asia/Urumqi", + "/usr/share/zoneinfo/Asia/Ust-Nera", + "/usr/share/zoneinfo/Asia/Vientiane", + "/usr/share/zoneinfo/Asia/Vladivostok", + "/usr/share/zoneinfo/Asia/Yakutsk", + "/usr/share/zoneinfo/Asia/Yangon", + "/usr/share/zoneinfo/Asia/Yekaterinburg", + "/usr/share/zoneinfo/Asia/Yerevan", + "/usr/share/zoneinfo/Atlantic", + "/usr/share/zoneinfo/Atlantic/Azores", + "/usr/share/zoneinfo/Atlantic/Bermuda", + "/usr/share/zoneinfo/Atlantic/Canary", + "/usr/share/zoneinfo/Atlantic/Cape_Verde", + "/usr/share/zoneinfo/Atlantic/Faeroe", + "/usr/share/zoneinfo/Atlantic/Faroe", + "/usr/share/zoneinfo/Atlantic/Jan_Mayen", + "/usr/share/zoneinfo/Atlantic/Madeira", + "/usr/share/zoneinfo/Atlantic/Reykjavik", + "/usr/share/zoneinfo/Atlantic/South_Georgia", + "/usr/share/zoneinfo/Atlantic/St_Helena", + "/usr/share/zoneinfo/Atlantic/Stanley", + "/usr/share/zoneinfo/Australia", + "/usr/share/zoneinfo/Australia/ACT", + "/usr/share/zoneinfo/Australia/Adelaide", + "/usr/share/zoneinfo/Australia/Brisbane", + "/usr/share/zoneinfo/Australia/Broken_Hill", + "/usr/share/zoneinfo/Australia/Canberra", + "/usr/share/zoneinfo/Australia/Currie", + "/usr/share/zoneinfo/Australia/Darwin", + "/usr/share/zoneinfo/Australia/Eucla", + "/usr/share/zoneinfo/Australia/Hobart", + "/usr/share/zoneinfo/Australia/LHI", + "/usr/share/zoneinfo/Australia/Lindeman", + "/usr/share/zoneinfo/Australia/Lord_Howe", + "/usr/share/zoneinfo/Australia/Melbourne", + "/usr/share/zoneinfo/Australia/NSW", + "/usr/share/zoneinfo/Australia/North", + "/usr/share/zoneinfo/Australia/Perth", + "/usr/share/zoneinfo/Australia/Queensland", + "/usr/share/zoneinfo/Australia/South", + "/usr/share/zoneinfo/Australia/Sydney", + "/usr/share/zoneinfo/Australia/Tasmania", + "/usr/share/zoneinfo/Australia/Victoria", + "/usr/share/zoneinfo/Australia/West", + "/usr/share/zoneinfo/Australia/Yancowinna", + "/usr/share/zoneinfo/Brazil", + "/usr/share/zoneinfo/Brazil/Acre", + "/usr/share/zoneinfo/Brazil/DeNoronha", + "/usr/share/zoneinfo/Brazil/East", + "/usr/share/zoneinfo/Brazil/West", + "/usr/share/zoneinfo/CET", + "/usr/share/zoneinfo/CST6CDT", + "/usr/share/zoneinfo/Canada", + "/usr/share/zoneinfo/Canada/Atlantic", + "/usr/share/zoneinfo/Canada/Central", + "/usr/share/zoneinfo/Canada/Eastern", + "/usr/share/zoneinfo/Canada/Mountain", + "/usr/share/zoneinfo/Canada/Newfoundland", + "/usr/share/zoneinfo/Canada/Pacific", + "/usr/share/zoneinfo/Canada/Saskatchewan", + "/usr/share/zoneinfo/Canada/Yukon", + "/usr/share/zoneinfo/Chile", + "/usr/share/zoneinfo/Chile/Continental", + "/usr/share/zoneinfo/Chile/EasterIsland", + "/usr/share/zoneinfo/Cuba", + "/usr/share/zoneinfo/EET", + "/usr/share/zoneinfo/EST", + "/usr/share/zoneinfo/EST5EDT", + "/usr/share/zoneinfo/Egypt", + "/usr/share/zoneinfo/Eire", + "/usr/share/zoneinfo/Etc", + "/usr/share/zoneinfo/Etc/GMT", + "/usr/share/zoneinfo/Etc/GMT+0", + "/usr/share/zoneinfo/Etc/GMT+1", + "/usr/share/zoneinfo/Etc/GMT+10", + "/usr/share/zoneinfo/Etc/GMT+11", + "/usr/share/zoneinfo/Etc/GMT+12", + "/usr/share/zoneinfo/Etc/GMT+2", + "/usr/share/zoneinfo/Etc/GMT+3", + "/usr/share/zoneinfo/Etc/GMT+4", + "/usr/share/zoneinfo/Etc/GMT+5", + "/usr/share/zoneinfo/Etc/GMT+6", + "/usr/share/zoneinfo/Etc/GMT+7", + "/usr/share/zoneinfo/Etc/GMT+8", + "/usr/share/zoneinfo/Etc/GMT+9", + "/usr/share/zoneinfo/Etc/GMT-0", + "/usr/share/zoneinfo/Etc/GMT-1", + "/usr/share/zoneinfo/Etc/GMT-10", + "/usr/share/zoneinfo/Etc/GMT-11", + "/usr/share/zoneinfo/Etc/GMT-12", + "/usr/share/zoneinfo/Etc/GMT-13", + "/usr/share/zoneinfo/Etc/GMT-14", + "/usr/share/zoneinfo/Etc/GMT-2", + "/usr/share/zoneinfo/Etc/GMT-3", + "/usr/share/zoneinfo/Etc/GMT-4", + "/usr/share/zoneinfo/Etc/GMT-5", + "/usr/share/zoneinfo/Etc/GMT-6", + "/usr/share/zoneinfo/Etc/GMT-7", + "/usr/share/zoneinfo/Etc/GMT-8", + "/usr/share/zoneinfo/Etc/GMT-9", + "/usr/share/zoneinfo/Etc/GMT0", + "/usr/share/zoneinfo/Etc/Greenwich", + "/usr/share/zoneinfo/Etc/UCT", + "/usr/share/zoneinfo/Etc/UTC", + "/usr/share/zoneinfo/Etc/Universal", + "/usr/share/zoneinfo/Etc/Zulu", + "/usr/share/zoneinfo/Europe", + "/usr/share/zoneinfo/Europe/Amsterdam", + "/usr/share/zoneinfo/Europe/Andorra", + "/usr/share/zoneinfo/Europe/Astrakhan", + "/usr/share/zoneinfo/Europe/Athens", + "/usr/share/zoneinfo/Europe/Belfast", + "/usr/share/zoneinfo/Europe/Belgrade", + "/usr/share/zoneinfo/Europe/Berlin", + "/usr/share/zoneinfo/Europe/Bratislava", + "/usr/share/zoneinfo/Europe/Brussels", + "/usr/share/zoneinfo/Europe/Bucharest", + "/usr/share/zoneinfo/Europe/Budapest", + "/usr/share/zoneinfo/Europe/Busingen", + "/usr/share/zoneinfo/Europe/Chisinau", + "/usr/share/zoneinfo/Europe/Copenhagen", + "/usr/share/zoneinfo/Europe/Dublin", + "/usr/share/zoneinfo/Europe/Gibraltar", + "/usr/share/zoneinfo/Europe/Guernsey", + "/usr/share/zoneinfo/Europe/Helsinki", + "/usr/share/zoneinfo/Europe/Isle_of_Man", + "/usr/share/zoneinfo/Europe/Istanbul", + "/usr/share/zoneinfo/Europe/Jersey", + "/usr/share/zoneinfo/Europe/Kaliningrad", + "/usr/share/zoneinfo/Europe/Kiev", + "/usr/share/zoneinfo/Europe/Kirov", + "/usr/share/zoneinfo/Europe/Kyiv", + "/usr/share/zoneinfo/Europe/Lisbon", + "/usr/share/zoneinfo/Europe/Ljubljana", + "/usr/share/zoneinfo/Europe/London", + "/usr/share/zoneinfo/Europe/Luxembourg", + "/usr/share/zoneinfo/Europe/Madrid", + "/usr/share/zoneinfo/Europe/Malta", + "/usr/share/zoneinfo/Europe/Mariehamn", + "/usr/share/zoneinfo/Europe/Minsk", + "/usr/share/zoneinfo/Europe/Monaco", + "/usr/share/zoneinfo/Europe/Moscow", + "/usr/share/zoneinfo/Europe/Nicosia", + "/usr/share/zoneinfo/Europe/Oslo", + "/usr/share/zoneinfo/Europe/Paris", + "/usr/share/zoneinfo/Europe/Podgorica", + "/usr/share/zoneinfo/Europe/Prague", + "/usr/share/zoneinfo/Europe/Riga", + "/usr/share/zoneinfo/Europe/Rome", + "/usr/share/zoneinfo/Europe/Samara", + "/usr/share/zoneinfo/Europe/San_Marino", + "/usr/share/zoneinfo/Europe/Sarajevo", + "/usr/share/zoneinfo/Europe/Saratov", + "/usr/share/zoneinfo/Europe/Simferopol", + "/usr/share/zoneinfo/Europe/Skopje", + "/usr/share/zoneinfo/Europe/Sofia", + "/usr/share/zoneinfo/Europe/Stockholm", + "/usr/share/zoneinfo/Europe/Tallinn", + "/usr/share/zoneinfo/Europe/Tirane", + "/usr/share/zoneinfo/Europe/Tiraspol", + "/usr/share/zoneinfo/Europe/Ulyanovsk", + "/usr/share/zoneinfo/Europe/Uzhgorod", + "/usr/share/zoneinfo/Europe/Vaduz", + "/usr/share/zoneinfo/Europe/Vatican", + "/usr/share/zoneinfo/Europe/Vienna", + "/usr/share/zoneinfo/Europe/Vilnius", + "/usr/share/zoneinfo/Europe/Volgograd", + "/usr/share/zoneinfo/Europe/Warsaw", + "/usr/share/zoneinfo/Europe/Zagreb", + "/usr/share/zoneinfo/Europe/Zaporozhye", + "/usr/share/zoneinfo/Europe/Zurich", + "/usr/share/zoneinfo/Factory", + "/usr/share/zoneinfo/GB", + "/usr/share/zoneinfo/GB-Eire", + "/usr/share/zoneinfo/GMT", + "/usr/share/zoneinfo/GMT+0", + "/usr/share/zoneinfo/GMT-0", + "/usr/share/zoneinfo/GMT0", + "/usr/share/zoneinfo/Greenwich", + "/usr/share/zoneinfo/HST", + "/usr/share/zoneinfo/Hongkong", + "/usr/share/zoneinfo/Iceland", + "/usr/share/zoneinfo/Indian", + "/usr/share/zoneinfo/Indian/Antananarivo", + "/usr/share/zoneinfo/Indian/Chagos", + "/usr/share/zoneinfo/Indian/Christmas", + "/usr/share/zoneinfo/Indian/Cocos", + "/usr/share/zoneinfo/Indian/Comoro", + "/usr/share/zoneinfo/Indian/Kerguelen", + "/usr/share/zoneinfo/Indian/Mahe", + "/usr/share/zoneinfo/Indian/Maldives", + "/usr/share/zoneinfo/Indian/Mauritius", + "/usr/share/zoneinfo/Indian/Mayotte", + "/usr/share/zoneinfo/Indian/Reunion", + "/usr/share/zoneinfo/Iran", + "/usr/share/zoneinfo/Israel", + "/usr/share/zoneinfo/Jamaica", + "/usr/share/zoneinfo/Japan", + "/usr/share/zoneinfo/Kwajalein", + "/usr/share/zoneinfo/Libya", + "/usr/share/zoneinfo/MET", + "/usr/share/zoneinfo/MST", + "/usr/share/zoneinfo/MST7MDT", + "/usr/share/zoneinfo/Mexico", + "/usr/share/zoneinfo/Mexico/BajaNorte", + "/usr/share/zoneinfo/Mexico/BajaSur", + "/usr/share/zoneinfo/Mexico/General", + "/usr/share/zoneinfo/NZ", + "/usr/share/zoneinfo/NZ-CHAT", + "/usr/share/zoneinfo/Navajo", + "/usr/share/zoneinfo/PRC", + "/usr/share/zoneinfo/PST8PDT", + "/usr/share/zoneinfo/Pacific", + "/usr/share/zoneinfo/Pacific/Apia", + "/usr/share/zoneinfo/Pacific/Auckland", + "/usr/share/zoneinfo/Pacific/Bougainville", + "/usr/share/zoneinfo/Pacific/Chatham", + "/usr/share/zoneinfo/Pacific/Chuuk", + "/usr/share/zoneinfo/Pacific/Easter", + "/usr/share/zoneinfo/Pacific/Efate", + "/usr/share/zoneinfo/Pacific/Enderbury", + "/usr/share/zoneinfo/Pacific/Fakaofo", + "/usr/share/zoneinfo/Pacific/Fiji", + "/usr/share/zoneinfo/Pacific/Funafuti", + "/usr/share/zoneinfo/Pacific/Galapagos", + "/usr/share/zoneinfo/Pacific/Gambier", + "/usr/share/zoneinfo/Pacific/Guadalcanal", + "/usr/share/zoneinfo/Pacific/Guam", + "/usr/share/zoneinfo/Pacific/Honolulu", + "/usr/share/zoneinfo/Pacific/Johnston", + "/usr/share/zoneinfo/Pacific/Kanton", + "/usr/share/zoneinfo/Pacific/Kiritimati", + "/usr/share/zoneinfo/Pacific/Kosrae", + "/usr/share/zoneinfo/Pacific/Kwajalein", + "/usr/share/zoneinfo/Pacific/Majuro", + "/usr/share/zoneinfo/Pacific/Marquesas", + "/usr/share/zoneinfo/Pacific/Midway", + "/usr/share/zoneinfo/Pacific/Nauru", + "/usr/share/zoneinfo/Pacific/Niue", + "/usr/share/zoneinfo/Pacific/Norfolk", + "/usr/share/zoneinfo/Pacific/Noumea", + "/usr/share/zoneinfo/Pacific/Pago_Pago", + "/usr/share/zoneinfo/Pacific/Palau", + "/usr/share/zoneinfo/Pacific/Pitcairn", + "/usr/share/zoneinfo/Pacific/Pohnpei", + "/usr/share/zoneinfo/Pacific/Ponape", + "/usr/share/zoneinfo/Pacific/Port_Moresby", + "/usr/share/zoneinfo/Pacific/Rarotonga", + "/usr/share/zoneinfo/Pacific/Saipan", + "/usr/share/zoneinfo/Pacific/Samoa", + "/usr/share/zoneinfo/Pacific/Tahiti", + "/usr/share/zoneinfo/Pacific/Tarawa", + "/usr/share/zoneinfo/Pacific/Tongatapu", + "/usr/share/zoneinfo/Pacific/Truk", + "/usr/share/zoneinfo/Pacific/Wake", + "/usr/share/zoneinfo/Pacific/Wallis", + "/usr/share/zoneinfo/Pacific/Yap", + "/usr/share/zoneinfo/Poland", + "/usr/share/zoneinfo/Portugal", + "/usr/share/zoneinfo/ROC", + "/usr/share/zoneinfo/ROK", + "/usr/share/zoneinfo/Singapore", + "/usr/share/zoneinfo/Turkey", + "/usr/share/zoneinfo/UCT", + "/usr/share/zoneinfo/US", + "/usr/share/zoneinfo/US/Alaska", + "/usr/share/zoneinfo/US/Aleutian", + "/usr/share/zoneinfo/US/Arizona", + "/usr/share/zoneinfo/US/Central", + "/usr/share/zoneinfo/US/East-Indiana", + "/usr/share/zoneinfo/US/Eastern", + "/usr/share/zoneinfo/US/Hawaii", + "/usr/share/zoneinfo/US/Indiana-Starke", + "/usr/share/zoneinfo/US/Michigan", + "/usr/share/zoneinfo/US/Mountain", + "/usr/share/zoneinfo/US/Pacific", + "/usr/share/zoneinfo/US/Samoa", + "/usr/share/zoneinfo/UTC", + "/usr/share/zoneinfo/Universal", + "/usr/share/zoneinfo/W-SU", + "/usr/share/zoneinfo/WET", + "/usr/share/zoneinfo/Zulu", + "/usr/share/zoneinfo/iso3166.tab", + "/usr/share/zoneinfo/leap-seconds.list", + "/usr/share/zoneinfo/leapseconds", + "/usr/share/zoneinfo/posix", + "/usr/share/zoneinfo/posix/Africa", + "/usr/share/zoneinfo/posix/Africa/Abidjan", + "/usr/share/zoneinfo/posix/Africa/Accra", + "/usr/share/zoneinfo/posix/Africa/Addis_Ababa", + "/usr/share/zoneinfo/posix/Africa/Algiers", + "/usr/share/zoneinfo/posix/Africa/Asmara", + "/usr/share/zoneinfo/posix/Africa/Asmera", + "/usr/share/zoneinfo/posix/Africa/Bamako", + "/usr/share/zoneinfo/posix/Africa/Bangui", + "/usr/share/zoneinfo/posix/Africa/Banjul", + "/usr/share/zoneinfo/posix/Africa/Bissau", + "/usr/share/zoneinfo/posix/Africa/Blantyre", + "/usr/share/zoneinfo/posix/Africa/Brazzaville", + "/usr/share/zoneinfo/posix/Africa/Bujumbura", + "/usr/share/zoneinfo/posix/Africa/Cairo", + "/usr/share/zoneinfo/posix/Africa/Casablanca", + "/usr/share/zoneinfo/posix/Africa/Ceuta", + "/usr/share/zoneinfo/posix/Africa/Conakry", + "/usr/share/zoneinfo/posix/Africa/Dakar", + "/usr/share/zoneinfo/posix/Africa/Dar_es_Salaam", + "/usr/share/zoneinfo/posix/Africa/Djibouti", + "/usr/share/zoneinfo/posix/Africa/Douala", + "/usr/share/zoneinfo/posix/Africa/El_Aaiun", + "/usr/share/zoneinfo/posix/Africa/Freetown", + "/usr/share/zoneinfo/posix/Africa/Gaborone", + "/usr/share/zoneinfo/posix/Africa/Harare", + "/usr/share/zoneinfo/posix/Africa/Johannesburg", + "/usr/share/zoneinfo/posix/Africa/Juba", + "/usr/share/zoneinfo/posix/Africa/Kampala", + "/usr/share/zoneinfo/posix/Africa/Khartoum", + "/usr/share/zoneinfo/posix/Africa/Kigali", + "/usr/share/zoneinfo/posix/Africa/Kinshasa", + "/usr/share/zoneinfo/posix/Africa/Lagos", + "/usr/share/zoneinfo/posix/Africa/Libreville", + "/usr/share/zoneinfo/posix/Africa/Lome", + "/usr/share/zoneinfo/posix/Africa/Luanda", + "/usr/share/zoneinfo/posix/Africa/Lubumbashi", + "/usr/share/zoneinfo/posix/Africa/Lusaka", + "/usr/share/zoneinfo/posix/Africa/Malabo", + "/usr/share/zoneinfo/posix/Africa/Maputo", + "/usr/share/zoneinfo/posix/Africa/Maseru", + "/usr/share/zoneinfo/posix/Africa/Mbabane", + "/usr/share/zoneinfo/posix/Africa/Mogadishu", + "/usr/share/zoneinfo/posix/Africa/Monrovia", + "/usr/share/zoneinfo/posix/Africa/Nairobi", + "/usr/share/zoneinfo/posix/Africa/Ndjamena", + "/usr/share/zoneinfo/posix/Africa/Niamey", + "/usr/share/zoneinfo/posix/Africa/Nouakchott", + "/usr/share/zoneinfo/posix/Africa/Ouagadougou", + "/usr/share/zoneinfo/posix/Africa/Porto-Novo", + "/usr/share/zoneinfo/posix/Africa/Sao_Tome", + "/usr/share/zoneinfo/posix/Africa/Timbuktu", + "/usr/share/zoneinfo/posix/Africa/Tripoli", + "/usr/share/zoneinfo/posix/Africa/Tunis", + "/usr/share/zoneinfo/posix/Africa/Windhoek", + "/usr/share/zoneinfo/posix/America", + "/usr/share/zoneinfo/posix/America/Adak", + "/usr/share/zoneinfo/posix/America/Anchorage", + "/usr/share/zoneinfo/posix/America/Anguilla", + "/usr/share/zoneinfo/posix/America/Antigua", + "/usr/share/zoneinfo/posix/America/Araguaina", + "/usr/share/zoneinfo/posix/America/Argentina", + "/usr/share/zoneinfo/posix/America/Argentina/Buenos_Aires", + "/usr/share/zoneinfo/posix/America/Argentina/Catamarca", + "/usr/share/zoneinfo/posix/America/Argentina/ComodRivadavia", + "/usr/share/zoneinfo/posix/America/Argentina/Cordoba", + "/usr/share/zoneinfo/posix/America/Argentina/Jujuy", + "/usr/share/zoneinfo/posix/America/Argentina/La_Rioja", + "/usr/share/zoneinfo/posix/America/Argentina/Mendoza", + "/usr/share/zoneinfo/posix/America/Argentina/Rio_Gallegos", + "/usr/share/zoneinfo/posix/America/Argentina/Salta", + "/usr/share/zoneinfo/posix/America/Argentina/San_Juan", + "/usr/share/zoneinfo/posix/America/Argentina/San_Luis", + "/usr/share/zoneinfo/posix/America/Argentina/Tucuman", + "/usr/share/zoneinfo/posix/America/Argentina/Ushuaia", + "/usr/share/zoneinfo/posix/America/Aruba", + "/usr/share/zoneinfo/posix/America/Asuncion", + "/usr/share/zoneinfo/posix/America/Atikokan", + "/usr/share/zoneinfo/posix/America/Atka", + "/usr/share/zoneinfo/posix/America/Bahia", + "/usr/share/zoneinfo/posix/America/Bahia_Banderas", + "/usr/share/zoneinfo/posix/America/Barbados", + "/usr/share/zoneinfo/posix/America/Belem", + "/usr/share/zoneinfo/posix/America/Belize", + "/usr/share/zoneinfo/posix/America/Blanc-Sablon", + "/usr/share/zoneinfo/posix/America/Boa_Vista", + "/usr/share/zoneinfo/posix/America/Bogota", + "/usr/share/zoneinfo/posix/America/Boise", + "/usr/share/zoneinfo/posix/America/Buenos_Aires", + "/usr/share/zoneinfo/posix/America/Cambridge_Bay", + "/usr/share/zoneinfo/posix/America/Campo_Grande", + "/usr/share/zoneinfo/posix/America/Cancun", + "/usr/share/zoneinfo/posix/America/Caracas", + "/usr/share/zoneinfo/posix/America/Catamarca", + "/usr/share/zoneinfo/posix/America/Cayenne", + "/usr/share/zoneinfo/posix/America/Cayman", + "/usr/share/zoneinfo/posix/America/Chicago", + "/usr/share/zoneinfo/posix/America/Chihuahua", + "/usr/share/zoneinfo/posix/America/Ciudad_Juarez", + "/usr/share/zoneinfo/posix/America/Coral_Harbour", + "/usr/share/zoneinfo/posix/America/Cordoba", + "/usr/share/zoneinfo/posix/America/Costa_Rica", + "/usr/share/zoneinfo/posix/America/Coyhaique", + "/usr/share/zoneinfo/posix/America/Creston", + "/usr/share/zoneinfo/posix/America/Cuiaba", + "/usr/share/zoneinfo/posix/America/Curacao", + "/usr/share/zoneinfo/posix/America/Danmarkshavn", + "/usr/share/zoneinfo/posix/America/Dawson", + "/usr/share/zoneinfo/posix/America/Dawson_Creek", + "/usr/share/zoneinfo/posix/America/Denver", + "/usr/share/zoneinfo/posix/America/Detroit", + "/usr/share/zoneinfo/posix/America/Dominica", + "/usr/share/zoneinfo/posix/America/Edmonton", + "/usr/share/zoneinfo/posix/America/Eirunepe", + "/usr/share/zoneinfo/posix/America/El_Salvador", + "/usr/share/zoneinfo/posix/America/Ensenada", + "/usr/share/zoneinfo/posix/America/Fort_Nelson", + "/usr/share/zoneinfo/posix/America/Fort_Wayne", + "/usr/share/zoneinfo/posix/America/Fortaleza", + "/usr/share/zoneinfo/posix/America/Glace_Bay", + "/usr/share/zoneinfo/posix/America/Godthab", + "/usr/share/zoneinfo/posix/America/Goose_Bay", + "/usr/share/zoneinfo/posix/America/Grand_Turk", + "/usr/share/zoneinfo/posix/America/Grenada", + "/usr/share/zoneinfo/posix/America/Guadeloupe", + "/usr/share/zoneinfo/posix/America/Guatemala", + "/usr/share/zoneinfo/posix/America/Guayaquil", + "/usr/share/zoneinfo/posix/America/Guyana", + "/usr/share/zoneinfo/posix/America/Halifax", + "/usr/share/zoneinfo/posix/America/Havana", + "/usr/share/zoneinfo/posix/America/Hermosillo", + "/usr/share/zoneinfo/posix/America/Indiana", + "/usr/share/zoneinfo/posix/America/Indiana/Indianapolis", + "/usr/share/zoneinfo/posix/America/Indiana/Knox", + "/usr/share/zoneinfo/posix/America/Indiana/Marengo", + "/usr/share/zoneinfo/posix/America/Indiana/Petersburg", + "/usr/share/zoneinfo/posix/America/Indiana/Tell_City", + "/usr/share/zoneinfo/posix/America/Indiana/Vevay", + "/usr/share/zoneinfo/posix/America/Indiana/Vincennes", + "/usr/share/zoneinfo/posix/America/Indiana/Winamac", + "/usr/share/zoneinfo/posix/America/Indianapolis", + "/usr/share/zoneinfo/posix/America/Inuvik", + "/usr/share/zoneinfo/posix/America/Iqaluit", + "/usr/share/zoneinfo/posix/America/Jamaica", + "/usr/share/zoneinfo/posix/America/Jujuy", + "/usr/share/zoneinfo/posix/America/Juneau", + "/usr/share/zoneinfo/posix/America/Kentucky", + "/usr/share/zoneinfo/posix/America/Kentucky/Louisville", + "/usr/share/zoneinfo/posix/America/Kentucky/Monticello", + "/usr/share/zoneinfo/posix/America/Knox_IN", + "/usr/share/zoneinfo/posix/America/Kralendijk", + "/usr/share/zoneinfo/posix/America/La_Paz", + "/usr/share/zoneinfo/posix/America/Lima", + "/usr/share/zoneinfo/posix/America/Los_Angeles", + "/usr/share/zoneinfo/posix/America/Louisville", + "/usr/share/zoneinfo/posix/America/Lower_Princes", + "/usr/share/zoneinfo/posix/America/Maceio", + "/usr/share/zoneinfo/posix/America/Managua", + "/usr/share/zoneinfo/posix/America/Manaus", + "/usr/share/zoneinfo/posix/America/Marigot", + "/usr/share/zoneinfo/posix/America/Martinique", + "/usr/share/zoneinfo/posix/America/Matamoros", + "/usr/share/zoneinfo/posix/America/Mazatlan", + "/usr/share/zoneinfo/posix/America/Mendoza", + "/usr/share/zoneinfo/posix/America/Menominee", + "/usr/share/zoneinfo/posix/America/Merida", + "/usr/share/zoneinfo/posix/America/Metlakatla", + "/usr/share/zoneinfo/posix/America/Mexico_City", + "/usr/share/zoneinfo/posix/America/Miquelon", + "/usr/share/zoneinfo/posix/America/Moncton", + "/usr/share/zoneinfo/posix/America/Monterrey", + "/usr/share/zoneinfo/posix/America/Montevideo", + "/usr/share/zoneinfo/posix/America/Montreal", + "/usr/share/zoneinfo/posix/America/Montserrat", + "/usr/share/zoneinfo/posix/America/Nassau", + "/usr/share/zoneinfo/posix/America/New_York", + "/usr/share/zoneinfo/posix/America/Nipigon", + "/usr/share/zoneinfo/posix/America/Nome", + "/usr/share/zoneinfo/posix/America/Noronha", + "/usr/share/zoneinfo/posix/America/North_Dakota", + "/usr/share/zoneinfo/posix/America/North_Dakota/Beulah", + "/usr/share/zoneinfo/posix/America/North_Dakota/Center", + "/usr/share/zoneinfo/posix/America/North_Dakota/New_Salem", + "/usr/share/zoneinfo/posix/America/Nuuk", + "/usr/share/zoneinfo/posix/America/Ojinaga", + "/usr/share/zoneinfo/posix/America/Panama", + "/usr/share/zoneinfo/posix/America/Pangnirtung", + "/usr/share/zoneinfo/posix/America/Paramaribo", + "/usr/share/zoneinfo/posix/America/Phoenix", + "/usr/share/zoneinfo/posix/America/Port-au-Prince", + "/usr/share/zoneinfo/posix/America/Port_of_Spain", + "/usr/share/zoneinfo/posix/America/Porto_Acre", + "/usr/share/zoneinfo/posix/America/Porto_Velho", + "/usr/share/zoneinfo/posix/America/Puerto_Rico", + "/usr/share/zoneinfo/posix/America/Punta_Arenas", + "/usr/share/zoneinfo/posix/America/Rainy_River", + "/usr/share/zoneinfo/posix/America/Rankin_Inlet", + "/usr/share/zoneinfo/posix/America/Recife", + "/usr/share/zoneinfo/posix/America/Regina", + "/usr/share/zoneinfo/posix/America/Resolute", + "/usr/share/zoneinfo/posix/America/Rio_Branco", + "/usr/share/zoneinfo/posix/America/Rosario", + "/usr/share/zoneinfo/posix/America/Santa_Isabel", + "/usr/share/zoneinfo/posix/America/Santarem", + "/usr/share/zoneinfo/posix/America/Santiago", + "/usr/share/zoneinfo/posix/America/Santo_Domingo", + "/usr/share/zoneinfo/posix/America/Sao_Paulo", + "/usr/share/zoneinfo/posix/America/Scoresbysund", + "/usr/share/zoneinfo/posix/America/Shiprock", + "/usr/share/zoneinfo/posix/America/Sitka", + "/usr/share/zoneinfo/posix/America/St_Barthelemy", + "/usr/share/zoneinfo/posix/America/St_Johns", + "/usr/share/zoneinfo/posix/America/St_Kitts", + "/usr/share/zoneinfo/posix/America/St_Lucia", + "/usr/share/zoneinfo/posix/America/St_Thomas", + "/usr/share/zoneinfo/posix/America/St_Vincent", + "/usr/share/zoneinfo/posix/America/Swift_Current", + "/usr/share/zoneinfo/posix/America/Tegucigalpa", + "/usr/share/zoneinfo/posix/America/Thule", + "/usr/share/zoneinfo/posix/America/Thunder_Bay", + "/usr/share/zoneinfo/posix/America/Tijuana", + "/usr/share/zoneinfo/posix/America/Toronto", + "/usr/share/zoneinfo/posix/America/Tortola", + "/usr/share/zoneinfo/posix/America/Vancouver", + "/usr/share/zoneinfo/posix/America/Virgin", + "/usr/share/zoneinfo/posix/America/Whitehorse", + "/usr/share/zoneinfo/posix/America/Winnipeg", + "/usr/share/zoneinfo/posix/America/Yakutat", + "/usr/share/zoneinfo/posix/America/Yellowknife", + "/usr/share/zoneinfo/posix/Antarctica", + "/usr/share/zoneinfo/posix/Antarctica/Casey", + "/usr/share/zoneinfo/posix/Antarctica/Davis", + "/usr/share/zoneinfo/posix/Antarctica/DumontDUrville", + "/usr/share/zoneinfo/posix/Antarctica/Macquarie", + "/usr/share/zoneinfo/posix/Antarctica/Mawson", + "/usr/share/zoneinfo/posix/Antarctica/McMurdo", + "/usr/share/zoneinfo/posix/Antarctica/Palmer", + "/usr/share/zoneinfo/posix/Antarctica/Rothera", + "/usr/share/zoneinfo/posix/Antarctica/South_Pole", + "/usr/share/zoneinfo/posix/Antarctica/Syowa", + "/usr/share/zoneinfo/posix/Antarctica/Troll", + "/usr/share/zoneinfo/posix/Antarctica/Vostok", + "/usr/share/zoneinfo/posix/Arctic", + "/usr/share/zoneinfo/posix/Arctic/Longyearbyen", + "/usr/share/zoneinfo/posix/Asia", + "/usr/share/zoneinfo/posix/Asia/Aden", + "/usr/share/zoneinfo/posix/Asia/Almaty", + "/usr/share/zoneinfo/posix/Asia/Amman", + "/usr/share/zoneinfo/posix/Asia/Anadyr", + "/usr/share/zoneinfo/posix/Asia/Aqtau", + "/usr/share/zoneinfo/posix/Asia/Aqtobe", + "/usr/share/zoneinfo/posix/Asia/Ashgabat", + "/usr/share/zoneinfo/posix/Asia/Ashkhabad", + "/usr/share/zoneinfo/posix/Asia/Atyrau", + "/usr/share/zoneinfo/posix/Asia/Baghdad", + "/usr/share/zoneinfo/posix/Asia/Bahrain", + "/usr/share/zoneinfo/posix/Asia/Baku", + "/usr/share/zoneinfo/posix/Asia/Bangkok", + "/usr/share/zoneinfo/posix/Asia/Barnaul", + "/usr/share/zoneinfo/posix/Asia/Beirut", + "/usr/share/zoneinfo/posix/Asia/Bishkek", + "/usr/share/zoneinfo/posix/Asia/Brunei", + "/usr/share/zoneinfo/posix/Asia/Calcutta", + "/usr/share/zoneinfo/posix/Asia/Chita", + "/usr/share/zoneinfo/posix/Asia/Choibalsan", + "/usr/share/zoneinfo/posix/Asia/Chongqing", + "/usr/share/zoneinfo/posix/Asia/Chungking", + "/usr/share/zoneinfo/posix/Asia/Colombo", + "/usr/share/zoneinfo/posix/Asia/Dacca", + "/usr/share/zoneinfo/posix/Asia/Damascus", + "/usr/share/zoneinfo/posix/Asia/Dhaka", + "/usr/share/zoneinfo/posix/Asia/Dili", + "/usr/share/zoneinfo/posix/Asia/Dubai", + "/usr/share/zoneinfo/posix/Asia/Dushanbe", + "/usr/share/zoneinfo/posix/Asia/Famagusta", + "/usr/share/zoneinfo/posix/Asia/Gaza", + "/usr/share/zoneinfo/posix/Asia/Harbin", + "/usr/share/zoneinfo/posix/Asia/Hebron", + "/usr/share/zoneinfo/posix/Asia/Ho_Chi_Minh", + "/usr/share/zoneinfo/posix/Asia/Hong_Kong", + "/usr/share/zoneinfo/posix/Asia/Hovd", + "/usr/share/zoneinfo/posix/Asia/Irkutsk", + "/usr/share/zoneinfo/posix/Asia/Istanbul", + "/usr/share/zoneinfo/posix/Asia/Jakarta", + "/usr/share/zoneinfo/posix/Asia/Jayapura", + "/usr/share/zoneinfo/posix/Asia/Jerusalem", + "/usr/share/zoneinfo/posix/Asia/Kabul", + "/usr/share/zoneinfo/posix/Asia/Kamchatka", + "/usr/share/zoneinfo/posix/Asia/Karachi", + "/usr/share/zoneinfo/posix/Asia/Kashgar", + "/usr/share/zoneinfo/posix/Asia/Kathmandu", + "/usr/share/zoneinfo/posix/Asia/Katmandu", + "/usr/share/zoneinfo/posix/Asia/Khandyga", + "/usr/share/zoneinfo/posix/Asia/Kolkata", + "/usr/share/zoneinfo/posix/Asia/Krasnoyarsk", + "/usr/share/zoneinfo/posix/Asia/Kuala_Lumpur", + "/usr/share/zoneinfo/posix/Asia/Kuching", + "/usr/share/zoneinfo/posix/Asia/Kuwait", + "/usr/share/zoneinfo/posix/Asia/Macao", + "/usr/share/zoneinfo/posix/Asia/Macau", + "/usr/share/zoneinfo/posix/Asia/Magadan", + "/usr/share/zoneinfo/posix/Asia/Makassar", + "/usr/share/zoneinfo/posix/Asia/Manila", + "/usr/share/zoneinfo/posix/Asia/Muscat", + "/usr/share/zoneinfo/posix/Asia/Nicosia", + "/usr/share/zoneinfo/posix/Asia/Novokuznetsk", + "/usr/share/zoneinfo/posix/Asia/Novosibirsk", + "/usr/share/zoneinfo/posix/Asia/Omsk", + "/usr/share/zoneinfo/posix/Asia/Oral", + "/usr/share/zoneinfo/posix/Asia/Phnom_Penh", + "/usr/share/zoneinfo/posix/Asia/Pontianak", + "/usr/share/zoneinfo/posix/Asia/Pyongyang", + "/usr/share/zoneinfo/posix/Asia/Qatar", + "/usr/share/zoneinfo/posix/Asia/Qostanay", + "/usr/share/zoneinfo/posix/Asia/Qyzylorda", + "/usr/share/zoneinfo/posix/Asia/Rangoon", + "/usr/share/zoneinfo/posix/Asia/Riyadh", + "/usr/share/zoneinfo/posix/Asia/Saigon", + "/usr/share/zoneinfo/posix/Asia/Sakhalin", + "/usr/share/zoneinfo/posix/Asia/Samarkand", + "/usr/share/zoneinfo/posix/Asia/Seoul", + "/usr/share/zoneinfo/posix/Asia/Shanghai", + "/usr/share/zoneinfo/posix/Asia/Singapore", + "/usr/share/zoneinfo/posix/Asia/Srednekolymsk", + "/usr/share/zoneinfo/posix/Asia/Taipei", + "/usr/share/zoneinfo/posix/Asia/Tashkent", + "/usr/share/zoneinfo/posix/Asia/Tbilisi", + "/usr/share/zoneinfo/posix/Asia/Tehran", + "/usr/share/zoneinfo/posix/Asia/Tel_Aviv", + "/usr/share/zoneinfo/posix/Asia/Thimbu", + "/usr/share/zoneinfo/posix/Asia/Thimphu", + "/usr/share/zoneinfo/posix/Asia/Tokyo", + "/usr/share/zoneinfo/posix/Asia/Tomsk", + "/usr/share/zoneinfo/posix/Asia/Ujung_Pandang", + "/usr/share/zoneinfo/posix/Asia/Ulaanbaatar", + "/usr/share/zoneinfo/posix/Asia/Ulan_Bator", + "/usr/share/zoneinfo/posix/Asia/Urumqi", + "/usr/share/zoneinfo/posix/Asia/Ust-Nera", + "/usr/share/zoneinfo/posix/Asia/Vientiane", + "/usr/share/zoneinfo/posix/Asia/Vladivostok", + "/usr/share/zoneinfo/posix/Asia/Yakutsk", + "/usr/share/zoneinfo/posix/Asia/Yangon", + "/usr/share/zoneinfo/posix/Asia/Yekaterinburg", + "/usr/share/zoneinfo/posix/Asia/Yerevan", + "/usr/share/zoneinfo/posix/Atlantic", + "/usr/share/zoneinfo/posix/Atlantic/Azores", + "/usr/share/zoneinfo/posix/Atlantic/Bermuda", + "/usr/share/zoneinfo/posix/Atlantic/Canary", + "/usr/share/zoneinfo/posix/Atlantic/Cape_Verde", + "/usr/share/zoneinfo/posix/Atlantic/Faeroe", + "/usr/share/zoneinfo/posix/Atlantic/Faroe", + "/usr/share/zoneinfo/posix/Atlantic/Jan_Mayen", + "/usr/share/zoneinfo/posix/Atlantic/Madeira", + "/usr/share/zoneinfo/posix/Atlantic/Reykjavik", + "/usr/share/zoneinfo/posix/Atlantic/South_Georgia", + "/usr/share/zoneinfo/posix/Atlantic/St_Helena", + "/usr/share/zoneinfo/posix/Atlantic/Stanley", + "/usr/share/zoneinfo/posix/Australia", + "/usr/share/zoneinfo/posix/Australia/ACT", + "/usr/share/zoneinfo/posix/Australia/Adelaide", + "/usr/share/zoneinfo/posix/Australia/Brisbane", + "/usr/share/zoneinfo/posix/Australia/Broken_Hill", + "/usr/share/zoneinfo/posix/Australia/Canberra", + "/usr/share/zoneinfo/posix/Australia/Currie", + "/usr/share/zoneinfo/posix/Australia/Darwin", + "/usr/share/zoneinfo/posix/Australia/Eucla", + "/usr/share/zoneinfo/posix/Australia/Hobart", + "/usr/share/zoneinfo/posix/Australia/LHI", + "/usr/share/zoneinfo/posix/Australia/Lindeman", + "/usr/share/zoneinfo/posix/Australia/Lord_Howe", + "/usr/share/zoneinfo/posix/Australia/Melbourne", + "/usr/share/zoneinfo/posix/Australia/NSW", + "/usr/share/zoneinfo/posix/Australia/North", + "/usr/share/zoneinfo/posix/Australia/Perth", + "/usr/share/zoneinfo/posix/Australia/Queensland", + "/usr/share/zoneinfo/posix/Australia/South", + "/usr/share/zoneinfo/posix/Australia/Sydney", + "/usr/share/zoneinfo/posix/Australia/Tasmania", + "/usr/share/zoneinfo/posix/Australia/Victoria", + "/usr/share/zoneinfo/posix/Australia/West", + "/usr/share/zoneinfo/posix/Australia/Yancowinna", + "/usr/share/zoneinfo/posix/Brazil", + "/usr/share/zoneinfo/posix/Brazil/Acre", + "/usr/share/zoneinfo/posix/Brazil/DeNoronha", + "/usr/share/zoneinfo/posix/Brazil/East", + "/usr/share/zoneinfo/posix/Brazil/West", + "/usr/share/zoneinfo/posix/CET", + "/usr/share/zoneinfo/posix/CST6CDT", + "/usr/share/zoneinfo/posix/Canada", + "/usr/share/zoneinfo/posix/Canada/Atlantic", + "/usr/share/zoneinfo/posix/Canada/Central", + "/usr/share/zoneinfo/posix/Canada/Eastern", + "/usr/share/zoneinfo/posix/Canada/Mountain", + "/usr/share/zoneinfo/posix/Canada/Newfoundland", + "/usr/share/zoneinfo/posix/Canada/Pacific", + "/usr/share/zoneinfo/posix/Canada/Saskatchewan", + "/usr/share/zoneinfo/posix/Canada/Yukon", + "/usr/share/zoneinfo/posix/Chile", + "/usr/share/zoneinfo/posix/Chile/Continental", + "/usr/share/zoneinfo/posix/Chile/EasterIsland", + "/usr/share/zoneinfo/posix/Cuba", + "/usr/share/zoneinfo/posix/EET", + "/usr/share/zoneinfo/posix/EST", + "/usr/share/zoneinfo/posix/EST5EDT", + "/usr/share/zoneinfo/posix/Egypt", + "/usr/share/zoneinfo/posix/Eire", + "/usr/share/zoneinfo/posix/Etc", + "/usr/share/zoneinfo/posix/Etc/GMT", + "/usr/share/zoneinfo/posix/Etc/GMT+0", + "/usr/share/zoneinfo/posix/Etc/GMT+1", + "/usr/share/zoneinfo/posix/Etc/GMT+10", + "/usr/share/zoneinfo/posix/Etc/GMT+11", + "/usr/share/zoneinfo/posix/Etc/GMT+12", + "/usr/share/zoneinfo/posix/Etc/GMT+2", + "/usr/share/zoneinfo/posix/Etc/GMT+3", + "/usr/share/zoneinfo/posix/Etc/GMT+4", + "/usr/share/zoneinfo/posix/Etc/GMT+5", + "/usr/share/zoneinfo/posix/Etc/GMT+6", + "/usr/share/zoneinfo/posix/Etc/GMT+7", + "/usr/share/zoneinfo/posix/Etc/GMT+8", + "/usr/share/zoneinfo/posix/Etc/GMT+9", + "/usr/share/zoneinfo/posix/Etc/GMT-0", + "/usr/share/zoneinfo/posix/Etc/GMT-1", + "/usr/share/zoneinfo/posix/Etc/GMT-10", + "/usr/share/zoneinfo/posix/Etc/GMT-11", + "/usr/share/zoneinfo/posix/Etc/GMT-12", + "/usr/share/zoneinfo/posix/Etc/GMT-13", + "/usr/share/zoneinfo/posix/Etc/GMT-14", + "/usr/share/zoneinfo/posix/Etc/GMT-2", + "/usr/share/zoneinfo/posix/Etc/GMT-3", + "/usr/share/zoneinfo/posix/Etc/GMT-4", + "/usr/share/zoneinfo/posix/Etc/GMT-5", + "/usr/share/zoneinfo/posix/Etc/GMT-6", + "/usr/share/zoneinfo/posix/Etc/GMT-7", + "/usr/share/zoneinfo/posix/Etc/GMT-8", + "/usr/share/zoneinfo/posix/Etc/GMT-9", + "/usr/share/zoneinfo/posix/Etc/GMT0", + "/usr/share/zoneinfo/posix/Etc/Greenwich", + "/usr/share/zoneinfo/posix/Etc/UCT", + "/usr/share/zoneinfo/posix/Etc/UTC", + "/usr/share/zoneinfo/posix/Etc/Universal", + "/usr/share/zoneinfo/posix/Etc/Zulu", + "/usr/share/zoneinfo/posix/Europe", + "/usr/share/zoneinfo/posix/Europe/Amsterdam", + "/usr/share/zoneinfo/posix/Europe/Andorra", + "/usr/share/zoneinfo/posix/Europe/Astrakhan", + "/usr/share/zoneinfo/posix/Europe/Athens", + "/usr/share/zoneinfo/posix/Europe/Belfast", + "/usr/share/zoneinfo/posix/Europe/Belgrade", + "/usr/share/zoneinfo/posix/Europe/Berlin", + "/usr/share/zoneinfo/posix/Europe/Bratislava", + "/usr/share/zoneinfo/posix/Europe/Brussels", + "/usr/share/zoneinfo/posix/Europe/Bucharest", + "/usr/share/zoneinfo/posix/Europe/Budapest", + "/usr/share/zoneinfo/posix/Europe/Busingen", + "/usr/share/zoneinfo/posix/Europe/Chisinau", + "/usr/share/zoneinfo/posix/Europe/Copenhagen", + "/usr/share/zoneinfo/posix/Europe/Dublin", + "/usr/share/zoneinfo/posix/Europe/Gibraltar", + "/usr/share/zoneinfo/posix/Europe/Guernsey", + "/usr/share/zoneinfo/posix/Europe/Helsinki", + "/usr/share/zoneinfo/posix/Europe/Isle_of_Man", + "/usr/share/zoneinfo/posix/Europe/Istanbul", + "/usr/share/zoneinfo/posix/Europe/Jersey", + "/usr/share/zoneinfo/posix/Europe/Kaliningrad", + "/usr/share/zoneinfo/posix/Europe/Kiev", + "/usr/share/zoneinfo/posix/Europe/Kirov", + "/usr/share/zoneinfo/posix/Europe/Kyiv", + "/usr/share/zoneinfo/posix/Europe/Lisbon", + "/usr/share/zoneinfo/posix/Europe/Ljubljana", + "/usr/share/zoneinfo/posix/Europe/London", + "/usr/share/zoneinfo/posix/Europe/Luxembourg", + "/usr/share/zoneinfo/posix/Europe/Madrid", + "/usr/share/zoneinfo/posix/Europe/Malta", + "/usr/share/zoneinfo/posix/Europe/Mariehamn", + "/usr/share/zoneinfo/posix/Europe/Minsk", + "/usr/share/zoneinfo/posix/Europe/Monaco", + "/usr/share/zoneinfo/posix/Europe/Moscow", + "/usr/share/zoneinfo/posix/Europe/Nicosia", + "/usr/share/zoneinfo/posix/Europe/Oslo", + "/usr/share/zoneinfo/posix/Europe/Paris", + "/usr/share/zoneinfo/posix/Europe/Podgorica", + "/usr/share/zoneinfo/posix/Europe/Prague", + "/usr/share/zoneinfo/posix/Europe/Riga", + "/usr/share/zoneinfo/posix/Europe/Rome", + "/usr/share/zoneinfo/posix/Europe/Samara", + "/usr/share/zoneinfo/posix/Europe/San_Marino", + "/usr/share/zoneinfo/posix/Europe/Sarajevo", + "/usr/share/zoneinfo/posix/Europe/Saratov", + "/usr/share/zoneinfo/posix/Europe/Simferopol", + "/usr/share/zoneinfo/posix/Europe/Skopje", + "/usr/share/zoneinfo/posix/Europe/Sofia", + "/usr/share/zoneinfo/posix/Europe/Stockholm", + "/usr/share/zoneinfo/posix/Europe/Tallinn", + "/usr/share/zoneinfo/posix/Europe/Tirane", + "/usr/share/zoneinfo/posix/Europe/Tiraspol", + "/usr/share/zoneinfo/posix/Europe/Ulyanovsk", + "/usr/share/zoneinfo/posix/Europe/Uzhgorod", + "/usr/share/zoneinfo/posix/Europe/Vaduz", + "/usr/share/zoneinfo/posix/Europe/Vatican", + "/usr/share/zoneinfo/posix/Europe/Vienna", + "/usr/share/zoneinfo/posix/Europe/Vilnius", + "/usr/share/zoneinfo/posix/Europe/Volgograd", + "/usr/share/zoneinfo/posix/Europe/Warsaw", + "/usr/share/zoneinfo/posix/Europe/Zagreb", + "/usr/share/zoneinfo/posix/Europe/Zaporozhye", + "/usr/share/zoneinfo/posix/Europe/Zurich", + "/usr/share/zoneinfo/posix/Factory", + "/usr/share/zoneinfo/posix/GB", + "/usr/share/zoneinfo/posix/GB-Eire", + "/usr/share/zoneinfo/posix/GMT", + "/usr/share/zoneinfo/posix/GMT+0", + "/usr/share/zoneinfo/posix/GMT-0", + "/usr/share/zoneinfo/posix/GMT0", + "/usr/share/zoneinfo/posix/Greenwich", + "/usr/share/zoneinfo/posix/HST", + "/usr/share/zoneinfo/posix/Hongkong", + "/usr/share/zoneinfo/posix/Iceland", + "/usr/share/zoneinfo/posix/Indian", + "/usr/share/zoneinfo/posix/Indian/Antananarivo", + "/usr/share/zoneinfo/posix/Indian/Chagos", + "/usr/share/zoneinfo/posix/Indian/Christmas", + "/usr/share/zoneinfo/posix/Indian/Cocos", + "/usr/share/zoneinfo/posix/Indian/Comoro", + "/usr/share/zoneinfo/posix/Indian/Kerguelen", + "/usr/share/zoneinfo/posix/Indian/Mahe", + "/usr/share/zoneinfo/posix/Indian/Maldives", + "/usr/share/zoneinfo/posix/Indian/Mauritius", + "/usr/share/zoneinfo/posix/Indian/Mayotte", + "/usr/share/zoneinfo/posix/Indian/Reunion", + "/usr/share/zoneinfo/posix/Iran", + "/usr/share/zoneinfo/posix/Israel", + "/usr/share/zoneinfo/posix/Jamaica", + "/usr/share/zoneinfo/posix/Japan", + "/usr/share/zoneinfo/posix/Kwajalein", + "/usr/share/zoneinfo/posix/Libya", + "/usr/share/zoneinfo/posix/MET", + "/usr/share/zoneinfo/posix/MST", + "/usr/share/zoneinfo/posix/MST7MDT", + "/usr/share/zoneinfo/posix/Mexico", + "/usr/share/zoneinfo/posix/Mexico/BajaNorte", + "/usr/share/zoneinfo/posix/Mexico/BajaSur", + "/usr/share/zoneinfo/posix/Mexico/General", + "/usr/share/zoneinfo/posix/NZ", + "/usr/share/zoneinfo/posix/NZ-CHAT", + "/usr/share/zoneinfo/posix/Navajo", + "/usr/share/zoneinfo/posix/PRC", + "/usr/share/zoneinfo/posix/PST8PDT", + "/usr/share/zoneinfo/posix/Pacific", + "/usr/share/zoneinfo/posix/Pacific/Apia", + "/usr/share/zoneinfo/posix/Pacific/Auckland", + "/usr/share/zoneinfo/posix/Pacific/Bougainville", + "/usr/share/zoneinfo/posix/Pacific/Chatham", + "/usr/share/zoneinfo/posix/Pacific/Chuuk", + "/usr/share/zoneinfo/posix/Pacific/Easter", + "/usr/share/zoneinfo/posix/Pacific/Efate", + "/usr/share/zoneinfo/posix/Pacific/Enderbury", + "/usr/share/zoneinfo/posix/Pacific/Fakaofo", + "/usr/share/zoneinfo/posix/Pacific/Fiji", + "/usr/share/zoneinfo/posix/Pacific/Funafuti", + "/usr/share/zoneinfo/posix/Pacific/Galapagos", + "/usr/share/zoneinfo/posix/Pacific/Gambier", + "/usr/share/zoneinfo/posix/Pacific/Guadalcanal", + "/usr/share/zoneinfo/posix/Pacific/Guam", + "/usr/share/zoneinfo/posix/Pacific/Honolulu", + "/usr/share/zoneinfo/posix/Pacific/Johnston", + "/usr/share/zoneinfo/posix/Pacific/Kanton", + "/usr/share/zoneinfo/posix/Pacific/Kiritimati", + "/usr/share/zoneinfo/posix/Pacific/Kosrae", + "/usr/share/zoneinfo/posix/Pacific/Kwajalein", + "/usr/share/zoneinfo/posix/Pacific/Majuro", + "/usr/share/zoneinfo/posix/Pacific/Marquesas", + "/usr/share/zoneinfo/posix/Pacific/Midway", + "/usr/share/zoneinfo/posix/Pacific/Nauru", + "/usr/share/zoneinfo/posix/Pacific/Niue", + "/usr/share/zoneinfo/posix/Pacific/Norfolk", + "/usr/share/zoneinfo/posix/Pacific/Noumea", + "/usr/share/zoneinfo/posix/Pacific/Pago_Pago", + "/usr/share/zoneinfo/posix/Pacific/Palau", + "/usr/share/zoneinfo/posix/Pacific/Pitcairn", + "/usr/share/zoneinfo/posix/Pacific/Pohnpei", + "/usr/share/zoneinfo/posix/Pacific/Ponape", + "/usr/share/zoneinfo/posix/Pacific/Port_Moresby", + "/usr/share/zoneinfo/posix/Pacific/Rarotonga", + "/usr/share/zoneinfo/posix/Pacific/Saipan", + "/usr/share/zoneinfo/posix/Pacific/Samoa", + "/usr/share/zoneinfo/posix/Pacific/Tahiti", + "/usr/share/zoneinfo/posix/Pacific/Tarawa", + "/usr/share/zoneinfo/posix/Pacific/Tongatapu", + "/usr/share/zoneinfo/posix/Pacific/Truk", + "/usr/share/zoneinfo/posix/Pacific/Wake", + "/usr/share/zoneinfo/posix/Pacific/Wallis", + "/usr/share/zoneinfo/posix/Pacific/Yap", + "/usr/share/zoneinfo/posix/Poland", + "/usr/share/zoneinfo/posix/Portugal", + "/usr/share/zoneinfo/posix/ROC", + "/usr/share/zoneinfo/posix/ROK", + "/usr/share/zoneinfo/posix/Singapore", + "/usr/share/zoneinfo/posix/Turkey", + "/usr/share/zoneinfo/posix/UCT", + "/usr/share/zoneinfo/posix/US", + "/usr/share/zoneinfo/posix/US/Alaska", + "/usr/share/zoneinfo/posix/US/Aleutian", + "/usr/share/zoneinfo/posix/US/Arizona", + "/usr/share/zoneinfo/posix/US/Central", + "/usr/share/zoneinfo/posix/US/East-Indiana", + "/usr/share/zoneinfo/posix/US/Eastern", + "/usr/share/zoneinfo/posix/US/Hawaii", + "/usr/share/zoneinfo/posix/US/Indiana-Starke", + "/usr/share/zoneinfo/posix/US/Michigan", + "/usr/share/zoneinfo/posix/US/Mountain", + "/usr/share/zoneinfo/posix/US/Pacific", + "/usr/share/zoneinfo/posix/US/Samoa", + "/usr/share/zoneinfo/posix/UTC", + "/usr/share/zoneinfo/posix/Universal", + "/usr/share/zoneinfo/posix/W-SU", + "/usr/share/zoneinfo/posix/WET", + "/usr/share/zoneinfo/posix/Zulu", + "/usr/share/zoneinfo/posixrules", + "/usr/share/zoneinfo/right", + "/usr/share/zoneinfo/right/Africa", + "/usr/share/zoneinfo/right/Africa/Abidjan", + "/usr/share/zoneinfo/right/Africa/Accra", + "/usr/share/zoneinfo/right/Africa/Addis_Ababa", + "/usr/share/zoneinfo/right/Africa/Algiers", + "/usr/share/zoneinfo/right/Africa/Asmara", + "/usr/share/zoneinfo/right/Africa/Asmera", + "/usr/share/zoneinfo/right/Africa/Bamako", + "/usr/share/zoneinfo/right/Africa/Bangui", + "/usr/share/zoneinfo/right/Africa/Banjul", + "/usr/share/zoneinfo/right/Africa/Bissau", + "/usr/share/zoneinfo/right/Africa/Blantyre", + "/usr/share/zoneinfo/right/Africa/Brazzaville", + "/usr/share/zoneinfo/right/Africa/Bujumbura", + "/usr/share/zoneinfo/right/Africa/Cairo", + "/usr/share/zoneinfo/right/Africa/Casablanca", + "/usr/share/zoneinfo/right/Africa/Ceuta", + "/usr/share/zoneinfo/right/Africa/Conakry", + "/usr/share/zoneinfo/right/Africa/Dakar", + "/usr/share/zoneinfo/right/Africa/Dar_es_Salaam", + "/usr/share/zoneinfo/right/Africa/Djibouti", + "/usr/share/zoneinfo/right/Africa/Douala", + "/usr/share/zoneinfo/right/Africa/El_Aaiun", + "/usr/share/zoneinfo/right/Africa/Freetown", + "/usr/share/zoneinfo/right/Africa/Gaborone", + "/usr/share/zoneinfo/right/Africa/Harare", + "/usr/share/zoneinfo/right/Africa/Johannesburg", + "/usr/share/zoneinfo/right/Africa/Juba", + "/usr/share/zoneinfo/right/Africa/Kampala", + "/usr/share/zoneinfo/right/Africa/Khartoum", + "/usr/share/zoneinfo/right/Africa/Kigali", + "/usr/share/zoneinfo/right/Africa/Kinshasa", + "/usr/share/zoneinfo/right/Africa/Lagos", + "/usr/share/zoneinfo/right/Africa/Libreville", + "/usr/share/zoneinfo/right/Africa/Lome", + "/usr/share/zoneinfo/right/Africa/Luanda", + "/usr/share/zoneinfo/right/Africa/Lubumbashi", + "/usr/share/zoneinfo/right/Africa/Lusaka", + "/usr/share/zoneinfo/right/Africa/Malabo", + "/usr/share/zoneinfo/right/Africa/Maputo", + "/usr/share/zoneinfo/right/Africa/Maseru", + "/usr/share/zoneinfo/right/Africa/Mbabane", + "/usr/share/zoneinfo/right/Africa/Mogadishu", + "/usr/share/zoneinfo/right/Africa/Monrovia", + "/usr/share/zoneinfo/right/Africa/Nairobi", + "/usr/share/zoneinfo/right/Africa/Ndjamena", + "/usr/share/zoneinfo/right/Africa/Niamey", + "/usr/share/zoneinfo/right/Africa/Nouakchott", + "/usr/share/zoneinfo/right/Africa/Ouagadougou", + "/usr/share/zoneinfo/right/Africa/Porto-Novo", + "/usr/share/zoneinfo/right/Africa/Sao_Tome", + "/usr/share/zoneinfo/right/Africa/Timbuktu", + "/usr/share/zoneinfo/right/Africa/Tripoli", + "/usr/share/zoneinfo/right/Africa/Tunis", + "/usr/share/zoneinfo/right/Africa/Windhoek", + "/usr/share/zoneinfo/right/America", + "/usr/share/zoneinfo/right/America/Adak", + "/usr/share/zoneinfo/right/America/Anchorage", + "/usr/share/zoneinfo/right/America/Anguilla", + "/usr/share/zoneinfo/right/America/Antigua", + "/usr/share/zoneinfo/right/America/Araguaina", + "/usr/share/zoneinfo/right/America/Argentina", + "/usr/share/zoneinfo/right/America/Argentina/Buenos_Aires", + "/usr/share/zoneinfo/right/America/Argentina/Catamarca", + "/usr/share/zoneinfo/right/America/Argentina/ComodRivadavia", + "/usr/share/zoneinfo/right/America/Argentina/Cordoba", + "/usr/share/zoneinfo/right/America/Argentina/Jujuy", + "/usr/share/zoneinfo/right/America/Argentina/La_Rioja", + "/usr/share/zoneinfo/right/America/Argentina/Mendoza", + "/usr/share/zoneinfo/right/America/Argentina/Rio_Gallegos", + "/usr/share/zoneinfo/right/America/Argentina/Salta", + "/usr/share/zoneinfo/right/America/Argentina/San_Juan", + "/usr/share/zoneinfo/right/America/Argentina/San_Luis", + "/usr/share/zoneinfo/right/America/Argentina/Tucuman", + "/usr/share/zoneinfo/right/America/Argentina/Ushuaia", + "/usr/share/zoneinfo/right/America/Aruba", + "/usr/share/zoneinfo/right/America/Asuncion", + "/usr/share/zoneinfo/right/America/Atikokan", + "/usr/share/zoneinfo/right/America/Atka", + "/usr/share/zoneinfo/right/America/Bahia", + "/usr/share/zoneinfo/right/America/Bahia_Banderas", + "/usr/share/zoneinfo/right/America/Barbados", + "/usr/share/zoneinfo/right/America/Belem", + "/usr/share/zoneinfo/right/America/Belize", + "/usr/share/zoneinfo/right/America/Blanc-Sablon", + "/usr/share/zoneinfo/right/America/Boa_Vista", + "/usr/share/zoneinfo/right/America/Bogota", + "/usr/share/zoneinfo/right/America/Boise", + "/usr/share/zoneinfo/right/America/Buenos_Aires", + "/usr/share/zoneinfo/right/America/Cambridge_Bay", + "/usr/share/zoneinfo/right/America/Campo_Grande", + "/usr/share/zoneinfo/right/America/Cancun", + "/usr/share/zoneinfo/right/America/Caracas", + "/usr/share/zoneinfo/right/America/Catamarca", + "/usr/share/zoneinfo/right/America/Cayenne", + "/usr/share/zoneinfo/right/America/Cayman", + "/usr/share/zoneinfo/right/America/Chicago", + "/usr/share/zoneinfo/right/America/Chihuahua", + "/usr/share/zoneinfo/right/America/Ciudad_Juarez", + "/usr/share/zoneinfo/right/America/Coral_Harbour", + "/usr/share/zoneinfo/right/America/Cordoba", + "/usr/share/zoneinfo/right/America/Costa_Rica", + "/usr/share/zoneinfo/right/America/Coyhaique", + "/usr/share/zoneinfo/right/America/Creston", + "/usr/share/zoneinfo/right/America/Cuiaba", + "/usr/share/zoneinfo/right/America/Curacao", + "/usr/share/zoneinfo/right/America/Danmarkshavn", + "/usr/share/zoneinfo/right/America/Dawson", + "/usr/share/zoneinfo/right/America/Dawson_Creek", + "/usr/share/zoneinfo/right/America/Denver", + "/usr/share/zoneinfo/right/America/Detroit", + "/usr/share/zoneinfo/right/America/Dominica", + "/usr/share/zoneinfo/right/America/Edmonton", + "/usr/share/zoneinfo/right/America/Eirunepe", + "/usr/share/zoneinfo/right/America/El_Salvador", + "/usr/share/zoneinfo/right/America/Ensenada", + "/usr/share/zoneinfo/right/America/Fort_Nelson", + "/usr/share/zoneinfo/right/America/Fort_Wayne", + "/usr/share/zoneinfo/right/America/Fortaleza", + "/usr/share/zoneinfo/right/America/Glace_Bay", + "/usr/share/zoneinfo/right/America/Godthab", + "/usr/share/zoneinfo/right/America/Goose_Bay", + "/usr/share/zoneinfo/right/America/Grand_Turk", + "/usr/share/zoneinfo/right/America/Grenada", + "/usr/share/zoneinfo/right/America/Guadeloupe", + "/usr/share/zoneinfo/right/America/Guatemala", + "/usr/share/zoneinfo/right/America/Guayaquil", + "/usr/share/zoneinfo/right/America/Guyana", + "/usr/share/zoneinfo/right/America/Halifax", + "/usr/share/zoneinfo/right/America/Havana", + "/usr/share/zoneinfo/right/America/Hermosillo", + "/usr/share/zoneinfo/right/America/Indiana", + "/usr/share/zoneinfo/right/America/Indiana/Indianapolis", + "/usr/share/zoneinfo/right/America/Indiana/Knox", + "/usr/share/zoneinfo/right/America/Indiana/Marengo", + "/usr/share/zoneinfo/right/America/Indiana/Petersburg", + "/usr/share/zoneinfo/right/America/Indiana/Tell_City", + "/usr/share/zoneinfo/right/America/Indiana/Vevay", + "/usr/share/zoneinfo/right/America/Indiana/Vincennes", + "/usr/share/zoneinfo/right/America/Indiana/Winamac", + "/usr/share/zoneinfo/right/America/Indianapolis", + "/usr/share/zoneinfo/right/America/Inuvik", + "/usr/share/zoneinfo/right/America/Iqaluit", + "/usr/share/zoneinfo/right/America/Jamaica", + "/usr/share/zoneinfo/right/America/Jujuy", + "/usr/share/zoneinfo/right/America/Juneau", + "/usr/share/zoneinfo/right/America/Kentucky", + "/usr/share/zoneinfo/right/America/Kentucky/Louisville", + "/usr/share/zoneinfo/right/America/Kentucky/Monticello", + "/usr/share/zoneinfo/right/America/Knox_IN", + "/usr/share/zoneinfo/right/America/Kralendijk", + "/usr/share/zoneinfo/right/America/La_Paz", + "/usr/share/zoneinfo/right/America/Lima", + "/usr/share/zoneinfo/right/America/Los_Angeles", + "/usr/share/zoneinfo/right/America/Louisville", + "/usr/share/zoneinfo/right/America/Lower_Princes", + "/usr/share/zoneinfo/right/America/Maceio", + "/usr/share/zoneinfo/right/America/Managua", + "/usr/share/zoneinfo/right/America/Manaus", + "/usr/share/zoneinfo/right/America/Marigot", + "/usr/share/zoneinfo/right/America/Martinique", + "/usr/share/zoneinfo/right/America/Matamoros", + "/usr/share/zoneinfo/right/America/Mazatlan", + "/usr/share/zoneinfo/right/America/Mendoza", + "/usr/share/zoneinfo/right/America/Menominee", + "/usr/share/zoneinfo/right/America/Merida", + "/usr/share/zoneinfo/right/America/Metlakatla", + "/usr/share/zoneinfo/right/America/Mexico_City", + "/usr/share/zoneinfo/right/America/Miquelon", + "/usr/share/zoneinfo/right/America/Moncton", + "/usr/share/zoneinfo/right/America/Monterrey", + "/usr/share/zoneinfo/right/America/Montevideo", + "/usr/share/zoneinfo/right/America/Montreal", + "/usr/share/zoneinfo/right/America/Montserrat", + "/usr/share/zoneinfo/right/America/Nassau", + "/usr/share/zoneinfo/right/America/New_York", + "/usr/share/zoneinfo/right/America/Nipigon", + "/usr/share/zoneinfo/right/America/Nome", + "/usr/share/zoneinfo/right/America/Noronha", + "/usr/share/zoneinfo/right/America/North_Dakota", + "/usr/share/zoneinfo/right/America/North_Dakota/Beulah", + "/usr/share/zoneinfo/right/America/North_Dakota/Center", + "/usr/share/zoneinfo/right/America/North_Dakota/New_Salem", + "/usr/share/zoneinfo/right/America/Nuuk", + "/usr/share/zoneinfo/right/America/Ojinaga", + "/usr/share/zoneinfo/right/America/Panama", + "/usr/share/zoneinfo/right/America/Pangnirtung", + "/usr/share/zoneinfo/right/America/Paramaribo", + "/usr/share/zoneinfo/right/America/Phoenix", + "/usr/share/zoneinfo/right/America/Port-au-Prince", + "/usr/share/zoneinfo/right/America/Port_of_Spain", + "/usr/share/zoneinfo/right/America/Porto_Acre", + "/usr/share/zoneinfo/right/America/Porto_Velho", + "/usr/share/zoneinfo/right/America/Puerto_Rico", + "/usr/share/zoneinfo/right/America/Punta_Arenas", + "/usr/share/zoneinfo/right/America/Rainy_River", + "/usr/share/zoneinfo/right/America/Rankin_Inlet", + "/usr/share/zoneinfo/right/America/Recife", + "/usr/share/zoneinfo/right/America/Regina", + "/usr/share/zoneinfo/right/America/Resolute", + "/usr/share/zoneinfo/right/America/Rio_Branco", + "/usr/share/zoneinfo/right/America/Rosario", + "/usr/share/zoneinfo/right/America/Santa_Isabel", + "/usr/share/zoneinfo/right/America/Santarem", + "/usr/share/zoneinfo/right/America/Santiago", + "/usr/share/zoneinfo/right/America/Santo_Domingo", + "/usr/share/zoneinfo/right/America/Sao_Paulo", + "/usr/share/zoneinfo/right/America/Scoresbysund", + "/usr/share/zoneinfo/right/America/Shiprock", + "/usr/share/zoneinfo/right/America/Sitka", + "/usr/share/zoneinfo/right/America/St_Barthelemy", + "/usr/share/zoneinfo/right/America/St_Johns", + "/usr/share/zoneinfo/right/America/St_Kitts", + "/usr/share/zoneinfo/right/America/St_Lucia", + "/usr/share/zoneinfo/right/America/St_Thomas", + "/usr/share/zoneinfo/right/America/St_Vincent", + "/usr/share/zoneinfo/right/America/Swift_Current", + "/usr/share/zoneinfo/right/America/Tegucigalpa", + "/usr/share/zoneinfo/right/America/Thule", + "/usr/share/zoneinfo/right/America/Thunder_Bay", + "/usr/share/zoneinfo/right/America/Tijuana", + "/usr/share/zoneinfo/right/America/Toronto", + "/usr/share/zoneinfo/right/America/Tortola", + "/usr/share/zoneinfo/right/America/Vancouver", + "/usr/share/zoneinfo/right/America/Virgin", + "/usr/share/zoneinfo/right/America/Whitehorse", + "/usr/share/zoneinfo/right/America/Winnipeg", + "/usr/share/zoneinfo/right/America/Yakutat", + "/usr/share/zoneinfo/right/America/Yellowknife", + "/usr/share/zoneinfo/right/Antarctica", + "/usr/share/zoneinfo/right/Antarctica/Casey", + "/usr/share/zoneinfo/right/Antarctica/Davis", + "/usr/share/zoneinfo/right/Antarctica/DumontDUrville", + "/usr/share/zoneinfo/right/Antarctica/Macquarie", + "/usr/share/zoneinfo/right/Antarctica/Mawson", + "/usr/share/zoneinfo/right/Antarctica/McMurdo", + "/usr/share/zoneinfo/right/Antarctica/Palmer", + "/usr/share/zoneinfo/right/Antarctica/Rothera", + "/usr/share/zoneinfo/right/Antarctica/South_Pole", + "/usr/share/zoneinfo/right/Antarctica/Syowa", + "/usr/share/zoneinfo/right/Antarctica/Troll", + "/usr/share/zoneinfo/right/Antarctica/Vostok", + "/usr/share/zoneinfo/right/Arctic", + "/usr/share/zoneinfo/right/Arctic/Longyearbyen", + "/usr/share/zoneinfo/right/Asia", + "/usr/share/zoneinfo/right/Asia/Aden", + "/usr/share/zoneinfo/right/Asia/Almaty", + "/usr/share/zoneinfo/right/Asia/Amman", + "/usr/share/zoneinfo/right/Asia/Anadyr", + "/usr/share/zoneinfo/right/Asia/Aqtau", + "/usr/share/zoneinfo/right/Asia/Aqtobe", + "/usr/share/zoneinfo/right/Asia/Ashgabat", + "/usr/share/zoneinfo/right/Asia/Ashkhabad", + "/usr/share/zoneinfo/right/Asia/Atyrau", + "/usr/share/zoneinfo/right/Asia/Baghdad", + "/usr/share/zoneinfo/right/Asia/Bahrain", + "/usr/share/zoneinfo/right/Asia/Baku", + "/usr/share/zoneinfo/right/Asia/Bangkok", + "/usr/share/zoneinfo/right/Asia/Barnaul", + "/usr/share/zoneinfo/right/Asia/Beirut", + "/usr/share/zoneinfo/right/Asia/Bishkek", + "/usr/share/zoneinfo/right/Asia/Brunei", + "/usr/share/zoneinfo/right/Asia/Calcutta", + "/usr/share/zoneinfo/right/Asia/Chita", + "/usr/share/zoneinfo/right/Asia/Choibalsan", + "/usr/share/zoneinfo/right/Asia/Chongqing", + "/usr/share/zoneinfo/right/Asia/Chungking", + "/usr/share/zoneinfo/right/Asia/Colombo", + "/usr/share/zoneinfo/right/Asia/Dacca", + "/usr/share/zoneinfo/right/Asia/Damascus", + "/usr/share/zoneinfo/right/Asia/Dhaka", + "/usr/share/zoneinfo/right/Asia/Dili", + "/usr/share/zoneinfo/right/Asia/Dubai", + "/usr/share/zoneinfo/right/Asia/Dushanbe", + "/usr/share/zoneinfo/right/Asia/Famagusta", + "/usr/share/zoneinfo/right/Asia/Gaza", + "/usr/share/zoneinfo/right/Asia/Harbin", + "/usr/share/zoneinfo/right/Asia/Hebron", + "/usr/share/zoneinfo/right/Asia/Ho_Chi_Minh", + "/usr/share/zoneinfo/right/Asia/Hong_Kong", + "/usr/share/zoneinfo/right/Asia/Hovd", + "/usr/share/zoneinfo/right/Asia/Irkutsk", + "/usr/share/zoneinfo/right/Asia/Istanbul", + "/usr/share/zoneinfo/right/Asia/Jakarta", + "/usr/share/zoneinfo/right/Asia/Jayapura", + "/usr/share/zoneinfo/right/Asia/Jerusalem", + "/usr/share/zoneinfo/right/Asia/Kabul", + "/usr/share/zoneinfo/right/Asia/Kamchatka", + "/usr/share/zoneinfo/right/Asia/Karachi", + "/usr/share/zoneinfo/right/Asia/Kashgar", + "/usr/share/zoneinfo/right/Asia/Kathmandu", + "/usr/share/zoneinfo/right/Asia/Katmandu", + "/usr/share/zoneinfo/right/Asia/Khandyga", + "/usr/share/zoneinfo/right/Asia/Kolkata", + "/usr/share/zoneinfo/right/Asia/Krasnoyarsk", + "/usr/share/zoneinfo/right/Asia/Kuala_Lumpur", + "/usr/share/zoneinfo/right/Asia/Kuching", + "/usr/share/zoneinfo/right/Asia/Kuwait", + "/usr/share/zoneinfo/right/Asia/Macao", + "/usr/share/zoneinfo/right/Asia/Macau", + "/usr/share/zoneinfo/right/Asia/Magadan", + "/usr/share/zoneinfo/right/Asia/Makassar", + "/usr/share/zoneinfo/right/Asia/Manila", + "/usr/share/zoneinfo/right/Asia/Muscat", + "/usr/share/zoneinfo/right/Asia/Nicosia", + "/usr/share/zoneinfo/right/Asia/Novokuznetsk", + "/usr/share/zoneinfo/right/Asia/Novosibirsk", + "/usr/share/zoneinfo/right/Asia/Omsk", + "/usr/share/zoneinfo/right/Asia/Oral", + "/usr/share/zoneinfo/right/Asia/Phnom_Penh", + "/usr/share/zoneinfo/right/Asia/Pontianak", + "/usr/share/zoneinfo/right/Asia/Pyongyang", + "/usr/share/zoneinfo/right/Asia/Qatar", + "/usr/share/zoneinfo/right/Asia/Qostanay", + "/usr/share/zoneinfo/right/Asia/Qyzylorda", + "/usr/share/zoneinfo/right/Asia/Rangoon", + "/usr/share/zoneinfo/right/Asia/Riyadh", + "/usr/share/zoneinfo/right/Asia/Saigon", + "/usr/share/zoneinfo/right/Asia/Sakhalin", + "/usr/share/zoneinfo/right/Asia/Samarkand", + "/usr/share/zoneinfo/right/Asia/Seoul", + "/usr/share/zoneinfo/right/Asia/Shanghai", + "/usr/share/zoneinfo/right/Asia/Singapore", + "/usr/share/zoneinfo/right/Asia/Srednekolymsk", + "/usr/share/zoneinfo/right/Asia/Taipei", + "/usr/share/zoneinfo/right/Asia/Tashkent", + "/usr/share/zoneinfo/right/Asia/Tbilisi", + "/usr/share/zoneinfo/right/Asia/Tehran", + "/usr/share/zoneinfo/right/Asia/Tel_Aviv", + "/usr/share/zoneinfo/right/Asia/Thimbu", + "/usr/share/zoneinfo/right/Asia/Thimphu", + "/usr/share/zoneinfo/right/Asia/Tokyo", + "/usr/share/zoneinfo/right/Asia/Tomsk", + "/usr/share/zoneinfo/right/Asia/Ujung_Pandang", + "/usr/share/zoneinfo/right/Asia/Ulaanbaatar", + "/usr/share/zoneinfo/right/Asia/Ulan_Bator", + "/usr/share/zoneinfo/right/Asia/Urumqi", + "/usr/share/zoneinfo/right/Asia/Ust-Nera", + "/usr/share/zoneinfo/right/Asia/Vientiane", + "/usr/share/zoneinfo/right/Asia/Vladivostok", + "/usr/share/zoneinfo/right/Asia/Yakutsk", + "/usr/share/zoneinfo/right/Asia/Yangon", + "/usr/share/zoneinfo/right/Asia/Yekaterinburg", + "/usr/share/zoneinfo/right/Asia/Yerevan", + "/usr/share/zoneinfo/right/Atlantic", + "/usr/share/zoneinfo/right/Atlantic/Azores", + "/usr/share/zoneinfo/right/Atlantic/Bermuda", + "/usr/share/zoneinfo/right/Atlantic/Canary", + "/usr/share/zoneinfo/right/Atlantic/Cape_Verde", + "/usr/share/zoneinfo/right/Atlantic/Faeroe", + "/usr/share/zoneinfo/right/Atlantic/Faroe", + "/usr/share/zoneinfo/right/Atlantic/Jan_Mayen", + "/usr/share/zoneinfo/right/Atlantic/Madeira", + "/usr/share/zoneinfo/right/Atlantic/Reykjavik", + "/usr/share/zoneinfo/right/Atlantic/South_Georgia", + "/usr/share/zoneinfo/right/Atlantic/St_Helena", + "/usr/share/zoneinfo/right/Atlantic/Stanley", + "/usr/share/zoneinfo/right/Australia", + "/usr/share/zoneinfo/right/Australia/ACT", + "/usr/share/zoneinfo/right/Australia/Adelaide", + "/usr/share/zoneinfo/right/Australia/Brisbane", + "/usr/share/zoneinfo/right/Australia/Broken_Hill", + "/usr/share/zoneinfo/right/Australia/Canberra", + "/usr/share/zoneinfo/right/Australia/Currie", + "/usr/share/zoneinfo/right/Australia/Darwin", + "/usr/share/zoneinfo/right/Australia/Eucla", + "/usr/share/zoneinfo/right/Australia/Hobart", + "/usr/share/zoneinfo/right/Australia/LHI", + "/usr/share/zoneinfo/right/Australia/Lindeman", + "/usr/share/zoneinfo/right/Australia/Lord_Howe", + "/usr/share/zoneinfo/right/Australia/Melbourne", + "/usr/share/zoneinfo/right/Australia/NSW", + "/usr/share/zoneinfo/right/Australia/North", + "/usr/share/zoneinfo/right/Australia/Perth", + "/usr/share/zoneinfo/right/Australia/Queensland", + "/usr/share/zoneinfo/right/Australia/South", + "/usr/share/zoneinfo/right/Australia/Sydney", + "/usr/share/zoneinfo/right/Australia/Tasmania", + "/usr/share/zoneinfo/right/Australia/Victoria", + "/usr/share/zoneinfo/right/Australia/West", + "/usr/share/zoneinfo/right/Australia/Yancowinna", + "/usr/share/zoneinfo/right/Brazil", + "/usr/share/zoneinfo/right/Brazil/Acre", + "/usr/share/zoneinfo/right/Brazil/DeNoronha", + "/usr/share/zoneinfo/right/Brazil/East", + "/usr/share/zoneinfo/right/Brazil/West", + "/usr/share/zoneinfo/right/CET", + "/usr/share/zoneinfo/right/CST6CDT", + "/usr/share/zoneinfo/right/Canada", + "/usr/share/zoneinfo/right/Canada/Atlantic", + "/usr/share/zoneinfo/right/Canada/Central", + "/usr/share/zoneinfo/right/Canada/Eastern", + "/usr/share/zoneinfo/right/Canada/Mountain", + "/usr/share/zoneinfo/right/Canada/Newfoundland", + "/usr/share/zoneinfo/right/Canada/Pacific", + "/usr/share/zoneinfo/right/Canada/Saskatchewan", + "/usr/share/zoneinfo/right/Canada/Yukon", + "/usr/share/zoneinfo/right/Chile", + "/usr/share/zoneinfo/right/Chile/Continental", + "/usr/share/zoneinfo/right/Chile/EasterIsland", + "/usr/share/zoneinfo/right/Cuba", + "/usr/share/zoneinfo/right/EET", + "/usr/share/zoneinfo/right/EST", + "/usr/share/zoneinfo/right/EST5EDT", + "/usr/share/zoneinfo/right/Egypt", + "/usr/share/zoneinfo/right/Eire", + "/usr/share/zoneinfo/right/Etc", + "/usr/share/zoneinfo/right/Etc/GMT", + "/usr/share/zoneinfo/right/Etc/GMT+0", + "/usr/share/zoneinfo/right/Etc/GMT+1", + "/usr/share/zoneinfo/right/Etc/GMT+10", + "/usr/share/zoneinfo/right/Etc/GMT+11", + "/usr/share/zoneinfo/right/Etc/GMT+12", + "/usr/share/zoneinfo/right/Etc/GMT+2", + "/usr/share/zoneinfo/right/Etc/GMT+3", + "/usr/share/zoneinfo/right/Etc/GMT+4", + "/usr/share/zoneinfo/right/Etc/GMT+5", + "/usr/share/zoneinfo/right/Etc/GMT+6", + "/usr/share/zoneinfo/right/Etc/GMT+7", + "/usr/share/zoneinfo/right/Etc/GMT+8", + "/usr/share/zoneinfo/right/Etc/GMT+9", + "/usr/share/zoneinfo/right/Etc/GMT-0", + "/usr/share/zoneinfo/right/Etc/GMT-1", + "/usr/share/zoneinfo/right/Etc/GMT-10", + "/usr/share/zoneinfo/right/Etc/GMT-11", + "/usr/share/zoneinfo/right/Etc/GMT-12", + "/usr/share/zoneinfo/right/Etc/GMT-13", + "/usr/share/zoneinfo/right/Etc/GMT-14", + "/usr/share/zoneinfo/right/Etc/GMT-2", + "/usr/share/zoneinfo/right/Etc/GMT-3", + "/usr/share/zoneinfo/right/Etc/GMT-4", + "/usr/share/zoneinfo/right/Etc/GMT-5", + "/usr/share/zoneinfo/right/Etc/GMT-6", + "/usr/share/zoneinfo/right/Etc/GMT-7", + "/usr/share/zoneinfo/right/Etc/GMT-8", + "/usr/share/zoneinfo/right/Etc/GMT-9", + "/usr/share/zoneinfo/right/Etc/GMT0", + "/usr/share/zoneinfo/right/Etc/Greenwich", + "/usr/share/zoneinfo/right/Etc/UCT", + "/usr/share/zoneinfo/right/Etc/UTC", + "/usr/share/zoneinfo/right/Etc/Universal", + "/usr/share/zoneinfo/right/Etc/Zulu", + "/usr/share/zoneinfo/right/Europe", + "/usr/share/zoneinfo/right/Europe/Amsterdam", + "/usr/share/zoneinfo/right/Europe/Andorra", + "/usr/share/zoneinfo/right/Europe/Astrakhan", + "/usr/share/zoneinfo/right/Europe/Athens", + "/usr/share/zoneinfo/right/Europe/Belfast", + "/usr/share/zoneinfo/right/Europe/Belgrade", + "/usr/share/zoneinfo/right/Europe/Berlin", + "/usr/share/zoneinfo/right/Europe/Bratislava", + "/usr/share/zoneinfo/right/Europe/Brussels", + "/usr/share/zoneinfo/right/Europe/Bucharest", + "/usr/share/zoneinfo/right/Europe/Budapest", + "/usr/share/zoneinfo/right/Europe/Busingen", + "/usr/share/zoneinfo/right/Europe/Chisinau", + "/usr/share/zoneinfo/right/Europe/Copenhagen", + "/usr/share/zoneinfo/right/Europe/Dublin", + "/usr/share/zoneinfo/right/Europe/Gibraltar", + "/usr/share/zoneinfo/right/Europe/Guernsey", + "/usr/share/zoneinfo/right/Europe/Helsinki", + "/usr/share/zoneinfo/right/Europe/Isle_of_Man", + "/usr/share/zoneinfo/right/Europe/Istanbul", + "/usr/share/zoneinfo/right/Europe/Jersey", + "/usr/share/zoneinfo/right/Europe/Kaliningrad", + "/usr/share/zoneinfo/right/Europe/Kiev", + "/usr/share/zoneinfo/right/Europe/Kirov", + "/usr/share/zoneinfo/right/Europe/Kyiv", + "/usr/share/zoneinfo/right/Europe/Lisbon", + "/usr/share/zoneinfo/right/Europe/Ljubljana", + "/usr/share/zoneinfo/right/Europe/London", + "/usr/share/zoneinfo/right/Europe/Luxembourg", + "/usr/share/zoneinfo/right/Europe/Madrid", + "/usr/share/zoneinfo/right/Europe/Malta", + "/usr/share/zoneinfo/right/Europe/Mariehamn", + "/usr/share/zoneinfo/right/Europe/Minsk", + "/usr/share/zoneinfo/right/Europe/Monaco", + "/usr/share/zoneinfo/right/Europe/Moscow", + "/usr/share/zoneinfo/right/Europe/Nicosia", + "/usr/share/zoneinfo/right/Europe/Oslo", + "/usr/share/zoneinfo/right/Europe/Paris", + "/usr/share/zoneinfo/right/Europe/Podgorica", + "/usr/share/zoneinfo/right/Europe/Prague", + "/usr/share/zoneinfo/right/Europe/Riga", + "/usr/share/zoneinfo/right/Europe/Rome", + "/usr/share/zoneinfo/right/Europe/Samara", + "/usr/share/zoneinfo/right/Europe/San_Marino", + "/usr/share/zoneinfo/right/Europe/Sarajevo", + "/usr/share/zoneinfo/right/Europe/Saratov", + "/usr/share/zoneinfo/right/Europe/Simferopol", + "/usr/share/zoneinfo/right/Europe/Skopje", + "/usr/share/zoneinfo/right/Europe/Sofia", + "/usr/share/zoneinfo/right/Europe/Stockholm", + "/usr/share/zoneinfo/right/Europe/Tallinn", + "/usr/share/zoneinfo/right/Europe/Tirane", + "/usr/share/zoneinfo/right/Europe/Tiraspol", + "/usr/share/zoneinfo/right/Europe/Ulyanovsk", + "/usr/share/zoneinfo/right/Europe/Uzhgorod", + "/usr/share/zoneinfo/right/Europe/Vaduz", + "/usr/share/zoneinfo/right/Europe/Vatican", + "/usr/share/zoneinfo/right/Europe/Vienna", + "/usr/share/zoneinfo/right/Europe/Vilnius", + "/usr/share/zoneinfo/right/Europe/Volgograd", + "/usr/share/zoneinfo/right/Europe/Warsaw", + "/usr/share/zoneinfo/right/Europe/Zagreb", + "/usr/share/zoneinfo/right/Europe/Zaporozhye", + "/usr/share/zoneinfo/right/Europe/Zurich", + "/usr/share/zoneinfo/right/Factory", + "/usr/share/zoneinfo/right/GB", + "/usr/share/zoneinfo/right/GB-Eire", + "/usr/share/zoneinfo/right/GMT", + "/usr/share/zoneinfo/right/GMT+0", + "/usr/share/zoneinfo/right/GMT-0", + "/usr/share/zoneinfo/right/GMT0", + "/usr/share/zoneinfo/right/Greenwich", + "/usr/share/zoneinfo/right/HST", + "/usr/share/zoneinfo/right/Hongkong", + "/usr/share/zoneinfo/right/Iceland", + "/usr/share/zoneinfo/right/Indian", + "/usr/share/zoneinfo/right/Indian/Antananarivo", + "/usr/share/zoneinfo/right/Indian/Chagos", + "/usr/share/zoneinfo/right/Indian/Christmas", + "/usr/share/zoneinfo/right/Indian/Cocos", + "/usr/share/zoneinfo/right/Indian/Comoro", + "/usr/share/zoneinfo/right/Indian/Kerguelen", + "/usr/share/zoneinfo/right/Indian/Mahe", + "/usr/share/zoneinfo/right/Indian/Maldives", + "/usr/share/zoneinfo/right/Indian/Mauritius", + "/usr/share/zoneinfo/right/Indian/Mayotte", + "/usr/share/zoneinfo/right/Indian/Reunion", + "/usr/share/zoneinfo/right/Iran", + "/usr/share/zoneinfo/right/Israel", + "/usr/share/zoneinfo/right/Jamaica", + "/usr/share/zoneinfo/right/Japan", + "/usr/share/zoneinfo/right/Kwajalein", + "/usr/share/zoneinfo/right/Libya", + "/usr/share/zoneinfo/right/MET", + "/usr/share/zoneinfo/right/MST", + "/usr/share/zoneinfo/right/MST7MDT", + "/usr/share/zoneinfo/right/Mexico", + "/usr/share/zoneinfo/right/Mexico/BajaNorte", + "/usr/share/zoneinfo/right/Mexico/BajaSur", + "/usr/share/zoneinfo/right/Mexico/General", + "/usr/share/zoneinfo/right/NZ", + "/usr/share/zoneinfo/right/NZ-CHAT", + "/usr/share/zoneinfo/right/Navajo", + "/usr/share/zoneinfo/right/PRC", + "/usr/share/zoneinfo/right/PST8PDT", + "/usr/share/zoneinfo/right/Pacific", + "/usr/share/zoneinfo/right/Pacific/Apia", + "/usr/share/zoneinfo/right/Pacific/Auckland", + "/usr/share/zoneinfo/right/Pacific/Bougainville", + "/usr/share/zoneinfo/right/Pacific/Chatham", + "/usr/share/zoneinfo/right/Pacific/Chuuk", + "/usr/share/zoneinfo/right/Pacific/Easter", + "/usr/share/zoneinfo/right/Pacific/Efate", + "/usr/share/zoneinfo/right/Pacific/Enderbury", + "/usr/share/zoneinfo/right/Pacific/Fakaofo", + "/usr/share/zoneinfo/right/Pacific/Fiji", + "/usr/share/zoneinfo/right/Pacific/Funafuti", + "/usr/share/zoneinfo/right/Pacific/Galapagos", + "/usr/share/zoneinfo/right/Pacific/Gambier", + "/usr/share/zoneinfo/right/Pacific/Guadalcanal", + "/usr/share/zoneinfo/right/Pacific/Guam", + "/usr/share/zoneinfo/right/Pacific/Honolulu", + "/usr/share/zoneinfo/right/Pacific/Johnston", + "/usr/share/zoneinfo/right/Pacific/Kanton", + "/usr/share/zoneinfo/right/Pacific/Kiritimati", + "/usr/share/zoneinfo/right/Pacific/Kosrae", + "/usr/share/zoneinfo/right/Pacific/Kwajalein", + "/usr/share/zoneinfo/right/Pacific/Majuro", + "/usr/share/zoneinfo/right/Pacific/Marquesas", + "/usr/share/zoneinfo/right/Pacific/Midway", + "/usr/share/zoneinfo/right/Pacific/Nauru", + "/usr/share/zoneinfo/right/Pacific/Niue", + "/usr/share/zoneinfo/right/Pacific/Norfolk", + "/usr/share/zoneinfo/right/Pacific/Noumea", + "/usr/share/zoneinfo/right/Pacific/Pago_Pago", + "/usr/share/zoneinfo/right/Pacific/Palau", + "/usr/share/zoneinfo/right/Pacific/Pitcairn", + "/usr/share/zoneinfo/right/Pacific/Pohnpei", + "/usr/share/zoneinfo/right/Pacific/Ponape", + "/usr/share/zoneinfo/right/Pacific/Port_Moresby", + "/usr/share/zoneinfo/right/Pacific/Rarotonga", + "/usr/share/zoneinfo/right/Pacific/Saipan", + "/usr/share/zoneinfo/right/Pacific/Samoa", + "/usr/share/zoneinfo/right/Pacific/Tahiti", + "/usr/share/zoneinfo/right/Pacific/Tarawa", + "/usr/share/zoneinfo/right/Pacific/Tongatapu", + "/usr/share/zoneinfo/right/Pacific/Truk", + "/usr/share/zoneinfo/right/Pacific/Wake", + "/usr/share/zoneinfo/right/Pacific/Wallis", + "/usr/share/zoneinfo/right/Pacific/Yap", + "/usr/share/zoneinfo/right/Poland", + "/usr/share/zoneinfo/right/Portugal", + "/usr/share/zoneinfo/right/ROC", + "/usr/share/zoneinfo/right/ROK", + "/usr/share/zoneinfo/right/Singapore", + "/usr/share/zoneinfo/right/Turkey", + "/usr/share/zoneinfo/right/UCT", + "/usr/share/zoneinfo/right/US", + "/usr/share/zoneinfo/right/US/Alaska", + "/usr/share/zoneinfo/right/US/Aleutian", + "/usr/share/zoneinfo/right/US/Arizona", + "/usr/share/zoneinfo/right/US/Central", + "/usr/share/zoneinfo/right/US/East-Indiana", + "/usr/share/zoneinfo/right/US/Eastern", + "/usr/share/zoneinfo/right/US/Hawaii", + "/usr/share/zoneinfo/right/US/Indiana-Starke", + "/usr/share/zoneinfo/right/US/Michigan", + "/usr/share/zoneinfo/right/US/Mountain", + "/usr/share/zoneinfo/right/US/Pacific", + "/usr/share/zoneinfo/right/US/Samoa", + "/usr/share/zoneinfo/right/UTC", + "/usr/share/zoneinfo/right/Universal", + "/usr/share/zoneinfo/right/W-SU", + "/usr/share/zoneinfo/right/WET", + "/usr/share/zoneinfo/right/Zulu", + "/usr/share/zoneinfo/tzdata.zi", + "/usr/share/zoneinfo/zone.tab", + "/usr/share/zoneinfo/zone1970.tab" + ], + "AnalyzedBy": "rpm" + } + ], + "Vulnerabilities": [ + { + "VulnerabilityID": "CVE-2026-54369", + "VendorIDs": [ + "RHSA-2026:42736" + ], + "PkgID": "libacl@2.3.1-4.el9.x86_64", + "PkgName": "libacl", + "PkgIdentifier": { + "PURL": "pkg:rpm/redhat/libacl@2.3.1-4.el9?arch=x86_64\u0026distro=redhat-9.5", + "UID": "55f4580a7b246b8d" + }, + "InstalledVersion": "2.3.1-4.el9", + "FixedVersion": "2.4.0-1.el9_8", + "Status": "fixed", + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "SeveritySource": "redhat", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54369", + "Fingerprint": "sha256:4a1856ed276d8238d1cc5ac6735178727ea6bb28fbf7c38222243c6089ed3242", + "Title": "acl: Symlink traversal privilege escalation via libacl functions", + "Description": "acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:34351", + "https://access.redhat.com/errata/RHSA-2026:42736", + "https://access.redhat.com/errata/RHSA-2026:42739", + "https://access.redhat.com/errata/RHSA-2026:43420", + "https://access.redhat.com/errata/RHSA-2026:44481", + "https://access.redhat.com/errata/RHSA-2026:46836", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:53371", + "https://access.redhat.com/errata/RHSA-2026:54769", + "https://access.redhat.com/errata/RHSA-2026:58981", + "https://access.redhat.com/errata/RHSA-2026:64805", + "https://access.redhat.com/security/cve/CVE-2026-54369", + "https://bugzilla.redhat.com/2490277", + "https://bugzilla.redhat.com/2490279", + "https://bugzilla.redhat.com/show_bug.cgi?id=2490277", + "https://bugzilla.redhat.com/show_bug.cgi?id=2490279", + "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5", + "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54369", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54370", + "https://errata.almalinux.org/9/ALSA-2026-42736.html", + "https://errata.rockylinux.org/RLSA-2026:42736", + "https://linux.oracle.com/cve/CVE-2026-54369.html", + "https://linux.oracle.com/errata/ELSA-2026-43420.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54369", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json", + "https://www.cve.org/CVERecord?id=CVE-2026-54369", + "https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions" + ], + "PublishedDate": "2026-06-29T14:16:57.487Z", + "LastModifiedDate": "2026-09-09T13:20:30.973Z" + }, + { + "VulnerabilityID": "CVE-2026-4878", + "VendorIDs": [ + "RHSA-2026:19346" + ], + "PkgID": "libcap@2.48-9.el9_2.x86_64", + "PkgName": "libcap", + "PkgIdentifier": { + "PURL": "pkg:rpm/redhat/libcap@2.48-9.el9_2?arch=x86_64\u0026distro=redhat-9.5", + "UID": "7826b36bb6020fd3" + }, + "InstalledVersion": "2.48-9.el9_2", + "FixedVersion": "2.48-10.el9_8.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:d949f716ce773b6952762453dba423b055fd2ae51e80707cbbb44b80d49a508f", + "DiffID": "sha256:a7ea3edf99845e113e999841d132de36776a3cd05a11512be990a61062eda01e" + }, + "SeveritySource": "redhat", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-4878", + "Fingerprint": "sha256:6881558d3f2d02e04be8812caba27927c422535fa69b6264825b89376f726d66", + "Title": "libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()", + "Description": "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "alma": 3, + "azure": 2, + "bottlerocket": 2, + "nvd": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 6.7 + } + }, + "References": [ + "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4878", + "http://www.openwall.com/lists/oss-security/2026/04/07/14", + "http://www.openwall.com/lists/oss-security/2026/04/07/4", + "http://www.openwall.com/lists/oss-security/2026/04/08/9", + "http://www.openwall.com/lists/oss-security/2026/04/09/5", + "http://www.openwall.com/lists/oss-security/2026/04/09/6", + "https://access.redhat.com/errata/RHSA-2026:12423", + "https://access.redhat.com/errata/RHSA-2026:12441", + "https://access.redhat.com/errata/RHSA-2026:13285", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14937", + "https://access.redhat.com/errata/RHSA-2026:19130", + "https://access.redhat.com/errata/RHSA-2026:19346", + "https://access.redhat.com/errata/RHSA-2026:19456", + "https://access.redhat.com/errata/RHSA-2026:19458", + "https://access.redhat.com/errata/RHSA-2026:20595", + "https://access.redhat.com/errata/RHSA-2026:21254", + "https://access.redhat.com/errata/RHSA-2026:21275", + "https://access.redhat.com/errata/RHSA-2026:22634", + "https://access.redhat.com/errata/RHSA-2026:22957", + "https://access.redhat.com/errata/RHSA-2026:23233", + "https://access.redhat.com/errata/RHSA-2026:23245", + "https://access.redhat.com/errata/RHSA-2026:24346", + "https://access.redhat.com/errata/RHSA-2026:25044", + "https://access.redhat.com/errata/RHSA-2026:25096", + "https://access.redhat.com/errata/RHSA-2026:25181", + "https://access.redhat.com/errata/RHSA-2026:26542", + "https://access.redhat.com/errata/RHSA-2026:27998", + "https://access.redhat.com/errata/RHSA-2026:28887", + "https://access.redhat.com/errata/RHSA-2026:29197", + "https://access.redhat.com/errata/RHSA-2026:30078", + "https://access.redhat.com/errata/RHSA-2026:30087", + "https://access.redhat.com/errata/RHSA-2026:30088", + "https://access.redhat.com/errata/RHSA-2026:30089", + "https://access.redhat.com/errata/RHSA-2026:34098", + "https://access.redhat.com/errata/RHSA-2026:39981", + "https://access.redhat.com/errata/RHSA-2026:58981", + "https://access.redhat.com/errata/RHSA-2026:59831", + "https://access.redhat.com/errata/RHSA-2026:7473", + "https://access.redhat.com/security/cve/CVE-2026-4878", + "https://bugzilla.redhat.com/2451615", + "https://bugzilla.redhat.com/show_bug.cgi?id=2447554", + "https://bugzilla.redhat.com/show_bug.cgi?id=2451615", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4878", + "https://errata.almalinux.org/9/ALSA-2026-19346.html", + "https://errata.rockylinux.org/RLSA-2026:19346", + "https://github.com/AndrewGMorgan/libcap_mirror/security/advisories/GHSA-f78v-p5hx-m7hh", + "https://github.com/bottlerocket-os/bottlerocket-core-kit/blob/develop/advisories/14.5.0/BRSA-b8okc9cb56gk.toml", + "https://linux.oracle.com/cve/CVE-2026-4878.html", + "https://linux.oracle.com/errata/ELSA-2026-19346.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-4878", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4878.json", + "https://sites.google.com/site/fullycapable/release-notes-for-libcap#h.x4zn8j3lss6r", + "https://ubuntu.com/security/notices/USN-8193-1", + "https://ubuntu.com/security/notices/USN-8193-2", + "https://www.cve.org/CVERecord?id=CVE-2026-4878" + ], + "PublishedDate": "2026-04-09T16:16:31.987Z", + "LastModifiedDate": "2026-09-09T13:20:24.613Z" + } + ] + }, + { + "Target": "usr/bin/mc", + "Class": "lang-pkgs", + "Type": "gobinary", + "Packages": [ + { + "ID": "github.com/minio/mc@v0.0.0-20250416181326-b00526b153a3+dirty", + "Name": "github.com/minio/mc", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/mc@v0.0.0-20250416181326-b00526b153a3%2Bdirty", + "UID": "1dfb16cd0d96f177" + }, + "Version": "v0.0.0-20250416181326-b00526b153a3+dirty", + "Relationship": "root", + "DependsOn": [ + "aead.dev/minisign@v0.3.0", + "github.com/VividCortex/ewma@v1.2.0", + "github.com/acarl005/stripansi@v0.0.0-20180116102854-5a71ef0e047d", + "github.com/aymanbagabas/go-osc52/v2@v2.0.1", + "github.com/beorn7/perks@v1.0.1", + "github.com/cespare/xxhash/v2@v2.3.0", + "github.com/charmbracelet/bubbles@v0.20.0", + "github.com/charmbracelet/bubbletea@v1.3.4", + "github.com/charmbracelet/lipgloss@v1.0.0", + "github.com/charmbracelet/x/ansi@v0.8.0", + "github.com/charmbracelet/x/term@v0.2.1", + "github.com/cheggaaa/pb@v1.0.29", + "github.com/coreos/go-semver@v0.3.1", + "github.com/coreos/go-systemd/v22@v22.5.0", + "github.com/dustin/go-humanize@v1.0.1", + "github.com/fatih/color@v1.18.0", + "github.com/fatih/structs@v1.1.0", + "github.com/go-ini/ini@v1.67.0", + "github.com/goccy/go-json@v0.10.5", + "github.com/gogo/protobuf@v1.3.2", + "github.com/golang-jwt/jwt/v4@v4.5.2", + "github.com/golang/protobuf@v1.5.4", + "github.com/google/shlex@v0.0.0-20191202100458-e7afc7fbc510", + "github.com/google/uuid@v1.6.0", + "github.com/hashicorp/errwrap@v1.1.0", + "github.com/hashicorp/go-multierror@v1.1.1", + "github.com/inconshreveable/mousetrap@v1.1.0", + "github.com/jedib0t/go-pretty/v6@v6.6.7", + "github.com/juju/ratelimit@v1.0.2", + "github.com/klauspost/compress@v1.18.0", + "github.com/klauspost/cpuid/v2@v2.2.10", + "github.com/lestrrat-go/blackmagic@v1.0.2", + "github.com/lestrrat-go/httpcc@v1.0.1", + "github.com/lestrrat-go/httprc@v1.0.6", + "github.com/lestrrat-go/iter@v1.0.2", + "github.com/lestrrat-go/jwx/v2@v2.1.4", + "github.com/lestrrat-go/option@v1.0.1", + "github.com/lucasb-eyer/go-colorful@v1.2.0", + "github.com/mattn/go-colorable@v0.1.14", + "github.com/mattn/go-ieproxy@v0.0.12", + "github.com/mattn/go-isatty@v0.0.20", + "github.com/mattn/go-runewidth@v0.0.16", + "github.com/matttproud/golang_protobuf_extensions@v1.0.4", + "github.com/minio/cli@v1.24.2", + "github.com/minio/colorjson@v1.0.8", + "github.com/minio/crc64nvme@v1.0.1", + "github.com/minio/filepath@v1.0.0", + "github.com/minio/madmin-go/v3@v3.0.107-0.20250415152934-4b504b82db63", + "github.com/minio/md5-simd@v1.1.2", + "github.com/minio/minio-go/v7@v7.0.90", + "github.com/minio/pkg/v3@v3.1.0", + "github.com/minio/selfupdate@v0.6.0", + "github.com/mitchellh/go-homedir@v1.1.0", + "github.com/muesli/ansi@v0.0.0-20230316100256-276c6243b2f6", + "github.com/muesli/cancelreader@v0.2.2", + "github.com/muesli/reflow@v0.3.0", + "github.com/muesli/termenv@v0.16.0", + "github.com/munnerz/goautoneg@v0.0.0-20191010083416-a7dc8b61c822", + "github.com/olekukonko/tablewriter@v0.0.5", + "github.com/philhofer/fwd@v1.1.3-0.20240916144458-20a13a1f6b7c", + "github.com/pkg/xattr@v0.4.10", + "github.com/posener/complete@v1.2.3", + "github.com/prometheus/client_golang@v1.21.1", + "github.com/prometheus/client_model@v0.6.2", + "github.com/prometheus/common@v0.63.0", + "github.com/prometheus/procfs@v0.16.0", + "github.com/prometheus/prom2json@v1.4.2", + "github.com/prometheus/prometheus@v0.303.0", + "github.com/rivo/uniseg@v0.4.7", + "github.com/rjeczalik/notify@v0.9.3", + "github.com/rs/xid@v1.6.0", + "github.com/safchain/ethtool@v0.5.10", + "github.com/secure-io/sio-go@v0.3.1", + "github.com/shirou/gopsutil/v3@v3.24.5", + "github.com/tidwall/gjson@v1.18.0", + "github.com/tidwall/match@v1.1.1", + "github.com/tidwall/pretty@v1.2.1", + "github.com/tinylib/msgp@v1.2.5", + "github.com/tklauser/go-sysconf@v0.3.15", + "github.com/tklauser/numcpus@v0.10.0", + "github.com/vbauerster/mpb/v8@v8.9.3", + "go.etcd.io/etcd/api/v3@v3.5.19", + "go.etcd.io/etcd/client/pkg/v3@v3.5.19", + "go.etcd.io/etcd/client/v3@v3.5.19", + "go.uber.org/multierr@v1.11.0", + "go.uber.org/zap@v1.27.0", + "golang.org/x/crypto@v0.37.0", + "golang.org/x/net@v0.39.0", + "golang.org/x/sync@v0.13.0", + "golang.org/x/sys@v0.32.0", + "golang.org/x/term@v0.31.0", + "golang.org/x/text@v0.24.0", + "google.golang.org/genproto/googleapis/api@v0.0.0-20250311173030-29e43e6258d7", + "google.golang.org/genproto/googleapis/rpc@v0.0.0-20250303144028-a0af3efb3deb", + "google.golang.org/grpc@v1.71.0", + "google.golang.org/protobuf@v1.36.6", + "gopkg.in/yaml.v2@v2.4.0", + "gopkg.in/yaml.v3@v3.0.1", + "stdlib@v1.24.2" + ], + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "stdlib@v1.24.2", + "Name": "stdlib", + "Identifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "Version": "v1.24.2", + "Relationship": "direct", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "aead.dev/minisign@v0.3.0", + "Name": "aead.dev/minisign", + "Identifier": { + "PURL": "pkg:golang/aead.dev/minisign@v0.3.0", + "UID": "4ec9cfd3ff63c816" + }, + "Version": "v0.3.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/VividCortex/ewma@v1.2.0", + "Name": "github.com/VividCortex/ewma", + "Identifier": { + "PURL": "pkg:golang/github.com/vividcortex/ewma@v1.2.0", + "UID": "1092a794af90e846" + }, + "Version": "v1.2.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/acarl005/stripansi@v0.0.0-20180116102854-5a71ef0e047d", + "Name": "github.com/acarl005/stripansi", + "Identifier": { + "PURL": "pkg:golang/github.com/acarl005/stripansi@v0.0.0-20180116102854-5a71ef0e047d", + "UID": "6edb309521f7575b" + }, + "Version": "v0.0.0-20180116102854-5a71ef0e047d", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/aymanbagabas/go-osc52/v2@v2.0.1", + "Name": "github.com/aymanbagabas/go-osc52/v2", + "Identifier": { + "PURL": "pkg:golang/github.com/aymanbagabas/go-osc52/v2@v2.0.1", + "UID": "b7cddc9cb66b4821" + }, + "Version": "v2.0.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/beorn7/perks@v1.0.1", + "Name": "github.com/beorn7/perks", + "Identifier": { + "PURL": "pkg:golang/github.com/beorn7/perks@v1.0.1", + "UID": "9d008f5b930abd78" + }, + "Version": "v1.0.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/cespare/xxhash/v2@v2.3.0", + "Name": "github.com/cespare/xxhash/v2", + "Identifier": { + "PURL": "pkg:golang/github.com/cespare/xxhash/v2@v2.3.0", + "UID": "858fa69532b47b2d" + }, + "Version": "v2.3.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/charmbracelet/bubbles@v0.20.0", + "Name": "github.com/charmbracelet/bubbles", + "Identifier": { + "PURL": "pkg:golang/github.com/charmbracelet/bubbles@v0.20.0", + "UID": "b8b97e5957a681e7" + }, + "Version": "v0.20.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/charmbracelet/bubbletea@v1.3.4", + "Name": "github.com/charmbracelet/bubbletea", + "Identifier": { + "PURL": "pkg:golang/github.com/charmbracelet/bubbletea@v1.3.4", + "UID": "9bcb2ce8056ba3fd" + }, + "Version": "v1.3.4", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/charmbracelet/lipgloss@v1.0.0", + "Name": "github.com/charmbracelet/lipgloss", + "Identifier": { + "PURL": "pkg:golang/github.com/charmbracelet/lipgloss@v1.0.0", + "UID": "417282bac330cb2e" + }, + "Version": "v1.0.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/charmbracelet/x/ansi@v0.8.0", + "Name": "github.com/charmbracelet/x/ansi", + "Identifier": { + "PURL": "pkg:golang/github.com/charmbracelet/x/ansi@v0.8.0", + "UID": "69d9332988699c2b" + }, + "Version": "v0.8.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/charmbracelet/x/term@v0.2.1", + "Name": "github.com/charmbracelet/x/term", + "Identifier": { + "PURL": "pkg:golang/github.com/charmbracelet/x/term@v0.2.1", + "UID": "ed13b6fe2c37696d" + }, + "Version": "v0.2.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/cheggaaa/pb@v1.0.29", + "Name": "github.com/cheggaaa/pb", + "Identifier": { + "PURL": "pkg:golang/github.com/cheggaaa/pb@v1.0.29", + "UID": "4570b6d7a93ecabe" + }, + "Version": "v1.0.29", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/coreos/go-semver@v0.3.1", + "Name": "github.com/coreos/go-semver", + "Identifier": { + "PURL": "pkg:golang/github.com/coreos/go-semver@v0.3.1", + "UID": "bbfbef6b475973ec" + }, + "Version": "v0.3.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/coreos/go-systemd/v22@v22.5.0", + "Name": "github.com/coreos/go-systemd/v22", + "Identifier": { + "PURL": "pkg:golang/github.com/coreos/go-systemd/v22@v22.5.0", + "UID": "c5943ab40dc39795" + }, + "Version": "v22.5.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/dustin/go-humanize@v1.0.1", + "Name": "github.com/dustin/go-humanize", + "Identifier": { + "PURL": "pkg:golang/github.com/dustin/go-humanize@v1.0.1", + "UID": "f6fbfe195c0a0bce" + }, + "Version": "v1.0.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/fatih/color@v1.18.0", + "Name": "github.com/fatih/color", + "Identifier": { + "PURL": "pkg:golang/github.com/fatih/color@v1.18.0", + "UID": "c25d0fb563102fbe" + }, + "Version": "v1.18.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/fatih/structs@v1.1.0", + "Name": "github.com/fatih/structs", + "Identifier": { + "PURL": "pkg:golang/github.com/fatih/structs@v1.1.0", + "UID": "dee4456a9cdfa538" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-ini/ini@v1.67.0", + "Name": "github.com/go-ini/ini", + "Identifier": { + "PURL": "pkg:golang/github.com/go-ini/ini@v1.67.0", + "UID": "bb85b4d173740948" + }, + "Version": "v1.67.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/goccy/go-json@v0.10.5", + "Name": "github.com/goccy/go-json", + "Identifier": { + "PURL": "pkg:golang/github.com/goccy/go-json@v0.10.5", + "UID": "3496581ff6226e6b" + }, + "Version": "v0.10.5", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/gogo/protobuf@v1.3.2", + "Name": "github.com/gogo/protobuf", + "Identifier": { + "PURL": "pkg:golang/github.com/gogo/protobuf@v1.3.2", + "UID": "4f465664d490c4a8" + }, + "Version": "v1.3.2", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/golang-jwt/jwt/v4@v4.5.2", + "Name": "github.com/golang-jwt/jwt/v4", + "Identifier": { + "PURL": "pkg:golang/github.com/golang-jwt/jwt/v4@v4.5.2", + "UID": "2b1d823364a24d86" + }, + "Version": "v4.5.2", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/golang/protobuf@v1.5.4", + "Name": "github.com/golang/protobuf", + "Identifier": { + "PURL": "pkg:golang/github.com/golang/protobuf@v1.5.4", + "UID": "98a16a6aa3469b4a" + }, + "Version": "v1.5.4", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/google/shlex@v0.0.0-20191202100458-e7afc7fbc510", + "Name": "github.com/google/shlex", + "Identifier": { + "PURL": "pkg:golang/github.com/google/shlex@v0.0.0-20191202100458-e7afc7fbc510", + "UID": "f88c6dd2589ecf1d" + }, + "Version": "v0.0.0-20191202100458-e7afc7fbc510", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/google/uuid@v1.6.0", + "Name": "github.com/google/uuid", + "Identifier": { + "PURL": "pkg:golang/github.com/google/uuid@v1.6.0", + "UID": "1feb135b3a65592a" + }, + "Version": "v1.6.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/hashicorp/errwrap@v1.1.0", + "Name": "github.com/hashicorp/errwrap", + "Identifier": { + "PURL": "pkg:golang/github.com/hashicorp/errwrap@v1.1.0", + "UID": "b0555c31bc4e07a6" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/hashicorp/go-multierror@v1.1.1", + "Name": "github.com/hashicorp/go-multierror", + "Identifier": { + "PURL": "pkg:golang/github.com/hashicorp/go-multierror@v1.1.1", + "UID": "36ee1e8448c9b5e4" + }, + "Version": "v1.1.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/inconshreveable/mousetrap@v1.1.0", + "Name": "github.com/inconshreveable/mousetrap", + "Identifier": { + "PURL": "pkg:golang/github.com/inconshreveable/mousetrap@v1.1.0", + "UID": "db2336b2354ab8e6" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/jedib0t/go-pretty/v6@v6.6.7", + "Name": "github.com/jedib0t/go-pretty/v6", + "Identifier": { + "PURL": "pkg:golang/github.com/jedib0t/go-pretty/v6@v6.6.7", + "UID": "1a4813d06bf3bc34" + }, + "Version": "v6.6.7", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/juju/ratelimit@v1.0.2", + "Name": "github.com/juju/ratelimit", + "Identifier": { + "PURL": "pkg:golang/github.com/juju/ratelimit@v1.0.2", + "UID": "febb0748e4273830" + }, + "Version": "v1.0.2", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/klauspost/compress@v1.18.0", + "Name": "github.com/klauspost/compress", + "Identifier": { + "PURL": "pkg:golang/github.com/klauspost/compress@v1.18.0", + "UID": "564ca1d735f1076b" + }, + "Version": "v1.18.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/klauspost/cpuid/v2@v2.2.10", + "Name": "github.com/klauspost/cpuid/v2", + "Identifier": { + "PURL": "pkg:golang/github.com/klauspost/cpuid/v2@v2.2.10", + "UID": "9ccd96f9a17062cb" + }, + "Version": "v2.2.10", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lestrrat-go/blackmagic@v1.0.2", + "Name": "github.com/lestrrat-go/blackmagic", + "Identifier": { + "PURL": "pkg:golang/github.com/lestrrat-go/blackmagic@v1.0.2", + "UID": "ecef9990e0b3f27f" + }, + "Version": "v1.0.2", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lestrrat-go/httpcc@v1.0.1", + "Name": "github.com/lestrrat-go/httpcc", + "Identifier": { + "PURL": "pkg:golang/github.com/lestrrat-go/httpcc@v1.0.1", + "UID": "c31dd685e716640c" + }, + "Version": "v1.0.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lestrrat-go/httprc@v1.0.6", + "Name": "github.com/lestrrat-go/httprc", + "Identifier": { + "PURL": "pkg:golang/github.com/lestrrat-go/httprc@v1.0.6", + "UID": "723374ad0324525b" + }, + "Version": "v1.0.6", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lestrrat-go/iter@v1.0.2", + "Name": "github.com/lestrrat-go/iter", + "Identifier": { + "PURL": "pkg:golang/github.com/lestrrat-go/iter@v1.0.2", + "UID": "1976bfde332bfbec" + }, + "Version": "v1.0.2", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lestrrat-go/jwx/v2@v2.1.4", + "Name": "github.com/lestrrat-go/jwx/v2", + "Identifier": { + "PURL": "pkg:golang/github.com/lestrrat-go/jwx/v2@v2.1.4", + "UID": "b8f24bb402d6b348" + }, + "Version": "v2.1.4", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lestrrat-go/option@v1.0.1", + "Name": "github.com/lestrrat-go/option", + "Identifier": { + "PURL": "pkg:golang/github.com/lestrrat-go/option@v1.0.1", + "UID": "e27d0abad3d92bff" + }, + "Version": "v1.0.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lucasb-eyer/go-colorful@v1.2.0", + "Name": "github.com/lucasb-eyer/go-colorful", + "Identifier": { + "PURL": "pkg:golang/github.com/lucasb-eyer/go-colorful@v1.2.0", + "UID": "9cd8d46c1246bdba" + }, + "Version": "v1.2.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/mattn/go-colorable@v0.1.14", + "Name": "github.com/mattn/go-colorable", + "Identifier": { + "PURL": "pkg:golang/github.com/mattn/go-colorable@v0.1.14", + "UID": "43dcde2f4accc8bb" + }, + "Version": "v0.1.14", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/mattn/go-ieproxy@v0.0.12", + "Name": "github.com/mattn/go-ieproxy", + "Identifier": { + "PURL": "pkg:golang/github.com/mattn/go-ieproxy@v0.0.12", + "UID": "8b34344da555397" + }, + "Version": "v0.0.12", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/mattn/go-isatty@v0.0.20", + "Name": "github.com/mattn/go-isatty", + "Identifier": { + "PURL": "pkg:golang/github.com/mattn/go-isatty@v0.0.20", + "UID": "bcdd900a2b530d5f" + }, + "Version": "v0.0.20", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/mattn/go-runewidth@v0.0.16", + "Name": "github.com/mattn/go-runewidth", + "Identifier": { + "PURL": "pkg:golang/github.com/mattn/go-runewidth@v0.0.16", + "UID": "543648c9f081db3c" + }, + "Version": "v0.0.16", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/matttproud/golang_protobuf_extensions@v1.0.4", + "Name": "github.com/matttproud/golang_protobuf_extensions", + "Identifier": { + "PURL": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.4", + "UID": "af999f443b51beb0" + }, + "Version": "v1.0.4", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/cli@v1.24.2", + "Name": "github.com/minio/cli", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/cli@v1.24.2", + "UID": "8f577e08000fe59b" + }, + "Version": "v1.24.2", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/colorjson@v1.0.8", + "Name": "github.com/minio/colorjson", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/colorjson@v1.0.8", + "UID": "fc821026bf4c34c1" + }, + "Version": "v1.0.8", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/crc64nvme@v1.0.1", + "Name": "github.com/minio/crc64nvme", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/crc64nvme@v1.0.1", + "UID": "d0dfbfea9a601eae" + }, + "Version": "v1.0.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/filepath@v1.0.0", + "Name": "github.com/minio/filepath", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/filepath@v1.0.0", + "UID": "b9a990cbe36fbd4d" + }, + "Version": "v1.0.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/madmin-go/v3@v3.0.107-0.20250415152934-4b504b82db63", + "Name": "github.com/minio/madmin-go/v3", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/madmin-go/v3@v3.0.107-0.20250415152934-4b504b82db63", + "UID": "7a4529fd53427dc5" + }, + "Version": "v3.0.107-0.20250415152934-4b504b82db63", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/md5-simd@v1.1.2", + "Name": "github.com/minio/md5-simd", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/md5-simd@v1.1.2", + "UID": "be3f4c8e01e752c8" + }, + "Version": "v1.1.2", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/minio-go/v7@v7.0.90", + "Name": "github.com/minio/minio-go/v7", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/minio-go/v7@v7.0.90", + "UID": "86098129ec3d5f30" + }, + "Version": "v7.0.90", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/pkg/v3@v3.1.0", + "Name": "github.com/minio/pkg/v3", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/pkg/v3@v3.1.0", + "UID": "371c34974adc9e38" + }, + "Version": "v3.1.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/selfupdate@v0.6.0", + "Name": "github.com/minio/selfupdate", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/selfupdate@v0.6.0", + "UID": "4827f3cae4baea38" + }, + "Version": "v0.6.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/mitchellh/go-homedir@v1.1.0", + "Name": "github.com/mitchellh/go-homedir", + "Identifier": { + "PURL": "pkg:golang/github.com/mitchellh/go-homedir@v1.1.0", + "UID": "4a383e8d1f53e29b" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/muesli/ansi@v0.0.0-20230316100256-276c6243b2f6", + "Name": "github.com/muesli/ansi", + "Identifier": { + "PURL": "pkg:golang/github.com/muesli/ansi@v0.0.0-20230316100256-276c6243b2f6", + "UID": "2c94a8673ad673fa" + }, + "Version": "v0.0.0-20230316100256-276c6243b2f6", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/muesli/cancelreader@v0.2.2", + "Name": "github.com/muesli/cancelreader", + "Identifier": { + "PURL": "pkg:golang/github.com/muesli/cancelreader@v0.2.2", + "UID": "759c5f0e9d43559a" + }, + "Version": "v0.2.2", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/muesli/reflow@v0.3.0", + "Name": "github.com/muesli/reflow", + "Identifier": { + "PURL": "pkg:golang/github.com/muesli/reflow@v0.3.0", + "UID": "b4d27ea6f15fa378" + }, + "Version": "v0.3.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/muesli/termenv@v0.16.0", + "Name": "github.com/muesli/termenv", + "Identifier": { + "PURL": "pkg:golang/github.com/muesli/termenv@v0.16.0", + "UID": "ee6ad80ce87af6ae" + }, + "Version": "v0.16.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/munnerz/goautoneg@v0.0.0-20191010083416-a7dc8b61c822", + "Name": "github.com/munnerz/goautoneg", + "Identifier": { + "PURL": "pkg:golang/github.com/munnerz/goautoneg@v0.0.0-20191010083416-a7dc8b61c822", + "UID": "7871db626b6df1f8" + }, + "Version": "v0.0.0-20191010083416-a7dc8b61c822", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/olekukonko/tablewriter@v0.0.5", + "Name": "github.com/olekukonko/tablewriter", + "Identifier": { + "PURL": "pkg:golang/github.com/olekukonko/tablewriter@v0.0.5", + "UID": "8a3e5fc8dd944666" + }, + "Version": "v0.0.5", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/philhofer/fwd@v1.1.3-0.20240916144458-20a13a1f6b7c", + "Name": "github.com/philhofer/fwd", + "Identifier": { + "PURL": "pkg:golang/github.com/philhofer/fwd@v1.1.3-0.20240916144458-20a13a1f6b7c", + "UID": "ef3b7c898a4650bf" + }, + "Version": "v1.1.3-0.20240916144458-20a13a1f6b7c", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/pkg/xattr@v0.4.10", + "Name": "github.com/pkg/xattr", + "Identifier": { + "PURL": "pkg:golang/github.com/pkg/xattr@v0.4.10", + "UID": "a6a628506fa20872" + }, + "Version": "v0.4.10", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/posener/complete@v1.2.3", + "Name": "github.com/posener/complete", + "Identifier": { + "PURL": "pkg:golang/github.com/posener/complete@v1.2.3", + "UID": "659b21703e6027ce" + }, + "Version": "v1.2.3", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/prometheus/client_golang@v1.21.1", + "Name": "github.com/prometheus/client_golang", + "Identifier": { + "PURL": "pkg:golang/github.com/prometheus/client_golang@v1.21.1", + "UID": "77e424d5b3488d88" + }, + "Version": "v1.21.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/prometheus/client_model@v0.6.2", + "Name": "github.com/prometheus/client_model", + "Identifier": { + "PURL": "pkg:golang/github.com/prometheus/client_model@v0.6.2", + "UID": "70d2240c40706b60" + }, + "Version": "v0.6.2", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/prometheus/common@v0.63.0", + "Name": "github.com/prometheus/common", + "Identifier": { + "PURL": "pkg:golang/github.com/prometheus/common@v0.63.0", + "UID": "791e2e5770475ba3" + }, + "Version": "v0.63.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/prometheus/procfs@v0.16.0", + "Name": "github.com/prometheus/procfs", + "Identifier": { + "PURL": "pkg:golang/github.com/prometheus/procfs@v0.16.0", + "UID": "204a768d18fcefd4" + }, + "Version": "v0.16.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/prometheus/prom2json@v1.4.2", + "Name": "github.com/prometheus/prom2json", + "Identifier": { + "PURL": "pkg:golang/github.com/prometheus/prom2json@v1.4.2", + "UID": "a2bca9d97721715f" + }, + "Version": "v1.4.2", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/prometheus/prometheus@v0.303.0", + "Name": "github.com/prometheus/prometheus", + "Identifier": { + "PURL": "pkg:golang/github.com/prometheus/prometheus@v0.303.0", + "UID": "8899d6a8d076bd15" + }, + "Version": "v0.303.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/rivo/uniseg@v0.4.7", + "Name": "github.com/rivo/uniseg", + "Identifier": { + "PURL": "pkg:golang/github.com/rivo/uniseg@v0.4.7", + "UID": "e16e241f3270821e" + }, + "Version": "v0.4.7", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/rjeczalik/notify@v0.9.3", + "Name": "github.com/rjeczalik/notify", + "Identifier": { + "PURL": "pkg:golang/github.com/rjeczalik/notify@v0.9.3", + "UID": "bf14f0fa542e31c2" + }, + "Version": "v0.9.3", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/rs/xid@v1.6.0", + "Name": "github.com/rs/xid", + "Identifier": { + "PURL": "pkg:golang/github.com/rs/xid@v1.6.0", + "UID": "aaef2e43d945ce9a" + }, + "Version": "v1.6.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/safchain/ethtool@v0.5.10", + "Name": "github.com/safchain/ethtool", + "Identifier": { + "PURL": "pkg:golang/github.com/safchain/ethtool@v0.5.10", + "UID": "b06860a6646ebe9e" + }, + "Version": "v0.5.10", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/secure-io/sio-go@v0.3.1", + "Name": "github.com/secure-io/sio-go", + "Identifier": { + "PURL": "pkg:golang/github.com/secure-io/sio-go@v0.3.1", + "UID": "c42c915e88ac061f" + }, + "Version": "v0.3.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/shirou/gopsutil/v3@v3.24.5", + "Name": "github.com/shirou/gopsutil/v3", + "Identifier": { + "PURL": "pkg:golang/github.com/shirou/gopsutil/v3@v3.24.5", + "UID": "5deb642a200ba45b" + }, + "Version": "v3.24.5", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/tidwall/gjson@v1.18.0", + "Name": "github.com/tidwall/gjson", + "Identifier": { + "PURL": "pkg:golang/github.com/tidwall/gjson@v1.18.0", + "UID": "d957fb941ee0c8c5" + }, + "Version": "v1.18.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/tidwall/match@v1.1.1", + "Name": "github.com/tidwall/match", + "Identifier": { + "PURL": "pkg:golang/github.com/tidwall/match@v1.1.1", + "UID": "7cadf89ae70486d" + }, + "Version": "v1.1.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/tidwall/pretty@v1.2.1", + "Name": "github.com/tidwall/pretty", + "Identifier": { + "PURL": "pkg:golang/github.com/tidwall/pretty@v1.2.1", + "UID": "60ad7d37f22283c8" + }, + "Version": "v1.2.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/tinylib/msgp@v1.2.5", + "Name": "github.com/tinylib/msgp", + "Identifier": { + "PURL": "pkg:golang/github.com/tinylib/msgp@v1.2.5", + "UID": "484b4c7ba52b5ee8" + }, + "Version": "v1.2.5", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/tklauser/go-sysconf@v0.3.15", + "Name": "github.com/tklauser/go-sysconf", + "Identifier": { + "PURL": "pkg:golang/github.com/tklauser/go-sysconf@v0.3.15", + "UID": "3ec141cd5b992d60" + }, + "Version": "v0.3.15", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/tklauser/numcpus@v0.10.0", + "Name": "github.com/tklauser/numcpus", + "Identifier": { + "PURL": "pkg:golang/github.com/tklauser/numcpus@v0.10.0", + "UID": "293ededa01b2b9ea" + }, + "Version": "v0.10.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/vbauerster/mpb/v8@v8.9.3", + "Name": "github.com/vbauerster/mpb/v8", + "Identifier": { + "PURL": "pkg:golang/github.com/vbauerster/mpb/v8@v8.9.3", + "UID": "38354397520e26c5" + }, + "Version": "v8.9.3", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.etcd.io/etcd/api/v3@v3.5.19", + "Name": "go.etcd.io/etcd/api/v3", + "Identifier": { + "PURL": "pkg:golang/go.etcd.io/etcd/api/v3@v3.5.19", + "UID": "cbbcb48c5ec464e2" + }, + "Version": "v3.5.19", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.etcd.io/etcd/client/pkg/v3@v3.5.19", + "Name": "go.etcd.io/etcd/client/pkg/v3", + "Identifier": { + "PURL": "pkg:golang/go.etcd.io/etcd/client/pkg/v3@v3.5.19", + "UID": "3be7df9f201dd5c2" + }, + "Version": "v3.5.19", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.etcd.io/etcd/client/v3@v3.5.19", + "Name": "go.etcd.io/etcd/client/v3", + "Identifier": { + "PURL": "pkg:golang/go.etcd.io/etcd/client/v3@v3.5.19", + "UID": "869749c571517cf6" + }, + "Version": "v3.5.19", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.uber.org/multierr@v1.11.0", + "Name": "go.uber.org/multierr", + "Identifier": { + "PURL": "pkg:golang/go.uber.org/multierr@v1.11.0", + "UID": "33f6c92a557c9b30" + }, + "Version": "v1.11.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.uber.org/zap@v1.27.0", + "Name": "go.uber.org/zap", + "Identifier": { + "PURL": "pkg:golang/go.uber.org/zap@v1.27.0", + "UID": "9cf0a6206cf6323a" + }, + "Version": "v1.27.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/crypto@v0.37.0", + "Name": "golang.org/x/crypto", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "ad969d790d8a7b9f" + }, + "Version": "v0.37.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/net@v0.39.0", + "Name": "golang.org/x/net", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/net@v0.39.0", + "UID": "c07998ad7f068689" + }, + "Version": "v0.39.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/sync@v0.13.0", + "Name": "golang.org/x/sync", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/sync@v0.13.0", + "UID": "74e67505f8373217" + }, + "Version": "v0.13.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/sys@v0.32.0", + "Name": "golang.org/x/sys", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/sys@v0.32.0", + "UID": "1f4728c29d07f052" + }, + "Version": "v0.32.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/term@v0.31.0", + "Name": "golang.org/x/term", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/term@v0.31.0", + "UID": "b6d99157675848aa" + }, + "Version": "v0.31.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/text@v0.24.0", + "Name": "golang.org/x/text", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.24.0", + "UID": "b8f5cc63e58b41f5" + }, + "Version": "v0.24.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "google.golang.org/genproto/googleapis/api@v0.0.0-20250311173030-29e43e6258d7", + "Name": "google.golang.org/genproto/googleapis/api", + "Identifier": { + "PURL": "pkg:golang/google.golang.org/genproto/googleapis/api@v0.0.0-20250311173030-29e43e6258d7", + "UID": "dd4a048b485ab5c5" + }, + "Version": "v0.0.0-20250311173030-29e43e6258d7", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "google.golang.org/genproto/googleapis/rpc@v0.0.0-20250303144028-a0af3efb3deb", + "Name": "google.golang.org/genproto/googleapis/rpc", + "Identifier": { + "PURL": "pkg:golang/google.golang.org/genproto/googleapis/rpc@v0.0.0-20250303144028-a0af3efb3deb", + "UID": "5d09a4fa5adf8ccc" + }, + "Version": "v0.0.0-20250303144028-a0af3efb3deb", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "google.golang.org/grpc@v1.71.0", + "Name": "google.golang.org/grpc", + "Identifier": { + "PURL": "pkg:golang/google.golang.org/grpc@v1.71.0", + "UID": "769ee0210348e70d" + }, + "Version": "v1.71.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "google.golang.org/protobuf@v1.36.6", + "Name": "google.golang.org/protobuf", + "Identifier": { + "PURL": "pkg:golang/google.golang.org/protobuf@v1.36.6", + "UID": "8a1b6cf082049aed" + }, + "Version": "v1.36.6", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "gopkg.in/yaml.v2@v2.4.0", + "Name": "gopkg.in/yaml.v2", + "Identifier": { + "PURL": "pkg:golang/gopkg.in/yaml.v2@v2.4.0", + "UID": "a40b2e8e4f572718" + }, + "Version": "v2.4.0", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "gopkg.in/yaml.v3@v3.0.1", + "Name": "gopkg.in/yaml.v3", + "Identifier": { + "PURL": "pkg:golang/gopkg.in/yaml.v3@v3.0.1", + "UID": "453309756c04854c" + }, + "Version": "v3.0.1", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "AnalyzedBy": "gobinary" + } + ], + "Vulnerabilities": [ + { + "VulnerabilityID": "CVE-2026-42151", + "VendorIDs": [ + "GHSA-wg65-39gg-5wfj" + ], + "PkgID": "github.com/prometheus/prometheus@v0.303.0", + "PkgName": "github.com/prometheus/prometheus", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/prometheus/prometheus@v0.303.0", + "UID": "8899d6a8d076bd15" + }, + "InstalledVersion": "v0.303.0", + "FixedVersion": "0.311.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42151", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:135c4f92c272b4ed8c29bd37a43e3c004d3a56241c5215e89c9ec6048d38909a", + "Title": "github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API", + "Description": "Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200", + "CWE-312", + "CWE-256" + ], + "VendorSeverity": { + "alma": 3, + "azure": 2, + "bitnami": 3, + "ghsa": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:25039", + "https://access.redhat.com/errata/RHSA-2026:25245", + "https://access.redhat.com/errata/RHSA-2026:25504", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:37267", + "https://access.redhat.com/errata/RHSA-2026:37271", + "https://access.redhat.com/errata/RHSA-2026:37272", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40768", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40970", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:40974", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:50874", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54288", + "https://access.redhat.com/errata/RHSA-2026:54427", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:60386", + "https://access.redhat.com/errata/RHSA-2026:60387", + "https://access.redhat.com/errata/RHSA-2026:60388", + "https://access.redhat.com/errata/RHSA-2026:60389", + "https://access.redhat.com/errata/RHSA-2026:60390", + "https://access.redhat.com/errata/RHSA-2026:60391", + "https://access.redhat.com/errata/RHSA-2026:60441", + "https://access.redhat.com/errata/RHSA-2026:60477", + "https://access.redhat.com/errata/RHSA-2026:63103", + "https://access.redhat.com/security/cve/CVE-2026-42151", + "https://bugzilla.redhat.com/2466505", + "https://bugzilla.redhat.com/2466507", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/2480761", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2466505", + "https://bugzilla.redhat.com/show_bug.cgi?id=2466507", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480761", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42151", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42154", + "https://errata.almalinux.org/9/ALSA-2026-34359.html", + "https://errata.rockylinux.org/RLSA-2026:34359", + "https://github.com/prometheus/prometheus", + "https://github.com/prometheus/prometheus/pull/18587", + "https://github.com/prometheus/prometheus/pull/18590", + "https://github.com/prometheus/prometheus/releases/tag/v3.11.3", + "https://github.com/prometheus/prometheus/releases/tag/v3.5.3", + "https://github.com/prometheus/prometheus/security/advisories/GHSA-wg65-39gg-5wfj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42151", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42151.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42151" + ], + "PublishedDate": "2026-05-04T19:16:04.22Z", + "LastModifiedDate": "2026-09-10T13:20:06.057Z" + }, + { + "VulnerabilityID": "CVE-2026-42154", + "VendorIDs": [ + "GHSA-8rm2-7qqf-34qm" + ], + "PkgID": "github.com/prometheus/prometheus@v0.303.0", + "PkgName": "github.com/prometheus/prometheus", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/prometheus/prometheus@v0.303.0", + "UID": "8899d6a8d076bd15" + }, + "InstalledVersion": "v0.303.0", + "FixedVersion": "0.311.3, 0.305.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42154", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:423c6b9e13e07f810b6c739ae5a64d86a55acdf5c5d47e23f510dc6bb5224047", + "Title": "github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint", + "Description": "Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-789", + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "bitnami": 3, + "ghsa": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:25039", + "https://access.redhat.com/errata/RHSA-2026:25245", + "https://access.redhat.com/errata/RHSA-2026:29770", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34794", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40792", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40970", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:40974", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:44235", + "https://access.redhat.com/errata/RHSA-2026:44263", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47728", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48699", + "https://access.redhat.com/errata/RHSA-2026:50758", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54288", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60386", + "https://access.redhat.com/security/cve/CVE-2026-42154", + "https://bugzilla.redhat.com/2466505", + "https://bugzilla.redhat.com/2466507", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/2480761", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2466505", + "https://bugzilla.redhat.com/show_bug.cgi?id=2466507", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480761", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42151", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42154", + "https://errata.almalinux.org/9/ALSA-2026-34359.html", + "https://errata.rockylinux.org/RLSA-2026:34359", + "https://github.com/prometheus/prometheus", + "https://github.com/prometheus/prometheus/pull/18584", + "https://github.com/prometheus/prometheus/pull/18585", + "https://github.com/prometheus/prometheus/releases/tag/v3.11.3", + "https://github.com/prometheus/prometheus/releases/tag/v3.5.3", + "https://github.com/prometheus/prometheus/security/advisories/GHSA-8rm2-7qqf-34qm", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42154", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42154.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42154" + ], + "PublishedDate": "2026-05-04T19:16:04.397Z", + "LastModifiedDate": "2026-09-10T13:20:07.003Z" + }, + { + "VulnerabilityID": "CVE-2025-47913", + "VendorIDs": [ + "GO-2025-4116" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "ad969d790d8a7b9f" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.43.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47913", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:78f6265f9a75e181fff393276eb86f56398ef439b7a8713f416bc3d89a5c1017", + "Title": "golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS", + "Description": "SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-617" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0470", + "https://access.redhat.com/security/cve/CVE-2025-47913", + "https://bugzilla.redhat.com/2414943", + "https://bugzilla.redhat.com/show_bug.cgi?id=2414943", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47913", + "https://errata.almalinux.org/9/ALSA-2026-0470.html", + "https://errata.rockylinux.org/RLSA-2026:0470", + "https://github.com/advisories/GHSA-56w8-48fp-6mgv", + "https://github.com/advisories/GHSA-hcg3-q754-cr77", + "https://go-review.googlesource.com/c/crypto/+/700295", + "https://go.dev/cl/700295", + "https://go.dev/issue/75178", + "https://linux.oracle.com/cve/CVE-2025-47913.html", + "https://linux.oracle.com/errata/ELSA-2026-0753.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47913", + "https://pkg.go.dev/vuln/GO-2025-4116", + "https://ubuntu.com/security/notices/USN-8519-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47913" + ], + "PublishedDate": "2025-11-13T22:15:51.28Z", + "LastModifiedDate": "2026-06-17T09:28:50.357Z" + }, + { + "VulnerabilityID": "CVE-2026-39828", + "VendorIDs": [ + "GO-2026-5014" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "ad969d790d8a7b9f" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39828", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:98110914e30a45861f76d71802f25053b68250d999fd585d7f5c57e942b4445f", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions", + "Description": "When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295", + "CWE-281" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 2, + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:37268", + "https://access.redhat.com/errata/RHSA-2026:37271", + "https://access.redhat.com/errata/RHSA-2026:37272", + "https://access.redhat.com/errata/RHSA-2026:37278", + "https://access.redhat.com/errata/RHSA-2026:37286", + "https://access.redhat.com/errata/RHSA-2026:37296", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40969", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:40974", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51038", + "https://access.redhat.com/errata/RHSA-2026:52857", + "https://access.redhat.com/errata/RHSA-2026:52910", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66521", + "https://access.redhat.com/security/cve/CVE-2026-39828", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480687", + "https://go.dev/cl/781621", + "https://go.dev/issue/79562", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39828", + "https://pkg.go.dev/vuln/GO-2026-5014", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39828.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39828" + ], + "PublishedDate": "2026-05-22T04:16:22.19Z", + "LastModifiedDate": "2026-09-11T13:17:51.26Z" + }, + { + "VulnerabilityID": "CVE-2026-39829", + "VendorIDs": [ + "GO-2026-5018" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "ad969d790d8a7b9f" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39829", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:431df678d5cae5434519048ce53d825a14cd3e87cddad8266fe489ac49bb6055", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters", + "Description": "The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-347", + "CWE-1284" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:35833", + "https://access.redhat.com/errata/RHSA-2026:36199", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37072", + "https://access.redhat.com/errata/RHSA-2026:37123", + "https://access.redhat.com/errata/RHSA-2026:37268", + "https://access.redhat.com/errata/RHSA-2026:37271", + "https://access.redhat.com/errata/RHSA-2026:37272", + "https://access.redhat.com/errata/RHSA-2026:37278", + "https://access.redhat.com/errata/RHSA-2026:37286", + "https://access.redhat.com/errata/RHSA-2026:37296", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40969", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:40974", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47949", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:48693", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:52857", + "https://access.redhat.com/errata/RHSA-2026:52910", + "https://access.redhat.com/errata/RHSA-2026:54400", + "https://access.redhat.com/errata/RHSA-2026:54432", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57365", + "https://access.redhat.com/errata/RHSA-2026:57801", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59559", + "https://access.redhat.com/errata/RHSA-2026:59593", + "https://access.redhat.com/errata/RHSA-2026:60446", + "https://access.redhat.com/errata/RHSA-2026:60454", + "https://access.redhat.com/errata/RHSA-2026:60477", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65964", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/security/cve/CVE-2026-39829", + "https://bugzilla.redhat.com/2480680", + "https://bugzilla.redhat.com/2480681", + "https://bugzilla.redhat.com/2480685", + "https://bugzilla.redhat.com/2480688", + "https://bugzilla.redhat.com/2480757", + "https://bugzilla.redhat.com/2480761", + "https://bugzilla.redhat.com/2493620", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480680", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480681", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480685", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480688", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480757", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480761", + "https://bugzilla.redhat.com/show_bug.cgi?id=2493620", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42508", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57231", + "https://errata.almalinux.org/9/ALSA-2026-37123.html", + "https://errata.rockylinux.org/RLSA-2026:37123", + "https://go.dev/cl/781641", + "https://go.dev/cl/781661", + "https://go.dev/issue/79565", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://linux.oracle.com/cve/CVE-2026-39829.html", + "https://linux.oracle.com/errata/ELSA-2026-37123.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39829", + "https://pkg.go.dev/vuln/GO-2026-5018", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39829.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39829" + ], + "PublishedDate": "2026-05-22T04:16:22.31Z", + "LastModifiedDate": "2026-09-11T13:17:52.607Z" + }, + { + "VulnerabilityID": "CVE-2026-39830", + "VendorIDs": [ + "GO-2026-5017" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "ad969d790d8a7b9f" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39830", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:eb3ad04afcc0f23d6c07048ff0fe60d1b0ed8e563635fb2e396e1ab5cc925041", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses", + "Description": "A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-119", + "CWE-772" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:35833", + "https://access.redhat.com/errata/RHSA-2026:36199", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:37072", + "https://access.redhat.com/errata/RHSA-2026:37268", + "https://access.redhat.com/errata/RHSA-2026:37271", + "https://access.redhat.com/errata/RHSA-2026:37272", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:37278", + "https://access.redhat.com/errata/RHSA-2026:37286", + "https://access.redhat.com/errata/RHSA-2026:37296", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40969", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:40974", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:52857", + "https://access.redhat.com/errata/RHSA-2026:52910", + "https://access.redhat.com/errata/RHSA-2026:54400", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57801", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:65964", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66521", + "https://access.redhat.com/security/cve/CVE-2026-39830", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/2480681", + "https://bugzilla.redhat.com/2480684", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480681", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480684", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39830", + "https://errata.almalinux.org/9/ALSA-2026-29455.html", + "https://errata.rockylinux.org/RLSA-2026:29455", + "https://github.com/golang/crypto/commit/4e7a7384ecbc8d519f6f4c11b36fa9d761fc8946", + "https://go.dev/cl/781640", + "https://go.dev/cl/781664", + "https://go.dev/issue/79564", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://linux.oracle.com/cve/CVE-2026-39830.html", + "https://linux.oracle.com/errata/ELSA-2026-37072.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39830", + "https://pkg.go.dev/vuln/GO-2026-5017", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39830.json", + "https://ubuntu.com/security/notices/USN-8447-1", + "https://ubuntu.com/security/notices/USN-8447-2", + "https://ubuntu.com/security/notices/USN-8447-3", + "https://www.cve.org/CVERecord?id=CVE-2026-39830" + ], + "PublishedDate": "2026-05-22T04:16:22.44Z", + "LastModifiedDate": "2026-09-11T13:17:53.97Z" + }, + { + "VulnerabilityID": "CVE-2026-39831", + "VendorIDs": [ + "GO-2026-5019" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "ad969d790d8a7b9f" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39831", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:5d3522c28090436b1f5d784de746b60d4fb84d7cfd77e766628e63779bedab17", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check", + "Description": "The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a \"no-touch-required\" extension in Permissions.Extensions from PublicKeyCallback.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-862" + ], + "VendorSeverity": { + "amazon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-39831", + "https://github.com/golang/crypto/commit/b61cf853a89d82cad68da5e12a6beca2116f8456", + "https://go.dev/cl/781662", + "https://go.dev/issue/79566", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39831", + "https://pkg.go.dev/vuln/GO-2026-5019", + "https://ubuntu.com/security/notices/USN-8447-1", + "https://ubuntu.com/security/notices/USN-8447-3", + "https://www.cve.org/CVERecord?id=CVE-2026-39831" + ], + "PublishedDate": "2026-05-22T04:16:22.553Z", + "LastModifiedDate": "2026-07-23T16:10:00.137Z" + }, + { + "VulnerabilityID": "CVE-2026-39832", + "VendorIDs": [ + "GHSA-f5wc-c3c7-36mc", + "GO-2026-5006" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "ad969d790d8a7b9f" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39832", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:cceed63e7e6155e8a23fc562c918d81b2e991dc02d6e9bf989f2fa5af7a0213f", + "Title": "golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions", + "Description": "When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502", + "CWE-281" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N", + "V3Score": 8.7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:35833", + "https://access.redhat.com/errata/RHSA-2026:36199", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:37072", + "https://access.redhat.com/errata/RHSA-2026:37123", + "https://access.redhat.com/errata/RHSA-2026:37271", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37410", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:52857", + "https://access.redhat.com/errata/RHSA-2026:52910", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:59579", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:66521", + "https://access.redhat.com/security/cve/CVE-2026-39832", + "https://bugzilla.redhat.com/2480680", + "https://bugzilla.redhat.com/2480685", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480680", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480685", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835", + "https://errata.almalinux.org/9/ALSA-2026-37410.html", + "https://errata.rockylinux.org/RLSA-2026:37410", + "https://github.com/golang/crypto/commit/e3d1254f1e7e60baa086142c46174bf6d8d0fe50", + "https://go.dev/cl/778640", + "https://go.dev/cl/778641", + "https://go.dev/cl/778642", + "https://go.dev/issue/79435", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://linux.oracle.com/cve/CVE-2026-39832.html", + "https://linux.oracle.com/errata/ELSA-2026-37410.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39832", + "https://pkg.go.dev/vuln/GO-2026-5006", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json", + "https://ubuntu.com/security/notices/USN-8447-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39832" + ], + "PublishedDate": "2026-05-22T04:16:22.663Z", + "LastModifiedDate": "2026-09-11T13:17:55.683Z" + }, + { + "VulnerabilityID": "CVE-2026-39835", + "VendorIDs": [ + "GO-2026-5015" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "ad969d790d8a7b9f" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39835", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:01adece934ba25f6c6c87704000ce27416ba7ab154034902d10ac9bd2ab6a8de", + "Title": "golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate", + "Description": "SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295", + "CWE-476" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:36199", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:37072", + "https://access.redhat.com/errata/RHSA-2026:37123", + "https://access.redhat.com/errata/RHSA-2026:37268", + "https://access.redhat.com/errata/RHSA-2026:37271", + "https://access.redhat.com/errata/RHSA-2026:37272", + "https://access.redhat.com/errata/RHSA-2026:37286", + "https://access.redhat.com/errata/RHSA-2026:37296", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37410", + "https://access.redhat.com/errata/RHSA-2026:38504", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40969", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:40974", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47949", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51036", + "https://access.redhat.com/errata/RHSA-2026:51038", + "https://access.redhat.com/errata/RHSA-2026:52857", + "https://access.redhat.com/errata/RHSA-2026:52910", + "https://access.redhat.com/errata/RHSA-2026:54525", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59593", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:62260", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66521", + "https://access.redhat.com/security/cve/CVE-2026-39835", + "https://bugzilla.redhat.com/2480680", + "https://bugzilla.redhat.com/2480685", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480680", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480685", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835", + "https://errata.almalinux.org/9/ALSA-2026-37410.html", + "https://errata.rockylinux.org/RLSA-2026:37410", + "https://go.dev/cl/781660", + "https://go.dev/issue/79563", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://linux.oracle.com/cve/CVE-2026-39835.html", + "https://linux.oracle.com/errata/ELSA-2026-38504.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39835", + "https://pkg.go.dev/vuln/GO-2026-5015", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39835.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39835" + ], + "PublishedDate": "2026-05-22T04:16:24.53Z", + "LastModifiedDate": "2026-09-11T13:17:56.5Z" + }, + { + "VulnerabilityID": "CVE-2026-42508", + "VendorIDs": [ + "GHSA-5cgq-3rg8-m6cv", + "GO-2026-5021" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "ad969d790d8a7b9f" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42508", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:5b5ba9006578dc28b400dd41c577ad1cc7974b5a1f7e9607aa56fde0dcac31de", + "Title": "golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey", + "Description": "Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:35833", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:37072", + "https://access.redhat.com/errata/RHSA-2026:37123", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41064", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:52857", + "https://access.redhat.com/errata/RHSA-2026:52910", + "https://access.redhat.com/errata/RHSA-2026:54400", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66521", + "https://access.redhat.com/security/cve/CVE-2026-42508", + "https://bugzilla.redhat.com/2480680", + "https://bugzilla.redhat.com/2480681", + "https://bugzilla.redhat.com/2480685", + "https://bugzilla.redhat.com/2480688", + "https://bugzilla.redhat.com/2480757", + "https://bugzilla.redhat.com/2480761", + "https://bugzilla.redhat.com/2493620", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480680", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480681", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480685", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480688", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480757", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480761", + "https://bugzilla.redhat.com/show_bug.cgi?id=2493620", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42508", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57231", + "https://errata.almalinux.org/9/ALSA-2026-37123.html", + "https://errata.rockylinux.org/RLSA-2026:37123", + "https://github.com/golang/crypto/commit/f717e29698a271c548239ed56bf5dd9516d6f7e8", + "https://go.dev/cl/781220", + "https://go.dev/issue/79568", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://linux.oracle.com/cve/CVE-2026-42508.html", + "https://linux.oracle.com/errata/ELSA-2026-37123.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42508", + "https://pkg.go.dev/vuln/GO-2026-5021", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json", + "https://ubuntu.com/security/notices/USN-8447-1", + "https://ubuntu.com/security/notices/USN-8447-2", + "https://www.cve.org/CVERecord?id=CVE-2026-42508" + ], + "PublishedDate": "2026-05-22T04:16:25.44Z", + "LastModifiedDate": "2026-09-11T13:18:00.947Z" + }, + { + "VulnerabilityID": "CVE-2026-46595", + "VendorIDs": [ + "GO-2026-5023" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "ad969d790d8a7b9f" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-46595", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:99370bea7a9f40498a84a755b0474cd763804e9e551941a50588dcecdd5258c5", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation", + "Description": "Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-863", + "CWE-303" + ], + "VendorSeverity": { + "amazon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59558", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66521", + "https://access.redhat.com/security/cve/CVE-2026-46595", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480689", + "https://github.com/golang/crypto/commit/533fb3f7e4a5ae23f69d1837cd851d35ff5b76ce", + "https://go.dev/cl/781642", + "https://go.dev/issue/79570", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-46595", + "https://pkg.go.dev/vuln/GO-2026-5023", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json", + "https://ubuntu.com/security/notices/USN-8447-1", + "https://ubuntu.com/security/notices/USN-8447-3", + "https://www.cve.org/CVERecord?id=CVE-2026-46595" + ], + "PublishedDate": "2026-05-22T04:16:25.55Z", + "LastModifiedDate": "2026-09-11T13:18:12.367Z" + }, + { + "VulnerabilityID": "CVE-2026-46597", + "VendorIDs": [ + "GO-2026-5013" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "ad969d790d8a7b9f" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-46597", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d88fce0b3b647585d5cc3573b1bde5618b91cc04ac0a8cf18b37fba1154f98cc", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs", + "Description": "An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-704" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 3, + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-46597", + "https://go.dev/cl/781620", + "https://go.dev/issue/79561", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-46597", + "https://pkg.go.dev/vuln/GO-2026-5013", + "https://www.cve.org/CVERecord?id=CVE-2026-46597" + ], + "PublishedDate": "2026-05-22T04:16:26.003Z", + "LastModifiedDate": "2026-07-23T16:10:00.137Z" + }, + { + "VulnerabilityID": "CVE-2026-56854", + "VendorIDs": [ + "GO-2026-6303" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "ad969d790d8a7b9f" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.55.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56854", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:9d07a3f7d83d370195d942c3fdcb64347f0d6bafd207dd2f9de34403e6674d60", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions", + "Description": "The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-863" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56854", + "https://go.dev/cl/797040", + "https://go.dev/issue/80213", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56854", + "https://pkg.go.dev/vuln/GO-2026-6303", + "https://www.cve.org/CVERecord?id=CVE-2026-56854" + ], + "PublishedDate": "2026-08-28T16:18:17.607Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-25681", + "VendorIDs": [ + "GO-2026-5029" + ], + "PkgID": "golang.org/x/net@v0.39.0", + "PkgName": "golang.org/x/net", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/net@v0.39.0", + "UID": "c07998ad7f068689" + }, + "InstalledVersion": "v0.39.0", + "FixedVersion": "0.55.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25681", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:8e5bc42fd0f654cc109a4ca3d27a0b3a569256e9faa31e18d38aae4400edd326", + "Title": "golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting", + "Description": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1021" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:37123", + "https://access.redhat.com/security/cve/CVE-2026-25681", + "https://bugzilla.redhat.com/2480680", + "https://bugzilla.redhat.com/2480681", + "https://bugzilla.redhat.com/2480685", + "https://bugzilla.redhat.com/2480688", + "https://bugzilla.redhat.com/2480757", + "https://bugzilla.redhat.com/2480761", + "https://bugzilla.redhat.com/2493620", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480680", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480681", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480685", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480688", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480757", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480761", + "https://bugzilla.redhat.com/show_bug.cgi?id=2493620", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42508", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57231", + "https://errata.almalinux.org/9/ALSA-2026-37123.html", + "https://errata.rockylinux.org/RLSA-2026:37123", + "https://go.dev/cl/781703", + "https://go.dev/issue/79574", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-25681.html", + "https://linux.oracle.com/errata/ELSA-2026-37123.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25681", + "https://pkg.go.dev/vuln/GO-2026-5029", + "https://www.cve.org/CVERecord?id=CVE-2026-25681" + ], + "PublishedDate": "2026-05-22T16:16:19.863Z", + "LastModifiedDate": "2026-07-23T16:10:00.137Z" + }, + { + "VulnerabilityID": "CVE-2026-27136", + "VendorIDs": [ + "GO-2026-5030" + ], + "PkgID": "golang.org/x/net@v0.39.0", + "PkgName": "golang.org/x/net", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/net@v0.39.0", + "UID": "c07998ad7f068689" + }, + "InstalledVersion": "v0.39.0", + "FixedVersion": "0.55.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27136", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f76c22f0fc3a97522f34e01468f02ff3d18d7d49bdf45b6fbe942328034587b3", + "Title": "golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass", + "Description": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1021" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:37123", + "https://access.redhat.com/security/cve/CVE-2026-27136", + "https://bugzilla.redhat.com/2480680", + "https://bugzilla.redhat.com/2480681", + "https://bugzilla.redhat.com/2480685", + "https://bugzilla.redhat.com/2480688", + "https://bugzilla.redhat.com/2480757", + "https://bugzilla.redhat.com/2480761", + "https://bugzilla.redhat.com/2493620", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480680", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480681", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480685", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480688", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480757", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480761", + "https://bugzilla.redhat.com/show_bug.cgi?id=2493620", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42508", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57231", + "https://errata.almalinux.org/9/ALSA-2026-37123.html", + "https://errata.rockylinux.org/RLSA-2026:37123", + "https://go.dev/cl/781685", + "https://go.dev/issue/79575", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-27136.html", + "https://linux.oracle.com/errata/ELSA-2026-37123.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27136", + "https://pkg.go.dev/vuln/GO-2026-5030", + "https://www.cve.org/CVERecord?id=CVE-2026-27136" + ], + "PublishedDate": "2026-05-22T16:16:20.087Z", + "LastModifiedDate": "2026-07-23T16:10:00.137Z" + }, + { + "VulnerabilityID": "CVE-2026-33814", + "VendorIDs": [ + "GO-2026-4918" + ], + "PkgID": "golang.org/x/net@v0.39.0", + "PkgName": "golang.org/x/net", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/net@v0.39.0", + "UID": "c07998ad7f068689" + }, + "InstalledVersion": "v0.39.0", + "FixedVersion": "0.53.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b2ae0edebc07e674658b47cba5672a31b8848a6bbb5ce3a644ecb1e23e7590b0", + "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", + "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57365", + "https://access.redhat.com/errata/RHSA-2026:57367", + "https://access.redhat.com/errata/RHSA-2026:57408", + "https://access.redhat.com/errata/RHSA-2026:57545", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60023", + "https://access.redhat.com/errata/RHSA-2026:60025", + "https://access.redhat.com/errata/RHSA-2026:60441", + "https://access.redhat.com/errata/RHSA-2026:60442", + "https://access.redhat.com/errata/RHSA-2026:60446", + "https://access.redhat.com/errata/RHSA-2026:60447", + "https://access.redhat.com/errata/RHSA-2026:60454", + "https://access.redhat.com/errata/RHSA-2026:60477", + "https://access.redhat.com/errata/RHSA-2026:60478", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:60668", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62550", + "https://access.redhat.com/errata/RHSA-2026:62551", + "https://access.redhat.com/errata/RHSA-2026:63046", + "https://access.redhat.com/errata/RHSA-2026:63047", + "https://access.redhat.com/errata/RHSA-2026:63048", + "https://access.redhat.com/errata/RHSA-2026:63050", + "https://access.redhat.com/errata/RHSA-2026:63091", + "https://access.redhat.com/errata/RHSA-2026:63096", + "https://access.redhat.com/errata/RHSA-2026:63097", + "https://access.redhat.com/errata/RHSA-2026:63103", + "https://access.redhat.com/errata/RHSA-2026:63104", + "https://access.redhat.com/errata/RHSA-2026:63636", + "https://access.redhat.com/errata/RHSA-2026:63637", + "https://access.redhat.com/errata/RHSA-2026:63639", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/security/cve/CVE-2026-33814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467810", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467811", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467813", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467823", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467825", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467826", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467827", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501", + "https://errata.rockylinux.org/RLSA-2026:22121", + "https://github.com/golang/go/issues/78476", + "https://go-review.googlesource.com/c/go/+/761581", + "https://go-review.googlesource.com/c/net/+/761640", + "https://go.dev/cl/761581", + "https://go.dev/cl/761640", + "https://go.dev/issue/78476", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33814.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", + "https://pkg.go.dev/vuln/GO-2026-4918", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", + "https://ubuntu.com/security/notices/USN-8430-1", + "https://ubuntu.com/security/notices/USN-8471-1", + "https://ubuntu.com/security/notices/USN-8472-1", + "https://ubuntu.com/security/notices/USN-8473-1", + "https://www.cve.org/CVERecord?id=CVE-2026-33814" + ], + "PublishedDate": "2026-05-07T20:16:42.88Z", + "LastModifiedDate": "2026-09-10T13:18:21.31Z" + }, + { + "VulnerabilityID": "CVE-2026-39821", + "VendorIDs": [ + "GO-2026-5026" + ], + "PkgID": "golang.org/x/net@v0.39.0", + "PkgName": "golang.org/x/net", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/net@v0.39.0", + "UID": "c07998ad7f068689" + }, + "InstalledVersion": "v0.39.0", + "FixedVersion": "0.55.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:108d8399ea47444e34bdb6132c3604b0fdb774f4443d04133cc6a31a9eeafa2b", + "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", + "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1289" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:30853", + "https://access.redhat.com/errata/RHSA-2026:30854", + "https://access.redhat.com/errata/RHSA-2026:30855", + "https://access.redhat.com/errata/RHSA-2026:33155", + "https://access.redhat.com/errata/RHSA-2026:33160", + "https://access.redhat.com/errata/RHSA-2026:33163", + "https://access.redhat.com/errata/RHSA-2026:33173", + "https://access.redhat.com/errata/RHSA-2026:33183", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34789", + "https://access.redhat.com/errata/RHSA-2026:35826", + "https://access.redhat.com/errata/RHSA-2026:35827", + "https://access.redhat.com/errata/RHSA-2026:35828", + "https://access.redhat.com/errata/RHSA-2026:35829", + "https://access.redhat.com/errata/RHSA-2026:35830", + "https://access.redhat.com/errata/RHSA-2026:35831", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37435", + "https://access.redhat.com/errata/RHSA-2026:37436", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:44624", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:52826", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54395", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54580", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56143", + "https://access.redhat.com/errata/RHSA-2026:56223", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56431", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57541", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:59546", + "https://access.redhat.com/errata/RHSA-2026:59549", + "https://access.redhat.com/errata/RHSA-2026:59562", + "https://access.redhat.com/errata/RHSA-2026:60315", + "https://access.redhat.com/errata/RHSA-2026:60354", + "https://access.redhat.com/errata/RHSA-2026:60387", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61245", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62549", + "https://access.redhat.com/errata/RHSA-2026:63134", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65153", + "https://access.redhat.com/errata/RHSA-2026:65359", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:66016", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66432", + "https://access.redhat.com/security/cve/CVE-2026-39821", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-37435.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://github.com/golang/go/issues/78760", + "https://go.dev/cl/767220", + "https://go.dev/issue/78760", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-39821.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", + "https://pkg.go.dev/vuln/GO-2026-5026", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", + "https://ubuntu.com/security/notices/USN-8416-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39821" + ], + "PublishedDate": "2026-05-22T16:16:20.41Z", + "LastModifiedDate": "2026-09-11T13:17:49.237Z" + }, + { + "VulnerabilityID": "CVE-2026-46600", + "VendorIDs": [ + "GO-2026-5942" + ], + "PkgID": "golang.org/x/net@v0.39.0", + "PkgName": "golang.org/x/net", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/net@v0.39.0", + "UID": "c07998ad7f068689" + }, + "InstalledVersion": "v0.39.0", + "FixedVersion": "0.56.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-46600", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6f16f2bcdd9b69de36ab6c1538b7739504ee98e5eeae776007de92caa4dc77bc", + "Title": "golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing", + "Description": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-125" + ], + "VendorSeverity": { + "azure": 2, + "bitnami": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-46600", + "https://go.dev/cl/786345", + "https://go.dev/issue/79795", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-46600", + "https://pkg.go.dev/vuln/GO-2026-5942", + "https://www.cve.org/CVERecord?id=CVE-2026-46600" + ], + "PublishedDate": "2026-07-21T20:17:01.213Z", + "LastModifiedDate": "2026-08-14T16:16:55.673Z" + }, + { + "VulnerabilityID": "CVE-2026-56852", + "VendorIDs": [ + "GO-2026-5970" + ], + "PkgID": "golang.org/x/text@v0.24.0", + "PkgName": "golang.org/x/text", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.24.0", + "UID": "b8f5cc63e58b41f5" + }, + "InstalledVersion": "v0.24.0", + "FixedVersion": "0.39.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56852", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1cc356b5135a6916b7052c3f76bb3b6f842a0cde7dad7383d242fb9659a859f1", + "Title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input", + "Description": "A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 3, + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56852", + "https://go.dev/cl/794100", + "https://go.dev/issue/80142", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56852", + "https://pkg.go.dev/vuln/GO-2026-5970", + "https://www.cve.org/CVERecord?id=CVE-2026-56852" + ], + "PublishedDate": "2026-07-21T20:17:02.867Z", + "LastModifiedDate": "2026-07-23T18:27:48.877Z" + }, + { + "VulnerabilityID": "CVE-2026-33186", + "VendorIDs": [ + "GHSA-p77j-4mvh-x3m3" + ], + "PkgID": "google.golang.org/grpc@v1.71.0", + "PkgName": "google.golang.org/grpc", + "PkgIdentifier": { + "PURL": "pkg:golang/google.golang.org/grpc@v1.71.0", + "UID": "769ee0210348e70d" + }, + "InstalledVersion": "v1.71.0", + "FixedVersion": "1.79.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33186", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:4c654da24921f0f4f99bf2cb81f6fcb4046a4995c08ac100c9c3114d5a855082", + "Title": "google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation", + "Description": "gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, \"deny\" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback \"allow\" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific \"deny\" rules for canonical paths but allows other requests by default (a fallback \"allow\" rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers with a non-canonical path string. While upgrading is the most secure and recommended path, users can mitigate the vulnerability using one of the following methods: Use a validating interceptor (recommended mitigation); infrastructure-level normalization; and/or policy hardening.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-285", + "CWE-551" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "ghsa": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10093", + "https://access.redhat.com/errata/RHSA-2026:10094", + "https://access.redhat.com/errata/RHSA-2026:10105", + "https://access.redhat.com/errata/RHSA-2026:10107", + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10126", + "https://access.redhat.com/errata/RHSA-2026:10130", + "https://access.redhat.com/errata/RHSA-2026:10131", + "https://access.redhat.com/errata/RHSA-2026:10153", + "https://access.redhat.com/errata/RHSA-2026:10155", + "https://access.redhat.com/errata/RHSA-2026:10158", + "https://access.redhat.com/errata/RHSA-2026:10172", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10698", + "https://access.redhat.com/errata/RHSA-2026:10705", + "https://access.redhat.com/errata/RHSA-2026:10706", + "https://access.redhat.com/errata/RHSA-2026:11070", + "https://access.redhat.com/errata/RHSA-2026:11408", + "https://access.redhat.com/errata/RHSA-2026:11803", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12116", + "https://access.redhat.com/errata/RHSA-2026:12118", + "https://access.redhat.com/errata/RHSA-2026:12119", + "https://access.redhat.com/errata/RHSA-2026:12277", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:12283", + "https://access.redhat.com/errata/RHSA-2026:12337", + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14775", + "https://access.redhat.com/errata/RHSA-2026:15092", + "https://access.redhat.com/errata/RHSA-2026:17123", + "https://access.redhat.com/errata/RHSA-2026:17448", + "https://access.redhat.com/errata/RHSA-2026:17459", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17474", + "https://access.redhat.com/errata/RHSA-2026:17475", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:17599", + "https://access.redhat.com/errata/RHSA-2026:17789", + "https://access.redhat.com/errata/RHSA-2026:18068", + "https://access.redhat.com/errata/RHSA-2026:18585", + "https://access.redhat.com/errata/RHSA-2026:19099", + "https://access.redhat.com/errata/RHSA-2026:19108", + "https://access.redhat.com/errata/RHSA-2026:19109", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19207", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:20034", + "https://access.redhat.com/errata/RHSA-2026:20035", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20042", + "https://access.redhat.com/errata/RHSA-2026:20088", + "https://access.redhat.com/errata/RHSA-2026:20089", + "https://access.redhat.com/errata/RHSA-2026:20322", + "https://access.redhat.com/errata/RHSA-2026:20436", + "https://access.redhat.com/errata/RHSA-2026:20943", + "https://access.redhat.com/errata/RHSA-2026:20946", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21658", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:21692", + "https://access.redhat.com/errata/RHSA-2026:21696", + "https://access.redhat.com/errata/RHSA-2026:21697", + "https://access.redhat.com/errata/RHSA-2026:21703", + "https://access.redhat.com/errata/RHSA-2026:21704", + "https://access.redhat.com/errata/RHSA-2026:21709", + "https://access.redhat.com/errata/RHSA-2026:21710", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21931", + "https://access.redhat.com/errata/RHSA-2026:21932", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22645", + "https://access.redhat.com/errata/RHSA-2026:22689", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22800", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:22959", + "https://access.redhat.com/errata/RHSA-2026:22961", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23234", + "https://access.redhat.com/errata/RHSA-2026:23235", + "https://access.redhat.com/errata/RHSA-2026:23241", + "https://access.redhat.com/errata/RHSA-2026:23246", + "https://access.redhat.com/errata/RHSA-2026:23247", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24484", + "https://access.redhat.com/errata/RHSA-2026:24506", + "https://access.redhat.com/errata/RHSA-2026:24535", + "https://access.redhat.com/errata/RHSA-2026:24536", + "https://access.redhat.com/errata/RHSA-2026:24759", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25009", + "https://access.redhat.com/errata/RHSA-2026:25045", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25182", + "https://access.redhat.com/errata/RHSA-2026:25183", + "https://access.redhat.com/errata/RHSA-2026:25187", + "https://access.redhat.com/errata/RHSA-2026:25194", + "https://access.redhat.com/errata/RHSA-2026:25195", + "https://access.redhat.com/errata/RHSA-2026:25201", + "https://access.redhat.com/errata/RHSA-2026:26412", + "https://access.redhat.com/errata/RHSA-2026:26413", + "https://access.redhat.com/errata/RHSA-2026:26416", + "https://access.redhat.com/errata/RHSA-2026:26420", + "https://access.redhat.com/errata/RHSA-2026:26519", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26997", + "https://access.redhat.com/errata/RHSA-2026:26999", + "https://access.redhat.com/errata/RHSA-2026:27001", + "https://access.redhat.com/errata/RHSA-2026:27004", + "https://access.redhat.com/errata/RHSA-2026:27063", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:27712", + "https://access.redhat.com/errata/RHSA-2026:27856", + "https://access.redhat.com/errata/RHSA-2026:27892", + "https://access.redhat.com/errata/RHSA-2026:27893", + "https://access.redhat.com/errata/RHSA-2026:27901", + "https://access.redhat.com/errata/RHSA-2026:27957", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28893", + "https://access.redhat.com/errata/RHSA-2026:28964", + "https://access.redhat.com/errata/RHSA-2026:29079", + "https://access.redhat.com/errata/RHSA-2026:29082", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:34049", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34099", + "https://access.redhat.com/errata/RHSA-2026:34100", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34769", + "https://access.redhat.com/errata/RHSA-2026:34794", + "https://access.redhat.com/errata/RHSA-2026:34795", + "https://access.redhat.com/errata/RHSA-2026:36611", + "https://access.redhat.com/errata/RHSA-2026:36621", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:37192", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:37580", + "https://access.redhat.com/errata/RHSA-2026:37585", + "https://access.redhat.com/errata/RHSA-2026:40022", + "https://access.redhat.com/errata/RHSA-2026:40030", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40792", + "https://access.redhat.com/errata/RHSA-2026:40795", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40984", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:41944", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43225", + "https://access.redhat.com/errata/RHSA-2026:43227", + "https://access.redhat.com/errata/RHSA-2026:43253", + "https://access.redhat.com/errata/RHSA-2026:43331", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44233", + "https://access.redhat.com/errata/RHSA-2026:44235", + "https://access.redhat.com/errata/RHSA-2026:47728", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48699", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:50758", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:53728", + "https://access.redhat.com/errata/RHSA-2026:53763", + "https://access.redhat.com/errata/RHSA-2026:53773", + "https://access.redhat.com/errata/RHSA-2026:53804", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56366", + "https://access.redhat.com/errata/RHSA-2026:56431", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:56959", + "https://access.redhat.com/errata/RHSA-2026:57013", + "https://access.redhat.com/errata/RHSA-2026:57365", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60146", + "https://access.redhat.com/errata/RHSA-2026:61245", + "https://access.redhat.com/errata/RHSA-2026:6174", + "https://access.redhat.com/errata/RHSA-2026:6428", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6802", + "https://access.redhat.com/errata/RHSA-2026:7110", + "https://access.redhat.com/errata/RHSA-2026:7128", + "https://access.redhat.com/errata/RHSA-2026:7245", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8449", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:8484", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9388", + "https://access.redhat.com/errata/RHSA-2026:9440", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/errata/RHSA-2026:9872", + "https://access.redhat.com/security/cve/CVE-2026-33186", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2449833", + "https://bugzilla.redhat.com/2455470", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456335", + "https://bugzilla.redhat.com/2456336", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445345", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2449833", + "https://bugzilla.redhat.com/show_bug.cgi?id=2455470", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456336", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27137", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32282", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33186", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34986", + "https://errata.almalinux.org/9/ALSA-2026-19353.html", + "https://errata.rockylinux.org/RLSA-2026:23228", + "https://github.com/grpc/grpc-go", + "https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3", + "https://linux.oracle.com/cve/CVE-2026-33186.html", + "https://linux.oracle.com/errata/ELSA-2026-48790.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33186", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33186.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33186" + ], + "PublishedDate": "2026-03-20T23:16:45.18Z", + "LastModifiedDate": "2026-09-11T13:17:30.047Z" + }, + { + "VulnerabilityID": "CVE-2026-84304", + "VendorIDs": [ + "GHSA-vp52-pcj8-j9qc" + ], + "PkgID": "google.golang.org/grpc@v1.71.0", + "PkgName": "google.golang.org/grpc", + "PkgIdentifier": { + "PURL": "pkg:golang/google.golang.org/grpc@v1.71.0", + "UID": "769ee0210348e70d" + }, + "InstalledVersion": "v1.71.0", + "FixedVersion": "1.83.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-84304", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:dff4d2d82526483d8a2f6f4e1352102dd84e072b70cfe86e5073e1f827d1e27e", + "Title": "gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...", + "Description": "gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + } + }, + "References": [ + "https://github.com/grpc/grpc-go", + "https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176", + "https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77", + "https://github.com/grpc/grpc-go/pull/9331", + "https://github.com/grpc/grpc-go/pull/9333", + "https://github.com/grpc/grpc-go/releases/tag/v1.83.1", + "https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc", + "https://nvd.nist.gov/vuln/detail/CVE-2026-84304" + ], + "PublishedDate": "2026-09-01T19:17:30.743Z", + "LastModifiedDate": "2026-09-09T21:09:13.08Z" + }, + { + "VulnerabilityID": "CVE-2026-84445", + "VendorIDs": [ + "GHSA-2v4p-qf9q-27wj" + ], + "PkgID": "google.golang.org/grpc@v1.71.0", + "PkgName": "google.golang.org/grpc", + "PkgIdentifier": { + "PURL": "pkg:golang/google.golang.org/grpc@v1.71.0", + "UID": "769ee0210348e70d" + }, + "InstalledVersion": "v1.71.0", + "FixedVersion": "1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-84445", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:b725c935f2c4cf8d0a768e59805321cd5f3e7d4ca8ae5121de08771718a5d5b9", + "Title": "gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers", + "Description": "A vulnerability exists in gRPC-Go servers configured with `xds.NewGRPCServer()` where a crafted request missing both `:authority` and `Host` headers can cause a server panic, resulting in a Denial of Service (DoS).\n\nServers built with `xds.NewGRPCServer` install an xDS routing interceptor on every RPC. This interceptor looks up the request’s `:authority` header to pick a virtual host. The HTTP/2 server transport previously accepted requests that had neither `:authority` nor `Host`. When this happened, the xDS routing interceptor attempted to access the first element of an empty slice of authorities, leading to an index out of bounds panic. Since the per-RPC goroutine does not recover from panics, the entire server process would terminate.\n\nThis panic occurs in the interceptor pipeline, meaning the transport credentials handshake (TLS, mTLS, or ALTS) and HTTP/2 connection establishment must complete successfully before the crafted request can reach this logic.\n- Insecure/Standard TLS: If the server permits insecure (plaintext) connections or standard credentials (where client certs are not checked), any unauthenticated remote attacker can trigger the crash.\n- mTLS / ALTS: If strict transport-level authentication is enforced at the network edge or transport layer (e.g., requiring a valid client certificate), the attacker must possess valid transport credentials to initiate the stream and trigger the panic.\n\n### Impact\nAn attacker can cause a complete outage of the gRPC server by sending a request missing both `:authority` and `Host` headers, provided they can successfully establish a transport connection.\n\n### Patches\nThe issue has been addressed in `master` (and backported to `1.83.2` and `1.82.2`). The fix updates the HTTP/2 transport layer to reject requests missing both `:authority` and `Host` headers early, maintaining consistency with and other gRPC language implementations.", + "Severity": "HIGH", + "VendorSeverity": { + "ghsa": 3 + }, + "References": [ + "https://github.com/grpc/grpc-go", + "https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7", + "https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4", + "https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f", + "https://github.com/grpc/grpc-go/issues/9354", + "https://github.com/grpc/grpc-go/pull/9365", + "https://github.com/grpc/grpc-go/pull/9366", + "https://github.com/grpc/grpc-go/pull/9367", + "https://github.com/grpc/grpc-go/releases/tag/v1.82.2", + "https://github.com/grpc/grpc-go/releases/tag/v1.83.2", + "https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj" + ] + }, + { + "VulnerabilityID": "GHSA-hrxh-6v49-42gf", + "PkgID": "google.golang.org/grpc@v1.71.0", + "PkgName": "google.golang.org/grpc", + "PkgIdentifier": { + "PURL": "pkg:golang/google.golang.org/grpc@v1.71.0", + "UID": "769ee0210348e70d" + }, + "InstalledVersion": "v1.71.0", + "FixedVersion": "1.82.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://github.com/advisories/GHSA-hrxh-6v49-42gf", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:c14a8aff5235315c76c27d786dfdbfa0f6b2fe089df52b53c6b9bb1c965dbe15", + "Title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities", + "Description": "Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in:\n\n- Authorization Bypass (Fail-Open) when translating xDS RBAC policies containing `Metadata` or `RequestedServerName` fields.\n- Denial of Service (High CPU Consumption) due to an HTTP/2 Rapid Reset mitigation bypass during client-initiated stream resets.\n- Denial of Service (Server Panic) when parsing crafted xDS RBAC policies containing `NOT` rules around unsupported fields.\n\n\n### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\n#### xDS RBAC Authorization Bypass via `Metadata` \u0026 `RequestedServerName` matchers\n\n- Affected Component: xDS RBAC \n- Impact: When building policy matchers for gRPC RBAC from xDS configurations, unsupported `permission` and `principal` rules (specifically `Metadata` and `RequestedServerName`) were silently ignored and treated as no-ops.\n - If an authorization policy relied purely on these matchers for access control, treating those rules as no-ops effectively removed the restrictions.\n- If these unsupported rules were nested inside logical `NOT` rules (`Permission_NotRule` / `Principal_NotId`) or multi-condition `OR/AND` rules, silently dropping them changed the boolean logic flow of the authorization engine.\n\nAs a result, policy evaluation decisions could fail open, allowing unauthorized clients to access protected gRPC services or resources.\n\n#### HTTP/2 Rapid Reset Mitigation Bypass / Denial of Service via Stream Aborts\n\n- Affected Component: HTTP/2 transport\n- Impact: Earlier mitigations in grpc-go for HTTP/2 Rapid Reset only applied threshold checks to items that directly resulted in control frames being written back to the wire, such as `SETTINGS` ACKs or server-initiated `RST_STREAM`s.\n\nWhen a client initiated a rapid flood of stream creation (`HEADERS`) immediately followed by stream termination `RST_STREAM`, items queued up in the control buffer without counting against the transport response frame threshold. An attacker can repeatedly trigger this flood sequence to bypass reader blocking, resulting in high CPU usage, and Denial of Service (DoS).\n\n#### Denial of Service (Panic) in xDS RBAC Engine via Unsupported Fields inside NOT Rules\n\n- Affected Component: xDS RBAC \n- Impact: The xDS RBAC policy translators recursively generate matchers for nested rules. When a `NOT` rule wrapped an unsupported or unhandled field (such as `SourcedMetadata`), the recursive step returned an empty matcher. This could result in a runtime panic when the RBAC engine attempts to authorize an incoming request.\n\nAn attacker or misconfigured/malicious xDS management server delivering an LDS/RDS update containing a `NOT` rule around an unhandled field causes the gRPC server process to crash immediately (CWE-248 / Denial of Service).\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nAll three issues have been fixed in `master` and will be released in 1.82.1 shortly.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nIf upgrading grpc-go immediately is not possible, apply the following workarounds based on your deployment architecture:\n\n* For xDS RBAC Vulnerabilities \u0026 Panics: Ensure that upstream xDS management servers do not push RBAC policies containing `Metadata`, `RequestedServerName`, or `NOT` rules wrapping unsupported fields (such as `SourcedMetadata`) to grpc-go servers.\n* For HTTP/2 Rapid Reset DOS: Configure upstream reverse proxies or load balancers (such as Envoy) with strict HTTP/2 `max_concurrent_streams` limits and active rate limiting on `RST_STREAM` frequency per connection.\n\n### Severity\n\n | Vulnerability | Qualitative Severity | Approximate CVSS v3.1 Score | Primary Impact |\n | :--- | :--- | :--- | :--- |\n | **xDS RBAC Authorization Bypass** | **High** | `8.2` | Unauthorized Access / Fail-Open |\n | **HTTP/2 Rapid Reset DOS Bypass** | **High** | `7.5` | High CPU Consumption / Denial of Service |\n | **xDS RBAC Engine Server Panic** | **Medium** | `5.9` | Process Crash / Denial of Service |", + "Severity": "HIGH", + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.8 + } + }, + "References": [ + "https://github.com/grpc/grpc-go", + "https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935", + "https://github.com/grpc/grpc-go/pull/9236", + "https://github.com/grpc/grpc-go/releases/tag/v1.82.1", + "https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf" + ], + "PublishedDate": "2026-07-21T22:03:55Z", + "LastModifiedDate": "2026-07-21T22:03:56Z" + }, + { + "VulnerabilityID": "CVE-2025-68121", + "VendorIDs": [ + "GO-2026-4337" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.24.13, 1.25.7, 1.26.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-68121", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:771bb401420d66db0c854978e73a356eefd2b23dbac28a3e81d14a69068b7fb5", + "Title": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption", + "Description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 4, + "cbl-mariner": 2, + "nvd": 4, + "oracle-oval": 3, + "photon": 4, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/security/cve/CVE-2025-68121", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://github.com/golang/go/issues/77113", + "https://go.dev/cl/737700", + "https://go.dev/issue/77217", + "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-68121.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-68121", + "https://pkg.go.dev/vuln/GO-2026-4337", + "https://www.cve.org/CVERecord?id=CVE-2025-68121" + ], + "PublishedDate": "2026-02-05T18:16:10.857Z", + "LastModifiedDate": "2026-06-17T09:58:33.833Z" + }, + { + "VulnerabilityID": "CVE-2025-22874", + "VendorIDs": [ + "GO-2025-3749" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.24.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-22874", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c67520dd1d76f24bdddab6430c67f270b497cc8fe742de5f75d0bf5cf5759aed", + "Title": "crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509", + "Description": "Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.", + "Severity": "HIGH", + "VendorSeverity": { + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2025-22874", + "https://go.dev/cl/670375", + "https://go.dev/issue/73612", + "https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A", + "https://nvd.nist.gov/vuln/detail/CVE-2025-22874", + "https://pkg.go.dev/vuln/GO-2025-3749", + "https://www.cve.org/CVERecord?id=CVE-2025-22874" + ], + "PublishedDate": "2025-06-11T17:15:42.167Z", + "LastModifiedDate": "2026-06-17T08:50:42.733Z" + }, + { + "VulnerabilityID": "CVE-2025-61726", + "VendorIDs": [ + "GO-2026-4341" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.24.12, 1.25.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61726", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ae41ae62f789a72d1820ba8cf66c02768bdca35ece0b8371009e64eeda189177", + "Title": "golang: net/url: Memory exhaustion in query parameter parsing in net/url", + "Description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "cbl-mariner": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10096", + "https://access.redhat.com/errata/RHSA-2026:10104", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:11408", + "https://access.redhat.com/errata/RHSA-2026:11414", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13542", + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:13571", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:15984", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17446", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17595", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:18913", + "https://access.redhat.com/errata/RHSA-2026:19013", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26420", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2706", + "https://access.redhat.com/errata/RHSA-2026:2708", + "https://access.redhat.com/errata/RHSA-2026:2709", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:2844", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:2914", + "https://access.redhat.com/errata/RHSA-2026:2920", + "https://access.redhat.com/errata/RHSA-2026:3035", + "https://access.redhat.com/errata/RHSA-2026:3040", + "https://access.redhat.com/errata/RHSA-2026:3089", + "https://access.redhat.com/errata/RHSA-2026:3092", + "https://access.redhat.com/errata/RHSA-2026:3184", + "https://access.redhat.com/errata/RHSA-2026:3186", + "https://access.redhat.com/errata/RHSA-2026:3187", + "https://access.redhat.com/errata/RHSA-2026:3188", + "https://access.redhat.com/errata/RHSA-2026:3192", + "https://access.redhat.com/errata/RHSA-2026:3193", + "https://access.redhat.com/errata/RHSA-2026:3291", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:3297", + "https://access.redhat.com/errata/RHSA-2026:3298", + "https://access.redhat.com/errata/RHSA-2026:3336", + "https://access.redhat.com/errata/RHSA-2026:3337", + "https://access.redhat.com/errata/RHSA-2026:3340", + "https://access.redhat.com/errata/RHSA-2026:3341", + "https://access.redhat.com/errata/RHSA-2026:3343", + "https://access.redhat.com/errata/RHSA-2026:3391", + "https://access.redhat.com/errata/RHSA-2026:3416", + "https://access.redhat.com/errata/RHSA-2026:3427", + "https://access.redhat.com/errata/RHSA-2026:3459", + "https://access.redhat.com/errata/RHSA-2026:3468", + "https://access.redhat.com/errata/RHSA-2026:3469", + "https://access.redhat.com/errata/RHSA-2026:3470", + "https://access.redhat.com/errata/RHSA-2026:3471", + "https://access.redhat.com/errata/RHSA-2026:3472", + "https://access.redhat.com/errata/RHSA-2026:3473", + "https://access.redhat.com/errata/RHSA-2026:3489", + "https://access.redhat.com/errata/RHSA-2026:3506", + "https://access.redhat.com/errata/RHSA-2026:3556", + "https://access.redhat.com/errata/RHSA-2026:3559", + "https://access.redhat.com/errata/RHSA-2026:3668", + "https://access.redhat.com/errata/RHSA-2026:3669", + "https://access.redhat.com/errata/RHSA-2026:36873", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:3699", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:3752", + "https://access.redhat.com/errata/RHSA-2026:3753", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3812", + "https://access.redhat.com/errata/RHSA-2026:3813", + "https://access.redhat.com/errata/RHSA-2026:3814", + "https://access.redhat.com/errata/RHSA-2026:3815", + "https://access.redhat.com/errata/RHSA-2026:3816", + "https://access.redhat.com/errata/RHSA-2026:3817", + "https://access.redhat.com/errata/RHSA-2026:3818", + "https://access.redhat.com/errata/RHSA-2026:3820", + "https://access.redhat.com/errata/RHSA-2026:3821", + "https://access.redhat.com/errata/RHSA-2026:3822", + "https://access.redhat.com/errata/RHSA-2026:3831", + "https://access.redhat.com/errata/RHSA-2026:3833", + "https://access.redhat.com/errata/RHSA-2026:3835", + "https://access.redhat.com/errata/RHSA-2026:3836", + "https://access.redhat.com/errata/RHSA-2026:3838", + "https://access.redhat.com/errata/RHSA-2026:3839", + "https://access.redhat.com/errata/RHSA-2026:3840", + "https://access.redhat.com/errata/RHSA-2026:3841", + "https://access.redhat.com/errata/RHSA-2026:3843", + "https://access.redhat.com/errata/RHSA-2026:3854", + "https://access.redhat.com/errata/RHSA-2026:3855", + "https://access.redhat.com/errata/RHSA-2026:3856", + "https://access.redhat.com/errata/RHSA-2026:3864", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3875", + "https://access.redhat.com/errata/RHSA-2026:3879", + "https://access.redhat.com/errata/RHSA-2026:3880", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3898", + "https://access.redhat.com/errata/RHSA-2026:3905", + "https://access.redhat.com/errata/RHSA-2026:3906", + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/errata/RHSA-2026:3929", + "https://access.redhat.com/errata/RHSA-2026:3930", + "https://access.redhat.com/errata/RHSA-2026:3931", + "https://access.redhat.com/errata/RHSA-2026:3932", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:3970", + "https://access.redhat.com/errata/RHSA-2026:3971", + "https://access.redhat.com/errata/RHSA-2026:3972", + "https://access.redhat.com/errata/RHSA-2026:3973", + "https://access.redhat.com/errata/RHSA-2026:3974", + "https://access.redhat.com/errata/RHSA-2026:3977", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:3985", + "https://access.redhat.com/errata/RHSA-2026:40924", + "https://access.redhat.com/errata/RHSA-2026:4164", + "https://access.redhat.com/errata/RHSA-2026:4166", + "https://access.redhat.com/errata/RHSA-2026:4170", + "https://access.redhat.com/errata/RHSA-2026:4174", + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:4211", + "https://access.redhat.com/errata/RHSA-2026:4220", + "https://access.redhat.com/errata/RHSA-2026:4256", + "https://access.redhat.com/errata/RHSA-2026:4264", + "https://access.redhat.com/errata/RHSA-2026:4267", + "https://access.redhat.com/errata/RHSA-2026:4270", + "https://access.redhat.com/errata/RHSA-2026:4276", + "https://access.redhat.com/errata/RHSA-2026:4434", + "https://access.redhat.com/errata/RHSA-2026:4435", + "https://access.redhat.com/errata/RHSA-2026:4460", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:4498", + "https://access.redhat.com/errata/RHSA-2026:4500", + "https://access.redhat.com/errata/RHSA-2026:4510", + "https://access.redhat.com/errata/RHSA-2026:4511", + "https://access.redhat.com/errata/RHSA-2026:4672", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:4753", + "https://access.redhat.com/errata/RHSA-2026:4892", + "https://access.redhat.com/errata/RHSA-2026:4901", + "https://access.redhat.com/errata/RHSA-2026:4907", + "https://access.redhat.com/errata/RHSA-2026:4939", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:4943", + "https://access.redhat.com/errata/RHSA-2026:4952", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5022", + "https://access.redhat.com/errata/RHSA-2026:5030", + "https://access.redhat.com/errata/RHSA-2026:5031", + "https://access.redhat.com/errata/RHSA-2026:5076", + "https://access.redhat.com/errata/RHSA-2026:5077", + "https://access.redhat.com/errata/RHSA-2026:5078", + "https://access.redhat.com/errata/RHSA-2026:5079", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:5129", + "https://access.redhat.com/errata/RHSA-2026:5130", + "https://access.redhat.com/errata/RHSA-2026:5131", + "https://access.redhat.com/errata/RHSA-2026:5132", + "https://access.redhat.com/errata/RHSA-2026:5145", + "https://access.redhat.com/errata/RHSA-2026:5146", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5327", + "https://access.redhat.com/errata/RHSA-2026:5394", + "https://access.redhat.com/errata/RHSA-2026:5439", + "https://access.redhat.com/errata/RHSA-2026:5444", + "https://access.redhat.com/errata/RHSA-2026:5447", + "https://access.redhat.com/errata/RHSA-2026:5452", + "https://access.redhat.com/errata/RHSA-2026:5461", + "https://access.redhat.com/errata/RHSA-2026:5463", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5533", + "https://access.redhat.com/errata/RHSA-2026:5544", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5636", + "https://access.redhat.com/errata/RHSA-2026:56366", + "https://access.redhat.com/errata/RHSA-2026:56431", + "https://access.redhat.com/errata/RHSA-2026:5645", + "https://access.redhat.com/errata/RHSA-2026:5649", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:57013", + "https://access.redhat.com/errata/RHSA-2026:5807", + "https://access.redhat.com/errata/RHSA-2026:5851", + "https://access.redhat.com/errata/RHSA-2026:5852", + "https://access.redhat.com/errata/RHSA-2026:5853", + "https://access.redhat.com/errata/RHSA-2026:5948", + "https://access.redhat.com/errata/RHSA-2026:5950", + "https://access.redhat.com/errata/RHSA-2026:5952", + "https://access.redhat.com/errata/RHSA-2026:5968", + "https://access.redhat.com/errata/RHSA-2026:6184", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6226", + "https://access.redhat.com/errata/RHSA-2026:6251", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6428", + "https://access.redhat.com/errata/RHSA-2026:6429", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6554", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/errata/RHSA-2026:66401", + "https://access.redhat.com/errata/RHSA-2026:7052", + "https://access.redhat.com/errata/RHSA-2026:7249", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7676", + "https://access.redhat.com/errata/RHSA-2026:7854", + "https://access.redhat.com/errata/RHSA-2026:7942", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8218", + "https://access.redhat.com/errata/RHSA-2026:8229", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8431", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9848", + "https://access.redhat.com/security/cve/CVE-2025-61726", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://go.dev/cl/736712", + "https://go.dev/issue/77101", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-61726.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61726", + "https://pkg.go.dev/vuln/GO-2026-4341", + "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json", + "https://www.cve.org/CVERecord?id=CVE-2025-61726" + ], + "PublishedDate": "2026-01-28T20:16:09.713Z", + "LastModifiedDate": "2026-09-11T13:16:49.81Z" + }, + { + "VulnerabilityID": "CVE-2025-61729", + "VendorIDs": [ + "GO-2025-4155" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.24.11, 1.25.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61729", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:6631b2b6334290637324f93f84399574d85f53a7c06c8830231e8dc7a88540a8", + "Title": "crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate", + "Description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 1, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/security/cve/CVE-2025-61729", + "https://bugzilla.redhat.com/2418462", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-3928.html", + "https://errata.rockylinux.org/RLSA-2026:3928", + "https://go.dev/cl/725920", + "https://go.dev/issue/76445", + "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4", + "https://linux.oracle.com/cve/CVE-2025-61729.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61729", + "https://pkg.go.dev/vuln/GO-2025-4155", + "https://www.cve.org/CVERecord?id=CVE-2025-61729" + ], + "PublishedDate": "2025-12-02T19:15:51.447Z", + "LastModifiedDate": "2026-06-17T09:50:48.507Z" + }, + { + "VulnerabilityID": "CVE-2026-25679", + "VendorIDs": [ + "GO-2026-4601" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.8, 1.26.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25679", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d7419c432794bb0a20c48217acaf7bb13ffc6b186215eb5105f04b30eed11d19", + "Title": "net/url: Incorrect parsing of IPv6 host literals in net/url", + "Description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-425", + "CWE-1286" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10065", + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10133", + "https://access.redhat.com/errata/RHSA-2026:10140", + "https://access.redhat.com/errata/RHSA-2026:10141", + "https://access.redhat.com/errata/RHSA-2026:10158", + "https://access.redhat.com/errata/RHSA-2026:10169", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:10701", + "https://access.redhat.com/errata/RHSA-2026:10712", + "https://access.redhat.com/errata/RHSA-2026:10929", + "https://access.redhat.com/errata/RHSA-2026:11217", + "https://access.redhat.com/errata/RHSA-2026:11375", + "https://access.redhat.com/errata/RHSA-2026:11412", + "https://access.redhat.com/errata/RHSA-2026:11413", + "https://access.redhat.com/errata/RHSA-2026:11686", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:11768", + "https://access.redhat.com/errata/RHSA-2026:11800", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13508", + "https://access.redhat.com/errata/RHSA-2026:13512", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13642", + "https://access.redhat.com/errata/RHSA-2026:13643", + "https://access.redhat.com/errata/RHSA-2026:13671", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:19017", + "https://access.redhat.com/errata/RHSA-2026:19022", + "https://access.redhat.com/errata/RHSA-2026:19026", + "https://access.redhat.com/errata/RHSA-2026:19027", + "https://access.redhat.com/errata/RHSA-2026:19031", + "https://access.redhat.com/errata/RHSA-2026:19032", + "https://access.redhat.com/errata/RHSA-2026:19049", + "https://access.redhat.com/errata/RHSA-2026:19055", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19128", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19181", + "https://access.redhat.com/errata/RHSA-2026:19184", + "https://access.redhat.com/errata/RHSA-2026:19185", + "https://access.redhat.com/errata/RHSA-2026:19207", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19475", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20088", + "https://access.redhat.com/errata/RHSA-2026:20581", + "https://access.redhat.com/errata/RHSA-2026:20582", + "https://access.redhat.com/errata/RHSA-2026:20584", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:21696", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22733", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24386", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:25043", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26445", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28893", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:52389", + "https://access.redhat.com/errata/RHSA-2026:52390", + "https://access.redhat.com/errata/RHSA-2026:52391", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:56785", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:5941", + "https://access.redhat.com/errata/RHSA-2026:5942", + "https://access.redhat.com/errata/RHSA-2026:5943", + "https://access.redhat.com/errata/RHSA-2026:5944", + "https://access.redhat.com/errata/RHSA-2026:59830", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:6341", + "https://access.redhat.com/errata/RHSA-2026:6344", + "https://access.redhat.com/errata/RHSA-2026:6382", + "https://access.redhat.com/errata/RHSA-2026:6383", + "https://access.redhat.com/errata/RHSA-2026:6388", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:66401", + "https://access.redhat.com/errata/RHSA-2026:6720", + "https://access.redhat.com/errata/RHSA-2026:6802", + "https://access.redhat.com/errata/RHSA-2026:6949", + "https://access.redhat.com/errata/RHSA-2026:7005", + "https://access.redhat.com/errata/RHSA-2026:7009", + "https://access.redhat.com/errata/RHSA-2026:7011", + "https://access.redhat.com/errata/RHSA-2026:7259", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7315", + "https://access.redhat.com/errata/RHSA-2026:7328", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7665", + "https://access.redhat.com/errata/RHSA-2026:7669", + "https://access.redhat.com/errata/RHSA-2026:7674", + "https://access.redhat.com/errata/RHSA-2026:7833", + "https://access.redhat.com/errata/RHSA-2026:7834", + "https://access.redhat.com/errata/RHSA-2026:7876", + "https://access.redhat.com/errata/RHSA-2026:7877", + "https://access.redhat.com/errata/RHSA-2026:7878", + "https://access.redhat.com/errata/RHSA-2026:7879", + "https://access.redhat.com/errata/RHSA-2026:7883", + "https://access.redhat.com/errata/RHSA-2026:7992", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8314", + "https://access.redhat.com/errata/RHSA-2026:8322", + "https://access.redhat.com/errata/RHSA-2026:8324", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8434", + "https://access.redhat.com/errata/RHSA-2026:8456", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:8484", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:8840", + "https://access.redhat.com/errata/RHSA-2026:8841", + "https://access.redhat.com/errata/RHSA-2026:8842", + "https://access.redhat.com/errata/RHSA-2026:8845", + "https://access.redhat.com/errata/RHSA-2026:8847", + "https://access.redhat.com/errata/RHSA-2026:8848", + "https://access.redhat.com/errata/RHSA-2026:8849", + "https://access.redhat.com/errata/RHSA-2026:8851", + "https://access.redhat.com/errata/RHSA-2026:8852", + "https://access.redhat.com/errata/RHSA-2026:8853", + "https://access.redhat.com/errata/RHSA-2026:8855", + "https://access.redhat.com/errata/RHSA-2026:8856", + "https://access.redhat.com/errata/RHSA-2026:8860", + "https://access.redhat.com/errata/RHSA-2026:8877", + "https://access.redhat.com/errata/RHSA-2026:8878", + "https://access.redhat.com/errata/RHSA-2026:8879", + "https://access.redhat.com/errata/RHSA-2026:8881", + "https://access.redhat.com/errata/RHSA-2026:8882", + "https://access.redhat.com/errata/RHSA-2026:8930", + "https://access.redhat.com/errata/RHSA-2026:8931", + "https://access.redhat.com/errata/RHSA-2026:8949", + "https://access.redhat.com/errata/RHSA-2026:9043", + "https://access.redhat.com/errata/RHSA-2026:9044", + "https://access.redhat.com/errata/RHSA-2026:9052", + "https://access.redhat.com/errata/RHSA-2026:9090", + "https://access.redhat.com/errata/RHSA-2026:9093", + "https://access.redhat.com/errata/RHSA-2026:9094", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9434", + "https://access.redhat.com/errata/RHSA-2026:9435", + "https://access.redhat.com/errata/RHSA-2026:9436", + "https://access.redhat.com/errata/RHSA-2026:9439", + "https://access.redhat.com/errata/RHSA-2026:9440", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/errata/RHSA-2026:9461", + "https://access.redhat.com/errata/RHSA-2026:9695", + "https://access.redhat.com/errata/RHSA-2026:9742", + "https://access.redhat.com/errata/RHSA-2026:9872", + "https://access.redhat.com/security/cve/CVE-2026-25679", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://errata.almalinux.org/9/ALSA-2026-9044.html", + "https://errata.rockylinux.org/RLSA-2026:9044", + "https://go.dev/cl/752180", + "https://go.dev/issue/77578", + "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk", + "https://linux.oracle.com/cve/CVE-2026-25679.html", + "https://linux.oracle.com/errata/ELSA-2026-9044.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25679", + "https://pkg.go.dev/vuln/GO-2026-4601", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json", + "https://www.cve.org/CVERecord?id=CVE-2026-25679" + ], + "PublishedDate": "2026-03-06T22:16:00.72Z", + "LastModifiedDate": "2026-09-11T13:17:13.637Z" + }, + { + "VulnerabilityID": "CVE-2026-27145", + "VendorIDs": [ + "GO-2026-5037" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27145", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:542d9d90ea5626ddc8adec6f74e825e8312f1be950cf55ca83d8ffb8192e10e4", + "Title": "crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries", + "Description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:29980", + "https://access.redhat.com/errata/RHSA-2026:29981", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46394", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49705", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:49729", + "https://access.redhat.com/errata/RHSA-2026:49744", + "https://access.redhat.com/errata/RHSA-2026:49765", + "https://access.redhat.com/errata/RHSA-2026:49770", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:52946", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53416", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54427", + "https://access.redhat.com/errata/RHSA-2026:54432", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54525", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54603", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:55899", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57488", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:59556", + "https://access.redhat.com/errata/RHSA-2026:59557", + "https://access.redhat.com/errata/RHSA-2026:59558", + "https://access.redhat.com/errata/RHSA-2026:59559", + "https://access.redhat.com/errata/RHSA-2026:59579", + "https://access.redhat.com/errata/RHSA-2026:59593", + "https://access.redhat.com/errata/RHSA-2026:60025", + "https://access.redhat.com/errata/RHSA-2026:60315", + "https://access.redhat.com/errata/RHSA-2026:60354", + "https://access.redhat.com/errata/RHSA-2026:60386", + "https://access.redhat.com/errata/RHSA-2026:60387", + "https://access.redhat.com/errata/RHSA-2026:60388", + "https://access.redhat.com/errata/RHSA-2026:60390", + "https://access.redhat.com/errata/RHSA-2026:60391", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:63016", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/security/cve/CVE-2026-27145", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://errata.almalinux.org/9/ALSA-2026-36317.html", + "https://errata.rockylinux.org/RLSA-2026:36317", + "https://go.dev/cl/783621", + "https://go.dev/issue/79694", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-27145.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27145", + "https://pkg.go.dev/vuln/GO-2026-5037", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json", + "https://www.cve.org/CVERecord?id=CVE-2026-27145" + ], + "PublishedDate": "2026-06-02T23:16:35.57Z", + "LastModifiedDate": "2026-09-11T13:17:23.34Z" + }, + { + "VulnerabilityID": "CVE-2026-32280", + "VendorIDs": [ + "GO-2026-4947" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32280", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1c621c2220061b76702f5d6154967d20045c6d57ba4b8495624e55506f1efeba", + "Title": "crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building", + "Description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13826", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16476", + "https://access.redhat.com/errata/RHSA-2026:16477", + "https://access.redhat.com/errata/RHSA-2026:16505", + "https://access.redhat.com/errata/RHSA-2026:16508", + "https://access.redhat.com/errata/RHSA-2026:16532", + "https://access.redhat.com/errata/RHSA-2026:16534", + "https://access.redhat.com/errata/RHSA-2026:16535", + "https://access.redhat.com/errata/RHSA-2026:16537", + "https://access.redhat.com/errata/RHSA-2026:16542", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21338", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21772", + "https://access.redhat.com/errata/RHSA-2026:22130", + "https://access.redhat.com/errata/RHSA-2026:22141", + "https://access.redhat.com/errata/RHSA-2026:22258", + "https://access.redhat.com/errata/RHSA-2026:22260", + "https://access.redhat.com/errata/RHSA-2026:22268", + "https://access.redhat.com/errata/RHSA-2026:22309", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22415", + "https://access.redhat.com/errata/RHSA-2026:22422", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22958", + "https://access.redhat.com/errata/RHSA-2026:22959", + "https://access.redhat.com/errata/RHSA-2026:22960", + "https://access.redhat.com/errata/RHSA-2026:22961", + "https://access.redhat.com/errata/RHSA-2026:22962", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23244", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24359", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24478", + "https://access.redhat.com/errata/RHSA-2026:24716", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:28196", + "https://access.redhat.com/errata/RHSA-2026:28198", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:39894", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49526", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54603", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56785", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56855", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:56913", + "https://access.redhat.com/errata/RHSA-2026:57409", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57488", + "https://access.redhat.com/errata/RHSA-2026:59830", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:59834", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61685", + "https://access.redhat.com/errata/RHSA-2026:61906", + "https://access.redhat.com/errata/RHSA-2026:61907", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:66401", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/security/cve/CVE-2026-32280", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/758320", + "https://go.dev/issue/78282", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32280.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32280", + "https://pkg.go.dev/vuln/GO-2026-4947", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32280" + ], + "PublishedDate": "2026-04-08T02:16:03.247Z", + "LastModifiedDate": "2026-09-11T13:17:25.78Z" + }, + { + "VulnerabilityID": "CVE-2026-32281", + "VendorIDs": [ + "GO-2026-4946" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32281", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1022af34aa410d554ef48f6ff1dce65c64289f13032aec6fe5b0f621f92673cf", + "Title": "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation", + "Description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-32281", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/758061", + "https://go.dev/issue/78281", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32281.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32281", + "https://pkg.go.dev/vuln/GO-2026-4946", + "https://www.cve.org/CVERecord?id=CVE-2026-32281" + ], + "PublishedDate": "2026-04-08T02:16:03.35Z", + "LastModifiedDate": "2026-07-25T10:10:00.167Z" + }, + { + "VulnerabilityID": "CVE-2026-32283", + "VendorIDs": [ + "GO-2026-4870" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f15156339941d9babb13360fed88d8529676a5c0797cf8559d2ff009194db7c4", + "Title": "crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages", + "Description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-764" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11704", + "https://access.redhat.com/errata/RHSA-2026:11711", + "https://access.redhat.com/errata/RHSA-2026:11712", + "https://access.redhat.com/errata/RHSA-2026:11863", + "https://access.redhat.com/errata/RHSA-2026:11881", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17075", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19134", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19136", + "https://access.redhat.com/errata/RHSA-2026:19137", + "https://access.redhat.com/errata/RHSA-2026:19139", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19156", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19351", + "https://access.redhat.com/errata/RHSA-2026:19352", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19369", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:55898", + "https://access.redhat.com/errata/RHSA-2026:55900", + "https://access.redhat.com/errata/RHSA-2026:55901", + "https://access.redhat.com/errata/RHSA-2026:55902", + "https://access.redhat.com/errata/RHSA-2026:55903", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:57409", + "https://access.redhat.com/errata/RHSA-2026:57801", + "https://access.redhat.com/errata/RHSA-2026:57802", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65343", + "https://access.redhat.com/errata/RHSA-2026:65514", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66084", + "https://access.redhat.com/errata/RHSA-2026:66401", + "https://access.redhat.com/errata/RHSA-2026:66523", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/security/cve/CVE-2026-32283", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://errata.almalinux.org/9/ALSA-2026-29703.html", + "https://errata.rockylinux.org/RLSA-2026:29703", + "https://go.dev/cl/763767", + "https://go.dev/issue/78334", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32283.html", + "https://linux.oracle.com/errata/ELSA-2026-48790.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32283", + "https://pkg.go.dev/vuln/GO-2026-4870", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32283" + ], + "PublishedDate": "2026-04-08T02:16:03.58Z", + "LastModifiedDate": "2026-09-11T13:17:28.143Z" + }, + { + "VulnerabilityID": "CVE-2026-33811", + "VendorIDs": [ + "GO-2026-4981" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33811", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:49a1f42aea20225f1db3230a056459404513c5b4df99ac10a43d2911054d544d", + "Title": "net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME", + "Description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415", + "CWE-1341" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:35995", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36617", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36776", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38504", + "https://access.redhat.com/errata/RHSA-2026:39266", + "https://access.redhat.com/errata/RHSA-2026:39272", + "https://access.redhat.com/errata/RHSA-2026:39319", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40119", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:50336", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54552", + "https://access.redhat.com/errata/RHSA-2026:54556", + "https://access.redhat.com/errata/RHSA-2026:54584", + "https://access.redhat.com/errata/RHSA-2026:54602", + "https://access.redhat.com/errata/RHSA-2026:54603", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56785", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56790", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56855", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:56913", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57488", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59559", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:60025", + "https://access.redhat.com/errata/RHSA-2026:60302", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:61313", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/security/cve/CVE-2026-33811", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-39319.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/767860", + "https://go.dev/issue/78803", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33811.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33811", + "https://pkg.go.dev/vuln/GO-2026-4981", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33811" + ], + "PublishedDate": "2026-05-07T20:16:42.77Z", + "LastModifiedDate": "2026-09-11T13:17:36.897Z" + }, + { + "VulnerabilityID": "CVE-2026-33814", + "VendorIDs": [ + "GO-2026-4918" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:2856b8cd142c55c08614e52afa6fcda927076a2880d0fb70d93616bf79dd775c", + "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", + "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57365", + "https://access.redhat.com/errata/RHSA-2026:57367", + "https://access.redhat.com/errata/RHSA-2026:57408", + "https://access.redhat.com/errata/RHSA-2026:57545", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60023", + "https://access.redhat.com/errata/RHSA-2026:60025", + "https://access.redhat.com/errata/RHSA-2026:60441", + "https://access.redhat.com/errata/RHSA-2026:60442", + "https://access.redhat.com/errata/RHSA-2026:60446", + "https://access.redhat.com/errata/RHSA-2026:60447", + "https://access.redhat.com/errata/RHSA-2026:60454", + "https://access.redhat.com/errata/RHSA-2026:60477", + "https://access.redhat.com/errata/RHSA-2026:60478", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:60668", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62550", + "https://access.redhat.com/errata/RHSA-2026:62551", + "https://access.redhat.com/errata/RHSA-2026:63046", + "https://access.redhat.com/errata/RHSA-2026:63047", + "https://access.redhat.com/errata/RHSA-2026:63048", + "https://access.redhat.com/errata/RHSA-2026:63050", + "https://access.redhat.com/errata/RHSA-2026:63091", + "https://access.redhat.com/errata/RHSA-2026:63096", + "https://access.redhat.com/errata/RHSA-2026:63097", + "https://access.redhat.com/errata/RHSA-2026:63103", + "https://access.redhat.com/errata/RHSA-2026:63104", + "https://access.redhat.com/errata/RHSA-2026:63636", + "https://access.redhat.com/errata/RHSA-2026:63637", + "https://access.redhat.com/errata/RHSA-2026:63639", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/security/cve/CVE-2026-33814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467810", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467811", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467813", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467823", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467825", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467826", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467827", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501", + "https://errata.rockylinux.org/RLSA-2026:22121", + "https://github.com/golang/go/issues/78476", + "https://go-review.googlesource.com/c/go/+/761581", + "https://go-review.googlesource.com/c/net/+/761640", + "https://go.dev/cl/761581", + "https://go.dev/cl/761640", + "https://go.dev/issue/78476", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33814.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", + "https://pkg.go.dev/vuln/GO-2026-4918", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", + "https://ubuntu.com/security/notices/USN-8430-1", + "https://ubuntu.com/security/notices/USN-8471-1", + "https://ubuntu.com/security/notices/USN-8472-1", + "https://ubuntu.com/security/notices/USN-8473-1", + "https://www.cve.org/CVERecord?id=CVE-2026-33814" + ], + "PublishedDate": "2026-05-07T20:16:42.88Z", + "LastModifiedDate": "2026-09-10T13:18:21.31Z" + }, + { + "VulnerabilityID": "CVE-2026-33818", + "VendorIDs": [ + "GO-2026-5972" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33818", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4158133af994b72da4e9d6d4e153372fadefdb93b435c9b0babffdc78d28576b", + "Title": "encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal", + "Description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:66364", + "https://access.redhat.com/security/cve/CVE-2026-33818", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-66364.html", + "https://errata.rockylinux.org/RLSA-2026:66364", + "https://go.dev/cl/814980", + "https://go.dev/issue/80405", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-33818.html", + "https://linux.oracle.com/errata/ELSA-2026-66364-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33818", + "https://pkg.go.dev/vuln/GO-2026-5972", + "https://www.cve.org/CVERecord?id=CVE-2026-33818" + ], + "PublishedDate": "2026-08-13T22:17:19.84Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-39820", + "VendorIDs": [ + "GO-2026-4986" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39820", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:9b83fd6f1b0721cb443e9c2b3f1d4b3274d1aa9b505f90a69d9d69a3da47c9b4", + "Title": "net/mail: golang: Go net/mail: Denial of Service via crafted email inputs", + "Description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54552", + "https://access.redhat.com/errata/RHSA-2026:54555", + "https://access.redhat.com/errata/RHSA-2026:54583", + "https://access.redhat.com/errata/RHSA-2026:54602", + "https://access.redhat.com/errata/RHSA-2026:54883", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57401", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57487", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:57914", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59830", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:60023", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62260", + "https://access.redhat.com/errata/RHSA-2026:62406", + "https://access.redhat.com/errata/RHSA-2026:62407", + "https://access.redhat.com/errata/RHSA-2026:62753", + "https://access.redhat.com/errata/RHSA-2026:62754", + "https://access.redhat.com/errata/RHSA-2026:62803", + "https://access.redhat.com/errata/RHSA-2026:63022", + "https://access.redhat.com/errata/RHSA-2026:65116", + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65153", + "https://access.redhat.com/errata/RHSA-2026:65335", + "https://access.redhat.com/errata/RHSA-2026:65336", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:65895", + "https://access.redhat.com/errata/RHSA-2026:66016", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66327", + "https://access.redhat.com/security/cve/CVE-2026-39820", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/759940", + "https://go.dev/issue/78566", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39820.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39820", + "https://pkg.go.dev/vuln/GO-2026-4986", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39820" + ], + "PublishedDate": "2026-05-07T20:16:43.187Z", + "LastModifiedDate": "2026-09-11T13:17:48.093Z" + }, + { + "VulnerabilityID": "CVE-2026-39821", + "VendorIDs": [ + "GO-2026-5026" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a7be2ebd719f0e6c3360c0096bc90159433f618e4c680f30a519f694a670db6e", + "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", + "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1289" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:30853", + "https://access.redhat.com/errata/RHSA-2026:30854", + "https://access.redhat.com/errata/RHSA-2026:30855", + "https://access.redhat.com/errata/RHSA-2026:33155", + "https://access.redhat.com/errata/RHSA-2026:33160", + "https://access.redhat.com/errata/RHSA-2026:33163", + "https://access.redhat.com/errata/RHSA-2026:33173", + "https://access.redhat.com/errata/RHSA-2026:33183", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34789", + "https://access.redhat.com/errata/RHSA-2026:35826", + "https://access.redhat.com/errata/RHSA-2026:35827", + "https://access.redhat.com/errata/RHSA-2026:35828", + "https://access.redhat.com/errata/RHSA-2026:35829", + "https://access.redhat.com/errata/RHSA-2026:35830", + "https://access.redhat.com/errata/RHSA-2026:35831", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37435", + "https://access.redhat.com/errata/RHSA-2026:37436", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:44624", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:52826", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54395", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54580", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56143", + "https://access.redhat.com/errata/RHSA-2026:56223", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56431", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57541", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:59546", + "https://access.redhat.com/errata/RHSA-2026:59549", + "https://access.redhat.com/errata/RHSA-2026:59562", + "https://access.redhat.com/errata/RHSA-2026:60315", + "https://access.redhat.com/errata/RHSA-2026:60354", + "https://access.redhat.com/errata/RHSA-2026:60387", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61245", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62549", + "https://access.redhat.com/errata/RHSA-2026:63134", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65153", + "https://access.redhat.com/errata/RHSA-2026:65359", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:66016", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66432", + "https://access.redhat.com/security/cve/CVE-2026-39821", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-37435.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://github.com/golang/go/issues/78760", + "https://go.dev/cl/767220", + "https://go.dev/issue/78760", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-39821.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", + "https://pkg.go.dev/vuln/GO-2026-5026", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", + "https://ubuntu.com/security/notices/USN-8416-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39821" + ], + "PublishedDate": "2026-05-22T16:16:20.41Z", + "LastModifiedDate": "2026-09-11T13:17:49.237Z" + }, + { + "VulnerabilityID": "CVE-2026-39822", + "VendorIDs": [ + "GO-2026-4970" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.12, 1.26.5, 1.27.0-rc.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39822", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:687ef34c52cb686c08b064f3567fd99c007fab41e426cdc69a1aefbf9868c72a", + "Title": "golang: Go os.Root: Symlink following vulnerability allows directory traversal", + "Description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-61" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:38878", + "https://access.redhat.com/security/cve/CVE-2026-39822", + "https://bugzilla.redhat.com/2498152", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-38878.html", + "https://errata.rockylinux.org/RLSA-2026:38878", + "https://go.dev/cl/797880", + "https://go.dev/issue/79005", + "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc", + "https://linux.oracle.com/cve/CVE-2026-39822.html", + "https://linux.oracle.com/errata/ELSA-2026-38995.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39822", + "https://pkg.go.dev/vuln/GO-2026-4970", + "https://www.cve.org/CVERecord?id=CVE-2026-39822" + ], + "PublishedDate": "2026-07-08T17:17:21.31Z", + "LastModifiedDate": "2026-07-13T14:54:26.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39836", + "VendorIDs": [ + "GO-2026-4971" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39836", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:83aeed64e8cbac033d4e8725df6c573f1ec70796427e0d204e78f09351d6ef64", + "Title": "net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows", + "Description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/security/cve/CVE-2026-39836", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467810", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467811", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467813", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467823", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467825", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467826", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467827", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501", + "https://errata.rockylinux.org/RLSA-2026:22121", + "https://go.dev/cl/775320", + "https://go.dev/issue/79006", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39836.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39836", + "https://pkg.go.dev/vuln/GO-2026-4971", + "https://www.cve.org/CVERecord?id=CVE-2026-39836" + ], + "PublishedDate": "2026-05-07T20:16:43.593Z", + "LastModifiedDate": "2026-06-17T10:42:40.34Z" + }, + { + "VulnerabilityID": "CVE-2026-42499", + "VendorIDs": [ + "GO-2026-4977" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42499", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b12e5eda1d1f7c9be8b9f608171cdcfce548173b11ef0785e2781757c541c6eb", + "Title": "net/mail: golang: net/mail: Denial of Service via pathological email address parsing", + "Description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1046" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:17713", + "https://access.redhat.com/errata/RHSA-2026:17714", + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54552", + "https://access.redhat.com/errata/RHSA-2026:54555", + "https://access.redhat.com/errata/RHSA-2026:54583", + "https://access.redhat.com/errata/RHSA-2026:54602", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56785", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57487", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:57914", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59830", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:60023", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62260", + "https://access.redhat.com/errata/RHSA-2026:62406", + "https://access.redhat.com/errata/RHSA-2026:62407", + "https://access.redhat.com/errata/RHSA-2026:62753", + "https://access.redhat.com/errata/RHSA-2026:62754", + "https://access.redhat.com/errata/RHSA-2026:62803", + "https://access.redhat.com/errata/RHSA-2026:63022", + "https://access.redhat.com/errata/RHSA-2026:63163", + "https://access.redhat.com/errata/RHSA-2026:63332", + "https://access.redhat.com/errata/RHSA-2026:63636", + "https://access.redhat.com/errata/RHSA-2026:64818", + "https://access.redhat.com/errata/RHSA-2026:65116", + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65153", + "https://access.redhat.com/errata/RHSA-2026:65335", + "https://access.redhat.com/errata/RHSA-2026:65336", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:65895", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66327", + "https://access.redhat.com/security/cve/CVE-2026-42499", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/771520", + "https://go.dev/issue/78987", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-42499.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42499", + "https://pkg.go.dev/vuln/GO-2026-4977", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42499" + ], + "PublishedDate": "2026-05-07T20:16:44.54Z", + "LastModifiedDate": "2026-09-11T13:17:59.763Z" + }, + { + "VulnerabilityID": "CVE-2026-42504", + "VendorIDs": [ + "GO-2026-5038" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42504", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:12f21b5937cfb451ccc2a3f624dc10f888fcfc3ca477f5974c96b632d51d7c7d", + "Title": "mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header", + "Description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-42504", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/774481", + "https://go.dev/issue/79217", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-42504.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42504", + "https://pkg.go.dev/vuln/GO-2026-5038", + "https://www.cve.org/CVERecord?id=CVE-2026-42504" + ], + "PublishedDate": "2026-06-02T23:16:37.927Z", + "LastModifiedDate": "2026-07-22T19:10:00.12Z" + }, + { + "VulnerabilityID": "CVE-2026-56853", + "VendorIDs": [ + "GO-2026-6089" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56853", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:7bd0932d8ba6c6eaecf6eb9e4ba6748bb3152be7468919b0bc1235569f6e6251", + "Title": "net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service", + "Description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-56853", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/795540", + "https://go.dev/issue/80205", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56853.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56853", + "https://pkg.go.dev/vuln/GO-2026-6089", + "https://www.cve.org/CVERecord?id=CVE-2026-56853" + ], + "PublishedDate": "2026-08-13T22:17:22.093Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-56858", + "VendorIDs": [ + "GO-2026-6091" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56858", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:7d793f099536380a1d9e5f0f56cae3c950c23837feb1e129756d52f4ef86a265", + "Title": "html/template: golang: Go html/template: Cross-Site Scripting via pathological input", + "Description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 2, + "oracle-oval": 3, + "photon": 2, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", + "V3Score": 6.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-56858", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/807100", + "https://go.dev/issue/80435", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56858.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56858", + "https://pkg.go.dev/vuln/GO-2026-6091", + "https://www.cve.org/CVERecord?id=CVE-2026-56858" + ], + "PublishedDate": "2026-08-13T22:17:22.207Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-56859", + "VendorIDs": [ + "GO-2026-6088" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56859", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:9da4c6d208208d19f0f584480389408abe21be622f6bed4ade6f536f365e8b4f", + "Title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue", + "Description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-56859", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/803320", + "https://go.dev/issue/80481", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56859.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56859", + "https://pkg.go.dev/vuln/GO-2026-6088", + "https://www.cve.org/CVERecord?id=CVE-2026-56859" + ], + "PublishedDate": "2026-08-13T22:17:22.32Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-56860", + "VendorIDs": [ + "GO-2026-6218" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56860", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b4af08208f59b05ea640e49566c525479161195a15927f90798e4507c48ba0dc", + "Title": "net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution", + "Description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 2, + "oracle-oval": 3, + "photon": 2, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:66364", + "https://access.redhat.com/security/cve/CVE-2026-56860", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-66364.html", + "https://errata.rockylinux.org/RLSA-2026:66364", + "https://go.dev/cl/803681", + "https://go.dev/issue/80494", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56860.html", + "https://linux.oracle.com/errata/ELSA-2026-66364-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56860", + "https://pkg.go.dev/vuln/GO-2026-6218", + "https://www.cve.org/CVERecord?id=CVE-2026-56860" + ], + "PublishedDate": "2026-08-13T22:17:22.44Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-56862", + "VendorIDs": [ + "GO-2026-6090" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "de1f339478735e6f" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:df0d0d229f33f0af067b4345d8d577a83038467dfe6bd4832630cc292e8f66f9", + "DiffID": "sha256:8390681ea3dd7776f1beec1a91d30160f9279ce464977c88769d3dcd1fe7497e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56862", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b6850843969eadfa0f3ed4c688dafcc4306f2b476deff85f45a4cc517245368a", + "Title": "crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages", + "Description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:66364", + "https://access.redhat.com/security/cve/CVE-2026-56862", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-66364.html", + "https://errata.rockylinux.org/RLSA-2026:66364", + "https://go.dev/cl/804261", + "https://go.dev/issue/80528", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56862.html", + "https://linux.oracle.com/errata/ELSA-2026-66364-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56862", + "https://pkg.go.dev/vuln/GO-2026-6090", + "https://www.cve.org/CVERecord?id=CVE-2026-56862" + ], + "PublishedDate": "2026-08-13T22:17:22.55Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + } + ] + }, + { + "Target": "usr/bin/minio", + "Class": "lang-pkgs", + "Type": "gobinary", + "Packages": [ + { + "ID": "github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969+dirty", + "Name": "github.com/minio/minio", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969%2Bdirty", + "UID": "d2024c05322957d0" + }, + "Version": "v0.0.0-20250422221226-0d7408fc9969+dirty", + "Relationship": "root", + "DependsOn": [ + "aead.dev/mem@v0.2.0", + "aead.dev/minisign@v0.3.0", + "cel.dev/expr@v0.22.0", + "cloud.google.com/go/auth/oauth2adapt@v0.2.7", + "cloud.google.com/go/auth@v0.15.0", + "cloud.google.com/go/compute/metadata@v0.6.0", + "cloud.google.com/go/iam@v1.3.1", + "cloud.google.com/go/monitoring@v1.23.0", + "cloud.google.com/go/storage@v1.46.0", + "cloud.google.com/go@v0.118.0", + "filippo.io/edwards25519@v1.1.0", + "github.com/Azure/azure-sdk-for-go/sdk/azcore@v1.17.0", + "github.com/Azure/azure-sdk-for-go/sdk/azidentity@v1.8.2", + "github.com/Azure/azure-sdk-for-go/sdk/internal@v1.10.0", + "github.com/Azure/azure-sdk-for-go/sdk/storage/azblob@v1.6.0", + "github.com/Azure/go-ntlmssp@v0.0.0-20221128193559-754e69321358", + "github.com/AzureAD/microsoft-authentication-library-for-go@v1.4.1", + "github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp@v1.27.0", + "github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric@v0.51.0", + "github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping@v0.51.0", + "github.com/IBM/sarama@v1.45.1", + "github.com/VividCortex/ewma@v1.2.0", + "github.com/acarl005/stripansi@v0.0.0-20180116102854-5a71ef0e047d", + "github.com/alecthomas/participle@v0.7.1", + "github.com/apache/thrift@v0.21.0", + "github.com/asaskevich/govalidator@v0.0.0-20230301143203-a9d515a09cc2", + "github.com/aymanbagabas/go-osc52/v2@v2.0.1", + "github.com/beevik/ntp@v1.4.3", + "github.com/beorn7/perks@v1.0.1", + "github.com/buger/jsonparser@v1.1.1", + "github.com/cespare/xxhash/v2@v2.3.0", + "github.com/charmbracelet/bubbles@v0.20.0", + "github.com/charmbracelet/bubbletea@v1.3.4", + "github.com/charmbracelet/lipgloss@v1.0.0", + "github.com/charmbracelet/x/ansi@v0.8.0", + "github.com/charmbracelet/x/term@v0.2.1", + "github.com/cheggaaa/pb@v1.0.29", + "github.com/cncf/xds/go@v0.0.0-20250121191232-2f005788dc42", + "github.com/coreos/go-oidc/v3@v3.12.0", + "github.com/coreos/go-semver@v0.3.1", + "github.com/coreos/go-systemd/v22@v22.5.0", + "github.com/cosnicolaou/pbzip2@v1.0.5", + "github.com/davecgh/go-spew@v1.1.2-0.20180830191138-d8f796af33cc", + "github.com/dchest/siphash@v1.2.3", + "github.com/docker/go-units@v0.5.0", + "github.com/dustin/go-humanize@v1.0.1", + "github.com/eapache/go-resiliency@v1.7.0", + "github.com/eapache/go-xerial-snappy@v0.0.0-20230731223053-c322873962e3", + "github.com/eapache/queue@v1.1.0", + "github.com/eclipse/paho.mqtt.golang@v1.5.0", + "github.com/elastic/go-elasticsearch/v7@v7.17.10", + "github.com/envoyproxy/go-control-plane/envoy@v1.32.4", + "github.com/envoyproxy/protoc-gen-validate@v1.2.1", + "github.com/fatih/color@v1.18.0", + "github.com/fatih/structs@v1.1.0", + "github.com/felixge/fgprof@v0.9.5", + "github.com/felixge/httpsnoop@v1.0.4", + "github.com/fraugster/parquet-go@v0.12.0", + "github.com/go-asn1-ber/asn1-ber@v1.5.7", + "github.com/go-ini/ini@v1.67.0", + "github.com/go-jose/go-jose/v4@v4.0.5", + "github.com/go-ldap/ldap/v3@v3.4.10", + "github.com/go-logr/logr@v1.4.2", + "github.com/go-logr/stdr@v1.2.2", + "github.com/go-openapi/analysis@v0.23.0", + "github.com/go-openapi/errors@v0.22.0", + "github.com/go-openapi/jsonpointer@v0.21.1", + "github.com/go-openapi/jsonreference@v0.21.0", + "github.com/go-openapi/loads@v0.22.0", + "github.com/go-openapi/runtime@v0.28.0", + "github.com/go-openapi/spec@v0.21.0", + "github.com/go-openapi/strfmt@v0.23.0", + "github.com/go-openapi/swag@v0.23.1", + "github.com/go-openapi/validate@v0.24.0", + "github.com/go-sql-driver/mysql@v1.9.0", + "github.com/gobwas/httphead@v0.1.0", + "github.com/gobwas/pool@v0.2.1", + "github.com/gobwas/ws@v1.4.0", + "github.com/goccy/go-json@v0.10.5", + "github.com/gogo/protobuf@v1.3.2", + "github.com/golang-jwt/jwt/v4@v4.5.2", + "github.com/golang-jwt/jwt/v5@v5.2.2", + "github.com/golang/protobuf@v1.5.4", + "github.com/golang/snappy@v1.0.0", + "github.com/gomodule/redigo@v1.9.2", + "github.com/google/pprof@v0.0.0-20250302191652-9094ed2288e7", + "github.com/google/s2a-go@v0.1.9", + "github.com/google/shlex@v0.0.0-20191202100458-e7afc7fbc510", + "github.com/google/uuid@v1.6.0", + "github.com/googleapis/enterprise-certificate-proxy@v0.3.5", + "github.com/googleapis/gax-go/v2@v2.14.1", + "github.com/gorilla/websocket@v1.5.3", + "github.com/hashicorp/errwrap@v1.1.0", + "github.com/hashicorp/go-multierror@v1.1.1", + "github.com/hashicorp/go-uuid@v1.0.3", + "github.com/inconshreveable/mousetrap@v1.1.0", + "github.com/jcmturner/aescts/v2@v2.0.0", + "github.com/jcmturner/dnsutils/v2@v2.0.0", + "github.com/jcmturner/gofork@v1.7.6", + "github.com/jcmturner/gokrb5/v8@v8.4.4", + "github.com/jcmturner/rpc/v2@v2.0.3", + "github.com/jedib0t/go-pretty/v6@v6.6.7", + "github.com/jessevdk/go-flags@v1.6.1", + "github.com/josharian/intern@v1.0.0", + "github.com/json-iterator/go@v1.1.12", + "github.com/juju/ratelimit@v1.0.2", + "github.com/klauspost/compress@v1.18.0", + "github.com/klauspost/cpuid/v2@v2.2.10", + "github.com/klauspost/filepathx@v1.1.1", + "github.com/klauspost/pgzip@v1.2.6", + "github.com/klauspost/readahead@v1.4.0", + "github.com/klauspost/reedsolomon@v1.12.4", + "github.com/kr/fs@v0.1.0", + "github.com/kylelemons/godebug@v1.1.0", + "github.com/lestrrat-go/blackmagic@v1.0.2", + "github.com/lestrrat-go/httpcc@v1.0.1", + "github.com/lestrrat-go/httprc@v1.0.6", + "github.com/lestrrat-go/iter@v1.0.2", + "github.com/lestrrat-go/jwx/v2@v2.1.4", + "github.com/lestrrat-go/option@v1.0.1", + "github.com/lib/pq@v1.10.9", + "github.com/lithammer/shortuuid/v4@v4.2.0", + "github.com/lucasb-eyer/go-colorful@v1.2.0", + "github.com/mailru/easyjson@v0.9.0", + "github.com/mattn/go-colorable@v0.1.14", + "github.com/mattn/go-ieproxy@v0.0.12", + "github.com/mattn/go-isatty@v0.0.20", + "github.com/mattn/go-runewidth@v0.0.16", + "github.com/matttproud/golang_protobuf_extensions@v1.0.4", + "github.com/miekg/dns@v1.1.63", + "github.com/minio/cli@v1.24.2", + "github.com/minio/colorjson@v1.0.8", + "github.com/minio/console@v1.7.6", + "github.com/minio/crc64nvme@v1.0.1", + "github.com/minio/csvparser@v1.0.0", + "github.com/minio/dnscache@v0.1.1", + "github.com/minio/dperf@v0.6.3", + "github.com/minio/filepath@v1.0.0", + "github.com/minio/highwayhash@v1.0.3", + "github.com/minio/kms-go/kes@v0.3.1", + "github.com/minio/kms-go/kms@v0.4.0", + "github.com/minio/madmin-go/v3@v3.0.109", + "github.com/minio/mc@v0.0.0-20250312172924-c1d5d4cbb4ca", + "github.com/minio/md5-simd@v1.1.2", + "github.com/minio/minio-go/v7@v7.0.90", + "github.com/minio/mux@v1.9.2", + "github.com/minio/pkg/v3@v3.1.0", + "github.com/minio/selfupdate@v0.6.0", + "github.com/minio/simdjson-go@v0.4.5", + "github.com/minio/sio@v0.4.1", + "github.com/minio/websocket@v1.6.0", + "github.com/minio/xxml@v0.0.3", + "github.com/minio/zipindex@v0.4.0", + "github.com/mitchellh/go-homedir@v1.1.0", + "github.com/mitchellh/mapstructure@v1.5.0", + "github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd", + "github.com/modern-go/reflect2@v1.0.2", + "github.com/muesli/ansi@v0.0.0-20230316100256-276c6243b2f6", + "github.com/muesli/cancelreader@v0.2.2", + "github.com/muesli/reflow@v0.3.0", + "github.com/muesli/termenv@v0.16.0", + "github.com/munnerz/goautoneg@v0.0.0-20191010083416-a7dc8b61c822", + "github.com/nats-io/nats.go@v1.39.1", + "github.com/nats-io/nkeys@v0.4.10", + "github.com/nats-io/nuid@v1.0.1", + "github.com/nats-io/stan.go@v0.10.4", + "github.com/ncw/directio@v1.0.5", + "github.com/nsqio/go-nsq@v1.1.0", + "github.com/oklog/ulid@v1.3.1", + "github.com/olekukonko/tablewriter@v0.0.5", + "github.com/philhofer/fwd@v1.1.3-0.20240916144458-20a13a1f6b7c", + "github.com/pierrec/lz4/v4@v4.1.22", + "github.com/pkg/browser@v0.0.0-20240102092130-5ac0b6a4141c", + "github.com/pkg/errors@v0.9.1", + "github.com/pkg/sftp@v1.13.8", + "github.com/pkg/xattr@v0.4.10", + "github.com/posener/complete@v1.2.3", + "github.com/prometheus/client_golang@v1.21.1", + "github.com/prometheus/client_model@v0.6.2", + "github.com/prometheus/common@v0.63.0", + "github.com/prometheus/procfs@v0.16.0", + "github.com/prometheus/prom2json@v1.4.2", + "github.com/prometheus/prometheus@v0.303.0", + "github.com/puzpuzpuz/xsync/v3@v3.5.1", + "github.com/rabbitmq/amqp091-go@v1.10.0", + "github.com/rcrowley/go-metrics@v0.0.0-20201227073835-cf1acfcdf475", + "github.com/rivo/uniseg@v0.4.7", + "github.com/rjeczalik/notify@v0.9.3", + "github.com/rs/cors@v1.11.1", + "github.com/rs/xid@v1.6.0", + "github.com/safchain/ethtool@v0.5.10", + "github.com/secure-io/sio-go@v0.3.1", + "github.com/shirou/gopsutil/v3@v3.24.5", + "github.com/tidwall/gjson@v1.18.0", + "github.com/tidwall/match@v1.1.1", + "github.com/tidwall/pretty@v1.2.1", + "github.com/tinylib/msgp@v1.2.5", + "github.com/tklauser/go-sysconf@v0.3.15", + "github.com/tklauser/numcpus@v0.10.0", + "github.com/unrolled/secure@v1.17.0", + "github.com/valyala/bytebufferpool@v1.0.0", + "github.com/vbauerster/mpb/v8@v8.9.3", + "github.com/xdg/scram@v1.0.5", + "github.com/xdg/stringprep@v1.0.3", + "github.com/zeebo/xxh3@v1.0.2", + "go.etcd.io/etcd/api/v3@v3.5.19", + "go.etcd.io/etcd/client/pkg/v3@v3.5.19", + "go.etcd.io/etcd/client/v3@v3.5.19", + "go.mongodb.org/mongo-driver@v1.17.3", + "go.opentelemetry.io/auto/sdk@v1.1.0", + "go.opentelemetry.io/contrib/detectors/gcp@v1.35.0", + "go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.59.0", + "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp@v0.60.0", + "go.opentelemetry.io/otel/metric@v1.35.0", + "go.opentelemetry.io/otel/sdk/metric@v1.35.0", + "go.opentelemetry.io/otel/sdk@v1.35.0", + "go.opentelemetry.io/otel/trace@v1.35.0", + "go.opentelemetry.io/otel@v1.35.0", + "go.uber.org/atomic@v1.11.0", + "go.uber.org/multierr@v1.11.0", + "go.uber.org/zap@v1.27.0", + "goftp.io/server/v2@v2.0.1", + "golang.org/x/crypto@v0.37.0", + "golang.org/x/net@v0.39.0", + "golang.org/x/oauth2@v0.28.0", + "golang.org/x/sync@v0.13.0", + "golang.org/x/sys@v0.32.0", + "golang.org/x/term@v0.31.0", + "golang.org/x/text@v0.24.0", + "golang.org/x/time@v0.11.0", + "google.golang.org/api@v0.224.0", + "google.golang.org/genproto/googleapis/api@v0.0.0-20250311190419-81fb87f6b8bf", + "google.golang.org/genproto/googleapis/rpc@v0.0.0-20250311190419-81fb87f6b8bf", + "google.golang.org/genproto@v0.0.0-20250106144421-5f5ef82da422", + "google.golang.org/grpc@v1.71.0", + "google.golang.org/protobuf@v1.36.6", + "gopkg.in/yaml.v2@v2.4.0", + "gopkg.in/yaml.v3@v3.0.1", + "stdlib@v1.24.2" + ], + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "stdlib@v1.24.2", + "Name": "stdlib", + "Identifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "Version": "v1.24.2", + "Relationship": "direct", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "aead.dev/mem@v0.2.0", + "Name": "aead.dev/mem", + "Identifier": { + "PURL": "pkg:golang/aead.dev/mem@v0.2.0", + "UID": "1059a9f3d8305329" + }, + "Version": "v0.2.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "aead.dev/minisign@v0.3.0", + "Name": "aead.dev/minisign", + "Identifier": { + "PURL": "pkg:golang/aead.dev/minisign@v0.3.0", + "UID": "9bae28c348c25627" + }, + "Version": "v0.3.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "cel.dev/expr@v0.22.0", + "Name": "cel.dev/expr", + "Identifier": { + "PURL": "pkg:golang/cel.dev/expr@v0.22.0", + "UID": "245ea628bcd80a16" + }, + "Version": "v0.22.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "cloud.google.com/go@v0.118.0", + "Name": "cloud.google.com/go", + "Identifier": { + "PURL": "pkg:golang/cloud.google.com/go@v0.118.0", + "UID": "3a41e0dfb03a2b2c" + }, + "Version": "v0.118.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "cloud.google.com/go/auth@v0.15.0", + "Name": "cloud.google.com/go/auth", + "Identifier": { + "PURL": "pkg:golang/cloud.google.com/go/auth@v0.15.0", + "UID": "676e2cfc8e1c6a90" + }, + "Version": "v0.15.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "cloud.google.com/go/auth/oauth2adapt@v0.2.7", + "Name": "cloud.google.com/go/auth/oauth2adapt", + "Identifier": { + "PURL": "pkg:golang/cloud.google.com/go/auth/oauth2adapt@v0.2.7", + "UID": "b036b815364066aa" + }, + "Version": "v0.2.7", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "cloud.google.com/go/compute/metadata@v0.6.0", + "Name": "cloud.google.com/go/compute/metadata", + "Identifier": { + "PURL": "pkg:golang/cloud.google.com/go/compute/metadata@v0.6.0", + "UID": "fa67afb643f244de" + }, + "Version": "v0.6.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "cloud.google.com/go/iam@v1.3.1", + "Name": "cloud.google.com/go/iam", + "Identifier": { + "PURL": "pkg:golang/cloud.google.com/go/iam@v1.3.1", + "UID": "b166a9a7a714cb42" + }, + "Version": "v1.3.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "cloud.google.com/go/monitoring@v1.23.0", + "Name": "cloud.google.com/go/monitoring", + "Identifier": { + "PURL": "pkg:golang/cloud.google.com/go/monitoring@v1.23.0", + "UID": "603a47fcae7c967c" + }, + "Version": "v1.23.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "cloud.google.com/go/storage@v1.46.0", + "Name": "cloud.google.com/go/storage", + "Identifier": { + "PURL": "pkg:golang/cloud.google.com/go/storage@v1.46.0", + "UID": "c113371b28c094d6" + }, + "Version": "v1.46.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "filippo.io/edwards25519@v1.1.0", + "Name": "filippo.io/edwards25519", + "Identifier": { + "PURL": "pkg:golang/filippo.io/edwards25519@v1.1.0", + "UID": "95d4a77309f34195" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/Azure/azure-sdk-for-go/sdk/azcore@v1.17.0", + "Name": "github.com/Azure/azure-sdk-for-go/sdk/azcore", + "Identifier": { + "PURL": "pkg:golang/github.com/azure/azure-sdk-for-go/sdk/azcore@v1.17.0", + "UID": "7ea31cc75c6935d" + }, + "Version": "v1.17.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/Azure/azure-sdk-for-go/sdk/azidentity@v1.8.2", + "Name": "github.com/Azure/azure-sdk-for-go/sdk/azidentity", + "Identifier": { + "PURL": "pkg:golang/github.com/azure/azure-sdk-for-go/sdk/azidentity@v1.8.2", + "UID": "797e6ca0e549a6c6" + }, + "Version": "v1.8.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/Azure/azure-sdk-for-go/sdk/internal@v1.10.0", + "Name": "github.com/Azure/azure-sdk-for-go/sdk/internal", + "Identifier": { + "PURL": "pkg:golang/github.com/azure/azure-sdk-for-go/sdk/internal@v1.10.0", + "UID": "cb6dcadd0be3d6d4" + }, + "Version": "v1.10.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/Azure/azure-sdk-for-go/sdk/storage/azblob@v1.6.0", + "Name": "github.com/Azure/azure-sdk-for-go/sdk/storage/azblob", + "Identifier": { + "PURL": "pkg:golang/github.com/azure/azure-sdk-for-go/sdk/storage/azblob@v1.6.0", + "UID": "38949a0d50b9694e" + }, + "Version": "v1.6.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/Azure/go-ntlmssp@v0.0.0-20221128193559-754e69321358", + "Name": "github.com/Azure/go-ntlmssp", + "Identifier": { + "PURL": "pkg:golang/github.com/azure/go-ntlmssp@v0.0.0-20221128193559-754e69321358", + "UID": "cbc234d248b92cb9" + }, + "Version": "v0.0.0-20221128193559-754e69321358", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/AzureAD/microsoft-authentication-library-for-go@v1.4.1", + "Name": "github.com/AzureAD/microsoft-authentication-library-for-go", + "Identifier": { + "PURL": "pkg:golang/github.com/azuread/microsoft-authentication-library-for-go@v1.4.1", + "UID": "30ef85997372eb9" + }, + "Version": "v1.4.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp@v1.27.0", + "Name": "github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp", + "Identifier": { + "PURL": "pkg:golang/github.com/googlecloudplatform/opentelemetry-operations-go/detectors/gcp@v1.27.0", + "UID": "b5edd392f279965a" + }, + "Version": "v1.27.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric@v0.51.0", + "Name": "github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric", + "Identifier": { + "PURL": "pkg:golang/github.com/googlecloudplatform/opentelemetry-operations-go/exporter/metric@v0.51.0", + "UID": "34d056a90b619c4a" + }, + "Version": "v0.51.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping@v0.51.0", + "Name": "github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping", + "Identifier": { + "PURL": "pkg:golang/github.com/googlecloudplatform/opentelemetry-operations-go/internal/resourcemapping@v0.51.0", + "UID": "298bbbca13f04e8c" + }, + "Version": "v0.51.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/IBM/sarama@v1.45.1", + "Name": "github.com/IBM/sarama", + "Identifier": { + "PURL": "pkg:golang/github.com/ibm/sarama@v1.45.1", + "UID": "5431dc23f16eb3bc" + }, + "Version": "v1.45.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/VividCortex/ewma@v1.2.0", + "Name": "github.com/VividCortex/ewma", + "Identifier": { + "PURL": "pkg:golang/github.com/vividcortex/ewma@v1.2.0", + "UID": "1d87dae8d2ff4e67" + }, + "Version": "v1.2.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/acarl005/stripansi@v0.0.0-20180116102854-5a71ef0e047d", + "Name": "github.com/acarl005/stripansi", + "Identifier": { + "PURL": "pkg:golang/github.com/acarl005/stripansi@v0.0.0-20180116102854-5a71ef0e047d", + "UID": "ca2440ea523d498a" + }, + "Version": "v0.0.0-20180116102854-5a71ef0e047d", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/alecthomas/participle@v0.7.1", + "Name": "github.com/alecthomas/participle", + "Identifier": { + "PURL": "pkg:golang/github.com/alecthomas/participle@v0.7.1", + "UID": "5547a4a4dc2f127" + }, + "Version": "v0.7.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/apache/thrift@v0.21.0", + "Name": "github.com/apache/thrift", + "Identifier": { + "PURL": "pkg:golang/github.com/apache/thrift@v0.21.0", + "UID": "f1ce407aa81d636a" + }, + "Version": "v0.21.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/asaskevich/govalidator@v0.0.0-20230301143203-a9d515a09cc2", + "Name": "github.com/asaskevich/govalidator", + "Identifier": { + "PURL": "pkg:golang/github.com/asaskevich/govalidator@v0.0.0-20230301143203-a9d515a09cc2", + "UID": "7394c3282e2c31a2" + }, + "Version": "v0.0.0-20230301143203-a9d515a09cc2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/aymanbagabas/go-osc52/v2@v2.0.1", + "Name": "github.com/aymanbagabas/go-osc52/v2", + "Identifier": { + "PURL": "pkg:golang/github.com/aymanbagabas/go-osc52/v2@v2.0.1", + "UID": "40acfff0f340b8e8" + }, + "Version": "v2.0.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/beevik/ntp@v1.4.3", + "Name": "github.com/beevik/ntp", + "Identifier": { + "PURL": "pkg:golang/github.com/beevik/ntp@v1.4.3", + "UID": "cb026758a589d48a" + }, + "Version": "v1.4.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/beorn7/perks@v1.0.1", + "Name": "github.com/beorn7/perks", + "Identifier": { + "PURL": "pkg:golang/github.com/beorn7/perks@v1.0.1", + "UID": "492d1f01a8e0dff9" + }, + "Version": "v1.0.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/buger/jsonparser@v1.1.1", + "Name": "github.com/buger/jsonparser", + "Identifier": { + "PURL": "pkg:golang/github.com/buger/jsonparser@v1.1.1", + "UID": "f01ed774b231491b" + }, + "Version": "v1.1.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/cespare/xxhash/v2@v2.3.0", + "Name": "github.com/cespare/xxhash/v2", + "Identifier": { + "PURL": "pkg:golang/github.com/cespare/xxhash/v2@v2.3.0", + "UID": "4b38189ab50a9324" + }, + "Version": "v2.3.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/charmbracelet/bubbles@v0.20.0", + "Name": "github.com/charmbracelet/bubbles", + "Identifier": { + "PURL": "pkg:golang/github.com/charmbracelet/bubbles@v0.20.0", + "UID": "c2d10c1c84b90f9a" + }, + "Version": "v0.20.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/charmbracelet/bubbletea@v1.3.4", + "Name": "github.com/charmbracelet/bubbletea", + "Identifier": { + "PURL": "pkg:golang/github.com/charmbracelet/bubbletea@v1.3.4", + "UID": "2a479332e7625fd8" + }, + "Version": "v1.3.4", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/charmbracelet/lipgloss@v1.0.0", + "Name": "github.com/charmbracelet/lipgloss", + "Identifier": { + "PURL": "pkg:golang/github.com/charmbracelet/lipgloss@v1.0.0", + "UID": "4b2be292ad098617" + }, + "Version": "v1.0.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/charmbracelet/x/ansi@v0.8.0", + "Name": "github.com/charmbracelet/x/ansi", + "Identifier": { + "PURL": "pkg:golang/github.com/charmbracelet/x/ansi@v0.8.0", + "UID": "9a2aa722b1051f06" + }, + "Version": "v0.8.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/charmbracelet/x/term@v0.2.1", + "Name": "github.com/charmbracelet/x/term", + "Identifier": { + "PURL": "pkg:golang/github.com/charmbracelet/x/term@v0.2.1", + "UID": "6a8a9d9d28d98198" + }, + "Version": "v0.2.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/cheggaaa/pb@v1.0.29", + "Name": "github.com/cheggaaa/pb", + "Identifier": { + "PURL": "pkg:golang/github.com/cheggaaa/pb@v1.0.29", + "UID": "f670f3b17eaba0bf" + }, + "Version": "v1.0.29", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/cncf/xds/go@v0.0.0-20250121191232-2f005788dc42", + "Name": "github.com/cncf/xds/go", + "Identifier": { + "PURL": "pkg:golang/github.com/cncf/xds/go@v0.0.0-20250121191232-2f005788dc42", + "UID": "a93cebcd9de801ca" + }, + "Version": "v0.0.0-20250121191232-2f005788dc42", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/coreos/go-oidc/v3@v3.12.0", + "Name": "github.com/coreos/go-oidc/v3", + "Identifier": { + "PURL": "pkg:golang/github.com/coreos/go-oidc/v3@v3.12.0", + "UID": "4ac7c3ddc1c21f88" + }, + "Version": "v3.12.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/coreos/go-semver@v0.3.1", + "Name": "github.com/coreos/go-semver", + "Identifier": { + "PURL": "pkg:golang/github.com/coreos/go-semver@v0.3.1", + "UID": "e21bf94153e8b491" + }, + "Version": "v0.3.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/coreos/go-systemd/v22@v22.5.0", + "Name": "github.com/coreos/go-systemd/v22", + "Identifier": { + "PURL": "pkg:golang/github.com/coreos/go-systemd/v22@v22.5.0", + "UID": "2f65b82e5099a110" + }, + "Version": "v22.5.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/cosnicolaou/pbzip2@v1.0.5", + "Name": "github.com/cosnicolaou/pbzip2", + "Identifier": { + "PURL": "pkg:golang/github.com/cosnicolaou/pbzip2@v1.0.5", + "UID": "43e86a205d43a992" + }, + "Version": "v1.0.5", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/davecgh/go-spew@v1.1.2-0.20180830191138-d8f796af33cc", + "Name": "github.com/davecgh/go-spew", + "Identifier": { + "PURL": "pkg:golang/github.com/davecgh/go-spew@v1.1.2-0.20180830191138-d8f796af33cc", + "UID": "d7db07e511077345" + }, + "Version": "v1.1.2-0.20180830191138-d8f796af33cc", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/dchest/siphash@v1.2.3", + "Name": "github.com/dchest/siphash", + "Identifier": { + "PURL": "pkg:golang/github.com/dchest/siphash@v1.2.3", + "UID": "2aaf33e0f2dc0bf1" + }, + "Version": "v1.2.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/docker/go-units@v0.5.0", + "Name": "github.com/docker/go-units", + "Identifier": { + "PURL": "pkg:golang/github.com/docker/go-units@v0.5.0", + "UID": "cfffca6fe969976" + }, + "Version": "v0.5.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/dustin/go-humanize@v1.0.1", + "Name": "github.com/dustin/go-humanize", + "Identifier": { + "PURL": "pkg:golang/github.com/dustin/go-humanize@v1.0.1", + "UID": "d330b4b7b406b5b7" + }, + "Version": "v1.0.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/eapache/go-resiliency@v1.7.0", + "Name": "github.com/eapache/go-resiliency", + "Identifier": { + "PURL": "pkg:golang/github.com/eapache/go-resiliency@v1.7.0", + "UID": "12fc8f09134d8a91" + }, + "Version": "v1.7.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/eapache/go-xerial-snappy@v0.0.0-20230731223053-c322873962e3", + "Name": "github.com/eapache/go-xerial-snappy", + "Identifier": { + "PURL": "pkg:golang/github.com/eapache/go-xerial-snappy@v0.0.0-20230731223053-c322873962e3", + "UID": "220e9e2267f532b7" + }, + "Version": "v0.0.0-20230731223053-c322873962e3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/eapache/queue@v1.1.0", + "Name": "github.com/eapache/queue", + "Identifier": { + "PURL": "pkg:golang/github.com/eapache/queue@v1.1.0", + "UID": "a4b77df5fb6df1aa" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/eclipse/paho.mqtt.golang@v1.5.0", + "Name": "github.com/eclipse/paho.mqtt.golang", + "Identifier": { + "PURL": "pkg:golang/github.com/eclipse/paho.mqtt.golang@v1.5.0", + "UID": "d9fe53d3f0be979c" + }, + "Version": "v1.5.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/elastic/go-elasticsearch/v7@v7.17.10", + "Name": "github.com/elastic/go-elasticsearch/v7", + "Identifier": { + "PURL": "pkg:golang/github.com/elastic/go-elasticsearch/v7@v7.17.10", + "UID": "af3ff19157f0bbb2" + }, + "Version": "v7.17.10", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/envoyproxy/go-control-plane/envoy@v1.32.4", + "Name": "github.com/envoyproxy/go-control-plane/envoy", + "Identifier": { + "PURL": "pkg:golang/github.com/envoyproxy/go-control-plane/envoy@v1.32.4", + "UID": "f982784b2054521e" + }, + "Version": "v1.32.4", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/envoyproxy/protoc-gen-validate@v1.2.1", + "Name": "github.com/envoyproxy/protoc-gen-validate", + "Identifier": { + "PURL": "pkg:golang/github.com/envoyproxy/protoc-gen-validate@v1.2.1", + "UID": "711b70a49f83b184" + }, + "Version": "v1.2.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/fatih/color@v1.18.0", + "Name": "github.com/fatih/color", + "Identifier": { + "PURL": "pkg:golang/github.com/fatih/color@v1.18.0", + "UID": "42b31daa36ade573" + }, + "Version": "v1.18.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/fatih/structs@v1.1.0", + "Name": "github.com/fatih/structs", + "Identifier": { + "PURL": "pkg:golang/github.com/fatih/structs@v1.1.0", + "UID": "54dbaeea06b4dc4d" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/felixge/fgprof@v0.9.5", + "Name": "github.com/felixge/fgprof", + "Identifier": { + "PURL": "pkg:golang/github.com/felixge/fgprof@v0.9.5", + "UID": "1140df12c30200a4" + }, + "Version": "v0.9.5", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/felixge/httpsnoop@v1.0.4", + "Name": "github.com/felixge/httpsnoop", + "Identifier": { + "PURL": "pkg:golang/github.com/felixge/httpsnoop@v1.0.4", + "UID": "f0087509e73bbdaa" + }, + "Version": "v1.0.4", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/fraugster/parquet-go@v0.12.0", + "Name": "github.com/fraugster/parquet-go", + "Identifier": { + "PURL": "pkg:golang/github.com/fraugster/parquet-go@v0.12.0", + "UID": "16dfff54966225a" + }, + "Version": "v0.12.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-asn1-ber/asn1-ber@v1.5.7", + "Name": "github.com/go-asn1-ber/asn1-ber", + "Identifier": { + "PURL": "pkg:golang/github.com/go-asn1-ber/asn1-ber@v1.5.7", + "UID": "96c2a1d5d7e0f977" + }, + "Version": "v1.5.7", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-ini/ini@v1.67.0", + "Name": "github.com/go-ini/ini", + "Identifier": { + "PURL": "pkg:golang/github.com/go-ini/ini@v1.67.0", + "UID": "21b2143b808dab75" + }, + "Version": "v1.67.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-jose/go-jose/v4@v4.0.5", + "Name": "github.com/go-jose/go-jose/v4", + "Identifier": { + "PURL": "pkg:golang/github.com/go-jose/go-jose/v4@v4.0.5", + "UID": "77ca1e4a6b7a8ee3" + }, + "Version": "v4.0.5", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-ldap/ldap/v3@v3.4.10", + "Name": "github.com/go-ldap/ldap/v3", + "Identifier": { + "PURL": "pkg:golang/github.com/go-ldap/ldap/v3@v3.4.10", + "UID": "5dd0f5080b098465" + }, + "Version": "v3.4.10", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-logr/logr@v1.4.2", + "Name": "github.com/go-logr/logr", + "Identifier": { + "PURL": "pkg:golang/github.com/go-logr/logr@v1.4.2", + "UID": "d16930cb856ec0b7" + }, + "Version": "v1.4.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-logr/stdr@v1.2.2", + "Name": "github.com/go-logr/stdr", + "Identifier": { + "PURL": "pkg:golang/github.com/go-logr/stdr@v1.2.2", + "UID": "94399b67b9d46185" + }, + "Version": "v1.2.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-openapi/analysis@v0.23.0", + "Name": "github.com/go-openapi/analysis", + "Identifier": { + "PURL": "pkg:golang/github.com/go-openapi/analysis@v0.23.0", + "UID": "b50cf80db9f2feeb" + }, + "Version": "v0.23.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-openapi/errors@v0.22.0", + "Name": "github.com/go-openapi/errors", + "Identifier": { + "PURL": "pkg:golang/github.com/go-openapi/errors@v0.22.0", + "UID": "bc516b091a7d7e9" + }, + "Version": "v0.22.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-openapi/jsonpointer@v0.21.1", + "Name": "github.com/go-openapi/jsonpointer", + "Identifier": { + "PURL": "pkg:golang/github.com/go-openapi/jsonpointer@v0.21.1", + "UID": "c4b29fe90e4ce6d9" + }, + "Version": "v0.21.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-openapi/jsonreference@v0.21.0", + "Name": "github.com/go-openapi/jsonreference", + "Identifier": { + "PURL": "pkg:golang/github.com/go-openapi/jsonreference@v0.21.0", + "UID": "11c5652ec04101e3" + }, + "Version": "v0.21.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-openapi/loads@v0.22.0", + "Name": "github.com/go-openapi/loads", + "Identifier": { + "PURL": "pkg:golang/github.com/go-openapi/loads@v0.22.0", + "UID": "349df1896f252a22" + }, + "Version": "v0.22.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-openapi/runtime@v0.28.0", + "Name": "github.com/go-openapi/runtime", + "Identifier": { + "PURL": "pkg:golang/github.com/go-openapi/runtime@v0.28.0", + "UID": "268d3e4cf5496379" + }, + "Version": "v0.28.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-openapi/spec@v0.21.0", + "Name": "github.com/go-openapi/spec", + "Identifier": { + "PURL": "pkg:golang/github.com/go-openapi/spec@v0.21.0", + "UID": "ad904e5fe9c3d053" + }, + "Version": "v0.21.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-openapi/strfmt@v0.23.0", + "Name": "github.com/go-openapi/strfmt", + "Identifier": { + "PURL": "pkg:golang/github.com/go-openapi/strfmt@v0.23.0", + "UID": "7816eba0afa9c8b4" + }, + "Version": "v0.23.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-openapi/swag@v0.23.1", + "Name": "github.com/go-openapi/swag", + "Identifier": { + "PURL": "pkg:golang/github.com/go-openapi/swag@v0.23.1", + "UID": "e812faca14be3060" + }, + "Version": "v0.23.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-openapi/validate@v0.24.0", + "Name": "github.com/go-openapi/validate", + "Identifier": { + "PURL": "pkg:golang/github.com/go-openapi/validate@v0.24.0", + "UID": "f86ca0a7e2eda1b0" + }, + "Version": "v0.24.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/go-sql-driver/mysql@v1.9.0", + "Name": "github.com/go-sql-driver/mysql", + "Identifier": { + "PURL": "pkg:golang/github.com/go-sql-driver/mysql@v1.9.0", + "UID": "ec8e94c84bf4235" + }, + "Version": "v1.9.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/gobwas/httphead@v0.1.0", + "Name": "github.com/gobwas/httphead", + "Identifier": { + "PURL": "pkg:golang/github.com/gobwas/httphead@v0.1.0", + "UID": "c36dd7d39e5acf2b" + }, + "Version": "v0.1.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/gobwas/pool@v0.2.1", + "Name": "github.com/gobwas/pool", + "Identifier": { + "PURL": "pkg:golang/github.com/gobwas/pool@v0.2.1", + "UID": "8c8c77ba5eaf0b7d" + }, + "Version": "v0.2.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/gobwas/ws@v1.4.0", + "Name": "github.com/gobwas/ws", + "Identifier": { + "PURL": "pkg:golang/github.com/gobwas/ws@v1.4.0", + "UID": "42661ef6557d4a38" + }, + "Version": "v1.4.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/goccy/go-json@v0.10.5", + "Name": "github.com/goccy/go-json", + "Identifier": { + "PURL": "pkg:golang/github.com/goccy/go-json@v0.10.5", + "UID": "dfae22958471d322" + }, + "Version": "v0.10.5", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/gogo/protobuf@v1.3.2", + "Name": "github.com/gogo/protobuf", + "Identifier": { + "PURL": "pkg:golang/github.com/gogo/protobuf@v1.3.2", + "UID": "7d1171c76044cc4d" + }, + "Version": "v1.3.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/golang-jwt/jwt/v4@v4.5.2", + "Name": "github.com/golang-jwt/jwt/v4", + "Identifier": { + "PURL": "pkg:golang/github.com/golang-jwt/jwt/v4@v4.5.2", + "UID": "9bcada596d286e7b" + }, + "Version": "v4.5.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/golang-jwt/jwt/v5@v5.2.2", + "Name": "github.com/golang-jwt/jwt/v5", + "Identifier": { + "PURL": "pkg:golang/github.com/golang-jwt/jwt/v5@v5.2.2", + "UID": "908e3e0d974ffbce" + }, + "Version": "v5.2.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/golang/protobuf@v1.5.4", + "Name": "github.com/golang/protobuf", + "Identifier": { + "PURL": "pkg:golang/github.com/golang/protobuf@v1.5.4", + "UID": "21498dc3ca87383f" + }, + "Version": "v1.5.4", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/golang/snappy@v1.0.0", + "Name": "github.com/golang/snappy", + "Identifier": { + "PURL": "pkg:golang/github.com/golang/snappy@v1.0.0", + "UID": "30efd46c983351ba" + }, + "Version": "v1.0.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/gomodule/redigo@v1.9.2", + "Name": "github.com/gomodule/redigo", + "Identifier": { + "PURL": "pkg:golang/github.com/gomodule/redigo@v1.9.2", + "UID": "5ccedea5130798eb" + }, + "Version": "v1.9.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/google/pprof@v0.0.0-20250302191652-9094ed2288e7", + "Name": "github.com/google/pprof", + "Identifier": { + "PURL": "pkg:golang/github.com/google/pprof@v0.0.0-20250302191652-9094ed2288e7", + "UID": "f805915a44068251" + }, + "Version": "v0.0.0-20250302191652-9094ed2288e7", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/google/s2a-go@v0.1.9", + "Name": "github.com/google/s2a-go", + "Identifier": { + "PURL": "pkg:golang/github.com/google/s2a-go@v0.1.9", + "UID": "43680b5a03c8b88d" + }, + "Version": "v0.1.9", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/google/shlex@v0.0.0-20191202100458-e7afc7fbc510", + "Name": "github.com/google/shlex", + "Identifier": { + "PURL": "pkg:golang/github.com/google/shlex@v0.0.0-20191202100458-e7afc7fbc510", + "UID": "3c791c6ee8a9b8f8" + }, + "Version": "v0.0.0-20191202100458-e7afc7fbc510", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/google/uuid@v1.6.0", + "Name": "github.com/google/uuid", + "Identifier": { + "PURL": "pkg:golang/github.com/google/uuid@v1.6.0", + "UID": "5418973c5f4d4657" + }, + "Version": "v1.6.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/googleapis/enterprise-certificate-proxy@v0.3.5", + "Name": "github.com/googleapis/enterprise-certificate-proxy", + "Identifier": { + "PURL": "pkg:golang/github.com/googleapis/enterprise-certificate-proxy@v0.3.5", + "UID": "2e4cb56ed3b824ae" + }, + "Version": "v0.3.5", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/googleapis/gax-go/v2@v2.14.1", + "Name": "github.com/googleapis/gax-go/v2", + "Identifier": { + "PURL": "pkg:golang/github.com/googleapis/gax-go/v2@v2.14.1", + "UID": "32dac9aa0fade472" + }, + "Version": "v2.14.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/gorilla/websocket@v1.5.3", + "Name": "github.com/gorilla/websocket", + "Identifier": { + "PURL": "pkg:golang/github.com/gorilla/websocket@v1.5.3", + "UID": "b57d02ff6390a3d" + }, + "Version": "v1.5.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/hashicorp/errwrap@v1.1.0", + "Name": "github.com/hashicorp/errwrap", + "Identifier": { + "PURL": "pkg:golang/github.com/hashicorp/errwrap@v1.1.0", + "UID": "d9098a1cf951b493" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/hashicorp/go-multierror@v1.1.1", + "Name": "github.com/hashicorp/go-multierror", + "Identifier": { + "PURL": "pkg:golang/github.com/hashicorp/go-multierror@v1.1.1", + "UID": "c2f07b286cb1b0b5" + }, + "Version": "v1.1.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/hashicorp/go-uuid@v1.0.3", + "Name": "github.com/hashicorp/go-uuid", + "Identifier": { + "PURL": "pkg:golang/github.com/hashicorp/go-uuid@v1.0.3", + "UID": "6f130989597335f9" + }, + "Version": "v1.0.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/inconshreveable/mousetrap@v1.1.0", + "Name": "github.com/inconshreveable/mousetrap", + "Identifier": { + "PURL": "pkg:golang/github.com/inconshreveable/mousetrap@v1.1.0", + "UID": "be46a7ee211017f7" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/jcmturner/aescts/v2@v2.0.0", + "Name": "github.com/jcmturner/aescts/v2", + "Identifier": { + "PURL": "pkg:golang/github.com/jcmturner/aescts/v2@v2.0.0", + "UID": "159968da3dbf54fd" + }, + "Version": "v2.0.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/jcmturner/dnsutils/v2@v2.0.0", + "Name": "github.com/jcmturner/dnsutils/v2", + "Identifier": { + "PURL": "pkg:golang/github.com/jcmturner/dnsutils/v2@v2.0.0", + "UID": "f66c1984e2479d74" + }, + "Version": "v2.0.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/jcmturner/gofork@v1.7.6", + "Name": "github.com/jcmturner/gofork", + "Identifier": { + "PURL": "pkg:golang/github.com/jcmturner/gofork@v1.7.6", + "UID": "81cb50dd11532e2f" + }, + "Version": "v1.7.6", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/jcmturner/gokrb5/v8@v8.4.4", + "Name": "github.com/jcmturner/gokrb5/v8", + "Identifier": { + "PURL": "pkg:golang/github.com/jcmturner/gokrb5/v8@v8.4.4", + "UID": "6acd6448e22656ce" + }, + "Version": "v8.4.4", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/jcmturner/rpc/v2@v2.0.3", + "Name": "github.com/jcmturner/rpc/v2", + "Identifier": { + "PURL": "pkg:golang/github.com/jcmturner/rpc/v2@v2.0.3", + "UID": "6b49fc1e8702b97" + }, + "Version": "v2.0.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/jedib0t/go-pretty/v6@v6.6.7", + "Name": "github.com/jedib0t/go-pretty/v6", + "Identifier": { + "PURL": "pkg:golang/github.com/jedib0t/go-pretty/v6@v6.6.7", + "UID": "ad3d07ce76c2cec1" + }, + "Version": "v6.6.7", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/jessevdk/go-flags@v1.6.1", + "Name": "github.com/jessevdk/go-flags", + "Identifier": { + "PURL": "pkg:golang/github.com/jessevdk/go-flags@v1.6.1", + "UID": "5e3b7ea38d82f796" + }, + "Version": "v1.6.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/josharian/intern@v1.0.0", + "Name": "github.com/josharian/intern", + "Identifier": { + "PURL": "pkg:golang/github.com/josharian/intern@v1.0.0", + "UID": "3c99ea2d65774661" + }, + "Version": "v1.0.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/json-iterator/go@v1.1.12", + "Name": "github.com/json-iterator/go", + "Identifier": { + "PURL": "pkg:golang/github.com/json-iterator/go@v1.1.12", + "UID": "4db006325977631" + }, + "Version": "v1.1.12", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/juju/ratelimit@v1.0.2", + "Name": "github.com/juju/ratelimit", + "Identifier": { + "PURL": "pkg:golang/github.com/juju/ratelimit@v1.0.2", + "UID": "b97d02f91ac62b39" + }, + "Version": "v1.0.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/klauspost/compress@v1.18.0", + "Name": "github.com/klauspost/compress", + "Identifier": { + "PURL": "pkg:golang/github.com/klauspost/compress@v1.18.0", + "UID": "9e14e21f4a07677e" + }, + "Version": "v1.18.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/klauspost/cpuid/v2@v2.2.10", + "Name": "github.com/klauspost/cpuid/v2", + "Identifier": { + "PURL": "pkg:golang/github.com/klauspost/cpuid/v2@v2.2.10", + "UID": "c814f38b102acc52" + }, + "Version": "v2.2.10", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/klauspost/filepathx@v1.1.1", + "Name": "github.com/klauspost/filepathx", + "Identifier": { + "PURL": "pkg:golang/github.com/klauspost/filepathx@v1.1.1", + "UID": "9bfbc8aa5a74302e" + }, + "Version": "v1.1.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/klauspost/pgzip@v1.2.6", + "Name": "github.com/klauspost/pgzip", + "Identifier": { + "PURL": "pkg:golang/github.com/klauspost/pgzip@v1.2.6", + "UID": "3194717fb640629b" + }, + "Version": "v1.2.6", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/klauspost/readahead@v1.4.0", + "Name": "github.com/klauspost/readahead", + "Identifier": { + "PURL": "pkg:golang/github.com/klauspost/readahead@v1.4.0", + "UID": "6a827444e65212a5" + }, + "Version": "v1.4.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/klauspost/reedsolomon@v1.12.4", + "Name": "github.com/klauspost/reedsolomon", + "Identifier": { + "PURL": "pkg:golang/github.com/klauspost/reedsolomon@v1.12.4", + "UID": "b1cb2a6bdf62446e" + }, + "Version": "v1.12.4", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/kr/fs@v0.1.0", + "Name": "github.com/kr/fs", + "Identifier": { + "PURL": "pkg:golang/github.com/kr/fs@v0.1.0", + "UID": "a4197530302546cc" + }, + "Version": "v0.1.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/kylelemons/godebug@v1.1.0", + "Name": "github.com/kylelemons/godebug", + "Identifier": { + "PURL": "pkg:golang/github.com/kylelemons/godebug@v1.1.0", + "UID": "cd0961f2a1da3152" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lestrrat-go/blackmagic@v1.0.2", + "Name": "github.com/lestrrat-go/blackmagic", + "Identifier": { + "PURL": "pkg:golang/github.com/lestrrat-go/blackmagic@v1.0.2", + "UID": "7cad5e6f0b3d8006" + }, + "Version": "v1.0.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lestrrat-go/httpcc@v1.0.1", + "Name": "github.com/lestrrat-go/httpcc", + "Identifier": { + "PURL": "pkg:golang/github.com/lestrrat-go/httpcc@v1.0.1", + "UID": "efacf367508ad79d" + }, + "Version": "v1.0.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lestrrat-go/httprc@v1.0.6", + "Name": "github.com/lestrrat-go/httprc", + "Identifier": { + "PURL": "pkg:golang/github.com/lestrrat-go/httprc@v1.0.6", + "UID": "d0a5f8a92d3879e" + }, + "Version": "v1.0.6", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lestrrat-go/iter@v1.0.2", + "Name": "github.com/lestrrat-go/iter", + "Identifier": { + "PURL": "pkg:golang/github.com/lestrrat-go/iter@v1.0.2", + "UID": "100eb657a0b6849" + }, + "Version": "v1.0.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lestrrat-go/jwx/v2@v2.1.4", + "Name": "github.com/lestrrat-go/jwx/v2", + "Identifier": { + "PURL": "pkg:golang/github.com/lestrrat-go/jwx/v2@v2.1.4", + "UID": "6ca09633eaf99ddd" + }, + "Version": "v2.1.4", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lestrrat-go/option@v1.0.1", + "Name": "github.com/lestrrat-go/option", + "Identifier": { + "PURL": "pkg:golang/github.com/lestrrat-go/option@v1.0.1", + "UID": "c875c842a8ab71b6" + }, + "Version": "v1.0.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lib/pq@v1.10.9", + "Name": "github.com/lib/pq", + "Identifier": { + "PURL": "pkg:golang/github.com/lib/pq@v1.10.9", + "UID": "faba3a4057527b0d" + }, + "Version": "v1.10.9", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lithammer/shortuuid/v4@v4.2.0", + "Name": "github.com/lithammer/shortuuid/v4", + "Identifier": { + "PURL": "pkg:golang/github.com/lithammer/shortuuid/v4@v4.2.0", + "UID": "254968b0e26b2f0b" + }, + "Version": "v4.2.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/lucasb-eyer/go-colorful@v1.2.0", + "Name": "github.com/lucasb-eyer/go-colorful", + "Identifier": { + "PURL": "pkg:golang/github.com/lucasb-eyer/go-colorful@v1.2.0", + "UID": "1614ee4786af67f3" + }, + "Version": "v1.2.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/mailru/easyjson@v0.9.0", + "Name": "github.com/mailru/easyjson", + "Identifier": { + "PURL": "pkg:golang/github.com/mailru/easyjson@v0.9.0", + "UID": "a40d84b230e14ef5" + }, + "Version": "v0.9.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/mattn/go-colorable@v0.1.14", + "Name": "github.com/mattn/go-colorable", + "Identifier": { + "PURL": "pkg:golang/github.com/mattn/go-colorable@v0.1.14", + "UID": "e98c0cde996b57ea" + }, + "Version": "v0.1.14", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/mattn/go-ieproxy@v0.0.12", + "Name": "github.com/mattn/go-ieproxy", + "Identifier": { + "PURL": "pkg:golang/github.com/mattn/go-ieproxy@v0.0.12", + "UID": "cc80dc34ba81611a" + }, + "Version": "v0.0.12", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/mattn/go-isatty@v0.0.20", + "Name": "github.com/mattn/go-isatty", + "Identifier": { + "PURL": "pkg:golang/github.com/mattn/go-isatty@v0.0.20", + "UID": "e6e2dda025afcf6e" + }, + "Version": "v0.0.20", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/mattn/go-runewidth@v0.0.16", + "Name": "github.com/mattn/go-runewidth", + "Identifier": { + "PURL": "pkg:golang/github.com/mattn/go-runewidth@v0.0.16", + "UID": "11556e9375867c31" + }, + "Version": "v0.0.16", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/matttproud/golang_protobuf_extensions@v1.0.4", + "Name": "github.com/matttproud/golang_protobuf_extensions", + "Identifier": { + "PURL": "pkg:golang/github.com/matttproud/golang_protobuf_extensions@v1.0.4", + "UID": "42a74bc42f57c3e9" + }, + "Version": "v1.0.4", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/miekg/dns@v1.1.63", + "Name": "github.com/miekg/dns", + "Identifier": { + "PURL": "pkg:golang/github.com/miekg/dns@v1.1.63", + "UID": "8476f60bbaad8aa8" + }, + "Version": "v1.1.63", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/cli@v1.24.2", + "Name": "github.com/minio/cli", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/cli@v1.24.2", + "UID": "f557846b6528d62" + }, + "Version": "v1.24.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/colorjson@v1.0.8", + "Name": "github.com/minio/colorjson", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/colorjson@v1.0.8", + "UID": "6f4e1a5171926a4c" + }, + "Version": "v1.0.8", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/console@v1.7.6", + "Name": "github.com/minio/console", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/console@v1.7.6", + "UID": "a50c17683cd0924d" + }, + "Version": "v1.7.6", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/crc64nvme@v1.0.1", + "Name": "github.com/minio/crc64nvme", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/crc64nvme@v1.0.1", + "UID": "eac3696d1d733ceb" + }, + "Version": "v1.0.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/csvparser@v1.0.0", + "Name": "github.com/minio/csvparser", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/csvparser@v1.0.0", + "UID": "4e893cdabc327d77" + }, + "Version": "v1.0.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/dnscache@v0.1.1", + "Name": "github.com/minio/dnscache", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/dnscache@v0.1.1", + "UID": "445284a63ece317f" + }, + "Version": "v0.1.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/dperf@v0.6.3", + "Name": "github.com/minio/dperf", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/dperf@v0.6.3", + "UID": "5ad372481512c635" + }, + "Version": "v0.6.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/filepath@v1.0.0", + "Name": "github.com/minio/filepath", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/filepath@v1.0.0", + "UID": "66bd33e2b8aee17c" + }, + "Version": "v1.0.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/highwayhash@v1.0.3", + "Name": "github.com/minio/highwayhash", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/highwayhash@v1.0.3", + "UID": "44fd933084147d79" + }, + "Version": "v1.0.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/kms-go/kes@v0.3.1", + "Name": "github.com/minio/kms-go/kes", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/kms-go/kes@v0.3.1", + "UID": "314e437fb7e6a6de" + }, + "Version": "v0.3.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/kms-go/kms@v0.4.0", + "Name": "github.com/minio/kms-go/kms", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/kms-go/kms@v0.4.0", + "UID": "5e860944b4cec35f" + }, + "Version": "v0.4.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/madmin-go/v3@v3.0.109", + "Name": "github.com/minio/madmin-go/v3", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/madmin-go/v3@v3.0.109", + "UID": "ea3372a33059eaad" + }, + "Version": "v3.0.109", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/mc@v0.0.0-20250312172924-c1d5d4cbb4ca", + "Name": "github.com/minio/mc", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/mc@v0.0.0-20250312172924-c1d5d4cbb4ca", + "UID": "5aa2ced088c15172" + }, + "Version": "v0.0.0-20250312172924-c1d5d4cbb4ca", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/md5-simd@v1.1.2", + "Name": "github.com/minio/md5-simd", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/md5-simd@v1.1.2", + "UID": "86dd4408818660a5" + }, + "Version": "v1.1.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/minio-go/v7@v7.0.90", + "Name": "github.com/minio/minio-go/v7", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/minio-go/v7@v7.0.90", + "UID": "f73629ee19837ed1" + }, + "Version": "v7.0.90", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/mux@v1.9.2", + "Name": "github.com/minio/mux", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/mux@v1.9.2", + "UID": "e274eb89cc0ceef2" + }, + "Version": "v1.9.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/pkg/v3@v3.1.0", + "Name": "github.com/minio/pkg/v3", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/pkg/v3@v3.1.0", + "UID": "8a5326b5d554ce95" + }, + "Version": "v3.1.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/selfupdate@v0.6.0", + "Name": "github.com/minio/selfupdate", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/selfupdate@v0.6.0", + "UID": "1b5637ffc473df49" + }, + "Version": "v0.6.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/simdjson-go@v0.4.5", + "Name": "github.com/minio/simdjson-go", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/simdjson-go@v0.4.5", + "UID": "3e86935ca5bea96d" + }, + "Version": "v0.4.5", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/sio@v0.4.1", + "Name": "github.com/minio/sio", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/sio@v0.4.1", + "UID": "111c4a0cd567e53a" + }, + "Version": "v0.4.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/websocket@v1.6.0", + "Name": "github.com/minio/websocket", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/websocket@v1.6.0", + "UID": "4698d8c7ca1cd725" + }, + "Version": "v1.6.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/xxml@v0.0.3", + "Name": "github.com/minio/xxml", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/xxml@v0.0.3", + "UID": "f2711942d72ec4e3" + }, + "Version": "v0.0.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/minio/zipindex@v0.4.0", + "Name": "github.com/minio/zipindex", + "Identifier": { + "PURL": "pkg:golang/github.com/minio/zipindex@v0.4.0", + "UID": "8c7c1836068aa0ec" + }, + "Version": "v0.4.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/mitchellh/go-homedir@v1.1.0", + "Name": "github.com/mitchellh/go-homedir", + "Identifier": { + "PURL": "pkg:golang/github.com/mitchellh/go-homedir@v1.1.0", + "UID": "c7a34666ba2e95f6" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/mitchellh/mapstructure@v1.5.0", + "Name": "github.com/mitchellh/mapstructure", + "Identifier": { + "PURL": "pkg:golang/github.com/mitchellh/mapstructure@v1.5.0", + "UID": "fa88f78b554e537" + }, + "Version": "v1.5.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd", + "Name": "github.com/modern-go/concurrent", + "Identifier": { + "PURL": "pkg:golang/github.com/modern-go/concurrent@v0.0.0-20180306012644-bacd9c7ef1dd", + "UID": "873542454b6df4ff" + }, + "Version": "v0.0.0-20180306012644-bacd9c7ef1dd", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/modern-go/reflect2@v1.0.2", + "Name": "github.com/modern-go/reflect2", + "Identifier": { + "PURL": "pkg:golang/github.com/modern-go/reflect2@v1.0.2", + "UID": "8b8e6d7ca293a9f7" + }, + "Version": "v1.0.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/muesli/ansi@v0.0.0-20230316100256-276c6243b2f6", + "Name": "github.com/muesli/ansi", + "Identifier": { + "PURL": "pkg:golang/github.com/muesli/ansi@v0.0.0-20230316100256-276c6243b2f6", + "UID": "490967cd762eba23" + }, + "Version": "v0.0.0-20230316100256-276c6243b2f6", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/muesli/cancelreader@v0.2.2", + "Name": "github.com/muesli/cancelreader", + "Identifier": { + "PURL": "pkg:golang/github.com/muesli/cancelreader@v0.2.2", + "UID": "303cca4bb8cbf247" + }, + "Version": "v0.2.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/muesli/reflow@v0.3.0", + "Name": "github.com/muesli/reflow", + "Identifier": { + "PURL": "pkg:golang/github.com/muesli/reflow@v0.3.0", + "UID": "bccce02192269179" + }, + "Version": "v0.3.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/muesli/termenv@v0.16.0", + "Name": "github.com/muesli/termenv", + "Identifier": { + "PURL": "pkg:golang/github.com/muesli/termenv@v0.16.0", + "UID": "2f8bfbb59c3d2c5b" + }, + "Version": "v0.16.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/munnerz/goautoneg@v0.0.0-20191010083416-a7dc8b61c822", + "Name": "github.com/munnerz/goautoneg", + "Identifier": { + "PURL": "pkg:golang/github.com/munnerz/goautoneg@v0.0.0-20191010083416-a7dc8b61c822", + "UID": "1c4a100ae685a45" + }, + "Version": "v0.0.0-20191010083416-a7dc8b61c822", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/nats-io/nats.go@v1.39.1", + "Name": "github.com/nats-io/nats.go", + "Identifier": { + "PURL": "pkg:golang/github.com/nats-io/nats.go@v1.39.1", + "UID": "1cdb026718c6efaa" + }, + "Version": "v1.39.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/nats-io/nkeys@v0.4.10", + "Name": "github.com/nats-io/nkeys", + "Identifier": { + "PURL": "pkg:golang/github.com/nats-io/nkeys@v0.4.10", + "UID": "965568a7de331df6" + }, + "Version": "v0.4.10", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/nats-io/nuid@v1.0.1", + "Name": "github.com/nats-io/nuid", + "Identifier": { + "PURL": "pkg:golang/github.com/nats-io/nuid@v1.0.1", + "UID": "3a5888656853189d" + }, + "Version": "v1.0.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/nats-io/stan.go@v0.10.4", + "Name": "github.com/nats-io/stan.go", + "Identifier": { + "PURL": "pkg:golang/github.com/nats-io/stan.go@v0.10.4", + "UID": "d62157637def1814" + }, + "Version": "v0.10.4", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/ncw/directio@v1.0.5", + "Name": "github.com/ncw/directio", + "Identifier": { + "PURL": "pkg:golang/github.com/ncw/directio@v1.0.5", + "UID": "dda09029f46f2972" + }, + "Version": "v1.0.5", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/nsqio/go-nsq@v1.1.0", + "Name": "github.com/nsqio/go-nsq", + "Identifier": { + "PURL": "pkg:golang/github.com/nsqio/go-nsq@v1.1.0", + "UID": "a433a608a9b6bc36" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/oklog/ulid@v1.3.1", + "Name": "github.com/oklog/ulid", + "Identifier": { + "PURL": "pkg:golang/github.com/oklog/ulid@v1.3.1", + "UID": "a130210540ede0c3" + }, + "Version": "v1.3.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/olekukonko/tablewriter@v0.0.5", + "Name": "github.com/olekukonko/tablewriter", + "Identifier": { + "PURL": "pkg:golang/github.com/olekukonko/tablewriter@v0.0.5", + "UID": "941f21852cb05963" + }, + "Version": "v0.0.5", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/philhofer/fwd@v1.1.3-0.20240916144458-20a13a1f6b7c", + "Name": "github.com/philhofer/fwd", + "Identifier": { + "PURL": "pkg:golang/github.com/philhofer/fwd@v1.1.3-0.20240916144458-20a13a1f6b7c", + "UID": "62dbccd959215312" + }, + "Version": "v1.1.3-0.20240916144458-20a13a1f6b7c", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/pierrec/lz4/v4@v4.1.22", + "Name": "github.com/pierrec/lz4/v4", + "Identifier": { + "PURL": "pkg:golang/github.com/pierrec/lz4/v4@v4.1.22", + "UID": "4b76ae69c9a929" + }, + "Version": "v4.1.22", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/pkg/browser@v0.0.0-20240102092130-5ac0b6a4141c", + "Name": "github.com/pkg/browser", + "Identifier": { + "PURL": "pkg:golang/github.com/pkg/browser@v0.0.0-20240102092130-5ac0b6a4141c", + "UID": "16f28d3fa096aacb" + }, + "Version": "v0.0.0-20240102092130-5ac0b6a4141c", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/pkg/errors@v0.9.1", + "Name": "github.com/pkg/errors", + "Identifier": { + "PURL": "pkg:golang/github.com/pkg/errors@v0.9.1", + "UID": "45afe04d5763fa87" + }, + "Version": "v0.9.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/pkg/sftp@v1.13.8", + "Name": "github.com/pkg/sftp", + "Identifier": { + "PURL": "pkg:golang/github.com/pkg/sftp@v1.13.8", + "UID": "77664c2b643300d9" + }, + "Version": "v1.13.8", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/pkg/xattr@v0.4.10", + "Name": "github.com/pkg/xattr", + "Identifier": { + "PURL": "pkg:golang/github.com/pkg/xattr@v0.4.10", + "UID": "25a0771b76baf4a7" + }, + "Version": "v0.4.10", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/posener/complete@v1.2.3", + "Name": "github.com/posener/complete", + "Identifier": { + "PURL": "pkg:golang/github.com/posener/complete@v1.2.3", + "UID": "c982846562531703" + }, + "Version": "v1.2.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/prometheus/client_golang@v1.21.1", + "Name": "github.com/prometheus/client_golang", + "Identifier": { + "PURL": "pkg:golang/github.com/prometheus/client_golang@v1.21.1", + "UID": "57c38e7d5085d519" + }, + "Version": "v1.21.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/prometheus/client_model@v0.6.2", + "Name": "github.com/prometheus/client_model", + "Identifier": { + "PURL": "pkg:golang/github.com/prometheus/client_model@v0.6.2", + "UID": "b953cef0de4d9a7d" + }, + "Version": "v0.6.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/prometheus/common@v0.63.0", + "Name": "github.com/prometheus/common", + "Identifier": { + "PURL": "pkg:golang/github.com/prometheus/common@v0.63.0", + "UID": "a6fc9db0858a85aa" + }, + "Version": "v0.63.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/prometheus/procfs@v0.16.0", + "Name": "github.com/prometheus/procfs", + "Identifier": { + "PURL": "pkg:golang/github.com/prometheus/procfs@v0.16.0", + "UID": "cee55359f4937f95" + }, + "Version": "v0.16.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/prometheus/prom2json@v1.4.2", + "Name": "github.com/prometheus/prom2json", + "Identifier": { + "PURL": "pkg:golang/github.com/prometheus/prom2json@v1.4.2", + "UID": "5a620e7a59b91442" + }, + "Version": "v1.4.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/prometheus/prometheus@v0.303.0", + "Name": "github.com/prometheus/prometheus", + "Identifier": { + "PURL": "pkg:golang/github.com/prometheus/prometheus@v0.303.0", + "UID": "e731b806e3c9c0d4" + }, + "Version": "v0.303.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/puzpuzpuz/xsync/v3@v3.5.1", + "Name": "github.com/puzpuzpuz/xsync/v3", + "Identifier": { + "PURL": "pkg:golang/github.com/puzpuzpuz/xsync/v3@v3.5.1", + "UID": "5801f48b55563b20" + }, + "Version": "v3.5.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/rabbitmq/amqp091-go@v1.10.0", + "Name": "github.com/rabbitmq/amqp091-go", + "Identifier": { + "PURL": "pkg:golang/github.com/rabbitmq/amqp091-go@v1.10.0", + "UID": "27d4991559d475bf" + }, + "Version": "v1.10.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/rcrowley/go-metrics@v0.0.0-20201227073835-cf1acfcdf475", + "Name": "github.com/rcrowley/go-metrics", + "Identifier": { + "PURL": "pkg:golang/github.com/rcrowley/go-metrics@v0.0.0-20201227073835-cf1acfcdf475", + "UID": "e389cfc4de64d2f7" + }, + "Version": "v0.0.0-20201227073835-cf1acfcdf475", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/rivo/uniseg@v0.4.7", + "Name": "github.com/rivo/uniseg", + "Identifier": { + "PURL": "pkg:golang/github.com/rivo/uniseg@v0.4.7", + "UID": "8df3189923f72b8b" + }, + "Version": "v0.4.7", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/rjeczalik/notify@v0.9.3", + "Name": "github.com/rjeczalik/notify", + "Identifier": { + "PURL": "pkg:golang/github.com/rjeczalik/notify@v0.9.3", + "UID": "eda46b65e8bca8db" + }, + "Version": "v0.9.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/rs/cors@v1.11.1", + "Name": "github.com/rs/cors", + "Identifier": { + "PURL": "pkg:golang/github.com/rs/cors@v1.11.1", + "UID": "37d745fb1576983f" + }, + "Version": "v1.11.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/rs/xid@v1.6.0", + "Name": "github.com/rs/xid", + "Identifier": { + "PURL": "pkg:golang/github.com/rs/xid@v1.6.0", + "UID": "2085c68c52e88a0b" + }, + "Version": "v1.6.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/safchain/ethtool@v0.5.10", + "Name": "github.com/safchain/ethtool", + "Identifier": { + "PURL": "pkg:golang/github.com/safchain/ethtool@v0.5.10", + "UID": "61a8af2b6776d1db" + }, + "Version": "v0.5.10", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/secure-io/sio-go@v0.3.1", + "Name": "github.com/secure-io/sio-go", + "Identifier": { + "PURL": "pkg:golang/github.com/secure-io/sio-go@v0.3.1", + "UID": "85a6d74bc5098dae" + }, + "Version": "v0.3.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/shirou/gopsutil/v3@v3.24.5", + "Name": "github.com/shirou/gopsutil/v3", + "Identifier": { + "PURL": "pkg:golang/github.com/shirou/gopsutil/v3@v3.24.5", + "UID": "402042375cdf80d6" + }, + "Version": "v3.24.5", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/tidwall/gjson@v1.18.0", + "Name": "github.com/tidwall/gjson", + "Identifier": { + "PURL": "pkg:golang/github.com/tidwall/gjson@v1.18.0", + "UID": "6f28f9bb99ea55d4" + }, + "Version": "v1.18.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/tidwall/match@v1.1.1", + "Name": "github.com/tidwall/match", + "Identifier": { + "PURL": "pkg:golang/github.com/tidwall/match@v1.1.1", + "UID": "9a2ad5026d28dd4" + }, + "Version": "v1.1.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/tidwall/pretty@v1.2.1", + "Name": "github.com/tidwall/pretty", + "Identifier": { + "PURL": "pkg:golang/github.com/tidwall/pretty@v1.2.1", + "UID": "3375af149cff880d" + }, + "Version": "v1.2.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/tinylib/msgp@v1.2.5", + "Name": "github.com/tinylib/msgp", + "Identifier": { + "PURL": "pkg:golang/github.com/tinylib/msgp@v1.2.5", + "UID": "87e495d466ce1aad" + }, + "Version": "v1.2.5", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/tklauser/go-sysconf@v0.3.15", + "Name": "github.com/tklauser/go-sysconf", + "Identifier": { + "PURL": "pkg:golang/github.com/tklauser/go-sysconf@v0.3.15", + "UID": "a8fdea8b8e24c9cd" + }, + "Version": "v0.3.15", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/tklauser/numcpus@v0.10.0", + "Name": "github.com/tklauser/numcpus", + "Identifier": { + "PURL": "pkg:golang/github.com/tklauser/numcpus@v0.10.0", + "UID": "42decd6d908b4b2f" + }, + "Version": "v0.10.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/unrolled/secure@v1.17.0", + "Name": "github.com/unrolled/secure", + "Identifier": { + "PURL": "pkg:golang/github.com/unrolled/secure@v1.17.0", + "UID": "fa391e086287cbdd" + }, + "Version": "v1.17.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/valyala/bytebufferpool@v1.0.0", + "Name": "github.com/valyala/bytebufferpool", + "Identifier": { + "PURL": "pkg:golang/github.com/valyala/bytebufferpool@v1.0.0", + "UID": "660c79eda309d40d" + }, + "Version": "v1.0.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/vbauerster/mpb/v8@v8.9.3", + "Name": "github.com/vbauerster/mpb/v8", + "Identifier": { + "PURL": "pkg:golang/github.com/vbauerster/mpb/v8@v8.9.3", + "UID": "12eaf766128f3cc4" + }, + "Version": "v8.9.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/xdg/scram@v1.0.5", + "Name": "github.com/xdg/scram", + "Identifier": { + "PURL": "pkg:golang/github.com/xdg/scram@v1.0.5", + "UID": "5799b7ab2d939155" + }, + "Version": "v1.0.5", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/xdg/stringprep@v1.0.3", + "Name": "github.com/xdg/stringprep", + "Identifier": { + "PURL": "pkg:golang/github.com/xdg/stringprep@v1.0.3", + "UID": "72a80e305f7f3f54" + }, + "Version": "v1.0.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/zeebo/xxh3@v1.0.2", + "Name": "github.com/zeebo/xxh3", + "Identifier": { + "PURL": "pkg:golang/github.com/zeebo/xxh3@v1.0.2", + "UID": "80170682c1930e28" + }, + "Version": "v1.0.2", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.etcd.io/etcd/api/v3@v3.5.19", + "Name": "go.etcd.io/etcd/api/v3", + "Identifier": { + "PURL": "pkg:golang/go.etcd.io/etcd/api/v3@v3.5.19", + "UID": "9e5c966fb044ad5b" + }, + "Version": "v3.5.19", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.etcd.io/etcd/client/pkg/v3@v3.5.19", + "Name": "go.etcd.io/etcd/client/pkg/v3", + "Identifier": { + "PURL": "pkg:golang/go.etcd.io/etcd/client/pkg/v3@v3.5.19", + "UID": "4735d57605064c6b" + }, + "Version": "v3.5.19", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.etcd.io/etcd/client/v3@v3.5.19", + "Name": "go.etcd.io/etcd/client/v3", + "Identifier": { + "PURL": "pkg:golang/go.etcd.io/etcd/client/v3@v3.5.19", + "UID": "f231dc1afdd4be5b" + }, + "Version": "v3.5.19", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.mongodb.org/mongo-driver@v1.17.3", + "Name": "go.mongodb.org/mongo-driver", + "Identifier": { + "PURL": "pkg:golang/go.mongodb.org/mongo-driver@v1.17.3", + "UID": "ca87bb62248b90db" + }, + "Version": "v1.17.3", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.opentelemetry.io/auto/sdk@v1.1.0", + "Name": "go.opentelemetry.io/auto/sdk", + "Identifier": { + "PURL": "pkg:golang/go.opentelemetry.io/auto/sdk@v1.1.0", + "UID": "965edab6dd8341c6" + }, + "Version": "v1.1.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.opentelemetry.io/contrib/detectors/gcp@v1.35.0", + "Name": "go.opentelemetry.io/contrib/detectors/gcp", + "Identifier": { + "PURL": "pkg:golang/go.opentelemetry.io/contrib/detectors/gcp@v1.35.0", + "UID": "70d9d5b4496e9623" + }, + "Version": "v1.35.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.59.0", + "Name": "go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc", + "Identifier": { + "PURL": "pkg:golang/go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.59.0", + "UID": "57d170f9964409c" + }, + "Version": "v0.59.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp@v0.60.0", + "Name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp", + "Identifier": { + "PURL": "pkg:golang/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp@v0.60.0", + "UID": "768e1b1cdcb650df" + }, + "Version": "v0.60.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.opentelemetry.io/otel@v1.35.0", + "Name": "go.opentelemetry.io/otel", + "Identifier": { + "PURL": "pkg:golang/go.opentelemetry.io/otel@v1.35.0", + "UID": "1bf7ed6d3420db17" + }, + "Version": "v1.35.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.opentelemetry.io/otel/metric@v1.35.0", + "Name": "go.opentelemetry.io/otel/metric", + "Identifier": { + "PURL": "pkg:golang/go.opentelemetry.io/otel/metric@v1.35.0", + "UID": "fc671d30c87ae3e2" + }, + "Version": "v1.35.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.opentelemetry.io/otel/sdk@v1.35.0", + "Name": "go.opentelemetry.io/otel/sdk", + "Identifier": { + "PURL": "pkg:golang/go.opentelemetry.io/otel/sdk@v1.35.0", + "UID": "4b6910fdc62a06b5" + }, + "Version": "v1.35.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.opentelemetry.io/otel/sdk/metric@v1.35.0", + "Name": "go.opentelemetry.io/otel/sdk/metric", + "Identifier": { + "PURL": "pkg:golang/go.opentelemetry.io/otel/sdk/metric@v1.35.0", + "UID": "b157957f4a7544a4" + }, + "Version": "v1.35.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.opentelemetry.io/otel/trace@v1.35.0", + "Name": "go.opentelemetry.io/otel/trace", + "Identifier": { + "PURL": "pkg:golang/go.opentelemetry.io/otel/trace@v1.35.0", + "UID": "f04bc355ca68d53d" + }, + "Version": "v1.35.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.uber.org/atomic@v1.11.0", + "Name": "go.uber.org/atomic", + "Identifier": { + "PURL": "pkg:golang/go.uber.org/atomic@v1.11.0", + "UID": "34a6512905f923e8" + }, + "Version": "v1.11.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.uber.org/multierr@v1.11.0", + "Name": "go.uber.org/multierr", + "Identifier": { + "PURL": "pkg:golang/go.uber.org/multierr@v1.11.0", + "UID": "e4641076e596e769" + }, + "Version": "v1.11.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "go.uber.org/zap@v1.27.0", + "Name": "go.uber.org/zap", + "Identifier": { + "PURL": "pkg:golang/go.uber.org/zap@v1.27.0", + "UID": "f3047d4b585f4c4b" + }, + "Version": "v1.27.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "goftp.io/server/v2@v2.0.1", + "Name": "goftp.io/server/v2", + "Identifier": { + "PURL": "pkg:golang/goftp.io/server/v2@v2.0.1", + "UID": "98f77bd743804ea4" + }, + "Version": "v2.0.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/crypto@v0.37.0", + "Name": "golang.org/x/crypto", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "114f8a84bd734d66" + }, + "Version": "v0.37.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/net@v0.39.0", + "Name": "golang.org/x/net", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/net@v0.39.0", + "UID": "6d6810bfd2c03190" + }, + "Version": "v0.39.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/oauth2@v0.28.0", + "Name": "golang.org/x/oauth2", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/oauth2@v0.28.0", + "UID": "351cd42ef1a2b266" + }, + "Version": "v0.28.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/sync@v0.13.0", + "Name": "golang.org/x/sync", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/sync@v0.13.0", + "UID": "b51642bd245b968a" + }, + "Version": "v0.13.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/sys@v0.32.0", + "Name": "golang.org/x/sys", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/sys@v0.32.0", + "UID": "7a71abbcd9b7358b" + }, + "Version": "v0.32.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/term@v0.31.0", + "Name": "golang.org/x/term", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/term@v0.31.0", + "UID": "f13b8582122dc85f" + }, + "Version": "v0.31.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/text@v0.24.0", + "Name": "golang.org/x/text", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.24.0", + "UID": "5daaee8034347960" + }, + "Version": "v0.24.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/time@v0.11.0", + "Name": "golang.org/x/time", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/time@v0.11.0", + "UID": "e95af96946378026" + }, + "Version": "v0.11.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "google.golang.org/api@v0.224.0", + "Name": "google.golang.org/api", + "Identifier": { + "PURL": "pkg:golang/google.golang.org/api@v0.224.0", + "UID": "6074c1dabbce53bd" + }, + "Version": "v0.224.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "google.golang.org/genproto@v0.0.0-20250106144421-5f5ef82da422", + "Name": "google.golang.org/genproto", + "Identifier": { + "PURL": "pkg:golang/google.golang.org/genproto@v0.0.0-20250106144421-5f5ef82da422", + "UID": "4bed866ea709d133" + }, + "Version": "v0.0.0-20250106144421-5f5ef82da422", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "google.golang.org/genproto/googleapis/api@v0.0.0-20250311190419-81fb87f6b8bf", + "Name": "google.golang.org/genproto/googleapis/api", + "Identifier": { + "PURL": "pkg:golang/google.golang.org/genproto/googleapis/api@v0.0.0-20250311190419-81fb87f6b8bf", + "UID": "74cc5437b414b958" + }, + "Version": "v0.0.0-20250311190419-81fb87f6b8bf", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "google.golang.org/genproto/googleapis/rpc@v0.0.0-20250311190419-81fb87f6b8bf", + "Name": "google.golang.org/genproto/googleapis/rpc", + "Identifier": { + "PURL": "pkg:golang/google.golang.org/genproto/googleapis/rpc@v0.0.0-20250311190419-81fb87f6b8bf", + "UID": "5080f8720a4dc991" + }, + "Version": "v0.0.0-20250311190419-81fb87f6b8bf", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "google.golang.org/grpc@v1.71.0", + "Name": "google.golang.org/grpc", + "Identifier": { + "PURL": "pkg:golang/google.golang.org/grpc@v1.71.0", + "UID": "70ed0c7baf32264" + }, + "Version": "v1.71.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "google.golang.org/protobuf@v1.36.6", + "Name": "google.golang.org/protobuf", + "Identifier": { + "PURL": "pkg:golang/google.golang.org/protobuf@v1.36.6", + "UID": "2a63734746e00288" + }, + "Version": "v1.36.6", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "gopkg.in/yaml.v2@v2.4.0", + "Name": "gopkg.in/yaml.v2", + "Identifier": { + "PURL": "pkg:golang/gopkg.in/yaml.v2@v2.4.0", + "UID": "b3b99896b033000d" + }, + "Version": "v2.4.0", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "gopkg.in/yaml.v3@v3.0.1", + "Name": "gopkg.in/yaml.v3", + "Identifier": { + "PURL": "pkg:golang/gopkg.in/yaml.v3@v3.0.1", + "UID": "28666a7dd8f12cd9" + }, + "Version": "v3.0.1", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "AnalyzedBy": "gobinary" + } + ], + "Vulnerabilities": [ + { + "VulnerabilityID": "CVE-2026-41602", + "VendorIDs": [ + "GHSA-wf45-q9ch-q8gh" + ], + "PkgID": "github.com/apache/thrift@v0.21.0", + "PkgName": "github.com/apache/thrift", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/apache/thrift@v0.21.0", + "UID": "f1ce407aa81d636a" + }, + "InstalledVersion": "v0.21.0", + "FixedVersion": "0.23.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-41602", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:0d51c61fe23f9f1a67e872aa2d67b04033b222f1145c25f29c2286aeeaa1b725", + "Title": "github.com/apache/thrift: Apache Thrift: Integer Overflow in TFramedTransport Go implementation", + "Description": "Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 3, + "bitnami": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/04/28/6", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14885", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24503", + "https://access.redhat.com/errata/RHSA-2026:24539", + "https://access.redhat.com/errata/RHSA-2026:25273", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/security/cve/CVE-2026-41602", + "https://bugzilla.redhat.com/show_bug.cgi?id=2463407", + "https://github.com/apache/thrift", + "https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql", + "https://nvd.nist.gov/vuln/detail/CVE-2026-41602", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41602.json", + "https://www.cve.org/CVERecord?id=CVE-2026-41602" + ], + "PublishedDate": "2026-04-28T10:16:03Z", + "LastModifiedDate": "2026-09-09T13:19:53.8Z" + }, + { + "VulnerabilityID": "CVE-2026-43871", + "VendorIDs": [ + "GHSA-8wv5-x4w7-5gww" + ], + "PkgID": "github.com/apache/thrift@v0.21.0", + "PkgName": "github.com/apache/thrift", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/apache/thrift@v0.21.0", + "UID": "f1ce407aa81d636a" + }, + "InstalledVersion": "v0.21.0", + "FixedVersion": "0.24.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-43871", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:1882942c42207dfa9444859d8ea00d44a6ede57cbaa18d1a6ab89cab2b263244", + "Title": "thrift: Apache Thrift: Denial of Service via infinite loop", + "Description": "Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "azure": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 8.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/07/24/33", + "https://access.redhat.com/security/cve/CVE-2026-43871", + "https://github.com/apache/thrift", + "https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9", + "https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby", + "https://nvd.nist.gov/vuln/detail/CVE-2026-43871", + "https://www.cve.org/CVERecord?id=CVE-2026-43871" + ], + "PublishedDate": "2026-07-27T12:16:44.413Z", + "LastModifiedDate": "2026-07-27T19:51:36.197Z" + }, + { + "VulnerabilityID": "CVE-2026-32285", + "VendorIDs": [ + "GHSA-6g7g-w4f8-9c9x" + ], + "PkgID": "github.com/buger/jsonparser@v1.1.1", + "PkgName": "github.com/buger/jsonparser", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/buger/jsonparser@v1.1.1", + "UID": "f01ed774b231491b" + }, + "InstalledVersion": "v1.1.1", + "FixedVersion": "1.1.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32285", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:d3366e80909b448e5d7f2f60c357aa6b3a00ea5417cc213e9945ae1c97120a8d", + "Title": "github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input", + "Description": "The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-129", + "CWE-1285" + ], + "VendorSeverity": { + "amazon": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:17121", + "https://access.redhat.com/errata/RHSA-2026:17123", + "https://access.redhat.com/errata/RHSA-2026:19099", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:35111", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:7191", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/security/cve/CVE-2026-32285", + "https://bugzilla.redhat.com/show_bug.cgi?id=2451846", + "https://github.com/buger/jsonparser", + "https://github.com/buger/jsonparser/commit/a69e7e01cd4ad67bdfd3ac2c080b9212af16f4b0", + "https://github.com/buger/jsonparser/issues/275", + "https://github.com/buger/jsonparser/pull/276", + "https://github.com/buger/jsonparser/releases/tag/v1.1.2", + "https://github.com/golang/vulndb/issues/4514", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32285", + "https://pkg.go.dev/vuln/GO-2026-4514", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32285.json", + "https://securityinfinity.com/research/buger-jsonparser-negative-slice-panic-dos-2026", + "https://www.cve.org/CVERecord?id=CVE-2026-32285" + ], + "PublishedDate": "2026-03-26T20:16:12.197Z", + "LastModifiedDate": "2026-09-09T13:19:17.09Z" + }, + { + "VulnerabilityID": "CVE-2026-34986", + "VendorIDs": [ + "GHSA-78h2-9frx-2jm8" + ], + "PkgID": "github.com/go-jose/go-jose/v4@v4.0.5", + "PkgName": "github.com/go-jose/go-jose/v4", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/go-jose/go-jose/v4@v4.0.5", + "UID": "77ca1e4a6b7a8ee3" + }, + "InstalledVersion": "v4.0.5", + "FixedVersion": "4.1.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-34986", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:94597403908411853792c3db6c8725eccf1d03c8c9345347c5fc10d362bc8992", + "Title": "github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object", + "Description": "Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-248", + "CWE-131" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "ghsa": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10130", + "https://access.redhat.com/errata/RHSA-2026:10135", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:11070", + "https://access.redhat.com/errata/RHSA-2026:11217", + "https://access.redhat.com/errata/RHSA-2026:11512", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12116", + "https://access.redhat.com/errata/RHSA-2026:12277", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17121", + "https://access.redhat.com/errata/RHSA-2026:17123", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:17448", + "https://access.redhat.com/errata/RHSA-2026:17458", + "https://access.redhat.com/errata/RHSA-2026:17459", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17474", + "https://access.redhat.com/errata/RHSA-2026:17547", + "https://access.redhat.com/errata/RHSA-2026:17550", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:17789", + "https://access.redhat.com/errata/RHSA-2026:18584", + "https://access.redhat.com/errata/RHSA-2026:18585", + "https://access.redhat.com/errata/RHSA-2026:19017", + "https://access.redhat.com/errata/RHSA-2026:19099", + "https://access.redhat.com/errata/RHSA-2026:19108", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19173", + "https://access.redhat.com/errata/RHSA-2026:19186", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:20034", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:20946", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21703", + "https://access.redhat.com/errata/RHSA-2026:21709", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21931", + "https://access.redhat.com/errata/RHSA-2026:21932", + "https://access.redhat.com/errata/RHSA-2026:22258", + "https://access.redhat.com/errata/RHSA-2026:22260", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22629", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23241", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24471", + "https://access.redhat.com/errata/RHSA-2026:24475", + "https://access.redhat.com/errata/RHSA-2026:24477", + "https://access.redhat.com/errata/RHSA-2026:24479", + "https://access.redhat.com/errata/RHSA-2026:24482", + "https://access.redhat.com/errata/RHSA-2026:24484", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25187", + "https://access.redhat.com/errata/RHSA-2026:25194", + "https://access.redhat.com/errata/RHSA-2026:25206", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:26054", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27001", + "https://access.redhat.com/errata/RHSA-2026:27004", + "https://access.redhat.com/errata/RHSA-2026:27044", + "https://access.redhat.com/errata/RHSA-2026:27063", + "https://access.redhat.com/errata/RHSA-2026:27856", + "https://access.redhat.com/errata/RHSA-2026:28198", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:32991", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34099", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34794", + "https://access.redhat.com/errata/RHSA-2026:35833", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:40984", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:41944", + "https://access.redhat.com/errata/RHSA-2026:44267", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48085", + "https://access.redhat.com/errata/RHSA-2026:48676", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54602", + "https://access.redhat.com/errata/RHSA-2026:56366", + "https://access.redhat.com/errata/RHSA-2026:56431", + "https://access.redhat.com/errata/RHSA-2026:56968", + "https://access.redhat.com/errata/RHSA-2026:57013", + "https://access.redhat.com/errata/RHSA-2026:57408", + "https://access.redhat.com/errata/RHSA-2026:57487", + "https://access.redhat.com/errata/RHSA-2026:57590", + "https://access.redhat.com/errata/RHSA-2026:60023", + "https://access.redhat.com/errata/RHSA-2026:60444", + "https://access.redhat.com/errata/RHSA-2026:60449", + "https://access.redhat.com/errata/RHSA-2026:60452", + "https://access.redhat.com/errata/RHSA-2026:62260", + "https://access.redhat.com/errata/RHSA-2026:62548", + "https://access.redhat.com/errata/RHSA-2026:62550", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9388", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/security/cve/CVE-2026-34986", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2449833", + "https://bugzilla.redhat.com/2455470", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456335", + "https://bugzilla.redhat.com/2456336", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445345", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2449833", + "https://bugzilla.redhat.com/show_bug.cgi?id=2455470", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456336", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27137", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32282", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33186", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34986", + "https://errata.almalinux.org/9/ALSA-2026-19353.html", + "https://errata.rockylinux.org/RLSA-2026:23228", + "https://github.com/go-jose/go-jose", + "https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8", + "https://linux.oracle.com/cve/CVE-2026-34986.html", + "https://linux.oracle.com/errata/ELSA-2026-48790.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-34986", + "https://pkg.go.dev/github.com/go-jose/go-jose/v4#pkg-constants", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34986.json", + "https://www.cve.org/CVERecord?id=CVE-2026-34986" + ], + "PublishedDate": "2026-04-06T17:17:11.87Z", + "LastModifiedDate": "2026-09-10T13:19:46.98Z" + }, + { + "VulnerabilityID": "CVE-2026-33322", + "VendorIDs": [ + "GHSA-5cx5-wh4m-82fh" + ], + "PkgID": "github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969+dirty", + "PkgName": "github.com/minio/minio", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969%2Bdirty", + "UID": "d2024c05322957d0" + }, + "InstalledVersion": "v0.0.0-20250422221226-0d7408fc9969+dirty", + "Status": "affected", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33322", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:721ffc125c45fca671c579f4e454591013aad9d388054666a4c7f50cc663bae4", + "Title": "MinIO has JWT Algorithm Confusion in OIDC Authentication", + "Description": "MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials with any policy, including consoleAdmin. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-287" + ], + "VendorSeverity": { + "bitnami": 4, + "ghsa": 4, + "nvd": 4 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 9.2 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 9.2 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + } + }, + "References": [ + "https://github.com/minio/minio", + "https://github.com/minio/minio/security/advisories/GHSA-5cx5-wh4m-82fh", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33322" + ], + "PublishedDate": "2026-03-24T20:16:27.857Z", + "LastModifiedDate": "2026-06-17T10:37:19.35Z" + }, + { + "VulnerabilityID": "CVE-2026-33419", + "VendorIDs": [ + "GHSA-jv87-32hw-hh99" + ], + "PkgID": "github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969+dirty", + "PkgName": "github.com/minio/minio", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969%2Bdirty", + "UID": "d2024c05322957d0" + }, + "InstalledVersion": "v0.0.0-20250422221226-0d7408fc9969+dirty", + "Status": "affected", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33419", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:067b77989069ab3cda121acbe61fbb569f786a246519d418e665e355873820d2", + "Title": "MinIO LDAP login brute-force via user enumeration and missing rate limit", + "Description": "MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security Token Service) AssumeRoleWithLDAPIdentity endpoint is vulnerable to LDAP credential brute-forcing due to two combined weaknesses: (1) distinguishable error responses that enable username enumeration, and (2) absence of rate limiting on authentication attempts. An unauthenticated network attacker can enumerate valid LDAP usernames and then perform unlimited password guessing to obtain temporary AWS-style STS credentials, gaining access to the victim's S3 buckets and objects. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-204", + "CWE-307" + ], + "VendorSeverity": { + "bitnami": 4, + "ghsa": 4, + "nvd": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N", + "V40Score": 9.1 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N", + "V40Score": 9.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/minio/minio", + "https://github.com/minio/minio/security/advisories/GHSA-jv87-32hw-hh99", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33419" + ], + "PublishedDate": "2026-03-24T20:16:29.9Z", + "LastModifiedDate": "2026-06-17T10:37:27.917Z" + }, + { + "VulnerabilityID": "CVE-2025-62506", + "VendorIDs": [ + "GHSA-jjjj-jwhf-8rgr" + ], + "PkgID": "github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969+dirty", + "PkgName": "github.com/minio/minio", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969%2Bdirty", + "UID": "d2024c05322957d0" + }, + "InstalledVersion": "v0.0.0-20250422221226-0d7408fc9969+dirty", + "FixedVersion": "0.0.0-20251015170045-c1a49490c78e", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-62506", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:1e74557c803a17c975945e66ec27533edee9cf8820bd07b084e8e796bf882bdb", + "Title": "MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS", + "Description": "MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege escalation vulnerability allows service accounts and STS (Security Token Service) accounts with restricted session policies to bypass their inline policy restrictions when performing operations on their own account, specifically when creating new service accounts for the same user. The vulnerability exists in the IAM policy validation logic where the code incorrectly relied on the DenyOnly argument when validating session policies for restricted accounts. When a session policy is present, the system should validate that the action is allowed by the session policy, not just that it is not denied. An attacker with valid credentials for a restricted service or STS account can create a new service account for itself without policy restrictions, resulting in a new service account with full parent privileges instead of being restricted by the inline policy. This allows the attacker to access buckets and objects beyond their intended restrictions and modify, delete, or create objects outside their authorized scope. The vulnerability is fixed in version RELEASE.2025-10-15T17-29-55Z.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-863" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://github.com/minio/minio", + "https://github.com/minio/minio/commit/c1a49490c78e9c3ebcad86ba0662319138ace190", + "https://github.com/minio/minio/discussions/21655", + "https://github.com/minio/minio/issues/21647", + "https://github.com/minio/minio/pull/21642", + "https://github.com/minio/minio/security/advisories/GHSA-jjjj-jwhf-8rgr", + "https://news.ycombinator.com/item?id=45684035", + "https://nvd.nist.gov/vuln/detail/CVE-2025-62506" + ], + "PublishedDate": "2025-10-16T22:15:31.703Z", + "LastModifiedDate": "2026-06-17T09:52:00.233Z" + }, + { + "VulnerabilityID": "CVE-2026-34204", + "VendorIDs": [ + "GHSA-3rh2-v3gr-35p9" + ], + "PkgID": "github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969+dirty", + "PkgName": "github.com/minio/minio", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969%2Bdirty", + "UID": "d2024c05322957d0" + }, + "InstalledVersion": "v0.0.0-20250422221226-0d7408fc9969+dirty", + "Status": "affected", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-34204", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:d9e0b98c0ea6f8894c2aecfdffe57c850d58d065ea26accabe58808c3a1d7413", + "Title": "MinIO is Vulnerable to SSE Metadata Injection via Replication Headers", + "Description": "MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption metadata into objects by sending crafted X-Minio-Replication-* headers on a normal PutObject request. This issue has been patched in version RELEASE.2026-03-26T21-24-40Z.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-287" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N", + "V40Score": 7.1 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N", + "V3Score": 7.1, + "V40Score": 7.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 7.1 + } + }, + "References": [ + "https://docs.min.io/enterprise/aistor-object-store/upgrade-aistor-server/community-edition", + "https://github.com/minio/minio", + "https://github.com/minio/minio/security/advisories/GHSA-3rh2-v3gr-35p9", + "https://nvd.nist.gov/vuln/detail/CVE-2026-34204" + ], + "PublishedDate": "2026-03-31T20:16:28.583Z", + "LastModifiedDate": "2026-07-24T20:10:00.147Z" + }, + { + "VulnerabilityID": "CVE-2026-39414", + "VendorIDs": [ + "GHSA-h749-fxx7-pwpg" + ], + "PkgID": "github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969+dirty", + "PkgName": "github.com/minio/minio", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969%2Bdirty", + "UID": "d2024c05322957d0" + }, + "InstalledVersion": "v0.0.0-20250422221226-0d7408fc9969+dirty", + "Status": "affected", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39414", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:a8223bc29366f6917a21b3ede837de0dc4ac2740c3e2391bef4c9c7dfe75558a", + "Title": "MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing", + "Description": "MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, MinIO's S3 Select feature is vulnerable to memory exhaustion when processing CSV files containing lines longer than available memory. The CSV reader's nextSplit() function calls bufio.Reader.ReadBytes('\\n') with no size limit, buffering the entire input in memory until a newline is found. A CSV file with no newline characters causes the entire contents to be read into a single allocation, leading to an OOM crash of the MinIO server process. This is exploitable by any authenticated user with s3:PutObject and s3:GetObject permissions. The attack is especially practical when combined with compression: a ~2 MB gzip-compressed CSV can decompress to gigabytes of data without newlines, allowing a small upload to cause large memory consumption on the server. However, compression is not required — a sufficiently large uncompressed CSV with no newlines triggers the same issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 7.1 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 7.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://docs.min.io/enterprise/aistor-object-store/upgrade-aistor-server/community-edition", + "https://github.com/minio/minio", + "https://github.com/minio/minio/commit/7c14cdb60e53dbfdad2be644dfb180cab19fffa7", + "https://github.com/minio/minio/pull/8200", + "https://github.com/minio/minio/security/advisories/GHSA-h749-fxx7-pwpg", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39414", + "https://pkg.go.dev/vuln/GO-2026-5415?q" + ], + "PublishedDate": "2026-04-08T21:16:58.877Z", + "LastModifiedDate": "2026-07-24T21:10:00.143Z" + }, + { + "VulnerabilityID": "CVE-2026-40344", + "VendorIDs": [ + "GHSA-9c4q-hq6p-c237" + ], + "PkgID": "github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969+dirty", + "PkgName": "github.com/minio/minio", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969%2Bdirty", + "UID": "d2024c05322957d0" + }, + "InstalledVersion": "v0.0.0-20250422221226-0d7408fc9969+dirty", + "Status": "affected", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40344", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:a9e83e5bfd6819b67547e5adc5fe9c0ba5380d4cd637b6fcf29e9a96ce66ca9b", + "Title": "MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer Uploads", + "Description": "MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's Snowball auto-extract handler (`PutObjectExtractHandler`) allows any user who knows a valid access key to write arbitrary objects to any bucket without knowing the secret key or providing a valid cryptographic signature. Any MinIO deployment is impacted. The attack requires only a valid access key (the well-known default `minioadmin`, or any key with WRITE permission on a bucket) and a target bucket name. When `authTypeStreamingUnsignedTrailer` support was added, the new auth type was handled in `PutObjectHandler` and `PutObjectPartHandler` but was never added to `PutObjectExtractHandler`. The snowball auto-extract handler's `switch rAuthType` block has no case for `authTypeStreamingUnsignedTrailer`, so execution falls through with zero signature verification. The `isPutActionAllowed` call before the switch extracts the access key and checks IAM permissions, but does not verify the cryptographic signature. An attacker sends a PUT request with `X-Amz-Content-Sha256: STREAMING-UNSIGNED-PAYLOAD-TRAILER`, `X-Amz-Meta-Snowball-Auto-Extract: true`, and an `Authorization` header containing a valid access key with a completely fabricated signature. The request is accepted and the tar payload is extracted into the bucket. Users of the open-source minio/minio project should upgrade to MinIO AIStor RELEASE.2026-04-11T03-20-12Z or later. If upgrading is not immediately possible, block unsigned-trailer requests at the load balancer. Reject any request containing X-Amz-Content-Sha256: STREAMING-UNSIGNED-PAYLOAD-TRAILER at the reverse proxy or WAF layer. Clients can use STREAMING-AWS4-HMAC-SHA256-PAYLOAD-TRAILER (the signed variant) instead. Alternatively, restrict WRITE permissions. Limit s3:PutObject grants to trusted principals. While this reduces the attack surface, it does not eliminate the vulnerability since any user with WRITE permission can exploit it with only their access key.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-287", + "CWE-306" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N", + "V40Score": 8.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N", + "V3Score": 8.2, + "V40Score": 8.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L", + "V3Score": 8.2 + } + }, + "References": [ + "https://github.com/minio/minio", + "https://github.com/minio/minio/commit/76913a9fd5c6e5c2dbd4e8c7faf56ed9e9e24091", + "https://github.com/minio/minio/pull/16484", + "https://github.com/minio/minio/security/advisories/GHSA-9c4q-hq6p-c237", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40344" + ], + "PublishedDate": "2026-04-22T01:16:05.43Z", + "LastModifiedDate": "2026-06-17T10:45:09.29Z" + }, + { + "VulnerabilityID": "CVE-2026-41145", + "VendorIDs": [ + "GHSA-hv4r-mvr4-25vw" + ], + "PkgID": "github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969+dirty", + "PkgName": "github.com/minio/minio", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/minio/minio@v0.0.0-20250422221226-0d7408fc9969%2Bdirty", + "UID": "d2024c05322957d0" + }, + "InstalledVersion": "v0.0.0-20250422221226-0d7408fc9969+dirty", + "Status": "affected", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-41145", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:87478445fba04ddeaf0190df2f97f1a352980ce11305c239b7361cc97432833f", + "Title": "MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads", + "Description": "MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's `STREAMING-UNSIGNED-PAYLOAD-TRAILER` code path\nallows any user who knows a valid access key to write arbitrary objects to any bucket without knowing the secret key or providing a valid cryptographic signature. Any MinIO deployment is impacted. The attack requires only a valid access key (the well-known default `minioadmin`, or any key with WRITE permission on a bucket) and a target bucket name. `PutObjectHandler` and `PutObjectPartHandler` call `newUnsignedV4ChunkedReader` with a signature verification gate based solely on the presence of the `Authorization` header. Meanwhile, `isPutActionAllowed` extracts credentials from either the `Authorization` header or the\n`X-Amz-Credential` query parameter, and trusts whichever it finds. An attacker omits the `Authorization` header and supplies credentials exclusively via the query string. The signature gate evaluates to `false`, `doesSignatureMatch` is never called, and the request proceeds with the permissions of the impersonated access key. This affects `PutObjectHandler` (standard and tables/warehouse bucket paths) and `PutObjectPartHandler` (multipart uploads). Users of the open-source `minio/minio` project should upgrade to MinIO AIStor `RELEASE.2026-04-11T03-20-12Z` or later. If upgrading is not immediately possible, block unsigned-trailer requests at the load balancer. Reject any request containing `X-Amz-Content-Sha256: STREAMING-UNSIGNED-PAYLOAD-TRAILER` at the reverse proxy or WAF layer. Clients can use `STREAMING-AWS4-HMAC-SHA256-PAYLOAD-TRAILER` (the signed variant) instead. Alternatively, restrict WRITE permissions. Limit `s3:PutObject` grants to trusted principals. While this reduces the attack surface, it does not eliminate the vulnerability since any user with WRITE permission can exploit it with only their access key.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-287" + ], + "VendorSeverity": { + "bitnami": 3, + "ghsa": 3, + "nvd": 3 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N", + "V40Score": 8.8 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L", + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N", + "V3Score": 8.2, + "V40Score": 8.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L", + "V3Score": 8.2 + } + }, + "References": [ + "https://github.com/minio/minio", + "https://github.com/minio/minio/commit/76913a9fd5c6e5c2dbd4e8c7faf56ed9e9e24091", + "https://github.com/minio/minio/pull/16484", + "https://github.com/minio/minio/security/advisories/GHSA-hv4r-mvr4-25vw", + "https://nvd.nist.gov/vuln/detail/CVE-2026-41145" + ], + "PublishedDate": "2026-04-22T01:16:05.603Z", + "LastModifiedDate": "2026-06-17T10:46:14.033Z" + }, + { + "VulnerabilityID": "CVE-2026-42151", + "VendorIDs": [ + "GHSA-wg65-39gg-5wfj" + ], + "PkgID": "github.com/prometheus/prometheus@v0.303.0", + "PkgName": "github.com/prometheus/prometheus", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/prometheus/prometheus@v0.303.0", + "UID": "e731b806e3c9c0d4" + }, + "InstalledVersion": "v0.303.0", + "FixedVersion": "0.311.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42151", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:b7e07a7b288c277a16dc0b43f3df9b4abf0df33706cf91d867e5beb543671d62", + "Title": "github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API", + "Description": "Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-200", + "CWE-312", + "CWE-256" + ], + "VendorSeverity": { + "alma": 3, + "azure": 2, + "bitnami": 3, + "ghsa": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:25039", + "https://access.redhat.com/errata/RHSA-2026:25245", + "https://access.redhat.com/errata/RHSA-2026:25504", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:37267", + "https://access.redhat.com/errata/RHSA-2026:37271", + "https://access.redhat.com/errata/RHSA-2026:37272", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40768", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40970", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:40974", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:50874", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54288", + "https://access.redhat.com/errata/RHSA-2026:54427", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:60386", + "https://access.redhat.com/errata/RHSA-2026:60387", + "https://access.redhat.com/errata/RHSA-2026:60388", + "https://access.redhat.com/errata/RHSA-2026:60389", + "https://access.redhat.com/errata/RHSA-2026:60390", + "https://access.redhat.com/errata/RHSA-2026:60391", + "https://access.redhat.com/errata/RHSA-2026:60441", + "https://access.redhat.com/errata/RHSA-2026:60477", + "https://access.redhat.com/errata/RHSA-2026:63103", + "https://access.redhat.com/security/cve/CVE-2026-42151", + "https://bugzilla.redhat.com/2466505", + "https://bugzilla.redhat.com/2466507", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/2480761", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2466505", + "https://bugzilla.redhat.com/show_bug.cgi?id=2466507", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480761", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42151", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42154", + "https://errata.almalinux.org/9/ALSA-2026-34359.html", + "https://errata.rockylinux.org/RLSA-2026:34359", + "https://github.com/prometheus/prometheus", + "https://github.com/prometheus/prometheus/pull/18587", + "https://github.com/prometheus/prometheus/pull/18590", + "https://github.com/prometheus/prometheus/releases/tag/v3.11.3", + "https://github.com/prometheus/prometheus/releases/tag/v3.5.3", + "https://github.com/prometheus/prometheus/security/advisories/GHSA-wg65-39gg-5wfj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42151", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42151.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42151" + ], + "PublishedDate": "2026-05-04T19:16:04.22Z", + "LastModifiedDate": "2026-09-10T13:20:06.057Z" + }, + { + "VulnerabilityID": "CVE-2026-42154", + "VendorIDs": [ + "GHSA-8rm2-7qqf-34qm" + ], + "PkgID": "github.com/prometheus/prometheus@v0.303.0", + "PkgName": "github.com/prometheus/prometheus", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/prometheus/prometheus@v0.303.0", + "UID": "e731b806e3c9c0d4" + }, + "InstalledVersion": "v0.303.0", + "FixedVersion": "0.311.3, 0.305.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42154", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:cab35dd790d3b257f8cf968066024b2b9f5cfd29760dd0813d200a489735ffc6", + "Title": "github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint", + "Description": "Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400", + "CWE-789", + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "bitnami": 3, + "ghsa": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:25039", + "https://access.redhat.com/errata/RHSA-2026:25245", + "https://access.redhat.com/errata/RHSA-2026:29770", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34794", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40792", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40970", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:40974", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:44235", + "https://access.redhat.com/errata/RHSA-2026:44263", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47728", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48699", + "https://access.redhat.com/errata/RHSA-2026:50758", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54288", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60386", + "https://access.redhat.com/security/cve/CVE-2026-42154", + "https://bugzilla.redhat.com/2466505", + "https://bugzilla.redhat.com/2466507", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/2480761", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2466505", + "https://bugzilla.redhat.com/show_bug.cgi?id=2466507", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480761", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42151", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42154", + "https://errata.almalinux.org/9/ALSA-2026-34359.html", + "https://errata.rockylinux.org/RLSA-2026:34359", + "https://github.com/prometheus/prometheus", + "https://github.com/prometheus/prometheus/pull/18584", + "https://github.com/prometheus/prometheus/pull/18585", + "https://github.com/prometheus/prometheus/releases/tag/v3.11.3", + "https://github.com/prometheus/prometheus/releases/tag/v3.5.3", + "https://github.com/prometheus/prometheus/security/advisories/GHSA-8rm2-7qqf-34qm", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42154", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42154.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42154" + ], + "PublishedDate": "2026-05-04T19:16:04.397Z", + "LastModifiedDate": "2026-09-10T13:20:07.003Z" + }, + { + "VulnerabilityID": "CVE-2026-79921", + "VendorIDs": [ + "GHSA-6c5v-hqjr-5xxp" + ], + "PkgID": "github.com/rabbitmq/amqp091-go@v1.10.0", + "PkgName": "github.com/rabbitmq/amqp091-go", + "PkgIdentifier": { + "PURL": "pkg:golang/github.com/rabbitmq/amqp091-go@v1.10.0", + "UID": "27d4991559d475bf" + }, + "InstalledVersion": "v1.10.0", + "FixedVersion": "1.13.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-79921", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:f519281595ba43f51ad5a0ef2cffe56cb8458a475bcbc3eb4b10534bb651039b", + "Title": "github.com/rabbitmq/amqp091-go: amqp091-go: Denial of Service via oversized AMQP payloads", + "Description": "amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "azure": 3, + "ghsa": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H", + "V40Score": 8.9 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-79921", + "https://github.com/rabbitmq/amqp091-go", + "https://github.com/rabbitmq/amqp091-go/commit/6beb7b51f59e46ddcf8066ad498dad32491d3be0", + "https://github.com/rabbitmq/amqp091-go/pull/353", + "https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0", + "https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-6c5v-hqjr-5xxp", + "https://nvd.nist.gov/vuln/detail/CVE-2026-79921", + "https://www.cve.org/CVERecord?id=CVE-2026-79921" + ], + "PublishedDate": "2026-08-26T21:16:41.873Z", + "LastModifiedDate": "2026-09-09T21:09:13.08Z" + }, + { + "VulnerabilityID": "CVE-2026-24051", + "VendorIDs": [ + "GHSA-9h8m-3fm2-qjrq" + ], + "PkgID": "go.opentelemetry.io/otel/sdk@v1.35.0", + "PkgName": "go.opentelemetry.io/otel/sdk", + "PkgIdentifier": { + "PURL": "pkg:golang/go.opentelemetry.io/otel/sdk@v1.35.0", + "UID": "4b6910fdc62a06b5" + }, + "InstalledVersion": "v1.35.0", + "FixedVersion": "1.40.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-24051", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:519ed2e9199ce6e2dee6d6b2e69d2b4426c24c1ca7401bd3feaf990d80e6c405", + "Title": "opentelemetry-go: OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking", + "Description": "OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-426" + ], + "VendorSeverity": { + "ghsa": 3, + "redhat": 1 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-24051", + "https://github.com/open-telemetry/opentelemetry-go", + "https://github.com/open-telemetry/opentelemetry-go/commit/d45961bcda453fcbdb6469c22d6e88a1f9970a53", + "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-9h8m-3fm2-qjrq", + "https://nvd.nist.gov/vuln/detail/CVE-2026-24051", + "https://pkg.go.dev/vuln/GO-2026-4394", + "https://www.cve.org/CVERecord?id=CVE-2026-24051" + ], + "PublishedDate": "2026-02-02T23:16:07.963Z", + "LastModifiedDate": "2026-06-17T10:22:31.507Z" + }, + { + "VulnerabilityID": "CVE-2026-39883", + "VendorIDs": [ + "GHSA-hfvc-g4fc-pqhx" + ], + "PkgID": "go.opentelemetry.io/otel/sdk@v1.35.0", + "PkgName": "go.opentelemetry.io/otel/sdk", + "PkgIdentifier": { + "PURL": "pkg:golang/go.opentelemetry.io/otel/sdk@v1.35.0", + "UID": "4b6910fdc62a06b5" + }, + "InstalledVersion": "v1.35.0", + "FixedVersion": "1.43.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39883", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:a407dc7ea24cfaceca21190a2a027cb5fd0e7930c9e784f975bf324199446447", + "Title": "github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris", + "Description": "OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-426" + ], + "VendorSeverity": { + "ghsa": 3, + "nvd": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 7.3 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "http://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.43.0", + "https://access.redhat.com/errata/RHSA-2026:26254", + "https://access.redhat.com/errata/RHSA-2026:26257", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:63140", + "https://access.redhat.com/security/cve/CVE-2026-39883", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456718", + "https://github.com/open-telemetry/opentelemetry-go", + "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hfvc-g4fc-pqhx", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39883", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39883.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39883" + ], + "PublishedDate": "2026-04-08T21:17:00.697Z", + "LastModifiedDate": "2026-09-09T13:19:48.837Z" + }, + { + "VulnerabilityID": "CVE-2025-47913", + "VendorIDs": [ + "GO-2025-4116" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "114f8a84bd734d66" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.43.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47913", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c6fc23876910423e3690ce46f7adb4773de7f8098f8c52b40e7562b780871a39", + "Title": "golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS", + "Description": "SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-617" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "cbl-mariner": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:0470", + "https://access.redhat.com/security/cve/CVE-2025-47913", + "https://bugzilla.redhat.com/2414943", + "https://bugzilla.redhat.com/show_bug.cgi?id=2414943", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47913", + "https://errata.almalinux.org/9/ALSA-2026-0470.html", + "https://errata.rockylinux.org/RLSA-2026:0470", + "https://github.com/advisories/GHSA-56w8-48fp-6mgv", + "https://github.com/advisories/GHSA-hcg3-q754-cr77", + "https://go-review.googlesource.com/c/crypto/+/700295", + "https://go.dev/cl/700295", + "https://go.dev/issue/75178", + "https://linux.oracle.com/cve/CVE-2025-47913.html", + "https://linux.oracle.com/errata/ELSA-2026-0753.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47913", + "https://pkg.go.dev/vuln/GO-2025-4116", + "https://ubuntu.com/security/notices/USN-8519-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47913" + ], + "PublishedDate": "2025-11-13T22:15:51.28Z", + "LastModifiedDate": "2026-06-17T09:28:50.357Z" + }, + { + "VulnerabilityID": "CVE-2026-39828", + "VendorIDs": [ + "GO-2026-5014" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "114f8a84bd734d66" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39828", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:bbd10eb2c8c0b32f97d2323a6e61f7574c9616e85f1b4aee2ea1da141fd794fa", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions", + "Description": "When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295", + "CWE-281" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 2, + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:37268", + "https://access.redhat.com/errata/RHSA-2026:37271", + "https://access.redhat.com/errata/RHSA-2026:37272", + "https://access.redhat.com/errata/RHSA-2026:37278", + "https://access.redhat.com/errata/RHSA-2026:37286", + "https://access.redhat.com/errata/RHSA-2026:37296", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40969", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:40974", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51038", + "https://access.redhat.com/errata/RHSA-2026:52857", + "https://access.redhat.com/errata/RHSA-2026:52910", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66521", + "https://access.redhat.com/security/cve/CVE-2026-39828", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480687", + "https://go.dev/cl/781621", + "https://go.dev/issue/79562", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39828", + "https://pkg.go.dev/vuln/GO-2026-5014", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39828.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39828" + ], + "PublishedDate": "2026-05-22T04:16:22.19Z", + "LastModifiedDate": "2026-09-11T13:17:51.26Z" + }, + { + "VulnerabilityID": "CVE-2026-39829", + "VendorIDs": [ + "GO-2026-5018" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "114f8a84bd734d66" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39829", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:84bdd4e0f1f9029fd2427a115d6cf526ec4eed081a1469818b9b88e4f2c54a69", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters", + "Description": "The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-347", + "CWE-1284" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:35833", + "https://access.redhat.com/errata/RHSA-2026:36199", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37072", + "https://access.redhat.com/errata/RHSA-2026:37123", + "https://access.redhat.com/errata/RHSA-2026:37268", + "https://access.redhat.com/errata/RHSA-2026:37271", + "https://access.redhat.com/errata/RHSA-2026:37272", + "https://access.redhat.com/errata/RHSA-2026:37278", + "https://access.redhat.com/errata/RHSA-2026:37286", + "https://access.redhat.com/errata/RHSA-2026:37296", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40969", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:40974", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47949", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:48693", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:52857", + "https://access.redhat.com/errata/RHSA-2026:52910", + "https://access.redhat.com/errata/RHSA-2026:54400", + "https://access.redhat.com/errata/RHSA-2026:54432", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57365", + "https://access.redhat.com/errata/RHSA-2026:57801", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59559", + "https://access.redhat.com/errata/RHSA-2026:59593", + "https://access.redhat.com/errata/RHSA-2026:60446", + "https://access.redhat.com/errata/RHSA-2026:60454", + "https://access.redhat.com/errata/RHSA-2026:60477", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65964", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/security/cve/CVE-2026-39829", + "https://bugzilla.redhat.com/2480680", + "https://bugzilla.redhat.com/2480681", + "https://bugzilla.redhat.com/2480685", + "https://bugzilla.redhat.com/2480688", + "https://bugzilla.redhat.com/2480757", + "https://bugzilla.redhat.com/2480761", + "https://bugzilla.redhat.com/2493620", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480680", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480681", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480685", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480688", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480757", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480761", + "https://bugzilla.redhat.com/show_bug.cgi?id=2493620", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42508", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57231", + "https://errata.almalinux.org/9/ALSA-2026-37123.html", + "https://errata.rockylinux.org/RLSA-2026:37123", + "https://go.dev/cl/781641", + "https://go.dev/cl/781661", + "https://go.dev/issue/79565", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://linux.oracle.com/cve/CVE-2026-39829.html", + "https://linux.oracle.com/errata/ELSA-2026-37123.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39829", + "https://pkg.go.dev/vuln/GO-2026-5018", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39829.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39829" + ], + "PublishedDate": "2026-05-22T04:16:22.31Z", + "LastModifiedDate": "2026-09-11T13:17:52.607Z" + }, + { + "VulnerabilityID": "CVE-2026-39830", + "VendorIDs": [ + "GO-2026-5017" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "114f8a84bd734d66" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39830", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d3df68ce0d293a7685949e08f0c04cad346fdf6e4abc4c1bb62e63203b5f37d7", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses", + "Description": "A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-119", + "CWE-772" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:35833", + "https://access.redhat.com/errata/RHSA-2026:36199", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:37072", + "https://access.redhat.com/errata/RHSA-2026:37268", + "https://access.redhat.com/errata/RHSA-2026:37271", + "https://access.redhat.com/errata/RHSA-2026:37272", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:37278", + "https://access.redhat.com/errata/RHSA-2026:37286", + "https://access.redhat.com/errata/RHSA-2026:37296", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40969", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:40974", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:52857", + "https://access.redhat.com/errata/RHSA-2026:52910", + "https://access.redhat.com/errata/RHSA-2026:54400", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57801", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:65964", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66521", + "https://access.redhat.com/security/cve/CVE-2026-39830", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/2480681", + "https://bugzilla.redhat.com/2480684", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480681", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480684", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39830", + "https://errata.almalinux.org/9/ALSA-2026-29455.html", + "https://errata.rockylinux.org/RLSA-2026:29455", + "https://github.com/golang/crypto/commit/4e7a7384ecbc8d519f6f4c11b36fa9d761fc8946", + "https://go.dev/cl/781640", + "https://go.dev/cl/781664", + "https://go.dev/issue/79564", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://linux.oracle.com/cve/CVE-2026-39830.html", + "https://linux.oracle.com/errata/ELSA-2026-37072.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39830", + "https://pkg.go.dev/vuln/GO-2026-5017", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39830.json", + "https://ubuntu.com/security/notices/USN-8447-1", + "https://ubuntu.com/security/notices/USN-8447-2", + "https://ubuntu.com/security/notices/USN-8447-3", + "https://www.cve.org/CVERecord?id=CVE-2026-39830" + ], + "PublishedDate": "2026-05-22T04:16:22.44Z", + "LastModifiedDate": "2026-09-11T13:17:53.97Z" + }, + { + "VulnerabilityID": "CVE-2026-39831", + "VendorIDs": [ + "GO-2026-5019" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "114f8a84bd734d66" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39831", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ffb583a099b127297797e71ad29f459a7ab42423a053d372936b89705fd57f45", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check", + "Description": "The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a \"no-touch-required\" extension in Permissions.Extensions from PublicKeyCallback.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-862" + ], + "VendorSeverity": { + "amazon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-39831", + "https://github.com/golang/crypto/commit/b61cf853a89d82cad68da5e12a6beca2116f8456", + "https://go.dev/cl/781662", + "https://go.dev/issue/79566", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39831", + "https://pkg.go.dev/vuln/GO-2026-5019", + "https://ubuntu.com/security/notices/USN-8447-1", + "https://ubuntu.com/security/notices/USN-8447-3", + "https://www.cve.org/CVERecord?id=CVE-2026-39831" + ], + "PublishedDate": "2026-05-22T04:16:22.553Z", + "LastModifiedDate": "2026-07-23T16:10:00.137Z" + }, + { + "VulnerabilityID": "CVE-2026-39832", + "VendorIDs": [ + "GHSA-f5wc-c3c7-36mc", + "GO-2026-5006" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "114f8a84bd734d66" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39832", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:99a80f14527b9c66cbc889038bc7bd29a9181059b6b7556ed6c722b445b9eb36", + "Title": "golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions", + "Description": "When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-502", + "CWE-281" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N", + "V3Score": 8.7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:35833", + "https://access.redhat.com/errata/RHSA-2026:36199", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:37072", + "https://access.redhat.com/errata/RHSA-2026:37123", + "https://access.redhat.com/errata/RHSA-2026:37271", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37410", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:52857", + "https://access.redhat.com/errata/RHSA-2026:52910", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:59579", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:66521", + "https://access.redhat.com/security/cve/CVE-2026-39832", + "https://bugzilla.redhat.com/2480680", + "https://bugzilla.redhat.com/2480685", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480680", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480685", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835", + "https://errata.almalinux.org/9/ALSA-2026-37410.html", + "https://errata.rockylinux.org/RLSA-2026:37410", + "https://github.com/golang/crypto/commit/e3d1254f1e7e60baa086142c46174bf6d8d0fe50", + "https://go.dev/cl/778640", + "https://go.dev/cl/778641", + "https://go.dev/cl/778642", + "https://go.dev/issue/79435", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://linux.oracle.com/cve/CVE-2026-39832.html", + "https://linux.oracle.com/errata/ELSA-2026-37410.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39832", + "https://pkg.go.dev/vuln/GO-2026-5006", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json", + "https://ubuntu.com/security/notices/USN-8447-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39832" + ], + "PublishedDate": "2026-05-22T04:16:22.663Z", + "LastModifiedDate": "2026-09-11T13:17:55.683Z" + }, + { + "VulnerabilityID": "CVE-2026-39835", + "VendorIDs": [ + "GO-2026-5015" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "114f8a84bd734d66" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39835", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c058329e2c46ab52d47bf9557fc048b156efd6f2162a464e5a621599f7942a7d", + "Title": "golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate", + "Description": "SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295", + "CWE-476" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:36199", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:37072", + "https://access.redhat.com/errata/RHSA-2026:37123", + "https://access.redhat.com/errata/RHSA-2026:37268", + "https://access.redhat.com/errata/RHSA-2026:37271", + "https://access.redhat.com/errata/RHSA-2026:37272", + "https://access.redhat.com/errata/RHSA-2026:37286", + "https://access.redhat.com/errata/RHSA-2026:37296", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37410", + "https://access.redhat.com/errata/RHSA-2026:38504", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40969", + "https://access.redhat.com/errata/RHSA-2026:40972", + "https://access.redhat.com/errata/RHSA-2026:40974", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47949", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51036", + "https://access.redhat.com/errata/RHSA-2026:51038", + "https://access.redhat.com/errata/RHSA-2026:52857", + "https://access.redhat.com/errata/RHSA-2026:52910", + "https://access.redhat.com/errata/RHSA-2026:54525", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59593", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:62260", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66521", + "https://access.redhat.com/security/cve/CVE-2026-39835", + "https://bugzilla.redhat.com/2480680", + "https://bugzilla.redhat.com/2480685", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480680", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480685", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835", + "https://errata.almalinux.org/9/ALSA-2026-37410.html", + "https://errata.rockylinux.org/RLSA-2026:37410", + "https://go.dev/cl/781660", + "https://go.dev/issue/79563", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://linux.oracle.com/cve/CVE-2026-39835.html", + "https://linux.oracle.com/errata/ELSA-2026-38504.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39835", + "https://pkg.go.dev/vuln/GO-2026-5015", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39835.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39835" + ], + "PublishedDate": "2026-05-22T04:16:24.53Z", + "LastModifiedDate": "2026-09-11T13:17:56.5Z" + }, + { + "VulnerabilityID": "CVE-2026-42508", + "VendorIDs": [ + "GHSA-5cgq-3rg8-m6cv", + "GO-2026-5021" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "114f8a84bd734d66" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42508", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:bfcf54375e3048d0fce51aff51fe5a2a5c35425fd58fb17894d5319d2e8559db", + "Title": "golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey", + "Description": "Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:35833", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:37072", + "https://access.redhat.com/errata/RHSA-2026:37123", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41064", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:52857", + "https://access.redhat.com/errata/RHSA-2026:52910", + "https://access.redhat.com/errata/RHSA-2026:54400", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66521", + "https://access.redhat.com/security/cve/CVE-2026-42508", + "https://bugzilla.redhat.com/2480680", + "https://bugzilla.redhat.com/2480681", + "https://bugzilla.redhat.com/2480685", + "https://bugzilla.redhat.com/2480688", + "https://bugzilla.redhat.com/2480757", + "https://bugzilla.redhat.com/2480761", + "https://bugzilla.redhat.com/2493620", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480680", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480681", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480685", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480688", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480757", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480761", + "https://bugzilla.redhat.com/show_bug.cgi?id=2493620", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42508", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57231", + "https://errata.almalinux.org/9/ALSA-2026-37123.html", + "https://errata.rockylinux.org/RLSA-2026:37123", + "https://github.com/golang/crypto/commit/f717e29698a271c548239ed56bf5dd9516d6f7e8", + "https://go.dev/cl/781220", + "https://go.dev/issue/79568", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://linux.oracle.com/cve/CVE-2026-42508.html", + "https://linux.oracle.com/errata/ELSA-2026-37123.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42508", + "https://pkg.go.dev/vuln/GO-2026-5021", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json", + "https://ubuntu.com/security/notices/USN-8447-1", + "https://ubuntu.com/security/notices/USN-8447-2", + "https://www.cve.org/CVERecord?id=CVE-2026-42508" + ], + "PublishedDate": "2026-05-22T04:16:25.44Z", + "LastModifiedDate": "2026-09-11T13:18:00.947Z" + }, + { + "VulnerabilityID": "CVE-2026-46595", + "VendorIDs": [ + "GO-2026-5023" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "114f8a84bd734d66" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-46595", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:2fbc89015ea1af58b586f04743cbbbc6fbd7d31fabfb315ee9c81e96f98c5eed", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation", + "Description": "Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-863", + "CWE-303" + ], + "VendorSeverity": { + "amazon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59558", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66521", + "https://access.redhat.com/security/cve/CVE-2026-46595", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480689", + "https://github.com/golang/crypto/commit/533fb3f7e4a5ae23f69d1837cd851d35ff5b76ce", + "https://go.dev/cl/781642", + "https://go.dev/issue/79570", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-46595", + "https://pkg.go.dev/vuln/GO-2026-5023", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json", + "https://ubuntu.com/security/notices/USN-8447-1", + "https://ubuntu.com/security/notices/USN-8447-3", + "https://www.cve.org/CVERecord?id=CVE-2026-46595" + ], + "PublishedDate": "2026-05-22T04:16:25.55Z", + "LastModifiedDate": "2026-09-11T13:18:12.367Z" + }, + { + "VulnerabilityID": "CVE-2026-46597", + "VendorIDs": [ + "GO-2026-5013" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "114f8a84bd734d66" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.52.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-46597", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:856cf92d10455f0a28528c66150d8fe6d1471df33228619089d6ddb4524c23fe", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs", + "Description": "An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-704" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 3, + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-46597", + "https://go.dev/cl/781620", + "https://go.dev/issue/79561", + "https://groups.google.com/g/golang-announce/c/a082jnz-LvI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-46597", + "https://pkg.go.dev/vuln/GO-2026-5013", + "https://www.cve.org/CVERecord?id=CVE-2026-46597" + ], + "PublishedDate": "2026-05-22T04:16:26.003Z", + "LastModifiedDate": "2026-07-23T16:10:00.137Z" + }, + { + "VulnerabilityID": "CVE-2026-56854", + "VendorIDs": [ + "GO-2026-6303" + ], + "PkgID": "golang.org/x/crypto@v0.37.0", + "PkgName": "golang.org/x/crypto", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/crypto@v0.37.0", + "UID": "114f8a84bd734d66" + }, + "InstalledVersion": "v0.37.0", + "FixedVersion": "0.55.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56854", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:896fc47aff7be3d792e08cdfb0a22f9d896d5f387e0970a53017002ae0df20b5", + "Title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions", + "Description": "The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-863" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 6.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56854", + "https://go.dev/cl/797040", + "https://go.dev/issue/80213", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56854", + "https://pkg.go.dev/vuln/GO-2026-6303", + "https://www.cve.org/CVERecord?id=CVE-2026-56854" + ], + "PublishedDate": "2026-08-28T16:18:17.607Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-25681", + "VendorIDs": [ + "GO-2026-5029" + ], + "PkgID": "golang.org/x/net@v0.39.0", + "PkgName": "golang.org/x/net", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/net@v0.39.0", + "UID": "6d6810bfd2c03190" + }, + "InstalledVersion": "v0.39.0", + "FixedVersion": "0.55.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25681", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:dda41443a7bf6f888ed161344253da370f63656f64a427bd55bbdf9ae2618f17", + "Title": "golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting", + "Description": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1021" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:37123", + "https://access.redhat.com/security/cve/CVE-2026-25681", + "https://bugzilla.redhat.com/2480680", + "https://bugzilla.redhat.com/2480681", + "https://bugzilla.redhat.com/2480685", + "https://bugzilla.redhat.com/2480688", + "https://bugzilla.redhat.com/2480757", + "https://bugzilla.redhat.com/2480761", + "https://bugzilla.redhat.com/2493620", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480680", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480681", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480685", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480688", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480757", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480761", + "https://bugzilla.redhat.com/show_bug.cgi?id=2493620", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42508", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57231", + "https://errata.almalinux.org/9/ALSA-2026-37123.html", + "https://errata.rockylinux.org/RLSA-2026:37123", + "https://go.dev/cl/781703", + "https://go.dev/issue/79574", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-25681.html", + "https://linux.oracle.com/errata/ELSA-2026-37123.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25681", + "https://pkg.go.dev/vuln/GO-2026-5029", + "https://www.cve.org/CVERecord?id=CVE-2026-25681" + ], + "PublishedDate": "2026-05-22T16:16:19.863Z", + "LastModifiedDate": "2026-07-23T16:10:00.137Z" + }, + { + "VulnerabilityID": "CVE-2026-27136", + "VendorIDs": [ + "GO-2026-5030" + ], + "PkgID": "golang.org/x/net@v0.39.0", + "PkgName": "golang.org/x/net", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/net@v0.39.0", + "UID": "6d6810bfd2c03190" + }, + "InstalledVersion": "v0.39.0", + "FixedVersion": "0.55.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27136", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:708cc0d375da7acf5b759163d76eef5a44b3b3a58ec1c60e0d9da5a9c2147d90", + "Title": "golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass", + "Description": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1021" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 2, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:37123", + "https://access.redhat.com/security/cve/CVE-2026-27136", + "https://bugzilla.redhat.com/2480680", + "https://bugzilla.redhat.com/2480681", + "https://bugzilla.redhat.com/2480685", + "https://bugzilla.redhat.com/2480688", + "https://bugzilla.redhat.com/2480757", + "https://bugzilla.redhat.com/2480761", + "https://bugzilla.redhat.com/2493620", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480680", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480681", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480685", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480688", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480757", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480761", + "https://bugzilla.redhat.com/show_bug.cgi?id=2493620", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25681", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27136", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39829", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39832", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39835", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42508", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57231", + "https://errata.almalinux.org/9/ALSA-2026-37123.html", + "https://errata.rockylinux.org/RLSA-2026:37123", + "https://go.dev/cl/781685", + "https://go.dev/issue/79575", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-27136.html", + "https://linux.oracle.com/errata/ELSA-2026-37123.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27136", + "https://pkg.go.dev/vuln/GO-2026-5030", + "https://www.cve.org/CVERecord?id=CVE-2026-27136" + ], + "PublishedDate": "2026-05-22T16:16:20.087Z", + "LastModifiedDate": "2026-07-23T16:10:00.137Z" + }, + { + "VulnerabilityID": "CVE-2026-33814", + "VendorIDs": [ + "GO-2026-4918" + ], + "PkgID": "golang.org/x/net@v0.39.0", + "PkgName": "golang.org/x/net", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/net@v0.39.0", + "UID": "6d6810bfd2c03190" + }, + "InstalledVersion": "v0.39.0", + "FixedVersion": "0.53.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:47ea2e458e2bb3d349f8854ac4e966db89606692296c05e752c646f53a8d92a9", + "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", + "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57365", + "https://access.redhat.com/errata/RHSA-2026:57367", + "https://access.redhat.com/errata/RHSA-2026:57408", + "https://access.redhat.com/errata/RHSA-2026:57545", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60023", + "https://access.redhat.com/errata/RHSA-2026:60025", + "https://access.redhat.com/errata/RHSA-2026:60441", + "https://access.redhat.com/errata/RHSA-2026:60442", + "https://access.redhat.com/errata/RHSA-2026:60446", + "https://access.redhat.com/errata/RHSA-2026:60447", + "https://access.redhat.com/errata/RHSA-2026:60454", + "https://access.redhat.com/errata/RHSA-2026:60477", + "https://access.redhat.com/errata/RHSA-2026:60478", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:60668", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62550", + "https://access.redhat.com/errata/RHSA-2026:62551", + "https://access.redhat.com/errata/RHSA-2026:63046", + "https://access.redhat.com/errata/RHSA-2026:63047", + "https://access.redhat.com/errata/RHSA-2026:63048", + "https://access.redhat.com/errata/RHSA-2026:63050", + "https://access.redhat.com/errata/RHSA-2026:63091", + "https://access.redhat.com/errata/RHSA-2026:63096", + "https://access.redhat.com/errata/RHSA-2026:63097", + "https://access.redhat.com/errata/RHSA-2026:63103", + "https://access.redhat.com/errata/RHSA-2026:63104", + "https://access.redhat.com/errata/RHSA-2026:63636", + "https://access.redhat.com/errata/RHSA-2026:63637", + "https://access.redhat.com/errata/RHSA-2026:63639", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/security/cve/CVE-2026-33814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467810", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467811", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467813", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467823", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467825", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467826", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467827", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501", + "https://errata.rockylinux.org/RLSA-2026:22121", + "https://github.com/golang/go/issues/78476", + "https://go-review.googlesource.com/c/go/+/761581", + "https://go-review.googlesource.com/c/net/+/761640", + "https://go.dev/cl/761581", + "https://go.dev/cl/761640", + "https://go.dev/issue/78476", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33814.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", + "https://pkg.go.dev/vuln/GO-2026-4918", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", + "https://ubuntu.com/security/notices/USN-8430-1", + "https://ubuntu.com/security/notices/USN-8471-1", + "https://ubuntu.com/security/notices/USN-8472-1", + "https://ubuntu.com/security/notices/USN-8473-1", + "https://www.cve.org/CVERecord?id=CVE-2026-33814" + ], + "PublishedDate": "2026-05-07T20:16:42.88Z", + "LastModifiedDate": "2026-09-10T13:18:21.31Z" + }, + { + "VulnerabilityID": "CVE-2026-39821", + "VendorIDs": [ + "GO-2026-5026" + ], + "PkgID": "golang.org/x/net@v0.39.0", + "PkgName": "golang.org/x/net", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/net@v0.39.0", + "UID": "6d6810bfd2c03190" + }, + "InstalledVersion": "v0.39.0", + "FixedVersion": "0.55.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:8e2ca7b2aa6f3ce4aee5983e88b8e9ff249575420748d98491b5df7848d4b385", + "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", + "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1289" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:30853", + "https://access.redhat.com/errata/RHSA-2026:30854", + "https://access.redhat.com/errata/RHSA-2026:30855", + "https://access.redhat.com/errata/RHSA-2026:33155", + "https://access.redhat.com/errata/RHSA-2026:33160", + "https://access.redhat.com/errata/RHSA-2026:33163", + "https://access.redhat.com/errata/RHSA-2026:33173", + "https://access.redhat.com/errata/RHSA-2026:33183", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34789", + "https://access.redhat.com/errata/RHSA-2026:35826", + "https://access.redhat.com/errata/RHSA-2026:35827", + "https://access.redhat.com/errata/RHSA-2026:35828", + "https://access.redhat.com/errata/RHSA-2026:35829", + "https://access.redhat.com/errata/RHSA-2026:35830", + "https://access.redhat.com/errata/RHSA-2026:35831", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37435", + "https://access.redhat.com/errata/RHSA-2026:37436", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:44624", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:52826", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54395", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54580", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56143", + "https://access.redhat.com/errata/RHSA-2026:56223", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56431", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57541", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:59546", + "https://access.redhat.com/errata/RHSA-2026:59549", + "https://access.redhat.com/errata/RHSA-2026:59562", + "https://access.redhat.com/errata/RHSA-2026:60315", + "https://access.redhat.com/errata/RHSA-2026:60354", + "https://access.redhat.com/errata/RHSA-2026:60387", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61245", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62549", + "https://access.redhat.com/errata/RHSA-2026:63134", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65153", + "https://access.redhat.com/errata/RHSA-2026:65359", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:66016", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66432", + "https://access.redhat.com/security/cve/CVE-2026-39821", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-37435.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://github.com/golang/go/issues/78760", + "https://go.dev/cl/767220", + "https://go.dev/issue/78760", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-39821.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", + "https://pkg.go.dev/vuln/GO-2026-5026", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", + "https://ubuntu.com/security/notices/USN-8416-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39821" + ], + "PublishedDate": "2026-05-22T16:16:20.41Z", + "LastModifiedDate": "2026-09-11T13:17:49.237Z" + }, + { + "VulnerabilityID": "CVE-2026-46600", + "VendorIDs": [ + "GO-2026-5942" + ], + "PkgID": "golang.org/x/net@v0.39.0", + "PkgName": "golang.org/x/net", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/net@v0.39.0", + "UID": "6d6810bfd2c03190" + }, + "InstalledVersion": "v0.39.0", + "FixedVersion": "0.56.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-46600", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:07cfa20cd0d6635d5f20bd59b62c754dd593ec88aae29405be7e7b709ba2adcd", + "Title": "golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing", + "Description": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-125" + ], + "VendorSeverity": { + "azure": 2, + "bitnami": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-46600", + "https://go.dev/cl/786345", + "https://go.dev/issue/79795", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://nvd.nist.gov/vuln/detail/CVE-2026-46600", + "https://pkg.go.dev/vuln/GO-2026-5942", + "https://www.cve.org/CVERecord?id=CVE-2026-46600" + ], + "PublishedDate": "2026-07-21T20:17:01.213Z", + "LastModifiedDate": "2026-08-14T16:16:55.673Z" + }, + { + "VulnerabilityID": "CVE-2026-56852", + "VendorIDs": [ + "GO-2026-5970" + ], + "PkgID": "golang.org/x/text@v0.24.0", + "PkgName": "golang.org/x/text", + "PkgIdentifier": { + "PURL": "pkg:golang/golang.org/x/text@v0.24.0", + "UID": "5daaee8034347960" + }, + "InstalledVersion": "v0.24.0", + "FixedVersion": "0.39.0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56852", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b3f52bb5709aff9fa1c8bd574d4799a743187cb1991a288c50c00cf8fe57782a", + "Title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input", + "Description": "A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 3, + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-56852", + "https://go.dev/cl/794100", + "https://go.dev/issue/80142", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56852", + "https://pkg.go.dev/vuln/GO-2026-5970", + "https://www.cve.org/CVERecord?id=CVE-2026-56852" + ], + "PublishedDate": "2026-07-21T20:17:02.867Z", + "LastModifiedDate": "2026-07-23T18:27:48.877Z" + }, + { + "VulnerabilityID": "CVE-2026-33186", + "VendorIDs": [ + "GHSA-p77j-4mvh-x3m3" + ], + "PkgID": "google.golang.org/grpc@v1.71.0", + "PkgName": "google.golang.org/grpc", + "PkgIdentifier": { + "PURL": "pkg:golang/google.golang.org/grpc@v1.71.0", + "UID": "70ed0c7baf32264" + }, + "InstalledVersion": "v1.71.0", + "FixedVersion": "1.79.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33186", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:3c6c91dd861ee159804c38771ec9c06052927bde3aaf580dab42f230fc1fc4aa", + "Title": "google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation", + "Description": "gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, \"deny\" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback \"allow\" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific \"deny\" rules for canonical paths but allows other requests by default (a fallback \"allow\" rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers with a non-canonical path string. While upgrading is the most secure and recommended path, users can mitigate the vulnerability using one of the following methods: Use a validating interceptor (recommended mitigation); infrastructure-level normalization; and/or policy hardening.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-285", + "CWE-551" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "ghsa": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10093", + "https://access.redhat.com/errata/RHSA-2026:10094", + "https://access.redhat.com/errata/RHSA-2026:10105", + "https://access.redhat.com/errata/RHSA-2026:10107", + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10126", + "https://access.redhat.com/errata/RHSA-2026:10130", + "https://access.redhat.com/errata/RHSA-2026:10131", + "https://access.redhat.com/errata/RHSA-2026:10153", + "https://access.redhat.com/errata/RHSA-2026:10155", + "https://access.redhat.com/errata/RHSA-2026:10158", + "https://access.redhat.com/errata/RHSA-2026:10172", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10698", + "https://access.redhat.com/errata/RHSA-2026:10705", + "https://access.redhat.com/errata/RHSA-2026:10706", + "https://access.redhat.com/errata/RHSA-2026:11070", + "https://access.redhat.com/errata/RHSA-2026:11408", + "https://access.redhat.com/errata/RHSA-2026:11803", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12116", + "https://access.redhat.com/errata/RHSA-2026:12118", + "https://access.redhat.com/errata/RHSA-2026:12119", + "https://access.redhat.com/errata/RHSA-2026:12277", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:12283", + "https://access.redhat.com/errata/RHSA-2026:12337", + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14775", + "https://access.redhat.com/errata/RHSA-2026:15092", + "https://access.redhat.com/errata/RHSA-2026:17123", + "https://access.redhat.com/errata/RHSA-2026:17448", + "https://access.redhat.com/errata/RHSA-2026:17459", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17474", + "https://access.redhat.com/errata/RHSA-2026:17475", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:17599", + "https://access.redhat.com/errata/RHSA-2026:17789", + "https://access.redhat.com/errata/RHSA-2026:18068", + "https://access.redhat.com/errata/RHSA-2026:18585", + "https://access.redhat.com/errata/RHSA-2026:19099", + "https://access.redhat.com/errata/RHSA-2026:19108", + "https://access.redhat.com/errata/RHSA-2026:19109", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19207", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:20034", + "https://access.redhat.com/errata/RHSA-2026:20035", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20042", + "https://access.redhat.com/errata/RHSA-2026:20088", + "https://access.redhat.com/errata/RHSA-2026:20089", + "https://access.redhat.com/errata/RHSA-2026:20322", + "https://access.redhat.com/errata/RHSA-2026:20436", + "https://access.redhat.com/errata/RHSA-2026:20943", + "https://access.redhat.com/errata/RHSA-2026:20946", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21658", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:21692", + "https://access.redhat.com/errata/RHSA-2026:21696", + "https://access.redhat.com/errata/RHSA-2026:21697", + "https://access.redhat.com/errata/RHSA-2026:21703", + "https://access.redhat.com/errata/RHSA-2026:21704", + "https://access.redhat.com/errata/RHSA-2026:21709", + "https://access.redhat.com/errata/RHSA-2026:21710", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21931", + "https://access.redhat.com/errata/RHSA-2026:21932", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22645", + "https://access.redhat.com/errata/RHSA-2026:22689", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22800", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:22959", + "https://access.redhat.com/errata/RHSA-2026:22961", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23234", + "https://access.redhat.com/errata/RHSA-2026:23235", + "https://access.redhat.com/errata/RHSA-2026:23241", + "https://access.redhat.com/errata/RHSA-2026:23246", + "https://access.redhat.com/errata/RHSA-2026:23247", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24484", + "https://access.redhat.com/errata/RHSA-2026:24506", + "https://access.redhat.com/errata/RHSA-2026:24535", + "https://access.redhat.com/errata/RHSA-2026:24536", + "https://access.redhat.com/errata/RHSA-2026:24759", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25009", + "https://access.redhat.com/errata/RHSA-2026:25045", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25182", + "https://access.redhat.com/errata/RHSA-2026:25183", + "https://access.redhat.com/errata/RHSA-2026:25187", + "https://access.redhat.com/errata/RHSA-2026:25194", + "https://access.redhat.com/errata/RHSA-2026:25195", + "https://access.redhat.com/errata/RHSA-2026:25201", + "https://access.redhat.com/errata/RHSA-2026:26412", + "https://access.redhat.com/errata/RHSA-2026:26413", + "https://access.redhat.com/errata/RHSA-2026:26416", + "https://access.redhat.com/errata/RHSA-2026:26420", + "https://access.redhat.com/errata/RHSA-2026:26519", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26997", + "https://access.redhat.com/errata/RHSA-2026:26999", + "https://access.redhat.com/errata/RHSA-2026:27001", + "https://access.redhat.com/errata/RHSA-2026:27004", + "https://access.redhat.com/errata/RHSA-2026:27063", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:27712", + "https://access.redhat.com/errata/RHSA-2026:27856", + "https://access.redhat.com/errata/RHSA-2026:27892", + "https://access.redhat.com/errata/RHSA-2026:27893", + "https://access.redhat.com/errata/RHSA-2026:27901", + "https://access.redhat.com/errata/RHSA-2026:27957", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28893", + "https://access.redhat.com/errata/RHSA-2026:28964", + "https://access.redhat.com/errata/RHSA-2026:29079", + "https://access.redhat.com/errata/RHSA-2026:29082", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:34049", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34099", + "https://access.redhat.com/errata/RHSA-2026:34100", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34769", + "https://access.redhat.com/errata/RHSA-2026:34794", + "https://access.redhat.com/errata/RHSA-2026:34795", + "https://access.redhat.com/errata/RHSA-2026:36611", + "https://access.redhat.com/errata/RHSA-2026:36621", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:37192", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:37580", + "https://access.redhat.com/errata/RHSA-2026:37585", + "https://access.redhat.com/errata/RHSA-2026:40022", + "https://access.redhat.com/errata/RHSA-2026:40030", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40792", + "https://access.redhat.com/errata/RHSA-2026:40795", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:40984", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:41944", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43225", + "https://access.redhat.com/errata/RHSA-2026:43227", + "https://access.redhat.com/errata/RHSA-2026:43253", + "https://access.redhat.com/errata/RHSA-2026:43331", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44233", + "https://access.redhat.com/errata/RHSA-2026:44235", + "https://access.redhat.com/errata/RHSA-2026:47728", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48699", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:50758", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:53728", + "https://access.redhat.com/errata/RHSA-2026:53763", + "https://access.redhat.com/errata/RHSA-2026:53773", + "https://access.redhat.com/errata/RHSA-2026:53804", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56366", + "https://access.redhat.com/errata/RHSA-2026:56431", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:56959", + "https://access.redhat.com/errata/RHSA-2026:57013", + "https://access.redhat.com/errata/RHSA-2026:57365", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60146", + "https://access.redhat.com/errata/RHSA-2026:61245", + "https://access.redhat.com/errata/RHSA-2026:6174", + "https://access.redhat.com/errata/RHSA-2026:6428", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6802", + "https://access.redhat.com/errata/RHSA-2026:7110", + "https://access.redhat.com/errata/RHSA-2026:7128", + "https://access.redhat.com/errata/RHSA-2026:7245", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8449", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:8484", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9388", + "https://access.redhat.com/errata/RHSA-2026:9440", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/errata/RHSA-2026:9872", + "https://access.redhat.com/security/cve/CVE-2026-33186", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2449833", + "https://bugzilla.redhat.com/2455470", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456335", + "https://bugzilla.redhat.com/2456336", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445345", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2449833", + "https://bugzilla.redhat.com/show_bug.cgi?id=2455470", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456336", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27137", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32282", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33186", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34986", + "https://errata.almalinux.org/9/ALSA-2026-19353.html", + "https://errata.rockylinux.org/RLSA-2026:23228", + "https://github.com/grpc/grpc-go", + "https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3", + "https://linux.oracle.com/cve/CVE-2026-33186.html", + "https://linux.oracle.com/errata/ELSA-2026-48790.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33186", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33186.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33186" + ], + "PublishedDate": "2026-03-20T23:16:45.18Z", + "LastModifiedDate": "2026-09-11T13:17:30.047Z" + }, + { + "VulnerabilityID": "CVE-2026-84304", + "VendorIDs": [ + "GHSA-vp52-pcj8-j9qc" + ], + "PkgID": "google.golang.org/grpc@v1.71.0", + "PkgName": "google.golang.org/grpc", + "PkgIdentifier": { + "PURL": "pkg:golang/google.golang.org/grpc@v1.71.0", + "UID": "70ed0c7baf32264" + }, + "InstalledVersion": "v1.71.0", + "FixedVersion": "1.83.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-84304", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:96003e2fa2376d4983c65af236c423e74f52b7eef173e620c9ccd826e7466d7a", + "Title": "gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...", + "Description": "gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.7 + } + }, + "References": [ + "https://github.com/grpc/grpc-go", + "https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176", + "https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77", + "https://github.com/grpc/grpc-go/pull/9331", + "https://github.com/grpc/grpc-go/pull/9333", + "https://github.com/grpc/grpc-go/releases/tag/v1.83.1", + "https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc", + "https://nvd.nist.gov/vuln/detail/CVE-2026-84304" + ], + "PublishedDate": "2026-09-01T19:17:30.743Z", + "LastModifiedDate": "2026-09-09T21:09:13.08Z" + }, + { + "VulnerabilityID": "CVE-2026-84445", + "VendorIDs": [ + "GHSA-2v4p-qf9q-27wj" + ], + "PkgID": "google.golang.org/grpc@v1.71.0", + "PkgName": "google.golang.org/grpc", + "PkgIdentifier": { + "PURL": "pkg:golang/google.golang.org/grpc@v1.71.0", + "UID": "70ed0c7baf32264" + }, + "InstalledVersion": "v1.71.0", + "FixedVersion": "1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-84445", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:2afa3a04be4c308c85b90981f400b435e32c82f9d0b844a3c5921b0646fc05e0", + "Title": "gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers", + "Description": "A vulnerability exists in gRPC-Go servers configured with `xds.NewGRPCServer()` where a crafted request missing both `:authority` and `Host` headers can cause a server panic, resulting in a Denial of Service (DoS).\n\nServers built with `xds.NewGRPCServer` install an xDS routing interceptor on every RPC. This interceptor looks up the request’s `:authority` header to pick a virtual host. The HTTP/2 server transport previously accepted requests that had neither `:authority` nor `Host`. When this happened, the xDS routing interceptor attempted to access the first element of an empty slice of authorities, leading to an index out of bounds panic. Since the per-RPC goroutine does not recover from panics, the entire server process would terminate.\n\nThis panic occurs in the interceptor pipeline, meaning the transport credentials handshake (TLS, mTLS, or ALTS) and HTTP/2 connection establishment must complete successfully before the crafted request can reach this logic.\n- Insecure/Standard TLS: If the server permits insecure (plaintext) connections or standard credentials (where client certs are not checked), any unauthenticated remote attacker can trigger the crash.\n- mTLS / ALTS: If strict transport-level authentication is enforced at the network edge or transport layer (e.g., requiring a valid client certificate), the attacker must possess valid transport credentials to initiate the stream and trigger the panic.\n\n### Impact\nAn attacker can cause a complete outage of the gRPC server by sending a request missing both `:authority` and `Host` headers, provided they can successfully establish a transport connection.\n\n### Patches\nThe issue has been addressed in `master` (and backported to `1.83.2` and `1.82.2`). The fix updates the HTTP/2 transport layer to reject requests missing both `:authority` and `Host` headers early, maintaining consistency with and other gRPC language implementations.", + "Severity": "HIGH", + "VendorSeverity": { + "ghsa": 3 + }, + "References": [ + "https://github.com/grpc/grpc-go", + "https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7", + "https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4", + "https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f", + "https://github.com/grpc/grpc-go/issues/9354", + "https://github.com/grpc/grpc-go/pull/9365", + "https://github.com/grpc/grpc-go/pull/9366", + "https://github.com/grpc/grpc-go/pull/9367", + "https://github.com/grpc/grpc-go/releases/tag/v1.82.2", + "https://github.com/grpc/grpc-go/releases/tag/v1.83.2", + "https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj" + ] + }, + { + "VulnerabilityID": "GHSA-hrxh-6v49-42gf", + "PkgID": "google.golang.org/grpc@v1.71.0", + "PkgName": "google.golang.org/grpc", + "PkgIdentifier": { + "PURL": "pkg:golang/google.golang.org/grpc@v1.71.0", + "UID": "70ed0c7baf32264" + }, + "InstalledVersion": "v1.71.0", + "FixedVersion": "1.82.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://github.com/advisories/GHSA-hrxh-6v49-42gf", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory Go", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Ago" + }, + "Fingerprint": "sha256:270baeb847305aaa28456635215b05c3f3e2beb6dbb0bfc8f3816eea33fb7d8a", + "Title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities", + "Description": "Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in:\n\n- Authorization Bypass (Fail-Open) when translating xDS RBAC policies containing `Metadata` or `RequestedServerName` fields.\n- Denial of Service (High CPU Consumption) due to an HTTP/2 Rapid Reset mitigation bypass during client-initiated stream resets.\n- Denial of Service (Server Panic) when parsing crafted xDS RBAC policies containing `NOT` rules around unsupported fields.\n\n\n### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\n#### xDS RBAC Authorization Bypass via `Metadata` \u0026 `RequestedServerName` matchers\n\n- Affected Component: xDS RBAC \n- Impact: When building policy matchers for gRPC RBAC from xDS configurations, unsupported `permission` and `principal` rules (specifically `Metadata` and `RequestedServerName`) were silently ignored and treated as no-ops.\n - If an authorization policy relied purely on these matchers for access control, treating those rules as no-ops effectively removed the restrictions.\n- If these unsupported rules were nested inside logical `NOT` rules (`Permission_NotRule` / `Principal_NotId`) or multi-condition `OR/AND` rules, silently dropping them changed the boolean logic flow of the authorization engine.\n\nAs a result, policy evaluation decisions could fail open, allowing unauthorized clients to access protected gRPC services or resources.\n\n#### HTTP/2 Rapid Reset Mitigation Bypass / Denial of Service via Stream Aborts\n\n- Affected Component: HTTP/2 transport\n- Impact: Earlier mitigations in grpc-go for HTTP/2 Rapid Reset only applied threshold checks to items that directly resulted in control frames being written back to the wire, such as `SETTINGS` ACKs or server-initiated `RST_STREAM`s.\n\nWhen a client initiated a rapid flood of stream creation (`HEADERS`) immediately followed by stream termination `RST_STREAM`, items queued up in the control buffer without counting against the transport response frame threshold. An attacker can repeatedly trigger this flood sequence to bypass reader blocking, resulting in high CPU usage, and Denial of Service (DoS).\n\n#### Denial of Service (Panic) in xDS RBAC Engine via Unsupported Fields inside NOT Rules\n\n- Affected Component: xDS RBAC \n- Impact: The xDS RBAC policy translators recursively generate matchers for nested rules. When a `NOT` rule wrapped an unsupported or unhandled field (such as `SourcedMetadata`), the recursive step returned an empty matcher. This could result in a runtime panic when the RBAC engine attempts to authorize an incoming request.\n\nAn attacker or misconfigured/malicious xDS management server delivering an LDS/RDS update containing a `NOT` rule around an unhandled field causes the gRPC server process to crash immediately (CWE-248 / Denial of Service).\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nAll three issues have been fixed in `master` and will be released in 1.82.1 shortly.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nIf upgrading grpc-go immediately is not possible, apply the following workarounds based on your deployment architecture:\n\n* For xDS RBAC Vulnerabilities \u0026 Panics: Ensure that upstream xDS management servers do not push RBAC policies containing `Metadata`, `RequestedServerName`, or `NOT` rules wrapping unsupported fields (such as `SourcedMetadata`) to grpc-go servers.\n* For HTTP/2 Rapid Reset DOS: Configure upstream reverse proxies or load balancers (such as Envoy) with strict HTTP/2 `max_concurrent_streams` limits and active rate limiting on `RST_STREAM` frequency per connection.\n\n### Severity\n\n | Vulnerability | Qualitative Severity | Approximate CVSS v3.1 Score | Primary Impact |\n | :--- | :--- | :--- | :--- |\n | **xDS RBAC Authorization Bypass** | **High** | `8.2` | Unauthorized Access / Fail-Open |\n | **HTTP/2 Rapid Reset DOS Bypass** | **High** | `7.5` | High CPU Consumption / Denial of Service |\n | **xDS RBAC Engine Server Panic** | **Medium** | `5.9` | Process Crash / Denial of Service |", + "Severity": "HIGH", + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.8 + } + }, + "References": [ + "https://github.com/grpc/grpc-go", + "https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935", + "https://github.com/grpc/grpc-go/pull/9236", + "https://github.com/grpc/grpc-go/releases/tag/v1.82.1", + "https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf" + ], + "PublishedDate": "2026-07-21T22:03:55Z", + "LastModifiedDate": "2026-07-21T22:03:56Z" + }, + { + "VulnerabilityID": "CVE-2025-68121", + "VendorIDs": [ + "GO-2026-4337" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.24.13, 1.25.7, 1.26.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-68121", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d8abbd32688860176e25ccb307b1fa9a2ae760d6349d242c03e139820acafe8b", + "Title": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption", + "Description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 4, + "cbl-mariner": 2, + "nvd": 4, + "oracle-oval": 3, + "photon": 4, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/security/cve/CVE-2025-68121", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://github.com/golang/go/issues/77113", + "https://go.dev/cl/737700", + "https://go.dev/issue/77217", + "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-68121.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-68121", + "https://pkg.go.dev/vuln/GO-2026-4337", + "https://www.cve.org/CVERecord?id=CVE-2025-68121" + ], + "PublishedDate": "2026-02-05T18:16:10.857Z", + "LastModifiedDate": "2026-06-17T09:58:33.833Z" + }, + { + "VulnerabilityID": "CVE-2025-22874", + "VendorIDs": [ + "GO-2025-3749" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.24.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-22874", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:39b83fc0c68eaa5045a644918e65595ce9f1f5e5f5d6e5b9d304c371f730516c", + "Title": "crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509", + "Description": "Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.", + "Severity": "HIGH", + "VendorSeverity": { + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 3, + "photon": 3, + "redhat": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2025-22874", + "https://go.dev/cl/670375", + "https://go.dev/issue/73612", + "https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A", + "https://nvd.nist.gov/vuln/detail/CVE-2025-22874", + "https://pkg.go.dev/vuln/GO-2025-3749", + "https://www.cve.org/CVERecord?id=CVE-2025-22874" + ], + "PublishedDate": "2025-06-11T17:15:42.167Z", + "LastModifiedDate": "2026-06-17T08:50:42.733Z" + }, + { + "VulnerabilityID": "CVE-2025-61726", + "VendorIDs": [ + "GO-2026-4341" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.24.12, 1.25.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61726", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c1731112cd63a34e11036731969cce916a1358bf62f67167bd00b0b96747e809", + "Title": "golang: net/url: Memory exhaustion in query parameter parsing in net/url", + "Description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "cbl-mariner": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10096", + "https://access.redhat.com/errata/RHSA-2026:10104", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:11408", + "https://access.redhat.com/errata/RHSA-2026:11414", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13542", + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:13571", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:15984", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17446", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17595", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:18913", + "https://access.redhat.com/errata/RHSA-2026:19013", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26420", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2706", + "https://access.redhat.com/errata/RHSA-2026:2708", + "https://access.redhat.com/errata/RHSA-2026:2709", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:2844", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:2914", + "https://access.redhat.com/errata/RHSA-2026:2920", + "https://access.redhat.com/errata/RHSA-2026:3035", + "https://access.redhat.com/errata/RHSA-2026:3040", + "https://access.redhat.com/errata/RHSA-2026:3089", + "https://access.redhat.com/errata/RHSA-2026:3092", + "https://access.redhat.com/errata/RHSA-2026:3184", + "https://access.redhat.com/errata/RHSA-2026:3186", + "https://access.redhat.com/errata/RHSA-2026:3187", + "https://access.redhat.com/errata/RHSA-2026:3188", + "https://access.redhat.com/errata/RHSA-2026:3192", + "https://access.redhat.com/errata/RHSA-2026:3193", + "https://access.redhat.com/errata/RHSA-2026:3291", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:3297", + "https://access.redhat.com/errata/RHSA-2026:3298", + "https://access.redhat.com/errata/RHSA-2026:3336", + "https://access.redhat.com/errata/RHSA-2026:3337", + "https://access.redhat.com/errata/RHSA-2026:3340", + "https://access.redhat.com/errata/RHSA-2026:3341", + "https://access.redhat.com/errata/RHSA-2026:3343", + "https://access.redhat.com/errata/RHSA-2026:3391", + "https://access.redhat.com/errata/RHSA-2026:3416", + "https://access.redhat.com/errata/RHSA-2026:3427", + "https://access.redhat.com/errata/RHSA-2026:3459", + "https://access.redhat.com/errata/RHSA-2026:3468", + "https://access.redhat.com/errata/RHSA-2026:3469", + "https://access.redhat.com/errata/RHSA-2026:3470", + "https://access.redhat.com/errata/RHSA-2026:3471", + "https://access.redhat.com/errata/RHSA-2026:3472", + "https://access.redhat.com/errata/RHSA-2026:3473", + "https://access.redhat.com/errata/RHSA-2026:3489", + "https://access.redhat.com/errata/RHSA-2026:3506", + "https://access.redhat.com/errata/RHSA-2026:3556", + "https://access.redhat.com/errata/RHSA-2026:3559", + "https://access.redhat.com/errata/RHSA-2026:3668", + "https://access.redhat.com/errata/RHSA-2026:3669", + "https://access.redhat.com/errata/RHSA-2026:36873", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:3699", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:3752", + "https://access.redhat.com/errata/RHSA-2026:3753", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3812", + "https://access.redhat.com/errata/RHSA-2026:3813", + "https://access.redhat.com/errata/RHSA-2026:3814", + "https://access.redhat.com/errata/RHSA-2026:3815", + "https://access.redhat.com/errata/RHSA-2026:3816", + "https://access.redhat.com/errata/RHSA-2026:3817", + "https://access.redhat.com/errata/RHSA-2026:3818", + "https://access.redhat.com/errata/RHSA-2026:3820", + "https://access.redhat.com/errata/RHSA-2026:3821", + "https://access.redhat.com/errata/RHSA-2026:3822", + "https://access.redhat.com/errata/RHSA-2026:3831", + "https://access.redhat.com/errata/RHSA-2026:3833", + "https://access.redhat.com/errata/RHSA-2026:3835", + "https://access.redhat.com/errata/RHSA-2026:3836", + "https://access.redhat.com/errata/RHSA-2026:3838", + "https://access.redhat.com/errata/RHSA-2026:3839", + "https://access.redhat.com/errata/RHSA-2026:3840", + "https://access.redhat.com/errata/RHSA-2026:3841", + "https://access.redhat.com/errata/RHSA-2026:3843", + "https://access.redhat.com/errata/RHSA-2026:3854", + "https://access.redhat.com/errata/RHSA-2026:3855", + "https://access.redhat.com/errata/RHSA-2026:3856", + "https://access.redhat.com/errata/RHSA-2026:3864", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3875", + "https://access.redhat.com/errata/RHSA-2026:3879", + "https://access.redhat.com/errata/RHSA-2026:3880", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3898", + "https://access.redhat.com/errata/RHSA-2026:3905", + "https://access.redhat.com/errata/RHSA-2026:3906", + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/errata/RHSA-2026:3929", + "https://access.redhat.com/errata/RHSA-2026:3930", + "https://access.redhat.com/errata/RHSA-2026:3931", + "https://access.redhat.com/errata/RHSA-2026:3932", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:3970", + "https://access.redhat.com/errata/RHSA-2026:3971", + "https://access.redhat.com/errata/RHSA-2026:3972", + "https://access.redhat.com/errata/RHSA-2026:3973", + "https://access.redhat.com/errata/RHSA-2026:3974", + "https://access.redhat.com/errata/RHSA-2026:3977", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:3985", + "https://access.redhat.com/errata/RHSA-2026:40924", + "https://access.redhat.com/errata/RHSA-2026:4164", + "https://access.redhat.com/errata/RHSA-2026:4166", + "https://access.redhat.com/errata/RHSA-2026:4170", + "https://access.redhat.com/errata/RHSA-2026:4174", + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:4211", + "https://access.redhat.com/errata/RHSA-2026:4220", + "https://access.redhat.com/errata/RHSA-2026:4256", + "https://access.redhat.com/errata/RHSA-2026:4264", + "https://access.redhat.com/errata/RHSA-2026:4267", + "https://access.redhat.com/errata/RHSA-2026:4270", + "https://access.redhat.com/errata/RHSA-2026:4276", + "https://access.redhat.com/errata/RHSA-2026:4434", + "https://access.redhat.com/errata/RHSA-2026:4435", + "https://access.redhat.com/errata/RHSA-2026:4460", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:4498", + "https://access.redhat.com/errata/RHSA-2026:4500", + "https://access.redhat.com/errata/RHSA-2026:4510", + "https://access.redhat.com/errata/RHSA-2026:4511", + "https://access.redhat.com/errata/RHSA-2026:4672", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:4753", + "https://access.redhat.com/errata/RHSA-2026:4892", + "https://access.redhat.com/errata/RHSA-2026:4901", + "https://access.redhat.com/errata/RHSA-2026:4907", + "https://access.redhat.com/errata/RHSA-2026:4939", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:4943", + "https://access.redhat.com/errata/RHSA-2026:4952", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5022", + "https://access.redhat.com/errata/RHSA-2026:5030", + "https://access.redhat.com/errata/RHSA-2026:5031", + "https://access.redhat.com/errata/RHSA-2026:5076", + "https://access.redhat.com/errata/RHSA-2026:5077", + "https://access.redhat.com/errata/RHSA-2026:5078", + "https://access.redhat.com/errata/RHSA-2026:5079", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:5129", + "https://access.redhat.com/errata/RHSA-2026:5130", + "https://access.redhat.com/errata/RHSA-2026:5131", + "https://access.redhat.com/errata/RHSA-2026:5132", + "https://access.redhat.com/errata/RHSA-2026:5145", + "https://access.redhat.com/errata/RHSA-2026:5146", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5327", + "https://access.redhat.com/errata/RHSA-2026:5394", + "https://access.redhat.com/errata/RHSA-2026:5439", + "https://access.redhat.com/errata/RHSA-2026:5444", + "https://access.redhat.com/errata/RHSA-2026:5447", + "https://access.redhat.com/errata/RHSA-2026:5452", + "https://access.redhat.com/errata/RHSA-2026:5461", + "https://access.redhat.com/errata/RHSA-2026:5463", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5533", + "https://access.redhat.com/errata/RHSA-2026:5544", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5636", + "https://access.redhat.com/errata/RHSA-2026:56366", + "https://access.redhat.com/errata/RHSA-2026:56431", + "https://access.redhat.com/errata/RHSA-2026:5645", + "https://access.redhat.com/errata/RHSA-2026:5649", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:57013", + "https://access.redhat.com/errata/RHSA-2026:5807", + "https://access.redhat.com/errata/RHSA-2026:5851", + "https://access.redhat.com/errata/RHSA-2026:5852", + "https://access.redhat.com/errata/RHSA-2026:5853", + "https://access.redhat.com/errata/RHSA-2026:5948", + "https://access.redhat.com/errata/RHSA-2026:5950", + "https://access.redhat.com/errata/RHSA-2026:5952", + "https://access.redhat.com/errata/RHSA-2026:5968", + "https://access.redhat.com/errata/RHSA-2026:6184", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6226", + "https://access.redhat.com/errata/RHSA-2026:6251", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6428", + "https://access.redhat.com/errata/RHSA-2026:6429", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6554", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/errata/RHSA-2026:66401", + "https://access.redhat.com/errata/RHSA-2026:7052", + "https://access.redhat.com/errata/RHSA-2026:7249", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7676", + "https://access.redhat.com/errata/RHSA-2026:7854", + "https://access.redhat.com/errata/RHSA-2026:7942", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8218", + "https://access.redhat.com/errata/RHSA-2026:8229", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8431", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9848", + "https://access.redhat.com/security/cve/CVE-2025-61726", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://go.dev/cl/736712", + "https://go.dev/issue/77101", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-61726.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61726", + "https://pkg.go.dev/vuln/GO-2026-4341", + "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json", + "https://www.cve.org/CVERecord?id=CVE-2025-61726" + ], + "PublishedDate": "2026-01-28T20:16:09.713Z", + "LastModifiedDate": "2026-09-11T13:16:49.81Z" + }, + { + "VulnerabilityID": "CVE-2025-61729", + "VendorIDs": [ + "GO-2025-4155" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.24.11, 1.25.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61729", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ef588a56f9d919b840dd7d27dd38bdaebc11e5996ccac1f8a84c7dc70db5025a", + "Title": "crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate", + "Description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 1, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/security/cve/CVE-2025-61729", + "https://bugzilla.redhat.com/2418462", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-3928.html", + "https://errata.rockylinux.org/RLSA-2026:3928", + "https://go.dev/cl/725920", + "https://go.dev/issue/76445", + "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4", + "https://linux.oracle.com/cve/CVE-2025-61729.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61729", + "https://pkg.go.dev/vuln/GO-2025-4155", + "https://www.cve.org/CVERecord?id=CVE-2025-61729" + ], + "PublishedDate": "2025-12-02T19:15:51.447Z", + "LastModifiedDate": "2026-06-17T09:50:48.507Z" + }, + { + "VulnerabilityID": "CVE-2026-25679", + "VendorIDs": [ + "GO-2026-4601" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.8, 1.26.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25679", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:a6e33bf588ed853a7408082275fc2af6ef649bb424af66cb3bf3a51ab41cf72d", + "Title": "net/url: Incorrect parsing of IPv6 host literals in net/url", + "Description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-425", + "CWE-1286" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10065", + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10133", + "https://access.redhat.com/errata/RHSA-2026:10140", + "https://access.redhat.com/errata/RHSA-2026:10141", + "https://access.redhat.com/errata/RHSA-2026:10158", + "https://access.redhat.com/errata/RHSA-2026:10169", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:10701", + "https://access.redhat.com/errata/RHSA-2026:10712", + "https://access.redhat.com/errata/RHSA-2026:10929", + "https://access.redhat.com/errata/RHSA-2026:11217", + "https://access.redhat.com/errata/RHSA-2026:11375", + "https://access.redhat.com/errata/RHSA-2026:11412", + "https://access.redhat.com/errata/RHSA-2026:11413", + "https://access.redhat.com/errata/RHSA-2026:11686", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:11768", + "https://access.redhat.com/errata/RHSA-2026:11800", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13508", + "https://access.redhat.com/errata/RHSA-2026:13512", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13642", + "https://access.redhat.com/errata/RHSA-2026:13643", + "https://access.redhat.com/errata/RHSA-2026:13671", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:19017", + "https://access.redhat.com/errata/RHSA-2026:19022", + "https://access.redhat.com/errata/RHSA-2026:19026", + "https://access.redhat.com/errata/RHSA-2026:19027", + "https://access.redhat.com/errata/RHSA-2026:19031", + "https://access.redhat.com/errata/RHSA-2026:19032", + "https://access.redhat.com/errata/RHSA-2026:19049", + "https://access.redhat.com/errata/RHSA-2026:19055", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19128", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19181", + "https://access.redhat.com/errata/RHSA-2026:19184", + "https://access.redhat.com/errata/RHSA-2026:19185", + "https://access.redhat.com/errata/RHSA-2026:19207", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19475", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20088", + "https://access.redhat.com/errata/RHSA-2026:20581", + "https://access.redhat.com/errata/RHSA-2026:20582", + "https://access.redhat.com/errata/RHSA-2026:20584", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:21696", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22733", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24386", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:25043", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26445", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28893", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:52389", + "https://access.redhat.com/errata/RHSA-2026:52390", + "https://access.redhat.com/errata/RHSA-2026:52391", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:56785", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:5941", + "https://access.redhat.com/errata/RHSA-2026:5942", + "https://access.redhat.com/errata/RHSA-2026:5943", + "https://access.redhat.com/errata/RHSA-2026:5944", + "https://access.redhat.com/errata/RHSA-2026:59830", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:6341", + "https://access.redhat.com/errata/RHSA-2026:6344", + "https://access.redhat.com/errata/RHSA-2026:6382", + "https://access.redhat.com/errata/RHSA-2026:6383", + "https://access.redhat.com/errata/RHSA-2026:6388", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:66401", + "https://access.redhat.com/errata/RHSA-2026:6720", + "https://access.redhat.com/errata/RHSA-2026:6802", + "https://access.redhat.com/errata/RHSA-2026:6949", + "https://access.redhat.com/errata/RHSA-2026:7005", + "https://access.redhat.com/errata/RHSA-2026:7009", + "https://access.redhat.com/errata/RHSA-2026:7011", + "https://access.redhat.com/errata/RHSA-2026:7259", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7315", + "https://access.redhat.com/errata/RHSA-2026:7328", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7665", + "https://access.redhat.com/errata/RHSA-2026:7669", + "https://access.redhat.com/errata/RHSA-2026:7674", + "https://access.redhat.com/errata/RHSA-2026:7833", + "https://access.redhat.com/errata/RHSA-2026:7834", + "https://access.redhat.com/errata/RHSA-2026:7876", + "https://access.redhat.com/errata/RHSA-2026:7877", + "https://access.redhat.com/errata/RHSA-2026:7878", + "https://access.redhat.com/errata/RHSA-2026:7879", + "https://access.redhat.com/errata/RHSA-2026:7883", + "https://access.redhat.com/errata/RHSA-2026:7992", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8314", + "https://access.redhat.com/errata/RHSA-2026:8322", + "https://access.redhat.com/errata/RHSA-2026:8324", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8434", + "https://access.redhat.com/errata/RHSA-2026:8456", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:8484", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:8840", + "https://access.redhat.com/errata/RHSA-2026:8841", + "https://access.redhat.com/errata/RHSA-2026:8842", + "https://access.redhat.com/errata/RHSA-2026:8845", + "https://access.redhat.com/errata/RHSA-2026:8847", + "https://access.redhat.com/errata/RHSA-2026:8848", + "https://access.redhat.com/errata/RHSA-2026:8849", + "https://access.redhat.com/errata/RHSA-2026:8851", + "https://access.redhat.com/errata/RHSA-2026:8852", + "https://access.redhat.com/errata/RHSA-2026:8853", + "https://access.redhat.com/errata/RHSA-2026:8855", + "https://access.redhat.com/errata/RHSA-2026:8856", + "https://access.redhat.com/errata/RHSA-2026:8860", + "https://access.redhat.com/errata/RHSA-2026:8877", + "https://access.redhat.com/errata/RHSA-2026:8878", + "https://access.redhat.com/errata/RHSA-2026:8879", + "https://access.redhat.com/errata/RHSA-2026:8881", + "https://access.redhat.com/errata/RHSA-2026:8882", + "https://access.redhat.com/errata/RHSA-2026:8930", + "https://access.redhat.com/errata/RHSA-2026:8931", + "https://access.redhat.com/errata/RHSA-2026:8949", + "https://access.redhat.com/errata/RHSA-2026:9043", + "https://access.redhat.com/errata/RHSA-2026:9044", + "https://access.redhat.com/errata/RHSA-2026:9052", + "https://access.redhat.com/errata/RHSA-2026:9090", + "https://access.redhat.com/errata/RHSA-2026:9093", + "https://access.redhat.com/errata/RHSA-2026:9094", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9434", + "https://access.redhat.com/errata/RHSA-2026:9435", + "https://access.redhat.com/errata/RHSA-2026:9436", + "https://access.redhat.com/errata/RHSA-2026:9439", + "https://access.redhat.com/errata/RHSA-2026:9440", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/errata/RHSA-2026:9461", + "https://access.redhat.com/errata/RHSA-2026:9695", + "https://access.redhat.com/errata/RHSA-2026:9742", + "https://access.redhat.com/errata/RHSA-2026:9872", + "https://access.redhat.com/security/cve/CVE-2026-25679", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://errata.almalinux.org/9/ALSA-2026-9044.html", + "https://errata.rockylinux.org/RLSA-2026:9044", + "https://go.dev/cl/752180", + "https://go.dev/issue/77578", + "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk", + "https://linux.oracle.com/cve/CVE-2026-25679.html", + "https://linux.oracle.com/errata/ELSA-2026-9044.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25679", + "https://pkg.go.dev/vuln/GO-2026-4601", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json", + "https://www.cve.org/CVERecord?id=CVE-2026-25679" + ], + "PublishedDate": "2026-03-06T22:16:00.72Z", + "LastModifiedDate": "2026-09-11T13:17:13.637Z" + }, + { + "VulnerabilityID": "CVE-2026-27145", + "VendorIDs": [ + "GO-2026-5037" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27145", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f4edd7a8fdc1c687153091d25e635496f8c791c9e7b593e902b766748ec9f8d3", + "Title": "crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries", + "Description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:29980", + "https://access.redhat.com/errata/RHSA-2026:29981", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46394", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49705", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:49729", + "https://access.redhat.com/errata/RHSA-2026:49744", + "https://access.redhat.com/errata/RHSA-2026:49765", + "https://access.redhat.com/errata/RHSA-2026:49770", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:52946", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53416", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54427", + "https://access.redhat.com/errata/RHSA-2026:54432", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54525", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54603", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:55899", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57488", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:59556", + "https://access.redhat.com/errata/RHSA-2026:59557", + "https://access.redhat.com/errata/RHSA-2026:59558", + "https://access.redhat.com/errata/RHSA-2026:59559", + "https://access.redhat.com/errata/RHSA-2026:59579", + "https://access.redhat.com/errata/RHSA-2026:59593", + "https://access.redhat.com/errata/RHSA-2026:60025", + "https://access.redhat.com/errata/RHSA-2026:60315", + "https://access.redhat.com/errata/RHSA-2026:60354", + "https://access.redhat.com/errata/RHSA-2026:60386", + "https://access.redhat.com/errata/RHSA-2026:60387", + "https://access.redhat.com/errata/RHSA-2026:60388", + "https://access.redhat.com/errata/RHSA-2026:60390", + "https://access.redhat.com/errata/RHSA-2026:60391", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:63016", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/security/cve/CVE-2026-27145", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://errata.almalinux.org/9/ALSA-2026-36317.html", + "https://errata.rockylinux.org/RLSA-2026:36317", + "https://go.dev/cl/783621", + "https://go.dev/issue/79694", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-27145.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27145", + "https://pkg.go.dev/vuln/GO-2026-5037", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json", + "https://www.cve.org/CVERecord?id=CVE-2026-27145" + ], + "PublishedDate": "2026-06-02T23:16:35.57Z", + "LastModifiedDate": "2026-09-11T13:17:23.34Z" + }, + { + "VulnerabilityID": "CVE-2026-32280", + "VendorIDs": [ + "GO-2026-4947" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32280", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:f7f1fca0f201f4913f740049b15dc23fc97e5393ef03a64734cc1b4bc32d2b56", + "Title": "crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building", + "Description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13826", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16476", + "https://access.redhat.com/errata/RHSA-2026:16477", + "https://access.redhat.com/errata/RHSA-2026:16505", + "https://access.redhat.com/errata/RHSA-2026:16508", + "https://access.redhat.com/errata/RHSA-2026:16532", + "https://access.redhat.com/errata/RHSA-2026:16534", + "https://access.redhat.com/errata/RHSA-2026:16535", + "https://access.redhat.com/errata/RHSA-2026:16537", + "https://access.redhat.com/errata/RHSA-2026:16542", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21338", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21772", + "https://access.redhat.com/errata/RHSA-2026:22130", + "https://access.redhat.com/errata/RHSA-2026:22141", + "https://access.redhat.com/errata/RHSA-2026:22258", + "https://access.redhat.com/errata/RHSA-2026:22260", + "https://access.redhat.com/errata/RHSA-2026:22268", + "https://access.redhat.com/errata/RHSA-2026:22309", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22415", + "https://access.redhat.com/errata/RHSA-2026:22422", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22958", + "https://access.redhat.com/errata/RHSA-2026:22959", + "https://access.redhat.com/errata/RHSA-2026:22960", + "https://access.redhat.com/errata/RHSA-2026:22961", + "https://access.redhat.com/errata/RHSA-2026:22962", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23244", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24359", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24478", + "https://access.redhat.com/errata/RHSA-2026:24716", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:28196", + "https://access.redhat.com/errata/RHSA-2026:28198", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:39894", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49526", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54603", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56785", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56855", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:56913", + "https://access.redhat.com/errata/RHSA-2026:57409", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57488", + "https://access.redhat.com/errata/RHSA-2026:59830", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:59834", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61685", + "https://access.redhat.com/errata/RHSA-2026:61906", + "https://access.redhat.com/errata/RHSA-2026:61907", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:66401", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/security/cve/CVE-2026-32280", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/758320", + "https://go.dev/issue/78282", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32280.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32280", + "https://pkg.go.dev/vuln/GO-2026-4947", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32280" + ], + "PublishedDate": "2026-04-08T02:16:03.247Z", + "LastModifiedDate": "2026-09-11T13:17:25.78Z" + }, + { + "VulnerabilityID": "CVE-2026-32281", + "VendorIDs": [ + "GO-2026-4946" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32281", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:37458e3db1d802ba655afa16a1572b177f80eb8d080ad98b7bcc62f4de121699", + "Title": "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation", + "Description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-32281", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/758061", + "https://go.dev/issue/78281", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32281.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32281", + "https://pkg.go.dev/vuln/GO-2026-4946", + "https://www.cve.org/CVERecord?id=CVE-2026-32281" + ], + "PublishedDate": "2026-04-08T02:16:03.35Z", + "LastModifiedDate": "2026-07-25T10:10:00.167Z" + }, + { + "VulnerabilityID": "CVE-2026-32283", + "VendorIDs": [ + "GO-2026-4870" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:308fdf1ee36f4196d4d6058073853fb597f06cdb2f63aec9c98e9e17af426e7d", + "Title": "crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages", + "Description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-764" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11704", + "https://access.redhat.com/errata/RHSA-2026:11711", + "https://access.redhat.com/errata/RHSA-2026:11712", + "https://access.redhat.com/errata/RHSA-2026:11863", + "https://access.redhat.com/errata/RHSA-2026:11881", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17075", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19134", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19136", + "https://access.redhat.com/errata/RHSA-2026:19137", + "https://access.redhat.com/errata/RHSA-2026:19139", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19156", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19351", + "https://access.redhat.com/errata/RHSA-2026:19352", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19369", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:55898", + "https://access.redhat.com/errata/RHSA-2026:55900", + "https://access.redhat.com/errata/RHSA-2026:55901", + "https://access.redhat.com/errata/RHSA-2026:55902", + "https://access.redhat.com/errata/RHSA-2026:55903", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:57409", + "https://access.redhat.com/errata/RHSA-2026:57801", + "https://access.redhat.com/errata/RHSA-2026:57802", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65343", + "https://access.redhat.com/errata/RHSA-2026:65514", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66084", + "https://access.redhat.com/errata/RHSA-2026:66401", + "https://access.redhat.com/errata/RHSA-2026:66523", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/security/cve/CVE-2026-32283", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://errata.almalinux.org/9/ALSA-2026-29703.html", + "https://errata.rockylinux.org/RLSA-2026:29703", + "https://go.dev/cl/763767", + "https://go.dev/issue/78334", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32283.html", + "https://linux.oracle.com/errata/ELSA-2026-48790.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32283", + "https://pkg.go.dev/vuln/GO-2026-4870", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32283" + ], + "PublishedDate": "2026-04-08T02:16:03.58Z", + "LastModifiedDate": "2026-09-11T13:17:28.143Z" + }, + { + "VulnerabilityID": "CVE-2026-33811", + "VendorIDs": [ + "GO-2026-4981" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33811", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ee965aae43117c55827562a45f5a95838d830d7c12b398bc46d6595055798803", + "Title": "net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME", + "Description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415", + "CWE-1341" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:35995", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36617", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36776", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38504", + "https://access.redhat.com/errata/RHSA-2026:39266", + "https://access.redhat.com/errata/RHSA-2026:39272", + "https://access.redhat.com/errata/RHSA-2026:39319", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40119", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:50336", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54552", + "https://access.redhat.com/errata/RHSA-2026:54556", + "https://access.redhat.com/errata/RHSA-2026:54584", + "https://access.redhat.com/errata/RHSA-2026:54602", + "https://access.redhat.com/errata/RHSA-2026:54603", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56785", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56790", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56855", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:56913", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57488", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59559", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:60025", + "https://access.redhat.com/errata/RHSA-2026:60302", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:61313", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/security/cve/CVE-2026-33811", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-39319.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/767860", + "https://go.dev/issue/78803", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33811.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33811", + "https://pkg.go.dev/vuln/GO-2026-4981", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33811" + ], + "PublishedDate": "2026-05-07T20:16:42.77Z", + "LastModifiedDate": "2026-09-11T13:17:36.897Z" + }, + { + "VulnerabilityID": "CVE-2026-33814", + "VendorIDs": [ + "GO-2026-4918" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ce05f1d68ba17d4a088f195faf87d4091685683325dc5202ffeb0d78464dbb88", + "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", + "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57365", + "https://access.redhat.com/errata/RHSA-2026:57367", + "https://access.redhat.com/errata/RHSA-2026:57408", + "https://access.redhat.com/errata/RHSA-2026:57545", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60023", + "https://access.redhat.com/errata/RHSA-2026:60025", + "https://access.redhat.com/errata/RHSA-2026:60441", + "https://access.redhat.com/errata/RHSA-2026:60442", + "https://access.redhat.com/errata/RHSA-2026:60446", + "https://access.redhat.com/errata/RHSA-2026:60447", + "https://access.redhat.com/errata/RHSA-2026:60454", + "https://access.redhat.com/errata/RHSA-2026:60477", + "https://access.redhat.com/errata/RHSA-2026:60478", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:60668", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62550", + "https://access.redhat.com/errata/RHSA-2026:62551", + "https://access.redhat.com/errata/RHSA-2026:63046", + "https://access.redhat.com/errata/RHSA-2026:63047", + "https://access.redhat.com/errata/RHSA-2026:63048", + "https://access.redhat.com/errata/RHSA-2026:63050", + "https://access.redhat.com/errata/RHSA-2026:63091", + "https://access.redhat.com/errata/RHSA-2026:63096", + "https://access.redhat.com/errata/RHSA-2026:63097", + "https://access.redhat.com/errata/RHSA-2026:63103", + "https://access.redhat.com/errata/RHSA-2026:63104", + "https://access.redhat.com/errata/RHSA-2026:63636", + "https://access.redhat.com/errata/RHSA-2026:63637", + "https://access.redhat.com/errata/RHSA-2026:63639", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/security/cve/CVE-2026-33814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467810", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467811", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467813", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467823", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467825", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467826", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467827", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501", + "https://errata.rockylinux.org/RLSA-2026:22121", + "https://github.com/golang/go/issues/78476", + "https://go-review.googlesource.com/c/go/+/761581", + "https://go-review.googlesource.com/c/net/+/761640", + "https://go.dev/cl/761581", + "https://go.dev/cl/761640", + "https://go.dev/issue/78476", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33814.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", + "https://pkg.go.dev/vuln/GO-2026-4918", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", + "https://ubuntu.com/security/notices/USN-8430-1", + "https://ubuntu.com/security/notices/USN-8471-1", + "https://ubuntu.com/security/notices/USN-8472-1", + "https://ubuntu.com/security/notices/USN-8473-1", + "https://www.cve.org/CVERecord?id=CVE-2026-33814" + ], + "PublishedDate": "2026-05-07T20:16:42.88Z", + "LastModifiedDate": "2026-09-10T13:18:21.31Z" + }, + { + "VulnerabilityID": "CVE-2026-33818", + "VendorIDs": [ + "GO-2026-5972" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33818", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:2eb8735187daad9f69fad032da86492db0010dea74e315a164672dd1b1f7c4cd", + "Title": "encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal", + "Description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:66364", + "https://access.redhat.com/security/cve/CVE-2026-33818", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-66364.html", + "https://errata.rockylinux.org/RLSA-2026:66364", + "https://go.dev/cl/814980", + "https://go.dev/issue/80405", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-33818.html", + "https://linux.oracle.com/errata/ELSA-2026-66364-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33818", + "https://pkg.go.dev/vuln/GO-2026-5972", + "https://www.cve.org/CVERecord?id=CVE-2026-33818" + ], + "PublishedDate": "2026-08-13T22:17:19.84Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-39820", + "VendorIDs": [ + "GO-2026-4986" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39820", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:45b16800c56706e8d877ed98de3ea67d596c068abd88a35915e2ad0317380f2a", + "Title": "net/mail: golang: Go net/mail: Denial of Service via crafted email inputs", + "Description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54552", + "https://access.redhat.com/errata/RHSA-2026:54555", + "https://access.redhat.com/errata/RHSA-2026:54583", + "https://access.redhat.com/errata/RHSA-2026:54602", + "https://access.redhat.com/errata/RHSA-2026:54883", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57401", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57487", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:57914", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59830", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:60023", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62260", + "https://access.redhat.com/errata/RHSA-2026:62406", + "https://access.redhat.com/errata/RHSA-2026:62407", + "https://access.redhat.com/errata/RHSA-2026:62753", + "https://access.redhat.com/errata/RHSA-2026:62754", + "https://access.redhat.com/errata/RHSA-2026:62803", + "https://access.redhat.com/errata/RHSA-2026:63022", + "https://access.redhat.com/errata/RHSA-2026:65116", + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65153", + "https://access.redhat.com/errata/RHSA-2026:65335", + "https://access.redhat.com/errata/RHSA-2026:65336", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:65895", + "https://access.redhat.com/errata/RHSA-2026:66016", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66327", + "https://access.redhat.com/security/cve/CVE-2026-39820", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/759940", + "https://go.dev/issue/78566", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39820.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39820", + "https://pkg.go.dev/vuln/GO-2026-4986", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39820" + ], + "PublishedDate": "2026-05-07T20:16:43.187Z", + "LastModifiedDate": "2026-09-11T13:17:48.093Z" + }, + { + "VulnerabilityID": "CVE-2026-39821", + "VendorIDs": [ + "GO-2026-5026" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:34ae8501b8f45a3ec867c88d62397e9a7c1fc1e1a3a185142eafdc9cc59f67a3", + "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", + "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1289" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:30853", + "https://access.redhat.com/errata/RHSA-2026:30854", + "https://access.redhat.com/errata/RHSA-2026:30855", + "https://access.redhat.com/errata/RHSA-2026:33155", + "https://access.redhat.com/errata/RHSA-2026:33160", + "https://access.redhat.com/errata/RHSA-2026:33163", + "https://access.redhat.com/errata/RHSA-2026:33173", + "https://access.redhat.com/errata/RHSA-2026:33183", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34789", + "https://access.redhat.com/errata/RHSA-2026:35826", + "https://access.redhat.com/errata/RHSA-2026:35827", + "https://access.redhat.com/errata/RHSA-2026:35828", + "https://access.redhat.com/errata/RHSA-2026:35829", + "https://access.redhat.com/errata/RHSA-2026:35830", + "https://access.redhat.com/errata/RHSA-2026:35831", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37435", + "https://access.redhat.com/errata/RHSA-2026:37436", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:44624", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:52826", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54395", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54580", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56143", + "https://access.redhat.com/errata/RHSA-2026:56223", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56431", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57541", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:59546", + "https://access.redhat.com/errata/RHSA-2026:59549", + "https://access.redhat.com/errata/RHSA-2026:59562", + "https://access.redhat.com/errata/RHSA-2026:60315", + "https://access.redhat.com/errata/RHSA-2026:60354", + "https://access.redhat.com/errata/RHSA-2026:60387", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61245", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62549", + "https://access.redhat.com/errata/RHSA-2026:63134", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65153", + "https://access.redhat.com/errata/RHSA-2026:65359", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:66016", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66432", + "https://access.redhat.com/security/cve/CVE-2026-39821", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-37435.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://github.com/golang/go/issues/78760", + "https://go.dev/cl/767220", + "https://go.dev/issue/78760", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-39821.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", + "https://pkg.go.dev/vuln/GO-2026-5026", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", + "https://ubuntu.com/security/notices/USN-8416-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39821" + ], + "PublishedDate": "2026-05-22T16:16:20.41Z", + "LastModifiedDate": "2026-09-11T13:17:49.237Z" + }, + { + "VulnerabilityID": "CVE-2026-39822", + "VendorIDs": [ + "GO-2026-4970" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.12, 1.26.5, 1.27.0-rc.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39822", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:08184652bdc1bb0540914d5d9a4ce5624518ea2013e34b5db80f25ee99267190", + "Title": "golang: Go os.Root: Symlink following vulnerability allows directory traversal", + "Description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-61" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:38878", + "https://access.redhat.com/security/cve/CVE-2026-39822", + "https://bugzilla.redhat.com/2498152", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-38878.html", + "https://errata.rockylinux.org/RLSA-2026:38878", + "https://go.dev/cl/797880", + "https://go.dev/issue/79005", + "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc", + "https://linux.oracle.com/cve/CVE-2026-39822.html", + "https://linux.oracle.com/errata/ELSA-2026-38995.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39822", + "https://pkg.go.dev/vuln/GO-2026-4970", + "https://www.cve.org/CVERecord?id=CVE-2026-39822" + ], + "PublishedDate": "2026-07-08T17:17:21.31Z", + "LastModifiedDate": "2026-07-13T14:54:26.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39836", + "VendorIDs": [ + "GO-2026-4971" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39836", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:36efd5a6b3fec3a782c0e76c1cddf7c2c02a3c79bcf371a164b92691871ab142", + "Title": "net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows", + "Description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/security/cve/CVE-2026-39836", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467810", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467811", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467813", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467823", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467825", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467826", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467827", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501", + "https://errata.rockylinux.org/RLSA-2026:22121", + "https://go.dev/cl/775320", + "https://go.dev/issue/79006", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39836.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39836", + "https://pkg.go.dev/vuln/GO-2026-4971", + "https://www.cve.org/CVERecord?id=CVE-2026-39836" + ], + "PublishedDate": "2026-05-07T20:16:43.593Z", + "LastModifiedDate": "2026-06-17T10:42:40.34Z" + }, + { + "VulnerabilityID": "CVE-2026-42499", + "VendorIDs": [ + "GO-2026-4977" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42499", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:8fca283e179658fa2bb144961ba5c8d1c355efdf9a18c112efd15fde9e754808", + "Title": "net/mail: golang: net/mail: Denial of Service via pathological email address parsing", + "Description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1046" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:17713", + "https://access.redhat.com/errata/RHSA-2026:17714", + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54552", + "https://access.redhat.com/errata/RHSA-2026:54555", + "https://access.redhat.com/errata/RHSA-2026:54583", + "https://access.redhat.com/errata/RHSA-2026:54602", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56785", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57487", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:57914", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59830", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:60023", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62260", + "https://access.redhat.com/errata/RHSA-2026:62406", + "https://access.redhat.com/errata/RHSA-2026:62407", + "https://access.redhat.com/errata/RHSA-2026:62753", + "https://access.redhat.com/errata/RHSA-2026:62754", + "https://access.redhat.com/errata/RHSA-2026:62803", + "https://access.redhat.com/errata/RHSA-2026:63022", + "https://access.redhat.com/errata/RHSA-2026:63163", + "https://access.redhat.com/errata/RHSA-2026:63332", + "https://access.redhat.com/errata/RHSA-2026:63636", + "https://access.redhat.com/errata/RHSA-2026:64818", + "https://access.redhat.com/errata/RHSA-2026:65116", + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65153", + "https://access.redhat.com/errata/RHSA-2026:65335", + "https://access.redhat.com/errata/RHSA-2026:65336", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:65895", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66327", + "https://access.redhat.com/security/cve/CVE-2026-42499", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/771520", + "https://go.dev/issue/78987", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-42499.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42499", + "https://pkg.go.dev/vuln/GO-2026-4977", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42499" + ], + "PublishedDate": "2026-05-07T20:16:44.54Z", + "LastModifiedDate": "2026-09-11T13:17:59.763Z" + }, + { + "VulnerabilityID": "CVE-2026-42504", + "VendorIDs": [ + "GO-2026-5038" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42504", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:294669388e15c82b7f04c63116c26a92e49698d1207a4f6f89db5e874cca26e4", + "Title": "mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header", + "Description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-42504", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/774481", + "https://go.dev/issue/79217", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-42504.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42504", + "https://pkg.go.dev/vuln/GO-2026-5038", + "https://www.cve.org/CVERecord?id=CVE-2026-42504" + ], + "PublishedDate": "2026-06-02T23:16:37.927Z", + "LastModifiedDate": "2026-07-22T19:10:00.12Z" + }, + { + "VulnerabilityID": "CVE-2026-56853", + "VendorIDs": [ + "GO-2026-6089" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56853", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:c3c843d202008fe00359a67415f4c40e1fd9fdd6237db89ef8498d29585952d1", + "Title": "net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service", + "Description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-56853", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/795540", + "https://go.dev/issue/80205", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56853.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56853", + "https://pkg.go.dev/vuln/GO-2026-6089", + "https://www.cve.org/CVERecord?id=CVE-2026-56853" + ], + "PublishedDate": "2026-08-13T22:17:22.093Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-56858", + "VendorIDs": [ + "GO-2026-6091" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56858", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:2aaa7161133b43ec213d88f6c71b8f5f4759a82dd57f8f701e17deb9d41baea2", + "Title": "html/template: golang: Go html/template: Cross-Site Scripting via pathological input", + "Description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 2, + "oracle-oval": 3, + "photon": 2, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", + "V3Score": 6.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-56858", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/807100", + "https://go.dev/issue/80435", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56858.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56858", + "https://pkg.go.dev/vuln/GO-2026-6091", + "https://www.cve.org/CVERecord?id=CVE-2026-56858" + ], + "PublishedDate": "2026-08-13T22:17:22.207Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-56859", + "VendorIDs": [ + "GO-2026-6088" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56859", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:7694a2d446635ff912fce524c5658ddc4515a267c9ed035bbecc7045afe748a2", + "Title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue", + "Description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-56859", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/803320", + "https://go.dev/issue/80481", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56859.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56859", + "https://pkg.go.dev/vuln/GO-2026-6088", + "https://www.cve.org/CVERecord?id=CVE-2026-56859" + ], + "PublishedDate": "2026-08-13T22:17:22.32Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-56860", + "VendorIDs": [ + "GO-2026-6218" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56860", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:43a53f81707a870c2106724fd1a8c5345c6abd1cc10f4293c5f7723fbfacb4a8", + "Title": "net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution", + "Description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 2, + "oracle-oval": 3, + "photon": 2, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:66364", + "https://access.redhat.com/security/cve/CVE-2026-56860", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-66364.html", + "https://errata.rockylinux.org/RLSA-2026:66364", + "https://go.dev/cl/803681", + "https://go.dev/issue/80494", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56860.html", + "https://linux.oracle.com/errata/ELSA-2026-66364-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56860", + "https://pkg.go.dev/vuln/GO-2026-6218", + "https://www.cve.org/CVERecord?id=CVE-2026-56860" + ], + "PublishedDate": "2026-08-13T22:17:22.44Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-56862", + "VendorIDs": [ + "GO-2026-6090" + ], + "PkgID": "stdlib@v1.24.2", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.2", + "UID": "8e7981434499a212" + }, + "InstalledVersion": "v1.24.2", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:cf67644788eb8e2f7556c241a8d1d5ff89079d85bfb2fb4555fd5fc794a857c2", + "DiffID": "sha256:9d4660f28d34d8712fa5a6d2a382d00799b8c9aae14ed032525df3a365ed32b5" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56862", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:931f3eeffae7d1f91c1bd369f1e5c30efd71391e7b479a317156297ec54cfac2", + "Title": "crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages", + "Description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:66364", + "https://access.redhat.com/security/cve/CVE-2026-56862", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-66364.html", + "https://errata.rockylinux.org/RLSA-2026:66364", + "https://go.dev/cl/804261", + "https://go.dev/issue/80528", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56862.html", + "https://linux.oracle.com/errata/ELSA-2026-66364-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56862", + "https://pkg.go.dev/vuln/GO-2026-6090", + "https://www.cve.org/CVERecord?id=CVE-2026-56862" + ], + "PublishedDate": "2026-08-13T22:17:22.55Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + } + ] + } + ] +} diff --git a/output/security/postgres-container-audit.json b/output/security/postgres-container-audit.json new file mode 100644 index 0000000..5d0b9dc --- /dev/null +++ b/output/security/postgres-container-audit.json @@ -0,0 +1,6387 @@ +{ + "SchemaVersion": 2, + "Trivy": { + "Version": "0.74.0" + }, + "ReportID": "01a0a031-5163-772d-a4fa-e9c174ed058b", + "CreatedAt": "2026-09-14T13:53:01.795473157Z", + "ArtifactID": "sha256:5e3704ea581305776a643c58dbedfc0cc2e72f31ae7a3a4b073fb87e48af539a", + "ArtifactName": "postgres:17-alpine", + "ArtifactType": "container_image", + "Metadata": { + "Size": 300003840, + "OS": { + "Family": "alpine", + "Name": "3.24.1" + }, + "ImageID": "sha256:18cfe3ef5e6815560c98237d6216d1e5119702fb0f3894c8785dd58b8bbe5d73", + "DiffIDs": [ + "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c", + "sha256:b2adc719066f2e72bc57ac86d624af3fac5dd2e605eb0c973e82a7de7a768226", + "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58", + "sha256:850d61e3d4a2ebb0f51637f13f51934a6a22be1b29d4795c27d73e50be07a54e", + "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99", + "sha256:28e87f320c566cac1f7dd501ae171a5193df42572321822ea3fce9af732d31e0", + "sha256:3760a7bba846724694304711cb42c53c6e44573e32ea580a8085cc6f45cfc2a0", + "sha256:65ba394136a046fdf332b728990d70ae7e01fe82eb8f3bd7a21dec4a786e402d", + "sha256:a2267e22cca23dcf497f8e341968a4ff363f7c826e165d878cccc6daa8f83242", + "sha256:3bdce6f822805ba4643019b2dfe2e1a0a38159d4288c81598c46d651aba47212" + ], + "RepoTags": [ + "postgres:17-alpine" + ], + "RepoDigests": [ + "postgres@sha256:18cfe3ef5e6815560c98237d6216d1e5119702fb0f3894c8785dd58b8bbe5d73" + ], + "Reference": "postgres:17-alpine", + "ImageConfig": { + "architecture": "amd64", + "created": "2026-08-13T19:17:35.122910679Z", + "history": [ + { + "created": "2026-06-16T00:01:29Z", + "created_by": "ADD alpine-minirootfs-3.24.1-x86_64.tar.gz / # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-06-16T00:01:29Z", + "created_by": "CMD [\"/bin/sh\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-08-13T19:15:15Z", + "created_by": "RUN /bin/sh -c set -eux; \taddgroup -g 70 -S postgres; \tadduser -u 70 -S -D -G postgres -H -h /var/lib/postgresql -s /bin/sh postgres; \tinstall --verbose --directory --owner postgres --group postgres --mode 1777 /var/lib/postgresql # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-08-13T19:15:18Z", + "created_by": "ENV GOSU_VERSION=1.19", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-08-13T19:15:18Z", + "created_by": "RUN /bin/sh -c set -eux; \t\tapk add --no-cache --virtual .gosu-deps \t\tca-certificates \t\tdpkg \t\tgnupg \t; \t\tdpkgArch=\"$(dpkg --print-architecture | awk -F- '{ print $NF }')\"; \twget -O /usr/local/bin/gosu \"https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$dpkgArch\"; \twget -O /usr/local/bin/gosu.asc \"https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$dpkgArch.asc\"; \t\texport GNUPGHOME=\"$(mktemp -d)\"; \tgpg --batch --keyserver hkps://keys.openpgp.org --recv-keys B42F6819007F00F88E364FD4036A9C25BF357DD4; \tgpg --batch --verify /usr/local/bin/gosu.asc /usr/local/bin/gosu; \tgpgconf --kill all; \trm -rf \"$GNUPGHOME\" /usr/local/bin/gosu.asc; \t\tapk del --no-network .gosu-deps; \t\tchmod +x /usr/local/bin/gosu; \tgosu --version; \tgosu nobody true # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-08-13T19:15:18Z", + "created_by": "ENV LANG=en_US.utf8", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-08-13T19:15:18Z", + "created_by": "RUN /bin/sh -c mkdir /docker-entrypoint-initdb.d # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-08-13T19:15:18Z", + "created_by": "ENV PG_MAJOR=17", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-08-13T19:15:18Z", + "created_by": "ENV PG_VERSION=17.11", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-08-13T19:15:18Z", + "created_by": "ENV PG_SHA256=dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-08-13T19:15:18Z", + "created_by": "ENV DOCKER_PG_LLVM_DEPS=llvm21-dev \t\tclang21", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-08-13T19:17:34Z", + "created_by": "RUN /bin/sh -c set -eux; \t\twget -O postgresql.tar.bz2 \"https://ftp.postgresql.org/pub/source/v$PG_VERSION/postgresql-$PG_VERSION.tar.bz2\"; \techo \"$PG_SHA256 *postgresql.tar.bz2\" | sha256sum -c -; \tmkdir -p /usr/src/postgresql; \ttar \t\t--extract \t\t--file postgresql.tar.bz2 \t\t--directory /usr/src/postgresql \t\t--strip-components 1 \t; \trm postgresql.tar.bz2; \t\tapk add --no-cache --virtual .build-deps \t\t$DOCKER_PG_LLVM_DEPS \t\tbison \t\tcoreutils \t\tdpkg-dev dpkg \t\tflex \t\tg++ \t\tgcc \t\tkrb5-dev \t\tlibc-dev \t\tlibedit-dev \t\tlibxml2-dev \t\tlibxslt-dev \t\tlinux-headers \t\tmake \t\topenldap-dev \t\topenssl-dev \t\tperl-dev \t\tperl-ipc-run \t\tperl-utils \t\tpython3-dev \t\ttcl-dev \t\tutil-linux-dev \t\tzlib-dev \t\ticu-dev \t\tlz4-dev \t\tzstd-dev \t; \t\tcd /usr/src/postgresql; \tawk '$1 == \"#define\" \u0026\u0026 $2 == \"DEFAULT_PGSOCKET_DIR\" \u0026\u0026 $3 == \"\\\"/tmp\\\"\" { $3 = \"\\\"/var/run/postgresql\\\"\"; print; next } { print }' src/include/pg_config_manual.h \u003e src/include/pg_config_manual.h.new; \tgrep '/var/run/postgresql' src/include/pg_config_manual.h.new; \tmv src/include/pg_config_manual.h.new src/include/pg_config_manual.h; \tgnuArch=\"$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)\"; \t\texport LLVM_CONFIG=\"/usr/lib/llvm21/bin/llvm-config\"; \texport CLANG=clang-21; \t\t./configure \t\t--enable-option-checking=fatal \t\t--build=\"$gnuArch\" \t\t--enable-integer-datetimes \t\t--enable-tap-tests \t\t--disable-rpath \t\t--with-uuid=e2fs \t\t--with-pgport=5432 \t\t--with-system-tzdata=/usr/share/zoneinfo \t\t--prefix=/usr/local \t\t--with-includes=/usr/local/include \t\t--with-libraries=/usr/local/lib \t\t--with-gssapi \t\t--with-icu \t\t--with-ldap \t\t--with-libxml \t\t--with-libxslt \t\t--with-llvm \t\t--with-lz4 \t\t--with-openssl \t\t--with-perl \t\t--with-python \t\t--with-tcl \t\t--with-zstd \t; \tmake -j \"$(nproc)\" world-bin; \tmake install-world-bin; \tmake -C contrib install; \t\trunDeps=\"$( \t\tscanelf --needed --nobanner --format '%n#p' --recursive /usr/local \t\t\t| tr ',' '\\n' \t\t\t| sort -u \t\t\t| awk 'system(\"[ -e /usr/local/lib/\" $1 \" ]\") == 0 { next } { print \"so:\" $1 }' \t\t\t| grep -v -e perl -e python -e tcl \t)\"; \tapk add --no-cache --virtual .postgresql-rundeps \t\t$runDeps \t\tbash \t\ttzdata \t\tzstd \t\ticu-data-full \t\t$([ \"$(apk --print-arch)\" != 'ppc64le' ] \u0026\u0026 echo 'nss_wrapper') \t; \tapk del --no-network .build-deps; \tcd /; \trm -rf \t\t/usr/src/postgresql \t\t/usr/local/share/doc \t\t/usr/local/share/man \t; \t\tpostgres --version # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-08-13T19:17:34Z", + "created_by": "RUN /bin/sh -c set -eux; \tcp -v /usr/local/share/postgresql/postgresql.conf.sample /usr/local/share/postgresql/postgresql.conf.sample.orig; \tsed -ri \"s!^#?(listen_addresses)\\s*=\\s*\\S+.*!\\1 = '*'!\" /usr/local/share/postgresql/postgresql.conf.sample; \tgrep -F \"listen_addresses = '*'\" /usr/local/share/postgresql/postgresql.conf.sample # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-08-13T19:17:34Z", + "created_by": "RUN /bin/sh -c install --verbose --directory --owner postgres --group postgres --mode 3777 /var/run/postgresql # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-08-13T19:17:34Z", + "created_by": "ENV PGDATA=/var/lib/postgresql/data", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-08-13T19:17:35Z", + "created_by": "RUN /bin/sh -c install --verbose --directory --owner postgres --group postgres --mode 1777 \"$PGDATA\" # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-08-13T19:17:35Z", + "created_by": "VOLUME [/var/lib/postgresql/data]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-08-13T19:17:35Z", + "created_by": "COPY docker-entrypoint.sh docker-ensure-initdb.sh /usr/local/bin/ # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-08-13T19:17:35Z", + "created_by": "RUN /bin/sh -c ln -sT docker-ensure-initdb.sh /usr/local/bin/docker-enforce-initdb.sh # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-08-13T19:17:35Z", + "created_by": "ENTRYPOINT [\"docker-entrypoint.sh\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-08-13T19:17:35Z", + "created_by": "STOPSIGNAL SIGINT", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-08-13T19:17:35Z", + "created_by": "EXPOSE map[5432/tcp:{}]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-08-13T19:17:35Z", + "created_by": "CMD [\"postgres\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + } + ], + "os": "linux", + "rootfs": { + "type": "layers", + "diff_ids": [ + "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c", + "sha256:b2adc719066f2e72bc57ac86d624af3fac5dd2e605eb0c973e82a7de7a768226", + "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58", + "sha256:850d61e3d4a2ebb0f51637f13f51934a6a22be1b29d4795c27d73e50be07a54e", + "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99", + "sha256:28e87f320c566cac1f7dd501ae171a5193df42572321822ea3fce9af732d31e0", + "sha256:3760a7bba846724694304711cb42c53c6e44573e32ea580a8085cc6f45cfc2a0", + "sha256:65ba394136a046fdf332b728990d70ae7e01fe82eb8f3bd7a21dec4a786e402d", + "sha256:a2267e22cca23dcf497f8e341968a4ff363f7c826e165d878cccc6daa8f83242", + "sha256:3bdce6f822805ba4643019b2dfe2e1a0a38159d4288c81598c46d651aba47212" + ] + }, + "config": { + "Cmd": [ + "postgres" + ], + "Entrypoint": [ + "docker-entrypoint.sh" + ], + "Env": [ + "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", + "GOSU_VERSION=1.19", + "LANG=en_US.utf8", + "PG_MAJOR=17", + "PG_VERSION=17.11", + "PG_SHA256=dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", + "DOCKER_PG_LLVM_DEPS=llvm21-dev \t\tclang21", + "PGDATA=/var/lib/postgresql/data" + ], + "Volumes": { + "/var/lib/postgresql/data": {} + }, + "WorkingDir": "/", + "ExposedPorts": { + "5432/tcp": {} + }, + "StopSignal": "SIGINT" + } + }, + "Layers": [ + { + "Size": 8697856, + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + { + "Size": 11264, + "Digest": "sha256:4d80c046a9c75283330c9ea2f7f3e5b3fbfe521c980e19d4164116dd95dfc730", + "DiffID": "sha256:b2adc719066f2e72bc57ac86d624af3fac5dd2e605eb0c973e82a7de7a768226" + }, + { + "Size": 1988096, + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + { + "Size": 1536, + "Digest": "sha256:a12187db4b1792bf47380df49cfd84fd703811abd04c5d84568001a484afbf2d", + "DiffID": "sha256:850d61e3d4a2ebb0f51637f13f51934a6a22be1b29d4795c27d73e50be07a54e" + }, + { + "Size": 289209344, + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + { + "Size": 66560, + "Digest": "sha256:75de48f507ff913f69fa75a49da59f83db0ece385f649eefa7bcde930a9b573e", + "DiffID": "sha256:28e87f320c566cac1f7dd501ae171a5193df42572321822ea3fce9af732d31e0" + }, + { + "Size": 2048, + "Digest": "sha256:d884d6f49732553e9690257554497e612cdcc1a6d83562fe08d582dec39e34e9", + "DiffID": "sha256:3760a7bba846724694304711cb42c53c6e44573e32ea580a8085cc6f45cfc2a0" + }, + { + "Size": 3072, + "Digest": "sha256:b36c1b75fdb7939cb2a580ab05adfa65c8b118425f42cd8811cf632f37bb8616", + "DiffID": "sha256:65ba394136a046fdf332b728990d70ae7e01fe82eb8f3bd7a21dec4a786e402d" + }, + { + "Size": 20992, + "Digest": "sha256:f070a657786685e37135e54207238cd1580e6869c6f5e8e6da85b2c9871ab31e", + "DiffID": "sha256:a2267e22cca23dcf497f8e341968a4ff363f7c826e165d878cccc6daa8f83242" + }, + { + "Size": 3072, + "Digest": "sha256:7f3590dcd8434508e0c0bd953c80ed459f14f3a9005a3ac945bdb855abe58389", + "DiffID": "sha256:3bdce6f822805ba4643019b2dfe2e1a0a38159d4288c81598c46d651aba47212" + } + ] + }, + "Results": [ + { + "Target": "postgres:17-alpine (alpine 3.24.1)", + "Class": "os-pkgs", + "Type": "alpine", + "Packages": [ + { + "ID": ".postgresql-rundeps@20260813.191733", + "Name": ".postgresql-rundeps", + "Identifier": { + "PURL": "pkg:apk/alpine/.postgresql-rundeps@20260813.191733?arch=noarch\u0026distro=3.24.1", + "UID": "3e859114216d029b" + }, + "Version": "20260813.191733", + "Arch": "noarch", + "DependsOn": [ + "bash@5.3.9-r1", + "icu-data-full@78.1-r0", + "icu-libs@78.1-r0", + "krb5-libs@1.22.2-r1", + "libcrypto3@3.5.7-r0", + "libedit@20260508.3.1-r1", + "libgcc@15.2.0-r5", + "libldap@2.6.14-r0", + "libssl3@3.5.7-r0", + "libstdc++@15.2.0-r5", + "libuuid@2.42.1-r0", + "libxml2@2.13.9-r2", + "libxslt@1.1.43-r3", + "llvm21-libs@21.1.8-r1", + "lz4-libs@1.10.0-r1", + "musl@1.2.6-r2", + "nss_wrapper@1.1.12-r1", + "tzdata@2026c-r0", + "zlib@1.3.2-r0", + "zstd-libs@1.5.7-r2", + "zstd@1.5.7-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:e22124318c23791fa7e066f4281f078493b426be", + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-baselayout@3.7.2-r1", + "Name": "alpine-baselayout", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-baselayout@3.7.2-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "1b9c543300f8073e" + }, + "Version": "3.7.2-r1", + "Arch": "x86_64", + "SrcName": "alpine-baselayout", + "SrcVersion": "3.7.2-r1", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "alpine-baselayout-data@3.7.2-r1", + "busybox-binsh@1.37.0-r31" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:f0fcfdc2f4da058af6473bc45c4eab62916225b2", + "InstalledFiles": [ + "etc/motd", + "etc/crontabs/root", + "etc/modprobe.d/aliases.conf", + "etc/modprobe.d/blacklist.conf", + "etc/modprobe.d/i386.conf", + "etc/profile.d/20locale.sh", + "etc/profile.d/README", + "etc/profile.d/color_prompt.sh.disabled", + "usr/lib/sysctl.d/00-alpine.conf", + "var/lock", + "var/run", + "var/spool/mail", + "var/spool/cron/crontabs" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-baselayout-data@3.7.2-r1", + "Name": "alpine-baselayout-data", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-baselayout-data@3.7.2-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "fcc3cd90122d8aa7" + }, + "Version": "3.7.2-r1", + "Arch": "x86_64", + "SrcName": "alpine-baselayout", + "SrcVersion": "3.7.2-r1", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:c6f9bded17d844b6f1b0bb5766d2c35c0d5c8508", + "InstalledFiles": [ + "etc/fstab", + "etc/group", + "etc/hostname", + "etc/hosts", + "etc/inittab", + "etc/modules", + "etc/mtab", + "etc/nsswitch.conf", + "etc/passwd", + "etc/profile", + "etc/protocols", + "etc/services", + "etc/shadow", + "etc/shells", + "etc/sysctl.conf" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-keys@2.6-r0", + "Name": "alpine-keys", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-keys@2.6-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "cb1f6c8fa74713e0" + }, + "Version": "2.6-r0", + "Arch": "x86_64", + "SrcName": "alpine-keys", + "SrcVersion": "2.6-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:d8d6b80e53c059a77e4915da78ba964f3ffea240", + "InstalledFiles": [ + "etc/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "etc/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", + "etc/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub", + "usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub", + "usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub", + "usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", + "usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub", + "usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", + "usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub", + "usr/share/apk/keys/loongarch64/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub", + "usr/share/apk/keys/mips64/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub", + "usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub", + "usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub", + "usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub", + "usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub", + "usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub", + "usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub", + "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub", + "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub", + "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", + "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-release@3.24.1-r0", + "Name": "alpine-release", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-release@3.24.1-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "6cfad6f36e1f31aa" + }, + "Version": "3.24.1-r0", + "Arch": "x86_64", + "SrcName": "alpine-base", + "SrcVersion": "3.24.1-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "alpine-keys@2.6-r0" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:bc6912a25cdc7733e0035ed509eceaa4026946e3", + "InstalledFiles": [ + "etc/alpine-release", + "etc/issue", + "etc/os-release", + "etc/secfixes.d/alpine", + "usr/lib/os-release" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "apk-tools@3.0.6-r0", + "Name": "apk-tools", + "Identifier": { + "PURL": "pkg:apk/alpine/apk-tools@3.0.6-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "c6097cc137f3de8c" + }, + "Version": "3.0.6-r0", + "Arch": "x86_64", + "SrcName": "apk-tools", + "SrcVersion": "3.0.6-r0", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "ca-certificates-bundle@20260611-r0", + "libapk@3.0.6-r0", + "libcrypto3@3.5.7-r0", + "musl@1.2.6-r2", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:043333589798a1f52e09ae63f026c6c8fa676d34", + "InstalledFiles": [ + "sbin/apk" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "bash@5.3.9-r1", + "Name": "bash", + "Identifier": { + "PURL": "pkg:apk/alpine/bash@5.3.9-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "89d1544dc9bae858" + }, + "Version": "5.3.9-r1", + "Arch": "x86_64", + "SrcName": "bash", + "SrcVersion": "5.3.9-r1", + "Licenses": [ + "GPL-3.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r31", + "musl@1.2.6-r2", + "readline@8.3.3-r1" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:2ce9606f1c31438297b40df5875dbceb66afb675", + "InstalledFiles": [ + "bin/bash", + "etc/bash/bashrc", + "etc/profile.d/00-bashrc.sh", + "usr/lib/bash/accept", + "usr/lib/bash/basename", + "usr/lib/bash/chmod", + "usr/lib/bash/csv", + "usr/lib/bash/cut", + "usr/lib/bash/dirname", + "usr/lib/bash/dsv", + "usr/lib/bash/fdflags", + "usr/lib/bash/finfo", + "usr/lib/bash/fltexpr", + "usr/lib/bash/getconf", + "usr/lib/bash/head", + "usr/lib/bash/id", + "usr/lib/bash/kv", + "usr/lib/bash/ln", + "usr/lib/bash/logname", + "usr/lib/bash/mkdir", + "usr/lib/bash/mkfifo", + "usr/lib/bash/mktemp", + "usr/lib/bash/mypid", + "usr/lib/bash/pathchk", + "usr/lib/bash/print", + "usr/lib/bash/printenv", + "usr/lib/bash/push", + "usr/lib/bash/realpath", + "usr/lib/bash/rm", + "usr/lib/bash/rmdir", + "usr/lib/bash/seq", + "usr/lib/bash/setpgid", + "usr/lib/bash/sleep", + "usr/lib/bash/stat", + "usr/lib/bash/strftime", + "usr/lib/bash/strptime", + "usr/lib/bash/sync", + "usr/lib/bash/tee", + "usr/lib/bash/truefalse", + "usr/lib/bash/tty", + "usr/lib/bash/uname", + "usr/lib/bash/unlink", + "usr/lib/bash/whoami" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "busybox@1.37.0-r31", + "Name": "busybox", + "Identifier": { + "PURL": "pkg:apk/alpine/busybox@1.37.0-r31?arch=x86_64\u0026distro=3.24.1", + "UID": "771020c43c8440bf" + }, + "Version": "1.37.0-r31", + "Arch": "x86_64", + "SrcName": "busybox", + "SrcVersion": "1.37.0-r31", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:b5405ebc02f7dd8be95b6265c54b243d5456ab8f", + "InstalledFiles": [ + "bin/busybox", + "etc/securetty", + "etc/busybox-paths.d/busybox", + "etc/logrotate.d/acpid", + "etc/network/if-up.d/dad", + "etc/udhcpc/udhcpc.conf", + "usr/share/udhcpc/default.script" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "busybox-binsh@1.37.0-r31", + "Name": "busybox-binsh", + "Identifier": { + "PURL": "pkg:apk/alpine/busybox-binsh@1.37.0-r31?arch=x86_64\u0026distro=3.24.1", + "UID": "1ec8a3d5d2b63297" + }, + "Version": "1.37.0-r31", + "Arch": "x86_64", + "SrcName": "busybox", + "SrcVersion": "1.37.0-r31", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", + "DependsOn": [ + "busybox@1.37.0-r31" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:5cbd14acc6f1804c5bac6c77dc2c492f010b0fc7", + "InstalledFiles": [ + "bin/sh" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ca-certificates-bundle@20260611-r0", + "Name": "ca-certificates-bundle", + "Identifier": { + "PURL": "pkg:apk/alpine/ca-certificates-bundle@20260611-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "20337c2ea28bef28" + }, + "Version": "20260611-r0", + "Arch": "x86_64", + "SrcName": "ca-certificates", + "SrcVersion": "20260611-r0", + "Licenses": [ + "MPL-2.0", + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:c9534a03750bdfae341f10969016090fc11febbd", + "InstalledFiles": [ + "etc/ssl/cert.pem", + "etc/ssl/certs/ca-certificates.crt", + "etc/ssl1.1/cert.pem", + "etc/ssl1.1/certs" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "gdbm@1.26-r0", + "Name": "gdbm", + "Identifier": { + "PURL": "pkg:apk/alpine/gdbm@1.26-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "5eb1a3f86262ca77" + }, + "Version": "1.26-r0", + "Arch": "x86_64", + "SrcName": "gdbm", + "SrcVersion": "1.26-r0", + "Licenses": [ + "GPL-3.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:619493d8124fe49a8ee1d8f7a1372cf7e3977337", + "InstalledFiles": [ + "usr/lib/libgdbm.so.6", + "usr/lib/libgdbm.so.6.0.0", + "usr/lib/libgdbm_compat.so.4", + "usr/lib/libgdbm_compat.so.4.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "icu-data-full@78.1-r0", + "Name": "icu-data-full", + "Identifier": { + "PURL": "pkg:apk/alpine/icu-data-full@78.1-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "4fa30f43b2e5f036" + }, + "Version": "78.1-r0", + "Arch": "x86_64", + "SrcName": "icu", + "SrcVersion": "78.1-r0", + "Licenses": [ + "ICU" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:1a2db5e6bc16c62c85c29cfc8897570f9051cf14", + "InstalledFiles": [ + "usr/share/icu/78.1/icudt78l.dat" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "icu-libs@78.1-r0", + "Name": "icu-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/icu-libs@78.1-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "66c4aa79b293e4ff" + }, + "Version": "78.1-r0", + "Arch": "x86_64", + "SrcName": "icu", + "SrcVersion": "78.1-r0", + "Licenses": [ + "ICU" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "icu-data-full@78.1-r0", + "libgcc@15.2.0-r5", + "libstdc++@15.2.0-r5", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:46bd3617f6d112f035d806d24c5cf8ea6e597f50", + "InstalledFiles": [ + "usr/lib/libicudata.so.78", + "usr/lib/libicudata.so.78.1", + "usr/lib/libicui18n.so.78", + "usr/lib/libicui18n.so.78.1", + "usr/lib/libicuio.so.78", + "usr/lib/libicuio.so.78.1", + "usr/lib/libicuuc.so.78", + "usr/lib/libicuuc.so.78.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "keyutils-libs@1.6.3-r4", + "Name": "keyutils-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/keyutils-libs@1.6.3-r4?arch=x86_64\u0026distro=3.24.1", + "UID": "a1a29120eb342032" + }, + "Version": "1.6.3-r4", + "Arch": "x86_64", + "SrcName": "keyutils", + "SrcVersion": "1.6.3-r4", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-2.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:b7331c96f077fc3522ee4361a441d1097204cd90", + "InstalledFiles": [ + "usr/lib/libkeyutils.so.1", + "usr/lib/libkeyutils.so.1.10" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "krb5-conf@1.0-r2", + "Name": "krb5-conf", + "Identifier": { + "PURL": "pkg:apk/alpine/krb5-conf@1.0-r2?arch=x86_64\u0026distro=3.24.1", + "UID": "e7cf94ba8b6dbc33" + }, + "Version": "1.0-r2", + "Arch": "x86_64", + "SrcName": "krb5-conf", + "SrcVersion": "1.0-r2", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:40a11e0690a59e110367b62a80661024e9942a2d", + "InstalledFiles": [ + "etc/krb5.conf" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "krb5-libs@1.22.2-r1", + "Name": "krb5-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/krb5-libs@1.22.2-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "b2a26eefd488c92b" + }, + "Version": "1.22.2-r1", + "Arch": "x86_64", + "SrcName": "krb5", + "SrcVersion": "1.22.2-r1", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "keyutils-libs@1.6.3-r4", + "krb5-conf@1.0-r2", + "libcom_err@1.47.4-r0", + "libcrypto3@3.5.7-r0", + "libssl3@3.5.7-r0", + "libverto@0.3.2-r2", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:ef02346e21b817ff379e4601e5b1fc9760e5e31a", + "InstalledFiles": [ + "usr/lib/libgssapi_krb5.so.2", + "usr/lib/libgssapi_krb5.so.2.2", + "usr/lib/libgssrpc.so.4", + "usr/lib/libgssrpc.so.4.2", + "usr/lib/libk5crypto.so.3", + "usr/lib/libk5crypto.so.3.1", + "usr/lib/libkadm5clnt_mit.so.12", + "usr/lib/libkadm5clnt_mit.so.12.0", + "usr/lib/libkadm5srv_mit.so.12", + "usr/lib/libkadm5srv_mit.so.12.0", + "usr/lib/libkdb5.so.10", + "usr/lib/libkdb5.so.10.0", + "usr/lib/libkrad.so.0", + "usr/lib/libkrad.so.0.0", + "usr/lib/libkrb5.so.3", + "usr/lib/libkrb5.so.3.3", + "usr/lib/libkrb5support.so.0", + "usr/lib/libkrb5support.so.0.1", + "usr/lib/krb5/plugins/kdb/db2.so", + "usr/lib/krb5/plugins/preauth/otp.so", + "usr/lib/krb5/plugins/preauth/spake.so", + "usr/lib/krb5/plugins/preauth/test.so", + "usr/lib/krb5/plugins/tls/k5tls.so" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libapk@3.0.6-r0", + "Name": "libapk", + "Identifier": { + "PURL": "pkg:apk/alpine/libapk@3.0.6-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "99b3039c6c4890c4" + }, + "Version": "3.0.6-r0", + "Arch": "x86_64", + "SrcName": "apk-tools", + "SrcVersion": "3.0.6-r0", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libcrypto3@3.5.7-r0", + "libssl3@3.5.7-r0", + "musl@1.2.6-r2", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:523a8f58104589f74f743d501c81bf6517155378", + "InstalledFiles": [ + "usr/lib/libapk.so.3.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libcom_err@1.47.4-r0", + "Name": "libcom_err", + "Identifier": { + "PURL": "pkg:apk/alpine/libcom_err@1.47.4-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "3fc35a3f66d192af" + }, + "Version": "1.47.4-r0", + "Arch": "x86_64", + "SrcName": "e2fsprogs", + "SrcVersion": "1.47.4-r0", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-2.0-or-later", + "BSD-3-Clause", + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:4b9fb5899ea0b1c0cfbb2a2c5952704437d4ecef", + "InstalledFiles": [ + "usr/lib/libcom_err.so.2", + "usr/lib/libcom_err.so.2.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libcrypto3@3.5.7-r0", + "Name": "libcrypto3", + "Identifier": { + "PURL": "pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "9ce2cdb3f0bf014b" + }, + "Version": "3.5.7-r0", + "Arch": "x86_64", + "SrcName": "openssl", + "SrcVersion": "3.5.7-r0", + "Licenses": [ + "Apache-2.0" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:481afbc52bcf06f2316c93a0a81ce8f72bed503e", + "InstalledFiles": [ + "etc/ssl/ct_log_list.cnf", + "etc/ssl/ct_log_list.cnf.dist", + "etc/ssl/openssl.cnf", + "etc/ssl/openssl.cnf.dist", + "usr/lib/libcrypto.so.3", + "usr/lib/engines-3/afalg.so", + "usr/lib/engines-3/capi.so", + "usr/lib/engines-3/loader_attic.so", + "usr/lib/engines-3/padlock.so", + "usr/lib/ossl-modules/legacy.so" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libedit@20260508.3.1-r1", + "Name": "libedit", + "Identifier": { + "PURL": "pkg:apk/alpine/libedit@20260508.3.1-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "98a763e822f29606" + }, + "Version": "20260508.3.1-r1", + "Arch": "x86_64", + "SrcName": "libedit", + "SrcVersion": "20260508.3.1-r1", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e", + "DependsOn": [ + "libncursesw@6.6_p20260516-r0", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:4084f8ff8e83fe17ce0c9ec3f313604d6adc7481", + "InstalledFiles": [ + "usr/lib/libedit.so.0", + "usr/lib/libedit.so.0.0.77" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libffi@3.5.2-r1", + "Name": "libffi", + "Identifier": { + "PURL": "pkg:apk/alpine/libffi@3.5.2-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "d3eaa921287b1ccd" + }, + "Version": "3.5.2-r1", + "Arch": "x86_64", + "SrcName": "libffi", + "SrcVersion": "3.5.2-r1", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:2f7b261f7fcecc4eebd8b330e7f6fb80713bfe3a", + "InstalledFiles": [ + "usr/lib/libffi.so.8", + "usr/lib/libffi.so.8.2.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libgcc@15.2.0-r5", + "Name": "libgcc", + "Identifier": { + "PURL": "pkg:apk/alpine/libgcc@15.2.0-r5?arch=x86_64\u0026distro=3.24.1", + "UID": "8cf3d813d20beeee" + }, + "Version": "15.2.0-r5", + "Arch": "x86_64", + "SrcName": "gcc", + "SrcVersion": "15.2.0-r5", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-2.1-or-later" + ], + "Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:379c156c53e0cc140e87c79c0a3dd22b6ee51552", + "InstalledFiles": [ + "usr/lib/libgcc_s.so.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libldap@2.6.14-r0", + "Name": "libldap", + "Identifier": { + "PURL": "pkg:apk/alpine/libldap@2.6.14-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "2094cbf3bb65575a" + }, + "Version": "2.6.14-r0", + "Arch": "x86_64", + "SrcName": "openldap", + "SrcVersion": "2.6.14-r0", + "Licenses": [ + "OLDAP-2.8" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libcrypto3@3.5.7-r0", + "libsasl@2.1.28-r9", + "libssl3@3.5.7-r0", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:112ff31072f41119840e739c4195b6f2489fe048", + "InstalledFiles": [ + "etc/openldap/ldap.conf", + "usr/lib/liblber.so.2", + "usr/lib/liblber.so.2.0.200", + "usr/lib/libldap.so.2", + "usr/lib/libldap.so.2.0.200" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libncursesw@6.6_p20260516-r0", + "Name": "libncursesw", + "Identifier": { + "PURL": "pkg:apk/alpine/libncursesw@6.6_p20260516-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "e8939f45e2191bcc" + }, + "Version": "6.6_p20260516-r0", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.6_p20260516-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Milan P. Stanić \u003cmps@arvanta.net\u003e", + "DependsOn": [ + "musl@1.2.6-r2", + "ncurses-terminfo-base@6.6_p20260516-r0" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:9f318e6e324d6827274829194cf6ac6afbaded12", + "InstalledFiles": [ + "usr/lib/libncursesw.so.6", + "usr/lib/libncursesw.so.6.6" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libsasl@2.1.28-r9", + "Name": "libsasl", + "Identifier": { + "PURL": "pkg:apk/alpine/libsasl@2.1.28-r9?arch=x86_64\u0026distro=3.24.1", + "UID": "28cd83afcf08300b" + }, + "Version": "2.1.28-r9", + "Arch": "x86_64", + "SrcName": "cyrus-sasl", + "SrcVersion": "2.1.28-r9", + "Licenses": [ + "BSD-3-Clause-Attribution", + "BSD-4-Clause" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "gdbm@1.26-r0", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:422ebe8defd4a2d2aaea34662f6ff853cfc2f95f", + "InstalledFiles": [ + "usr/lib/libsasl2.so.3", + "usr/lib/libsasl2.so.3.0.0", + "usr/lib/sasl2/libanonymous.so", + "usr/lib/sasl2/libanonymous.so.3", + "usr/lib/sasl2/libanonymous.so.3.0.0", + "usr/lib/sasl2/libplain.so", + "usr/lib/sasl2/libplain.so.3", + "usr/lib/sasl2/libplain.so.3.0.0", + "usr/lib/sasl2/libsasldb.so", + "usr/lib/sasl2/libsasldb.so.3", + "usr/lib/sasl2/libsasldb.so.3.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libssl3@3.5.7-r0", + "Name": "libssl3", + "Identifier": { + "PURL": "pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "a25152af95b643e0" + }, + "Version": "3.5.7-r0", + "Arch": "x86_64", + "SrcName": "openssl", + "SrcVersion": "3.5.7-r0", + "Licenses": [ + "Apache-2.0" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libcrypto3@3.5.7-r0", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:240c8252d1ca145873c03c997966698eb509f745", + "InstalledFiles": [ + "usr/lib/libssl.so.3" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libstdc++@15.2.0-r5", + "Name": "libstdc++", + "Identifier": { + "PURL": "pkg:apk/alpine/libstdc%2B%2B@15.2.0-r5?arch=x86_64\u0026distro=3.24.1", + "UID": "2eed307edf277aae" + }, + "Version": "15.2.0-r5", + "Arch": "x86_64", + "SrcName": "gcc", + "SrcVersion": "15.2.0-r5", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-2.1-or-later" + ], + "Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e", + "DependsOn": [ + "libgcc@15.2.0-r5", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:5f7a2ad7646128ba02cc0d6fb94672b6845648d5", + "InstalledFiles": [ + "usr/lib/libstdc++.so.6", + "usr/lib/libstdc++.so.6.0.34" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libuuid@2.42.1-r0", + "Name": "libuuid", + "Identifier": { + "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "61e289a52fcab6f6" + }, + "Version": "2.42.1-r0", + "Arch": "x86_64", + "SrcName": "util-linux", + "SrcVersion": "2.42.1-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:6acb0e27112dfb784e6f7ccceb0e968fafa09713", + "InstalledFiles": [ + "usr/lib/libuuid.so.1", + "usr/lib/libuuid.so.1.3.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libverto@0.3.2-r2", + "Name": "libverto", + "Identifier": { + "PURL": "pkg:apk/alpine/libverto@0.3.2-r2?arch=x86_64\u0026distro=3.24.1", + "UID": "9df4321a283a6cf6" + }, + "Version": "0.3.2-r2", + "Arch": "x86_64", + "SrcName": "libverto", + "SrcVersion": "0.3.2-r2", + "Licenses": [ + "MIT" + ], + "Maintainer": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:73233059338142e4ac6d8fb8bb0074e93da75dc1", + "InstalledFiles": [ + "usr/lib/libverto.so.1", + "usr/lib/libverto.so.1.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxml2@2.13.9-r2", + "Name": "libxml2", + "Identifier": { + "PURL": "pkg:apk/alpine/libxml2@2.13.9-r2?arch=x86_64\u0026distro=3.24.1", + "UID": "661e2a4b0a2b6c43" + }, + "Version": "2.13.9-r2", + "Arch": "x86_64", + "SrcName": "libxml2", + "SrcVersion": "2.13.9-r2", + "Licenses": [ + "MIT" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2", + "xz-libs@5.8.3-r0", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:c2c2cb44647ddc8c82ae78c8aca9bd4ad5a736da", + "InstalledFiles": [ + "usr/lib/libxml2.so.2", + "usr/lib/libxml2.so.2.13.9" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxslt@1.1.43-r3", + "Name": "libxslt", + "Identifier": { + "PURL": "pkg:apk/alpine/libxslt@1.1.43-r3?arch=x86_64\u0026distro=3.24.1", + "UID": "2810f2fbfcee454a" + }, + "Version": "1.1.43-r3", + "Arch": "x86_64", + "SrcName": "libxslt", + "SrcVersion": "1.1.43-r3", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libxml2@2.13.9-r2", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:a78a1c96aa4f4a763ab8d2eeb285734c0387eb31", + "InstalledFiles": [ + "usr/bin/xsltproc", + "usr/lib/libexslt.so.0", + "usr/lib/libexslt.so.0.8.24", + "usr/lib/libxslt.so.1", + "usr/lib/libxslt.so.1.1.43" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "llvm21-libs@21.1.8-r1", + "Name": "llvm21-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/llvm21-libs@21.1.8-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "b4a6fa05ae868a0d" + }, + "Version": "21.1.8-r1", + "Arch": "x86_64", + "SrcName": "llvm21", + "SrcVersion": "21.1.8-r1", + "Licenses": [ + "Apache-2.0" + ], + "Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e", + "DependsOn": [ + "libffi@3.5.2-r1", + "libgcc@15.2.0-r5", + "libstdc++@15.2.0-r5", + "libxml2@2.13.9-r2", + "musl@1.2.6-r2", + "zlib@1.3.2-r0", + "zstd-libs@1.5.7-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:d9f9cafee3a86cc6103c92614ea769b3a169cff3", + "InstalledFiles": [ + "usr/lib/libLLVM-21.so", + "usr/lib/libLLVM.so.21.1", + "usr/lib/llvm21/lib/libLLVM.so.21.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "lz4-libs@1.10.0-r1", + "Name": "lz4-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/lz4-libs@1.10.0-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "697c5d416b5775fb" + }, + "Version": "1.10.0-r1", + "Arch": "x86_64", + "SrcName": "lz4", + "SrcVersion": "1.10.0-r1", + "Licenses": [ + "BSD-2-Clause", + "GPL-2.0-or-later" + ], + "Maintainer": "Stuart Cardall \u003cdeveloper@it-offshore.co.uk\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:d63bb2e1707aa4ca0b75a867706ea03df70bc5bd", + "InstalledFiles": [ + "usr/lib/liblz4.so.1", + "usr/lib/liblz4.so.1.10.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "musl@1.2.6-r2", + "Name": "musl", + "Identifier": { + "PURL": "pkg:apk/alpine/musl@1.2.6-r2?arch=x86_64\u0026distro=3.24.1", + "UID": "1f8cb44befe503d4" + }, + "Version": "1.2.6-r2", + "Arch": "x86_64", + "SrcName": "musl", + "SrcVersion": "1.2.6-r2", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:0f7e5827e4e1a73631beda27b78431a8ba240e05", + "InstalledFiles": [ + "lib/ld-musl-x86_64.so.1", + "lib/libc.musl-x86_64.so.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "musl-utils@1.2.6-r2", + "Name": "musl-utils", + "Identifier": { + "PURL": "pkg:apk/alpine/musl-utils@1.2.6-r2?arch=x86_64\u0026distro=3.24.1", + "UID": "4497482ec1d943e1" + }, + "Version": "1.2.6-r2", + "Arch": "x86_64", + "SrcName": "musl", + "SrcVersion": "1.2.6-r2", + "Licenses": [ + "MIT", + "BSD-2-Clause", + "GPL-2.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2", + "scanelf@1.3.9-r1" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:75ada3c48d63ec5d87c42fdf934a3fdd11298dc5", + "InstalledFiles": [ + "sbin/ldconfig", + "usr/bin/getconf", + "usr/bin/getent", + "usr/bin/iconv", + "usr/bin/ldd" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ncurses-terminfo-base@6.6_p20260516-r0", + "Name": "ncurses-terminfo-base", + "Identifier": { + "PURL": "pkg:apk/alpine/ncurses-terminfo-base@6.6_p20260516-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "e7fac5c6a6e9ae8" + }, + "Version": "6.6_p20260516-r0", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.6_p20260516-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Milan P. Stanić \u003cmps@arvanta.net\u003e", + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:9d551d828e9c8ee52c5801c1d6046828ebf15752", + "InstalledFiles": [ + "etc/terminfo/a/alacritty", + "etc/terminfo/a/ansi", + "etc/terminfo/d/dumb", + "etc/terminfo/g/gnome", + "etc/terminfo/g/gnome-256color", + "etc/terminfo/k/konsole", + "etc/terminfo/k/konsole-256color", + "etc/terminfo/k/konsole-linux", + "etc/terminfo/l/linux", + "etc/terminfo/p/putty", + "etc/terminfo/p/putty-256color", + "etc/terminfo/r/rxvt", + "etc/terminfo/r/rxvt-256color", + "etc/terminfo/s/screen", + "etc/terminfo/s/screen-256color", + "etc/terminfo/s/st-0.6", + "etc/terminfo/s/st-0.7", + "etc/terminfo/s/st-0.8", + "etc/terminfo/s/st-0.8.5", + "etc/terminfo/s/st-16color", + "etc/terminfo/s/st-256color", + "etc/terminfo/s/st-direct", + "etc/terminfo/s/sun", + "etc/terminfo/t/terminator", + "etc/terminfo/t/terminology", + "etc/terminfo/t/terminology-0.6.1", + "etc/terminfo/t/terminology-1.0.0", + "etc/terminfo/t/terminology-1.8.1", + "etc/terminfo/t/tmux", + "etc/terminfo/t/tmux-256color", + "etc/terminfo/v/vt100", + "etc/terminfo/v/vt102", + "etc/terminfo/v/vt200", + "etc/terminfo/v/vt220", + "etc/terminfo/v/vt52", + "etc/terminfo/v/vte", + "etc/terminfo/v/vte-256color", + "etc/terminfo/x/xterm", + "etc/terminfo/x/xterm-256color", + "etc/terminfo/x/xterm-color", + "etc/terminfo/x/xterm-xfree86" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nss_wrapper@1.1.12-r1", + "Name": "nss_wrapper", + "Identifier": { + "PURL": "pkg:apk/alpine/nss_wrapper@1.1.12-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "da8371470b181c32" + }, + "Version": "1.1.12-r1", + "Arch": "x86_64", + "SrcName": "nss_wrapper", + "SrcVersion": "1.1.12-r1", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Wolfgang Walther \u003copensource@technowledgy.de\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:46b34dd323a8388eb2480dc65ee56d9179148ffe", + "InstalledFiles": [ + "usr/lib/libnss_wrapper.so", + "usr/lib/libnss_wrapper.so.0", + "usr/lib/libnss_wrapper.so.0.3.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "readline@8.3.3-r1", + "Name": "readline", + "Identifier": { + "PURL": "pkg:apk/alpine/readline@8.3.3-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "f50058781c93e1f2" + }, + "Version": "8.3.3-r1", + "Arch": "x86_64", + "SrcName": "readline", + "SrcVersion": "8.3.3-r1", + "Licenses": [ + "GPL-3.0-or-later" + ], + "Maintainer": "qaqland \u003cqaq@qaq.land\u003e", + "DependsOn": [ + "libncursesw@6.6_p20260516-r0", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:945b16e378bc00e44d89d4de8124bba7647fdf4d", + "InstalledFiles": [ + "etc/inputrc", + "usr/lib/libreadline.so.8", + "usr/lib/libreadline.so.8.3" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "scanelf@1.3.9-r1", + "Name": "scanelf", + "Identifier": { + "PURL": "pkg:apk/alpine/scanelf@1.3.9-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "936394657a1626fb" + }, + "Version": "1.3.9-r1", + "Arch": "x86_64", + "SrcName": "pax-utils", + "SrcVersion": "1.3.9-r1", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:013f903d0ba219673aebbdd04f74bb5ed82b01f0", + "InstalledFiles": [ + "usr/bin/scanelf" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ssl_client@1.37.0-r31", + "Name": "ssl_client", + "Identifier": { + "PURL": "pkg:apk/alpine/ssl_client@1.37.0-r31?arch=x86_64\u0026distro=3.24.1", + "UID": "2884df80ae89778e" + }, + "Version": "1.37.0-r31", + "Arch": "x86_64", + "SrcName": "busybox", + "SrcVersion": "1.37.0-r31", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", + "DependsOn": [ + "libcrypto3@3.5.7-r0", + "libssl3@3.5.7-r0", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:c220f4a5125a313af733e98def94132bb1e9d40d", + "InstalledFiles": [ + "usr/bin/ssl_client" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "tzdata@2026c-r0", + "Name": "tzdata", + "Identifier": { + "PURL": "pkg:apk/alpine/tzdata@2026c-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "52c6b50eff629f9d" + }, + "Version": "2026c-r0", + "Arch": "x86_64", + "SrcName": "tzdata", + "SrcVersion": "2026c-r0", + "Licenses": [ + "Public-Domain" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:61f7544ecd8dd63eac23fe3e645702fda92ef02a", + "InstalledFiles": [ + "usr/share/zoneinfo/CET", + "usr/share/zoneinfo/CST6CDT", + "usr/share/zoneinfo/Cuba", + "usr/share/zoneinfo/EET", + "usr/share/zoneinfo/EST", + "usr/share/zoneinfo/EST5EDT", + "usr/share/zoneinfo/Egypt", + "usr/share/zoneinfo/Eire", + "usr/share/zoneinfo/Factory", + "usr/share/zoneinfo/GB", + "usr/share/zoneinfo/GB-Eire", + "usr/share/zoneinfo/GMT", + "usr/share/zoneinfo/GMT+0", + "usr/share/zoneinfo/GMT-0", + "usr/share/zoneinfo/GMT0", + "usr/share/zoneinfo/Greenwich", + "usr/share/zoneinfo/HST", + "usr/share/zoneinfo/Hongkong", + "usr/share/zoneinfo/Iceland", + "usr/share/zoneinfo/Iran", + "usr/share/zoneinfo/Israel", + "usr/share/zoneinfo/Jamaica", + "usr/share/zoneinfo/Japan", + "usr/share/zoneinfo/Kwajalein", + "usr/share/zoneinfo/Libya", + "usr/share/zoneinfo/MET", + "usr/share/zoneinfo/MST", + "usr/share/zoneinfo/MST7MDT", + "usr/share/zoneinfo/NZ", + "usr/share/zoneinfo/NZ-CHAT", + "usr/share/zoneinfo/Navajo", + "usr/share/zoneinfo/PRC", + "usr/share/zoneinfo/PST8PDT", + "usr/share/zoneinfo/Poland", + "usr/share/zoneinfo/Portugal", + "usr/share/zoneinfo/ROC", + "usr/share/zoneinfo/ROK", + "usr/share/zoneinfo/Singapore", + "usr/share/zoneinfo/Turkey", + "usr/share/zoneinfo/UCT", + "usr/share/zoneinfo/UTC", + "usr/share/zoneinfo/Universal", + "usr/share/zoneinfo/W-SU", + "usr/share/zoneinfo/WET", + "usr/share/zoneinfo/Zulu", + "usr/share/zoneinfo/iso3166.tab", + "usr/share/zoneinfo/leap-seconds.list", + "usr/share/zoneinfo/posixrules", + "usr/share/zoneinfo/zone.tab", + "usr/share/zoneinfo/zone1970.tab", + "usr/share/zoneinfo/Africa/Abidjan", + "usr/share/zoneinfo/Africa/Accra", + "usr/share/zoneinfo/Africa/Addis_Ababa", + "usr/share/zoneinfo/Africa/Algiers", + "usr/share/zoneinfo/Africa/Asmara", + "usr/share/zoneinfo/Africa/Asmera", + "usr/share/zoneinfo/Africa/Bamako", + "usr/share/zoneinfo/Africa/Bangui", + "usr/share/zoneinfo/Africa/Banjul", + "usr/share/zoneinfo/Africa/Bissau", + "usr/share/zoneinfo/Africa/Blantyre", + "usr/share/zoneinfo/Africa/Brazzaville", + "usr/share/zoneinfo/Africa/Bujumbura", + "usr/share/zoneinfo/Africa/Cairo", + "usr/share/zoneinfo/Africa/Casablanca", + "usr/share/zoneinfo/Africa/Ceuta", + "usr/share/zoneinfo/Africa/Conakry", + "usr/share/zoneinfo/Africa/Dakar", + "usr/share/zoneinfo/Africa/Dar_es_Salaam", + "usr/share/zoneinfo/Africa/Djibouti", + "usr/share/zoneinfo/Africa/Douala", + "usr/share/zoneinfo/Africa/El_Aaiun", + "usr/share/zoneinfo/Africa/Freetown", + "usr/share/zoneinfo/Africa/Gaborone", + "usr/share/zoneinfo/Africa/Harare", + "usr/share/zoneinfo/Africa/Johannesburg", + "usr/share/zoneinfo/Africa/Juba", + "usr/share/zoneinfo/Africa/Kampala", + "usr/share/zoneinfo/Africa/Khartoum", + "usr/share/zoneinfo/Africa/Kigali", + "usr/share/zoneinfo/Africa/Kinshasa", + "usr/share/zoneinfo/Africa/Lagos", + "usr/share/zoneinfo/Africa/Libreville", + "usr/share/zoneinfo/Africa/Lome", + "usr/share/zoneinfo/Africa/Luanda", + "usr/share/zoneinfo/Africa/Lubumbashi", + "usr/share/zoneinfo/Africa/Lusaka", + "usr/share/zoneinfo/Africa/Malabo", + "usr/share/zoneinfo/Africa/Maputo", + "usr/share/zoneinfo/Africa/Maseru", + "usr/share/zoneinfo/Africa/Mbabane", + "usr/share/zoneinfo/Africa/Mogadishu", + "usr/share/zoneinfo/Africa/Monrovia", + "usr/share/zoneinfo/Africa/Nairobi", + "usr/share/zoneinfo/Africa/Ndjamena", + "usr/share/zoneinfo/Africa/Niamey", + "usr/share/zoneinfo/Africa/Nouakchott", + "usr/share/zoneinfo/Africa/Ouagadougou", + "usr/share/zoneinfo/Africa/Porto-Novo", + "usr/share/zoneinfo/Africa/Sao_Tome", + "usr/share/zoneinfo/Africa/Timbuktu", + "usr/share/zoneinfo/Africa/Tripoli", + "usr/share/zoneinfo/Africa/Tunis", + "usr/share/zoneinfo/Africa/Windhoek", + "usr/share/zoneinfo/America/Adak", + "usr/share/zoneinfo/America/Anchorage", + "usr/share/zoneinfo/America/Anguilla", + "usr/share/zoneinfo/America/Antigua", + "usr/share/zoneinfo/America/Araguaina", + "usr/share/zoneinfo/America/Aruba", + "usr/share/zoneinfo/America/Asuncion", + "usr/share/zoneinfo/America/Atikokan", + "usr/share/zoneinfo/America/Atka", + "usr/share/zoneinfo/America/Bahia", + "usr/share/zoneinfo/America/Bahia_Banderas", + "usr/share/zoneinfo/America/Barbados", + "usr/share/zoneinfo/America/Belem", + "usr/share/zoneinfo/America/Belize", + "usr/share/zoneinfo/America/Blanc-Sablon", + "usr/share/zoneinfo/America/Boa_Vista", + "usr/share/zoneinfo/America/Bogota", + "usr/share/zoneinfo/America/Boise", + "usr/share/zoneinfo/America/Buenos_Aires", + "usr/share/zoneinfo/America/Cambridge_Bay", + "usr/share/zoneinfo/America/Campo_Grande", + "usr/share/zoneinfo/America/Cancun", + "usr/share/zoneinfo/America/Caracas", + "usr/share/zoneinfo/America/Catamarca", + "usr/share/zoneinfo/America/Cayenne", + "usr/share/zoneinfo/America/Cayman", + "usr/share/zoneinfo/America/Chicago", + "usr/share/zoneinfo/America/Chihuahua", + "usr/share/zoneinfo/America/Ciudad_Juarez", + "usr/share/zoneinfo/America/Coral_Harbour", + "usr/share/zoneinfo/America/Cordoba", + "usr/share/zoneinfo/America/Costa_Rica", + "usr/share/zoneinfo/America/Coyhaique", + "usr/share/zoneinfo/America/Creston", + "usr/share/zoneinfo/America/Cuiaba", + "usr/share/zoneinfo/America/Curacao", + "usr/share/zoneinfo/America/Danmarkshavn", + "usr/share/zoneinfo/America/Dawson", + "usr/share/zoneinfo/America/Dawson_Creek", + "usr/share/zoneinfo/America/Denver", + "usr/share/zoneinfo/America/Detroit", + "usr/share/zoneinfo/America/Dominica", + "usr/share/zoneinfo/America/Edmonton", + "usr/share/zoneinfo/America/Eirunepe", + "usr/share/zoneinfo/America/El_Salvador", + "usr/share/zoneinfo/America/Ensenada", + "usr/share/zoneinfo/America/Fort_Nelson", + "usr/share/zoneinfo/America/Fort_Wayne", + "usr/share/zoneinfo/America/Fortaleza", + "usr/share/zoneinfo/America/Glace_Bay", + "usr/share/zoneinfo/America/Godthab", + "usr/share/zoneinfo/America/Goose_Bay", + "usr/share/zoneinfo/America/Grand_Turk", + "usr/share/zoneinfo/America/Grenada", + "usr/share/zoneinfo/America/Guadeloupe", + "usr/share/zoneinfo/America/Guatemala", + "usr/share/zoneinfo/America/Guayaquil", + "usr/share/zoneinfo/America/Guyana", + "usr/share/zoneinfo/America/Halifax", + "usr/share/zoneinfo/America/Havana", + "usr/share/zoneinfo/America/Hermosillo", + "usr/share/zoneinfo/America/Indianapolis", + "usr/share/zoneinfo/America/Inuvik", + "usr/share/zoneinfo/America/Iqaluit", + "usr/share/zoneinfo/America/Jamaica", + "usr/share/zoneinfo/America/Jujuy", + "usr/share/zoneinfo/America/Juneau", + "usr/share/zoneinfo/America/Knox_IN", + "usr/share/zoneinfo/America/Kralendijk", + "usr/share/zoneinfo/America/La_Paz", + "usr/share/zoneinfo/America/Lima", + "usr/share/zoneinfo/America/Los_Angeles", + "usr/share/zoneinfo/America/Louisville", + "usr/share/zoneinfo/America/Lower_Princes", + "usr/share/zoneinfo/America/Maceio", + "usr/share/zoneinfo/America/Managua", + "usr/share/zoneinfo/America/Manaus", + "usr/share/zoneinfo/America/Marigot", + "usr/share/zoneinfo/America/Martinique", + "usr/share/zoneinfo/America/Matamoros", + "usr/share/zoneinfo/America/Mazatlan", + "usr/share/zoneinfo/America/Mendoza", + "usr/share/zoneinfo/America/Menominee", + "usr/share/zoneinfo/America/Merida", + "usr/share/zoneinfo/America/Metlakatla", + "usr/share/zoneinfo/America/Mexico_City", + "usr/share/zoneinfo/America/Miquelon", + "usr/share/zoneinfo/America/Moncton", + "usr/share/zoneinfo/America/Monterrey", + "usr/share/zoneinfo/America/Montevideo", + "usr/share/zoneinfo/America/Montreal", + "usr/share/zoneinfo/America/Montserrat", + "usr/share/zoneinfo/America/Nassau", + "usr/share/zoneinfo/America/New_York", + "usr/share/zoneinfo/America/Nipigon", + "usr/share/zoneinfo/America/Nome", + "usr/share/zoneinfo/America/Noronha", + "usr/share/zoneinfo/America/Nuuk", + "usr/share/zoneinfo/America/Ojinaga", + "usr/share/zoneinfo/America/Panama", + "usr/share/zoneinfo/America/Pangnirtung", + "usr/share/zoneinfo/America/Paramaribo", + "usr/share/zoneinfo/America/Phoenix", + "usr/share/zoneinfo/America/Port-au-Prince", + "usr/share/zoneinfo/America/Port_of_Spain", + "usr/share/zoneinfo/America/Porto_Acre", + "usr/share/zoneinfo/America/Porto_Velho", + "usr/share/zoneinfo/America/Puerto_Rico", + "usr/share/zoneinfo/America/Punta_Arenas", + "usr/share/zoneinfo/America/Rainy_River", + "usr/share/zoneinfo/America/Rankin_Inlet", + "usr/share/zoneinfo/America/Recife", + "usr/share/zoneinfo/America/Regina", + "usr/share/zoneinfo/America/Resolute", + "usr/share/zoneinfo/America/Rio_Branco", + "usr/share/zoneinfo/America/Rosario", + "usr/share/zoneinfo/America/Santa_Isabel", + "usr/share/zoneinfo/America/Santarem", + "usr/share/zoneinfo/America/Santiago", + "usr/share/zoneinfo/America/Santo_Domingo", + "usr/share/zoneinfo/America/Sao_Paulo", + "usr/share/zoneinfo/America/Scoresbysund", + "usr/share/zoneinfo/America/Shiprock", + "usr/share/zoneinfo/America/Sitka", + "usr/share/zoneinfo/America/St_Barthelemy", + "usr/share/zoneinfo/America/St_Johns", + "usr/share/zoneinfo/America/St_Kitts", + "usr/share/zoneinfo/America/St_Lucia", + "usr/share/zoneinfo/America/St_Thomas", + "usr/share/zoneinfo/America/St_Vincent", + "usr/share/zoneinfo/America/Swift_Current", + "usr/share/zoneinfo/America/Tegucigalpa", + "usr/share/zoneinfo/America/Thule", + "usr/share/zoneinfo/America/Thunder_Bay", + "usr/share/zoneinfo/America/Tijuana", + "usr/share/zoneinfo/America/Toronto", + "usr/share/zoneinfo/America/Tortola", + "usr/share/zoneinfo/America/Vancouver", + "usr/share/zoneinfo/America/Virgin", + "usr/share/zoneinfo/America/Whitehorse", + "usr/share/zoneinfo/America/Winnipeg", + "usr/share/zoneinfo/America/Yakutat", + "usr/share/zoneinfo/America/Yellowknife", + "usr/share/zoneinfo/America/Argentina/Buenos_Aires", + "usr/share/zoneinfo/America/Argentina/Catamarca", + "usr/share/zoneinfo/America/Argentina/ComodRivadavia", + "usr/share/zoneinfo/America/Argentina/Cordoba", + "usr/share/zoneinfo/America/Argentina/Jujuy", + "usr/share/zoneinfo/America/Argentina/La_Rioja", + "usr/share/zoneinfo/America/Argentina/Mendoza", + "usr/share/zoneinfo/America/Argentina/Rio_Gallegos", + "usr/share/zoneinfo/America/Argentina/Salta", + "usr/share/zoneinfo/America/Argentina/San_Juan", + "usr/share/zoneinfo/America/Argentina/San_Luis", + "usr/share/zoneinfo/America/Argentina/Tucuman", + "usr/share/zoneinfo/America/Argentina/Ushuaia", + "usr/share/zoneinfo/America/Indiana/Indianapolis", + "usr/share/zoneinfo/America/Indiana/Knox", + "usr/share/zoneinfo/America/Indiana/Marengo", + "usr/share/zoneinfo/America/Indiana/Petersburg", + "usr/share/zoneinfo/America/Indiana/Tell_City", + "usr/share/zoneinfo/America/Indiana/Vevay", + "usr/share/zoneinfo/America/Indiana/Vincennes", + "usr/share/zoneinfo/America/Indiana/Winamac", + "usr/share/zoneinfo/America/Kentucky/Louisville", + "usr/share/zoneinfo/America/Kentucky/Monticello", + "usr/share/zoneinfo/America/North_Dakota/Beulah", + "usr/share/zoneinfo/America/North_Dakota/Center", + "usr/share/zoneinfo/America/North_Dakota/New_Salem", + "usr/share/zoneinfo/Antarctica/Casey", + "usr/share/zoneinfo/Antarctica/Davis", + "usr/share/zoneinfo/Antarctica/DumontDUrville", + "usr/share/zoneinfo/Antarctica/Macquarie", + "usr/share/zoneinfo/Antarctica/Mawson", + "usr/share/zoneinfo/Antarctica/McMurdo", + "usr/share/zoneinfo/Antarctica/Palmer", + "usr/share/zoneinfo/Antarctica/Rothera", + "usr/share/zoneinfo/Antarctica/South_Pole", + "usr/share/zoneinfo/Antarctica/Syowa", + "usr/share/zoneinfo/Antarctica/Troll", + "usr/share/zoneinfo/Antarctica/Vostok", + "usr/share/zoneinfo/Arctic/Longyearbyen", + "usr/share/zoneinfo/Asia/Aden", + "usr/share/zoneinfo/Asia/Almaty", + "usr/share/zoneinfo/Asia/Amman", + "usr/share/zoneinfo/Asia/Anadyr", + "usr/share/zoneinfo/Asia/Aqtau", + "usr/share/zoneinfo/Asia/Aqtobe", + "usr/share/zoneinfo/Asia/Ashgabat", + "usr/share/zoneinfo/Asia/Ashkhabad", + "usr/share/zoneinfo/Asia/Atyrau", + "usr/share/zoneinfo/Asia/Baghdad", + "usr/share/zoneinfo/Asia/Bahrain", + "usr/share/zoneinfo/Asia/Baku", + "usr/share/zoneinfo/Asia/Bangkok", + "usr/share/zoneinfo/Asia/Barnaul", + "usr/share/zoneinfo/Asia/Beirut", + "usr/share/zoneinfo/Asia/Bishkek", + "usr/share/zoneinfo/Asia/Brunei", + "usr/share/zoneinfo/Asia/Calcutta", + "usr/share/zoneinfo/Asia/Chita", + "usr/share/zoneinfo/Asia/Choibalsan", + "usr/share/zoneinfo/Asia/Chongqing", + "usr/share/zoneinfo/Asia/Chungking", + "usr/share/zoneinfo/Asia/Colombo", + "usr/share/zoneinfo/Asia/Dacca", + "usr/share/zoneinfo/Asia/Damascus", + "usr/share/zoneinfo/Asia/Dhaka", + "usr/share/zoneinfo/Asia/Dili", + "usr/share/zoneinfo/Asia/Dubai", + "usr/share/zoneinfo/Asia/Dushanbe", + "usr/share/zoneinfo/Asia/Famagusta", + "usr/share/zoneinfo/Asia/Gaza", + "usr/share/zoneinfo/Asia/Harbin", + "usr/share/zoneinfo/Asia/Hebron", + "usr/share/zoneinfo/Asia/Ho_Chi_Minh", + "usr/share/zoneinfo/Asia/Hong_Kong", + "usr/share/zoneinfo/Asia/Hovd", + "usr/share/zoneinfo/Asia/Irkutsk", + "usr/share/zoneinfo/Asia/Istanbul", + "usr/share/zoneinfo/Asia/Jakarta", + "usr/share/zoneinfo/Asia/Jayapura", + "usr/share/zoneinfo/Asia/Jerusalem", + "usr/share/zoneinfo/Asia/Kabul", + "usr/share/zoneinfo/Asia/Kamchatka", + "usr/share/zoneinfo/Asia/Karachi", + "usr/share/zoneinfo/Asia/Kashgar", + "usr/share/zoneinfo/Asia/Kathmandu", + "usr/share/zoneinfo/Asia/Katmandu", + "usr/share/zoneinfo/Asia/Khandyga", + "usr/share/zoneinfo/Asia/Kolkata", + "usr/share/zoneinfo/Asia/Krasnoyarsk", + "usr/share/zoneinfo/Asia/Kuala_Lumpur", + "usr/share/zoneinfo/Asia/Kuching", + "usr/share/zoneinfo/Asia/Kuwait", + "usr/share/zoneinfo/Asia/Macao", + "usr/share/zoneinfo/Asia/Macau", + "usr/share/zoneinfo/Asia/Magadan", + "usr/share/zoneinfo/Asia/Makassar", + "usr/share/zoneinfo/Asia/Manila", + "usr/share/zoneinfo/Asia/Muscat", + "usr/share/zoneinfo/Asia/Nicosia", + "usr/share/zoneinfo/Asia/Novokuznetsk", + "usr/share/zoneinfo/Asia/Novosibirsk", + "usr/share/zoneinfo/Asia/Omsk", + "usr/share/zoneinfo/Asia/Oral", + "usr/share/zoneinfo/Asia/Phnom_Penh", + "usr/share/zoneinfo/Asia/Pontianak", + "usr/share/zoneinfo/Asia/Pyongyang", + "usr/share/zoneinfo/Asia/Qatar", + "usr/share/zoneinfo/Asia/Qostanay", + "usr/share/zoneinfo/Asia/Qyzylorda", + "usr/share/zoneinfo/Asia/Rangoon", + "usr/share/zoneinfo/Asia/Riyadh", + "usr/share/zoneinfo/Asia/Saigon", + "usr/share/zoneinfo/Asia/Sakhalin", + "usr/share/zoneinfo/Asia/Samarkand", + "usr/share/zoneinfo/Asia/Seoul", + "usr/share/zoneinfo/Asia/Shanghai", + "usr/share/zoneinfo/Asia/Singapore", + "usr/share/zoneinfo/Asia/Srednekolymsk", + "usr/share/zoneinfo/Asia/Taipei", + "usr/share/zoneinfo/Asia/Tashkent", + "usr/share/zoneinfo/Asia/Tbilisi", + "usr/share/zoneinfo/Asia/Tehran", + "usr/share/zoneinfo/Asia/Tel_Aviv", + "usr/share/zoneinfo/Asia/Thimbu", + "usr/share/zoneinfo/Asia/Thimphu", + "usr/share/zoneinfo/Asia/Tokyo", + "usr/share/zoneinfo/Asia/Tomsk", + "usr/share/zoneinfo/Asia/Ujung_Pandang", + "usr/share/zoneinfo/Asia/Ulaanbaatar", + "usr/share/zoneinfo/Asia/Ulan_Bator", + "usr/share/zoneinfo/Asia/Urumqi", + "usr/share/zoneinfo/Asia/Ust-Nera", + "usr/share/zoneinfo/Asia/Vientiane", + "usr/share/zoneinfo/Asia/Vladivostok", + "usr/share/zoneinfo/Asia/Yakutsk", + "usr/share/zoneinfo/Asia/Yangon", + "usr/share/zoneinfo/Asia/Yekaterinburg", + "usr/share/zoneinfo/Asia/Yerevan", + "usr/share/zoneinfo/Atlantic/Azores", + "usr/share/zoneinfo/Atlantic/Bermuda", + "usr/share/zoneinfo/Atlantic/Canary", + "usr/share/zoneinfo/Atlantic/Cape_Verde", + "usr/share/zoneinfo/Atlantic/Faeroe", + "usr/share/zoneinfo/Atlantic/Faroe", + "usr/share/zoneinfo/Atlantic/Jan_Mayen", + "usr/share/zoneinfo/Atlantic/Madeira", + "usr/share/zoneinfo/Atlantic/Reykjavik", + "usr/share/zoneinfo/Atlantic/South_Georgia", + "usr/share/zoneinfo/Atlantic/St_Helena", + "usr/share/zoneinfo/Atlantic/Stanley", + "usr/share/zoneinfo/Australia/ACT", + "usr/share/zoneinfo/Australia/Adelaide", + "usr/share/zoneinfo/Australia/Brisbane", + "usr/share/zoneinfo/Australia/Broken_Hill", + "usr/share/zoneinfo/Australia/Canberra", + "usr/share/zoneinfo/Australia/Currie", + "usr/share/zoneinfo/Australia/Darwin", + "usr/share/zoneinfo/Australia/Eucla", + "usr/share/zoneinfo/Australia/Hobart", + "usr/share/zoneinfo/Australia/LHI", + "usr/share/zoneinfo/Australia/Lindeman", + "usr/share/zoneinfo/Australia/Lord_Howe", + "usr/share/zoneinfo/Australia/Melbourne", + "usr/share/zoneinfo/Australia/NSW", + "usr/share/zoneinfo/Australia/North", + "usr/share/zoneinfo/Australia/Perth", + "usr/share/zoneinfo/Australia/Queensland", + "usr/share/zoneinfo/Australia/South", + "usr/share/zoneinfo/Australia/Sydney", + "usr/share/zoneinfo/Australia/Tasmania", + "usr/share/zoneinfo/Australia/Victoria", + "usr/share/zoneinfo/Australia/West", + "usr/share/zoneinfo/Australia/Yancowinna", + "usr/share/zoneinfo/Brazil/Acre", + "usr/share/zoneinfo/Brazil/DeNoronha", + "usr/share/zoneinfo/Brazil/East", + "usr/share/zoneinfo/Brazil/West", + "usr/share/zoneinfo/Canada/Atlantic", + "usr/share/zoneinfo/Canada/Central", + "usr/share/zoneinfo/Canada/Eastern", + "usr/share/zoneinfo/Canada/Mountain", + "usr/share/zoneinfo/Canada/Newfoundland", + "usr/share/zoneinfo/Canada/Pacific", + "usr/share/zoneinfo/Canada/Saskatchewan", + "usr/share/zoneinfo/Canada/Yukon", + "usr/share/zoneinfo/Chile/Continental", + "usr/share/zoneinfo/Chile/EasterIsland", + "usr/share/zoneinfo/Etc/GMT", + "usr/share/zoneinfo/Etc/GMT+0", + "usr/share/zoneinfo/Etc/GMT+1", + "usr/share/zoneinfo/Etc/GMT+10", + "usr/share/zoneinfo/Etc/GMT+11", + "usr/share/zoneinfo/Etc/GMT+12", + "usr/share/zoneinfo/Etc/GMT+2", + "usr/share/zoneinfo/Etc/GMT+3", + "usr/share/zoneinfo/Etc/GMT+4", + "usr/share/zoneinfo/Etc/GMT+5", + "usr/share/zoneinfo/Etc/GMT+6", + "usr/share/zoneinfo/Etc/GMT+7", + "usr/share/zoneinfo/Etc/GMT+8", + "usr/share/zoneinfo/Etc/GMT+9", + "usr/share/zoneinfo/Etc/GMT-0", + "usr/share/zoneinfo/Etc/GMT-1", + "usr/share/zoneinfo/Etc/GMT-10", + "usr/share/zoneinfo/Etc/GMT-11", + "usr/share/zoneinfo/Etc/GMT-12", + "usr/share/zoneinfo/Etc/GMT-13", + "usr/share/zoneinfo/Etc/GMT-14", + "usr/share/zoneinfo/Etc/GMT-2", + "usr/share/zoneinfo/Etc/GMT-3", + "usr/share/zoneinfo/Etc/GMT-4", + "usr/share/zoneinfo/Etc/GMT-5", + "usr/share/zoneinfo/Etc/GMT-6", + "usr/share/zoneinfo/Etc/GMT-7", + "usr/share/zoneinfo/Etc/GMT-8", + "usr/share/zoneinfo/Etc/GMT-9", + "usr/share/zoneinfo/Etc/GMT0", + "usr/share/zoneinfo/Etc/Greenwich", + "usr/share/zoneinfo/Etc/UCT", + "usr/share/zoneinfo/Etc/UTC", + "usr/share/zoneinfo/Etc/Universal", + "usr/share/zoneinfo/Etc/Zulu", + "usr/share/zoneinfo/Europe/Amsterdam", + "usr/share/zoneinfo/Europe/Andorra", + "usr/share/zoneinfo/Europe/Astrakhan", + "usr/share/zoneinfo/Europe/Athens", + "usr/share/zoneinfo/Europe/Belfast", + "usr/share/zoneinfo/Europe/Belgrade", + "usr/share/zoneinfo/Europe/Berlin", + "usr/share/zoneinfo/Europe/Bratislava", + "usr/share/zoneinfo/Europe/Brussels", + "usr/share/zoneinfo/Europe/Bucharest", + "usr/share/zoneinfo/Europe/Budapest", + "usr/share/zoneinfo/Europe/Busingen", + "usr/share/zoneinfo/Europe/Chisinau", + "usr/share/zoneinfo/Europe/Copenhagen", + "usr/share/zoneinfo/Europe/Dublin", + "usr/share/zoneinfo/Europe/Gibraltar", + "usr/share/zoneinfo/Europe/Guernsey", + "usr/share/zoneinfo/Europe/Helsinki", + "usr/share/zoneinfo/Europe/Isle_of_Man", + "usr/share/zoneinfo/Europe/Istanbul", + "usr/share/zoneinfo/Europe/Jersey", + "usr/share/zoneinfo/Europe/Kaliningrad", + "usr/share/zoneinfo/Europe/Kiev", + "usr/share/zoneinfo/Europe/Kirov", + "usr/share/zoneinfo/Europe/Kyiv", + "usr/share/zoneinfo/Europe/Lisbon", + "usr/share/zoneinfo/Europe/Ljubljana", + "usr/share/zoneinfo/Europe/London", + "usr/share/zoneinfo/Europe/Luxembourg", + "usr/share/zoneinfo/Europe/Madrid", + "usr/share/zoneinfo/Europe/Malta", + "usr/share/zoneinfo/Europe/Mariehamn", + "usr/share/zoneinfo/Europe/Minsk", + "usr/share/zoneinfo/Europe/Monaco", + "usr/share/zoneinfo/Europe/Moscow", + "usr/share/zoneinfo/Europe/Nicosia", + "usr/share/zoneinfo/Europe/Oslo", + "usr/share/zoneinfo/Europe/Paris", + "usr/share/zoneinfo/Europe/Podgorica", + "usr/share/zoneinfo/Europe/Prague", + "usr/share/zoneinfo/Europe/Riga", + "usr/share/zoneinfo/Europe/Rome", + "usr/share/zoneinfo/Europe/Samara", + "usr/share/zoneinfo/Europe/San_Marino", + "usr/share/zoneinfo/Europe/Sarajevo", + "usr/share/zoneinfo/Europe/Saratov", + "usr/share/zoneinfo/Europe/Simferopol", + "usr/share/zoneinfo/Europe/Skopje", + "usr/share/zoneinfo/Europe/Sofia", + "usr/share/zoneinfo/Europe/Stockholm", + "usr/share/zoneinfo/Europe/Tallinn", + "usr/share/zoneinfo/Europe/Tirane", + "usr/share/zoneinfo/Europe/Tiraspol", + "usr/share/zoneinfo/Europe/Ulyanovsk", + "usr/share/zoneinfo/Europe/Uzhgorod", + "usr/share/zoneinfo/Europe/Vaduz", + "usr/share/zoneinfo/Europe/Vatican", + "usr/share/zoneinfo/Europe/Vienna", + "usr/share/zoneinfo/Europe/Vilnius", + "usr/share/zoneinfo/Europe/Volgograd", + "usr/share/zoneinfo/Europe/Warsaw", + "usr/share/zoneinfo/Europe/Zagreb", + "usr/share/zoneinfo/Europe/Zaporozhye", + "usr/share/zoneinfo/Europe/Zurich", + "usr/share/zoneinfo/Indian/Antananarivo", + "usr/share/zoneinfo/Indian/Chagos", + "usr/share/zoneinfo/Indian/Christmas", + "usr/share/zoneinfo/Indian/Cocos", + "usr/share/zoneinfo/Indian/Comoro", + "usr/share/zoneinfo/Indian/Kerguelen", + "usr/share/zoneinfo/Indian/Mahe", + "usr/share/zoneinfo/Indian/Maldives", + "usr/share/zoneinfo/Indian/Mauritius", + "usr/share/zoneinfo/Indian/Mayotte", + "usr/share/zoneinfo/Indian/Reunion", + "usr/share/zoneinfo/Mexico/BajaNorte", + "usr/share/zoneinfo/Mexico/BajaSur", + "usr/share/zoneinfo/Mexico/General", + "usr/share/zoneinfo/Pacific/Apia", + "usr/share/zoneinfo/Pacific/Auckland", + "usr/share/zoneinfo/Pacific/Bougainville", + "usr/share/zoneinfo/Pacific/Chatham", + "usr/share/zoneinfo/Pacific/Chuuk", + "usr/share/zoneinfo/Pacific/Easter", + "usr/share/zoneinfo/Pacific/Efate", + "usr/share/zoneinfo/Pacific/Enderbury", + "usr/share/zoneinfo/Pacific/Fakaofo", + "usr/share/zoneinfo/Pacific/Fiji", + "usr/share/zoneinfo/Pacific/Funafuti", + "usr/share/zoneinfo/Pacific/Galapagos", + "usr/share/zoneinfo/Pacific/Gambier", + "usr/share/zoneinfo/Pacific/Guadalcanal", + "usr/share/zoneinfo/Pacific/Guam", + "usr/share/zoneinfo/Pacific/Honolulu", + "usr/share/zoneinfo/Pacific/Johnston", + "usr/share/zoneinfo/Pacific/Kanton", + "usr/share/zoneinfo/Pacific/Kiritimati", + "usr/share/zoneinfo/Pacific/Kosrae", + "usr/share/zoneinfo/Pacific/Kwajalein", + "usr/share/zoneinfo/Pacific/Majuro", + "usr/share/zoneinfo/Pacific/Marquesas", + "usr/share/zoneinfo/Pacific/Midway", + "usr/share/zoneinfo/Pacific/Nauru", + "usr/share/zoneinfo/Pacific/Niue", + "usr/share/zoneinfo/Pacific/Norfolk", + "usr/share/zoneinfo/Pacific/Noumea", + "usr/share/zoneinfo/Pacific/Pago_Pago", + "usr/share/zoneinfo/Pacific/Palau", + "usr/share/zoneinfo/Pacific/Pitcairn", + "usr/share/zoneinfo/Pacific/Pohnpei", + "usr/share/zoneinfo/Pacific/Ponape", + "usr/share/zoneinfo/Pacific/Port_Moresby", + "usr/share/zoneinfo/Pacific/Rarotonga", + "usr/share/zoneinfo/Pacific/Saipan", + "usr/share/zoneinfo/Pacific/Samoa", + "usr/share/zoneinfo/Pacific/Tahiti", + "usr/share/zoneinfo/Pacific/Tarawa", + "usr/share/zoneinfo/Pacific/Tongatapu", + "usr/share/zoneinfo/Pacific/Truk", + "usr/share/zoneinfo/Pacific/Wake", + "usr/share/zoneinfo/Pacific/Wallis", + "usr/share/zoneinfo/Pacific/Yap", + "usr/share/zoneinfo/US/Alaska", + "usr/share/zoneinfo/US/Aleutian", + "usr/share/zoneinfo/US/Arizona", + "usr/share/zoneinfo/US/Central", + "usr/share/zoneinfo/US/East-Indiana", + "usr/share/zoneinfo/US/Eastern", + "usr/share/zoneinfo/US/Hawaii", + "usr/share/zoneinfo/US/Indiana-Starke", + "usr/share/zoneinfo/US/Michigan", + "usr/share/zoneinfo/US/Mountain", + "usr/share/zoneinfo/US/Pacific", + "usr/share/zoneinfo/US/Samoa" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "xz-libs@5.8.3-r0", + "Name": "xz-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/xz-libs@5.8.3-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "1ae658a5f132a091" + }, + "Version": "5.8.3-r0", + "Arch": "x86_64", + "SrcName": "xz", + "SrcVersion": "5.8.3-r0", + "Licenses": [ + "GPL-2.0-or-later", + "0BSD", + "Public-Domain", + "LGPL-2.1-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:4c92c5be0c5bef404e93c880eba9037a9b147347", + "InstalledFiles": [ + "usr/lib/liblzma.so.5", + "usr/lib/liblzma.so.5.8.3" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "zlib@1.3.2-r0", + "Name": "zlib", + "Identifier": { + "PURL": "pkg:apk/alpine/zlib@1.3.2-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "e37054a2982d6c16" + }, + "Version": "1.3.2-r0", + "Arch": "x86_64", + "SrcName": "zlib", + "SrcVersion": "1.3.2-r0", + "Licenses": [ + "Zlib" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:dd4c3d102acaef2a71a1495951d55fabc8680613", + "InstalledFiles": [ + "usr/lib/libz.so.1", + "usr/lib/libz.so.1.3.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "zstd@1.5.7-r2", + "Name": "zstd", + "Identifier": { + "PURL": "pkg:apk/alpine/zstd@1.5.7-r2?arch=x86_64\u0026distro=3.24.1", + "UID": "71f39af918e4d14c" + }, + "Version": "1.5.7-r2", + "Arch": "x86_64", + "SrcName": "zstd", + "SrcVersion": "1.5.7-r2", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libgcc@15.2.0-r5", + "libstdc++@15.2.0-r5", + "musl@1.2.6-r2", + "zstd-libs@1.5.7-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:ff3000882c17e89e5e13c020554b5bccc1bfd4df", + "InstalledFiles": [ + "usr/bin/pzstd", + "usr/bin/unzstd", + "usr/bin/zstd", + "usr/bin/zstdcat", + "usr/bin/zstdgrep", + "usr/bin/zstdless", + "usr/bin/zstdmt" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "zstd-libs@1.5.7-r2", + "Name": "zstd-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/zstd-libs@1.5.7-r2?arch=x86_64\u0026distro=3.24.1", + "UID": "b33716e8bc222f1f" + }, + "Version": "1.5.7-r2", + "Arch": "x86_64", + "SrcName": "zstd", + "SrcVersion": "1.5.7-r2", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "Digest": "sha1:9569ce3a97c4109e8e53ddde9f3e1bd272613540", + "InstalledFiles": [ + "usr/lib/libzstd.so.1", + "usr/lib/libzstd.so.1.5.7" + ], + "AnalyzedBy": "apk" + } + ], + "Vulnerabilities": [ + { + "VulnerabilityID": "CVE-2026-14456", + "PkgID": "libcrypto3@3.5.7-r0", + "PkgName": "libcrypto3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcrypto3@3.5.7-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "9ce2cdb3f0bf014b" + }, + "InstalledVersion": "3.5.7-r0", + "FixedVersion": "3.5.8-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-14456", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:66effbd554e6873981bdd52ae60692654faf106690b53c78751499d91ea7a8d6", + "Title": "openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server", + "Description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/08/13/4", + "https://access.redhat.com/security/cve/CVE-2026-14456", + "https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9", + "https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b", + "https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139", + "https://nvd.nist.gov/vuln/detail/CVE-2026-14456", + "https://openssl-library.org/news/secadv/20260813.txt", + "https://ubuntu.com/security/notices/USN-8678-1", + "https://www.cve.org/CVERecord?id=CVE-2026-14456" + ], + "PublishedDate": "2026-08-13T15:19:31.82Z", + "LastModifiedDate": "2026-08-28T19:46:29.323Z" + }, + { + "VulnerabilityID": "CVE-2026-14456", + "PkgID": "libssl3@3.5.7-r0", + "PkgName": "libssl3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libssl3@3.5.7-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "a25152af95b643e0" + }, + "InstalledVersion": "3.5.7-r0", + "FixedVersion": "3.5.8-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-14456", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:bd686aaa2ece4a82e1ad494f4a7598bb66d77b700c2133b3ab3ab8585d4e7ca9", + "Title": "openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server", + "Description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/08/13/4", + "https://access.redhat.com/security/cve/CVE-2026-14456", + "https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9", + "https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b", + "https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139", + "https://nvd.nist.gov/vuln/detail/CVE-2026-14456", + "https://openssl-library.org/news/secadv/20260813.txt", + "https://ubuntu.com/security/notices/USN-8678-1", + "https://www.cve.org/CVERecord?id=CVE-2026-14456" + ], + "PublishedDate": "2026-08-13T15:19:31.82Z", + "LastModifiedDate": "2026-08-28T19:46:29.323Z" + }, + { + "VulnerabilityID": "CVE-2026-53612", + "PkgID": "libuuid@2.42.1-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "61e289a52fcab6f6" + }, + "InstalledVersion": "2.42.1-r0", + "FixedVersion": "2.42.3-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53612", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:81113f5360d14790e635b7331d78d5ed14e9be40a6e43bf022263dda73ce75b0", + "Title": "util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes", + "Description": "A flaw was found in util-linux. When an /etc/fstab entry uses the user option together with X-mount.owner, X-mount.group, or X-mount.mode, mount(8) changes ownership or permissions on the mount target after mounting without re-verifying the path. A local unprivileged user can exploit this Time-of-Check-Time-of-Use (TOCTOU) window by swapping the target directory, redirecting the ownership/permission change to an arbitrary file and potentially escalating privileges to root.", + "Severity": "HIGH", + "VendorSeverity": { + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-53612", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-g8wm-75wr-g2vh", + "https://nvd.nist.gov/vuln/detail/CVE-2026-53612", + "https://ubuntu.com/security/notices/USN-8702-1", + "https://www.cve.org/CVERecord?id=CVE-2026-53612" + ] + }, + { + "VulnerabilityID": "CVE-2026-53613", + "PkgID": "libuuid@2.42.1-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "61e289a52fcab6f6" + }, + "InstalledVersion": "2.42.1-r0", + "FixedVersion": "2.42.3-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53613", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:54e037da093c8c174ad0e2d784253fc9a9814e055fd0549ad80221defddd87a1", + "Title": "util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path", + "Description": "When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.", + "Severity": "HIGH", + "VendorSeverity": { + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-53613", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g", + "https://nvd.nist.gov/vuln/detail/CVE-2026-53613", + "https://ubuntu.com/security/notices/USN-8702-1", + "https://www.cve.org/CVERecord?id=CVE-2026-53613" + ] + }, + { + "VulnerabilityID": "CVE-2026-53614", + "PkgID": "libuuid@2.42.1-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "61e289a52fcab6f6" + }, + "InstalledVersion": "2.42.1-r0", + "FixedVersion": "2.42.3-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53614", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:dece0b29d6edc204a95c04c1c1f0eeeec1528eccf524218f803681d69aafe7d5", + "Title": "util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2", + "Description": "A flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root.", + "Severity": "HIGH", + "VendorSeverity": { + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-53614", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-67r7-8m5w-22wx", + "https://nvd.nist.gov/vuln/detail/CVE-2026-53614", + "https://ubuntu.com/security/notices/USN-8702-1", + "https://www.cve.org/CVERecord?id=CVE-2026-53614" + ] + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "libuuid@2.42.1-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "61e289a52fcab6f6" + }, + "InstalledVersion": "2.42.1-r0", + "FixedVersion": "2.42.3-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:c142dcd00764dca9205218728a4d9d7f698986302926f2816106eaa9bbae8774", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "libuuid@2.42.1-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "61e289a52fcab6f6" + }, + "InstalledVersion": "2.42.1-r0", + "FixedVersion": "2.42.3-r1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:c639fbde964fa844de700c2d7a0665d771dcc8ee4a143560cc0c74f12355cbc6", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "libuuid@2.42.1-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "61e289a52fcab6f6" + }, + "InstalledVersion": "2.42.1-r0", + "FixedVersion": "2.42.3-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:e1ecbe00c3f557417e81e566a983e8869f8972ee1499e6de061810bffa516dc2", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "libuuid@2.42.1-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.42.1-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "61e289a52fcab6f6" + }, + "InstalledVersion": "2.42.1-r0", + "FixedVersion": "2.42.3-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:5858a3f690eab3dfde37f933ab035d3453f4a56f38fb963ce98186b9d7d15e80", + "DiffID": "sha256:67f703ac42fb80d5dbc632d6da23922e4aadf47aab745a14af3c66c5192e3e99" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:0916dc51e28a7f0613d801b5b47f1f387bfaa9a446dd75898a4903017e142f5c", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + } + ] + }, + { + "Target": "usr/local/bin/gosu", + "Class": "lang-pkgs", + "Type": "gobinary", + "Packages": [ + { + "ID": "github.com/tianon/gosu@v1.19.0", + "Name": "github.com/tianon/gosu", + "Identifier": { + "PURL": "pkg:golang/github.com/tianon/gosu@v1.19.0", + "UID": "1057a82ec313601" + }, + "Version": "v1.19.0", + "Relationship": "root", + "DependsOn": [ + "github.com/moby/sys/user@v0.1.0", + "golang.org/x/sys@v0.1.0", + "stdlib@v1.24.6" + ], + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "stdlib@v1.24.6", + "Name": "stdlib", + "Identifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "Version": "v1.24.6", + "Relationship": "direct", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "github.com/moby/sys/user@v0.1.0", + "Name": "github.com/moby/sys/user", + "Identifier": { + "PURL": "pkg:golang/github.com/moby/sys/user@v0.1.0", + "UID": "cfd815b74e215fdf" + }, + "Version": "v0.1.0", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "AnalyzedBy": "gobinary" + }, + { + "ID": "golang.org/x/sys@v0.1.0", + "Name": "golang.org/x/sys", + "Identifier": { + "PURL": "pkg:golang/golang.org/x/sys@v0.1.0", + "UID": "11ab2e48c80f8e7d" + }, + "Version": "v0.1.0", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "AnalyzedBy": "gobinary" + } + ], + "Vulnerabilities": [ + { + "VulnerabilityID": "CVE-2025-68121", + "VendorIDs": [ + "GO-2026-4337" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.24.13, 1.25.7, 1.26.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-68121", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:85e5aa144410093742432b138a09862fced9579b0f57deb4cbdd217755d26e54", + "Title": "crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption", + "Description": "During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 4, + "cbl-mariner": 2, + "nvd": 4, + "oracle-oval": 3, + "photon": 4, + "redhat": 2, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 10 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/security/cve/CVE-2025-68121", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://github.com/golang/go/issues/77113", + "https://go.dev/cl/737700", + "https://go.dev/issue/77217", + "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-68121.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-68121", + "https://pkg.go.dev/vuln/GO-2026-4337", + "https://www.cve.org/CVERecord?id=CVE-2025-68121" + ], + "PublishedDate": "2026-02-05T18:16:10.857Z", + "LastModifiedDate": "2026-06-17T09:58:33.833Z" + }, + { + "VulnerabilityID": "CVE-2025-61726", + "VendorIDs": [ + "GO-2026-4341" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.24.12, 1.25.6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61726", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:376f163e2679190aec7e2c2067f0d65ec348cf7c5697676194fffc9ae4598d32", + "Title": "golang: net/url: Memory exhaustion in query parameter parsing in net/url", + "Description": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "cbl-mariner": 2, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10096", + "https://access.redhat.com/errata/RHSA-2026:10104", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:11408", + "https://access.redhat.com/errata/RHSA-2026:11414", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12279", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13542", + "https://access.redhat.com/errata/RHSA-2026:13548", + "https://access.redhat.com/errata/RHSA-2026:13571", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:15984", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17446", + "https://access.redhat.com/errata/RHSA-2026:17460", + "https://access.redhat.com/errata/RHSA-2026:17463", + "https://access.redhat.com/errata/RHSA-2026:17468", + "https://access.redhat.com/errata/RHSA-2026:17595", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:18913", + "https://access.redhat.com/errata/RHSA-2026:19013", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19712", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26420", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:2681", + "https://access.redhat.com/errata/RHSA-2026:2706", + "https://access.redhat.com/errata/RHSA-2026:2708", + "https://access.redhat.com/errata/RHSA-2026:2709", + "https://access.redhat.com/errata/RHSA-2026:2754", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:2844", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:2914", + "https://access.redhat.com/errata/RHSA-2026:2920", + "https://access.redhat.com/errata/RHSA-2026:3035", + "https://access.redhat.com/errata/RHSA-2026:3040", + "https://access.redhat.com/errata/RHSA-2026:3089", + "https://access.redhat.com/errata/RHSA-2026:3092", + "https://access.redhat.com/errata/RHSA-2026:3184", + "https://access.redhat.com/errata/RHSA-2026:3186", + "https://access.redhat.com/errata/RHSA-2026:3187", + "https://access.redhat.com/errata/RHSA-2026:3188", + "https://access.redhat.com/errata/RHSA-2026:3192", + "https://access.redhat.com/errata/RHSA-2026:3193", + "https://access.redhat.com/errata/RHSA-2026:3291", + "https://access.redhat.com/errata/RHSA-2026:3296", + "https://access.redhat.com/errata/RHSA-2026:3297", + "https://access.redhat.com/errata/RHSA-2026:3298", + "https://access.redhat.com/errata/RHSA-2026:3336", + "https://access.redhat.com/errata/RHSA-2026:3337", + "https://access.redhat.com/errata/RHSA-2026:3340", + "https://access.redhat.com/errata/RHSA-2026:3341", + "https://access.redhat.com/errata/RHSA-2026:3343", + "https://access.redhat.com/errata/RHSA-2026:3391", + "https://access.redhat.com/errata/RHSA-2026:3416", + "https://access.redhat.com/errata/RHSA-2026:3427", + "https://access.redhat.com/errata/RHSA-2026:3459", + "https://access.redhat.com/errata/RHSA-2026:3468", + "https://access.redhat.com/errata/RHSA-2026:3469", + "https://access.redhat.com/errata/RHSA-2026:3470", + "https://access.redhat.com/errata/RHSA-2026:3471", + "https://access.redhat.com/errata/RHSA-2026:3472", + "https://access.redhat.com/errata/RHSA-2026:3473", + "https://access.redhat.com/errata/RHSA-2026:3489", + "https://access.redhat.com/errata/RHSA-2026:3506", + "https://access.redhat.com/errata/RHSA-2026:3556", + "https://access.redhat.com/errata/RHSA-2026:3559", + "https://access.redhat.com/errata/RHSA-2026:3668", + "https://access.redhat.com/errata/RHSA-2026:3669", + "https://access.redhat.com/errata/RHSA-2026:36873", + "https://access.redhat.com/errata/RHSA-2026:36882", + "https://access.redhat.com/errata/RHSA-2026:3699", + "https://access.redhat.com/errata/RHSA-2026:3713", + "https://access.redhat.com/errata/RHSA-2026:37275", + "https://access.redhat.com/errata/RHSA-2026:3752", + "https://access.redhat.com/errata/RHSA-2026:3753", + "https://access.redhat.com/errata/RHSA-2026:3782", + "https://access.redhat.com/errata/RHSA-2026:3812", + "https://access.redhat.com/errata/RHSA-2026:3813", + "https://access.redhat.com/errata/RHSA-2026:3814", + "https://access.redhat.com/errata/RHSA-2026:3815", + "https://access.redhat.com/errata/RHSA-2026:3816", + "https://access.redhat.com/errata/RHSA-2026:3817", + "https://access.redhat.com/errata/RHSA-2026:3818", + "https://access.redhat.com/errata/RHSA-2026:3820", + "https://access.redhat.com/errata/RHSA-2026:3821", + "https://access.redhat.com/errata/RHSA-2026:3822", + "https://access.redhat.com/errata/RHSA-2026:3831", + "https://access.redhat.com/errata/RHSA-2026:3833", + "https://access.redhat.com/errata/RHSA-2026:3835", + "https://access.redhat.com/errata/RHSA-2026:3836", + "https://access.redhat.com/errata/RHSA-2026:3838", + "https://access.redhat.com/errata/RHSA-2026:3839", + "https://access.redhat.com/errata/RHSA-2026:3840", + "https://access.redhat.com/errata/RHSA-2026:3841", + "https://access.redhat.com/errata/RHSA-2026:3843", + "https://access.redhat.com/errata/RHSA-2026:3854", + "https://access.redhat.com/errata/RHSA-2026:3855", + "https://access.redhat.com/errata/RHSA-2026:3856", + "https://access.redhat.com/errata/RHSA-2026:3864", + "https://access.redhat.com/errata/RHSA-2026:3869", + "https://access.redhat.com/errata/RHSA-2026:3874", + "https://access.redhat.com/errata/RHSA-2026:3875", + "https://access.redhat.com/errata/RHSA-2026:3879", + "https://access.redhat.com/errata/RHSA-2026:3880", + "https://access.redhat.com/errata/RHSA-2026:3884", + "https://access.redhat.com/errata/RHSA-2026:3898", + "https://access.redhat.com/errata/RHSA-2026:3905", + "https://access.redhat.com/errata/RHSA-2026:3906", + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/errata/RHSA-2026:3929", + "https://access.redhat.com/errata/RHSA-2026:3930", + "https://access.redhat.com/errata/RHSA-2026:3931", + "https://access.redhat.com/errata/RHSA-2026:3932", + "https://access.redhat.com/errata/RHSA-2026:3958", + "https://access.redhat.com/errata/RHSA-2026:3959", + "https://access.redhat.com/errata/RHSA-2026:3960", + "https://access.redhat.com/errata/RHSA-2026:3970", + "https://access.redhat.com/errata/RHSA-2026:3971", + "https://access.redhat.com/errata/RHSA-2026:3972", + "https://access.redhat.com/errata/RHSA-2026:3973", + "https://access.redhat.com/errata/RHSA-2026:3974", + "https://access.redhat.com/errata/RHSA-2026:3977", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:3985", + "https://access.redhat.com/errata/RHSA-2026:40924", + "https://access.redhat.com/errata/RHSA-2026:4164", + "https://access.redhat.com/errata/RHSA-2026:4166", + "https://access.redhat.com/errata/RHSA-2026:4170", + "https://access.redhat.com/errata/RHSA-2026:4174", + "https://access.redhat.com/errata/RHSA-2026:4177", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41941", + "https://access.redhat.com/errata/RHSA-2026:4211", + "https://access.redhat.com/errata/RHSA-2026:4220", + "https://access.redhat.com/errata/RHSA-2026:4256", + "https://access.redhat.com/errata/RHSA-2026:4264", + "https://access.redhat.com/errata/RHSA-2026:4267", + "https://access.redhat.com/errata/RHSA-2026:4270", + "https://access.redhat.com/errata/RHSA-2026:4276", + "https://access.redhat.com/errata/RHSA-2026:4434", + "https://access.redhat.com/errata/RHSA-2026:4435", + "https://access.redhat.com/errata/RHSA-2026:4460", + "https://access.redhat.com/errata/RHSA-2026:4466", + "https://access.redhat.com/errata/RHSA-2026:4467", + "https://access.redhat.com/errata/RHSA-2026:4498", + "https://access.redhat.com/errata/RHSA-2026:4500", + "https://access.redhat.com/errata/RHSA-2026:4510", + "https://access.redhat.com/errata/RHSA-2026:4511", + "https://access.redhat.com/errata/RHSA-2026:4672", + "https://access.redhat.com/errata/RHSA-2026:46903", + "https://access.redhat.com/errata/RHSA-2026:4753", + "https://access.redhat.com/errata/RHSA-2026:4892", + "https://access.redhat.com/errata/RHSA-2026:4901", + "https://access.redhat.com/errata/RHSA-2026:4907", + "https://access.redhat.com/errata/RHSA-2026:4939", + "https://access.redhat.com/errata/RHSA-2026:4942", + "https://access.redhat.com/errata/RHSA-2026:4943", + "https://access.redhat.com/errata/RHSA-2026:4952", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5022", + "https://access.redhat.com/errata/RHSA-2026:5030", + "https://access.redhat.com/errata/RHSA-2026:5031", + "https://access.redhat.com/errata/RHSA-2026:5076", + "https://access.redhat.com/errata/RHSA-2026:5077", + "https://access.redhat.com/errata/RHSA-2026:5078", + "https://access.redhat.com/errata/RHSA-2026:5079", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:5129", + "https://access.redhat.com/errata/RHSA-2026:5130", + "https://access.redhat.com/errata/RHSA-2026:5131", + "https://access.redhat.com/errata/RHSA-2026:5132", + "https://access.redhat.com/errata/RHSA-2026:5145", + "https://access.redhat.com/errata/RHSA-2026:5146", + "https://access.redhat.com/errata/RHSA-2026:5168", + "https://access.redhat.com/errata/RHSA-2026:5327", + "https://access.redhat.com/errata/RHSA-2026:5394", + "https://access.redhat.com/errata/RHSA-2026:5439", + "https://access.redhat.com/errata/RHSA-2026:5444", + "https://access.redhat.com/errata/RHSA-2026:5447", + "https://access.redhat.com/errata/RHSA-2026:5452", + "https://access.redhat.com/errata/RHSA-2026:5461", + "https://access.redhat.com/errata/RHSA-2026:5463", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5533", + "https://access.redhat.com/errata/RHSA-2026:5544", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:5636", + "https://access.redhat.com/errata/RHSA-2026:56366", + "https://access.redhat.com/errata/RHSA-2026:56431", + "https://access.redhat.com/errata/RHSA-2026:5645", + "https://access.redhat.com/errata/RHSA-2026:5649", + "https://access.redhat.com/errata/RHSA-2026:5665", + "https://access.redhat.com/errata/RHSA-2026:57013", + "https://access.redhat.com/errata/RHSA-2026:5807", + "https://access.redhat.com/errata/RHSA-2026:5851", + "https://access.redhat.com/errata/RHSA-2026:5852", + "https://access.redhat.com/errata/RHSA-2026:5853", + "https://access.redhat.com/errata/RHSA-2026:5948", + "https://access.redhat.com/errata/RHSA-2026:5950", + "https://access.redhat.com/errata/RHSA-2026:5952", + "https://access.redhat.com/errata/RHSA-2026:5968", + "https://access.redhat.com/errata/RHSA-2026:6184", + "https://access.redhat.com/errata/RHSA-2026:6192", + "https://access.redhat.com/errata/RHSA-2026:6226", + "https://access.redhat.com/errata/RHSA-2026:6251", + "https://access.redhat.com/errata/RHSA-2026:6277", + "https://access.redhat.com/errata/RHSA-2026:6278", + "https://access.redhat.com/errata/RHSA-2026:6428", + "https://access.redhat.com/errata/RHSA-2026:6429", + "https://access.redhat.com/errata/RHSA-2026:6497", + "https://access.redhat.com/errata/RHSA-2026:6554", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:6567", + "https://access.redhat.com/errata/RHSA-2026:6568", + "https://access.redhat.com/errata/RHSA-2026:66401", + "https://access.redhat.com/errata/RHSA-2026:7052", + "https://access.redhat.com/errata/RHSA-2026:7249", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7676", + "https://access.redhat.com/errata/RHSA-2026:7854", + "https://access.redhat.com/errata/RHSA-2026:7942", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8218", + "https://access.redhat.com/errata/RHSA-2026:8229", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8431", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9848", + "https://access.redhat.com/security/cve/CVE-2025-61726", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-4177.html", + "https://errata.rockylinux.org/RLSA-2026:4177", + "https://go.dev/cl/736712", + "https://go.dev/issue/77101", + "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc", + "https://linux.oracle.com/cve/CVE-2025-61726.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61726", + "https://pkg.go.dev/vuln/GO-2026-4341", + "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json", + "https://www.cve.org/CVERecord?id=CVE-2025-61726" + ], + "PublishedDate": "2026-01-28T20:16:09.713Z", + "LastModifiedDate": "2026-09-11T13:16:49.81Z" + }, + { + "VulnerabilityID": "CVE-2025-61729", + "VendorIDs": [ + "GO-2025-4155" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.24.11, 1.25.5", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-61729", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:d7e5e7734c69cbd7621f0b90b22f75df51bbf1668935979fe9f2f86054824576", + "Title": "crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate", + "Description": "Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "cbl-mariner": 1, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:3928", + "https://access.redhat.com/security/cve/CVE-2025-61729", + "https://bugzilla.redhat.com/2418462", + "https://bugzilla.redhat.com/2434432", + "https://bugzilla.redhat.com/2437111", + "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", + "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", + "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61726", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61729", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68121", + "https://errata.almalinux.org/9/ALSA-2026-3928.html", + "https://errata.rockylinux.org/RLSA-2026:3928", + "https://go.dev/cl/725920", + "https://go.dev/issue/76445", + "https://groups.google.com/g/golang-announce/c/8FJoBkPddm4", + "https://linux.oracle.com/cve/CVE-2025-61729.html", + "https://linux.oracle.com/errata/ELSA-2026-5146.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-61729", + "https://pkg.go.dev/vuln/GO-2025-4155", + "https://www.cve.org/CVERecord?id=CVE-2025-61729" + ], + "PublishedDate": "2025-12-02T19:15:51.447Z", + "LastModifiedDate": "2026-06-17T09:50:48.507Z" + }, + { + "VulnerabilityID": "CVE-2026-25679", + "VendorIDs": [ + "GO-2026-4601" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.8, 1.26.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-25679", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:56e02f7cd346e0e23b77d3b151ceb12bd4d1daf93a5328ceceea0634ece1a7ac", + "Title": "net/url: Incorrect parsing of IPv6 host literals in net/url", + "Description": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-425", + "CWE-1286" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10065", + "https://access.redhat.com/errata/RHSA-2026:10125", + "https://access.redhat.com/errata/RHSA-2026:10133", + "https://access.redhat.com/errata/RHSA-2026:10140", + "https://access.redhat.com/errata/RHSA-2026:10141", + "https://access.redhat.com/errata/RHSA-2026:10158", + "https://access.redhat.com/errata/RHSA-2026:10169", + "https://access.redhat.com/errata/RHSA-2026:10175", + "https://access.redhat.com/errata/RHSA-2026:10184", + "https://access.redhat.com/errata/RHSA-2026:10225", + "https://access.redhat.com/errata/RHSA-2026:10250", + "https://access.redhat.com/errata/RHSA-2026:10701", + "https://access.redhat.com/errata/RHSA-2026:10712", + "https://access.redhat.com/errata/RHSA-2026:10929", + "https://access.redhat.com/errata/RHSA-2026:11217", + "https://access.redhat.com/errata/RHSA-2026:11375", + "https://access.redhat.com/errata/RHSA-2026:11412", + "https://access.redhat.com/errata/RHSA-2026:11413", + "https://access.redhat.com/errata/RHSA-2026:11686", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:11747", + "https://access.redhat.com/errata/RHSA-2026:11749", + "https://access.redhat.com/errata/RHSA-2026:11768", + "https://access.redhat.com/errata/RHSA-2026:11800", + "https://access.redhat.com/errata/RHSA-2026:11856", + "https://access.redhat.com/errata/RHSA-2026:11916", + "https://access.redhat.com/errata/RHSA-2026:11996", + "https://access.redhat.com/errata/RHSA-2026:12028", + "https://access.redhat.com/errata/RHSA-2026:12029", + "https://access.redhat.com/errata/RHSA-2026:12030", + "https://access.redhat.com/errata/RHSA-2026:12031", + "https://access.redhat.com/errata/RHSA-2026:12032", + "https://access.redhat.com/errata/RHSA-2026:12033", + "https://access.redhat.com/errata/RHSA-2026:12282", + "https://access.redhat.com/errata/RHSA-2026:13508", + "https://access.redhat.com/errata/RHSA-2026:13512", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13642", + "https://access.redhat.com/errata/RHSA-2026:13643", + "https://access.redhat.com/errata/RHSA-2026:13671", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14100", + "https://access.redhat.com/errata/RHSA-2026:14774", + "https://access.redhat.com/errata/RHSA-2026:14868", + "https://access.redhat.com/errata/RHSA-2026:14879", + "https://access.redhat.com/errata/RHSA-2026:15091", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16696", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17040", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:17598", + "https://access.redhat.com/errata/RHSA-2026:19017", + "https://access.redhat.com/errata/RHSA-2026:19022", + "https://access.redhat.com/errata/RHSA-2026:19026", + "https://access.redhat.com/errata/RHSA-2026:19027", + "https://access.redhat.com/errata/RHSA-2026:19031", + "https://access.redhat.com/errata/RHSA-2026:19032", + "https://access.redhat.com/errata/RHSA-2026:19049", + "https://access.redhat.com/errata/RHSA-2026:19055", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19128", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19181", + "https://access.redhat.com/errata/RHSA-2026:19184", + "https://access.redhat.com/errata/RHSA-2026:19185", + "https://access.redhat.com/errata/RHSA-2026:19207", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19475", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:20041", + "https://access.redhat.com/errata/RHSA-2026:20088", + "https://access.redhat.com/errata/RHSA-2026:20581", + "https://access.redhat.com/errata/RHSA-2026:20582", + "https://access.redhat.com/errata/RHSA-2026:20584", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21657", + "https://access.redhat.com/errata/RHSA-2026:21691", + "https://access.redhat.com/errata/RHSA-2026:21696", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22627", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22733", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24386", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:25043", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26445", + "https://access.redhat.com/errata/RHSA-2026:26527", + "https://access.redhat.com/errata/RHSA-2026:26541", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28893", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:5110", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:52389", + "https://access.redhat.com/errata/RHSA-2026:52390", + "https://access.redhat.com/errata/RHSA-2026:52391", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:5549", + "https://access.redhat.com/errata/RHSA-2026:56785", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:5941", + "https://access.redhat.com/errata/RHSA-2026:5942", + "https://access.redhat.com/errata/RHSA-2026:5943", + "https://access.redhat.com/errata/RHSA-2026:5944", + "https://access.redhat.com/errata/RHSA-2026:59830", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:6341", + "https://access.redhat.com/errata/RHSA-2026:6344", + "https://access.redhat.com/errata/RHSA-2026:6382", + "https://access.redhat.com/errata/RHSA-2026:6383", + "https://access.redhat.com/errata/RHSA-2026:6388", + "https://access.redhat.com/errata/RHSA-2026:6564", + "https://access.redhat.com/errata/RHSA-2026:66401", + "https://access.redhat.com/errata/RHSA-2026:6720", + "https://access.redhat.com/errata/RHSA-2026:6802", + "https://access.redhat.com/errata/RHSA-2026:6949", + "https://access.redhat.com/errata/RHSA-2026:7005", + "https://access.redhat.com/errata/RHSA-2026:7009", + "https://access.redhat.com/errata/RHSA-2026:7011", + "https://access.redhat.com/errata/RHSA-2026:7259", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7315", + "https://access.redhat.com/errata/RHSA-2026:7328", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/errata/RHSA-2026:7665", + "https://access.redhat.com/errata/RHSA-2026:7669", + "https://access.redhat.com/errata/RHSA-2026:7674", + "https://access.redhat.com/errata/RHSA-2026:7833", + "https://access.redhat.com/errata/RHSA-2026:7834", + "https://access.redhat.com/errata/RHSA-2026:7876", + "https://access.redhat.com/errata/RHSA-2026:7877", + "https://access.redhat.com/errata/RHSA-2026:7878", + "https://access.redhat.com/errata/RHSA-2026:7879", + "https://access.redhat.com/errata/RHSA-2026:7883", + "https://access.redhat.com/errata/RHSA-2026:7992", + "https://access.redhat.com/errata/RHSA-2026:8151", + "https://access.redhat.com/errata/RHSA-2026:8167", + "https://access.redhat.com/errata/RHSA-2026:8314", + "https://access.redhat.com/errata/RHSA-2026:8322", + "https://access.redhat.com/errata/RHSA-2026:8324", + "https://access.redhat.com/errata/RHSA-2026:8337", + "https://access.redhat.com/errata/RHSA-2026:8338", + "https://access.redhat.com/errata/RHSA-2026:8433", + "https://access.redhat.com/errata/RHSA-2026:8434", + "https://access.redhat.com/errata/RHSA-2026:8456", + "https://access.redhat.com/errata/RHSA-2026:8483", + "https://access.redhat.com/errata/RHSA-2026:8484", + "https://access.redhat.com/errata/RHSA-2026:8490", + "https://access.redhat.com/errata/RHSA-2026:8491", + "https://access.redhat.com/errata/RHSA-2026:8493", + "https://access.redhat.com/errata/RHSA-2026:8840", + "https://access.redhat.com/errata/RHSA-2026:8841", + "https://access.redhat.com/errata/RHSA-2026:8842", + "https://access.redhat.com/errata/RHSA-2026:8845", + "https://access.redhat.com/errata/RHSA-2026:8847", + "https://access.redhat.com/errata/RHSA-2026:8848", + "https://access.redhat.com/errata/RHSA-2026:8849", + "https://access.redhat.com/errata/RHSA-2026:8851", + "https://access.redhat.com/errata/RHSA-2026:8852", + "https://access.redhat.com/errata/RHSA-2026:8853", + "https://access.redhat.com/errata/RHSA-2026:8855", + "https://access.redhat.com/errata/RHSA-2026:8856", + "https://access.redhat.com/errata/RHSA-2026:8860", + "https://access.redhat.com/errata/RHSA-2026:8877", + "https://access.redhat.com/errata/RHSA-2026:8878", + "https://access.redhat.com/errata/RHSA-2026:8879", + "https://access.redhat.com/errata/RHSA-2026:8881", + "https://access.redhat.com/errata/RHSA-2026:8882", + "https://access.redhat.com/errata/RHSA-2026:8930", + "https://access.redhat.com/errata/RHSA-2026:8931", + "https://access.redhat.com/errata/RHSA-2026:8949", + "https://access.redhat.com/errata/RHSA-2026:9043", + "https://access.redhat.com/errata/RHSA-2026:9044", + "https://access.redhat.com/errata/RHSA-2026:9052", + "https://access.redhat.com/errata/RHSA-2026:9090", + "https://access.redhat.com/errata/RHSA-2026:9093", + "https://access.redhat.com/errata/RHSA-2026:9094", + "https://access.redhat.com/errata/RHSA-2026:9097", + "https://access.redhat.com/errata/RHSA-2026:9098", + "https://access.redhat.com/errata/RHSA-2026:9108", + "https://access.redhat.com/errata/RHSA-2026:9109", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/errata/RHSA-2026:9434", + "https://access.redhat.com/errata/RHSA-2026:9435", + "https://access.redhat.com/errata/RHSA-2026:9436", + "https://access.redhat.com/errata/RHSA-2026:9439", + "https://access.redhat.com/errata/RHSA-2026:9440", + "https://access.redhat.com/errata/RHSA-2026:9448", + "https://access.redhat.com/errata/RHSA-2026:9453", + "https://access.redhat.com/errata/RHSA-2026:9461", + "https://access.redhat.com/errata/RHSA-2026:9695", + "https://access.redhat.com/errata/RHSA-2026:9742", + "https://access.redhat.com/errata/RHSA-2026:9872", + "https://access.redhat.com/security/cve/CVE-2026-25679", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://errata.almalinux.org/9/ALSA-2026-9044.html", + "https://errata.rockylinux.org/RLSA-2026:9044", + "https://go.dev/cl/752180", + "https://go.dev/issue/77578", + "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk", + "https://linux.oracle.com/cve/CVE-2026-25679.html", + "https://linux.oracle.com/errata/ELSA-2026-9044.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-25679", + "https://pkg.go.dev/vuln/GO-2026-4601", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json", + "https://www.cve.org/CVERecord?id=CVE-2026-25679" + ], + "PublishedDate": "2026-03-06T22:16:00.72Z", + "LastModifiedDate": "2026-09-11T13:17:13.637Z" + }, + { + "VulnerabilityID": "CVE-2026-27145", + "VendorIDs": [ + "GO-2026-5037" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27145", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3a7c09b1d1aae4c56ea7871cfa8b82a1887516521bbe983e8dcf0a1b590fb325", + "Title": "crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries", + "Description": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:29980", + "https://access.redhat.com/errata/RHSA-2026:29981", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:36317", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46394", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49705", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:49729", + "https://access.redhat.com/errata/RHSA-2026:49744", + "https://access.redhat.com/errata/RHSA-2026:49765", + "https://access.redhat.com/errata/RHSA-2026:49770", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:52946", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53416", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54427", + "https://access.redhat.com/errata/RHSA-2026:54432", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54525", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54603", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:55899", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57488", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:59556", + "https://access.redhat.com/errata/RHSA-2026:59557", + "https://access.redhat.com/errata/RHSA-2026:59558", + "https://access.redhat.com/errata/RHSA-2026:59559", + "https://access.redhat.com/errata/RHSA-2026:59579", + "https://access.redhat.com/errata/RHSA-2026:59593", + "https://access.redhat.com/errata/RHSA-2026:60025", + "https://access.redhat.com/errata/RHSA-2026:60315", + "https://access.redhat.com/errata/RHSA-2026:60354", + "https://access.redhat.com/errata/RHSA-2026:60386", + "https://access.redhat.com/errata/RHSA-2026:60387", + "https://access.redhat.com/errata/RHSA-2026:60388", + "https://access.redhat.com/errata/RHSA-2026:60390", + "https://access.redhat.com/errata/RHSA-2026:60391", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:61314", + "https://access.redhat.com/errata/RHSA-2026:63016", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/security/cve/CVE-2026-27145", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2484207", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", + "https://errata.almalinux.org/9/ALSA-2026-36317.html", + "https://errata.rockylinux.org/RLSA-2026:36317", + "https://go.dev/cl/783621", + "https://go.dev/issue/79694", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-27145.html", + "https://linux.oracle.com/errata/ELSA-2026-46395.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27145", + "https://pkg.go.dev/vuln/GO-2026-5037", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json", + "https://www.cve.org/CVERecord?id=CVE-2026-27145" + ], + "PublishedDate": "2026-06-02T23:16:35.57Z", + "LastModifiedDate": "2026-09-11T13:17:23.34Z" + }, + { + "VulnerabilityID": "CVE-2026-32280", + "VendorIDs": [ + "GO-2026-4947" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32280", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:410ae40aee7fb35c67628e5cd49f29fceb7608c091a712b76b32aa59d9e10eac", + "Title": "crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building", + "Description": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11688", + "https://access.redhat.com/errata/RHSA-2026:13545", + "https://access.redhat.com/errata/RHSA-2026:13791", + "https://access.redhat.com/errata/RHSA-2026:13826", + "https://access.redhat.com/errata/RHSA-2026:13829", + "https://access.redhat.com/errata/RHSA-2026:14020", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16476", + "https://access.redhat.com/errata/RHSA-2026:16477", + "https://access.redhat.com/errata/RHSA-2026:16505", + "https://access.redhat.com/errata/RHSA-2026:16508", + "https://access.redhat.com/errata/RHSA-2026:16532", + "https://access.redhat.com/errata/RHSA-2026:16534", + "https://access.redhat.com/errata/RHSA-2026:16535", + "https://access.redhat.com/errata/RHSA-2026:16537", + "https://access.redhat.com/errata/RHSA-2026:16542", + "https://access.redhat.com/errata/RHSA-2026:16874", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19375", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:20889", + "https://access.redhat.com/errata/RHSA-2026:21017", + "https://access.redhat.com/errata/RHSA-2026:21338", + "https://access.redhat.com/errata/RHSA-2026:21655", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:21772", + "https://access.redhat.com/errata/RHSA-2026:22130", + "https://access.redhat.com/errata/RHSA-2026:22141", + "https://access.redhat.com/errata/RHSA-2026:22258", + "https://access.redhat.com/errata/RHSA-2026:22260", + "https://access.redhat.com/errata/RHSA-2026:22268", + "https://access.redhat.com/errata/RHSA-2026:22309", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22415", + "https://access.redhat.com/errata/RHSA-2026:22422", + "https://access.redhat.com/errata/RHSA-2026:22465", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22840", + "https://access.redhat.com/errata/RHSA-2026:22862", + "https://access.redhat.com/errata/RHSA-2026:22958", + "https://access.redhat.com/errata/RHSA-2026:22959", + "https://access.redhat.com/errata/RHSA-2026:22960", + "https://access.redhat.com/errata/RHSA-2026:22961", + "https://access.redhat.com/errata/RHSA-2026:22962", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23244", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:23361", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24359", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24478", + "https://access.redhat.com/errata/RHSA-2026:24716", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:24853", + "https://access.redhat.com/errata/RHSA-2026:24977", + "https://access.redhat.com/errata/RHSA-2026:25089", + "https://access.redhat.com/errata/RHSA-2026:25127", + "https://access.redhat.com/errata/RHSA-2026:25180", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:25253", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26568", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26585", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:28196", + "https://access.redhat.com/errata/RHSA-2026:28198", + "https://access.redhat.com/errata/RHSA-2026:28441", + "https://access.redhat.com/errata/RHSA-2026:28886", + "https://access.redhat.com/errata/RHSA-2026:28961", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29702", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:29854", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34097", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:39894", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49526", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54603", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56785", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56855", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:56913", + "https://access.redhat.com/errata/RHSA-2026:57409", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57488", + "https://access.redhat.com/errata/RHSA-2026:59830", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:59834", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61685", + "https://access.redhat.com/errata/RHSA-2026:61906", + "https://access.redhat.com/errata/RHSA-2026:61907", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:66401", + "https://access.redhat.com/errata/RHSA-2026:9385", + "https://access.redhat.com/security/cve/CVE-2026-32280", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/758320", + "https://go.dev/issue/78282", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32280.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32280", + "https://pkg.go.dev/vuln/GO-2026-4947", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32280" + ], + "PublishedDate": "2026-04-08T02:16:03.247Z", + "LastModifiedDate": "2026-09-11T13:17:25.78Z" + }, + { + "VulnerabilityID": "CVE-2026-32281", + "VendorIDs": [ + "GO-2026-4946" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32281", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3947214e46925b7bcc5973fb91791daf2df731a64d5664c98c3670ffb6aef6e8", + "Title": "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation", + "Description": "Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:49838", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-32281", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-49838.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/758061", + "https://go.dev/issue/78281", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32281.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32281", + "https://pkg.go.dev/vuln/GO-2026-4946", + "https://www.cve.org/CVERecord?id=CVE-2026-32281" + ], + "PublishedDate": "2026-04-08T02:16:03.35Z", + "LastModifiedDate": "2026-07-25T10:10:00.167Z" + }, + { + "VulnerabilityID": "CVE-2026-32283", + "VendorIDs": [ + "GO-2026-4870" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.9, 1.26.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-32283", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:965802bb9463307b15770c73fae0a2f95f237afbd1db40c33004e4bc4f732115", + "Title": "crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages", + "Description": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-764" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:10217", + "https://access.redhat.com/errata/RHSA-2026:10219", + "https://access.redhat.com/errata/RHSA-2026:10704", + "https://access.redhat.com/errata/RHSA-2026:11507", + "https://access.redhat.com/errata/RHSA-2026:11514", + "https://access.redhat.com/errata/RHSA-2026:11704", + "https://access.redhat.com/errata/RHSA-2026:11711", + "https://access.redhat.com/errata/RHSA-2026:11712", + "https://access.redhat.com/errata/RHSA-2026:11863", + "https://access.redhat.com/errata/RHSA-2026:11881", + "https://access.redhat.com/errata/RHSA-2026:14162", + "https://access.redhat.com/errata/RHSA-2026:14200", + "https://access.redhat.com/errata/RHSA-2026:14391", + "https://access.redhat.com/errata/RHSA-2026:15980", + "https://access.redhat.com/errata/RHSA-2026:16021", + "https://access.redhat.com/errata/RHSA-2026:16024", + "https://access.redhat.com/errata/RHSA-2026:16101", + "https://access.redhat.com/errata/RHSA-2026:16102", + "https://access.redhat.com/errata/RHSA-2026:16875", + "https://access.redhat.com/errata/RHSA-2026:17075", + "https://access.redhat.com/errata/RHSA-2026:17084", + "https://access.redhat.com/errata/RHSA-2026:17287", + "https://access.redhat.com/errata/RHSA-2026:18027", + "https://access.redhat.com/errata/RHSA-2026:18032", + "https://access.redhat.com/errata/RHSA-2026:19126", + "https://access.redhat.com/errata/RHSA-2026:19132", + "https://access.redhat.com/errata/RHSA-2026:19133", + "https://access.redhat.com/errata/RHSA-2026:19134", + "https://access.redhat.com/errata/RHSA-2026:19135", + "https://access.redhat.com/errata/RHSA-2026:19136", + "https://access.redhat.com/errata/RHSA-2026:19137", + "https://access.redhat.com/errata/RHSA-2026:19139", + "https://access.redhat.com/errata/RHSA-2026:19144", + "https://access.redhat.com/errata/RHSA-2026:19156", + "https://access.redhat.com/errata/RHSA-2026:19350", + "https://access.redhat.com/errata/RHSA-2026:19351", + "https://access.redhat.com/errata/RHSA-2026:19352", + "https://access.redhat.com/errata/RHSA-2026:19353", + "https://access.redhat.com/errata/RHSA-2026:19369", + "https://access.redhat.com/errata/RHSA-2026:19450", + "https://access.redhat.com/errata/RHSA-2026:19550", + "https://access.redhat.com/errata/RHSA-2026:19634", + "https://access.redhat.com/errata/RHSA-2026:19714", + "https://access.redhat.com/errata/RHSA-2026:19715", + "https://access.redhat.com/errata/RHSA-2026:19719", + "https://access.redhat.com/errata/RHSA-2026:19720", + "https://access.redhat.com/errata/RHSA-2026:19721", + "https://access.redhat.com/errata/RHSA-2026:19722", + "https://access.redhat.com/errata/RHSA-2026:19750", + "https://access.redhat.com/errata/RHSA-2026:19839", + "https://access.redhat.com/errata/RHSA-2026:20556", + "https://access.redhat.com/errata/RHSA-2026:20569", + "https://access.redhat.com/errata/RHSA-2026:20570", + "https://access.redhat.com/errata/RHSA-2026:20571", + "https://access.redhat.com/errata/RHSA-2026:20607", + "https://access.redhat.com/errata/RHSA-2026:20608", + "https://access.redhat.com/errata/RHSA-2026:20609", + "https://access.redhat.com/errata/RHSA-2026:21769", + "https://access.redhat.com/errata/RHSA-2026:22347", + "https://access.redhat.com/errata/RHSA-2026:22423", + "https://access.redhat.com/errata/RHSA-2026:22450", + "https://access.redhat.com/errata/RHSA-2026:22485", + "https://access.redhat.com/errata/RHSA-2026:22709", + "https://access.redhat.com/errata/RHSA-2026:22713", + "https://access.redhat.com/errata/RHSA-2026:22714", + "https://access.redhat.com/errata/RHSA-2026:22937", + "https://access.redhat.com/errata/RHSA-2026:23102", + "https://access.redhat.com/errata/RHSA-2026:23103", + "https://access.redhat.com/errata/RHSA-2026:23228", + "https://access.redhat.com/errata/RHSA-2026:23345", + "https://access.redhat.com/errata/RHSA-2026:24337", + "https://access.redhat.com/errata/RHSA-2026:24470", + "https://access.redhat.com/errata/RHSA-2026:24761", + "https://access.redhat.com/errata/RHSA-2026:24762", + "https://access.redhat.com/errata/RHSA-2026:25248", + "https://access.redhat.com/errata/RHSA-2026:25250", + "https://access.redhat.com/errata/RHSA-2026:25251", + "https://access.redhat.com/errata/RHSA-2026:25252", + "https://access.redhat.com/errata/RHSA-2026:26447", + "https://access.redhat.com/errata/RHSA-2026:26571", + "https://access.redhat.com/errata/RHSA-2026:26636", + "https://access.redhat.com/errata/RHSA-2026:27076", + "https://access.redhat.com/errata/RHSA-2026:28038", + "https://access.redhat.com/errata/RHSA-2026:28047", + "https://access.redhat.com/errata/RHSA-2026:28074", + "https://access.redhat.com/errata/RHSA-2026:29035", + "https://access.redhat.com/errata/RHSA-2026:29195", + "https://access.redhat.com/errata/RHSA-2026:29455", + "https://access.redhat.com/errata/RHSA-2026:29703", + "https://access.redhat.com/errata/RHSA-2026:33722", + "https://access.redhat.com/errata/RHSA-2026:34192", + "https://access.redhat.com/errata/RHSA-2026:34196", + "https://access.redhat.com/errata/RHSA-2026:34197", + "https://access.redhat.com/errata/RHSA-2026:34365", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:47712", + "https://access.redhat.com/errata/RHSA-2026:47714", + "https://access.redhat.com/errata/RHSA-2026:47716", + "https://access.redhat.com/errata/RHSA-2026:47719", + "https://access.redhat.com/errata/RHSA-2026:47721", + "https://access.redhat.com/errata/RHSA-2026:47722", + "https://access.redhat.com/errata/RHSA-2026:47910", + "https://access.redhat.com/errata/RHSA-2026:48036", + "https://access.redhat.com/errata/RHSA-2026:48790", + "https://access.redhat.com/errata/RHSA-2026:49509", + "https://access.redhat.com/errata/RHSA-2026:49600", + "https://access.redhat.com/errata/RHSA-2026:49944", + "https://access.redhat.com/errata/RHSA-2026:51288", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:55898", + "https://access.redhat.com/errata/RHSA-2026:55900", + "https://access.redhat.com/errata/RHSA-2026:55901", + "https://access.redhat.com/errata/RHSA-2026:55902", + "https://access.redhat.com/errata/RHSA-2026:55903", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:57409", + "https://access.redhat.com/errata/RHSA-2026:57801", + "https://access.redhat.com/errata/RHSA-2026:57802", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65343", + "https://access.redhat.com/errata/RHSA-2026:65514", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66084", + "https://access.redhat.com/errata/RHSA-2026:66401", + "https://access.redhat.com/errata/RHSA-2026:66523", + "https://access.redhat.com/errata/RHSA-2026:7291", + "https://access.redhat.com/errata/RHSA-2026:7385", + "https://access.redhat.com/security/cve/CVE-2026-32283", + "https://bugzilla.redhat.com/2445356", + "https://bugzilla.redhat.com/2456333", + "https://bugzilla.redhat.com/2456338", + "https://bugzilla.redhat.com/2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456338", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32283", + "https://errata.almalinux.org/9/ALSA-2026-29703.html", + "https://errata.rockylinux.org/RLSA-2026:29703", + "https://go.dev/cl/763767", + "https://go.dev/issue/78334", + "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU", + "https://linux.oracle.com/cve/CVE-2026-32283.html", + "https://linux.oracle.com/errata/ELSA-2026-48790.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-32283", + "https://pkg.go.dev/vuln/GO-2026-4870", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json", + "https://www.cve.org/CVERecord?id=CVE-2026-32283" + ], + "PublishedDate": "2026-04-08T02:16:03.58Z", + "LastModifiedDate": "2026-09-11T13:17:28.143Z" + }, + { + "VulnerabilityID": "CVE-2026-33811", + "VendorIDs": [ + "GO-2026-4981" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33811", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:004312b4e1707e898ddf8ceb2af30341987542cfd2599ecdf4ee230992ae6179", + "Title": "net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME", + "Description": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415", + "CWE-1341" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:35832", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:35995", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36617", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36776", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:38504", + "https://access.redhat.com/errata/RHSA-2026:39266", + "https://access.redhat.com/errata/RHSA-2026:39272", + "https://access.redhat.com/errata/RHSA-2026:39319", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39810", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40119", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:42946", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:46885", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:48151", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49703", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50319", + "https://access.redhat.com/errata/RHSA-2026:50336", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51057", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54168", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54500", + "https://access.redhat.com/errata/RHSA-2026:54552", + "https://access.redhat.com/errata/RHSA-2026:54556", + "https://access.redhat.com/errata/RHSA-2026:54584", + "https://access.redhat.com/errata/RHSA-2026:54602", + "https://access.redhat.com/errata/RHSA-2026:54603", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56785", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56790", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56855", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:56913", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57488", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59559", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:60025", + "https://access.redhat.com/errata/RHSA-2026:60302", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:61313", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/security/cve/CVE-2026-33811", + "https://bugzilla.redhat.com/2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-39319.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/767860", + "https://go.dev/issue/78803", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33811.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33811", + "https://pkg.go.dev/vuln/GO-2026-4981", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json", + "https://www.cve.org/CVERecord?id=CVE-2026-33811" + ], + "PublishedDate": "2026-05-07T20:16:42.77Z", + "LastModifiedDate": "2026-09-11T13:17:36.897Z" + }, + { + "VulnerabilityID": "CVE-2026-33814", + "VendorIDs": [ + "GO-2026-4918" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33814", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:4a7b8118d6015a5713995ff44a1b2afc1358fbdf564b3deb943a8be585211fe2", + "Title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame", + "Description": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835", + "CWE-606" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:57191", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57365", + "https://access.redhat.com/errata/RHSA-2026:57367", + "https://access.redhat.com/errata/RHSA-2026:57408", + "https://access.redhat.com/errata/RHSA-2026:57545", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60023", + "https://access.redhat.com/errata/RHSA-2026:60025", + "https://access.redhat.com/errata/RHSA-2026:60441", + "https://access.redhat.com/errata/RHSA-2026:60442", + "https://access.redhat.com/errata/RHSA-2026:60446", + "https://access.redhat.com/errata/RHSA-2026:60447", + "https://access.redhat.com/errata/RHSA-2026:60454", + "https://access.redhat.com/errata/RHSA-2026:60477", + "https://access.redhat.com/errata/RHSA-2026:60478", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:60668", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62550", + "https://access.redhat.com/errata/RHSA-2026:62551", + "https://access.redhat.com/errata/RHSA-2026:63046", + "https://access.redhat.com/errata/RHSA-2026:63047", + "https://access.redhat.com/errata/RHSA-2026:63048", + "https://access.redhat.com/errata/RHSA-2026:63050", + "https://access.redhat.com/errata/RHSA-2026:63091", + "https://access.redhat.com/errata/RHSA-2026:63096", + "https://access.redhat.com/errata/RHSA-2026:63097", + "https://access.redhat.com/errata/RHSA-2026:63103", + "https://access.redhat.com/errata/RHSA-2026:63104", + "https://access.redhat.com/errata/RHSA-2026:63636", + "https://access.redhat.com/errata/RHSA-2026:63637", + "https://access.redhat.com/errata/RHSA-2026:63639", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/security/cve/CVE-2026-33814", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467810", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467811", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467813", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467823", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467825", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467826", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467827", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501", + "https://errata.rockylinux.org/RLSA-2026:22121", + "https://github.com/golang/go/issues/78476", + "https://go-review.googlesource.com/c/go/+/761581", + "https://go-review.googlesource.com/c/net/+/761640", + "https://go.dev/cl/761581", + "https://go.dev/cl/761640", + "https://go.dev/issue/78476", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-33814.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33814", + "https://pkg.go.dev/vuln/GO-2026-4918", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json", + "https://ubuntu.com/security/notices/USN-8430-1", + "https://ubuntu.com/security/notices/USN-8471-1", + "https://ubuntu.com/security/notices/USN-8472-1", + "https://ubuntu.com/security/notices/USN-8473-1", + "https://www.cve.org/CVERecord?id=CVE-2026-33814" + ], + "PublishedDate": "2026-05-07T20:16:42.88Z", + "LastModifiedDate": "2026-09-10T13:18:21.31Z" + }, + { + "VulnerabilityID": "CVE-2026-33818", + "VendorIDs": [ + "GO-2026-5972" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33818", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:21423acbb2f332d0c0700e765ddce51b45aa9858321f74ef03a70715096882c2", + "Title": "encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal", + "Description": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-400" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:66364", + "https://access.redhat.com/security/cve/CVE-2026-33818", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-66364.html", + "https://errata.rockylinux.org/RLSA-2026:66364", + "https://go.dev/cl/814980", + "https://go.dev/issue/80405", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-33818.html", + "https://linux.oracle.com/errata/ELSA-2026-66364-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33818", + "https://pkg.go.dev/vuln/GO-2026-5972", + "https://www.cve.org/CVERecord?id=CVE-2026-33818" + ], + "PublishedDate": "2026-08-13T22:17:19.84Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-39820", + "VendorIDs": [ + "GO-2026-4986" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39820", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:b9afbb8ba13f7400e14d3ffe6f645c0ae91f9935214373052359edeb17762135", + "Title": "net/mail: golang: Go net/mail: Denial of Service via crafted email inputs", + "Description": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770", + "CWE-606" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54552", + "https://access.redhat.com/errata/RHSA-2026:54555", + "https://access.redhat.com/errata/RHSA-2026:54583", + "https://access.redhat.com/errata/RHSA-2026:54602", + "https://access.redhat.com/errata/RHSA-2026:54883", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57401", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57487", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:57914", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59830", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:60023", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62260", + "https://access.redhat.com/errata/RHSA-2026:62406", + "https://access.redhat.com/errata/RHSA-2026:62407", + "https://access.redhat.com/errata/RHSA-2026:62753", + "https://access.redhat.com/errata/RHSA-2026:62754", + "https://access.redhat.com/errata/RHSA-2026:62803", + "https://access.redhat.com/errata/RHSA-2026:63022", + "https://access.redhat.com/errata/RHSA-2026:65116", + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65153", + "https://access.redhat.com/errata/RHSA-2026:65335", + "https://access.redhat.com/errata/RHSA-2026:65336", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:65895", + "https://access.redhat.com/errata/RHSA-2026:66016", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66327", + "https://access.redhat.com/security/cve/CVE-2026-39820", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/759940", + "https://go.dev/issue/78566", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39820.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39820", + "https://pkg.go.dev/vuln/GO-2026-4986", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json", + "https://www.cve.org/CVERecord?id=CVE-2026-39820" + ], + "PublishedDate": "2026-05-07T20:16:43.187Z", + "LastModifiedDate": "2026-09-11T13:17:48.093Z" + }, + { + "VulnerabilityID": "CVE-2026-39821", + "VendorIDs": [ + "GO-2026-5026" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39821", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:2be5ddbedd46473bb90605212e4e00a96dce84ee4d0bdf8f0d9667f60eba259e", + "Title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing", + "Description": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1289" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:23262", + "https://access.redhat.com/errata/RHSA-2026:23264", + "https://access.redhat.com/errata/RHSA-2026:26546", + "https://access.redhat.com/errata/RHSA-2026:26547", + "https://access.redhat.com/errata/RHSA-2026:30650", + "https://access.redhat.com/errata/RHSA-2026:30651", + "https://access.redhat.com/errata/RHSA-2026:30853", + "https://access.redhat.com/errata/RHSA-2026:30854", + "https://access.redhat.com/errata/RHSA-2026:30855", + "https://access.redhat.com/errata/RHSA-2026:33155", + "https://access.redhat.com/errata/RHSA-2026:33160", + "https://access.redhat.com/errata/RHSA-2026:33163", + "https://access.redhat.com/errata/RHSA-2026:33173", + "https://access.redhat.com/errata/RHSA-2026:33183", + "https://access.redhat.com/errata/RHSA-2026:33524", + "https://access.redhat.com/errata/RHSA-2026:33531", + "https://access.redhat.com/errata/RHSA-2026:34342", + "https://access.redhat.com/errata/RHSA-2026:34357", + "https://access.redhat.com/errata/RHSA-2026:34359", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:34789", + "https://access.redhat.com/errata/RHSA-2026:35826", + "https://access.redhat.com/errata/RHSA-2026:35827", + "https://access.redhat.com/errata/RHSA-2026:35828", + "https://access.redhat.com/errata/RHSA-2026:35829", + "https://access.redhat.com/errata/RHSA-2026:35830", + "https://access.redhat.com/errata/RHSA-2026:35831", + "https://access.redhat.com/errata/RHSA-2026:35993", + "https://access.redhat.com/errata/RHSA-2026:35994", + "https://access.redhat.com/errata/RHSA-2026:36105", + "https://access.redhat.com/errata/RHSA-2026:36167", + "https://access.redhat.com/errata/RHSA-2026:36207", + "https://access.redhat.com/errata/RHSA-2026:36648", + "https://access.redhat.com/errata/RHSA-2026:36651", + "https://access.redhat.com/errata/RHSA-2026:36796", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:36808", + "https://access.redhat.com/errata/RHSA-2026:36820", + "https://access.redhat.com/errata/RHSA-2026:36883", + "https://access.redhat.com/errata/RHSA-2026:37387", + "https://access.redhat.com/errata/RHSA-2026:37435", + "https://access.redhat.com/errata/RHSA-2026:37436", + "https://access.redhat.com/errata/RHSA-2026:38995", + "https://access.redhat.com/errata/RHSA-2026:39005", + "https://access.redhat.com/errata/RHSA-2026:39573", + "https://access.redhat.com/errata/RHSA-2026:39879", + "https://access.redhat.com/errata/RHSA-2026:40118", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:40945", + "https://access.redhat.com/errata/RHSA-2026:41019", + "https://access.redhat.com/errata/RHSA-2026:41030", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41036", + "https://access.redhat.com/errata/RHSA-2026:41055", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:41930", + "https://access.redhat.com/errata/RHSA-2026:42043", + "https://access.redhat.com/errata/RHSA-2026:42047", + "https://access.redhat.com/errata/RHSA-2026:42048", + "https://access.redhat.com/errata/RHSA-2026:42049", + "https://access.redhat.com/errata/RHSA-2026:42050", + "https://access.redhat.com/errata/RHSA-2026:42051", + "https://access.redhat.com/errata/RHSA-2026:42078", + "https://access.redhat.com/errata/RHSA-2026:42079", + "https://access.redhat.com/errata/RHSA-2026:42080", + "https://access.redhat.com/errata/RHSA-2026:42082", + "https://access.redhat.com/errata/RHSA-2026:42132", + "https://access.redhat.com/errata/RHSA-2026:42142", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42150", + "https://access.redhat.com/errata/RHSA-2026:42151", + "https://access.redhat.com/errata/RHSA-2026:42240", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:42852", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:44622", + "https://access.redhat.com/errata/RHSA-2026:44624", + "https://access.redhat.com/errata/RHSA-2026:46395", + "https://access.redhat.com/errata/RHSA-2026:47149", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:51187", + "https://access.redhat.com/errata/RHSA-2026:51194", + "https://access.redhat.com/errata/RHSA-2026:51341", + "https://access.redhat.com/errata/RHSA-2026:52826", + "https://access.redhat.com/errata/RHSA-2026:53374", + "https://access.redhat.com/errata/RHSA-2026:53412", + "https://access.redhat.com/errata/RHSA-2026:53413", + "https://access.redhat.com/errata/RHSA-2026:53415", + "https://access.redhat.com/errata/RHSA-2026:53530", + "https://access.redhat.com/errata/RHSA-2026:54191", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54395", + "https://access.redhat.com/errata/RHSA-2026:54401", + "https://access.redhat.com/errata/RHSA-2026:54435", + "https://access.redhat.com/errata/RHSA-2026:54441", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54580", + "https://access.redhat.com/errata/RHSA-2026:54757", + "https://access.redhat.com/errata/RHSA-2026:56143", + "https://access.redhat.com/errata/RHSA-2026:56223", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56431", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57541", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:59546", + "https://access.redhat.com/errata/RHSA-2026:59549", + "https://access.redhat.com/errata/RHSA-2026:59562", + "https://access.redhat.com/errata/RHSA-2026:60315", + "https://access.redhat.com/errata/RHSA-2026:60354", + "https://access.redhat.com/errata/RHSA-2026:60387", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61245", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62549", + "https://access.redhat.com/errata/RHSA-2026:63134", + "https://access.redhat.com/errata/RHSA-2026:65126", + "https://access.redhat.com/errata/RHSA-2026:65153", + "https://access.redhat.com/errata/RHSA-2026:65359", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:66016", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66432", + "https://access.redhat.com/security/cve/CVE-2026-39821", + "https://bugzilla.redhat.com/2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-37435.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://github.com/golang/go/issues/78760", + "https://go.dev/cl/767220", + "https://go.dev/issue/78760", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8", + "https://linux.oracle.com/cve/CVE-2026-39821.html", + "https://linux.oracle.com/errata/ELSA-2026-65886-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39821", + "https://pkg.go.dev/vuln/GO-2026-5026", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json", + "https://ubuntu.com/security/notices/USN-8416-1", + "https://www.cve.org/CVERecord?id=CVE-2026-39821" + ], + "PublishedDate": "2026-05-22T16:16:20.41Z", + "LastModifiedDate": "2026-09-11T13:17:49.237Z" + }, + { + "VulnerabilityID": "CVE-2026-39822", + "VendorIDs": [ + "GO-2026-4970" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.12, 1.26.5, 1.27.0-rc.2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39822", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:096a5fae6ae18cedd89d345f861f0eafa0c46af7a8efc076cf6e3cb941ead50d", + "Title": "golang: Go os.Root: Symlink following vulnerability allows directory traversal", + "Description": "On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-61" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:38878", + "https://access.redhat.com/security/cve/CVE-2026-39822", + "https://bugzilla.redhat.com/2498152", + "https://bugzilla.redhat.com/show_bug.cgi?id=2498152", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822", + "https://errata.almalinux.org/9/ALSA-2026-38878.html", + "https://errata.rockylinux.org/RLSA-2026:38878", + "https://go.dev/cl/797880", + "https://go.dev/issue/79005", + "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc", + "https://linux.oracle.com/cve/CVE-2026-39822.html", + "https://linux.oracle.com/errata/ELSA-2026-38995.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39822", + "https://pkg.go.dev/vuln/GO-2026-4970", + "https://www.cve.org/CVERecord?id=CVE-2026-39822" + ], + "PublishedDate": "2026-07-08T17:17:21.31Z", + "LastModifiedDate": "2026-07-13T14:54:26.317Z" + }, + { + "VulnerabilityID": "CVE-2026-39836", + "VendorIDs": [ + "GO-2026-4971" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-39836", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:fcfd0f80d772511c98e49faad20a1959e8fbfb9032322c9708d6028df332b15d", + "Title": "net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows", + "Description": "The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "bitnami": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 2, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/security/cve/CVE-2026-39836", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467810", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467811", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467813", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467823", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467825", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467826", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467827", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33814", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39817", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39819", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39823", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39825", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39826", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39836", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42501", + "https://errata.rockylinux.org/RLSA-2026:22121", + "https://go.dev/cl/775320", + "https://go.dev/issue/79006", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-39836.html", + "https://linux.oracle.com/errata/ELSA-2026-22121.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-39836", + "https://pkg.go.dev/vuln/GO-2026-4971", + "https://www.cve.org/CVERecord?id=CVE-2026-39836" + ], + "PublishedDate": "2026-05-07T20:16:43.593Z", + "LastModifiedDate": "2026-06-17T10:42:40.34Z" + }, + { + "VulnerabilityID": "CVE-2026-42499", + "VendorIDs": [ + "GO-2026-4977" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.10, 1.26.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42499", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:3812f89a5d6b0b5adc7ee5bfb034243adb69a3555dbc4af3dc29136f788ab678", + "Title": "net/mail: golang: net/mail: Denial of Service via pathological email address parsing", + "Description": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-1046" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:17713", + "https://access.redhat.com/errata/RHSA-2026:17714", + "https://access.redhat.com/errata/RHSA-2026:22112", + "https://access.redhat.com/errata/RHSA-2026:22120", + "https://access.redhat.com/errata/RHSA-2026:22121", + "https://access.redhat.com/errata/RHSA-2026:33120", + "https://access.redhat.com/errata/RHSA-2026:33123", + "https://access.redhat.com/errata/RHSA-2026:33142", + "https://access.redhat.com/errata/RHSA-2026:33150", + "https://access.redhat.com/errata/RHSA-2026:33574", + "https://access.redhat.com/errata/RHSA-2026:34364", + "https://access.redhat.com/errata/RHSA-2026:36319", + "https://access.redhat.com/errata/RHSA-2026:36625", + "https://access.redhat.com/errata/RHSA-2026:36754", + "https://access.redhat.com/errata/RHSA-2026:36797", + "https://access.redhat.com/errata/RHSA-2026:40262", + "https://access.redhat.com/errata/RHSA-2026:41031", + "https://access.redhat.com/errata/RHSA-2026:41066", + "https://access.redhat.com/errata/RHSA-2026:41928", + "https://access.redhat.com/errata/RHSA-2026:42146", + "https://access.redhat.com/errata/RHSA-2026:42644", + "https://access.redhat.com/errata/RHSA-2026:42796", + "https://access.redhat.com/errata/RHSA-2026:43038", + "https://access.redhat.com/errata/RHSA-2026:43052", + "https://access.redhat.com/errata/RHSA-2026:43692", + "https://access.redhat.com/errata/RHSA-2026:47952", + "https://access.redhat.com/errata/RHSA-2026:49702", + "https://access.redhat.com/errata/RHSA-2026:49712", + "https://access.redhat.com/errata/RHSA-2026:50300", + "https://access.redhat.com/errata/RHSA-2026:50843", + "https://access.redhat.com/errata/RHSA-2026:51033", + "https://access.redhat.com/errata/RHSA-2026:51112", + "https://access.redhat.com/errata/RHSA-2026:54274", + "https://access.redhat.com/errata/RHSA-2026:54283", + "https://access.redhat.com/errata/RHSA-2026:54284", + "https://access.redhat.com/errata/RHSA-2026:54285", + "https://access.redhat.com/errata/RHSA-2026:54286", + "https://access.redhat.com/errata/RHSA-2026:54287", + "https://access.redhat.com/errata/RHSA-2026:54531", + "https://access.redhat.com/errata/RHSA-2026:54552", + "https://access.redhat.com/errata/RHSA-2026:54555", + "https://access.redhat.com/errata/RHSA-2026:54583", + "https://access.redhat.com/errata/RHSA-2026:54602", + "https://access.redhat.com/errata/RHSA-2026:56340", + "https://access.redhat.com/errata/RHSA-2026:56785", + "https://access.redhat.com/errata/RHSA-2026:56789", + "https://access.redhat.com/errata/RHSA-2026:56852", + "https://access.redhat.com/errata/RHSA-2026:56854", + "https://access.redhat.com/errata/RHSA-2026:56910", + "https://access.redhat.com/errata/RHSA-2026:56912", + "https://access.redhat.com/errata/RHSA-2026:57194", + "https://access.redhat.com/errata/RHSA-2026:57482", + "https://access.redhat.com/errata/RHSA-2026:57487", + "https://access.redhat.com/errata/RHSA-2026:57649", + "https://access.redhat.com/errata/RHSA-2026:57845", + "https://access.redhat.com/errata/RHSA-2026:57914", + "https://access.redhat.com/errata/RHSA-2026:59467", + "https://access.redhat.com/errata/RHSA-2026:59830", + "https://access.redhat.com/errata/RHSA-2026:59833", + "https://access.redhat.com/errata/RHSA-2026:60018", + "https://access.redhat.com/errata/RHSA-2026:60023", + "https://access.redhat.com/errata/RHSA-2026:60520", + "https://access.redhat.com/errata/RHSA-2026:61253", + "https://access.redhat.com/errata/RHSA-2026:62260", + "https://access.redhat.com/errata/RHSA-2026:62406", + "https://access.redhat.com/errata/RHSA-2026:62407", + "https://access.redhat.com/errata/RHSA-2026:62753", + "https://access.redhat.com/errata/RHSA-2026:62754", + "https://access.redhat.com/errata/RHSA-2026:62803", + "https://access.redhat.com/errata/RHSA-2026:63022", + "https://access.redhat.com/errata/RHSA-2026:63163", + "https://access.redhat.com/errata/RHSA-2026:63332", + "https://access.redhat.com/errata/RHSA-2026:63636", + "https://access.redhat.com/errata/RHSA-2026:64818", + "https://access.redhat.com/errata/RHSA-2026:65116", + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65153", + "https://access.redhat.com/errata/RHSA-2026:65335", + "https://access.redhat.com/errata/RHSA-2026:65336", + "https://access.redhat.com/errata/RHSA-2026:65534", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/errata/RHSA-2026:65895", + "https://access.redhat.com/errata/RHSA-2026:66022", + "https://access.redhat.com/errata/RHSA-2026:66327", + "https://access.redhat.com/security/cve/CVE-2026-42499", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/771520", + "https://go.dev/issue/78987", + "https://groups.google.com/g/golang-announce/c/qcCIEXso47M", + "https://linux.oracle.com/cve/CVE-2026-42499.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42499", + "https://pkg.go.dev/vuln/GO-2026-4977", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json", + "https://www.cve.org/CVERecord?id=CVE-2026-42499" + ], + "PublishedDate": "2026-05-07T20:16:44.54Z", + "LastModifiedDate": "2026-09-11T13:17:59.763Z" + }, + { + "VulnerabilityID": "CVE-2026-42504", + "VendorIDs": [ + "GO-2026-5038" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.11, 1.26.4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42504", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:95e006aded6bebd459634358fd77bd04c5f917ae94d9c7852dfd5b9d9d631771", + "Title": "mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header", + "Description": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-42504", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/774481", + "https://go.dev/issue/79217", + "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw", + "https://linux.oracle.com/cve/CVE-2026-42504.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42504", + "https://pkg.go.dev/vuln/GO-2026-5038", + "https://www.cve.org/CVERecord?id=CVE-2026-42504" + ], + "PublishedDate": "2026-06-02T23:16:37.927Z", + "LastModifiedDate": "2026-07-22T19:10:00.12Z" + }, + { + "VulnerabilityID": "CVE-2026-56853", + "VendorIDs": [ + "GO-2026-6089" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56853", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:1202c86987b2c2564cd2da971d0ded8ba567117b0ba4c25358e3c9ac0f2c5168", + "Title": "net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service", + "Description": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-56853", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/795540", + "https://go.dev/issue/80205", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56853.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56853", + "https://pkg.go.dev/vuln/GO-2026-6089", + "https://www.cve.org/CVERecord?id=CVE-2026-56853" + ], + "PublishedDate": "2026-08-13T22:17:22.093Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-56858", + "VendorIDs": [ + "GO-2026-6091" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56858", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:bc535ab86cc107c694cd6971a6b23ba96728bd03585a8d23f526abfce22ff433", + "Title": "html/template: golang: Go html/template: Cross-Site Scripting via pathological input", + "Description": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-79" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 2, + "oracle-oval": 3, + "photon": 2, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", + "V3Score": 6.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-56858", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/807100", + "https://go.dev/issue/80435", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56858.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56858", + "https://pkg.go.dev/vuln/GO-2026-6091", + "https://www.cve.org/CVERecord?id=CVE-2026-56858" + ], + "PublishedDate": "2026-08-13T22:17:22.207Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-56859", + "VendorIDs": [ + "GO-2026-6088" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56859", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:ab62dc3557cb81326d275230a92ad6d0dea55e1c3efa0b4c054834941047dfed", + "Title": "encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue", + "Description": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:65117", + "https://access.redhat.com/errata/RHSA-2026:65886", + "https://access.redhat.com/security/cve/CVE-2026-56859", + "https://bugzilla.redhat.com/2467809", + "https://bugzilla.redhat.com/2467820", + "https://bugzilla.redhat.com/2484204", + "https://bugzilla.redhat.com/2484830", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515827", + "https://bugzilla.redhat.com/2515838", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/2515840", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456333", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456339", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467809", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", + "https://bugzilla.redhat.com/show_bug.cgi?id=2484204", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515827", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515838", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515840", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32280", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32281", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39820", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42499", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42504", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56853", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56858", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56859", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-65117.html", + "https://errata.rockylinux.org/RLSA-2026:65886", + "https://go.dev/cl/803320", + "https://go.dev/issue/80481", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56859.html", + "https://linux.oracle.com/errata/ELSA-2026-65895-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56859", + "https://pkg.go.dev/vuln/GO-2026-6088", + "https://www.cve.org/CVERecord?id=CVE-2026-56859" + ], + "PublishedDate": "2026-08-13T22:17:22.32Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-56860", + "VendorIDs": [ + "GO-2026-6218" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56860", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:5d4edc047f09241e4bc2ddff96c80d1d0c26a3143a6496a32bab6d3c0845da66", + "Title": "net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution", + "Description": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 2, + "oracle-oval": 3, + "photon": 2, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:66364", + "https://access.redhat.com/security/cve/CVE-2026-56860", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-66364.html", + "https://errata.rockylinux.org/RLSA-2026:66364", + "https://go.dev/cl/803681", + "https://go.dev/issue/80494", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56860.html", + "https://linux.oracle.com/errata/ELSA-2026-66364-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56860", + "https://pkg.go.dev/vuln/GO-2026-6218", + "https://www.cve.org/CVERecord?id=CVE-2026-56860" + ], + "PublishedDate": "2026-08-13T22:17:22.44Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + }, + { + "VulnerabilityID": "CVE-2026-56862", + "VendorIDs": [ + "GO-2026-6090" + ], + "PkgID": "stdlib@v1.24.6", + "PkgName": "stdlib", + "PkgIdentifier": { + "PURL": "pkg:golang/stdlib@v1.24.6", + "UID": "5a9b484fa87e1a00" + }, + "InstalledVersion": "v1.24.6", + "FixedVersion": "1.25.13, 1.26.6, 1.27.0-rc.3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:59234992055286eabeae83e92fd49c182136fabecaab40e96e44201d0b7acab6", + "DiffID": "sha256:a1a9bacee3af3a2374cef8bdb3ab30509ed3ee6ea066b28cb99c8c3d5bdc4b58" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-56862", + "DataSource": { + "ID": "govulndb", + "Name": "The Go Vulnerability Database", + "URL": "https://pkg.go.dev/vuln/" + }, + "Fingerprint": "sha256:0334074ecb18a8ca06b9e645342012eb7692b13a5b9f2e86505ce36d27fb1064", + "Title": "crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages", + "Description": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:66364", + "https://access.redhat.com/security/cve/CVE-2026-56862", + "https://bugzilla.redhat.com/2515815", + "https://bugzilla.redhat.com/2515820", + "https://bugzilla.redhat.com/2515839", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515815", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515820", + "https://bugzilla.redhat.com/show_bug.cgi?id=2515839", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33818", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56860", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56862", + "https://errata.almalinux.org/9/ALSA-2026-66364.html", + "https://errata.rockylinux.org/RLSA-2026:66364", + "https://go.dev/cl/804261", + "https://go.dev/issue/80528", + "https://groups.google.com/g/golang-announce/c/94pEornpRlI", + "https://linux.oracle.com/cve/CVE-2026-56862.html", + "https://linux.oracle.com/errata/ELSA-2026-66364-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-56862", + "https://pkg.go.dev/vuln/GO-2026-6090", + "https://www.cve.org/CVERecord?id=CVE-2026-56862" + ], + "PublishedDate": "2026-08-13T22:17:22.55Z", + "LastModifiedDate": "2026-09-03T16:37:52.17Z" + } + ] + } + ] +} diff --git a/output/security/production-api-container-audit.json b/output/security/production-api-container-audit.json new file mode 100644 index 0000000..cbfd120 --- /dev/null +++ b/output/security/production-api-container-audit.json @@ -0,0 +1,11836 @@ +{ + "SchemaVersion": 2, + "Trivy": { + "Version": "0.74.0" + }, + "ReportID": "01a0a620-e19e-7ee5-b3f4-a7918f757165", + "CreatedAt": "2026-09-15T17:32:47.902979541Z", + "ArtifactID": "sha256:0d67eeb9afa80ed2b8deb361bf5bc0ce82ab7cc624511fe1c5c0741597c028b5", + "ArtifactName": "dtf-production-api:validation", + "ArtifactType": "container_image", + "Metadata": { + "Size": 204374528, + "OS": { + "Family": "debian", + "Name": "13.6" + }, + "ImageID": "sha256:465475796376bbd5962562fc6ede4c33e9bc076f25b32c723433f6dca017152b", + "DiffIDs": [ + "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3", + "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca", + "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca", + "sha256:24257af4ce5bde01d3c7ebd6d366ec4a298ed27c794bbd6832ef5ce934a66170", + "sha256:1aab1c292107941a7771e8bce1eac635099043402b900322f03f5194f1bc1323", + "sha256:b5f324bde28d08c5a427ef72ca1f34928ea35eb6ee4d9f196d69959a9d945d9b", + "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce", + "sha256:11e77f4eb4aa9a2b55e45f50fe928f3b6260afc590747aa075e1d53d8d381a52", + "sha256:e9d2fc3f8d7f9566f4b960fe12daa94ec52825a3242219d8c3d2e16944cca6a3" + ], + "RepoTags": [ + "dtf-production-api:validation" + ], + "RepoDigests": [ + "dtf-production-api@sha256:465475796376bbd5962562fc6ede4c33e9bc076f25b32c723433f6dca017152b" + ], + "Reference": "dtf-production-api:validation", + "ImageConfig": { + "architecture": "amd64", + "created": "2026-09-15T14:31:10.123541158-03:00", + "history": [ + { + "created": "2026-08-24T00:00:00Z", + "created_by": "# debian.sh --arch 'amd64' out/ 'trixie' '@1787529600'", + "comment": "debuerreotype 0.17" + }, + { + "created": "2026-09-01T00:02:59.446345026Z", + "created_by": "ENV PATH=/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-01T00:02:59.446345026Z", + "created_by": "ENV LANG=C.UTF-8", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-01T00:02:59.446345026Z", + "created_by": "RUN /bin/sh -c set -eux; \tapt-get update; \tapt-get install -y --no-install-recommends \t\tca-certificates \t\tnetbase \t\ttzdata \t; \tapt-get dist-clean # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-01T00:02:59.446345026Z", + "created_by": "ENV GPG_KEY=7169605F62C751356D054A26A821E680E5FA6305", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-01T00:02:59.446345026Z", + "created_by": "ENV PYTHON_VERSION=3.12.14", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-01T00:02:59.446345026Z", + "created_by": "ENV PYTHON_SHA256=5c8462af5790baf43a321a1559dbe0db06d1be4300fb85fb53c40060668e548a", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-01T00:12:40.004923065Z", + "created_by": "RUN /bin/sh -c set -eux; \t\tsavedAptMark=\"$(apt-mark showmanual)\"; \tapt-get update; \tapt-get install -y --no-install-recommends \t\tdpkg-dev \t\tg++ \t\tgcc \t\tgnupg \t\tlibbluetooth-dev \t\tlibbz2-dev \t\tlibc6-dev \t\tlibdb-dev \t\tlibffi-dev \t\tlibgdbm-dev \t\tliblzma-dev \t\tlibncursesw5-dev \t\tlibreadline-dev \t\tlibsqlite3-dev \t\tlibssl-dev \t\tmake \t\ttk-dev \t\tuuid-dev \t\twget \t\txz-utils \t\tzlib1g-dev \t; \t\twget -O python.tar.xz \"https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz\"; \techo \"$PYTHON_SHA256 *python.tar.xz\" | sha256sum -c -; \twget -O python.tar.xz.asc \"https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz.asc\"; \tGNUPGHOME=\"$(mktemp -d)\"; export GNUPGHOME; \tgpg --batch --keyserver hkps://keys.openpgp.org --recv-keys \"$GPG_KEY\"; \tgpg --batch --verify python.tar.xz.asc python.tar.xz; \tgpgconf --kill all; \trm -rf \"$GNUPGHOME\" python.tar.xz.asc; \tmkdir -p /usr/src/python; \ttar --extract --directory /usr/src/python --strip-components=1 --file python.tar.xz; \trm python.tar.xz; \t\tcd /usr/src/python; \tgnuArch=\"$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)\"; \t./configure \t\t--build=\"$gnuArch\" \t\t--enable-loadable-sqlite-extensions \t\t--enable-optimizations \t\t--enable-option-checking=fatal \t\t--enable-shared \t\t$(test \"${gnuArch%%-*}\" != 'riscv64' \u0026\u0026 echo '--with-lto') \t\t--with-ensurepip \t; \tnproc=\"$(nproc)\"; \tEXTRA_CFLAGS=\"$(dpkg-buildflags --get CFLAGS)\"; \tLDFLAGS=\"$(dpkg-buildflags --get LDFLAGS)\"; \tLDFLAGS=\"${LDFLAGS:-} -Wl,--strip-all\"; \tarch=\"$(dpkg --print-architecture)\"; arch=\"${arch##*-}\"; \tcase \"$arch\" in \t\tamd64|arm64) \t\t\tEXTRA_CFLAGS=\"${EXTRA_CFLAGS:-} -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer\"; \t\t\t;; \t\ti386) \t\t\t;; \t\t*) \t\t\tEXTRA_CFLAGS=\"${EXTRA_CFLAGS:-} -fno-omit-frame-pointer\"; \t\t\t;; \tesac; \tmake -j \"$nproc\" \t\t\"EXTRA_CFLAGS=${EXTRA_CFLAGS:-}\" \t\t\"LDFLAGS=${LDFLAGS:-}\" \t; \trm python; \tmake -j \"$nproc\" \t\t\"EXTRA_CFLAGS=${EXTRA_CFLAGS:-}\" \t\t\"LDFLAGS=${LDFLAGS:-} -Wl,-rpath='\\$\\$ORIGIN/../lib'\" \t\tpython \t; \tmake install; \t\tcd /; \trm -rf /usr/src/python; \t\tfind /usr/local -depth \t\t\\( \t\t\t\\( -type d -a \\( -name test -o -name tests -o -name idle_test \\) \\) \t\t\t-o \\( -type f -a \\( -name '*.pyc' -o -name '*.pyo' -o -name 'libpython*.a' \\) \\) \t\t\\) -exec rm -rf '{}' + \t; \t\tldconfig; \t\tapt-mark auto '.*' \u003e /dev/null; \tapt-mark manual $savedAptMark; \tfind /usr/local -type f -executable -not \\( -name '*tkinter*' \\) -exec ldd '{}' ';' \t\t| awk '/=\u003e/ { so = $(NF-1); if (index(so, \"/usr/local/\") == 1) { next }; gsub(\"^/(usr/)?\", \"\", so); printf \"*%s\\n\", so }' \t\t| sort -u \t\t| xargs -rt dpkg-query --search \t\t| awk 'sub(\":$\", \"\", $1) { print $1 }' \t\t| sort -u \t\t| xargs -r apt-mark manual \t; \tapt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \tapt-get dist-clean; \t\texport PYTHONDONTWRITEBYTECODE=1; \tpython3 --version; \tpip3 --version # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-01T00:12:40.129211396Z", + "created_by": "RUN /bin/sh -c set -eux; \tfor src in idle3 pip3 pydoc3 python3 python3-config; do \t\tdst=\"$(echo \"$src\" | tr -d 3)\"; \t\t[ -s \"/usr/local/bin/$src\" ]; \t\t[ ! -e \"/usr/local/bin/$dst\" ]; \t\tln -svT \"$src\" \"/usr/local/bin/$dst\"; \tdone # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-01T00:12:40.129211396Z", + "created_by": "CMD [\"python3\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-15T13:26:07.43418765-03:00", + "created_by": "/bin/sh -c #(nop) ARG VCS_REF=unknown", + "empty_layer": true + }, + { + "created": "2026-09-15T13:26:14.228286409-03:00", + "created_by": "/bin/sh -c #(nop) LABEL org.opencontainers.image.title=DTF Portal/API org.opencontainers.image.revision=local-validation org.opencontainers.image.source=DTF System repository", + "empty_layer": true + }, + { + "created": "2026-09-15T13:26:17.236336146-03:00", + "created_by": "/bin/sh -c #(nop) WORKDIR /app" + }, + { + "created": "2026-09-15T16:26:18.609643872Z", + "created_by": "/bin/sh -c #(nop) COPY multi:44e342f57133c52eba09aee6b662543a8618f56eecf2e947d947e03eda2a29d2 in /app/local/ " + }, + { + "created": "2026-09-15T13:26:53.703375458-03:00", + "created_by": "|1 VCS_REF=local-validation /bin/sh -c python -m pip install --no-cache-dir --require-hashes -r local/requirements.lock" + }, + { + "created": "2026-09-15T16:27:01.707143163Z", + "created_by": "/bin/sh -c #(nop) COPY dir:d85c8aa24c1073bcd5d6056cb956818fbef784153aa88a4833c936f6ab41619a in /app/local " + }, + { + "created": "2026-09-15T13:27:05.419678294-03:00", + "created_by": "|1 VCS_REF=local-validation /bin/sh -c useradd --uid 10001 --create-home --shell /usr/sbin/nologin dtf" + }, + { + "created": "2026-09-15T13:27:08.095762801-03:00", + "created_by": "/bin/sh -c #(nop) USER 10001:10001", + "empty_layer": true + }, + { + "created": "2026-09-15T13:27:10.865334-03:00", + "created_by": "/bin/sh -c #(nop) ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1 PYTHONPATH=/app", + "empty_layer": true + }, + { + "created": "2026-09-15T13:27:13.371521329-03:00", + "created_by": "/bin/sh -c #(nop) EXPOSE 8000", + "empty_layer": true + }, + { + "created": "2026-09-15T14:31:10.123541158-03:00", + "created_by": "/bin/sh -c #(nop) CMD [\"uvicorn\" \"local.app:app\" \"--host\" \"0.0.0.0\" \"--port\" \"8000\" \"--no-access-log\"]", + "empty_layer": true + } + ], + "os": "linux", + "rootfs": { + "type": "layers", + "diff_ids": [ + "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3", + "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca", + "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca", + "sha256:24257af4ce5bde01d3c7ebd6d366ec4a298ed27c794bbd6832ef5ce934a66170", + "sha256:1aab1c292107941a7771e8bce1eac635099043402b900322f03f5194f1bc1323", + "sha256:b5f324bde28d08c5a427ef72ca1f34928ea35eb6ee4d9f196d69959a9d945d9b", + "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce", + "sha256:11e77f4eb4aa9a2b55e45f50fe928f3b6260afc590747aa075e1d53d8d381a52", + "sha256:e9d2fc3f8d7f9566f4b960fe12daa94ec52825a3242219d8c3d2e16944cca6a3" + ] + }, + "config": { + "Cmd": [ + "uvicorn", + "local.app:app", + "--host", + "0.0.0.0", + "--port", + "8000", + "--no-access-log" + ], + "Env": [ + "PATH=/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", + "LANG=C.UTF-8", + "GPG_KEY=7169605F62C751356D054A26A821E680E5FA6305", + "PYTHON_VERSION=3.12.14", + "PYTHON_SHA256=5c8462af5790baf43a321a1559dbe0db06d1be4300fb85fb53c40060668e548a", + "PYTHONDONTWRITEBYTECODE=1", + "PYTHONUNBUFFERED=1", + "PYTHONPATH=/app" + ], + "Labels": { + "org.opencontainers.image.revision": "local-validation", + "org.opencontainers.image.source": "DTF System repository", + "org.opencontainers.image.title": "DTF Portal/API" + }, + "User": "10001:10001", + "WorkingDir": "/app", + "ExposedPorts": { + "8000/tcp": {} + } + } + }, + "Layers": [ + { + "Size": 81070080, + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + { + "Size": 12298752, + "Digest": "sha256:dbd0b7849e6c06b61e1fa6b7ffe053f246ce0075890620e3db64b47bb662433a", + "DiffID": "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca" + }, + { + "Size": 38131712, + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + { + "Size": 5120, + "Digest": "sha256:56235e4245636e401a28cf88944d543b29ee028ae3b6c27e03d6b43e7b4eac5f", + "DiffID": "sha256:24257af4ce5bde01d3c7ebd6d366ec4a298ed27c794bbd6832ef5ce934a66170" + }, + { + "Size": 1536, + "Digest": "sha256:2807ed1c23bc7cb7c5d37c8742a5c27a0295fbfeac20e39249350b26a2c174ec", + "DiffID": "sha256:1aab1c292107941a7771e8bce1eac635099043402b900322f03f5194f1bc1323" + }, + { + "Size": 25088, + "Digest": "sha256:2cb3a4af57b94003de7d0a22eb36df9d7cc6d45ca0aa808f0dd80458a5c188ea", + "DiffID": "sha256:b5f324bde28d08c5a427ef72ca1f34928ea35eb6ee4d9f196d69959a9d945d9b" + }, + { + "Size": 72619520, + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + { + "Size": 201216, + "Digest": "sha256:3a09925dc64c9d3bdc46274537e8a9f3e09181c13ad67f82735a8c89693876d8", + "DiffID": "sha256:11e77f4eb4aa9a2b55e45f50fe928f3b6260afc590747aa075e1d53d8d381a52" + }, + { + "Size": 21504, + "Digest": "sha256:93d80f74d25ed781cc0fecb07658089347790c14a29dabfd20b96b26fb8fbd16", + "DiffID": "sha256:e9d2fc3f8d7f9566f4b960fe12daa94ec52825a3242219d8c3d2e16944cca6a3" + } + ] + }, + "Results": [ + { + "Target": "dtf-production-api:validation (debian 13.6)", + "Class": "os-pkgs", + "Type": "debian", + "Packages": [ + { + "ID": "adduser@3.152", + "Name": "adduser", + "Identifier": { + "PURL": "pkg:deb/debian/adduser@3.152?arch=all\u0026distro=debian-13.6", + "UID": "681428a4291e51" + }, + "Version": "3.152", + "Arch": "all", + "SrcName": "adduser", + "SrcVersion": "3.152", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Debian Adduser Developers \u003cadduser@packages.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "passwd@1:4.17.4-2" + ], + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "InstalledFiles": [ + "/usr/sbin/adduser", + "/usr/sbin/deluser", + "/usr/share/doc/adduser/NEWS.Debian.gz", + "/usr/share/doc/adduser/README.gz", + "/usr/share/doc/adduser/TODO", + "/usr/share/doc/adduser/changelog.gz", + "/usr/share/doc/adduser/copyright", + "/usr/share/doc/adduser/examples/INSTALL", + "/usr/share/doc/adduser/examples/README", + "/usr/share/doc/adduser/examples/adduser.conf", + "/usr/share/doc/adduser/examples/adduser.local", + "/usr/share/doc/adduser/examples/adduser.local.conf", + "/usr/share/doc/adduser/examples/adduser.local.conf.examples/bash.bashrc", + "/usr/share/doc/adduser/examples/adduser.local.conf.examples/profile", + "/usr/share/doc/adduser/examples/adduser.local.conf.examples/skel.other/index.html", + "/usr/share/doc/adduser/examples/adduser.local.conf.examples/skel/dot.bash_logout", + "/usr/share/doc/adduser/examples/adduser.local.conf.examples/skel/dot.bash_profile", + "/usr/share/doc/adduser/examples/adduser.local.conf.examples/skel/dot.bashrc", + "/usr/share/doc/adduser/examples/deluser.conf", + "/usr/share/man/da/man5/deluser.conf.5.gz", + "/usr/share/man/de/man5/adduser.conf.5.gz", + "/usr/share/man/de/man5/deluser.conf.5.gz", + "/usr/share/man/de/man8/adduser.8.gz", + "/usr/share/man/de/man8/adduser.local.8.gz", + "/usr/share/man/de/man8/deluser.8.gz", + "/usr/share/man/es/man5/deluser.conf.5.gz", + "/usr/share/man/fr/man5/adduser.conf.5.gz", + "/usr/share/man/fr/man5/deluser.conf.5.gz", + "/usr/share/man/fr/man8/adduser.8.gz", + "/usr/share/man/fr/man8/deluser.8.gz", + "/usr/share/man/it/man5/deluser.conf.5.gz", + "/usr/share/man/man5/adduser.conf.5.gz", + "/usr/share/man/man5/deluser.conf.5.gz", + "/usr/share/man/man8/adduser.8.gz", + "/usr/share/man/man8/adduser.local.8.gz", + "/usr/share/man/man8/deluser.8.gz", + "/usr/share/man/nl/man5/adduser.conf.5.gz", + "/usr/share/man/nl/man5/deluser.conf.5.gz", + "/usr/share/man/nl/man8/adduser.8.gz", + "/usr/share/man/nl/man8/adduser.local.8.gz", + "/usr/share/man/nl/man8/deluser.8.gz", + "/usr/share/man/pl/man5/deluser.conf.5.gz", + "/usr/share/man/pt/man5/adduser.conf.5.gz", + "/usr/share/man/pt/man5/deluser.conf.5.gz", + "/usr/share/man/pt/man8/adduser.8.gz", + "/usr/share/man/pt/man8/adduser.local.8.gz", + "/usr/share/man/pt/man8/deluser.8.gz", + "/usr/share/man/ro/man5/adduser.conf.5.gz", + "/usr/share/man/ro/man5/deluser.conf.5.gz", + "/usr/share/man/ro/man8/adduser.8.gz", + "/usr/share/man/ro/man8/adduser.local.8.gz", + "/usr/share/man/ro/man8/deluser.8.gz", + "/usr/share/man/ru/man5/deluser.conf.5.gz", + "/usr/share/man/sv/man5/deluser.conf.5.gz", + "/usr/share/perl5/Debian/AdduserCommon.pm", + "/usr/share/perl5/Debian/AdduserLogging.pm", + "/usr/share/perl5/Debian/AdduserRetvalues.pm" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "apt@3.0.3", + "Name": "apt", + "Identifier": { + "PURL": "pkg:deb/debian/apt@3.0.3?arch=amd64\u0026distro=debian-13.6", + "UID": "1c5db4816123219d" + }, + "Version": "3.0.3", + "Arch": "amd64", + "SrcName": "apt", + "SrcVersion": "3.0.3", + "Licenses": [ + "GPL-2.0-or-later", + "curl", + "BSD-3-Clause", + "MIT", + "GPL-2.0-only" + ], + "Maintainer": "APT Development Team \u003cdeity@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "adduser@3.152", + "base-passwd@3.6.7", + "debian-archive-keyring@2025.1", + "libapt-pkg7.0@3.0.3", + "libc6@2.41-12+deb13u3", + "libgcc-s1@14.2.0-19", + "libseccomp2@2.6.0-2", + "libssl3t64@3.5.7-1~deb13u2", + "libstdc++6@14.2.0-19", + "libsystemd0@257.13-1~deb13u1", + "sqv@1.3.0-3+b2" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/apt", + "/usr/bin/apt-cache", + "/usr/bin/apt-cdrom", + "/usr/bin/apt-config", + "/usr/bin/apt-get", + "/usr/bin/apt-mark", + "/usr/lib/apt/apt-extracttemplates", + "/usr/lib/apt/apt-helper", + "/usr/lib/apt/apt.systemd.daily", + "/usr/lib/apt/methods/cdrom", + "/usr/lib/apt/methods/copy", + "/usr/lib/apt/methods/file", + "/usr/lib/apt/methods/gpgv", + "/usr/lib/apt/methods/http", + "/usr/lib/apt/methods/mirror", + "/usr/lib/apt/methods/rred", + "/usr/lib/apt/methods/sqv", + "/usr/lib/apt/methods/store", + "/usr/lib/apt/solvers/dump", + "/usr/lib/dpkg/methods/apt/desc.apt", + "/usr/lib/dpkg/methods/apt/install", + "/usr/lib/dpkg/methods/apt/names", + "/usr/lib/dpkg/methods/apt/setup", + "/usr/lib/dpkg/methods/apt/update", + "/usr/lib/systemd/system/apt-daily-upgrade.service", + "/usr/lib/systemd/system/apt-daily-upgrade.timer", + "/usr/lib/systemd/system/apt-daily.service", + "/usr/lib/systemd/system/apt-daily.timer", + "/usr/lib/x86_64-linux-gnu/libapt-private.so.0.0.0", + "/usr/share/apt/default-sequoia.config", + "/usr/share/bash-completion/completions/apt", + "/usr/share/bug/apt/script", + "/usr/share/doc/apt/NEWS.Debian.gz", + "/usr/share/doc/apt/README.md.gz", + "/usr/share/doc/apt/changelog.gz", + "/usr/share/doc/apt/copyright", + "/usr/share/doc/apt/examples/apt.conf", + "/usr/share/doc/apt/examples/configure-index", + "/usr/share/doc/apt/examples/debian.sources", + "/usr/share/doc/apt/examples/preferences", + "/usr/share/lintian/overrides/apt", + "/usr/share/locale/ar/LC_MESSAGES/apt.mo", + "/usr/share/locale/ast/LC_MESSAGES/apt.mo", + "/usr/share/locale/bg/LC_MESSAGES/apt.mo", + "/usr/share/locale/bs/LC_MESSAGES/apt.mo", + "/usr/share/locale/ca/LC_MESSAGES/apt.mo", + "/usr/share/locale/cs/LC_MESSAGES/apt.mo", + "/usr/share/locale/cy/LC_MESSAGES/apt.mo", + "/usr/share/locale/da/LC_MESSAGES/apt.mo", + "/usr/share/locale/de/LC_MESSAGES/apt.mo", + "/usr/share/locale/dz/LC_MESSAGES/apt.mo", + "/usr/share/locale/el/LC_MESSAGES/apt.mo", + "/usr/share/locale/es/LC_MESSAGES/apt.mo", + "/usr/share/locale/eu/LC_MESSAGES/apt.mo", + "/usr/share/locale/fi/LC_MESSAGES/apt.mo", + "/usr/share/locale/fr/LC_MESSAGES/apt.mo", + "/usr/share/locale/gl/LC_MESSAGES/apt.mo", + "/usr/share/locale/hu/LC_MESSAGES/apt.mo", + "/usr/share/locale/it/LC_MESSAGES/apt.mo", + "/usr/share/locale/ja/LC_MESSAGES/apt.mo", + "/usr/share/locale/km/LC_MESSAGES/apt.mo", + "/usr/share/locale/ko/LC_MESSAGES/apt.mo", + "/usr/share/locale/ku/LC_MESSAGES/apt.mo", + "/usr/share/locale/lt/LC_MESSAGES/apt.mo", + "/usr/share/locale/mr/LC_MESSAGES/apt.mo", + "/usr/share/locale/nb/LC_MESSAGES/apt.mo", + "/usr/share/locale/ne/LC_MESSAGES/apt.mo", + "/usr/share/locale/nl/LC_MESSAGES/apt.mo", + "/usr/share/locale/nn/LC_MESSAGES/apt.mo", + "/usr/share/locale/pl/LC_MESSAGES/apt.mo", + "/usr/share/locale/pt/LC_MESSAGES/apt.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/apt.mo", + "/usr/share/locale/ro/LC_MESSAGES/apt.mo", + "/usr/share/locale/ru/LC_MESSAGES/apt.mo", + "/usr/share/locale/sk/LC_MESSAGES/apt.mo", + "/usr/share/locale/sl/LC_MESSAGES/apt.mo", + "/usr/share/locale/sv/LC_MESSAGES/apt.mo", + "/usr/share/locale/th/LC_MESSAGES/apt.mo", + "/usr/share/locale/tl/LC_MESSAGES/apt.mo", + "/usr/share/locale/tr/LC_MESSAGES/apt.mo", + "/usr/share/locale/uk/LC_MESSAGES/apt.mo", + "/usr/share/locale/vi/LC_MESSAGES/apt.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/apt.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/apt.mo", + "/usr/share/man/de/man1/apt-transport-http.1.gz", + "/usr/share/man/de/man1/apt-transport-https.1.gz", + "/usr/share/man/de/man1/apt-transport-mirror.1.gz", + "/usr/share/man/de/man5/apt.conf.5.gz", + "/usr/share/man/de/man5/apt_auth.conf.5.gz", + "/usr/share/man/de/man5/apt_preferences.5.gz", + "/usr/share/man/de/man5/sources.list.5.gz", + "/usr/share/man/de/man7/apt-patterns.7.gz", + "/usr/share/man/de/man8/apt-cache.8.gz", + "/usr/share/man/de/man8/apt-cdrom.8.gz", + "/usr/share/man/de/man8/apt-config.8.gz", + "/usr/share/man/de/man8/apt-get.8.gz", + "/usr/share/man/de/man8/apt-mark.8.gz", + "/usr/share/man/de/man8/apt-secure.8.gz", + "/usr/share/man/de/man8/apt.8.gz", + "/usr/share/man/es/man5/apt_preferences.5.gz", + "/usr/share/man/es/man8/apt-cache.8.gz", + "/usr/share/man/es/man8/apt-cdrom.8.gz", + "/usr/share/man/es/man8/apt-config.8.gz", + "/usr/share/man/fr/man1/apt-transport-http.1.gz", + "/usr/share/man/fr/man1/apt-transport-https.1.gz", + "/usr/share/man/fr/man1/apt-transport-mirror.1.gz", + "/usr/share/man/fr/man5/apt.conf.5.gz", + "/usr/share/man/fr/man5/apt_auth.conf.5.gz", + "/usr/share/man/fr/man5/apt_preferences.5.gz", + "/usr/share/man/fr/man5/sources.list.5.gz", + "/usr/share/man/fr/man7/apt-patterns.7.gz", + "/usr/share/man/fr/man8/apt-cache.8.gz", + "/usr/share/man/fr/man8/apt-cdrom.8.gz", + "/usr/share/man/fr/man8/apt-config.8.gz", + "/usr/share/man/fr/man8/apt-get.8.gz", + "/usr/share/man/fr/man8/apt-mark.8.gz", + "/usr/share/man/fr/man8/apt-secure.8.gz", + "/usr/share/man/fr/man8/apt.8.gz", + "/usr/share/man/it/man5/apt.conf.5.gz", + "/usr/share/man/it/man5/apt_preferences.5.gz", + "/usr/share/man/it/man8/apt-cache.8.gz", + "/usr/share/man/it/man8/apt-cdrom.8.gz", + "/usr/share/man/it/man8/apt-config.8.gz", + "/usr/share/man/it/man8/apt-mark.8.gz", + "/usr/share/man/it/man8/apt.8.gz", + "/usr/share/man/ja/man5/apt.conf.5.gz", + "/usr/share/man/ja/man5/apt_preferences.5.gz", + "/usr/share/man/ja/man8/apt-cache.8.gz", + "/usr/share/man/ja/man8/apt-cdrom.8.gz", + "/usr/share/man/ja/man8/apt-config.8.gz", + "/usr/share/man/ja/man8/apt-mark.8.gz", + "/usr/share/man/ja/man8/apt.8.gz", + "/usr/share/man/man1/apt-transport-http.1.gz", + "/usr/share/man/man1/apt-transport-https.1.gz", + "/usr/share/man/man1/apt-transport-mirror.1.gz", + "/usr/share/man/man5/apt.conf.5.gz", + "/usr/share/man/man5/apt_auth.conf.5.gz", + "/usr/share/man/man5/apt_preferences.5.gz", + "/usr/share/man/man5/sources.list.5.gz", + "/usr/share/man/man7/apt-patterns.7.gz", + "/usr/share/man/man8/apt-cache.8.gz", + "/usr/share/man/man8/apt-cdrom.8.gz", + "/usr/share/man/man8/apt-config.8.gz", + "/usr/share/man/man8/apt-get.8.gz", + "/usr/share/man/man8/apt-mark.8.gz", + "/usr/share/man/man8/apt-secure.8.gz", + "/usr/share/man/man8/apt.8.gz", + "/usr/share/man/nl/man1/apt-transport-http.1.gz", + "/usr/share/man/nl/man1/apt-transport-https.1.gz", + "/usr/share/man/nl/man1/apt-transport-mirror.1.gz", + "/usr/share/man/nl/man5/apt.conf.5.gz", + "/usr/share/man/nl/man5/apt_auth.conf.5.gz", + "/usr/share/man/nl/man5/apt_preferences.5.gz", + "/usr/share/man/nl/man5/sources.list.5.gz", + "/usr/share/man/nl/man7/apt-patterns.7.gz", + "/usr/share/man/nl/man8/apt-cache.8.gz", + "/usr/share/man/nl/man8/apt-cdrom.8.gz", + "/usr/share/man/nl/man8/apt-config.8.gz", + "/usr/share/man/nl/man8/apt-get.8.gz", + "/usr/share/man/nl/man8/apt-mark.8.gz", + "/usr/share/man/nl/man8/apt-secure.8.gz", + "/usr/share/man/nl/man8/apt.8.gz", + "/usr/share/man/pl/man5/apt_preferences.5.gz", + "/usr/share/man/pl/man8/apt-cache.8.gz", + "/usr/share/man/pl/man8/apt-cdrom.8.gz", + "/usr/share/man/pl/man8/apt-config.8.gz", + "/usr/share/man/pt/man1/apt-transport-http.1.gz", + "/usr/share/man/pt/man1/apt-transport-https.1.gz", + "/usr/share/man/pt/man1/apt-transport-mirror.1.gz", + "/usr/share/man/pt/man5/apt.conf.5.gz", + "/usr/share/man/pt/man5/apt_auth.conf.5.gz", + "/usr/share/man/pt/man5/apt_preferences.5.gz", + "/usr/share/man/pt/man5/sources.list.5.gz", + "/usr/share/man/pt/man7/apt-patterns.7.gz", + "/usr/share/man/pt/man8/apt-cache.8.gz", + "/usr/share/man/pt/man8/apt-cdrom.8.gz", + "/usr/share/man/pt/man8/apt-config.8.gz", + "/usr/share/man/pt/man8/apt-get.8.gz", + "/usr/share/man/pt/man8/apt-mark.8.gz", + "/usr/share/man/pt/man8/apt-secure.8.gz", + "/usr/share/man/pt/man8/apt.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "base-files@13.8+deb13u6", + "Name": "base-files", + "Identifier": { + "PURL": "pkg:deb/debian/base-files@13.8%2Bdeb13u6?arch=amd64\u0026distro=debian-13.6", + "UID": "92f0efebffd8c58f" + }, + "Version": "13.8+deb13u6", + "Arch": "amd64", + "SrcName": "base-files", + "SrcVersion": "13.8+deb13u6", + "Licenses": [ + "GPL-2.0-or-later", + "verbatim" + ], + "Maintainer": "Santiago Vila \u003csanvila@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/os-release", + "/usr/share/base-files/dot.bashrc", + "/usr/share/base-files/dot.profile", + "/usr/share/base-files/dot.profile.md5sums", + "/usr/share/base-files/info.dir", + "/usr/share/base-files/motd", + "/usr/share/base-files/profile", + "/usr/share/base-files/profile.md5sums", + "/usr/share/base-files/staff-group-for-usr-local", + "/usr/share/common-licenses/Apache-2.0", + "/usr/share/common-licenses/Artistic", + "/usr/share/common-licenses/BSD", + "/usr/share/common-licenses/CC0-1.0", + "/usr/share/common-licenses/GFDL-1.2", + "/usr/share/common-licenses/GFDL-1.3", + "/usr/share/common-licenses/GPL-1", + "/usr/share/common-licenses/GPL-2", + "/usr/share/common-licenses/GPL-3", + "/usr/share/common-licenses/LGPL-2", + "/usr/share/common-licenses/LGPL-2.1", + "/usr/share/common-licenses/LGPL-3", + "/usr/share/common-licenses/MPL-1.1", + "/usr/share/common-licenses/MPL-2.0", + "/usr/share/doc/base-files/NEWS.Debian.gz", + "/usr/share/doc/base-files/README", + "/usr/share/doc/base-files/README.FHS", + "/usr/share/doc/base-files/changelog.gz", + "/usr/share/doc/base-files/copyright", + "/usr/share/lintian/overrides/base-files" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "base-passwd@3.6.7", + "Name": "base-passwd", + "Identifier": { + "PURL": "pkg:deb/debian/base-passwd@3.6.7?arch=amd64\u0026distro=debian-13.6", + "UID": "f77779fa356eca05" + }, + "Version": "3.6.7", + "Arch": "amd64", + "SrcName": "base-passwd", + "SrcVersion": "3.6.7", + "Licenses": [ + "GPL-2.0-only", + "public-domain" + ], + "Maintainer": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libdebconfclient0@0.280", + "libselinux1@3.8.1-1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/sbin/update-passwd", + "/usr/share/base-passwd/group.master", + "/usr/share/base-passwd/passwd.master", + "/usr/share/doc-base/base-passwd.users-and-groups", + "/usr/share/doc/base-passwd/README", + "/usr/share/doc/base-passwd/changelog.gz", + "/usr/share/doc/base-passwd/copyright", + "/usr/share/doc/base-passwd/users-and-groups.html", + "/usr/share/doc/base-passwd/users-and-groups.txt.gz", + "/usr/share/lintian/overrides/base-passwd", + "/usr/share/man/de/man8/update-passwd.8.gz", + "/usr/share/man/es/man8/update-passwd.8.gz", + "/usr/share/man/fr/man8/update-passwd.8.gz", + "/usr/share/man/ja/man8/update-passwd.8.gz", + "/usr/share/man/man8/update-passwd.8.gz", + "/usr/share/man/pl/man8/update-passwd.8.gz", + "/usr/share/man/ro/man8/update-passwd.8.gz", + "/usr/share/man/ru/man8/update-passwd.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "bash@5.2.37-2+b9", + "Name": "bash", + "Identifier": { + "PURL": "pkg:deb/debian/bash@5.2.37-2%2Bb9?arch=amd64\u0026distro=debian-13.6", + "UID": "84e3d9e7d9c5b184" + }, + "Version": "5.2.37", + "Release": "2+b9", + "Arch": "amd64", + "SrcName": "bash", + "SrcVersion": "5.2.37", + "SrcRelease": "2", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-3.0-only", + "GPL-3+ with Bison exception", + "GPL-2.0-or-later", + "GPL-2.0-only", + "GFDL-1.3-no-invariants-only", + "GFDL-1.3-only", + "Latex2e", + "BSD-4-Clause-UC", + "MIT", + "permissive" + ], + "Maintainer": "Matthias Klose \u003cdoko@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "base-files@13.8+deb13u6", + "debianutils@5.23.2" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/bash", + "/usr/bin/bashbug", + "/usr/bin/clear_console", + "/usr/share/debianutils/shells.d/bash", + "/usr/share/doc/bash/CHANGES.gz", + "/usr/share/doc/bash/COMPAT.gz", + "/usr/share/doc/bash/INTRO.gz", + "/usr/share/doc/bash/NEWS.gz", + "/usr/share/doc/bash/POSIX.gz", + "/usr/share/doc/bash/RBASH", + "/usr/share/doc/bash/README.Debian.gz", + "/usr/share/doc/bash/README.abs-guide", + "/usr/share/doc/bash/README.commands.gz", + "/usr/share/doc/bash/README.gz", + "/usr/share/doc/bash/changelog.Debian.amd64.gz", + "/usr/share/doc/bash/changelog.Debian.gz", + "/usr/share/doc/bash/changelog.gz", + "/usr/share/doc/bash/copyright", + "/usr/share/doc/bash/inputrc.arrows", + "/usr/share/lintian/overrides/bash", + "/usr/share/locale/af/LC_MESSAGES/bash.mo", + "/usr/share/locale/bg/LC_MESSAGES/bash.mo", + "/usr/share/locale/ca/LC_MESSAGES/bash.mo", + "/usr/share/locale/cs/LC_MESSAGES/bash.mo", + "/usr/share/locale/da/LC_MESSAGES/bash.mo", + "/usr/share/locale/de/LC_MESSAGES/bash.mo", + "/usr/share/locale/el/LC_MESSAGES/bash.mo", + "/usr/share/locale/en@boldquot/LC_MESSAGES/bash.mo", + "/usr/share/locale/en@quot/LC_MESSAGES/bash.mo", + "/usr/share/locale/eo/LC_MESSAGES/bash.mo", + "/usr/share/locale/es/LC_MESSAGES/bash.mo", + "/usr/share/locale/et/LC_MESSAGES/bash.mo", + "/usr/share/locale/fi/LC_MESSAGES/bash.mo", + "/usr/share/locale/fr/LC_MESSAGES/bash.mo", + "/usr/share/locale/ga/LC_MESSAGES/bash.mo", + "/usr/share/locale/gl/LC_MESSAGES/bash.mo", + "/usr/share/locale/hr/LC_MESSAGES/bash.mo", + "/usr/share/locale/hu/LC_MESSAGES/bash.mo", + "/usr/share/locale/id/LC_MESSAGES/bash.mo", + "/usr/share/locale/it/LC_MESSAGES/bash.mo", + "/usr/share/locale/ja/LC_MESSAGES/bash.mo", + "/usr/share/locale/ko/LC_MESSAGES/bash.mo", + "/usr/share/locale/lt/LC_MESSAGES/bash.mo", + "/usr/share/locale/nb/LC_MESSAGES/bash.mo", + "/usr/share/locale/nl/LC_MESSAGES/bash.mo", + "/usr/share/locale/pl/LC_MESSAGES/bash.mo", + "/usr/share/locale/pt/LC_MESSAGES/bash.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/bash.mo", + "/usr/share/locale/ro/LC_MESSAGES/bash.mo", + "/usr/share/locale/ru/LC_MESSAGES/bash.mo", + "/usr/share/locale/sk/LC_MESSAGES/bash.mo", + "/usr/share/locale/sl/LC_MESSAGES/bash.mo", + "/usr/share/locale/sr/LC_MESSAGES/bash.mo", + "/usr/share/locale/sv/LC_MESSAGES/bash.mo", + "/usr/share/locale/tr/LC_MESSAGES/bash.mo", + "/usr/share/locale/uk/LC_MESSAGES/bash.mo", + "/usr/share/locale/vi/LC_MESSAGES/bash.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/bash.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/bash.mo", + "/usr/share/man/man1/bash.1.gz", + "/usr/share/man/man1/bashbug.1.gz", + "/usr/share/man/man1/clear_console.1.gz", + "/usr/share/man/man1/rbash.1.gz", + "/usr/share/man/man7/bash-builtins.7.gz", + "/usr/share/menu/bash" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "bsdutils@1:2.41.5-0+deb13u1", + "Name": "bsdutils", + "Identifier": { + "PURL": "pkg:deb/debian/bsdutils@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "a4b47561565a3535" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/logger", + "/usr/bin/renice", + "/usr/bin/script", + "/usr/bin/scriptlive", + "/usr/bin/scriptreplay", + "/usr/bin/wall", + "/usr/share/bash-completion/completions/logger", + "/usr/share/bash-completion/completions/renice", + "/usr/share/bash-completion/completions/script", + "/usr/share/bash-completion/completions/scriptlive", + "/usr/share/bash-completion/completions/scriptreplay", + "/usr/share/bash-completion/completions/wall", + "/usr/share/doc/bsdutils/NEWS.Debian.gz", + "/usr/share/doc/bsdutils/changelog.Debian.gz", + "/usr/share/doc/bsdutils/changelog.gz", + "/usr/share/doc/bsdutils/copyright", + "/usr/share/lintian/overrides/bsdutils", + "/usr/share/man/man1/logger.1.gz", + "/usr/share/man/man1/renice.1.gz", + "/usr/share/man/man1/script.1.gz", + "/usr/share/man/man1/scriptlive.1.gz", + "/usr/share/man/man1/scriptreplay.1.gz", + "/usr/share/man/man1/wall.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "ca-certificates@20250419", + "Name": "ca-certificates", + "Identifier": { + "PURL": "pkg:deb/debian/ca-certificates@20250419?arch=all\u0026distro=debian-13.6", + "UID": "7d49b711f66cb392" + }, + "Version": "20250419", + "Arch": "all", + "SrcName": "ca-certificates", + "SrcVersion": "20250419", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "MPL-2.0" + ], + "Maintainer": "Julien Cristau \u003cjcristau@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "debconf@1.5.91", + "openssl@3.5.7-1~deb13u2" + ], + "Layer": { + "Digest": "sha256:dbd0b7849e6c06b61e1fa6b7ffe053f246ce0075890620e3db64b47bb662433a", + "DiffID": "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca" + }, + "InstalledFiles": [ + "/usr/sbin/update-ca-certificates", + "/usr/share/ca-certificates/mozilla/ACCVRAIZ1.crt", + "/usr/share/ca-certificates/mozilla/AC_RAIZ_FNMT-RCM.crt", + "/usr/share/ca-certificates/mozilla/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.crt", + "/usr/share/ca-certificates/mozilla/ANF_Secure_Server_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/Actalis_Authentication_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/AffirmTrust_Commercial.crt", + "/usr/share/ca-certificates/mozilla/AffirmTrust_Networking.crt", + "/usr/share/ca-certificates/mozilla/AffirmTrust_Premium.crt", + "/usr/share/ca-certificates/mozilla/AffirmTrust_Premium_ECC.crt", + "/usr/share/ca-certificates/mozilla/Amazon_Root_CA_1.crt", + "/usr/share/ca-certificates/mozilla/Amazon_Root_CA_2.crt", + "/usr/share/ca-certificates/mozilla/Amazon_Root_CA_3.crt", + "/usr/share/ca-certificates/mozilla/Amazon_Root_CA_4.crt", + "/usr/share/ca-certificates/mozilla/Atos_TrustedRoot_2011.crt", + "/usr/share/ca-certificates/mozilla/Atos_TrustedRoot_Root_CA_ECC_TLS_2021.crt", + "/usr/share/ca-certificates/mozilla/Atos_TrustedRoot_Root_CA_RSA_TLS_2021.crt", + "/usr/share/ca-certificates/mozilla/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.crt", + "/usr/share/ca-certificates/mozilla/BJCA_Global_Root_CA1.crt", + "/usr/share/ca-certificates/mozilla/BJCA_Global_Root_CA2.crt", + "/usr/share/ca-certificates/mozilla/Baltimore_CyberTrust_Root.crt", + "/usr/share/ca-certificates/mozilla/Buypass_Class_2_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/Buypass_Class_3_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/CA_Disig_Root_R2.crt", + "/usr/share/ca-certificates/mozilla/CFCA_EV_ROOT.crt", + "/usr/share/ca-certificates/mozilla/COMODO_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/COMODO_ECC_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/COMODO_RSA_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/Certainly_Root_E1.crt", + "/usr/share/ca-certificates/mozilla/Certainly_Root_R1.crt", + "/usr/share/ca-certificates/mozilla/Certigna.crt", + "/usr/share/ca-certificates/mozilla/Certigna_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/Certum_EC-384_CA.crt", + "/usr/share/ca-certificates/mozilla/Certum_Trusted_Network_CA.crt", + "/usr/share/ca-certificates/mozilla/Certum_Trusted_Network_CA_2.crt", + "/usr/share/ca-certificates/mozilla/Certum_Trusted_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/CommScope_Public_Trust_ECC_Root-01.crt", + "/usr/share/ca-certificates/mozilla/CommScope_Public_Trust_ECC_Root-02.crt", + "/usr/share/ca-certificates/mozilla/CommScope_Public_Trust_RSA_Root-01.crt", + "/usr/share/ca-certificates/mozilla/CommScope_Public_Trust_RSA_Root-02.crt", + "/usr/share/ca-certificates/mozilla/Comodo_AAA_Services_root.crt", + "/usr/share/ca-certificates/mozilla/D-TRUST_BR_Root_CA_1_2020.crt", + "/usr/share/ca-certificates/mozilla/D-TRUST_BR_Root_CA_2_2023.crt", + "/usr/share/ca-certificates/mozilla/D-TRUST_EV_Root_CA_1_2020.crt", + "/usr/share/ca-certificates/mozilla/D-TRUST_EV_Root_CA_2_2023.crt", + "/usr/share/ca-certificates/mozilla/D-TRUST_Root_Class_3_CA_2_2009.crt", + "/usr/share/ca-certificates/mozilla/D-TRUST_Root_Class_3_CA_2_EV_2009.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_G2.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_G3.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Global_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Global_Root_G2.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Global_Root_G3.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_High_Assurance_EV_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_TLS_ECC_P384_Root_G5.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_TLS_RSA4096_Root_G5.crt", + "/usr/share/ca-certificates/mozilla/DigiCert_Trusted_Root_G4.crt", + "/usr/share/ca-certificates/mozilla/Entrust.net_Premium_2048_Secure_Server_CA.crt", + "/usr/share/ca-certificates/mozilla/Entrust_Root_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/Entrust_Root_Certification_Authority_-_EC1.crt", + "/usr/share/ca-certificates/mozilla/Entrust_Root_Certification_Authority_-_G2.crt", + "/usr/share/ca-certificates/mozilla/FIRMAPROFESIONAL_CA_ROOT-A_WEB.crt", + "/usr/share/ca-certificates/mozilla/GDCA_TrustAUTH_R5_ROOT.crt", + "/usr/share/ca-certificates/mozilla/GLOBALTRUST_2020.crt", + "/usr/share/ca-certificates/mozilla/GTS_Root_R1.crt", + "/usr/share/ca-certificates/mozilla/GTS_Root_R2.crt", + "/usr/share/ca-certificates/mozilla/GTS_Root_R3.crt", + "/usr/share/ca-certificates/mozilla/GTS_Root_R4.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_ECC_Root_CA_-_R4.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_ECC_Root_CA_-_R5.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_Root_CA_-_R3.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_Root_CA_-_R6.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_Root_E46.crt", + "/usr/share/ca-certificates/mozilla/GlobalSign_Root_R46.crt", + "/usr/share/ca-certificates/mozilla/Go_Daddy_Class_2_CA.crt", + "/usr/share/ca-certificates/mozilla/Go_Daddy_Root_Certificate_Authority_-_G2.crt", + "/usr/share/ca-certificates/mozilla/HARICA_TLS_ECC_Root_CA_2021.crt", + "/usr/share/ca-certificates/mozilla/HARICA_TLS_RSA_Root_CA_2021.crt", + "/usr/share/ca-certificates/mozilla/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.crt", + "/usr/share/ca-certificates/mozilla/Hellenic_Academic_and_Research_Institutions_RootCA_2015.crt", + "/usr/share/ca-certificates/mozilla/HiPKI_Root_CA_-_G1.crt", + "/usr/share/ca-certificates/mozilla/Hongkong_Post_Root_CA_3.crt", + "/usr/share/ca-certificates/mozilla/ISRG_Root_X1.crt", + "/usr/share/ca-certificates/mozilla/ISRG_Root_X2.crt", + "/usr/share/ca-certificates/mozilla/IdenTrust_Commercial_Root_CA_1.crt", + "/usr/share/ca-certificates/mozilla/IdenTrust_Public_Sector_Root_CA_1.crt", + "/usr/share/ca-certificates/mozilla/Izenpe.com.crt", + "/usr/share/ca-certificates/mozilla/Microsec_e-Szigno_Root_CA_2009.crt", + "/usr/share/ca-certificates/mozilla/Microsoft_ECC_Root_Certificate_Authority_2017.crt", + "/usr/share/ca-certificates/mozilla/Microsoft_RSA_Root_Certificate_Authority_2017.crt", + "/usr/share/ca-certificates/mozilla/NAVER_Global_Root_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/NetLock_Arany_=Class_Gold=_Főtanúsítvány.crt", + "/usr/share/ca-certificates/mozilla/OISTE_WISeKey_Global_Root_GB_CA.crt", + "/usr/share/ca-certificates/mozilla/OISTE_WISeKey_Global_Root_GC_CA.crt", + "/usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_1_G3.crt", + "/usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_2.crt", + "/usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_2_G3.crt", + "/usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_3.crt", + "/usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_3_G3.crt", + "/usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_ECC.crt", + "/usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_RSA_R2.crt", + "/usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_ECC.crt", + "/usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_RSA.crt", + "/usr/share/ca-certificates/mozilla/SSL.com_TLS_ECC_Root_CA_2022.crt", + "/usr/share/ca-certificates/mozilla/SSL.com_TLS_RSA_Root_CA_2022.crt", + "/usr/share/ca-certificates/mozilla/SZAFIR_ROOT_CA2.crt", + "/usr/share/ca-certificates/mozilla/Sectigo_Public_Server_Authentication_Root_E46.crt", + "/usr/share/ca-certificates/mozilla/Sectigo_Public_Server_Authentication_Root_R46.crt", + "/usr/share/ca-certificates/mozilla/SecureSign_Root_CA12.crt", + "/usr/share/ca-certificates/mozilla/SecureSign_Root_CA14.crt", + "/usr/share/ca-certificates/mozilla/SecureSign_Root_CA15.crt", + "/usr/share/ca-certificates/mozilla/SecureTrust_CA.crt", + "/usr/share/ca-certificates/mozilla/Secure_Global_CA.crt", + "/usr/share/ca-certificates/mozilla/Security_Communication_ECC_RootCA1.crt", + "/usr/share/ca-certificates/mozilla/Security_Communication_RootCA2.crt", + "/usr/share/ca-certificates/mozilla/Starfield_Class_2_CA.crt", + "/usr/share/ca-certificates/mozilla/Starfield_Root_Certificate_Authority_-_G2.crt", + "/usr/share/ca-certificates/mozilla/Starfield_Services_Root_Certificate_Authority_-_G2.crt", + "/usr/share/ca-certificates/mozilla/SwissSign_Gold_CA_-_G2.crt", + "/usr/share/ca-certificates/mozilla/T-TeleSec_GlobalRoot_Class_2.crt", + "/usr/share/ca-certificates/mozilla/T-TeleSec_GlobalRoot_Class_3.crt", + "/usr/share/ca-certificates/mozilla/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.crt", + "/usr/share/ca-certificates/mozilla/TWCA_CYBER_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/TWCA_Global_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/TWCA_Root_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/Telekom_Security_TLS_ECC_Root_2020.crt", + "/usr/share/ca-certificates/mozilla/Telekom_Security_TLS_RSA_Root_2023.crt", + "/usr/share/ca-certificates/mozilla/TeliaSonera_Root_CA_v1.crt", + "/usr/share/ca-certificates/mozilla/Telia_Root_CA_v2.crt", + "/usr/share/ca-certificates/mozilla/TrustAsia_Global_Root_CA_G3.crt", + "/usr/share/ca-certificates/mozilla/TrustAsia_Global_Root_CA_G4.crt", + "/usr/share/ca-certificates/mozilla/Trustwave_Global_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/Trustwave_Global_ECC_P256_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/Trustwave_Global_ECC_P384_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/TunTrust_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/UCA_Extended_Validation_Root.crt", + "/usr/share/ca-certificates/mozilla/UCA_Global_G2_Root.crt", + "/usr/share/ca-certificates/mozilla/USERTrust_ECC_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/USERTrust_RSA_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/XRamp_Global_CA_Root.crt", + "/usr/share/ca-certificates/mozilla/certSIGN_ROOT_CA.crt", + "/usr/share/ca-certificates/mozilla/certSIGN_Root_CA_G2.crt", + "/usr/share/ca-certificates/mozilla/e-Szigno_Root_CA_2017.crt", + "/usr/share/ca-certificates/mozilla/ePKI_Root_Certification_Authority.crt", + "/usr/share/ca-certificates/mozilla/emSign_ECC_Root_CA_-_C3.crt", + "/usr/share/ca-certificates/mozilla/emSign_ECC_Root_CA_-_G3.crt", + "/usr/share/ca-certificates/mozilla/emSign_Root_CA_-_C1.crt", + "/usr/share/ca-certificates/mozilla/emSign_Root_CA_-_G1.crt", + "/usr/share/ca-certificates/mozilla/vTrus_ECC_Root_CA.crt", + "/usr/share/ca-certificates/mozilla/vTrus_Root_CA.crt", + "/usr/share/doc/ca-certificates/README.Debian", + "/usr/share/doc/ca-certificates/changelog.gz", + "/usr/share/doc/ca-certificates/copyright", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/Makefile", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/README", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/ca-certificates-local.triggers", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/changelog", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/compat", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/control", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/copyright", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/postrm", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/rules", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/debian/source/format", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/local/Local_Root_CA.crt", + "/usr/share/doc/ca-certificates/examples/ca-certificates-local/local/Makefile", + "/usr/share/man/man8/update-ca-certificates.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "coreutils@9.7-3", + "Name": "coreutils", + "Identifier": { + "PURL": "pkg:deb/debian/coreutils@9.7-3?arch=amd64\u0026distro=debian-13.6", + "UID": "cb4a55f50bda2393" + }, + "Version": "9.7", + "Release": "3", + "Arch": "amd64", + "SrcName": "coreutils", + "SrcVersion": "9.7", + "SrcRelease": "3", + "Licenses": [ + "GPL-3.0-or-later", + "BSD-4-Clause-UC", + "GPL-3.0-only", + "ISC", + "FSFULLR", + "GFDL-1.3-no-invariants-only", + "GFDL-1.3-only" + ], + "Maintainer": "Michael Stone \u003cmstone@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/[", + "/usr/bin/arch", + "/usr/bin/b2sum", + "/usr/bin/base32", + "/usr/bin/base64", + "/usr/bin/basename", + "/usr/bin/basenc", + "/usr/bin/cat", + "/usr/bin/chcon", + "/usr/bin/chgrp", + "/usr/bin/chmod", + "/usr/bin/chown", + "/usr/bin/cksum", + "/usr/bin/comm", + "/usr/bin/cp", + "/usr/bin/csplit", + "/usr/bin/cut", + "/usr/bin/date", + "/usr/bin/dd", + "/usr/bin/df", + "/usr/bin/dir", + "/usr/bin/dircolors", + "/usr/bin/dirname", + "/usr/bin/du", + "/usr/bin/echo", + "/usr/bin/env", + "/usr/bin/expand", + "/usr/bin/expr", + "/usr/bin/factor", + "/usr/bin/false", + "/usr/bin/fmt", + "/usr/bin/fold", + "/usr/bin/groups", + "/usr/bin/head", + "/usr/bin/hostid", + "/usr/bin/id", + "/usr/bin/install", + "/usr/bin/join", + "/usr/bin/link", + "/usr/bin/ln", + "/usr/bin/logname", + "/usr/bin/ls", + "/usr/bin/md5sum", + "/usr/bin/mkdir", + "/usr/bin/mkfifo", + "/usr/bin/mknod", + "/usr/bin/mktemp", + "/usr/bin/mv", + "/usr/bin/nice", + "/usr/bin/nl", + "/usr/bin/nohup", + "/usr/bin/nproc", + "/usr/bin/numfmt", + "/usr/bin/od", + "/usr/bin/paste", + "/usr/bin/pathchk", + "/usr/bin/pinky", + "/usr/bin/pr", + "/usr/bin/printenv", + "/usr/bin/printf", + "/usr/bin/ptx", + "/usr/bin/pwd", + "/usr/bin/readlink", + "/usr/bin/realpath", + "/usr/bin/rm", + "/usr/bin/rmdir", + "/usr/bin/runcon", + "/usr/bin/seq", + "/usr/bin/sha1sum", + "/usr/bin/sha224sum", + "/usr/bin/sha256sum", + "/usr/bin/sha384sum", + "/usr/bin/sha512sum", + "/usr/bin/shred", + "/usr/bin/shuf", + "/usr/bin/sleep", + "/usr/bin/sort", + "/usr/bin/split", + "/usr/bin/stat", + "/usr/bin/stdbuf", + "/usr/bin/stty", + "/usr/bin/sum", + "/usr/bin/sync", + "/usr/bin/tac", + "/usr/bin/tail", + "/usr/bin/tee", + "/usr/bin/test", + "/usr/bin/timeout", + "/usr/bin/touch", + "/usr/bin/tr", + "/usr/bin/true", + "/usr/bin/truncate", + "/usr/bin/tsort", + "/usr/bin/tty", + "/usr/bin/uname", + "/usr/bin/unexpand", + "/usr/bin/uniq", + "/usr/bin/unlink", + "/usr/bin/users", + "/usr/bin/vdir", + "/usr/bin/wc", + "/usr/bin/who", + "/usr/bin/whoami", + "/usr/bin/yes", + "/usr/libexec/coreutils/libstdbuf.so", + "/usr/sbin/chroot", + "/usr/share/doc/coreutils/AUTHORS", + "/usr/share/doc/coreutils/NEWS.gz", + "/usr/share/doc/coreutils/README.Debian", + "/usr/share/doc/coreutils/README.gz", + "/usr/share/doc/coreutils/THANKS.gz", + "/usr/share/doc/coreutils/TODO.gz", + "/usr/share/doc/coreutils/changelog.Debian.gz", + "/usr/share/doc/coreutils/changelog.gz", + "/usr/share/doc/coreutils/copyright", + "/usr/share/info/coreutils.info.gz", + "/usr/share/lintian/overrides/coreutils", + "/usr/share/locale/af/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/be/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/bg/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ca/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/cs/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/da/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/de/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/el/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/eo/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/es/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/et/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/eu/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/fi/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/fr/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ga/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/gl/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/hr/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/hu/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ia/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/id/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/it/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ja/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ka/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/kk/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ko/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/lg/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/lt/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ms/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/nb/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/nl/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/pl/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/pt/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ro/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ru/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/sk/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/sl/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/sr/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/sv/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/ta/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/tr/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/uk/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/vi/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/coreutils.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/coreutils.mo", + "/usr/share/man/man1/arch.1.gz", + "/usr/share/man/man1/b2sum.1.gz", + "/usr/share/man/man1/base32.1.gz", + "/usr/share/man/man1/base64.1.gz", + "/usr/share/man/man1/basename.1.gz", + "/usr/share/man/man1/basenc.1.gz", + "/usr/share/man/man1/cat.1.gz", + "/usr/share/man/man1/chcon.1.gz", + "/usr/share/man/man1/chgrp.1.gz", + "/usr/share/man/man1/chmod.1.gz", + "/usr/share/man/man1/chown.1.gz", + "/usr/share/man/man1/cksum.1.gz", + "/usr/share/man/man1/comm.1.gz", + "/usr/share/man/man1/cp.1.gz", + "/usr/share/man/man1/csplit.1.gz", + "/usr/share/man/man1/cut.1.gz", + "/usr/share/man/man1/date.1.gz", + "/usr/share/man/man1/dd.1.gz", + "/usr/share/man/man1/df.1.gz", + "/usr/share/man/man1/dir.1.gz", + "/usr/share/man/man1/dircolors.1.gz", + "/usr/share/man/man1/dirname.1.gz", + "/usr/share/man/man1/du.1.gz", + "/usr/share/man/man1/echo.1.gz", + "/usr/share/man/man1/env.1.gz", + "/usr/share/man/man1/expand.1.gz", + "/usr/share/man/man1/expr.1.gz", + "/usr/share/man/man1/factor.1.gz", + "/usr/share/man/man1/false.1.gz", + "/usr/share/man/man1/fmt.1.gz", + "/usr/share/man/man1/fold.1.gz", + "/usr/share/man/man1/groups.1.gz", + "/usr/share/man/man1/head.1.gz", + "/usr/share/man/man1/hostid.1.gz", + "/usr/share/man/man1/id.1.gz", + "/usr/share/man/man1/install.1.gz", + "/usr/share/man/man1/join.1.gz", + "/usr/share/man/man1/link.1.gz", + "/usr/share/man/man1/ln.1.gz", + "/usr/share/man/man1/logname.1.gz", + "/usr/share/man/man1/ls.1.gz", + "/usr/share/man/man1/md5sum.1.gz", + "/usr/share/man/man1/mkdir.1.gz", + "/usr/share/man/man1/mkfifo.1.gz", + "/usr/share/man/man1/mknod.1.gz", + "/usr/share/man/man1/mktemp.1.gz", + "/usr/share/man/man1/mv.1.gz", + "/usr/share/man/man1/nice.1.gz", + "/usr/share/man/man1/nl.1.gz", + "/usr/share/man/man1/nohup.1.gz", + "/usr/share/man/man1/nproc.1.gz", + "/usr/share/man/man1/numfmt.1.gz", + "/usr/share/man/man1/od.1.gz", + "/usr/share/man/man1/paste.1.gz", + "/usr/share/man/man1/pathchk.1.gz", + "/usr/share/man/man1/pinky.1.gz", + "/usr/share/man/man1/pr.1.gz", + "/usr/share/man/man1/printenv.1.gz", + "/usr/share/man/man1/printf.1.gz", + "/usr/share/man/man1/ptx.1.gz", + "/usr/share/man/man1/pwd.1.gz", + "/usr/share/man/man1/readlink.1.gz", + "/usr/share/man/man1/realpath.1.gz", + "/usr/share/man/man1/rm.1.gz", + "/usr/share/man/man1/rmdir.1.gz", + "/usr/share/man/man1/runcon.1.gz", + "/usr/share/man/man1/seq.1.gz", + "/usr/share/man/man1/sha1sum.1.gz", + "/usr/share/man/man1/sha224sum.1.gz", + "/usr/share/man/man1/sha256sum.1.gz", + "/usr/share/man/man1/sha384sum.1.gz", + "/usr/share/man/man1/sha512sum.1.gz", + "/usr/share/man/man1/shred.1.gz", + "/usr/share/man/man1/shuf.1.gz", + "/usr/share/man/man1/sleep.1.gz", + "/usr/share/man/man1/sort.1.gz", + "/usr/share/man/man1/split.1.gz", + "/usr/share/man/man1/stat.1.gz", + "/usr/share/man/man1/stdbuf.1.gz", + "/usr/share/man/man1/stty.1.gz", + "/usr/share/man/man1/sum.1.gz", + "/usr/share/man/man1/sync.1.gz", + "/usr/share/man/man1/tac.1.gz", + "/usr/share/man/man1/tail.1.gz", + "/usr/share/man/man1/tee.1.gz", + "/usr/share/man/man1/test.1.gz", + "/usr/share/man/man1/timeout.1.gz", + "/usr/share/man/man1/touch.1.gz", + "/usr/share/man/man1/tr.1.gz", + "/usr/share/man/man1/true.1.gz", + "/usr/share/man/man1/truncate.1.gz", + "/usr/share/man/man1/tsort.1.gz", + "/usr/share/man/man1/tty.1.gz", + "/usr/share/man/man1/uname.1.gz", + "/usr/share/man/man1/unexpand.1.gz", + "/usr/share/man/man1/uniq.1.gz", + "/usr/share/man/man1/unlink.1.gz", + "/usr/share/man/man1/users.1.gz", + "/usr/share/man/man1/vdir.1.gz", + "/usr/share/man/man1/wc.1.gz", + "/usr/share/man/man1/who.1.gz", + "/usr/share/man/man1/whoami.1.gz", + "/usr/share/man/man1/yes.1.gz", + "/usr/share/man/man8/chroot.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "dash@0.5.12-12", + "Name": "dash", + "Identifier": { + "PURL": "pkg:deb/debian/dash@0.5.12-12?arch=amd64\u0026distro=debian-13.6", + "UID": "4990b2098a2a3724" + }, + "Version": "0.5.12", + "Release": "12", + "Arch": "amd64", + "SrcName": "dash", + "SrcVersion": "0.5.12", + "SrcRelease": "12", + "Licenses": [ + "BSD-3-Clause", + "public-domain", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Andrej Shadura \u003candrewsh@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "debianutils@5.23.2" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/dash", + "/usr/share/debianutils/shells.d/dash", + "/usr/share/doc/dash/README.Debian.diet", + "/usr/share/doc/dash/README.source", + "/usr/share/doc/dash/changelog.Debian.gz", + "/usr/share/doc/dash/changelog.gz", + "/usr/share/doc/dash/copyright", + "/usr/share/lintian/overrides/dash", + "/usr/share/man/man1/dash.1.gz", + "/usr/share/menu/dash" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "debconf@1.5.91", + "Name": "debconf", + "Identifier": { + "PURL": "pkg:deb/debian/debconf@1.5.91?arch=all\u0026distro=debian-13.6", + "UID": "f7c8b7ba83ed5cfe" + }, + "Version": "1.5.91", + "Arch": "all", + "SrcName": "debconf", + "SrcVersion": "1.5.91", + "Licenses": [ + "BSD-2-Clause" + ], + "Maintainer": "Debconf Developers \u003cdebconf-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/debconf", + "/usr/bin/debconf-apt-progress", + "/usr/bin/debconf-communicate", + "/usr/bin/debconf-copydb", + "/usr/bin/debconf-escape", + "/usr/bin/debconf-set-selections", + "/usr/bin/debconf-show", + "/usr/sbin/dpkg-preconfigure", + "/usr/sbin/dpkg-reconfigure", + "/usr/share/bash-completion/completions/debconf", + "/usr/share/debconf/confmodule", + "/usr/share/debconf/confmodule.sh", + "/usr/share/debconf/debconf.conf", + "/usr/share/debconf/fix_db.pl", + "/usr/share/debconf/frontend", + "/usr/share/doc/debconf/README.Debian", + "/usr/share/doc/debconf/changelog.gz", + "/usr/share/doc/debconf/copyright", + "/usr/share/lintian/overrides/debconf", + "/usr/share/man/man1/debconf-apt-progress.1.gz", + "/usr/share/man/man1/debconf-communicate.1.gz", + "/usr/share/man/man1/debconf-copydb.1.gz", + "/usr/share/man/man1/debconf-escape.1.gz", + "/usr/share/man/man1/debconf-set-selections.1.gz", + "/usr/share/man/man1/debconf-show.1.gz", + "/usr/share/man/man1/debconf.1.gz", + "/usr/share/man/man8/dpkg-preconfigure.8.gz", + "/usr/share/man/man8/dpkg-reconfigure.8.gz", + "/usr/share/perl5/Debconf/AutoSelect.pm", + "/usr/share/perl5/Debconf/Base.pm", + "/usr/share/perl5/Debconf/Client/ConfModule.pm", + "/usr/share/perl5/Debconf/ConfModule.pm", + "/usr/share/perl5/Debconf/Config.pm", + "/usr/share/perl5/Debconf/Db.pm", + "/usr/share/perl5/Debconf/DbDriver.pm", + "/usr/share/perl5/Debconf/DbDriver/Backup.pm", + "/usr/share/perl5/Debconf/DbDriver/Cache.pm", + "/usr/share/perl5/Debconf/DbDriver/Copy.pm", + "/usr/share/perl5/Debconf/DbDriver/Debug.pm", + "/usr/share/perl5/Debconf/DbDriver/DirTree.pm", + "/usr/share/perl5/Debconf/DbDriver/Directory.pm", + "/usr/share/perl5/Debconf/DbDriver/File.pm", + "/usr/share/perl5/Debconf/DbDriver/LDAP.pm", + "/usr/share/perl5/Debconf/DbDriver/PackageDir.pm", + "/usr/share/perl5/Debconf/DbDriver/Pipe.pm", + "/usr/share/perl5/Debconf/DbDriver/Stack.pm", + "/usr/share/perl5/Debconf/Element.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Boolean.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Error.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Note.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Password.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Progress.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Select.pm", + "/usr/share/perl5/Debconf/Element/Dialog/String.pm", + "/usr/share/perl5/Debconf/Element/Dialog/Text.pm", + "/usr/share/perl5/Debconf/Element/Editor/Boolean.pm", + "/usr/share/perl5/Debconf/Element/Editor/Error.pm", + "/usr/share/perl5/Debconf/Element/Editor/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Editor/Note.pm", + "/usr/share/perl5/Debconf/Element/Editor/Password.pm", + "/usr/share/perl5/Debconf/Element/Editor/Progress.pm", + "/usr/share/perl5/Debconf/Element/Editor/Select.pm", + "/usr/share/perl5/Debconf/Element/Editor/String.pm", + "/usr/share/perl5/Debconf/Element/Editor/Text.pm", + "/usr/share/perl5/Debconf/Element/Gnome.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Boolean.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Error.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Note.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Password.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Progress.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Select.pm", + "/usr/share/perl5/Debconf/Element/Gnome/String.pm", + "/usr/share/perl5/Debconf/Element/Gnome/Text.pm", + "/usr/share/perl5/Debconf/Element/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Boolean.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Error.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Note.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Password.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Progress.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Select.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/String.pm", + "/usr/share/perl5/Debconf/Element/Noninteractive/Text.pm", + "/usr/share/perl5/Debconf/Element/Select.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Boolean.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Error.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Note.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Password.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Progress.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Select.pm", + "/usr/share/perl5/Debconf/Element/Teletype/String.pm", + "/usr/share/perl5/Debconf/Element/Teletype/Text.pm", + "/usr/share/perl5/Debconf/Element/Web/Boolean.pm", + "/usr/share/perl5/Debconf/Element/Web/Error.pm", + "/usr/share/perl5/Debconf/Element/Web/Multiselect.pm", + "/usr/share/perl5/Debconf/Element/Web/Note.pm", + "/usr/share/perl5/Debconf/Element/Web/Password.pm", + "/usr/share/perl5/Debconf/Element/Web/Progress.pm", + "/usr/share/perl5/Debconf/Element/Web/Select.pm", + "/usr/share/perl5/Debconf/Element/Web/String.pm", + "/usr/share/perl5/Debconf/Element/Web/Text.pm", + "/usr/share/perl5/Debconf/Encoding.pm", + "/usr/share/perl5/Debconf/Format.pm", + "/usr/share/perl5/Debconf/Format/822.pm", + "/usr/share/perl5/Debconf/FrontEnd.pm", + "/usr/share/perl5/Debconf/FrontEnd/Dialog.pm", + "/usr/share/perl5/Debconf/FrontEnd/Editor.pm", + "/usr/share/perl5/Debconf/FrontEnd/Gnome.pm", + "/usr/share/perl5/Debconf/FrontEnd/Kde.pm", + "/usr/share/perl5/Debconf/FrontEnd/Noninteractive.pm", + "/usr/share/perl5/Debconf/FrontEnd/Passthrough.pm", + "/usr/share/perl5/Debconf/FrontEnd/Readline.pm", + "/usr/share/perl5/Debconf/FrontEnd/ScreenSize.pm", + "/usr/share/perl5/Debconf/FrontEnd/Teletype.pm", + "/usr/share/perl5/Debconf/FrontEnd/Text.pm", + "/usr/share/perl5/Debconf/FrontEnd/Web.pm", + "/usr/share/perl5/Debconf/Gettext.pm", + "/usr/share/perl5/Debconf/Iterator.pm", + "/usr/share/perl5/Debconf/Log.pm", + "/usr/share/perl5/Debconf/Path.pm", + "/usr/share/perl5/Debconf/Priority.pm", + "/usr/share/perl5/Debconf/Question.pm", + "/usr/share/perl5/Debconf/Template.pm", + "/usr/share/perl5/Debconf/Template/Transient.pm", + "/usr/share/perl5/Debconf/TmpFile.pm", + "/usr/share/perl5/Debian/DebConf/Client/ConfModule.pm", + "/usr/share/pixmaps/debian-logo.png" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "debian-archive-keyring@2025.1", + "Name": "debian-archive-keyring", + "Identifier": { + "PURL": "pkg:deb/debian/debian-archive-keyring@2025.1?arch=all\u0026distro=debian-13.6", + "UID": "a22d861380b1187c" + }, + "Version": "2025.1", + "Arch": "all", + "SrcName": "debian-archive-keyring", + "SrcVersion": "2025.1", + "Licenses": [ + "GPL-2.0-or-later" + ], + "Maintainer": "Debian Release Team \u003cpackages@release.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/share/doc/debian-archive-keyring/NEWS.Debian.gz", + "/usr/share/doc/debian-archive-keyring/README", + "/usr/share/doc/debian-archive-keyring/changelog.gz", + "/usr/share/doc/debian-archive-keyring/copyright", + "/usr/share/keyrings/debian-archive-bookworm-automatic.pgp", + "/usr/share/keyrings/debian-archive-bookworm-security-automatic.pgp", + "/usr/share/keyrings/debian-archive-bookworm-stable.pgp", + "/usr/share/keyrings/debian-archive-bullseye-automatic.pgp", + "/usr/share/keyrings/debian-archive-bullseye-security-automatic.pgp", + "/usr/share/keyrings/debian-archive-bullseye-stable.pgp", + "/usr/share/keyrings/debian-archive-keyring.pgp", + "/usr/share/keyrings/debian-archive-removed-keys.pgp", + "/usr/share/keyrings/debian-archive-trixie-automatic.pgp", + "/usr/share/keyrings/debian-archive-trixie-security-automatic.pgp", + "/usr/share/keyrings/debian-archive-trixie-stable.pgp" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "debianutils@5.23.2", + "Name": "debianutils", + "Identifier": { + "PURL": "pkg:deb/debian/debianutils@5.23.2?arch=amd64\u0026distro=debian-13.6", + "UID": "3c5d0b66afafddbb" + }, + "Version": "5.23.2", + "Arch": "amd64", + "SrcName": "debianutils", + "SrcVersion": "5.23.2", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "public-domain", + "SMAIL-GPL" + ], + "Maintainer": "Ileana Dumitrescu \u003cileanadumitrescu95@gmail.com\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/ischroot", + "/usr/bin/run-parts", + "/usr/bin/savelog", + "/usr/bin/tempfile", + "/usr/bin/which.debianutils", + "/usr/sbin/add-shell", + "/usr/sbin/installkernel", + "/usr/sbin/remove-shell", + "/usr/sbin/update-shells", + "/usr/share/debianutils/shells", + "/usr/share/doc/debianutils/README.shells", + "/usr/share/doc/debianutils/changelog.gz", + "/usr/share/doc/debianutils/copyright", + "/usr/share/man/de/man1/which.debianutils.1.gz", + "/usr/share/man/de/man8/add-shell.8.gz", + "/usr/share/man/de/man8/installkernel.8.gz", + "/usr/share/man/de/man8/remove-shell.8.gz", + "/usr/share/man/de/man8/run-parts.8.gz", + "/usr/share/man/de/man8/savelog.8.gz", + "/usr/share/man/es/man1/which.debianutils.1.gz", + "/usr/share/man/es/man8/add-shell.8.gz", + "/usr/share/man/es/man8/installkernel.8.gz", + "/usr/share/man/es/man8/remove-shell.8.gz", + "/usr/share/man/es/man8/run-parts.8.gz", + "/usr/share/man/es/man8/savelog.8.gz", + "/usr/share/man/fr/man1/which.debianutils.1.gz", + "/usr/share/man/fr/man8/add-shell.8.gz", + "/usr/share/man/fr/man8/installkernel.8.gz", + "/usr/share/man/fr/man8/remove-shell.8.gz", + "/usr/share/man/fr/man8/run-parts.8.gz", + "/usr/share/man/fr/man8/savelog.8.gz", + "/usr/share/man/it/man1/which.debianutils.1.gz", + "/usr/share/man/it/man8/add-shell.8.gz", + "/usr/share/man/it/man8/installkernel.8.gz", + "/usr/share/man/it/man8/remove-shell.8.gz", + "/usr/share/man/it/man8/run-parts.8.gz", + "/usr/share/man/it/man8/savelog.8.gz", + "/usr/share/man/ja/man1/which.debianutils.1.gz", + "/usr/share/man/ja/man8/add-shell.8.gz", + "/usr/share/man/ja/man8/installkernel.8.gz", + "/usr/share/man/ja/man8/remove-shell.8.gz", + "/usr/share/man/ja/man8/run-parts.8.gz", + "/usr/share/man/ja/man8/savelog.8.gz", + "/usr/share/man/man1/ischroot.1.gz", + "/usr/share/man/man1/tempfile.1.gz", + "/usr/share/man/man1/which.debianutils.1.gz", + "/usr/share/man/man8/add-shell.8.gz", + "/usr/share/man/man8/installkernel.8.gz", + "/usr/share/man/man8/remove-shell.8.gz", + "/usr/share/man/man8/run-parts.8.gz", + "/usr/share/man/man8/savelog.8.gz", + "/usr/share/man/man8/update-shells.8.gz", + "/usr/share/man/pl/man1/which.debianutils.1.gz", + "/usr/share/man/pl/man8/add-shell.8.gz", + "/usr/share/man/pl/man8/installkernel.8.gz", + "/usr/share/man/pl/man8/remove-shell.8.gz", + "/usr/share/man/pl/man8/run-parts.8.gz", + "/usr/share/man/pl/man8/savelog.8.gz", + "/usr/share/man/pt/man1/which.debianutils.1.gz", + "/usr/share/man/pt/man8/add-shell.8.gz", + "/usr/share/man/pt/man8/installkernel.8.gz", + "/usr/share/man/pt/man8/remove-shell.8.gz", + "/usr/share/man/pt/man8/run-parts.8.gz", + "/usr/share/man/pt/man8/savelog.8.gz", + "/usr/share/man/sl/man1/which.debianutils.1.gz", + "/usr/share/man/sl/man8/add-shell.8.gz", + "/usr/share/man/sl/man8/installkernel.8.gz", + "/usr/share/man/sl/man8/remove-shell.8.gz", + "/usr/share/man/sl/man8/run-parts.8.gz", + "/usr/share/man/sl/man8/savelog.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "diffutils@1:3.10-4", + "Name": "diffutils", + "Identifier": { + "PURL": "pkg:deb/debian/diffutils@3.10-4?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "852f693a78aaa149" + }, + "Version": "3.10", + "Release": "4", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "diffutils", + "SrcVersion": "3.10", + "SrcRelease": "4", + "SrcEpoch": 1, + "Licenses": [ + "GPL-3.0-or-later", + "FSFULLR", + "LGPL-2.1-or-later", + "GPL-3.0-with-autoconf-exception+", + "GPL-3.0-only", + "GPL-3+ with texinfo exception", + "LGPL-2.0-or-later", + "GPL-2.0-or-later", + "X11", + "FSFAP", + "GFDL-1.3-no-invariants-only", + "LGPL-3.0-or-later", + "LGPL-3.0-only", + "public-domain", + "LGPL-2.0-only", + "LGPL-2.1-only", + "GPL-2.0-only", + "GFDL-1.3-only" + ], + "Maintainer": "Santiago Vila \u003csanvila@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/cmp", + "/usr/bin/diff", + "/usr/bin/diff3", + "/usr/bin/sdiff", + "/usr/share/doc/diffutils/NEWS.gz", + "/usr/share/doc/diffutils/changelog.Debian.gz", + "/usr/share/doc/diffutils/changelog.gz", + "/usr/share/doc/diffutils/copyright", + "/usr/share/info/diffutils.info.gz", + "/usr/share/locale/bg/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ca/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/cs/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/da/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/de/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/el/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/eo/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/es/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/fi/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/fr/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ga/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/gl/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/he/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/hr/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/hu/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/id/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/it/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ja/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ka/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ko/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/lv/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ms/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/nb/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/nl/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/pl/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/pt/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ro/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/ru/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/sr/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/sv/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/tr/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/uk/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/vi/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/diffutils.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/diffutils.mo", + "/usr/share/man/man1/cmp.1.gz", + "/usr/share/man/man1/diff.1.gz", + "/usr/share/man/man1/diff3.1.gz", + "/usr/share/man/man1/sdiff.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "dpkg@1.22.22", + "Name": "dpkg", + "Identifier": { + "PURL": "pkg:deb/debian/dpkg@1.22.22?arch=amd64\u0026distro=debian-13.6", + "UID": "7b97f27e3bec0417" + }, + "Version": "1.22.22", + "Arch": "amd64", + "SrcName": "dpkg", + "SrcVersion": "1.22.22", + "Licenses": [ + "GPL-2.0-or-later", + "public-domain-s-s-d", + "GPL-2.0-only" + ], + "Maintainer": "Dpkg Developers \u003cdebian-dpkg@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "tar@1.35+dfsg-3.1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/dpkg", + "/usr/bin/dpkg-deb", + "/usr/bin/dpkg-divert", + "/usr/bin/dpkg-maintscript-helper", + "/usr/bin/dpkg-query", + "/usr/bin/dpkg-realpath", + "/usr/bin/dpkg-split", + "/usr/bin/dpkg-statoverride", + "/usr/bin/dpkg-trigger", + "/usr/bin/update-alternatives", + "/usr/lib/systemd/system/dpkg-db-backup.service", + "/usr/lib/systemd/system/dpkg-db-backup.timer", + "/usr/libexec/dpkg/dpkg-db-backup", + "/usr/libexec/dpkg/dpkg-db-keeper", + "/usr/sbin/start-stop-daemon", + "/usr/share/doc/dpkg/AUTHORS", + "/usr/share/doc/dpkg/README.api", + "/usr/share/doc/dpkg/README.bug-usertags.gz", + "/usr/share/doc/dpkg/README.feature-removal-schedule.gz", + "/usr/share/doc/dpkg/THANKS.gz", + "/usr/share/doc/dpkg/changelog.gz", + "/usr/share/doc/dpkg/copyright", + "/usr/share/dpkg/abitable", + "/usr/share/dpkg/cputable", + "/usr/share/dpkg/ostable", + "/usr/share/dpkg/sh/dpkg-error.sh", + "/usr/share/dpkg/tupletable", + "/usr/share/lintian/overrides/dpkg", + "/usr/share/lintian/profiles/dpkg/main.profile", + "/usr/share/locale/ast/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/bs/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ca/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/cs/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/da/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/de/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/dz/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/el/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/eo/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/es/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/et/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/eu/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/fr/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/gl/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/hu/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/id/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/it/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ja/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/km/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ko/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ku/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/lt/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/mr/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/nb/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ne/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/nl/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/nn/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/oc/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/pa/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/pl/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/pt/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ro/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/ru/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/sk/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/sv/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/th/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/tl/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/tr/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/vi/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/dpkg.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/dpkg.mo", + "/usr/share/man/de/man1/dpkg-deb.1.gz", + "/usr/share/man/de/man1/dpkg-divert.1.gz", + "/usr/share/man/de/man1/dpkg-maintscript-helper.1.gz", + "/usr/share/man/de/man1/dpkg-query.1.gz", + "/usr/share/man/de/man1/dpkg-realpath.1.gz", + "/usr/share/man/de/man1/dpkg-split.1.gz", + "/usr/share/man/de/man1/dpkg-statoverride.1.gz", + "/usr/share/man/de/man1/dpkg-trigger.1.gz", + "/usr/share/man/de/man1/dpkg.1.gz", + "/usr/share/man/de/man1/update-alternatives.1.gz", + "/usr/share/man/de/man5/dpkg.cfg.5.gz", + "/usr/share/man/de/man8/start-stop-daemon.8.gz", + "/usr/share/man/es/man5/dpkg.cfg.5.gz", + "/usr/share/man/fr/man1/dpkg-divert.1.gz", + "/usr/share/man/fr/man1/dpkg-maintscript-helper.1.gz", + "/usr/share/man/fr/man1/dpkg-query.1.gz", + "/usr/share/man/fr/man1/dpkg-realpath.1.gz", + "/usr/share/man/fr/man1/dpkg-split.1.gz", + "/usr/share/man/fr/man1/dpkg-trigger.1.gz", + "/usr/share/man/fr/man1/update-alternatives.1.gz", + "/usr/share/man/fr/man5/dpkg.cfg.5.gz", + "/usr/share/man/fr/man8/start-stop-daemon.8.gz", + "/usr/share/man/it/man5/dpkg.cfg.5.gz", + "/usr/share/man/ja/man5/dpkg.cfg.5.gz", + "/usr/share/man/man1/dpkg-deb.1.gz", + "/usr/share/man/man1/dpkg-divert.1.gz", + "/usr/share/man/man1/dpkg-maintscript-helper.1.gz", + "/usr/share/man/man1/dpkg-query.1.gz", + "/usr/share/man/man1/dpkg-realpath.1.gz", + "/usr/share/man/man1/dpkg-split.1.gz", + "/usr/share/man/man1/dpkg-statoverride.1.gz", + "/usr/share/man/man1/dpkg-trigger.1.gz", + "/usr/share/man/man1/dpkg.1.gz", + "/usr/share/man/man1/update-alternatives.1.gz", + "/usr/share/man/man5/dpkg.cfg.5.gz", + "/usr/share/man/man8/start-stop-daemon.8.gz", + "/usr/share/man/nl/man1/dpkg-deb.1.gz", + "/usr/share/man/nl/man1/dpkg-divert.1.gz", + "/usr/share/man/nl/man1/dpkg-maintscript-helper.1.gz", + "/usr/share/man/nl/man1/dpkg-query.1.gz", + "/usr/share/man/nl/man1/dpkg-realpath.1.gz", + "/usr/share/man/nl/man1/dpkg-split.1.gz", + "/usr/share/man/nl/man1/dpkg-statoverride.1.gz", + "/usr/share/man/nl/man1/dpkg-trigger.1.gz", + "/usr/share/man/nl/man1/dpkg.1.gz", + "/usr/share/man/nl/man1/update-alternatives.1.gz", + "/usr/share/man/nl/man5/dpkg.cfg.5.gz", + "/usr/share/man/nl/man8/start-stop-daemon.8.gz", + "/usr/share/man/pl/man5/dpkg.cfg.5.gz", + "/usr/share/man/pt/man1/dpkg-deb.1.gz", + "/usr/share/man/pt/man1/dpkg-divert.1.gz", + "/usr/share/man/pt/man1/dpkg-maintscript-helper.1.gz", + "/usr/share/man/pt/man1/dpkg-query.1.gz", + "/usr/share/man/pt/man1/dpkg-realpath.1.gz", + "/usr/share/man/pt/man1/dpkg-split.1.gz", + "/usr/share/man/pt/man1/dpkg-statoverride.1.gz", + "/usr/share/man/pt/man1/dpkg-trigger.1.gz", + "/usr/share/man/pt/man1/dpkg.1.gz", + "/usr/share/man/pt/man1/update-alternatives.1.gz", + "/usr/share/man/pt/man5/dpkg.cfg.5.gz", + "/usr/share/man/pt/man8/start-stop-daemon.8.gz", + "/usr/share/man/sv/man1/dpkg-deb.1.gz", + "/usr/share/man/sv/man1/dpkg-divert.1.gz", + "/usr/share/man/sv/man1/dpkg-maintscript-helper.1.gz", + "/usr/share/man/sv/man1/dpkg-query.1.gz", + "/usr/share/man/sv/man1/dpkg-realpath.1.gz", + "/usr/share/man/sv/man1/dpkg-split.1.gz", + "/usr/share/man/sv/man1/dpkg-statoverride.1.gz", + "/usr/share/man/sv/man1/dpkg-trigger.1.gz", + "/usr/share/man/sv/man1/dpkg.1.gz", + "/usr/share/man/sv/man1/update-alternatives.1.gz", + "/usr/share/man/sv/man5/dpkg.cfg.5.gz", + "/usr/share/man/sv/man8/start-stop-daemon.8.gz", + "/usr/share/polkit-1/actions/org.dpkg.pkexec.update-alternatives.policy" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "findutils@4.10.0-3", + "Name": "findutils", + "Identifier": { + "PURL": "pkg:deb/debian/findutils@4.10.0-3?arch=amd64\u0026distro=debian-13.6", + "UID": "12e741692291b42a" + }, + "Version": "4.10.0", + "Release": "3", + "Arch": "amd64", + "SrcName": "findutils", + "SrcVersion": "4.10.0", + "SrcRelease": "3", + "Licenses": [ + "GFDL-1.3-no-invariants-or-later", + "GPL-3.0-or-later", + "FSFAP", + "GPL-2+ with Autoconf-data exception", + "GPL-3+ with Autoconf-data exception", + "FSFULLR", + "GPL-2.0-or-later", + "X11", + "public-domain", + "LGPL-2.1-or-later", + "GPL with automake exception", + "LGPL-2.0-or-later", + "LGPL-3.0-or-later", + "BSD-3-Clause", + "GPL-3+ with Bison-2.2 exception", + "LGPL-3.0-only", + "ISC", + "GFDL-1.3-only", + "GPL-2.0-only", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only" + ], + "Maintainer": "Andreas Metzler \u003cametzler@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/find", + "/usr/bin/xargs", + "/usr/share/doc-base/findutils.findutils", + "/usr/share/doc/findutils/NEWS.gz", + "/usr/share/doc/findutils/README.gz", + "/usr/share/doc/findutils/TODO", + "/usr/share/doc/findutils/changelog.Debian.gz", + "/usr/share/doc/findutils/changelog.gz", + "/usr/share/doc/findutils/copyright", + "/usr/share/info/find-maint.info.gz", + "/usr/share/info/find.info.gz", + "/usr/share/locale/be/LC_MESSAGES/findutils.mo", + "/usr/share/locale/bg/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ca/LC_MESSAGES/findutils.mo", + "/usr/share/locale/cs/LC_MESSAGES/findutils.mo", + "/usr/share/locale/da/LC_MESSAGES/findutils.mo", + "/usr/share/locale/de/LC_MESSAGES/findutils.mo", + "/usr/share/locale/el/LC_MESSAGES/findutils.mo", + "/usr/share/locale/eo/LC_MESSAGES/findutils.mo", + "/usr/share/locale/es/LC_MESSAGES/findutils.mo", + "/usr/share/locale/et/LC_MESSAGES/findutils.mo", + "/usr/share/locale/fi/LC_MESSAGES/findutils.mo", + "/usr/share/locale/fr/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ga/LC_MESSAGES/findutils.mo", + "/usr/share/locale/gl/LC_MESSAGES/findutils.mo", + "/usr/share/locale/hr/LC_MESSAGES/findutils.mo", + "/usr/share/locale/hu/LC_MESSAGES/findutils.mo", + "/usr/share/locale/id/LC_MESSAGES/findutils.mo", + "/usr/share/locale/it/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ja/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ka/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ko/LC_MESSAGES/findutils.mo", + "/usr/share/locale/lg/LC_MESSAGES/findutils.mo", + "/usr/share/locale/lt/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ms/LC_MESSAGES/findutils.mo", + "/usr/share/locale/nb/LC_MESSAGES/findutils.mo", + "/usr/share/locale/nl/LC_MESSAGES/findutils.mo", + "/usr/share/locale/pl/LC_MESSAGES/findutils.mo", + "/usr/share/locale/pt/LC_MESSAGES/findutils.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ro/LC_MESSAGES/findutils.mo", + "/usr/share/locale/ru/LC_MESSAGES/findutils.mo", + "/usr/share/locale/sk/LC_MESSAGES/findutils.mo", + "/usr/share/locale/sl/LC_MESSAGES/findutils.mo", + "/usr/share/locale/sr/LC_MESSAGES/findutils.mo", + "/usr/share/locale/sv/LC_MESSAGES/findutils.mo", + "/usr/share/locale/tr/LC_MESSAGES/findutils.mo", + "/usr/share/locale/uk/LC_MESSAGES/findutils.mo", + "/usr/share/locale/vi/LC_MESSAGES/findutils.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/findutils.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/findutils.mo", + "/usr/share/man/man1/find.1.gz", + "/usr/share/man/man1/xargs.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "gcc-14-base@14.2.0-19", + "Name": "gcc-14-base", + "Identifier": { + "PURL": "pkg:deb/debian/gcc-14-base@14.2.0-19?arch=amd64\u0026distro=debian-13.6", + "UID": "371c061d08215a1b" + }, + "Version": "14.2.0", + "Release": "19", + "Arch": "amd64", + "SrcName": "gcc-14", + "SrcVersion": "14.2.0", + "SrcRelease": "19", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-3.0-only", + "GFDL-1.2-only", + "Artistic-2.0", + "LGPL-2.0-or-later" + ], + "Maintainer": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/share/doc/gcc-14-base/README.Debian.amd64.gz", + "/usr/share/doc/gcc-14-base/TODO.Debian", + "/usr/share/doc/gcc-14-base/changelog.Debian.gz", + "/usr/share/doc/gcc-14-base/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "grep@3.11-4", + "Name": "grep", + "Identifier": { + "PURL": "pkg:deb/debian/grep@3.11-4?arch=amd64\u0026distro=debian-13.6", + "UID": "6ce8b4eed9c0d137" + }, + "Version": "3.11", + "Release": "4", + "Arch": "amd64", + "SrcName": "grep", + "SrcVersion": "3.11", + "SrcRelease": "4", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-3.0-only" + ], + "Maintainer": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/egrep", + "/usr/bin/fgrep", + "/usr/bin/grep", + "/usr/bin/rgrep", + "/usr/share/doc/grep/AUTHORS", + "/usr/share/doc/grep/NEWS.Debian.gz", + "/usr/share/doc/grep/NEWS.gz", + "/usr/share/doc/grep/README", + "/usr/share/doc/grep/THANKS.gz", + "/usr/share/doc/grep/TODO.gz", + "/usr/share/doc/grep/changelog.Debian.gz", + "/usr/share/doc/grep/changelog.gz", + "/usr/share/doc/grep/copyright", + "/usr/share/info/grep.info.gz", + "/usr/share/locale/af/LC_MESSAGES/grep.mo", + "/usr/share/locale/be/LC_MESSAGES/grep.mo", + "/usr/share/locale/bg/LC_MESSAGES/grep.mo", + "/usr/share/locale/ca/LC_MESSAGES/grep.mo", + "/usr/share/locale/cs/LC_MESSAGES/grep.mo", + "/usr/share/locale/da/LC_MESSAGES/grep.mo", + "/usr/share/locale/de/LC_MESSAGES/grep.mo", + "/usr/share/locale/el/LC_MESSAGES/grep.mo", + "/usr/share/locale/eo/LC_MESSAGES/grep.mo", + "/usr/share/locale/es/LC_MESSAGES/grep.mo", + "/usr/share/locale/et/LC_MESSAGES/grep.mo", + "/usr/share/locale/eu/LC_MESSAGES/grep.mo", + "/usr/share/locale/fi/LC_MESSAGES/grep.mo", + "/usr/share/locale/fr/LC_MESSAGES/grep.mo", + "/usr/share/locale/ga/LC_MESSAGES/grep.mo", + "/usr/share/locale/gl/LC_MESSAGES/grep.mo", + "/usr/share/locale/he/LC_MESSAGES/grep.mo", + "/usr/share/locale/hr/LC_MESSAGES/grep.mo", + "/usr/share/locale/hu/LC_MESSAGES/grep.mo", + "/usr/share/locale/id/LC_MESSAGES/grep.mo", + "/usr/share/locale/it/LC_MESSAGES/grep.mo", + "/usr/share/locale/ja/LC_MESSAGES/grep.mo", + "/usr/share/locale/ka/LC_MESSAGES/grep.mo", + "/usr/share/locale/ko/LC_MESSAGES/grep.mo", + "/usr/share/locale/ky/LC_MESSAGES/grep.mo", + "/usr/share/locale/lt/LC_MESSAGES/grep.mo", + "/usr/share/locale/nb/LC_MESSAGES/grep.mo", + "/usr/share/locale/nl/LC_MESSAGES/grep.mo", + "/usr/share/locale/pa/LC_MESSAGES/grep.mo", + "/usr/share/locale/pl/LC_MESSAGES/grep.mo", + "/usr/share/locale/pt/LC_MESSAGES/grep.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/grep.mo", + "/usr/share/locale/ro/LC_MESSAGES/grep.mo", + "/usr/share/locale/ru/LC_MESSAGES/grep.mo", + "/usr/share/locale/sk/LC_MESSAGES/grep.mo", + "/usr/share/locale/sl/LC_MESSAGES/grep.mo", + "/usr/share/locale/sr/LC_MESSAGES/grep.mo", + "/usr/share/locale/sv/LC_MESSAGES/grep.mo", + "/usr/share/locale/ta/LC_MESSAGES/grep.mo", + "/usr/share/locale/th/LC_MESSAGES/grep.mo", + "/usr/share/locale/tr/LC_MESSAGES/grep.mo", + "/usr/share/locale/uk/LC_MESSAGES/grep.mo", + "/usr/share/locale/vi/LC_MESSAGES/grep.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/grep.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/grep.mo", + "/usr/share/man/man1/grep.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "gzip@1.13-1", + "Name": "gzip", + "Identifier": { + "PURL": "pkg:deb/debian/gzip@1.13-1?arch=amd64\u0026distro=debian-13.6", + "UID": "954545ce99bc687e" + }, + "Version": "1.13", + "Release": "1", + "Arch": "amd64", + "SrcName": "gzip", + "SrcVersion": "1.13", + "SrcRelease": "1", + "Licenses": [ + "GPL-3.0-or-later", + "GFDL-1.3+-no-invariant", + "FSF-manpages", + "GPL-3.0-only", + "GFDL-3" + ], + "Maintainer": "Milan Kupcevic \u003cmilan@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/gunzip", + "/usr/bin/gzexe", + "/usr/bin/gzip", + "/usr/bin/zcat", + "/usr/bin/zcmp", + "/usr/bin/zdiff", + "/usr/bin/zegrep", + "/usr/bin/zfgrep", + "/usr/bin/zforce", + "/usr/bin/zgrep", + "/usr/bin/zless", + "/usr/bin/zmore", + "/usr/bin/znew", + "/usr/share/doc/gzip/NEWS.gz", + "/usr/share/doc/gzip/README.gz", + "/usr/share/doc/gzip/TODO", + "/usr/share/doc/gzip/changelog.Debian.gz", + "/usr/share/doc/gzip/changelog.gz", + "/usr/share/doc/gzip/copyright", + "/usr/share/info/gzip.info.gz", + "/usr/share/man/man1/gzexe.1.gz", + "/usr/share/man/man1/gzip.1.gz", + "/usr/share/man/man1/zdiff.1.gz", + "/usr/share/man/man1/zforce.1.gz", + "/usr/share/man/man1/zgrep.1.gz", + "/usr/share/man/man1/zless.1.gz", + "/usr/share/man/man1/zmore.1.gz", + "/usr/share/man/man1/znew.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "hostname@3.25", + "Name": "hostname", + "Identifier": { + "PURL": "pkg:deb/debian/hostname@3.25?arch=amd64\u0026distro=debian-13.6", + "UID": "641772722328aedf" + }, + "Version": "3.25", + "Arch": "amd64", + "SrcName": "hostname", + "SrcVersion": "3.25", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Michael Meskes \u003cmeskes@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/hostname", + "/usr/share/doc/hostname/changelog.gz", + "/usr/share/doc/hostname/copyright", + "/usr/share/man/man1/hostname.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "init-system-helpers@1.69~deb13u1", + "Name": "init-system-helpers", + "Identifier": { + "PURL": "pkg:deb/debian/init-system-helpers@1.69~deb13u1?arch=all\u0026distro=debian-13.6", + "UID": "cb52819ec2f1a236" + }, + "Version": "1.69~deb13u1", + "Arch": "all", + "SrcName": "init-system-helpers", + "SrcVersion": "1.69~deb13u1", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/deb-systemd-helper", + "/usr/bin/deb-systemd-invoke", + "/usr/sbin/invoke-rc.d", + "/usr/sbin/service", + "/usr/sbin/update-rc.d", + "/usr/share/bug/init-system-helpers/control", + "/usr/share/doc/init-system-helpers/README.invoke-rc.d.gz", + "/usr/share/doc/init-system-helpers/README.policy-rc.d.gz", + "/usr/share/doc/init-system-helpers/changelog.gz", + "/usr/share/doc/init-system-helpers/copyright", + "/usr/share/lintian/overrides/init-system-helpers", + "/usr/share/man/man1/deb-systemd-helper.1p.gz", + "/usr/share/man/man1/deb-systemd-invoke.1p.gz", + "/usr/share/man/man8/invoke-rc.d.8.gz", + "/usr/share/man/man8/service.8.gz", + "/usr/share/man/man8/update-rc.d.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libacl1@2.3.2-2+b1", + "Name": "libacl1", + "Identifier": { + "PURL": "pkg:deb/debian/libacl1@2.3.2-2%2Bb1?arch=amd64\u0026distro=debian-13.6", + "UID": "f9f7789d147b9636" + }, + "Version": "2.3.2", + "Release": "2+b1", + "Arch": "amd64", + "SrcName": "acl", + "SrcVersion": "2.3.2", + "SrcRelease": "2", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "LGPL-2.0-or-later", + "LGPL-2.1-only" + ], + "Maintainer": "Guillem Jover \u003cguillem@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libacl.so.1.1.2302", + "/usr/share/doc/libacl1/changelog.Debian.amd64.gz", + "/usr/share/doc/libacl1/changelog.Debian.gz", + "/usr/share/doc/libacl1/changelog.gz", + "/usr/share/doc/libacl1/copyright", + "/usr/share/lintian/overrides/libacl1" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libapt-pkg7.0@3.0.3", + "Name": "libapt-pkg7.0", + "Identifier": { + "PURL": "pkg:deb/debian/libapt-pkg7.0@3.0.3?arch=amd64\u0026distro=debian-13.6", + "UID": "f84404f3bc23d874" + }, + "Version": "3.0.3", + "Arch": "amd64", + "SrcName": "apt", + "SrcVersion": "3.0.3", + "Licenses": [ + "GPL-2.0-or-later", + "curl", + "BSD-3-Clause", + "MIT", + "GPL-2.0-only" + ], + "Maintainer": "APT Development Team \u003cdeity@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libbz2-1.0@1.0.8-6", + "libc6@2.41-12+deb13u3", + "libgcc-s1@14.2.0-19", + "liblz4-1@1.10.0-4", + "liblzma5@5.8.1-1+deb13u1", + "libssl3t64@3.5.7-1~deb13u2", + "libstdc++6@14.2.0-19", + "libsystemd0@257.13-1~deb13u1", + "libudev1@257.13-1~deb13u1", + "libxxhash0@0.8.3-2", + "libzstd1@1.5.7+dfsg-1", + "zlib1g@1:1.3.dfsg+really1.3.1-1+b1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libapt-pkg.so.7.0.0", + "/usr/share/doc/libapt-pkg7.0/NEWS.Debian.gz", + "/usr/share/doc/libapt-pkg7.0/changelog.gz", + "/usr/share/doc/libapt-pkg7.0/copyright", + "/usr/share/locale/ar/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ast/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/bg/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/bs/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ca/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/cs/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/cy/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/da/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/de/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/dz/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/el/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/es/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/eu/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/fi/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/fr/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/gl/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/hu/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/it/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ja/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/km/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ko/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ku/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/lt/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/mr/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/nb/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ne/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/nl/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/nn/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/pl/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/pt/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ro/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/ru/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/sk/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/sl/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/sv/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/th/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/tl/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/tr/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/uk/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/vi/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/libapt-pkg7.0.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/libapt-pkg7.0.mo" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libattr1@1:2.5.2-3", + "Name": "libattr1", + "Identifier": { + "PURL": "pkg:deb/debian/libattr1@2.5.2-3?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "90d554a582a8683b" + }, + "Version": "2.5.2", + "Release": "3", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "attr", + "SrcVersion": "2.5.2", + "SrcRelease": "3", + "SrcEpoch": 1, + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "LGPL-2.0-or-later", + "LGPL-2.1-only" + ], + "Maintainer": "Guillem Jover \u003cguillem@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libattr.so.1.1.2502", + "/usr/share/doc/libattr1/changelog.Debian.gz", + "/usr/share/doc/libattr1/changelog.gz", + "/usr/share/doc/libattr1/copyright", + "/usr/share/lintian/overrides/libattr1" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libaudit-common@1:4.0.2-2", + "Name": "libaudit-common", + "Identifier": { + "PURL": "pkg:deb/debian/libaudit-common@4.0.2-2?arch=all\u0026distro=debian-13.6\u0026epoch=1", + "UID": "d20cd9a11d8e018d" + }, + "Version": "4.0.2", + "Release": "2", + "Epoch": 1, + "Arch": "all", + "SrcName": "audit", + "SrcVersion": "4.0.2", + "SrcRelease": "2", + "SrcEpoch": 1, + "Licenses": [ + "GPL-2.0-only", + "LGPL-2.1-only", + "GPL-1.0-only" + ], + "Maintainer": "Laurent Bigonville \u003cbigon@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/share/doc/libaudit-common/changelog.Debian.gz", + "/usr/share/doc/libaudit-common/changelog.gz", + "/usr/share/doc/libaudit-common/copyright", + "/usr/share/man/man5/libaudit.conf.5.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libaudit1@1:4.0.2-2+b2", + "Name": "libaudit1", + "Identifier": { + "PURL": "pkg:deb/debian/libaudit1@4.0.2-2%2Bb2?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "c47a55b8e27ace3c" + }, + "Version": "4.0.2", + "Release": "2+b2", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "audit", + "SrcVersion": "4.0.2", + "SrcRelease": "2", + "SrcEpoch": 1, + "Licenses": [ + "GPL-2.0-only", + "LGPL-2.1-only", + "GPL-1.0-only" + ], + "Maintainer": "Laurent Bigonville \u003cbigon@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libaudit-common@1:4.0.2-2", + "libc6@2.41-12+deb13u3", + "libcap-ng0@0.8.5-4+b1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libaudit.so.1.0.0", + "/usr/share/doc/libaudit1/changelog.Debian.amd64.gz", + "/usr/share/doc/libaudit1/changelog.Debian.gz", + "/usr/share/doc/libaudit1/changelog.gz", + "/usr/share/doc/libaudit1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libblkid1@2.41.5-0+deb13u1", + "Name": "libblkid1", + "Identifier": { + "PURL": "pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "57ce331079f40f84" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libblkid.so.1.1.0", + "/usr/share/doc/libblkid1/NEWS.Debian.gz", + "/usr/share/doc/libblkid1/changelog.Debian.gz", + "/usr/share/doc/libblkid1/changelog.gz", + "/usr/share/doc/libblkid1/copyright", + "/usr/share/lintian/overrides/libblkid1" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libbsd0@0.12.2-2", + "Name": "libbsd0", + "Identifier": { + "PURL": "pkg:deb/debian/libbsd0@0.12.2-2?arch=amd64\u0026distro=debian-13.6", + "UID": "a8f4afa42f768363" + }, + "Version": "0.12.2", + "Release": "2", + "Arch": "amd64", + "SrcName": "libbsd", + "SrcVersion": "0.12.2", + "SrcRelease": "2", + "Licenses": [ + "BSD-3-Clause", + "BSD-3-clause-Regents", + "BSD-2-Clause-NetBSD", + "BSD-3-clause-author", + "BSD-3-clause-John-Birrell", + "BSD-5-clause-Peter-Wemm", + "BSD-2-Clause", + "BSD-2-clause-verbatim", + "BSD-2-clause-author", + "ISC", + "ISC-Original", + "MIT", + "public-domain", + "Beerware" + ], + "Maintainer": "Guillem Jover \u003cguillem@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libmd0@1.1.0-2+b1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libbsd.so.0.12.2", + "/usr/share/doc/libbsd0/changelog.Debian.gz", + "/usr/share/doc/libbsd0/changelog.gz", + "/usr/share/doc/libbsd0/copyright", + "/usr/share/lintian/overrides/libbsd0" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libbz2-1.0@1.0.8-6", + "Name": "libbz2-1.0", + "Identifier": { + "PURL": "pkg:deb/debian/libbz2-1.0@1.0.8-6?arch=amd64\u0026distro=debian-13.6", + "UID": "2da429aca83dde92" + }, + "Version": "1.0.8", + "Release": "6", + "Arch": "amd64", + "SrcName": "bzip2", + "SrcVersion": "1.0.8", + "SrcRelease": "6", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-only" + ], + "Maintainer": "Anibal Monsalve Salazar \u003canibal@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libbz2.so.1.0.4", + "/usr/share/doc/libbz2-1.0/changelog.Debian.gz", + "/usr/share/doc/libbz2-1.0/changelog.gz", + "/usr/share/doc/libbz2-1.0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libc-bin@2.41-12+deb13u3", + "Name": "libc-bin", + "Identifier": { + "PURL": "pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64\u0026distro=debian-13.6", + "UID": "c45af597301c8c0b" + }, + "Version": "2.41", + "Release": "12+deb13u3", + "Arch": "amd64", + "SrcName": "glibc", + "SrcVersion": "2.41", + "SrcRelease": "12+deb13u3", + "Licenses": [ + "LGPL-2.1-or-later", + "LGPL-2.0-or-later", + "LGPL-2.1+-with-link-exception", + "LGPL-3.0-or-later", + "GPL-2.0-or-later", + "GPL-2+-with-link-exception", + "GPL-2.0-only", + "GPL-3.0-or-later", + "FSFAP", + "Carnegie", + "Inner-Net", + "MIT-like-Lord", + "BSD-like-Spencer", + "PCRE", + "BSD-3-clause-Carnegie", + "Unicode-DFS-2016", + "BSL-1.0", + "SunPro", + "CORE-MATH", + "BSD-3-clause-Berkeley", + "BSD-3-clause-WIDE", + "BSD-2-Clause", + "BSD-3-clause-Oracle", + "DEC", + "IBM", + "ISC", + "Univ-Coimbra", + "public-domain", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/getconf", + "/usr/bin/getent", + "/usr/bin/iconv", + "/usr/bin/ldd", + "/usr/bin/locale", + "/usr/bin/localedef", + "/usr/bin/pldd", + "/usr/bin/tzselect", + "/usr/bin/zdump", + "/usr/lib/locale/C.utf8/LC_ADDRESS", + "/usr/lib/locale/C.utf8/LC_COLLATE", + "/usr/lib/locale/C.utf8/LC_CTYPE", + "/usr/lib/locale/C.utf8/LC_IDENTIFICATION", + "/usr/lib/locale/C.utf8/LC_MEASUREMENT", + "/usr/lib/locale/C.utf8/LC_MESSAGES/SYS_LC_MESSAGES", + "/usr/lib/locale/C.utf8/LC_MONETARY", + "/usr/lib/locale/C.utf8/LC_NAME", + "/usr/lib/locale/C.utf8/LC_NUMERIC", + "/usr/lib/locale/C.utf8/LC_PAPER", + "/usr/lib/locale/C.utf8/LC_TELEPHONE", + "/usr/lib/locale/C.utf8/LC_TIME", + "/usr/sbin/iconvconfig", + "/usr/sbin/ldconfig", + "/usr/sbin/zic", + "/usr/share/doc/libc-bin/changelog.Debian.gz", + "/usr/share/doc/libc-bin/changelog.gz", + "/usr/share/doc/libc-bin/copyright", + "/usr/share/libc-bin/nsswitch.conf", + "/usr/share/lintian/overrides/libc-bin", + "/usr/share/man/man1/getconf.1.gz", + "/usr/share/man/man1/tzselect.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libc6@2.41-12+deb13u3", + "Name": "libc6", + "Identifier": { + "PURL": "pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64\u0026distro=debian-13.6", + "UID": "2a1acf211abcdd46" + }, + "Version": "2.41", + "Release": "12+deb13u3", + "Arch": "amd64", + "SrcName": "glibc", + "SrcVersion": "2.41", + "SrcRelease": "12+deb13u3", + "Licenses": [ + "LGPL-2.1-or-later", + "LGPL-2.0-or-later", + "LGPL-2.1+-with-link-exception", + "LGPL-3.0-or-later", + "GPL-2.0-or-later", + "GPL-2+-with-link-exception", + "GPL-2.0-only", + "GPL-3.0-or-later", + "FSFAP", + "Carnegie", + "Inner-Net", + "MIT-like-Lord", + "BSD-like-Spencer", + "PCRE", + "BSD-3-clause-Carnegie", + "Unicode-DFS-2016", + "BSL-1.0", + "SunPro", + "CORE-MATH", + "BSD-3-clause-Berkeley", + "BSD-3-clause-WIDE", + "BSD-2-Clause", + "BSD-3-clause-Oracle", + "DEC", + "IBM", + "ISC", + "Univ-Coimbra", + "public-domain", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libgcc-s1@14.2.0-19" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/gconv/ANSI_X3.110.so", + "/usr/lib/x86_64-linux-gnu/gconv/ARMSCII-8.so", + "/usr/lib/x86_64-linux-gnu/gconv/ASMO_449.so", + "/usr/lib/x86_64-linux-gnu/gconv/BIG5.so", + "/usr/lib/x86_64-linux-gnu/gconv/BIG5HKSCS.so", + "/usr/lib/x86_64-linux-gnu/gconv/BRF.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP10007.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1125.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1250.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1251.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1252.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1253.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1254.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1255.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1256.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1257.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP1258.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP737.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP770.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP771.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP772.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP773.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP774.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP775.so", + "/usr/lib/x86_64-linux-gnu/gconv/CP932.so", + "/usr/lib/x86_64-linux-gnu/gconv/CSN_369103.so", + "/usr/lib/x86_64-linux-gnu/gconv/CWI.so", + "/usr/lib/x86_64-linux-gnu/gconv/DEC-MCS.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-AT-DE-A.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-AT-DE.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-CA-FR.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-DK-NO-A.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-DK-NO.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-ES-A.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-ES-S.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-ES.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-FI-SE-A.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-FI-SE.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-FR.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-IS-FRISS.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-IT.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-PT.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-UK.so", + "/usr/lib/x86_64-linux-gnu/gconv/EBCDIC-US.so", + "/usr/lib/x86_64-linux-gnu/gconv/ECMA-CYRILLIC.so", + "/usr/lib/x86_64-linux-gnu/gconv/EUC-CN.so", + "/usr/lib/x86_64-linux-gnu/gconv/EUC-JISX0213.so", + "/usr/lib/x86_64-linux-gnu/gconv/EUC-JP-MS.so", + "/usr/lib/x86_64-linux-gnu/gconv/EUC-JP.so", + "/usr/lib/x86_64-linux-gnu/gconv/EUC-KR.so", + "/usr/lib/x86_64-linux-gnu/gconv/EUC-TW.so", + "/usr/lib/x86_64-linux-gnu/gconv/GB18030.so", + "/usr/lib/x86_64-linux-gnu/gconv/GBBIG5.so", + "/usr/lib/x86_64-linux-gnu/gconv/GBGBK.so", + "/usr/lib/x86_64-linux-gnu/gconv/GBK.so", + "/usr/lib/x86_64-linux-gnu/gconv/GEORGIAN-ACADEMY.so", + "/usr/lib/x86_64-linux-gnu/gconv/GEORGIAN-PS.so", + "/usr/lib/x86_64-linux-gnu/gconv/GOST_19768-74.so", + "/usr/lib/x86_64-linux-gnu/gconv/GREEK-CCITT.so", + "/usr/lib/x86_64-linux-gnu/gconv/GREEK7-OLD.so", + "/usr/lib/x86_64-linux-gnu/gconv/GREEK7.so", + "/usr/lib/x86_64-linux-gnu/gconv/HP-GREEK8.so", + "/usr/lib/x86_64-linux-gnu/gconv/HP-ROMAN8.so", + "/usr/lib/x86_64-linux-gnu/gconv/HP-ROMAN9.so", + "/usr/lib/x86_64-linux-gnu/gconv/HP-THAI8.so", + "/usr/lib/x86_64-linux-gnu/gconv/HP-TURKISH8.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM037.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM038.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1004.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1008.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1008_420.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1025.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1026.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1046.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1047.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1097.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1112.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1122.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1123.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1124.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1129.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1130.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1132.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1133.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1137.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1140.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1141.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1142.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1143.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1144.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1145.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1146.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1147.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1148.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1149.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1153.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1154.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1155.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1156.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1157.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1158.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1160.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1161.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1162.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1163.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1164.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1166.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1167.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM12712.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1364.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1371.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1388.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1390.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM1399.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM16804.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM256.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM273.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM274.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM275.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM277.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM278.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM280.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM281.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM284.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM285.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM290.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM297.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM420.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM423.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM424.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM437.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM4517.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM4899.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM4909.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM4971.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM500.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM5347.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM803.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM850.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM851.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM852.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM855.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM856.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM857.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM858.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM860.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM861.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM862.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM863.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM864.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM865.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM866.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM866NAV.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM868.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM869.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM870.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM871.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM874.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM875.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM880.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM891.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM901.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM902.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM903.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM9030.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM904.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM905.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM9066.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM918.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM921.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM922.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM930.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM932.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM933.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM935.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM937.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM939.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM943.so", + "/usr/lib/x86_64-linux-gnu/gconv/IBM9448.so", + "/usr/lib/x86_64-linux-gnu/gconv/IEC_P27-1.so", + "/usr/lib/x86_64-linux-gnu/gconv/INIS-8.so", + "/usr/lib/x86_64-linux-gnu/gconv/INIS-CYRILLIC.so", + "/usr/lib/x86_64-linux-gnu/gconv/INIS.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISIRI-3342.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-2022-CN-EXT.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-2022-CN.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-2022-JP-3.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-2022-JP.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-2022-KR.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-IR-197.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO-IR-209.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO646.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-1.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-10.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-11.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-13.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-14.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-15.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-16.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-2.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-3.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-4.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-5.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-6.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-7.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-8.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-9.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO8859-9E.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_10367-BOX.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_11548-1.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_2033.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_5427-EXT.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_5427.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_5428.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_6937-2.so", + "/usr/lib/x86_64-linux-gnu/gconv/ISO_6937.so", + "/usr/lib/x86_64-linux-gnu/gconv/JOHAB.so", + "/usr/lib/x86_64-linux-gnu/gconv/KOI-8.so", + "/usr/lib/x86_64-linux-gnu/gconv/KOI8-R.so", + "/usr/lib/x86_64-linux-gnu/gconv/KOI8-RU.so", + "/usr/lib/x86_64-linux-gnu/gconv/KOI8-T.so", + "/usr/lib/x86_64-linux-gnu/gconv/KOI8-U.so", + "/usr/lib/x86_64-linux-gnu/gconv/LATIN-GREEK-1.so", + "/usr/lib/x86_64-linux-gnu/gconv/LATIN-GREEK.so", + "/usr/lib/x86_64-linux-gnu/gconv/MAC-CENTRALEUROPE.so", + "/usr/lib/x86_64-linux-gnu/gconv/MAC-IS.so", + "/usr/lib/x86_64-linux-gnu/gconv/MAC-SAMI.so", + "/usr/lib/x86_64-linux-gnu/gconv/MAC-UK.so", + "/usr/lib/x86_64-linux-gnu/gconv/MACINTOSH.so", + "/usr/lib/x86_64-linux-gnu/gconv/MIK.so", + "/usr/lib/x86_64-linux-gnu/gconv/NATS-DANO.so", + "/usr/lib/x86_64-linux-gnu/gconv/NATS-SEFI.so", + "/usr/lib/x86_64-linux-gnu/gconv/PT154.so", + "/usr/lib/x86_64-linux-gnu/gconv/RK1048.so", + "/usr/lib/x86_64-linux-gnu/gconv/SAMI-WS2.so", + "/usr/lib/x86_64-linux-gnu/gconv/SHIFT_JISX0213.so", + "/usr/lib/x86_64-linux-gnu/gconv/SJIS.so", + "/usr/lib/x86_64-linux-gnu/gconv/T.61.so", + "/usr/lib/x86_64-linux-gnu/gconv/TCVN5712-1.so", + "/usr/lib/x86_64-linux-gnu/gconv/TIS-620.so", + "/usr/lib/x86_64-linux-gnu/gconv/TSCII.so", + "/usr/lib/x86_64-linux-gnu/gconv/UHC.so", + "/usr/lib/x86_64-linux-gnu/gconv/UNICODE.so", + "/usr/lib/x86_64-linux-gnu/gconv/UTF-16.so", + "/usr/lib/x86_64-linux-gnu/gconv/UTF-32.so", + "/usr/lib/x86_64-linux-gnu/gconv/UTF-7.so", + "/usr/lib/x86_64-linux-gnu/gconv/VISCII.so", + "/usr/lib/x86_64-linux-gnu/gconv/gconv-modules", + "/usr/lib/x86_64-linux-gnu/gconv/gconv-modules.cache", + "/usr/lib/x86_64-linux-gnu/gconv/gconv-modules.d/gconv-modules-extra.conf", + "/usr/lib/x86_64-linux-gnu/gconv/libCNS.so", + "/usr/lib/x86_64-linux-gnu/gconv/libGB.so", + "/usr/lib/x86_64-linux-gnu/gconv/libISOIR165.so", + "/usr/lib/x86_64-linux-gnu/gconv/libJIS.so", + "/usr/lib/x86_64-linux-gnu/gconv/libJISX0213.so", + "/usr/lib/x86_64-linux-gnu/gconv/libKSC.so", + "/usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2", + "/usr/lib/x86_64-linux-gnu/libBrokenLocale.so.1", + "/usr/lib/x86_64-linux-gnu/libanl.so.1", + "/usr/lib/x86_64-linux-gnu/libc.so.6", + "/usr/lib/x86_64-linux-gnu/libc_malloc_debug.so.0", + "/usr/lib/x86_64-linux-gnu/libdl.so.2", + "/usr/lib/x86_64-linux-gnu/libm.so.6", + "/usr/lib/x86_64-linux-gnu/libmemusage.so", + "/usr/lib/x86_64-linux-gnu/libmvec.so.1", + "/usr/lib/x86_64-linux-gnu/libnsl.so.1", + "/usr/lib/x86_64-linux-gnu/libnss_compat.so.2", + "/usr/lib/x86_64-linux-gnu/libnss_dns.so.2", + "/usr/lib/x86_64-linux-gnu/libnss_files.so.2", + "/usr/lib/x86_64-linux-gnu/libnss_hesiod.so.2", + "/usr/lib/x86_64-linux-gnu/libpcprofile.so", + "/usr/lib/x86_64-linux-gnu/libpthread.so.0", + "/usr/lib/x86_64-linux-gnu/libresolv.so.2", + "/usr/lib/x86_64-linux-gnu/librt.so.1", + "/usr/lib/x86_64-linux-gnu/libthread_db.so.1", + "/usr/lib/x86_64-linux-gnu/libutil.so.1", + "/usr/share/doc/libc6/NEWS.Debian.gz", + "/usr/share/doc/libc6/NEWS.gz", + "/usr/share/doc/libc6/README.Debian.gz", + "/usr/share/doc/libc6/README.hesiod.gz", + "/usr/share/doc/libc6/changelog.Debian.gz", + "/usr/share/doc/libc6/changelog.gz", + "/usr/share/doc/libc6/copyright", + "/usr/share/lintian/overrides/libc6" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libcap-ng0@0.8.5-4+b1", + "Name": "libcap-ng0", + "Identifier": { + "PURL": "pkg:deb/debian/libcap-ng0@0.8.5-4%2Bb1?arch=amd64\u0026distro=debian-13.6", + "UID": "9b7c2d5667513e48" + }, + "Version": "0.8.5", + "Release": "4+b1", + "Arch": "amd64", + "SrcName": "libcap-ng", + "SrcVersion": "0.8.5", + "SrcRelease": "4", + "Licenses": [ + "LGPL-2.1-or-later", + "GPL-2.0-or-later", + "GPL-3.0-only", + "LGPL-2.1-only", + "GPL-2.0-only" + ], + "Maintainer": "Håvard F. Aasen \u003chavard.f.aasen@pfft.no\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libcap-ng.so.0.0.0", + "/usr/lib/x86_64-linux-gnu/libdrop_ambient.so.0.0.0", + "/usr/share/doc/libcap-ng0/changelog.Debian.amd64.gz", + "/usr/share/doc/libcap-ng0/changelog.Debian.gz", + "/usr/share/doc/libcap-ng0/changelog.gz", + "/usr/share/doc/libcap-ng0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libcap2@1:2.75-10+deb13u1+b1", + "Name": "libcap2", + "Identifier": { + "PURL": "pkg:deb/debian/libcap2@2.75-10%2Bdeb13u1%2Bb1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "7cefa0399e4d88d4" + }, + "Version": "2.75", + "Release": "10+deb13u1+b1", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "libcap2", + "SrcVersion": "2.75", + "SrcRelease": "10+deb13u1", + "SrcEpoch": 1, + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-only", + "GPL-2.0-or-later" + ], + "Maintainer": "Christian Kastner \u003cckk@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libcap.so.2.75", + "/usr/lib/x86_64-linux-gnu/libpsx.so.2.75", + "/usr/share/doc/libcap2/changelog.Debian.amd64.gz", + "/usr/share/doc/libcap2/changelog.Debian.gz", + "/usr/share/doc/libcap2/changelog.gz", + "/usr/share/doc/libcap2/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libcrypt1@1:4.4.38-1", + "Name": "libcrypt1", + "Identifier": { + "PURL": "pkg:deb/debian/libcrypt1@4.4.38-1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "afe984ba824f92ac" + }, + "Version": "4.4.38", + "Release": "1", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "libxcrypt", + "SrcVersion": "4.4.38", + "SrcRelease": "1", + "SrcEpoch": 1, + "Maintainer": "Marco d'Itri \u003cmd@linux.it\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libcrypt.so.1.1.0", + "/usr/share/doc/libcrypt1/changelog.Debian.gz", + "/usr/share/doc/libcrypt1/changelog.gz", + "/usr/share/doc/libcrypt1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libdb5.3t64@5.3.28+dfsg2-9", + "Name": "libdb5.3t64", + "Identifier": { + "PURL": "pkg:deb/debian/libdb5.3t64@5.3.28%2Bdfsg2-9?arch=amd64\u0026distro=debian-13.6", + "UID": "2f5f1c2fd77295dc" + }, + "Version": "5.3.28+dfsg2", + "Release": "9", + "Arch": "amd64", + "SrcName": "db5.3", + "SrcVersion": "5.3.28+dfsg2", + "SrcRelease": "9", + "Licenses": [ + "Sleepycat", + "BSD-3-Clause", + "MS-PL", + "GPL-2.0-or-later", + "Artistic-2.0", + "X11", + "MIT-old", + "TCL-like", + "BSD-3-clause-fjord", + "GPL-3.0-only", + "Zlib" + ], + "Maintainer": "Debian QA Group \u003cpackages@qa.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libdb-5.3.so", + "/usr/share/doc/libdb5.3t64/build_signature_amd64.txt", + "/usr/share/doc/libdb5.3t64/changelog.Debian.gz", + "/usr/share/doc/libdb5.3t64/copyright", + "/usr/share/lintian/overrides/libdb5.3t64" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libdebconfclient0@0.280", + "Name": "libdebconfclient0", + "Identifier": { + "PURL": "pkg:deb/debian/libdebconfclient0@0.280?arch=amd64\u0026distro=debian-13.6", + "UID": "fcad452fa456130" + }, + "Version": "0.280", + "Arch": "amd64", + "SrcName": "cdebconf", + "SrcVersion": "0.280", + "Licenses": [ + "BSD-2-Clause", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Debian Install System Team \u003cdebian-boot@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libdebconfclient.so.0.0.0", + "/usr/share/doc/libdebconfclient0/changelog.gz", + "/usr/share/doc/libdebconfclient0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libffi8@3.4.8-2", + "Name": "libffi8", + "Identifier": { + "PURL": "pkg:deb/debian/libffi8@3.4.8-2?arch=amd64\u0026distro=debian-13.6", + "UID": "e57a61a9119138e1" + }, + "Version": "3.4.8", + "Release": "2", + "Arch": "amd64", + "SrcName": "libffi", + "SrcVersion": "3.4.8", + "SrcRelease": "2", + "Licenses": [ + "MIT", + "X11", + "GPL-2.0-or-later", + "GPL-3.0-or-later", + "MPL-1.1", + "LGPL-2.1-or-later", + "public-domain" + ], + "Maintainer": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libffi.so.8.1.4", + "/usr/share/doc/libffi8/changelog.Debian.gz", + "/usr/share/doc/libffi8/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libgcc-s1@14.2.0-19", + "Name": "libgcc-s1", + "Identifier": { + "PURL": "pkg:deb/debian/libgcc-s1@14.2.0-19?arch=amd64\u0026distro=debian-13.6", + "UID": "6ebf985ba3bd76f3" + }, + "Version": "14.2.0", + "Release": "19", + "Arch": "amd64", + "SrcName": "gcc-14", + "SrcVersion": "14.2.0", + "SrcRelease": "19", + "Maintainer": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "gcc-14-base@14.2.0-19", + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libgcc_s.so.1", + "/usr/share/lintian/overrides/libgcc-s1" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libgdbm6t64@1.24-2", + "Name": "libgdbm6t64", + "Identifier": { + "PURL": "pkg:deb/debian/libgdbm6t64@1.24-2?arch=amd64\u0026distro=debian-13.6", + "UID": "a978781f1be6197e" + }, + "Version": "1.24", + "Release": "2", + "Arch": "amd64", + "SrcName": "gdbm", + "SrcVersion": "1.24", + "SrcRelease": "2", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-2.0-or-later", + "GFDL-1.3-no-invariants-or-later", + "GPL-3.0-only", + "GPL-2.0-only" + ], + "Maintainer": "Nicolas Mora \u003cbabelouest@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libgdbm.so.6.0.0", + "/usr/share/doc/libgdbm6t64/changelog.Debian.gz", + "/usr/share/doc/libgdbm6t64/changelog.gz", + "/usr/share/doc/libgdbm6t64/copyright", + "/usr/share/lintian/overrides/libgdbm6t64" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libgmp10@2:6.3.0+dfsg-3", + "Name": "libgmp10", + "Identifier": { + "PURL": "pkg:deb/debian/libgmp10@6.3.0%2Bdfsg-3?arch=amd64\u0026distro=debian-13.6\u0026epoch=2", + "UID": "fec85c1b440262e2" + }, + "Version": "6.3.0+dfsg", + "Release": "3", + "Epoch": 2, + "Arch": "amd64", + "SrcName": "gmp", + "SrcVersion": "6.3.0+dfsg", + "SrcRelease": "3", + "SrcEpoch": 2, + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-3.0-or-later", + "GPL-3.0-or-later", + "GPL-3+ with Bison exception", + "GPL-2.0-only", + "GPL-3.0-only", + "LGPL-3.0-only" + ], + "Maintainer": "Debian Science Maintainers \u003cdebian-science-maintainers@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libgmp.so.10.5.0", + "/usr/share/doc/libgmp10/README.Debian", + "/usr/share/doc/libgmp10/changelog.Debian.gz", + "/usr/share/doc/libgmp10/changelog.gz", + "/usr/share/doc/libgmp10/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libhogweed6t64@3.10.1-1", + "Name": "libhogweed6t64", + "Identifier": { + "PURL": "pkg:deb/debian/libhogweed6t64@3.10.1-1?arch=amd64\u0026distro=debian-13.6", + "UID": "8a048285d77ff6c0" + }, + "Version": "3.10.1", + "Release": "1", + "Arch": "amd64", + "SrcName": "nettle", + "SrcVersion": "3.10.1", + "SrcRelease": "1", + "Licenses": [ + "LGPL-3.0-or-later", + "GPL-2.0-or-later", + "LGPL-2.0-or-later", + "LGPL-2.0-only", + "MIT", + "GPL-3.0-with-autoconf-exception+", + "public-domain", + "GPL-2.0-only", + "GAP" + ], + "Maintainer": "Magnus Holmgren \u003cholmgren@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libgmp10@2:6.3.0+dfsg-3", + "libnettle8t64@3.10.1-1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libhogweed.so.6.10", + "/usr/share/doc/libhogweed6t64/changelog.Debian.gz", + "/usr/share/doc/libhogweed6t64/changelog.gz", + "/usr/share/doc/libhogweed6t64/copyright", + "/usr/share/lintian/overrides/libhogweed6t64" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "liblastlog2-2@2.41.5-0+deb13u1", + "Name": "liblastlog2-2", + "Identifier": { + "PURL": "pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "9b0fe2f2c9e6f842" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libsqlite3-0@3.46.1-7+deb13u1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/liblastlog2.so.2.0.0", + "/usr/share/doc/liblastlog2-2/NEWS.Debian.gz", + "/usr/share/doc/liblastlog2-2/changelog.Debian.gz", + "/usr/share/doc/liblastlog2-2/changelog.gz", + "/usr/share/doc/liblastlog2-2/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "liblz4-1@1.10.0-4", + "Name": "liblz4-1", + "Identifier": { + "PURL": "pkg:deb/debian/liblz4-1@1.10.0-4?arch=amd64\u0026distro=debian-13.6", + "UID": "c31b43410c927de" + }, + "Version": "1.10.0", + "Release": "4", + "Arch": "amd64", + "SrcName": "lz4", + "SrcVersion": "1.10.0", + "SrcRelease": "4", + "Licenses": [ + "GPL-2.0-or-later", + "BSD-2-Clause", + "GPL-2.0-only" + ], + "Maintainer": "Nobuhiro Iwamatsu \u003ciwamatsu@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libxxhash0@0.8.3-2" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/liblz4.so.1.10.0", + "/usr/share/doc/liblz4-1/changelog.Debian.gz", + "/usr/share/doc/liblz4-1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "liblzma5@5.8.1-1+deb13u1", + "Name": "liblzma5", + "Identifier": { + "PURL": "pkg:deb/debian/liblzma5@5.8.1-1%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "7c14fea99fdaf77" + }, + "Version": "5.8.1", + "Release": "1+deb13u1", + "Arch": "amd64", + "SrcName": "xz-utils", + "SrcVersion": "5.8.1", + "SrcRelease": "1+deb13u1", + "Licenses": [ + "0BSD", + "GPL-2.0-or-later", + "LGPL-2.1-or-later", + "FSFULLR", + "GPL-3.0-or-later-WITH-Autoconf-exception-macro", + "none", + "PD", + "permissive-nowarranty", + "FSFUL", + "noderivs", + "PD-debian", + "LGPL-2.1-only", + "GPL-2.0-only", + "GPL-3.0-only" + ], + "Maintainer": "Sebastian Andrzej Siewior \u003csebastian@breakpoint.cc\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/liblzma.so.5.8.1", + "/usr/share/doc/liblzma5/AUTHORS", + "/usr/share/doc/liblzma5/NEWS.gz", + "/usr/share/doc/liblzma5/THANKS.gz", + "/usr/share/doc/liblzma5/changelog.Debian.gz", + "/usr/share/doc/liblzma5/changelog.gz", + "/usr/share/doc/liblzma5/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libmd0@1.1.0-2+b1", + "Name": "libmd0", + "Identifier": { + "PURL": "pkg:deb/debian/libmd0@1.1.0-2%2Bb1?arch=amd64\u0026distro=debian-13.6", + "UID": "f3971c5b48c68b3c" + }, + "Version": "1.1.0", + "Release": "2+b1", + "Arch": "amd64", + "SrcName": "libmd", + "SrcVersion": "1.1.0", + "SrcRelease": "2", + "Licenses": [ + "BSD-3-Clause", + "BSD-3-clause-Aaron-D-Gifford", + "BSD-2-Clause", + "BSD-2-Clause-NetBSD", + "ISC", + "Beerware", + "public-domain-md4", + "public-domain-md5", + "public-domain-sha1" + ], + "Maintainer": "Guillem Jover \u003cguillem@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libmd.so.0.1.0", + "/usr/share/doc/libmd0/changelog.Debian.amd64.gz", + "/usr/share/doc/libmd0/changelog.Debian.gz", + "/usr/share/doc/libmd0/changelog.gz", + "/usr/share/doc/libmd0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libmount1@2.41.5-0+deb13u1", + "Name": "libmount1", + "Identifier": { + "PURL": "pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "b26c2651b95c08c5" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libblkid1@2.41.5-0+deb13u1", + "libc6@2.41-12+deb13u3", + "libselinux1@3.8.1-1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libmount.so.1.1.0", + "/usr/share/doc/libmount1/NEWS.Debian.gz", + "/usr/share/doc/libmount1/changelog.Debian.gz", + "/usr/share/doc/libmount1/changelog.gz", + "/usr/share/doc/libmount1/copyright", + "/usr/share/lintian/overrides/libmount1" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libncursesw6@6.5+20250216-2", + "Name": "libncursesw6", + "Identifier": { + "PURL": "pkg:deb/debian/libncursesw6@6.5%2B20250216-2?arch=amd64\u0026distro=debian-13.6", + "UID": "5efa2a2068c240d8" + }, + "Version": "6.5+20250216", + "Release": "2", + "Arch": "amd64", + "SrcName": "ncurses", + "SrcVersion": "6.5+20250216", + "SrcRelease": "2", + "Maintainer": "Ncurses Maintainers \u003cncurses@packages.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libtinfo6@6.5+20250216-2" + ], + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libformw.so.6.5", + "/usr/lib/x86_64-linux-gnu/libmenuw.so.6.5", + "/usr/lib/x86_64-linux-gnu/libncursesw.so.6.5", + "/usr/lib/x86_64-linux-gnu/libpanelw.so.6.5" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libnettle8t64@3.10.1-1", + "Name": "libnettle8t64", + "Identifier": { + "PURL": "pkg:deb/debian/libnettle8t64@3.10.1-1?arch=amd64\u0026distro=debian-13.6", + "UID": "fd78e15d23b25c1f" + }, + "Version": "3.10.1", + "Release": "1", + "Arch": "amd64", + "SrcName": "nettle", + "SrcVersion": "3.10.1", + "SrcRelease": "1", + "Licenses": [ + "LGPL-3.0-or-later", + "GPL-2.0-or-later", + "LGPL-2.0-or-later", + "LGPL-2.0-only", + "MIT", + "GPL-3.0-with-autoconf-exception+", + "public-domain", + "GPL-2.0-only", + "GAP" + ], + "Maintainer": "Magnus Holmgren \u003cholmgren@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libnettle.so.8.10", + "/usr/share/doc/libnettle8t64/NEWS.gz", + "/usr/share/doc/libnettle8t64/README", + "/usr/share/doc/libnettle8t64/changelog.Debian.gz", + "/usr/share/doc/libnettle8t64/changelog.gz", + "/usr/share/doc/libnettle8t64/copyright", + "/usr/share/lintian/overrides/libnettle8t64" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libpam-modules@1.7.0-5", + "Name": "libpam-modules", + "Identifier": { + "PURL": "pkg:deb/debian/libpam-modules@1.7.0-5?arch=amd64\u0026distro=debian-13.6", + "UID": "274a704398461ef0" + }, + "Version": "1.7.0", + "Release": "5", + "Arch": "amd64", + "SrcName": "pam", + "SrcVersion": "1.7.0", + "SrcRelease": "5", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later", + "GPL-1.0-only", + "GPL-2.0-only", + "GPL-3.0-only", + "GPL-3+ with Bison exception", + "BSD-tcp_wrappers", + "LGPL-2.0-or-later", + "LGPL-2.0-only", + "public-domain", + "Beerware" + ], + "Maintainer": "Sam Hartman \u003chartmans@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/security/pam_access.so", + "/usr/lib/x86_64-linux-gnu/security/pam_canonicalize_user.so", + "/usr/lib/x86_64-linux-gnu/security/pam_debug.so", + "/usr/lib/x86_64-linux-gnu/security/pam_deny.so", + "/usr/lib/x86_64-linux-gnu/security/pam_echo.so", + "/usr/lib/x86_64-linux-gnu/security/pam_env.so", + "/usr/lib/x86_64-linux-gnu/security/pam_exec.so", + "/usr/lib/x86_64-linux-gnu/security/pam_faildelay.so", + "/usr/lib/x86_64-linux-gnu/security/pam_faillock.so", + "/usr/lib/x86_64-linux-gnu/security/pam_filter.so", + "/usr/lib/x86_64-linux-gnu/security/pam_ftp.so", + "/usr/lib/x86_64-linux-gnu/security/pam_group.so", + "/usr/lib/x86_64-linux-gnu/security/pam_issue.so", + "/usr/lib/x86_64-linux-gnu/security/pam_keyinit.so", + "/usr/lib/x86_64-linux-gnu/security/pam_limits.so", + "/usr/lib/x86_64-linux-gnu/security/pam_listfile.so", + "/usr/lib/x86_64-linux-gnu/security/pam_localuser.so", + "/usr/lib/x86_64-linux-gnu/security/pam_loginuid.so", + "/usr/lib/x86_64-linux-gnu/security/pam_mail.so", + "/usr/lib/x86_64-linux-gnu/security/pam_mkhomedir.so", + "/usr/lib/x86_64-linux-gnu/security/pam_motd.so", + "/usr/lib/x86_64-linux-gnu/security/pam_namespace.so", + "/usr/lib/x86_64-linux-gnu/security/pam_nologin.so", + "/usr/lib/x86_64-linux-gnu/security/pam_permit.so", + "/usr/lib/x86_64-linux-gnu/security/pam_pwhistory.so", + "/usr/lib/x86_64-linux-gnu/security/pam_rhosts.so", + "/usr/lib/x86_64-linux-gnu/security/pam_rootok.so", + "/usr/lib/x86_64-linux-gnu/security/pam_securetty.so", + "/usr/lib/x86_64-linux-gnu/security/pam_selinux.so", + "/usr/lib/x86_64-linux-gnu/security/pam_sepermit.so", + "/usr/lib/x86_64-linux-gnu/security/pam_setquota.so", + "/usr/lib/x86_64-linux-gnu/security/pam_shells.so", + "/usr/lib/x86_64-linux-gnu/security/pam_stress.so", + "/usr/lib/x86_64-linux-gnu/security/pam_succeed_if.so", + "/usr/lib/x86_64-linux-gnu/security/pam_time.so", + "/usr/lib/x86_64-linux-gnu/security/pam_timestamp.so", + "/usr/lib/x86_64-linux-gnu/security/pam_tty_audit.so", + "/usr/lib/x86_64-linux-gnu/security/pam_umask.so", + "/usr/lib/x86_64-linux-gnu/security/pam_unix.so", + "/usr/lib/x86_64-linux-gnu/security/pam_userdb.so", + "/usr/lib/x86_64-linux-gnu/security/pam_usertype.so", + "/usr/lib/x86_64-linux-gnu/security/pam_warn.so", + "/usr/lib/x86_64-linux-gnu/security/pam_wheel.so", + "/usr/lib/x86_64-linux-gnu/security/pam_xauth.so", + "/usr/share/doc/libpam-modules/NEWS.Debian.gz", + "/usr/share/doc/libpam-modules/changelog.Debian.gz", + "/usr/share/doc/libpam-modules/changelog.gz", + "/usr/share/doc/libpam-modules/copyright", + "/usr/share/doc/libpam-modules/examples/upperLOWER.c", + "/usr/share/lintian/overrides/libpam-modules", + "/usr/share/pam-configs/mkhomedir" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libpam-modules-bin@1.7.0-5", + "Name": "libpam-modules-bin", + "Identifier": { + "PURL": "pkg:deb/debian/libpam-modules-bin@1.7.0-5?arch=amd64\u0026distro=debian-13.6", + "UID": "c9cbae9084b28bae" + }, + "Version": "1.7.0", + "Release": "5", + "Arch": "amd64", + "SrcName": "pam", + "SrcVersion": "1.7.0", + "SrcRelease": "5", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later", + "GPL-1.0-only", + "GPL-2.0-only", + "GPL-3.0-only", + "GPL-3+ with Bison exception", + "BSD-tcp_wrappers", + "LGPL-2.0-or-later", + "LGPL-2.0-only", + "public-domain", + "Beerware" + ], + "Maintainer": "Sam Hartman \u003chartmans@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libaudit1@1:4.0.2-2+b2", + "libc6@2.41-12+deb13u3", + "libcrypt1@1:4.4.38-1", + "libpam0g@1.7.0-5", + "libselinux1@3.8.1-1", + "libsystemd0@257.13-1~deb13u1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/systemd/system/pam_namespace.service", + "/usr/sbin/faillock", + "/usr/sbin/mkhomedir_helper", + "/usr/sbin/pam_namespace_helper", + "/usr/sbin/pam_timestamp_check", + "/usr/sbin/pwhistory_helper", + "/usr/sbin/unix_chkpwd", + "/usr/sbin/unix_update", + "/usr/share/doc/libpam-modules-bin/changelog.Debian.gz", + "/usr/share/doc/libpam-modules-bin/changelog.gz", + "/usr/share/doc/libpam-modules-bin/copyright", + "/usr/share/lintian/overrides/libpam-modules-bin" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libpam-runtime@1.7.0-5", + "Name": "libpam-runtime", + "Identifier": { + "PURL": "pkg:deb/debian/libpam-runtime@1.7.0-5?arch=all\u0026distro=debian-13.6", + "UID": "1d4f3eaf1c0f9548" + }, + "Version": "1.7.0", + "Release": "5", + "Arch": "all", + "SrcName": "pam", + "SrcVersion": "1.7.0", + "SrcRelease": "5", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later", + "GPL-1.0-only", + "GPL-2.0-only", + "GPL-3.0-only", + "GPL-3+ with Bison exception", + "BSD-tcp_wrappers", + "LGPL-2.0-or-later", + "LGPL-2.0-only", + "public-domain", + "Beerware" + ], + "Maintainer": "Sam Hartman \u003chartmans@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "debconf@1.5.91", + "libpam-modules@1.7.0-5" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/sbin/pam-auth-update", + "/usr/sbin/pam_getenv", + "/usr/share/doc/libpam-runtime/changelog.Debian.gz", + "/usr/share/doc/libpam-runtime/changelog.gz", + "/usr/share/doc/libpam-runtime/copyright", + "/usr/share/lintian/overrides/libpam-runtime", + "/usr/share/locale/af/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/am/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ar/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/as/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/az/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/be/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/bg/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/bn/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/bn_IN/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/bs/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ca/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/cs/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/cy/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/da/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/de/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/de_CH/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/el/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/eo/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/es/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/et/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/eu/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/fa/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/fi/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/fr/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ga/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/gl/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/gu/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/he/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/hi/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/hr/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/hu/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ia/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/id/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/is/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/it/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ja/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ka/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/kk/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/km/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/kn/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ko/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/kw_GB/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ky/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/lt/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/lv/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/mk/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ml/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/mn/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/mr/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ms/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/my/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/nb/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ne/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/nl/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/nn/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/or/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/pa/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/pl/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/pt/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ro/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ru/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/si/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/sk/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/sl/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/sq/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/sr/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/sr@latin/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/sv/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ta/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/te/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/tg/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/th/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/tr/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/uk/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/ur/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/vi/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/yo/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/zh_HK/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/locale/zu/LC_MESSAGES/Linux-PAM.mo", + "/usr/share/man/man5/access.conf.5.gz", + "/usr/share/man/man5/faillock.conf.5.gz", + "/usr/share/man/man5/group.conf.5.gz", + "/usr/share/man/man5/limits.conf.5.gz", + "/usr/share/man/man5/namespace.conf.5.gz", + "/usr/share/man/man5/pam.conf.5.gz", + "/usr/share/man/man5/pam_env.conf.5.gz", + "/usr/share/man/man5/pwhistory.conf.5.gz", + "/usr/share/man/man5/sepermit.conf.5.gz", + "/usr/share/man/man5/time.conf.5.gz", + "/usr/share/man/man7/PAM.7.gz", + "/usr/share/man/man8/faillock.8.gz", + "/usr/share/man/man8/mkhomedir_helper.8.gz", + "/usr/share/man/man8/pam-auth-update.8.gz", + "/usr/share/man/man8/pam_access.8.gz", + "/usr/share/man/man8/pam_canonicalize_user.8.gz", + "/usr/share/man/man8/pam_debug.8.gz", + "/usr/share/man/man8/pam_deny.8.gz", + "/usr/share/man/man8/pam_echo.8.gz", + "/usr/share/man/man8/pam_env.8.gz", + "/usr/share/man/man8/pam_exec.8.gz", + "/usr/share/man/man8/pam_faildelay.8.gz", + "/usr/share/man/man8/pam_faillock.8.gz", + "/usr/share/man/man8/pam_filter.8.gz", + "/usr/share/man/man8/pam_ftp.8.gz", + "/usr/share/man/man8/pam_getenv.8.gz", + "/usr/share/man/man8/pam_group.8.gz", + "/usr/share/man/man8/pam_issue.8.gz", + "/usr/share/man/man8/pam_keyinit.8.gz", + "/usr/share/man/man8/pam_limits.8.gz", + "/usr/share/man/man8/pam_listfile.8.gz", + "/usr/share/man/man8/pam_localuser.8.gz", + "/usr/share/man/man8/pam_loginuid.8.gz", + "/usr/share/man/man8/pam_mail.8.gz", + "/usr/share/man/man8/pam_mkhomedir.8.gz", + "/usr/share/man/man8/pam_motd.8.gz", + "/usr/share/man/man8/pam_namespace.8.gz", + "/usr/share/man/man8/pam_namespace_helper.8.gz", + "/usr/share/man/man8/pam_nologin.8.gz", + "/usr/share/man/man8/pam_permit.8.gz", + "/usr/share/man/man8/pam_pwhistory.8.gz", + "/usr/share/man/man8/pam_rhosts.8.gz", + "/usr/share/man/man8/pam_rootok.8.gz", + "/usr/share/man/man8/pam_securetty.8.gz", + "/usr/share/man/man8/pam_selinux.8.gz", + "/usr/share/man/man8/pam_sepermit.8.gz", + "/usr/share/man/man8/pam_setquota.8.gz", + "/usr/share/man/man8/pam_shells.8.gz", + "/usr/share/man/man8/pam_stress.8.gz", + "/usr/share/man/man8/pam_succeed_if.8.gz", + "/usr/share/man/man8/pam_time.8.gz", + "/usr/share/man/man8/pam_timestamp.8.gz", + "/usr/share/man/man8/pam_timestamp_check.8.gz", + "/usr/share/man/man8/pam_tty_audit.8.gz", + "/usr/share/man/man8/pam_umask.8.gz", + "/usr/share/man/man8/pam_unix.8.gz", + "/usr/share/man/man8/pam_userdb.8.gz", + "/usr/share/man/man8/pam_usertype.8.gz", + "/usr/share/man/man8/pam_warn.8.gz", + "/usr/share/man/man8/pam_wheel.8.gz", + "/usr/share/man/man8/pam_xauth.8.gz", + "/usr/share/man/man8/pwhistory_helper.8.gz", + "/usr/share/man/man8/unix_chkpwd.8.gz", + "/usr/share/man/man8/unix_update.8.gz", + "/usr/share/pam-configs/unix", + "/usr/share/pam/common-account", + "/usr/share/pam/common-account.md5sums", + "/usr/share/pam/common-auth", + "/usr/share/pam/common-auth.md5sums", + "/usr/share/pam/common-password", + "/usr/share/pam/common-password.md5sums", + "/usr/share/pam/common-session", + "/usr/share/pam/common-session-noninteractive", + "/usr/share/pam/common-session-noninteractive.md5sums", + "/usr/share/pam/common-session.md5sums" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libpam0g@1.7.0-5", + "Name": "libpam0g", + "Identifier": { + "PURL": "pkg:deb/debian/libpam0g@1.7.0-5?arch=amd64\u0026distro=debian-13.6", + "UID": "50a3886f7361785c" + }, + "Version": "1.7.0", + "Release": "5", + "Arch": "amd64", + "SrcName": "pam", + "SrcVersion": "1.7.0", + "SrcRelease": "5", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later", + "GPL-1.0-only", + "GPL-2.0-only", + "GPL-3.0-only", + "GPL-3+ with Bison exception", + "BSD-tcp_wrappers", + "LGPL-2.0-or-later", + "LGPL-2.0-only", + "public-domain", + "Beerware" + ], + "Maintainer": "Sam Hartman \u003chartmans@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "debconf@1.5.91", + "libaudit1@1:4.0.2-2+b2", + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libpam.so.0.85.1", + "/usr/lib/x86_64-linux-gnu/libpam_misc.so.0.82.1", + "/usr/lib/x86_64-linux-gnu/libpamc.so.0.82.1", + "/usr/share/doc/libpam0g/Debian-PAM-MiniPolicy.gz", + "/usr/share/doc/libpam0g/README", + "/usr/share/doc/libpam0g/README.Debian", + "/usr/share/doc/libpam0g/TODO.Debian", + "/usr/share/doc/libpam0g/changelog.Debian.gz", + "/usr/share/doc/libpam0g/changelog.gz", + "/usr/share/doc/libpam0g/copyright", + "/usr/share/lintian/overrides/libpam0g" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libpcre2-8-0@10.46-1~deb13u1", + "Name": "libpcre2-8-0", + "Identifier": { + "PURL": "pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "aa7e3a6ab471d889" + }, + "Version": "10.46", + "Release": "1~deb13u1", + "Arch": "amd64", + "SrcName": "pcre2", + "SrcVersion": "10.46", + "SrcRelease": "1~deb13u1", + "Licenses": [ + "BSD-3-clause-Cambridge with BINARY LIBRARY-LIKE PACKAGES exception", + "BSD-3-Clause", + "X11", + "BSD-2-Clause", + "public-domain" + ], + "Maintainer": "Matthew Vernon \u003cmatthew@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libpcre2-8.so.0.14.0", + "/usr/share/doc/libpcre2-8-0/README.Debian", + "/usr/share/doc/libpcre2-8-0/changelog.Debian.gz", + "/usr/share/doc/libpcre2-8-0/changelog.gz", + "/usr/share/doc/libpcre2-8-0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libreadline8t64@8.2-6", + "Name": "libreadline8t64", + "Identifier": { + "PURL": "pkg:deb/debian/libreadline8t64@8.2-6?arch=amd64\u0026distro=debian-13.6", + "UID": "a41a60a40a941961" + }, + "Version": "8.2", + "Release": "6", + "Arch": "amd64", + "SrcName": "readline", + "SrcVersion": "8.2", + "SrcRelease": "6", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-3.0-only", + "GPL-2.0-or-later", + "GPL-2.0-only", + "GFDL-1.3-no-invariants-or-later", + "GFDL-1.3-or-later", + "ISC-no-attribution" + ], + "Maintainer": "Matthias Klose \u003cdoko@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libtinfo6@6.5+20250216-2", + "readline-common@8.2-6" + ], + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libhistory.so.8.2", + "/usr/lib/x86_64-linux-gnu/libreadline.so.8.2", + "/usr/share/doc/libreadline8t64/README.Debian", + "/usr/share/doc/libreadline8t64/USAGE", + "/usr/share/doc/libreadline8t64/changelog.Debian.gz", + "/usr/share/doc/libreadline8t64/changelog.gz", + "/usr/share/doc/libreadline8t64/copyright", + "/usr/share/doc/libreadline8t64/examples/Inputrc", + "/usr/share/doc/libreadline8t64/inputrc.arrows" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libseccomp2@2.6.0-2", + "Name": "libseccomp2", + "Identifier": { + "PURL": "pkg:deb/debian/libseccomp2@2.6.0-2?arch=amd64\u0026distro=debian-13.6", + "UID": "97e0ed663a98e78b" + }, + "Version": "2.6.0", + "Release": "2", + "Arch": "amd64", + "SrcName": "libseccomp", + "SrcVersion": "2.6.0", + "SrcRelease": "2", + "Licenses": [ + "LGPL-2.1-only" + ], + "Maintainer": "Kees Cook \u003ckees@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libseccomp.so.2.6.0", + "/usr/share/doc/libseccomp2/changelog.Debian.gz", + "/usr/share/doc/libseccomp2/changelog.gz", + "/usr/share/doc/libseccomp2/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libselinux1@3.8.1-1", + "Name": "libselinux1", + "Identifier": { + "PURL": "pkg:deb/debian/libselinux1@3.8.1-1?arch=amd64\u0026distro=debian-13.6", + "UID": "f7d3a23ad693e5cb" + }, + "Version": "3.8.1", + "Release": "1", + "Arch": "amd64", + "SrcName": "libselinux", + "SrcVersion": "3.8.1", + "SrcRelease": "1", + "Licenses": [ + "public-domain", + "GPL-2.0-only" + ], + "Maintainer": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libpcre2-8-0@10.46-1~deb13u1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/tmpfiles.d/libselinux1.conf", + "/usr/lib/x86_64-linux-gnu/libselinux.so.1", + "/usr/share/doc/libselinux1/changelog.Debian.gz", + "/usr/share/doc/libselinux1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libsemanage-common@3.8.1-1", + "Name": "libsemanage-common", + "Identifier": { + "PURL": "pkg:deb/debian/libsemanage-common@3.8.1-1?arch=all\u0026distro=debian-13.6", + "UID": "ecc6b54d8bc6318c" + }, + "Version": "3.8.1", + "Release": "1", + "Arch": "all", + "SrcName": "libsemanage", + "SrcVersion": "3.8.1", + "SrcRelease": "1", + "Licenses": [ + "LGPL-2.1-or-later", + "LGPL-2.1-only", + "GPL-2.0-only" + ], + "Maintainer": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/share/doc/libsemanage-common/changelog.Debian.gz", + "/usr/share/doc/libsemanage-common/copyright", + "/usr/share/man/man5/semanage.conf.5.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libsemanage2@3.8.1-1", + "Name": "libsemanage2", + "Identifier": { + "PURL": "pkg:deb/debian/libsemanage2@3.8.1-1?arch=amd64\u0026distro=debian-13.6", + "UID": "5684bd063761ddb3" + }, + "Version": "3.8.1", + "Release": "1", + "Arch": "amd64", + "SrcName": "libsemanage", + "SrcVersion": "3.8.1", + "SrcRelease": "1", + "Licenses": [ + "LGPL-2.1-or-later", + "LGPL-2.1-only", + "GPL-2.0-only" + ], + "Maintainer": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libaudit1@1:4.0.2-2+b2", + "libbz2-1.0@1.0.8-6", + "libc6@2.41-12+deb13u3", + "libselinux1@3.8.1-1", + "libsemanage-common@3.8.1-1", + "libsepol2@3.8.1-1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libsemanage.so.2", + "/usr/share/doc/libsemanage2/changelog.Debian.gz", + "/usr/share/doc/libsemanage2/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libsepol2@3.8.1-1", + "Name": "libsepol2", + "Identifier": { + "PURL": "pkg:deb/debian/libsepol2@3.8.1-1?arch=amd64\u0026distro=debian-13.6", + "UID": "9990a97d658e13ae" + }, + "Version": "3.8.1", + "Release": "1", + "Arch": "amd64", + "SrcName": "libsepol", + "SrcVersion": "3.8.1", + "SrcRelease": "1", + "Licenses": [ + "LGPL-2.1-or-later", + "LGPL-2.1-only", + "Zlib", + "GPL-2.0-only", + "GPL-2.0-or-later" + ], + "Maintainer": "Debian SELinux maintainers \u003cselinux-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libsepol.so.2", + "/usr/share/doc/libsepol2/changelog.Debian.gz", + "/usr/share/doc/libsepol2/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libsmartcols1@2.41.5-0+deb13u1", + "Name": "libsmartcols1", + "Identifier": { + "PURL": "pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "20af24e636963c71" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libsmartcols.so.1.1.0", + "/usr/share/doc/libsmartcols1/NEWS.Debian.gz", + "/usr/share/doc/libsmartcols1/changelog.Debian.gz", + "/usr/share/doc/libsmartcols1/changelog.gz", + "/usr/share/doc/libsmartcols1/copyright", + "/usr/share/lintian/overrides/libsmartcols1" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libsqlite3-0@3.46.1-7+deb13u1", + "Name": "libsqlite3-0", + "Identifier": { + "PURL": "pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "c7da287e696e8198" + }, + "Version": "3.46.1", + "Release": "7+deb13u1", + "Arch": "amd64", + "SrcName": "sqlite3", + "SrcVersion": "3.46.1", + "SrcRelease": "7+deb13u1", + "Licenses": [ + "public-domain", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Laszlo Boszormenyi (GCS) \u003cgcs@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libsqlite3.so.0.8.6", + "/usr/share/doc/libsqlite3-0/README.Debian", + "/usr/share/doc/libsqlite3-0/changelog.Debian.gz", + "/usr/share/doc/libsqlite3-0/changelog.gz", + "/usr/share/doc/libsqlite3-0/changelog.html.gz", + "/usr/share/doc/libsqlite3-0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libssl3t64@3.5.7-1~deb13u2", + "Name": "libssl3t64", + "Identifier": { + "PURL": "pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64\u0026distro=debian-13.6", + "UID": "ef6621757ca9b535" + }, + "Version": "3.5.7", + "Release": "1~deb13u2", + "Arch": "amd64", + "SrcName": "openssl", + "SrcVersion": "3.5.7", + "SrcRelease": "1~deb13u2", + "Licenses": [ + "Apache-2.0", + "Artistic-2.0", + "GPL-1.0-or-later", + "GPL-1.0-only" + ], + "Maintainer": "Debian OpenSSL Team \u003cpkg-openssl-devel@alioth-lists.debian.net\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libzstd1@1.5.7+dfsg-1", + "openssl-provider-legacy@3.5.7-1~deb13u2", + "zlib1g@1:1.3.dfsg+really1.3.1-1+b1" + ], + "Layer": { + "Digest": "sha256:dbd0b7849e6c06b61e1fa6b7ffe053f246ce0075890620e3db64b47bb662433a", + "DiffID": "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/engines-3/afalg.so", + "/usr/lib/x86_64-linux-gnu/engines-3/loader_attic.so", + "/usr/lib/x86_64-linux-gnu/engines-3/padlock.so", + "/usr/lib/x86_64-linux-gnu/libcrypto.so.3", + "/usr/lib/x86_64-linux-gnu/libssl.so.3", + "/usr/share/doc/libssl3t64/NEWS.Debian.gz", + "/usr/share/doc/libssl3t64/changelog.Debian.gz", + "/usr/share/doc/libssl3t64/changelog.gz", + "/usr/share/doc/libssl3t64/copyright", + "/usr/share/lintian/overrides/libssl3t64" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libstdc++6@14.2.0-19", + "Name": "libstdc++6", + "Identifier": { + "PURL": "pkg:deb/debian/libstdc%2B%2B6@14.2.0-19?arch=amd64\u0026distro=debian-13.6", + "UID": "1b384a6346513d7c" + }, + "Version": "14.2.0", + "Release": "19", + "Arch": "amd64", + "SrcName": "gcc-14", + "SrcVersion": "14.2.0", + "SrcRelease": "19", + "Maintainer": "Debian GCC Maintainers \u003cdebian-gcc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "gcc-14-base@14.2.0-19", + "libc6@2.41-12+deb13u3", + "libgcc-s1@14.2.0-19" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libstdc++.so.6.0.33", + "/usr/share/gcc/python/libstdcxx/__init__.py", + "/usr/share/gcc/python/libstdcxx/v6/__init__.py", + "/usr/share/gcc/python/libstdcxx/v6/printers.py", + "/usr/share/gcc/python/libstdcxx/v6/xmethods.py", + "/usr/share/gdb/auto-load/usr/lib/x86_64-linux-gnu/libstdc++.so.6.0.33-gdb.py" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libsystemd0@257.13-1~deb13u1", + "Name": "libsystemd0", + "Identifier": { + "PURL": "pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "a2b4ba47389f858e" + }, + "Version": "257.13", + "Release": "1~deb13u1", + "Arch": "amd64", + "SrcName": "systemd", + "SrcVersion": "257.13", + "SrcRelease": "1~deb13u1", + "Licenses": [ + "LGPL-2.1-or-later", + "CC0-1.0", + "GPL-2 with Linux-syscall-note exception", + "MIT", + "public-domain", + "GPL-2.0-or-later", + "GPL-2.0-only", + "LGPL-2.1-only" + ], + "Maintainer": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libcap2@1:2.75-10+deb13u1+b1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0", + "/usr/share/doc/libsystemd0/NEWS.Debian.gz", + "/usr/share/doc/libsystemd0/changelog.Debian.gz", + "/usr/share/doc/libsystemd0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libtinfo6@6.5+20250216-2", + "Name": "libtinfo6", + "Identifier": { + "PURL": "pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64\u0026distro=debian-13.6", + "UID": "ba2c2b464f07108a" + }, + "Version": "6.5+20250216", + "Release": "2", + "Arch": "amd64", + "SrcName": "ncurses", + "SrcVersion": "6.5+20250216", + "SrcRelease": "2", + "Licenses": [ + "MIT/X11", + "X11", + "BSD-3-Clause" + ], + "Maintainer": "Ncurses Maintainers \u003cncurses@packages.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libtic.so.6.5", + "/usr/lib/x86_64-linux-gnu/libtinfo.so.6.5", + "/usr/share/doc/libtinfo6/changelog.Debian.gz", + "/usr/share/doc/libtinfo6/changelog.gz", + "/usr/share/doc/libtinfo6/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libudev1@257.13-1~deb13u1", + "Name": "libudev1", + "Identifier": { + "PURL": "pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "3b7a2f1a9ab169b" + }, + "Version": "257.13", + "Release": "1~deb13u1", + "Arch": "amd64", + "SrcName": "systemd", + "SrcVersion": "257.13", + "SrcRelease": "1~deb13u1", + "Licenses": [ + "LGPL-2.1-or-later", + "CC0-1.0", + "GPL-2 with Linux-syscall-note exception", + "MIT", + "public-domain", + "GPL-2.0-or-later", + "GPL-2.0-only", + "LGPL-2.1-only" + ], + "Maintainer": "Debian systemd Maintainers \u003cpkg-systemd-maintainers@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libcap2@1:2.75-10+deb13u1+b1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libudev.so.1.7.10", + "/usr/share/doc/libudev1/NEWS.Debian.gz", + "/usr/share/doc/libudev1/changelog.Debian.gz", + "/usr/share/doc/libudev1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libuuid1@2.41.5-0+deb13u1", + "Name": "libuuid1", + "Identifier": { + "PURL": "pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "67cba3b022acab2f" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libuuid.so.1.3.0", + "/usr/share/doc/libuuid1/NEWS.Debian.gz", + "/usr/share/doc/libuuid1/changelog.Debian.gz", + "/usr/share/doc/libuuid1/changelog.gz", + "/usr/share/doc/libuuid1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libxxhash0@0.8.3-2", + "Name": "libxxhash0", + "Identifier": { + "PURL": "pkg:deb/debian/libxxhash0@0.8.3-2?arch=amd64\u0026distro=debian-13.6", + "UID": "d91110b5edcae2d8" + }, + "Version": "0.8.3", + "Release": "2", + "Arch": "amd64", + "SrcName": "xxhash", + "SrcVersion": "0.8.3", + "SrcRelease": "2", + "Licenses": [ + "BSD-2-Clause", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Josue Ortega \u003cjosue@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libxxhash.so.0.8.3", + "/usr/share/doc/libxxhash0/changelog.Debian.gz", + "/usr/share/doc/libxxhash0/changelog.gz", + "/usr/share/doc/libxxhash0/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "libzstd1@1.5.7+dfsg-1", + "Name": "libzstd1", + "Identifier": { + "PURL": "pkg:deb/debian/libzstd1@1.5.7%2Bdfsg-1?arch=amd64\u0026distro=debian-13.6", + "UID": "ca4814a2bfd07696" + }, + "Version": "1.5.7+dfsg", + "Release": "1", + "Arch": "amd64", + "SrcName": "libzstd", + "SrcVersion": "1.5.7+dfsg", + "SrcRelease": "1", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-only", + "Zlib", + "MIT" + ], + "Maintainer": "RPM packaging team \u003cteam+pkg-rpm@tracker.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libzstd.so.1.5.7", + "/usr/share/doc/libzstd1/changelog.Debian.gz", + "/usr/share/doc/libzstd1/changelog.gz", + "/usr/share/doc/libzstd1/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "login@1:4.16.0-2+really2.41.5-0+deb13u1", + "Name": "login", + "Identifier": { + "PURL": "pkg:deb/debian/login@4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "10626ee86f1b653f" + }, + "Version": "4.16.0-2+really2.41.5", + "Release": "0+deb13u1", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libaudit1@1:4.0.2-2+b2", + "libc6@2.41-12+deb13u3", + "libcrypt1@1:4.4.38-1", + "libpam-modules@1.7.0-5", + "libpam-runtime@1.7.0-5", + "libpam0g@1.7.0-5" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/login", + "/usr/bin/newgrp", + "/usr/sbin/nologin", + "/usr/share/bash-completion/completions/newgrp", + "/usr/share/doc/login/NEWS.Debian.gz", + "/usr/share/doc/login/changelog.Debian.gz", + "/usr/share/doc/login/changelog.gz", + "/usr/share/doc/login/copyright", + "/usr/share/lintian/overrides/login", + "/usr/share/man/de/man1/login.1.gz", + "/usr/share/man/de/man1/newgrp.1.gz", + "/usr/share/man/de/man8/nologin.8.gz", + "/usr/share/man/fr/man1/login.1.gz", + "/usr/share/man/man1/login.1.gz", + "/usr/share/man/man1/newgrp.1.gz", + "/usr/share/man/man8/nologin.8.gz", + "/usr/share/man/pl/man1/login.1.gz", + "/usr/share/man/pl/man1/newgrp.1.gz", + "/usr/share/man/pl/man8/nologin.8.gz", + "/usr/share/man/ro/man1/login.1.gz", + "/usr/share/man/ro/man1/newgrp.1.gz", + "/usr/share/man/ro/man8/nologin.8.gz", + "/usr/share/man/sr/man1/login.1.gz", + "/usr/share/man/sr/man1/newgrp.1.gz", + "/usr/share/man/sr/man8/nologin.8.gz", + "/usr/share/man/uk/man1/login.1.gz", + "/usr/share/man/uk/man1/newgrp.1.gz", + "/usr/share/man/uk/man8/nologin.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "login.defs@1:4.17.4-2", + "Name": "login.defs", + "Identifier": { + "PURL": "pkg:deb/debian/login.defs@4.17.4-2?arch=all\u0026distro=debian-13.6\u0026epoch=1", + "UID": "b6a337588c67d5a3" + }, + "Version": "4.17.4", + "Release": "2", + "Epoch": 1, + "Arch": "all", + "SrcName": "shadow", + "SrcVersion": "4.17.4", + "SrcRelease": "2", + "SrcEpoch": 1, + "Licenses": [ + "BSD-3-Clause", + "GPL-1.0-only", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/share/doc/login.defs/NEWS.Debian.gz", + "/usr/share/doc/login.defs/changelog.Debian.gz", + "/usr/share/doc/login.defs/changelog.gz", + "/usr/share/doc/login.defs/copyright", + "/usr/share/man/de/man5/login.defs.5.gz", + "/usr/share/man/fr/man5/login.defs.5.gz", + "/usr/share/man/it/man5/login.defs.5.gz", + "/usr/share/man/ja/man5/login.defs.5.gz", + "/usr/share/man/man5/login.defs.5.gz", + "/usr/share/man/ru/man5/login.defs.5.gz", + "/usr/share/man/uk/man5/login.defs.5.gz", + "/usr/share/man/zh_CN/man5/login.defs.5.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "mawk@1.3.4.20250131-1", + "Name": "mawk", + "Identifier": { + "PURL": "pkg:deb/debian/mawk@1.3.4.20250131-1?arch=amd64\u0026distro=debian-13.6", + "UID": "a4460701c66e182d" + }, + "Version": "1.3.4.20250131", + "Release": "1", + "Arch": "amd64", + "SrcName": "mawk", + "SrcVersion": "1.3.4.20250131", + "SrcRelease": "1", + "Licenses": [ + "GPL-2.0-only", + "X11", + "CC-BY-3.0" + ], + "Maintainer": "Boyuan Yang \u003cbyang@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/mawk", + "/usr/share/doc/mawk/ACKNOWLEDGMENT", + "/usr/share/doc/mawk/README", + "/usr/share/doc/mawk/changelog.Debian.gz", + "/usr/share/doc/mawk/changelog.gz", + "/usr/share/doc/mawk/copyright", + "/usr/share/doc/mawk/examples/ct_length.awk", + "/usr/share/doc/mawk/examples/decl.awk", + "/usr/share/doc/mawk/examples/deps.awk", + "/usr/share/doc/mawk/examples/eatc.awk", + "/usr/share/doc/mawk/examples/gdecl.awk", + "/usr/share/doc/mawk/examples/hcal", + "/usr/share/doc/mawk/examples/hical", + "/usr/share/doc/mawk/examples/nocomment.awk", + "/usr/share/doc/mawk/examples/primes.awk", + "/usr/share/doc/mawk/examples/qsort.awk", + "/usr/share/man/man1/mawk.1.gz", + "/usr/share/man/man7/mawk-arrays.7.gz", + "/usr/share/man/man7/mawk-code.7.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "mount@2.41.5-0+deb13u1", + "Name": "mount", + "Identifier": { + "PURL": "pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "d781ec5616a75c78" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/mount", + "/usr/bin/umount", + "/usr/sbin/losetup", + "/usr/sbin/swapoff", + "/usr/sbin/swapon", + "/usr/share/bash-completion/completions/losetup", + "/usr/share/bash-completion/completions/mount", + "/usr/share/bash-completion/completions/swapoff", + "/usr/share/bash-completion/completions/swapon", + "/usr/share/bash-completion/completions/umount", + "/usr/share/doc/mount/NEWS.Debian.gz", + "/usr/share/doc/mount/changelog.Debian.gz", + "/usr/share/doc/mount/changelog.gz", + "/usr/share/doc/mount/copyright", + "/usr/share/doc/mount/examples/filesystems", + "/usr/share/doc/mount/examples/fstab", + "/usr/share/doc/mount/examples/mount.fstab", + "/usr/share/doc/mount/mount.txt", + "/usr/share/lintian/overrides/mount", + "/usr/share/man/man5/fstab.5.gz", + "/usr/share/man/man8/losetup.8.gz", + "/usr/share/man/man8/mount.8.gz", + "/usr/share/man/man8/swapon.8.gz", + "/usr/share/man/man8/umount.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "ncurses-base@6.5+20250216-2", + "Name": "ncurses-base", + "Identifier": { + "PURL": "pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all\u0026distro=debian-13.6", + "UID": "767a0231348a5cb5" + }, + "Version": "6.5+20250216", + "Release": "2", + "Arch": "all", + "SrcName": "ncurses", + "SrcVersion": "6.5+20250216", + "SrcRelease": "2", + "Licenses": [ + "MIT/X11", + "X11", + "BSD-3-Clause" + ], + "Maintainer": "Ncurses Maintainers \u003cncurses@packages.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/share/doc/ncurses-base/FAQ", + "/usr/share/doc/ncurses-base/TODO.Debian", + "/usr/share/doc/ncurses-base/changelog.Debian.gz", + "/usr/share/doc/ncurses-base/changelog.gz", + "/usr/share/doc/ncurses-base/copyright", + "/usr/share/lintian/overrides/ncurses-base", + "/usr/share/tabset/std", + "/usr/share/tabset/stdcrt", + "/usr/share/tabset/vt100", + "/usr/share/tabset/vt300", + "/usr/share/terminfo/E/Eterm", + "/usr/share/terminfo/a/ansi", + "/usr/share/terminfo/c/cons25", + "/usr/share/terminfo/c/cygwin", + "/usr/share/terminfo/d/dumb", + "/usr/share/terminfo/h/hurd", + "/usr/share/terminfo/l/linux", + "/usr/share/terminfo/m/mach", + "/usr/share/terminfo/m/mach-bold", + "/usr/share/terminfo/m/mach-color", + "/usr/share/terminfo/m/mach-gnu", + "/usr/share/terminfo/m/mach-gnu-color", + "/usr/share/terminfo/p/pcansi", + "/usr/share/terminfo/r/rxvt", + "/usr/share/terminfo/r/rxvt-basic", + "/usr/share/terminfo/r/rxvt-unicode", + "/usr/share/terminfo/r/rxvt-unicode-256color", + "/usr/share/terminfo/s/screen", + "/usr/share/terminfo/s/screen-256color", + "/usr/share/terminfo/s/screen-256color-bce", + "/usr/share/terminfo/s/screen-bce", + "/usr/share/terminfo/s/screen-s", + "/usr/share/terminfo/s/screen-w", + "/usr/share/terminfo/s/screen.xterm-256color", + "/usr/share/terminfo/s/sun", + "/usr/share/terminfo/t/tmux", + "/usr/share/terminfo/t/tmux-256color", + "/usr/share/terminfo/v/vt100", + "/usr/share/terminfo/v/vt102", + "/usr/share/terminfo/v/vt220", + "/usr/share/terminfo/v/vt52", + "/usr/share/terminfo/w/wsvt25", + "/usr/share/terminfo/w/wsvt25m", + "/usr/share/terminfo/x/xterm", + "/usr/share/terminfo/x/xterm-256color", + "/usr/share/terminfo/x/xterm-color", + "/usr/share/terminfo/x/xterm-mono", + "/usr/share/terminfo/x/xterm-r5", + "/usr/share/terminfo/x/xterm-r6", + "/usr/share/terminfo/x/xterm-vt220", + "/usr/share/terminfo/x/xterm-xfree86" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "ncurses-bin@6.5+20250216-2", + "Name": "ncurses-bin", + "Identifier": { + "PURL": "pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64\u0026distro=debian-13.6", + "UID": "5b541563cf6587e5" + }, + "Version": "6.5+20250216", + "Release": "2", + "Arch": "amd64", + "SrcName": "ncurses", + "SrcVersion": "6.5+20250216", + "SrcRelease": "2", + "Licenses": [ + "MIT/X11", + "X11", + "BSD-3-Clause" + ], + "Maintainer": "Ncurses Maintainers \u003cncurses@packages.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/clear", + "/usr/bin/infocmp", + "/usr/bin/tabs", + "/usr/bin/tic", + "/usr/bin/toe", + "/usr/bin/tput", + "/usr/bin/tset", + "/usr/share/doc/ncurses-bin/changelog.Debian.gz", + "/usr/share/doc/ncurses-bin/changelog.gz", + "/usr/share/doc/ncurses-bin/copyright", + "/usr/share/man/man1/captoinfo.1.gz", + "/usr/share/man/man1/clear.1.gz", + "/usr/share/man/man1/infocmp.1.gz", + "/usr/share/man/man1/infotocap.1.gz", + "/usr/share/man/man1/tabs.1.gz", + "/usr/share/man/man1/tic.1.gz", + "/usr/share/man/man1/toe.1.gz", + "/usr/share/man/man1/tput.1.gz", + "/usr/share/man/man1/tset.1.gz", + "/usr/share/man/man5/scr_dump.5.gz", + "/usr/share/man/man5/term.5.gz", + "/usr/share/man/man5/terminfo.5.gz", + "/usr/share/man/man5/user_caps.5.gz", + "/usr/share/man/man7/term.7.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "netbase@6.5", + "Name": "netbase", + "Identifier": { + "PURL": "pkg:deb/debian/netbase@6.5?arch=all\u0026distro=debian-13.6", + "UID": "9929ff265179fc61" + }, + "Version": "6.5", + "Arch": "all", + "SrcName": "netbase", + "SrcVersion": "6.5", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Marco d'Itri \u003cmd@linux.it\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:dbd0b7849e6c06b61e1fa6b7ffe053f246ce0075890620e3db64b47bb662433a", + "DiffID": "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca" + }, + "InstalledFiles": [ + "/usr/share/doc/netbase/changelog.gz", + "/usr/share/doc/netbase/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "openssl@3.5.7-1~deb13u2", + "Name": "openssl", + "Identifier": { + "PURL": "pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64\u0026distro=debian-13.6", + "UID": "4917554de562b1f6" + }, + "Version": "3.5.7", + "Release": "1~deb13u2", + "Arch": "amd64", + "SrcName": "openssl", + "SrcVersion": "3.5.7", + "SrcRelease": "1~deb13u2", + "Licenses": [ + "Apache-2.0", + "Artistic-2.0", + "GPL-1.0-or-later", + "GPL-1.0-only" + ], + "Maintainer": "Debian OpenSSL Team \u003cpkg-openssl-devel@alioth-lists.debian.net\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libssl3t64@3.5.7-1~deb13u2" + ], + "Layer": { + "Digest": "sha256:dbd0b7849e6c06b61e1fa6b7ffe053f246ce0075890620e3db64b47bb662433a", + "DiffID": "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca" + }, + "InstalledFiles": [ + "/usr/bin/c_rehash", + "/usr/bin/openssl", + "/usr/lib/ssl/misc/CA.pl", + "/usr/lib/ssl/misc/tsget.pl", + "/usr/share/doc/openssl/HOWTO/certificates.txt.gz", + "/usr/share/doc/openssl/HOWTO/documenting-functions-and-macros.md.gz", + "/usr/share/doc/openssl/HOWTO/keys.txt.gz", + "/usr/share/doc/openssl/NEWS.md.gz", + "/usr/share/doc/openssl/README-ENGINES.md.gz", + "/usr/share/doc/openssl/README-PROVIDERS.md.gz", + "/usr/share/doc/openssl/README-QUIC.md.gz", + "/usr/share/doc/openssl/README.Debian", + "/usr/share/doc/openssl/README.md.gz", + "/usr/share/doc/openssl/changelog.Debian.gz", + "/usr/share/doc/openssl/changelog.gz", + "/usr/share/doc/openssl/copyright", + "/usr/share/doc/openssl/fingerprints.txt", + "/usr/share/lintian/overrides/openssl", + "/usr/share/man/man1/CA.pl.1ssl.gz", + "/usr/share/man/man1/openssl-asn1parse.1ssl.gz", + "/usr/share/man/man1/openssl-ca.1ssl.gz", + "/usr/share/man/man1/openssl-ciphers.1ssl.gz", + "/usr/share/man/man1/openssl-cmds.1ssl.gz", + "/usr/share/man/man1/openssl-cmp.1ssl.gz", + "/usr/share/man/man1/openssl-cms.1ssl.gz", + "/usr/share/man/man1/openssl-crl.1ssl.gz", + "/usr/share/man/man1/openssl-crl2pkcs7.1ssl.gz", + "/usr/share/man/man1/openssl-dgst.1ssl.gz", + "/usr/share/man/man1/openssl-dhparam.1ssl.gz", + "/usr/share/man/man1/openssl-dsa.1ssl.gz", + "/usr/share/man/man1/openssl-dsaparam.1ssl.gz", + "/usr/share/man/man1/openssl-ec.1ssl.gz", + "/usr/share/man/man1/openssl-ecparam.1ssl.gz", + "/usr/share/man/man1/openssl-enc.1ssl.gz", + "/usr/share/man/man1/openssl-engine.1ssl.gz", + "/usr/share/man/man1/openssl-errstr.1ssl.gz", + "/usr/share/man/man1/openssl-fipsinstall.1ssl.gz", + "/usr/share/man/man1/openssl-format-options.1ssl.gz", + "/usr/share/man/man1/openssl-gendsa.1ssl.gz", + "/usr/share/man/man1/openssl-genpkey.1ssl.gz", + "/usr/share/man/man1/openssl-genrsa.1ssl.gz", + "/usr/share/man/man1/openssl-info.1ssl.gz", + "/usr/share/man/man1/openssl-kdf.1ssl.gz", + "/usr/share/man/man1/openssl-list.1ssl.gz", + "/usr/share/man/man1/openssl-mac.1ssl.gz", + "/usr/share/man/man1/openssl-namedisplay-options.1ssl.gz", + "/usr/share/man/man1/openssl-nseq.1ssl.gz", + "/usr/share/man/man1/openssl-ocsp.1ssl.gz", + "/usr/share/man/man1/openssl-passphrase-options.1ssl.gz", + "/usr/share/man/man1/openssl-passwd.1ssl.gz", + "/usr/share/man/man1/openssl-pkcs12.1ssl.gz", + "/usr/share/man/man1/openssl-pkcs7.1ssl.gz", + "/usr/share/man/man1/openssl-pkcs8.1ssl.gz", + "/usr/share/man/man1/openssl-pkey.1ssl.gz", + "/usr/share/man/man1/openssl-pkeyparam.1ssl.gz", + "/usr/share/man/man1/openssl-pkeyutl.1ssl.gz", + "/usr/share/man/man1/openssl-prime.1ssl.gz", + "/usr/share/man/man1/openssl-rand.1ssl.gz", + "/usr/share/man/man1/openssl-rehash.1ssl.gz", + "/usr/share/man/man1/openssl-req.1ssl.gz", + "/usr/share/man/man1/openssl-rsa.1ssl.gz", + "/usr/share/man/man1/openssl-rsautl.1ssl.gz", + "/usr/share/man/man1/openssl-s_client.1ssl.gz", + "/usr/share/man/man1/openssl-s_server.1ssl.gz", + "/usr/share/man/man1/openssl-s_time.1ssl.gz", + "/usr/share/man/man1/openssl-sess_id.1ssl.gz", + "/usr/share/man/man1/openssl-skeyutl.1ssl.gz", + "/usr/share/man/man1/openssl-smime.1ssl.gz", + "/usr/share/man/man1/openssl-speed.1ssl.gz", + "/usr/share/man/man1/openssl-spkac.1ssl.gz", + "/usr/share/man/man1/openssl-srp.1ssl.gz", + "/usr/share/man/man1/openssl-storeutl.1ssl.gz", + "/usr/share/man/man1/openssl-ts.1ssl.gz", + "/usr/share/man/man1/openssl-verification-options.1ssl.gz", + "/usr/share/man/man1/openssl-verify.1ssl.gz", + "/usr/share/man/man1/openssl-version.1ssl.gz", + "/usr/share/man/man1/openssl-x509.1ssl.gz", + "/usr/share/man/man1/openssl.1ssl.gz", + "/usr/share/man/man1/tsget.1ssl.gz", + "/usr/share/man/man5/config.5ssl.gz", + "/usr/share/man/man5/fips_config.5ssl.gz", + "/usr/share/man/man5/x509v3_config.5ssl.gz", + "/usr/share/man/man7/EVP_ASYM_CIPHER-RSA.7ssl.gz", + "/usr/share/man/man7/EVP_ASYM_CIPHER-SM2.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-AES.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-ARIA.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-BLOWFISH.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-CAMELLIA.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-CAST.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-CHACHA.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-DES.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-IDEA.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-NULL.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-RC2.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-RC4.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-RC5.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-SEED.7ssl.gz", + "/usr/share/man/man7/EVP_CIPHER-SM4.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-ARGON2.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-HKDF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-HMAC-DRBG.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-KB.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-KRB5KDF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-PBKDF1.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-PBKDF2.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-PKCS12KDF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-PVKKDF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-SCRYPT.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-SS.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-SSHKDF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-TLS13_KDF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-TLS1_PRF.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-X942-ASN1.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-X942-CONCAT.7ssl.gz", + "/usr/share/man/man7/EVP_KDF-X963.7ssl.gz", + "/usr/share/man/man7/EVP_KEM-EC.7ssl.gz", + "/usr/share/man/man7/EVP_KEM-ML-KEM.7ssl.gz", + "/usr/share/man/man7/EVP_KEM-RSA.7ssl.gz", + "/usr/share/man/man7/EVP_KEM-X25519.7ssl.gz", + "/usr/share/man/man7/EVP_KEYEXCH-DH.7ssl.gz", + "/usr/share/man/man7/EVP_KEYEXCH-ECDH.7ssl.gz", + "/usr/share/man/man7/EVP_KEYEXCH-X25519.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-BLAKE2.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-CMAC.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-GMAC.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-HMAC.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-KMAC.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-Poly1305.7ssl.gz", + "/usr/share/man/man7/EVP_MAC-Siphash.7ssl.gz", + "/usr/share/man/man7/EVP_MD-BLAKE2.7ssl.gz", + "/usr/share/man/man7/EVP_MD-KECCAK.7ssl.gz", + "/usr/share/man/man7/EVP_MD-MD2.7ssl.gz", + "/usr/share/man/man7/EVP_MD-MD4.7ssl.gz", + "/usr/share/man/man7/EVP_MD-MD5-SHA1.7ssl.gz", + "/usr/share/man/man7/EVP_MD-MD5.7ssl.gz", + "/usr/share/man/man7/EVP_MD-MDC2.7ssl.gz", + "/usr/share/man/man7/EVP_MD-NULL.7ssl.gz", + "/usr/share/man/man7/EVP_MD-RIPEMD160.7ssl.gz", + "/usr/share/man/man7/EVP_MD-SHA1.7ssl.gz", + "/usr/share/man/man7/EVP_MD-SHA2.7ssl.gz", + "/usr/share/man/man7/EVP_MD-SHA3.7ssl.gz", + "/usr/share/man/man7/EVP_MD-SHAKE.7ssl.gz", + "/usr/share/man/man7/EVP_MD-SM3.7ssl.gz", + "/usr/share/man/man7/EVP_MD-WHIRLPOOL.7ssl.gz", + "/usr/share/man/man7/EVP_MD-common.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-DH.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-DSA.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-EC.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-FFC.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-HMAC.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-ML-DSA.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-ML-KEM.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-RSA.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-SLH-DSA.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-SM2.7ssl.gz", + "/usr/share/man/man7/EVP_PKEY-X25519.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-CRNG-TEST.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-CTR-DRBG.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-HASH-DRBG.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-HMAC-DRBG.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-JITTER.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-SEED-SRC.7ssl.gz", + "/usr/share/man/man7/EVP_RAND-TEST-RAND.7ssl.gz", + "/usr/share/man/man7/EVP_RAND.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-DSA.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-ECDSA.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-ED25519.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-HMAC.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-ML-DSA.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-RSA.7ssl.gz", + "/usr/share/man/man7/EVP_SIGNATURE-SLH-DSA.7ssl.gz", + "/usr/share/man/man7/OSSL_PROVIDER-FIPS.7ssl.gz", + "/usr/share/man/man7/OSSL_PROVIDER-base.7ssl.gz", + "/usr/share/man/man7/OSSL_PROVIDER-default.7ssl.gz", + "/usr/share/man/man7/OSSL_PROVIDER-legacy.7ssl.gz", + "/usr/share/man/man7/OSSL_PROVIDER-null.7ssl.gz", + "/usr/share/man/man7/OSSL_STORE-winstore.7ssl.gz", + "/usr/share/man/man7/RAND.7ssl.gz", + "/usr/share/man/man7/RSA-PSS.7ssl.gz", + "/usr/share/man/man7/X25519.7ssl.gz", + "/usr/share/man/man7/bio.7ssl.gz", + "/usr/share/man/man7/ct.7ssl.gz", + "/usr/share/man/man7/des_modes.7ssl.gz", + "/usr/share/man/man7/evp.7ssl.gz", + "/usr/share/man/man7/fips_module.7ssl.gz", + "/usr/share/man/man7/life_cycle-cipher.7ssl.gz", + "/usr/share/man/man7/life_cycle-digest.7ssl.gz", + "/usr/share/man/man7/life_cycle-kdf.7ssl.gz", + "/usr/share/man/man7/life_cycle-mac.7ssl.gz", + "/usr/share/man/man7/life_cycle-pkey.7ssl.gz", + "/usr/share/man/man7/life_cycle-rand.7ssl.gz", + "/usr/share/man/man7/openssl-core.h.7ssl.gz", + "/usr/share/man/man7/openssl-core_dispatch.h.7ssl.gz", + "/usr/share/man/man7/openssl-core_names.h.7ssl.gz", + "/usr/share/man/man7/openssl-env.7ssl.gz", + "/usr/share/man/man7/openssl-glossary.7ssl.gz", + "/usr/share/man/man7/openssl-qlog.7ssl.gz", + "/usr/share/man/man7/openssl-quic-concurrency.7ssl.gz", + "/usr/share/man/man7/openssl-quic.7ssl.gz", + "/usr/share/man/man7/openssl-threads.7ssl.gz", + "/usr/share/man/man7/openssl_user_macros.7ssl.gz", + "/usr/share/man/man7/ossl-guide-introduction.7ssl.gz", + "/usr/share/man/man7/ossl-guide-libcrypto-introduction.7ssl.gz", + "/usr/share/man/man7/ossl-guide-libraries-introduction.7ssl.gz", + "/usr/share/man/man7/ossl-guide-libssl-introduction.7ssl.gz", + "/usr/share/man/man7/ossl-guide-migration.7ssl.gz", + "/usr/share/man/man7/ossl-guide-quic-client-block.7ssl.gz", + "/usr/share/man/man7/ossl-guide-quic-client-non-block.7ssl.gz", + "/usr/share/man/man7/ossl-guide-quic-introduction.7ssl.gz", + "/usr/share/man/man7/ossl-guide-quic-multi-stream.7ssl.gz", + "/usr/share/man/man7/ossl-guide-quic-server-block.7ssl.gz", + "/usr/share/man/man7/ossl-guide-quic-server-non-block.7ssl.gz", + "/usr/share/man/man7/ossl-guide-tls-client-block.7ssl.gz", + "/usr/share/man/man7/ossl-guide-tls-client-non-block.7ssl.gz", + "/usr/share/man/man7/ossl-guide-tls-introduction.7ssl.gz", + "/usr/share/man/man7/ossl-guide-tls-server-block.7ssl.gz", + "/usr/share/man/man7/ossl_store-file.7ssl.gz", + "/usr/share/man/man7/ossl_store.7ssl.gz", + "/usr/share/man/man7/passphrase-encoding.7ssl.gz", + "/usr/share/man/man7/property.7ssl.gz", + "/usr/share/man/man7/provider-asym_cipher.7ssl.gz", + "/usr/share/man/man7/provider-base.7ssl.gz", + "/usr/share/man/man7/provider-cipher.7ssl.gz", + "/usr/share/man/man7/provider-decoder.7ssl.gz", + "/usr/share/man/man7/provider-digest.7ssl.gz", + "/usr/share/man/man7/provider-encoder.7ssl.gz", + "/usr/share/man/man7/provider-kdf.7ssl.gz", + "/usr/share/man/man7/provider-kem.7ssl.gz", + "/usr/share/man/man7/provider-keyexch.7ssl.gz", + "/usr/share/man/man7/provider-keymgmt.7ssl.gz", + "/usr/share/man/man7/provider-mac.7ssl.gz", + "/usr/share/man/man7/provider-object.7ssl.gz", + "/usr/share/man/man7/provider-rand.7ssl.gz", + "/usr/share/man/man7/provider-signature.7ssl.gz", + "/usr/share/man/man7/provider-skeymgmt.7ssl.gz", + "/usr/share/man/man7/provider-storemgmt.7ssl.gz", + "/usr/share/man/man7/provider.7ssl.gz", + "/usr/share/man/man7/proxy-certificates.7ssl.gz", + "/usr/share/man/man7/x509.7ssl.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "openssl-provider-legacy@3.5.7-1~deb13u2", + "Name": "openssl-provider-legacy", + "Identifier": { + "PURL": "pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64\u0026distro=debian-13.6", + "UID": "9d3dbcbe1f7438f6" + }, + "Version": "3.5.7", + "Release": "1~deb13u2", + "Arch": "amd64", + "SrcName": "openssl", + "SrcVersion": "3.5.7", + "SrcRelease": "1~deb13u2", + "Licenses": [ + "Apache-2.0", + "Artistic-2.0", + "GPL-1.0-or-later", + "GPL-1.0-only" + ], + "Maintainer": "Debian OpenSSL Team \u003cpkg-openssl-devel@alioth-lists.debian.net\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libssl3t64@3.5.7-1~deb13u2" + ], + "Layer": { + "Digest": "sha256:dbd0b7849e6c06b61e1fa6b7ffe053f246ce0075890620e3db64b47bb662433a", + "DiffID": "sha256:3070bb8623db07ca38569112f9b296043371a00bfb3ee4d9f8f63ddfd2f2efca" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/ossl-modules/legacy.so", + "/usr/share/doc/openssl-provider-legacy/changelog.Debian.gz", + "/usr/share/doc/openssl-provider-legacy/changelog.gz", + "/usr/share/doc/openssl-provider-legacy/copyright" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "passwd@1:4.17.4-2", + "Name": "passwd", + "Identifier": { + "PURL": "pkg:deb/debian/passwd@4.17.4-2?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "d93f813ae3092e32" + }, + "Version": "4.17.4", + "Release": "2", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "shadow", + "SrcVersion": "4.17.4", + "SrcRelease": "2", + "SrcEpoch": 1, + "Licenses": [ + "BSD-3-Clause", + "GPL-1.0-only", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Shadow package maintainers \u003cpkg-shadow-devel@lists.alioth.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "base-passwd@3.6.7", + "libacl1@2.3.2-2+b1", + "libattr1@1:2.5.2-3", + "libaudit1@1:4.0.2-2+b2", + "libbsd0@0.12.2-2", + "libc6@2.41-12+deb13u3", + "libcrypt1@1:4.4.38-1", + "libpam-modules@1.7.0-5", + "libpam0g@1.7.0-5", + "libselinux1@3.8.1-1", + "libsemanage2@3.8.1-1", + "login.defs@1:4.17.4-2" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/chage", + "/usr/bin/chfn", + "/usr/bin/chsh", + "/usr/bin/expiry", + "/usr/bin/gpasswd", + "/usr/bin/passwd", + "/usr/lib/tmpfiles.d/passwd.conf", + "/usr/sbin/chgpasswd", + "/usr/sbin/chpasswd", + "/usr/sbin/groupadd", + "/usr/sbin/groupdel", + "/usr/sbin/groupmod", + "/usr/sbin/grpck", + "/usr/sbin/grpconv", + "/usr/sbin/grpunconv", + "/usr/sbin/newusers", + "/usr/sbin/pwck", + "/usr/sbin/pwconv", + "/usr/sbin/pwunconv", + "/usr/sbin/shadowconfig", + "/usr/sbin/useradd", + "/usr/sbin/userdel", + "/usr/sbin/usermod", + "/usr/sbin/vipw", + "/usr/share/doc/passwd/NEWS.Debian.gz", + "/usr/share/doc/passwd/README.Debian", + "/usr/share/doc/passwd/TODO.Debian", + "/usr/share/doc/passwd/changelog.Debian.gz", + "/usr/share/doc/passwd/changelog.gz", + "/usr/share/doc/passwd/copyright", + "/usr/share/doc/passwd/examples/passwd.expire.cron", + "/usr/share/lintian/overrides/passwd", + "/usr/share/locale/bs/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ca/LC_MESSAGES/shadow.mo", + "/usr/share/locale/cs/LC_MESSAGES/shadow.mo", + "/usr/share/locale/da/LC_MESSAGES/shadow.mo", + "/usr/share/locale/de/LC_MESSAGES/shadow.mo", + "/usr/share/locale/dz/LC_MESSAGES/shadow.mo", + "/usr/share/locale/el/LC_MESSAGES/shadow.mo", + "/usr/share/locale/es/LC_MESSAGES/shadow.mo", + "/usr/share/locale/eu/LC_MESSAGES/shadow.mo", + "/usr/share/locale/fi/LC_MESSAGES/shadow.mo", + "/usr/share/locale/fr/LC_MESSAGES/shadow.mo", + "/usr/share/locale/gl/LC_MESSAGES/shadow.mo", + "/usr/share/locale/he/LC_MESSAGES/shadow.mo", + "/usr/share/locale/hu/LC_MESSAGES/shadow.mo", + "/usr/share/locale/id/LC_MESSAGES/shadow.mo", + "/usr/share/locale/it/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ja/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ka/LC_MESSAGES/shadow.mo", + "/usr/share/locale/kk/LC_MESSAGES/shadow.mo", + "/usr/share/locale/km/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ko/LC_MESSAGES/shadow.mo", + "/usr/share/locale/nb/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ne/LC_MESSAGES/shadow.mo", + "/usr/share/locale/nl/LC_MESSAGES/shadow.mo", + "/usr/share/locale/nn/LC_MESSAGES/shadow.mo", + "/usr/share/locale/pl/LC_MESSAGES/shadow.mo", + "/usr/share/locale/pt/LC_MESSAGES/shadow.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ro/LC_MESSAGES/shadow.mo", + "/usr/share/locale/ru/LC_MESSAGES/shadow.mo", + "/usr/share/locale/sk/LC_MESSAGES/shadow.mo", + "/usr/share/locale/sq/LC_MESSAGES/shadow.mo", + "/usr/share/locale/sv/LC_MESSAGES/shadow.mo", + "/usr/share/locale/tl/LC_MESSAGES/shadow.mo", + "/usr/share/locale/tr/LC_MESSAGES/shadow.mo", + "/usr/share/locale/uk/LC_MESSAGES/shadow.mo", + "/usr/share/locale/vi/LC_MESSAGES/shadow.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/shadow.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/shadow.mo", + "/usr/share/man/cs/man1/expiry.1.gz", + "/usr/share/man/cs/man1/gpasswd.1.gz", + "/usr/share/man/cs/man5/gshadow.5.gz", + "/usr/share/man/cs/man5/passwd.5.gz", + "/usr/share/man/cs/man5/shadow.5.gz", + "/usr/share/man/cs/man8/groupadd.8.gz", + "/usr/share/man/cs/man8/groupdel.8.gz", + "/usr/share/man/cs/man8/groupmod.8.gz", + "/usr/share/man/cs/man8/grpck.8.gz", + "/usr/share/man/cs/man8/vipw.8.gz", + "/usr/share/man/da/man1/chfn.1.gz", + "/usr/share/man/da/man5/gshadow.5.gz", + "/usr/share/man/da/man8/groupdel.8.gz", + "/usr/share/man/da/man8/vipw.8.gz", + "/usr/share/man/de/man1/chage.1.gz", + "/usr/share/man/de/man1/chfn.1.gz", + "/usr/share/man/de/man1/chsh.1.gz", + "/usr/share/man/de/man1/expiry.1.gz", + "/usr/share/man/de/man1/gpasswd.1.gz", + "/usr/share/man/de/man1/passwd.1.gz", + "/usr/share/man/de/man5/gshadow.5.gz", + "/usr/share/man/de/man5/passwd.5.gz", + "/usr/share/man/de/man5/shadow.5.gz", + "/usr/share/man/de/man8/chgpasswd.8.gz", + "/usr/share/man/de/man8/chpasswd.8.gz", + "/usr/share/man/de/man8/groupadd.8.gz", + "/usr/share/man/de/man8/groupdel.8.gz", + "/usr/share/man/de/man8/groupmod.8.gz", + "/usr/share/man/de/man8/grpck.8.gz", + "/usr/share/man/de/man8/newusers.8.gz", + "/usr/share/man/de/man8/pwck.8.gz", + "/usr/share/man/de/man8/pwconv.8.gz", + "/usr/share/man/de/man8/useradd.8.gz", + "/usr/share/man/de/man8/userdel.8.gz", + "/usr/share/man/de/man8/usermod.8.gz", + "/usr/share/man/de/man8/vipw.8.gz", + "/usr/share/man/fi/man1/chfn.1.gz", + "/usr/share/man/fi/man1/chsh.1.gz", + "/usr/share/man/fr/man1/chage.1.gz", + "/usr/share/man/fr/man1/chfn.1.gz", + "/usr/share/man/fr/man1/chsh.1.gz", + "/usr/share/man/fr/man1/expiry.1.gz", + "/usr/share/man/fr/man1/gpasswd.1.gz", + "/usr/share/man/fr/man1/passwd.1.gz", + "/usr/share/man/fr/man5/gshadow.5.gz", + "/usr/share/man/fr/man5/passwd.5.gz", + "/usr/share/man/fr/man5/shadow.5.gz", + "/usr/share/man/fr/man5/subgid.5.gz", + "/usr/share/man/fr/man5/subuid.5.gz", + "/usr/share/man/fr/man8/chgpasswd.8.gz", + "/usr/share/man/fr/man8/chpasswd.8.gz", + "/usr/share/man/fr/man8/groupadd.8.gz", + "/usr/share/man/fr/man8/groupdel.8.gz", + "/usr/share/man/fr/man8/groupmod.8.gz", + "/usr/share/man/fr/man8/grpck.8.gz", + "/usr/share/man/fr/man8/newusers.8.gz", + "/usr/share/man/fr/man8/pwck.8.gz", + "/usr/share/man/fr/man8/pwconv.8.gz", + "/usr/share/man/fr/man8/useradd.8.gz", + "/usr/share/man/fr/man8/userdel.8.gz", + "/usr/share/man/fr/man8/usermod.8.gz", + "/usr/share/man/fr/man8/vipw.8.gz", + "/usr/share/man/hu/man1/chsh.1.gz", + "/usr/share/man/hu/man1/gpasswd.1.gz", + "/usr/share/man/hu/man1/passwd.1.gz", + "/usr/share/man/hu/man5/passwd.5.gz", + "/usr/share/man/id/man1/chsh.1.gz", + "/usr/share/man/id/man8/useradd.8.gz", + "/usr/share/man/it/man1/chage.1.gz", + "/usr/share/man/it/man1/chfn.1.gz", + "/usr/share/man/it/man1/chsh.1.gz", + "/usr/share/man/it/man1/expiry.1.gz", + "/usr/share/man/it/man1/gpasswd.1.gz", + "/usr/share/man/it/man1/passwd.1.gz", + "/usr/share/man/it/man5/gshadow.5.gz", + "/usr/share/man/it/man5/passwd.5.gz", + "/usr/share/man/it/man5/shadow.5.gz", + "/usr/share/man/it/man8/chgpasswd.8.gz", + "/usr/share/man/it/man8/chpasswd.8.gz", + "/usr/share/man/it/man8/groupadd.8.gz", + "/usr/share/man/it/man8/groupdel.8.gz", + "/usr/share/man/it/man8/groupmod.8.gz", + "/usr/share/man/it/man8/grpck.8.gz", + "/usr/share/man/it/man8/newusers.8.gz", + "/usr/share/man/it/man8/pwck.8.gz", + "/usr/share/man/it/man8/pwconv.8.gz", + "/usr/share/man/it/man8/useradd.8.gz", + "/usr/share/man/it/man8/userdel.8.gz", + "/usr/share/man/it/man8/usermod.8.gz", + "/usr/share/man/it/man8/vipw.8.gz", + "/usr/share/man/ja/man1/chage.1.gz", + "/usr/share/man/ja/man1/chfn.1.gz", + "/usr/share/man/ja/man1/chsh.1.gz", + "/usr/share/man/ja/man1/expiry.1.gz", + "/usr/share/man/ja/man1/gpasswd.1.gz", + "/usr/share/man/ja/man1/passwd.1.gz", + "/usr/share/man/ja/man5/passwd.5.gz", + "/usr/share/man/ja/man5/shadow.5.gz", + "/usr/share/man/ja/man8/chpasswd.8.gz", + "/usr/share/man/ja/man8/groupadd.8.gz", + "/usr/share/man/ja/man8/groupdel.8.gz", + "/usr/share/man/ja/man8/groupmod.8.gz", + "/usr/share/man/ja/man8/grpck.8.gz", + "/usr/share/man/ja/man8/newusers.8.gz", + "/usr/share/man/ja/man8/pwck.8.gz", + "/usr/share/man/ja/man8/pwconv.8.gz", + "/usr/share/man/ja/man8/useradd.8.gz", + "/usr/share/man/ja/man8/userdel.8.gz", + "/usr/share/man/ja/man8/usermod.8.gz", + "/usr/share/man/ja/man8/vipw.8.gz", + "/usr/share/man/ko/man1/chfn.1.gz", + "/usr/share/man/ko/man1/chsh.1.gz", + "/usr/share/man/ko/man5/passwd.5.gz", + "/usr/share/man/ko/man8/vipw.8.gz", + "/usr/share/man/man1/chage.1.gz", + "/usr/share/man/man1/chfn.1.gz", + "/usr/share/man/man1/chsh.1.gz", + "/usr/share/man/man1/expiry.1.gz", + "/usr/share/man/man1/gpasswd.1.gz", + "/usr/share/man/man1/passwd.1.gz", + "/usr/share/man/man5/gshadow.5.gz", + "/usr/share/man/man5/passwd.5.gz", + "/usr/share/man/man5/shadow.5.gz", + "/usr/share/man/man5/subgid.5.gz", + "/usr/share/man/man5/subuid.5.gz", + "/usr/share/man/man8/chgpasswd.8.gz", + "/usr/share/man/man8/chpasswd.8.gz", + "/usr/share/man/man8/groupadd.8.gz", + "/usr/share/man/man8/groupdel.8.gz", + "/usr/share/man/man8/groupmod.8.gz", + "/usr/share/man/man8/grpck.8.gz", + "/usr/share/man/man8/newusers.8.gz", + "/usr/share/man/man8/pwck.8.gz", + "/usr/share/man/man8/pwconv.8.gz", + "/usr/share/man/man8/shadowconfig.8.gz", + "/usr/share/man/man8/useradd.8.gz", + "/usr/share/man/man8/userdel.8.gz", + "/usr/share/man/man8/usermod.8.gz", + "/usr/share/man/man8/vipw.8.gz", + "/usr/share/man/pl/man1/chage.1.gz", + "/usr/share/man/pl/man1/chsh.1.gz", + "/usr/share/man/pl/man1/expiry.1.gz", + "/usr/share/man/pl/man8/groupadd.8.gz", + "/usr/share/man/pl/man8/groupdel.8.gz", + "/usr/share/man/pl/man8/groupmod.8.gz", + "/usr/share/man/pl/man8/grpck.8.gz", + "/usr/share/man/pl/man8/userdel.8.gz", + "/usr/share/man/pl/man8/usermod.8.gz", + "/usr/share/man/pl/man8/vipw.8.gz", + "/usr/share/man/pt_BR/man1/gpasswd.1.gz", + "/usr/share/man/pt_BR/man5/passwd.5.gz", + "/usr/share/man/pt_BR/man5/shadow.5.gz", + "/usr/share/man/pt_BR/man8/groupadd.8.gz", + "/usr/share/man/pt_BR/man8/groupdel.8.gz", + "/usr/share/man/pt_BR/man8/groupmod.8.gz", + "/usr/share/man/ru/man1/chage.1.gz", + "/usr/share/man/ru/man1/chfn.1.gz", + "/usr/share/man/ru/man1/chsh.1.gz", + "/usr/share/man/ru/man1/expiry.1.gz", + "/usr/share/man/ru/man1/gpasswd.1.gz", + "/usr/share/man/ru/man1/passwd.1.gz", + "/usr/share/man/ru/man5/gshadow.5.gz", + "/usr/share/man/ru/man5/passwd.5.gz", + "/usr/share/man/ru/man5/shadow.5.gz", + "/usr/share/man/ru/man8/chgpasswd.8.gz", + "/usr/share/man/ru/man8/chpasswd.8.gz", + "/usr/share/man/ru/man8/groupadd.8.gz", + "/usr/share/man/ru/man8/groupdel.8.gz", + "/usr/share/man/ru/man8/groupmod.8.gz", + "/usr/share/man/ru/man8/grpck.8.gz", + "/usr/share/man/ru/man8/newusers.8.gz", + "/usr/share/man/ru/man8/pwck.8.gz", + "/usr/share/man/ru/man8/pwconv.8.gz", + "/usr/share/man/ru/man8/useradd.8.gz", + "/usr/share/man/ru/man8/userdel.8.gz", + "/usr/share/man/ru/man8/usermod.8.gz", + "/usr/share/man/ru/man8/vipw.8.gz", + "/usr/share/man/sv/man1/chage.1.gz", + "/usr/share/man/sv/man1/chsh.1.gz", + "/usr/share/man/sv/man1/expiry.1.gz", + "/usr/share/man/sv/man1/passwd.1.gz", + "/usr/share/man/sv/man5/gshadow.5.gz", + "/usr/share/man/sv/man5/passwd.5.gz", + "/usr/share/man/sv/man8/groupadd.8.gz", + "/usr/share/man/sv/man8/groupdel.8.gz", + "/usr/share/man/sv/man8/groupmod.8.gz", + "/usr/share/man/sv/man8/grpck.8.gz", + "/usr/share/man/sv/man8/pwck.8.gz", + "/usr/share/man/sv/man8/userdel.8.gz", + "/usr/share/man/sv/man8/vipw.8.gz", + "/usr/share/man/tr/man1/chage.1.gz", + "/usr/share/man/tr/man1/chfn.1.gz", + "/usr/share/man/tr/man1/passwd.1.gz", + "/usr/share/man/tr/man5/passwd.5.gz", + "/usr/share/man/tr/man5/shadow.5.gz", + "/usr/share/man/tr/man8/groupadd.8.gz", + "/usr/share/man/tr/man8/groupdel.8.gz", + "/usr/share/man/tr/man8/groupmod.8.gz", + "/usr/share/man/tr/man8/useradd.8.gz", + "/usr/share/man/tr/man8/userdel.8.gz", + "/usr/share/man/tr/man8/usermod.8.gz", + "/usr/share/man/uk/man1/chage.1.gz", + "/usr/share/man/uk/man1/chfn.1.gz", + "/usr/share/man/uk/man1/chsh.1.gz", + "/usr/share/man/uk/man1/expiry.1.gz", + "/usr/share/man/uk/man1/gpasswd.1.gz", + "/usr/share/man/uk/man1/passwd.1.gz", + "/usr/share/man/uk/man5/gshadow.5.gz", + "/usr/share/man/uk/man5/passwd.5.gz", + "/usr/share/man/uk/man5/shadow.5.gz", + "/usr/share/man/uk/man8/chgpasswd.8.gz", + "/usr/share/man/uk/man8/chpasswd.8.gz", + "/usr/share/man/uk/man8/groupadd.8.gz", + "/usr/share/man/uk/man8/groupdel.8.gz", + "/usr/share/man/uk/man8/groupmod.8.gz", + "/usr/share/man/uk/man8/grpck.8.gz", + "/usr/share/man/uk/man8/newusers.8.gz", + "/usr/share/man/uk/man8/pwck.8.gz", + "/usr/share/man/uk/man8/pwconv.8.gz", + "/usr/share/man/uk/man8/useradd.8.gz", + "/usr/share/man/uk/man8/userdel.8.gz", + "/usr/share/man/uk/man8/usermod.8.gz", + "/usr/share/man/uk/man8/vipw.8.gz", + "/usr/share/man/zh_CN/man1/chage.1.gz", + "/usr/share/man/zh_CN/man1/chfn.1.gz", + "/usr/share/man/zh_CN/man1/chsh.1.gz", + "/usr/share/man/zh_CN/man1/expiry.1.gz", + "/usr/share/man/zh_CN/man1/gpasswd.1.gz", + "/usr/share/man/zh_CN/man1/passwd.1.gz", + "/usr/share/man/zh_CN/man5/gshadow.5.gz", + "/usr/share/man/zh_CN/man5/passwd.5.gz", + "/usr/share/man/zh_CN/man5/shadow.5.gz", + "/usr/share/man/zh_CN/man8/chgpasswd.8.gz", + "/usr/share/man/zh_CN/man8/chpasswd.8.gz", + "/usr/share/man/zh_CN/man8/groupadd.8.gz", + "/usr/share/man/zh_CN/man8/groupdel.8.gz", + "/usr/share/man/zh_CN/man8/groupmod.8.gz", + "/usr/share/man/zh_CN/man8/grpck.8.gz", + "/usr/share/man/zh_CN/man8/newusers.8.gz", + "/usr/share/man/zh_CN/man8/pwck.8.gz", + "/usr/share/man/zh_CN/man8/pwconv.8.gz", + "/usr/share/man/zh_CN/man8/useradd.8.gz", + "/usr/share/man/zh_CN/man8/userdel.8.gz", + "/usr/share/man/zh_CN/man8/usermod.8.gz", + "/usr/share/man/zh_CN/man8/vipw.8.gz", + "/usr/share/man/zh_TW/man1/chfn.1.gz", + "/usr/share/man/zh_TW/man1/chsh.1.gz", + "/usr/share/man/zh_TW/man5/passwd.5.gz", + "/usr/share/man/zh_TW/man8/chpasswd.8.gz", + "/usr/share/man/zh_TW/man8/groupadd.8.gz", + "/usr/share/man/zh_TW/man8/groupdel.8.gz", + "/usr/share/man/zh_TW/man8/groupmod.8.gz", + "/usr/share/man/zh_TW/man8/useradd.8.gz", + "/usr/share/man/zh_TW/man8/userdel.8.gz", + "/usr/share/man/zh_TW/man8/usermod.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "perl-base@5.40.1-6", + "Name": "perl-base", + "Identifier": { + "PURL": "pkg:deb/debian/perl-base@5.40.1-6?arch=amd64\u0026distro=debian-13.6", + "UID": "546ba1bdcd66d61" + }, + "Version": "5.40.1", + "Release": "6", + "Arch": "amd64", + "SrcName": "perl", + "SrcVersion": "5.40.1", + "SrcRelease": "6", + "Licenses": [ + "GPL-1.0-or-later", + "Artistic-2.0", + "MIT", + "REGCOMP", + "GPL-2.0-with-bison-exception+", + "Unicode", + "BZIP", + "Zlib", + "GPL-2.0-or-later", + "FSFAP", + "BSD-3-clause-with-weird-numbering", + "CC0-1.0", + "TEXT-TABS", + "BSD-4-clause-POWERDOG", + "BSD-3-clause-GENERIC", + "BSD-3-Clause", + "SDBM-PUBLIC-DOMAIN", + "DONT-CHANGE-THE-GPL", + "Artistic-dist", + "LGPL-2.1-only", + "GPL-1.0-only", + "GPL-2.0-only", + "Artistic-2" + ], + "Maintainer": "Niko Tyni \u003cntyni@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/perl", + "/usr/bin/perl5.40.1", + "/usr/lib/x86_64-linux-gnu/perl-base/AutoLoader.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Carp.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Carp/Heavy.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Config.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Config_git.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/Config_heavy.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/Cwd.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/DynaLoader.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Errno.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Exporter.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Exporter/Heavy.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Fcntl.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/File/Basename.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/File/Glob.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/File/Path.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/File/Spec.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/File/Spec/Unix.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/File/Temp.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/FileHandle.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Getopt/Long.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Getopt/Long/Parser.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Hash/Util.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/File.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Handle.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Pipe.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Seekable.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Select.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Socket.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Socket/INET.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Socket/IP.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IO/Socket/UNIX.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IPC/Open2.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/IPC/Open3.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/List/Util.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/POSIX.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Scalar/Util.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/SelectSaver.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Socket.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Symbol.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Text/ParseWords.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Text/Tabs.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Text/Wrap.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/Tie/Hash.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/XSLoader.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/attributes.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/Cwd/Cwd.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/Fcntl/Fcntl.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/File/Glob/Glob.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/Hash/Util/Util.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/IO/IO.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/List/Util/Util.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/POSIX/POSIX.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/Socket/Socket.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/attributes/attributes.so", + "/usr/lib/x86_64-linux-gnu/perl-base/auto/re/re.so", + "/usr/lib/x86_64-linux-gnu/perl-base/base.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/builtin.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/bytes.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/constant.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/feature.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/fields.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/integer.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/lib.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/locale.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/overload.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/overloading.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/parent.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/re.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/strict.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Age.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Bc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Bmg.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Bpb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Bpt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Cf.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Ea.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/EqUIdeo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/GCB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Gc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Hst.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Identif2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Identifi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/InPC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/InSC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Isc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Jg.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Jt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Lb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Lc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/NFCQC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/NFDQC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/NFKCCF.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/NFKCQC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/NFKDQC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Na1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/NameAlia.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Nt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Nv.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/PerlDeci.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/SB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Sc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Scx.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Tc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Uc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/Vo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/WB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/_PerlLB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/To/_PerlSCX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/NA.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V100.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V11.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V110.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V120.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V130.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V140.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V150.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V20.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V30.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V31.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V32.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V40.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V41.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V50.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V51.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V52.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V60.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V61.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V70.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V80.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Age/V90.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Alpha/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/AL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/AN.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/B.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/BN.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/CS.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/EN.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/ES.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/ET.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/L.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/NSM.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/ON.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/R.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bc/WS.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/BidiC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/BidiM/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Blk/NB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bpt/C.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bpt/N.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Bpt/O.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CE/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CI/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CWCF/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CWCM/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CWKCF/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CWL/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CWT/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CWU/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Cased/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/A.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/AL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/AR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/ATAR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/B.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/BR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/DB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/NK.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/NR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/OV.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ccc/VR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/CompEx/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/DI/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dash/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dep/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dia/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Com.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Enc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Fin.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Font.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Init.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Iso.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Med.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Nar.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Nb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/NonCanon.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Sqr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Sub.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Sup.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Dt/Vert.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/EBase/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/EComp/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/EPres/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ea/A.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ea/H.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ea/N.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ea/Na.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ea/W.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Emoji/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ext/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/ExtPict/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/CN.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/EX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/LV.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/LVT.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/PP.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/SM.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GCB/XX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/C.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Cf.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Cn.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/L.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/LC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Ll.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Lm.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Lo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Lu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/M.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Mc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Me.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Mn.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/N.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Nd.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Nl.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/No.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/P.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Pc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Pd.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Pe.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Pf.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Pi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Po.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Ps.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/S.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Sc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Sk.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Sm.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/So.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Z.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Gc/Zs.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GrBase/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/GrExt/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Hex/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Hst/NA.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Hyphen/T.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IDC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IDS/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdStatus/Allowed.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdStatus/Restrict.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/DefaultI.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/Exclusio.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/Inclusio.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/LimitedU.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/NotChara.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/NotNFKC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/NotXID.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/Obsolete.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/Recommen.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/Technica.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/IdType/Uncommon.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Ideo/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/10_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/11_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/12_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/12_1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/13_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/14_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/15_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/2_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/2_1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/3_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/3_1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/3_2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/4_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/4_1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/5_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/5_1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/5_2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/6_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/6_1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/6_2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/6_3.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/7_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/8_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/In/9_0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/Bottom.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/BottomAn.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/Left.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/LeftAndR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/NA.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/Overstru.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/Right.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/Top.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/TopAndBo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/TopAndL2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/TopAndLe.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/TopAndRi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InPC/VisualOr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Avagraha.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Bindu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Cantilla.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona3.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona4.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona5.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona6.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona7.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona8.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consona9.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Consonan.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Geminati.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Invisibl.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Nukta.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Number.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Other.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/PureKill.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Syllable.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/ToneMark.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Virama.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Visarga.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/Vowel.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/VowelDep.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/InSC/VowelInd.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Ain.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Alef.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Beh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Dal.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/FarsiYeh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Feh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Gaf.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Hah.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/HanifiRo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Kaf.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Lam.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/NoJoinin.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Noon.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Qaf.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Reh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Sad.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Seen.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Tah.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Waw.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jg/Yeh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jt/C.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jt/D.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jt/L.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jt/R.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jt/T.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Jt/U.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/AI.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/AL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/BA.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/BB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/CJ.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/CL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/CM.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/EX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/GL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/ID.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/IN.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/IS.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/NS.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/NU.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/OP.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/PO.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/PR.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/QU.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/SA.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lb/XX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Lower/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Math/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFCQC/M.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFCQC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFDQC/N.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFDQC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFKCQC/N.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFKCQC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFKDQC/N.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/NFKDQC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nt/Di.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nt/None.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nt/Nu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/0.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/10.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/100.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/10000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/100000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/11.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/12.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/13.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/14.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/15.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/16.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/17.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/18.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/19.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1_16.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1_2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1_3.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1_4.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1_6.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/1_8.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/20.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/200.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/2000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/20000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/2_3.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/3.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/30.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/300.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/3000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/30000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/3_16.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/3_4.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/4.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/40.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/400.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/4000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/40000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/5.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/50.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/500.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/5000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/50000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/6.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/60.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/600.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/6000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/60000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/7.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/70.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/700.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/7000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/70000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/8.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/80.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/800.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/8000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/80000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/9.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/90.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/900.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/9000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Nv/90000.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/PCM/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/PatSyn/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Alnum.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Assigned.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Blank.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Graph.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/PerlWord.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/PosixPun.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Print.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/SpacePer.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Title.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/Word.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/XPosixPu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlAny.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlCh2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlCha.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlFol.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlIDC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlIDS.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlIsI.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlNch.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlPat.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlPr2.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlPro.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Perl/_PerlQuo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/QMark/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/AT.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/CL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/EX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/FO.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/LE.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/LO.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/NU.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/SC.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/ST.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/Sp.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/UP.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SB/XX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/SD/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/STerm/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Arab.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Beng.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Cprt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Cyrl.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Deva.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Dupl.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Geor.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Glag.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Gong.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Gonm.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Gran.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Grek.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Gujr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Guru.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Han.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Hang.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Hira.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Kana.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Knda.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Latn.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Limb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Linb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Mlym.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Mong.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Mult.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Orya.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Sinh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Syrc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Taml.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Telu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Zinh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Sc/Zyyy.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Adlm.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Arab.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Armn.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Beng.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Bhks.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Bopo.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Cakm.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Cham.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Copt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Cprt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Cyrl.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Deva.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Diak.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Dupl.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Ethi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Geor.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Glag.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Gong.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Gonm.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Gran.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Grek.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Gujr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Guru.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Han.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Hang.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Hebr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Hira.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Hmng.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Hmnp.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Kana.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Khar.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Khmr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Khoj.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Knda.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Kthi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Lana.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Lao.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Latn.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Limb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Lina.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Linb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Mlym.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Mong.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Mult.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Mymr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Nand.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Nko.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Orya.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Phlp.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Rohg.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Shrd.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Sind.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Sinh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Syrc.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Tagb.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Takr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Talu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Taml.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Tang.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Telu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Thaa.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Tibt.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Tirh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Vith.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Xsux.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Yezi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Yi.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Zinh.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Zyyy.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Scx/Zzzz.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Term/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/UIdeo/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Upper/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/VS/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Vo/R.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Vo/Tr.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Vo/Tu.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/Vo/U.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/EX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/Extend.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/FO.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/HL.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/KA.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/LE.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/MB.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/ML.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/MN.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/NU.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/WSegSpac.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/WB/XX.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/XIDC/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/unicore/lib/XIDS/Y.pl", + "/usr/lib/x86_64-linux-gnu/perl-base/utf8.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/vars.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/warnings.pm", + "/usr/lib/x86_64-linux-gnu/perl-base/warnings/register.pm", + "/usr/share/doc/perl-base/changelog.Debian.gz", + "/usr/share/doc/perl-base/changelog.gz", + "/usr/share/doc/perl-base/copyright", + "/usr/share/doc/perl/AUTHORS.gz", + "/usr/share/doc/perl/Documentation", + "/usr/share/lintian/overrides/perl-base", + "/usr/share/man/man1/perl.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "readline-common@8.2-6", + "Name": "readline-common", + "Identifier": { + "PURL": "pkg:deb/debian/readline-common@8.2-6?arch=all\u0026distro=debian-13.6", + "UID": "e762758a1681f62e" + }, + "Version": "8.2", + "Release": "6", + "Arch": "all", + "SrcName": "readline", + "SrcVersion": "8.2", + "SrcRelease": "6", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-3.0-only", + "GPL-2.0-or-later", + "GPL-2.0-only", + "GFDL-1.3-no-invariants-or-later", + "GFDL-1.3-or-later", + "ISC-no-attribution" + ], + "Maintainer": "Matthias Klose \u003cdoko@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "InstalledFiles": [ + "/usr/share/doc/readline-common/changelog.Debian.gz", + "/usr/share/doc/readline-common/changelog.gz", + "/usr/share/doc/readline-common/copyright", + "/usr/share/doc/readline-common/inputrc.arrows", + "/usr/share/info/rluserman.info.gz", + "/usr/share/lintian/overrides/readline-common", + "/usr/share/man/man3/history.3readline.gz", + "/usr/share/man/man3/readline.3readline.gz", + "/usr/share/readline/inputrc" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "sed@4.9-2+deb13u1", + "Name": "sed", + "Identifier": { + "PURL": "pkg:deb/debian/sed@4.9-2%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "a041ea16982bb927" + }, + "Version": "4.9", + "Release": "2+deb13u1", + "Arch": "amd64", + "SrcName": "sed", + "SrcVersion": "4.9", + "SrcRelease": "2+deb13u1", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-3.0-only", + "X11", + "GFDL-1.3-no-invariants-or-later", + "GFDL-1.3-only", + "ISC", + "BSD-4-Clause-UC", + "BSL-1", + "pcre" + ], + "Maintainer": "Clint Adams \u003cclint@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/sed", + "/usr/share/doc/sed/AUTHORS", + "/usr/share/doc/sed/BUGS.gz", + "/usr/share/doc/sed/NEWS.gz", + "/usr/share/doc/sed/README", + "/usr/share/doc/sed/THANKS.gz", + "/usr/share/doc/sed/changelog.Debian.gz", + "/usr/share/doc/sed/changelog.gz", + "/usr/share/doc/sed/copyright", + "/usr/share/doc/sed/examples/dc.sed", + "/usr/share/doc/sed/sedfaq.txt.gz", + "/usr/share/info/sed.info.gz", + "/usr/share/locale/af/LC_MESSAGES/sed.mo", + "/usr/share/locale/ast/LC_MESSAGES/sed.mo", + "/usr/share/locale/bg/LC_MESSAGES/sed.mo", + "/usr/share/locale/ca/LC_MESSAGES/sed.mo", + "/usr/share/locale/cs/LC_MESSAGES/sed.mo", + "/usr/share/locale/da/LC_MESSAGES/sed.mo", + "/usr/share/locale/de/LC_MESSAGES/sed.mo", + "/usr/share/locale/el/LC_MESSAGES/sed.mo", + "/usr/share/locale/eo/LC_MESSAGES/sed.mo", + "/usr/share/locale/es/LC_MESSAGES/sed.mo", + "/usr/share/locale/et/LC_MESSAGES/sed.mo", + "/usr/share/locale/eu/LC_MESSAGES/sed.mo", + "/usr/share/locale/fi/LC_MESSAGES/sed.mo", + "/usr/share/locale/fr/LC_MESSAGES/sed.mo", + "/usr/share/locale/ga/LC_MESSAGES/sed.mo", + "/usr/share/locale/gl/LC_MESSAGES/sed.mo", + "/usr/share/locale/he/LC_MESSAGES/sed.mo", + "/usr/share/locale/hr/LC_MESSAGES/sed.mo", + "/usr/share/locale/hu/LC_MESSAGES/sed.mo", + "/usr/share/locale/id/LC_MESSAGES/sed.mo", + "/usr/share/locale/it/LC_MESSAGES/sed.mo", + "/usr/share/locale/ja/LC_MESSAGES/sed.mo", + "/usr/share/locale/ka/LC_MESSAGES/sed.mo", + "/usr/share/locale/ko/LC_MESSAGES/sed.mo", + "/usr/share/locale/nb/LC_MESSAGES/sed.mo", + "/usr/share/locale/nl/LC_MESSAGES/sed.mo", + "/usr/share/locale/pl/LC_MESSAGES/sed.mo", + "/usr/share/locale/pt/LC_MESSAGES/sed.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/sed.mo", + "/usr/share/locale/ro/LC_MESSAGES/sed.mo", + "/usr/share/locale/ru/LC_MESSAGES/sed.mo", + "/usr/share/locale/sk/LC_MESSAGES/sed.mo", + "/usr/share/locale/sl/LC_MESSAGES/sed.mo", + "/usr/share/locale/sr/LC_MESSAGES/sed.mo", + "/usr/share/locale/sv/LC_MESSAGES/sed.mo", + "/usr/share/locale/tr/LC_MESSAGES/sed.mo", + "/usr/share/locale/uk/LC_MESSAGES/sed.mo", + "/usr/share/locale/vi/LC_MESSAGES/sed.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/sed.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/sed.mo", + "/usr/share/man/man1/sed.1.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "sqv@1.3.0-3+b2", + "Name": "sqv", + "Identifier": { + "PURL": "pkg:deb/debian/sqv@1.3.0-3%2Bb2?arch=amd64\u0026distro=debian-13.6", + "UID": "2bf11ffe79190750" + }, + "Version": "1.3.0", + "Release": "3+b2", + "Arch": "amd64", + "SrcName": "rust-sequoia-sqv", + "SrcVersion": "1.3.0", + "SrcRelease": "3", + "Licenses": [ + "LGPL-2.0-or-later", + "LGPL-2.0-only" + ], + "Maintainer": "Debian Rust Maintainers \u003cpkg-rust-maintainers@alioth-lists.debian.net\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3", + "libgcc-s1@14.2.0-19", + "libgmp10@2:6.3.0+dfsg-3", + "libhogweed6t64@3.10.1-1", + "libnettle8t64@3.10.1-1" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/sqv", + "/usr/share/bash-completion/completions/sqv.bash", + "/usr/share/doc/sqv/NEWS.gz", + "/usr/share/doc/sqv/changelog.Debian.amd64.gz", + "/usr/share/doc/sqv/changelog.Debian.gz", + "/usr/share/doc/sqv/copyright", + "/usr/share/fish/completions/sqv.fish", + "/usr/share/man/man1/sqv.1.gz", + "/usr/share/zsh/vendor-completions/_sqv" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "sysvinit-utils@3.14-4", + "Name": "sysvinit-utils", + "Identifier": { + "PURL": "pkg:deb/debian/sysvinit-utils@3.14-4?arch=amd64\u0026distro=debian-13.6", + "UID": "f7fb888c58ca826e" + }, + "Version": "3.14", + "Release": "4", + "Arch": "amd64", + "SrcName": "sysvinit", + "SrcVersion": "3.14", + "SrcRelease": "4", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-2.1-or-later", + "GPL-3.0-only", + "GPL-2.0-only", + "LGPL-2.1-only" + ], + "Maintainer": "Debian sysvinit maintainers \u003cdebian-init-diversity@chiark.greenend.org.uk\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/init/init-d-script", + "/usr/lib/init/vars.sh", + "/usr/lib/lsb/init-functions", + "/usr/lib/lsb/init-functions.d/00-verbose", + "/usr/sbin/fstab-decode", + "/usr/sbin/killall5", + "/usr/share/doc/sysvinit-utils/changelog.Debian.gz", + "/usr/share/doc/sysvinit-utils/copyright", + "/usr/share/man/man5/init-d-script.5.gz", + "/usr/share/man/man8/fstab-decode.8.gz", + "/usr/share/man/man8/killall5.8.gz", + "/usr/share/man/man8/pidof.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "tar@1.35+dfsg-3.1", + "Name": "tar", + "Identifier": { + "PURL": "pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64\u0026distro=debian-13.6", + "UID": "4f69996c49afbaca" + }, + "Version": "1.35+dfsg", + "Release": "3.1", + "Arch": "amd64", + "SrcName": "tar", + "SrcVersion": "1.35+dfsg", + "SrcRelease": "3.1", + "Licenses": [ + "GPL-3.0-or-later", + "GPL-3.0-only", + "GPL-3+ with Bison exception", + "LGPL-2.1-or-later", + "LGPL-2.1-only", + "LGPL-3.0-or-later", + "LGPL-3.0-only", + "GPL-2.0-or-later", + "GPL-2.0-only" + ], + "Maintainer": "Janos Lenart \u003cocsi@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/tar", + "/usr/lib/mime/packages/tar", + "/usr/sbin/rmt-tar", + "/usr/sbin/tarcat", + "/usr/share/doc/tar/AUTHORS", + "/usr/share/doc/tar/NEWS.gz", + "/usr/share/doc/tar/README.Debian", + "/usr/share/doc/tar/THANKS.gz", + "/usr/share/doc/tar/changelog.1.gz", + "/usr/share/doc/tar/changelog.Debian.gz", + "/usr/share/doc/tar/changelog.gz", + "/usr/share/doc/tar/copyright", + "/usr/share/locale/bg/LC_MESSAGES/tar.mo", + "/usr/share/locale/ca/LC_MESSAGES/tar.mo", + "/usr/share/locale/cs/LC_MESSAGES/tar.mo", + "/usr/share/locale/da/LC_MESSAGES/tar.mo", + "/usr/share/locale/de/LC_MESSAGES/tar.mo", + "/usr/share/locale/el/LC_MESSAGES/tar.mo", + "/usr/share/locale/eo/LC_MESSAGES/tar.mo", + "/usr/share/locale/es/LC_MESSAGES/tar.mo", + "/usr/share/locale/et/LC_MESSAGES/tar.mo", + "/usr/share/locale/eu/LC_MESSAGES/tar.mo", + "/usr/share/locale/fi/LC_MESSAGES/tar.mo", + "/usr/share/locale/fr/LC_MESSAGES/tar.mo", + "/usr/share/locale/ga/LC_MESSAGES/tar.mo", + "/usr/share/locale/gl/LC_MESSAGES/tar.mo", + "/usr/share/locale/hr/LC_MESSAGES/tar.mo", + "/usr/share/locale/hu/LC_MESSAGES/tar.mo", + "/usr/share/locale/id/LC_MESSAGES/tar.mo", + "/usr/share/locale/it/LC_MESSAGES/tar.mo", + "/usr/share/locale/ja/LC_MESSAGES/tar.mo", + "/usr/share/locale/ka/LC_MESSAGES/tar.mo", + "/usr/share/locale/ko/LC_MESSAGES/tar.mo", + "/usr/share/locale/ky/LC_MESSAGES/tar.mo", + "/usr/share/locale/ms/LC_MESSAGES/tar.mo", + "/usr/share/locale/nb/LC_MESSAGES/tar.mo", + "/usr/share/locale/nl/LC_MESSAGES/tar.mo", + "/usr/share/locale/pl/LC_MESSAGES/tar.mo", + "/usr/share/locale/pt/LC_MESSAGES/tar.mo", + "/usr/share/locale/pt_BR/LC_MESSAGES/tar.mo", + "/usr/share/locale/ro/LC_MESSAGES/tar.mo", + "/usr/share/locale/ru/LC_MESSAGES/tar.mo", + "/usr/share/locale/sk/LC_MESSAGES/tar.mo", + "/usr/share/locale/sl/LC_MESSAGES/tar.mo", + "/usr/share/locale/sr/LC_MESSAGES/tar.mo", + "/usr/share/locale/sv/LC_MESSAGES/tar.mo", + "/usr/share/locale/tr/LC_MESSAGES/tar.mo", + "/usr/share/locale/uk/LC_MESSAGES/tar.mo", + "/usr/share/locale/vi/LC_MESSAGES/tar.mo", + "/usr/share/locale/zh_CN/LC_MESSAGES/tar.mo", + "/usr/share/locale/zh_TW/LC_MESSAGES/tar.mo", + "/usr/share/man/man1/tar.1.gz", + "/usr/share/man/man1/tarcat.1.gz", + "/usr/share/man/man8/rmt-tar.8.gz" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "tzdata@2026b-0+deb13u1", + "Name": "tzdata", + "Identifier": { + "PURL": "pkg:deb/debian/tzdata@2026b-0%2Bdeb13u1?arch=all\u0026distro=debian-13.6", + "UID": "9e352e373d8245f0" + }, + "Version": "2026b", + "Release": "0+deb13u1", + "Arch": "all", + "SrcName": "tzdata", + "SrcVersion": "2026b", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "public-domain" + ], + "Maintainer": "GNU Libc Maintainers \u003cdebian-glibc@lists.debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "debconf@1.5.91" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/share/doc/tzdata/NEWS.Debian.gz", + "/usr/share/doc/tzdata/README.Debian", + "/usr/share/doc/tzdata/changelog.Debian.gz", + "/usr/share/doc/tzdata/changelog.gz", + "/usr/share/doc/tzdata/copyright", + "/usr/share/lintian/overrides/tzdata", + "/usr/share/zoneinfo/Africa/Abidjan", + "/usr/share/zoneinfo/Africa/Accra", + "/usr/share/zoneinfo/Africa/Addis_Ababa", + "/usr/share/zoneinfo/Africa/Algiers", + "/usr/share/zoneinfo/Africa/Asmara", + "/usr/share/zoneinfo/Africa/Bamako", + "/usr/share/zoneinfo/Africa/Bangui", + "/usr/share/zoneinfo/Africa/Banjul", + "/usr/share/zoneinfo/Africa/Bissau", + "/usr/share/zoneinfo/Africa/Blantyre", + "/usr/share/zoneinfo/Africa/Brazzaville", + "/usr/share/zoneinfo/Africa/Bujumbura", + "/usr/share/zoneinfo/Africa/Cairo", + "/usr/share/zoneinfo/Africa/Casablanca", + "/usr/share/zoneinfo/Africa/Ceuta", + "/usr/share/zoneinfo/Africa/Conakry", + "/usr/share/zoneinfo/Africa/Dakar", + "/usr/share/zoneinfo/Africa/Dar_es_Salaam", + "/usr/share/zoneinfo/Africa/Djibouti", + "/usr/share/zoneinfo/Africa/Douala", + "/usr/share/zoneinfo/Africa/El_Aaiun", + "/usr/share/zoneinfo/Africa/Freetown", + "/usr/share/zoneinfo/Africa/Gaborone", + "/usr/share/zoneinfo/Africa/Harare", + "/usr/share/zoneinfo/Africa/Johannesburg", + "/usr/share/zoneinfo/Africa/Juba", + "/usr/share/zoneinfo/Africa/Kampala", + "/usr/share/zoneinfo/Africa/Khartoum", + "/usr/share/zoneinfo/Africa/Kigali", + "/usr/share/zoneinfo/Africa/Kinshasa", + "/usr/share/zoneinfo/Africa/Lagos", + "/usr/share/zoneinfo/Africa/Libreville", + "/usr/share/zoneinfo/Africa/Lome", + "/usr/share/zoneinfo/Africa/Luanda", + "/usr/share/zoneinfo/Africa/Lubumbashi", + "/usr/share/zoneinfo/Africa/Lusaka", + "/usr/share/zoneinfo/Africa/Malabo", + "/usr/share/zoneinfo/Africa/Maputo", + "/usr/share/zoneinfo/Africa/Maseru", + "/usr/share/zoneinfo/Africa/Mbabane", + "/usr/share/zoneinfo/Africa/Mogadishu", + "/usr/share/zoneinfo/Africa/Monrovia", + "/usr/share/zoneinfo/Africa/Nairobi", + "/usr/share/zoneinfo/Africa/Ndjamena", + "/usr/share/zoneinfo/Africa/Niamey", + "/usr/share/zoneinfo/Africa/Nouakchott", + "/usr/share/zoneinfo/Africa/Ouagadougou", + "/usr/share/zoneinfo/Africa/Porto-Novo", + "/usr/share/zoneinfo/Africa/Sao_Tome", + "/usr/share/zoneinfo/Africa/Tripoli", + "/usr/share/zoneinfo/Africa/Tunis", + "/usr/share/zoneinfo/Africa/Windhoek", + "/usr/share/zoneinfo/America/Adak", + "/usr/share/zoneinfo/America/Anchorage", + "/usr/share/zoneinfo/America/Anguilla", + "/usr/share/zoneinfo/America/Antigua", + "/usr/share/zoneinfo/America/Araguaina", + "/usr/share/zoneinfo/America/Argentina/Buenos_Aires", + "/usr/share/zoneinfo/America/Argentina/Catamarca", + "/usr/share/zoneinfo/America/Argentina/Cordoba", + "/usr/share/zoneinfo/America/Argentina/Jujuy", + "/usr/share/zoneinfo/America/Argentina/La_Rioja", + "/usr/share/zoneinfo/America/Argentina/Mendoza", + "/usr/share/zoneinfo/America/Argentina/Rio_Gallegos", + "/usr/share/zoneinfo/America/Argentina/Salta", + "/usr/share/zoneinfo/America/Argentina/San_Juan", + "/usr/share/zoneinfo/America/Argentina/San_Luis", + "/usr/share/zoneinfo/America/Argentina/Tucuman", + "/usr/share/zoneinfo/America/Argentina/Ushuaia", + "/usr/share/zoneinfo/America/Aruba", + "/usr/share/zoneinfo/America/Asuncion", + "/usr/share/zoneinfo/America/Atikokan", + "/usr/share/zoneinfo/America/Bahia", + "/usr/share/zoneinfo/America/Bahia_Banderas", + "/usr/share/zoneinfo/America/Barbados", + "/usr/share/zoneinfo/America/Belem", + "/usr/share/zoneinfo/America/Belize", + "/usr/share/zoneinfo/America/Blanc-Sablon", + "/usr/share/zoneinfo/America/Boa_Vista", + "/usr/share/zoneinfo/America/Bogota", + "/usr/share/zoneinfo/America/Boise", + "/usr/share/zoneinfo/America/Cambridge_Bay", + "/usr/share/zoneinfo/America/Campo_Grande", + "/usr/share/zoneinfo/America/Cancun", + "/usr/share/zoneinfo/America/Caracas", + "/usr/share/zoneinfo/America/Cayenne", + "/usr/share/zoneinfo/America/Cayman", + "/usr/share/zoneinfo/America/Chicago", + "/usr/share/zoneinfo/America/Chihuahua", + "/usr/share/zoneinfo/America/Ciudad_Juarez", + "/usr/share/zoneinfo/America/Costa_Rica", + "/usr/share/zoneinfo/America/Coyhaique", + "/usr/share/zoneinfo/America/Creston", + "/usr/share/zoneinfo/America/Cuiaba", + "/usr/share/zoneinfo/America/Curacao", + "/usr/share/zoneinfo/America/Danmarkshavn", + "/usr/share/zoneinfo/America/Dawson", + "/usr/share/zoneinfo/America/Dawson_Creek", + "/usr/share/zoneinfo/America/Denver", + "/usr/share/zoneinfo/America/Detroit", + "/usr/share/zoneinfo/America/Dominica", + "/usr/share/zoneinfo/America/Edmonton", + "/usr/share/zoneinfo/America/Eirunepe", + "/usr/share/zoneinfo/America/El_Salvador", + "/usr/share/zoneinfo/America/Fort_Nelson", + "/usr/share/zoneinfo/America/Fortaleza", + "/usr/share/zoneinfo/America/Glace_Bay", + "/usr/share/zoneinfo/America/Goose_Bay", + "/usr/share/zoneinfo/America/Grand_Turk", + "/usr/share/zoneinfo/America/Grenada", + "/usr/share/zoneinfo/America/Guadeloupe", + "/usr/share/zoneinfo/America/Guatemala", + "/usr/share/zoneinfo/America/Guayaquil", + "/usr/share/zoneinfo/America/Guyana", + "/usr/share/zoneinfo/America/Halifax", + "/usr/share/zoneinfo/America/Havana", + "/usr/share/zoneinfo/America/Hermosillo", + "/usr/share/zoneinfo/America/Indiana/Indianapolis", + "/usr/share/zoneinfo/America/Indiana/Knox", + "/usr/share/zoneinfo/America/Indiana/Marengo", + "/usr/share/zoneinfo/America/Indiana/Petersburg", + "/usr/share/zoneinfo/America/Indiana/Tell_City", + "/usr/share/zoneinfo/America/Indiana/Vevay", + "/usr/share/zoneinfo/America/Indiana/Vincennes", + "/usr/share/zoneinfo/America/Indiana/Winamac", + "/usr/share/zoneinfo/America/Inuvik", + "/usr/share/zoneinfo/America/Iqaluit", + "/usr/share/zoneinfo/America/Jamaica", + "/usr/share/zoneinfo/America/Juneau", + "/usr/share/zoneinfo/America/Kentucky/Louisville", + "/usr/share/zoneinfo/America/Kentucky/Monticello", + "/usr/share/zoneinfo/America/La_Paz", + "/usr/share/zoneinfo/America/Lima", + "/usr/share/zoneinfo/America/Los_Angeles", + "/usr/share/zoneinfo/America/Maceio", + "/usr/share/zoneinfo/America/Managua", + "/usr/share/zoneinfo/America/Manaus", + "/usr/share/zoneinfo/America/Martinique", + "/usr/share/zoneinfo/America/Matamoros", + "/usr/share/zoneinfo/America/Mazatlan", + "/usr/share/zoneinfo/America/Menominee", + "/usr/share/zoneinfo/America/Merida", + "/usr/share/zoneinfo/America/Metlakatla", + "/usr/share/zoneinfo/America/Mexico_City", + "/usr/share/zoneinfo/America/Miquelon", + "/usr/share/zoneinfo/America/Moncton", + "/usr/share/zoneinfo/America/Monterrey", + "/usr/share/zoneinfo/America/Montevideo", + "/usr/share/zoneinfo/America/Montserrat", + "/usr/share/zoneinfo/America/Nassau", + "/usr/share/zoneinfo/America/New_York", + "/usr/share/zoneinfo/America/Nome", + "/usr/share/zoneinfo/America/Noronha", + "/usr/share/zoneinfo/America/North_Dakota/Beulah", + "/usr/share/zoneinfo/America/North_Dakota/Center", + "/usr/share/zoneinfo/America/North_Dakota/New_Salem", + "/usr/share/zoneinfo/America/Nuuk", + "/usr/share/zoneinfo/America/Ojinaga", + "/usr/share/zoneinfo/America/Panama", + "/usr/share/zoneinfo/America/Paramaribo", + "/usr/share/zoneinfo/America/Phoenix", + "/usr/share/zoneinfo/America/Port-au-Prince", + "/usr/share/zoneinfo/America/Port_of_Spain", + "/usr/share/zoneinfo/America/Porto_Velho", + "/usr/share/zoneinfo/America/Puerto_Rico", + "/usr/share/zoneinfo/America/Punta_Arenas", + "/usr/share/zoneinfo/America/Rankin_Inlet", + "/usr/share/zoneinfo/America/Recife", + "/usr/share/zoneinfo/America/Regina", + "/usr/share/zoneinfo/America/Resolute", + "/usr/share/zoneinfo/America/Rio_Branco", + "/usr/share/zoneinfo/America/Santarem", + "/usr/share/zoneinfo/America/Santiago", + "/usr/share/zoneinfo/America/Santo_Domingo", + "/usr/share/zoneinfo/America/Sao_Paulo", + "/usr/share/zoneinfo/America/Scoresbysund", + "/usr/share/zoneinfo/America/Sitka", + "/usr/share/zoneinfo/America/St_Johns", + "/usr/share/zoneinfo/America/St_Kitts", + "/usr/share/zoneinfo/America/St_Lucia", + "/usr/share/zoneinfo/America/St_Thomas", + "/usr/share/zoneinfo/America/St_Vincent", + "/usr/share/zoneinfo/America/Swift_Current", + "/usr/share/zoneinfo/America/Tegucigalpa", + "/usr/share/zoneinfo/America/Thule", + "/usr/share/zoneinfo/America/Tijuana", + "/usr/share/zoneinfo/America/Toronto", + "/usr/share/zoneinfo/America/Tortola", + "/usr/share/zoneinfo/America/Vancouver", + "/usr/share/zoneinfo/America/Whitehorse", + "/usr/share/zoneinfo/America/Winnipeg", + "/usr/share/zoneinfo/America/Yakutat", + "/usr/share/zoneinfo/Antarctica/Casey", + "/usr/share/zoneinfo/Antarctica/Davis", + "/usr/share/zoneinfo/Antarctica/DumontDUrville", + "/usr/share/zoneinfo/Antarctica/Macquarie", + "/usr/share/zoneinfo/Antarctica/Mawson", + "/usr/share/zoneinfo/Antarctica/McMurdo", + "/usr/share/zoneinfo/Antarctica/Palmer", + "/usr/share/zoneinfo/Antarctica/Rothera", + "/usr/share/zoneinfo/Antarctica/Syowa", + "/usr/share/zoneinfo/Antarctica/Troll", + "/usr/share/zoneinfo/Antarctica/Vostok", + "/usr/share/zoneinfo/Asia/Aden", + "/usr/share/zoneinfo/Asia/Almaty", + "/usr/share/zoneinfo/Asia/Amman", + "/usr/share/zoneinfo/Asia/Anadyr", + "/usr/share/zoneinfo/Asia/Aqtau", + "/usr/share/zoneinfo/Asia/Aqtobe", + "/usr/share/zoneinfo/Asia/Ashgabat", + "/usr/share/zoneinfo/Asia/Atyrau", + "/usr/share/zoneinfo/Asia/Baghdad", + "/usr/share/zoneinfo/Asia/Bahrain", + "/usr/share/zoneinfo/Asia/Baku", + "/usr/share/zoneinfo/Asia/Bangkok", + "/usr/share/zoneinfo/Asia/Barnaul", + "/usr/share/zoneinfo/Asia/Beirut", + "/usr/share/zoneinfo/Asia/Bishkek", + "/usr/share/zoneinfo/Asia/Brunei", + "/usr/share/zoneinfo/Asia/Chita", + "/usr/share/zoneinfo/Asia/Colombo", + "/usr/share/zoneinfo/Asia/Damascus", + "/usr/share/zoneinfo/Asia/Dhaka", + "/usr/share/zoneinfo/Asia/Dili", + "/usr/share/zoneinfo/Asia/Dubai", + "/usr/share/zoneinfo/Asia/Dushanbe", + "/usr/share/zoneinfo/Asia/Famagusta", + "/usr/share/zoneinfo/Asia/Gaza", + "/usr/share/zoneinfo/Asia/Hebron", + "/usr/share/zoneinfo/Asia/Ho_Chi_Minh", + "/usr/share/zoneinfo/Asia/Hong_Kong", + "/usr/share/zoneinfo/Asia/Hovd", + "/usr/share/zoneinfo/Asia/Irkutsk", + "/usr/share/zoneinfo/Asia/Jakarta", + "/usr/share/zoneinfo/Asia/Jayapura", + "/usr/share/zoneinfo/Asia/Jerusalem", + "/usr/share/zoneinfo/Asia/Kabul", + "/usr/share/zoneinfo/Asia/Kamchatka", + "/usr/share/zoneinfo/Asia/Karachi", + "/usr/share/zoneinfo/Asia/Kathmandu", + "/usr/share/zoneinfo/Asia/Khandyga", + "/usr/share/zoneinfo/Asia/Kolkata", + "/usr/share/zoneinfo/Asia/Krasnoyarsk", + "/usr/share/zoneinfo/Asia/Kuala_Lumpur", + "/usr/share/zoneinfo/Asia/Kuching", + "/usr/share/zoneinfo/Asia/Kuwait", + "/usr/share/zoneinfo/Asia/Macau", + "/usr/share/zoneinfo/Asia/Magadan", + "/usr/share/zoneinfo/Asia/Makassar", + "/usr/share/zoneinfo/Asia/Manila", + "/usr/share/zoneinfo/Asia/Muscat", + "/usr/share/zoneinfo/Asia/Nicosia", + "/usr/share/zoneinfo/Asia/Novokuznetsk", + "/usr/share/zoneinfo/Asia/Novosibirsk", + "/usr/share/zoneinfo/Asia/Omsk", + "/usr/share/zoneinfo/Asia/Oral", + "/usr/share/zoneinfo/Asia/Phnom_Penh", + "/usr/share/zoneinfo/Asia/Pontianak", + "/usr/share/zoneinfo/Asia/Pyongyang", + "/usr/share/zoneinfo/Asia/Qatar", + "/usr/share/zoneinfo/Asia/Qostanay", + "/usr/share/zoneinfo/Asia/Qyzylorda", + "/usr/share/zoneinfo/Asia/Riyadh", + "/usr/share/zoneinfo/Asia/Sakhalin", + "/usr/share/zoneinfo/Asia/Samarkand", + "/usr/share/zoneinfo/Asia/Seoul", + "/usr/share/zoneinfo/Asia/Shanghai", + "/usr/share/zoneinfo/Asia/Singapore", + "/usr/share/zoneinfo/Asia/Srednekolymsk", + "/usr/share/zoneinfo/Asia/Taipei", + "/usr/share/zoneinfo/Asia/Tashkent", + "/usr/share/zoneinfo/Asia/Tbilisi", + "/usr/share/zoneinfo/Asia/Tehran", + "/usr/share/zoneinfo/Asia/Thimphu", + "/usr/share/zoneinfo/Asia/Tokyo", + "/usr/share/zoneinfo/Asia/Tomsk", + "/usr/share/zoneinfo/Asia/Ulaanbaatar", + "/usr/share/zoneinfo/Asia/Urumqi", + "/usr/share/zoneinfo/Asia/Ust-Nera", + "/usr/share/zoneinfo/Asia/Vientiane", + "/usr/share/zoneinfo/Asia/Vladivostok", + "/usr/share/zoneinfo/Asia/Yakutsk", + "/usr/share/zoneinfo/Asia/Yangon", + "/usr/share/zoneinfo/Asia/Yekaterinburg", + "/usr/share/zoneinfo/Asia/Yerevan", + "/usr/share/zoneinfo/Atlantic/Azores", + "/usr/share/zoneinfo/Atlantic/Bermuda", + "/usr/share/zoneinfo/Atlantic/Canary", + "/usr/share/zoneinfo/Atlantic/Cape_Verde", + "/usr/share/zoneinfo/Atlantic/Faroe", + "/usr/share/zoneinfo/Atlantic/Madeira", + "/usr/share/zoneinfo/Atlantic/Reykjavik", + "/usr/share/zoneinfo/Atlantic/South_Georgia", + "/usr/share/zoneinfo/Atlantic/St_Helena", + "/usr/share/zoneinfo/Atlantic/Stanley", + "/usr/share/zoneinfo/Australia/Adelaide", + "/usr/share/zoneinfo/Australia/Brisbane", + "/usr/share/zoneinfo/Australia/Broken_Hill", + "/usr/share/zoneinfo/Australia/Darwin", + "/usr/share/zoneinfo/Australia/Eucla", + "/usr/share/zoneinfo/Australia/Hobart", + "/usr/share/zoneinfo/Australia/Lindeman", + "/usr/share/zoneinfo/Australia/Lord_Howe", + "/usr/share/zoneinfo/Australia/Melbourne", + "/usr/share/zoneinfo/Australia/Perth", + "/usr/share/zoneinfo/Australia/Sydney", + "/usr/share/zoneinfo/Etc/GMT", + "/usr/share/zoneinfo/Etc/GMT+1", + "/usr/share/zoneinfo/Etc/GMT+10", + "/usr/share/zoneinfo/Etc/GMT+11", + "/usr/share/zoneinfo/Etc/GMT+12", + "/usr/share/zoneinfo/Etc/GMT+2", + "/usr/share/zoneinfo/Etc/GMT+3", + "/usr/share/zoneinfo/Etc/GMT+4", + "/usr/share/zoneinfo/Etc/GMT+5", + "/usr/share/zoneinfo/Etc/GMT+6", + "/usr/share/zoneinfo/Etc/GMT+7", + "/usr/share/zoneinfo/Etc/GMT+8", + "/usr/share/zoneinfo/Etc/GMT+9", + "/usr/share/zoneinfo/Etc/GMT-1", + "/usr/share/zoneinfo/Etc/GMT-10", + "/usr/share/zoneinfo/Etc/GMT-11", + "/usr/share/zoneinfo/Etc/GMT-12", + "/usr/share/zoneinfo/Etc/GMT-13", + "/usr/share/zoneinfo/Etc/GMT-14", + "/usr/share/zoneinfo/Etc/GMT-2", + "/usr/share/zoneinfo/Etc/GMT-3", + "/usr/share/zoneinfo/Etc/GMT-4", + "/usr/share/zoneinfo/Etc/GMT-5", + "/usr/share/zoneinfo/Etc/GMT-6", + "/usr/share/zoneinfo/Etc/GMT-7", + "/usr/share/zoneinfo/Etc/GMT-8", + "/usr/share/zoneinfo/Etc/GMT-9", + "/usr/share/zoneinfo/Etc/UTC", + "/usr/share/zoneinfo/Europe/Amsterdam", + "/usr/share/zoneinfo/Europe/Andorra", + "/usr/share/zoneinfo/Europe/Astrakhan", + "/usr/share/zoneinfo/Europe/Athens", + "/usr/share/zoneinfo/Europe/Belgrade", + "/usr/share/zoneinfo/Europe/Berlin", + "/usr/share/zoneinfo/Europe/Brussels", + "/usr/share/zoneinfo/Europe/Bucharest", + "/usr/share/zoneinfo/Europe/Budapest", + "/usr/share/zoneinfo/Europe/Chisinau", + "/usr/share/zoneinfo/Europe/Copenhagen", + "/usr/share/zoneinfo/Europe/Dublin", + "/usr/share/zoneinfo/Europe/Gibraltar", + "/usr/share/zoneinfo/Europe/Guernsey", + "/usr/share/zoneinfo/Europe/Helsinki", + "/usr/share/zoneinfo/Europe/Isle_of_Man", + "/usr/share/zoneinfo/Europe/Istanbul", + "/usr/share/zoneinfo/Europe/Jersey", + "/usr/share/zoneinfo/Europe/Kaliningrad", + "/usr/share/zoneinfo/Europe/Kirov", + "/usr/share/zoneinfo/Europe/Kyiv", + "/usr/share/zoneinfo/Europe/Lisbon", + "/usr/share/zoneinfo/Europe/Ljubljana", + "/usr/share/zoneinfo/Europe/London", + "/usr/share/zoneinfo/Europe/Luxembourg", + "/usr/share/zoneinfo/Europe/Madrid", + "/usr/share/zoneinfo/Europe/Malta", + "/usr/share/zoneinfo/Europe/Minsk", + "/usr/share/zoneinfo/Europe/Monaco", + "/usr/share/zoneinfo/Europe/Moscow", + "/usr/share/zoneinfo/Europe/Oslo", + "/usr/share/zoneinfo/Europe/Paris", + "/usr/share/zoneinfo/Europe/Prague", + "/usr/share/zoneinfo/Europe/Riga", + "/usr/share/zoneinfo/Europe/Rome", + "/usr/share/zoneinfo/Europe/Samara", + "/usr/share/zoneinfo/Europe/Sarajevo", + "/usr/share/zoneinfo/Europe/Saratov", + "/usr/share/zoneinfo/Europe/Simferopol", + "/usr/share/zoneinfo/Europe/Skopje", + "/usr/share/zoneinfo/Europe/Sofia", + "/usr/share/zoneinfo/Europe/Stockholm", + "/usr/share/zoneinfo/Europe/Tallinn", + "/usr/share/zoneinfo/Europe/Tirane", + "/usr/share/zoneinfo/Europe/Ulyanovsk", + "/usr/share/zoneinfo/Europe/Vaduz", + "/usr/share/zoneinfo/Europe/Vienna", + "/usr/share/zoneinfo/Europe/Vilnius", + "/usr/share/zoneinfo/Europe/Volgograd", + "/usr/share/zoneinfo/Europe/Warsaw", + "/usr/share/zoneinfo/Europe/Zagreb", + "/usr/share/zoneinfo/Europe/Zurich", + "/usr/share/zoneinfo/Factory", + "/usr/share/zoneinfo/Indian/Antananarivo", + "/usr/share/zoneinfo/Indian/Chagos", + "/usr/share/zoneinfo/Indian/Christmas", + "/usr/share/zoneinfo/Indian/Cocos", + "/usr/share/zoneinfo/Indian/Comoro", + "/usr/share/zoneinfo/Indian/Kerguelen", + "/usr/share/zoneinfo/Indian/Mahe", + "/usr/share/zoneinfo/Indian/Maldives", + "/usr/share/zoneinfo/Indian/Mauritius", + "/usr/share/zoneinfo/Indian/Mayotte", + "/usr/share/zoneinfo/Indian/Reunion", + "/usr/share/zoneinfo/Pacific/Apia", + "/usr/share/zoneinfo/Pacific/Auckland", + "/usr/share/zoneinfo/Pacific/Bougainville", + "/usr/share/zoneinfo/Pacific/Chatham", + "/usr/share/zoneinfo/Pacific/Chuuk", + "/usr/share/zoneinfo/Pacific/Easter", + "/usr/share/zoneinfo/Pacific/Efate", + "/usr/share/zoneinfo/Pacific/Fakaofo", + "/usr/share/zoneinfo/Pacific/Fiji", + "/usr/share/zoneinfo/Pacific/Funafuti", + "/usr/share/zoneinfo/Pacific/Galapagos", + "/usr/share/zoneinfo/Pacific/Gambier", + "/usr/share/zoneinfo/Pacific/Guadalcanal", + "/usr/share/zoneinfo/Pacific/Guam", + "/usr/share/zoneinfo/Pacific/Honolulu", + "/usr/share/zoneinfo/Pacific/Kanton", + "/usr/share/zoneinfo/Pacific/Kiritimati", + "/usr/share/zoneinfo/Pacific/Kosrae", + "/usr/share/zoneinfo/Pacific/Kwajalein", + "/usr/share/zoneinfo/Pacific/Majuro", + "/usr/share/zoneinfo/Pacific/Marquesas", + "/usr/share/zoneinfo/Pacific/Midway", + "/usr/share/zoneinfo/Pacific/Nauru", + "/usr/share/zoneinfo/Pacific/Niue", + "/usr/share/zoneinfo/Pacific/Norfolk", + "/usr/share/zoneinfo/Pacific/Noumea", + "/usr/share/zoneinfo/Pacific/Pago_Pago", + "/usr/share/zoneinfo/Pacific/Palau", + "/usr/share/zoneinfo/Pacific/Pitcairn", + "/usr/share/zoneinfo/Pacific/Pohnpei", + "/usr/share/zoneinfo/Pacific/Port_Moresby", + "/usr/share/zoneinfo/Pacific/Rarotonga", + "/usr/share/zoneinfo/Pacific/Saipan", + "/usr/share/zoneinfo/Pacific/Tahiti", + "/usr/share/zoneinfo/Pacific/Tarawa", + "/usr/share/zoneinfo/Pacific/Tongatapu", + "/usr/share/zoneinfo/Pacific/Wake", + "/usr/share/zoneinfo/Pacific/Wallis", + "/usr/share/zoneinfo/iso3166.tab", + "/usr/share/zoneinfo/leap-seconds.list", + "/usr/share/zoneinfo/leapseconds", + "/usr/share/zoneinfo/tzdata.zi", + "/usr/share/zoneinfo/zone.tab", + "/usr/share/zoneinfo/zone1970.tab", + "/usr/share/zoneinfo/zonenow.tab" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "util-linux@2.41.5-0+deb13u1", + "Name": "util-linux", + "Identifier": { + "PURL": "pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "e4d9863928456765" + }, + "Version": "2.41.5", + "Release": "0+deb13u1", + "Arch": "amd64", + "SrcName": "util-linux", + "SrcVersion": "2.41.5", + "SrcRelease": "0+deb13u1", + "Licenses": [ + "GPL-2.0-or-later", + "GPL-2.0-only", + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "public-domain", + "BSD-4-Clause", + "MIT", + "ISC", + "BSD-3-Clause", + "BSLA", + "LGPL-2.0-or-later", + "BSD-2-Clause", + "LGPL-3.0-or-later", + "GPL-3.0-only", + "LGPL-2.0-only", + "LGPL-2.1-only", + "LGPL-3.0-only" + ], + "Maintainer": "Chris Hofstaedtler \u003czeha@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/bin/choom", + "/usr/bin/chrt", + "/usr/bin/dmesg", + "/usr/bin/fallocate", + "/usr/bin/findmnt", + "/usr/bin/flock", + "/usr/bin/getopt", + "/usr/bin/hardlink", + "/usr/bin/ionice", + "/usr/bin/ipcmk", + "/usr/bin/ipcrm", + "/usr/bin/ipcs", + "/usr/bin/lsblk", + "/usr/bin/lscpu", + "/usr/bin/lsipc", + "/usr/bin/lslocks", + "/usr/bin/lslogins", + "/usr/bin/lsmem", + "/usr/bin/lsns", + "/usr/bin/mcookie", + "/usr/bin/more", + "/usr/bin/mountpoint", + "/usr/bin/namei", + "/usr/bin/nsenter", + "/usr/bin/partx", + "/usr/bin/prlimit", + "/usr/bin/rename.ul", + "/usr/bin/rev", + "/usr/bin/setarch", + "/usr/bin/setpriv", + "/usr/bin/setsid", + "/usr/bin/setterm", + "/usr/bin/su", + "/usr/bin/taskset", + "/usr/bin/uclampset", + "/usr/bin/unshare", + "/usr/bin/wdctl", + "/usr/bin/whereis", + "/usr/lib/mime/packages/util-linux", + "/usr/lib/systemd/system/fstrim.service", + "/usr/lib/systemd/system/fstrim.timer", + "/usr/sbin/agetty", + "/usr/sbin/blkdiscard", + "/usr/sbin/blkid", + "/usr/sbin/blkzone", + "/usr/sbin/blockdev", + "/usr/sbin/chcpu", + "/usr/sbin/chmem", + "/usr/sbin/findfs", + "/usr/sbin/fsck", + "/usr/sbin/fsfreeze", + "/usr/sbin/fstrim", + "/usr/sbin/isosize", + "/usr/sbin/ldattach", + "/usr/sbin/mkfs", + "/usr/sbin/mkswap", + "/usr/sbin/pivot_root", + "/usr/sbin/readprofile", + "/usr/sbin/rtcwake", + "/usr/sbin/runuser", + "/usr/sbin/sulogin", + "/usr/sbin/swaplabel", + "/usr/sbin/switch_root", + "/usr/sbin/wipefs", + "/usr/sbin/zramctl", + "/usr/share/bash-completion/completions/blkdiscard", + "/usr/share/bash-completion/completions/blkid", + "/usr/share/bash-completion/completions/blkzone", + "/usr/share/bash-completion/completions/blockdev", + "/usr/share/bash-completion/completions/chcpu", + "/usr/share/bash-completion/completions/chmem", + "/usr/share/bash-completion/completions/chrt", + "/usr/share/bash-completion/completions/dmesg", + "/usr/share/bash-completion/completions/fallocate", + "/usr/share/bash-completion/completions/findfs", + "/usr/share/bash-completion/completions/findmnt", + "/usr/share/bash-completion/completions/flock", + "/usr/share/bash-completion/completions/fsck", + "/usr/share/bash-completion/completions/fsfreeze", + "/usr/share/bash-completion/completions/fstrim", + "/usr/share/bash-completion/completions/getopt", + "/usr/share/bash-completion/completions/hardlink", + "/usr/share/bash-completion/completions/ionice", + "/usr/share/bash-completion/completions/ipcmk", + "/usr/share/bash-completion/completions/ipcrm", + "/usr/share/bash-completion/completions/ipcs", + "/usr/share/bash-completion/completions/isosize", + "/usr/share/bash-completion/completions/ldattach", + "/usr/share/bash-completion/completions/lsblk", + "/usr/share/bash-completion/completions/lscpu", + "/usr/share/bash-completion/completions/lsipc", + "/usr/share/bash-completion/completions/lslocks", + "/usr/share/bash-completion/completions/lslogins", + "/usr/share/bash-completion/completions/lsmem", + "/usr/share/bash-completion/completions/lsns", + "/usr/share/bash-completion/completions/mcookie", + "/usr/share/bash-completion/completions/mkfs", + "/usr/share/bash-completion/completions/mkswap", + "/usr/share/bash-completion/completions/more", + "/usr/share/bash-completion/completions/mountpoint", + "/usr/share/bash-completion/completions/namei", + "/usr/share/bash-completion/completions/nsenter", + "/usr/share/bash-completion/completions/partx", + "/usr/share/bash-completion/completions/pivot_root", + "/usr/share/bash-completion/completions/prlimit", + "/usr/share/bash-completion/completions/readprofile", + "/usr/share/bash-completion/completions/rename.ul", + "/usr/share/bash-completion/completions/rev", + "/usr/share/bash-completion/completions/rtcwake", + "/usr/share/bash-completion/completions/setarch", + "/usr/share/bash-completion/completions/setpriv", + "/usr/share/bash-completion/completions/setsid", + "/usr/share/bash-completion/completions/setterm", + "/usr/share/bash-completion/completions/su", + "/usr/share/bash-completion/completions/swaplabel", + "/usr/share/bash-completion/completions/taskset", + "/usr/share/bash-completion/completions/uclampset", + "/usr/share/bash-completion/completions/unshare", + "/usr/share/bash-completion/completions/wdctl", + "/usr/share/bash-completion/completions/whereis", + "/usr/share/bash-completion/completions/wipefs", + "/usr/share/bash-completion/completions/zramctl", + "/usr/share/doc/util-linux/00-about-docs.txt", + "/usr/share/doc/util-linux/AUTHORS.gz", + "/usr/share/doc/util-linux/NEWS.Debian.gz", + "/usr/share/doc/util-linux/PAM-configuration.txt", + "/usr/share/doc/util-linux/README.Debian", + "/usr/share/doc/util-linux/blkid.txt", + "/usr/share/doc/util-linux/cal.txt", + "/usr/share/doc/util-linux/changelog.Debian.gz", + "/usr/share/doc/util-linux/changelog.gz", + "/usr/share/doc/util-linux/col.txt", + "/usr/share/doc/util-linux/copyright", + "/usr/share/doc/util-linux/deprecated.txt", + "/usr/share/doc/util-linux/examples/getopt-example.bash", + "/usr/share/doc/util-linux/getopt.txt", + "/usr/share/doc/util-linux/getopt_changelog.txt", + "/usr/share/doc/util-linux/howto-build-sys.txt", + "/usr/share/doc/util-linux/howto-compilation.txt", + "/usr/share/doc/util-linux/howto-contribute.txt.gz", + "/usr/share/doc/util-linux/howto-debug.txt", + "/usr/share/doc/util-linux/howto-man-page.txt", + "/usr/share/doc/util-linux/howto-pull-request.txt.gz", + "/usr/share/doc/util-linux/howto-tests.txt", + "/usr/share/doc/util-linux/howto-usage-function.txt.gz", + "/usr/share/doc/util-linux/hwclock.txt", + "/usr/share/doc/util-linux/modems-with-agetty.txt", + "/usr/share/doc/util-linux/mount.txt", + "/usr/share/doc/util-linux/parse-date.txt.gz", + "/usr/share/doc/util-linux/pg.txt", + "/usr/share/doc/util-linux/poeigl.txt.gz", + "/usr/share/doc/util-linux/release-schedule.txt", + "/usr/share/doc/util-linux/releases/v2.13-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.14-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.15-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.16-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.17-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.18-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.19-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.20-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.21-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.22-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.23-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.24-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.25-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.26-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.27-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.28-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.29-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.30-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.31-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.32-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.33-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.34-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.35-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.36-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.37-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.38-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.39-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.40-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.41-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.41.1-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.41.2-ReleaseNotes.gz", + "/usr/share/doc/util-linux/releases/v2.41.3-ReleaseNotes", + "/usr/share/doc/util-linux/releases/v2.41.4-ReleaseNotes", + "/usr/share/doc/util-linux/releases/v2.41.5-ReleaseNotes", + "/usr/share/lintian/overrides/util-linux", + "/usr/share/man/man1/choom.1.gz", + "/usr/share/man/man1/chrt.1.gz", + "/usr/share/man/man1/dmesg.1.gz", + "/usr/share/man/man1/fallocate.1.gz", + "/usr/share/man/man1/flock.1.gz", + "/usr/share/man/man1/getopt.1.gz", + "/usr/share/man/man1/hardlink.1.gz", + "/usr/share/man/man1/ionice.1.gz", + "/usr/share/man/man1/ipcmk.1.gz", + "/usr/share/man/man1/ipcrm.1.gz", + "/usr/share/man/man1/ipcs.1.gz", + "/usr/share/man/man1/lscpu.1.gz", + "/usr/share/man/man1/lsipc.1.gz", + "/usr/share/man/man1/lslogins.1.gz", + "/usr/share/man/man1/lsmem.1.gz", + "/usr/share/man/man1/mcookie.1.gz", + "/usr/share/man/man1/more.1.gz", + "/usr/share/man/man1/mountpoint.1.gz", + "/usr/share/man/man1/namei.1.gz", + "/usr/share/man/man1/nsenter.1.gz", + "/usr/share/man/man1/prlimit.1.gz", + "/usr/share/man/man1/rename.ul.1.gz", + "/usr/share/man/man1/rev.1.gz", + "/usr/share/man/man1/runuser.1.gz", + "/usr/share/man/man1/setpriv.1.gz", + "/usr/share/man/man1/setsid.1.gz", + "/usr/share/man/man1/setterm.1.gz", + "/usr/share/man/man1/su.1.gz", + "/usr/share/man/man1/taskset.1.gz", + "/usr/share/man/man1/uclampset.1.gz", + "/usr/share/man/man1/unshare.1.gz", + "/usr/share/man/man1/whereis.1.gz", + "/usr/share/man/man5/adjtime_config.5.gz", + "/usr/share/man/man5/scols-filter.5.gz", + "/usr/share/man/man5/terminal-colors.d.5.gz", + "/usr/share/man/man8/agetty.8.gz", + "/usr/share/man/man8/blkdiscard.8.gz", + "/usr/share/man/man8/blkid.8.gz", + "/usr/share/man/man8/blkzone.8.gz", + "/usr/share/man/man8/blockdev.8.gz", + "/usr/share/man/man8/chcpu.8.gz", + "/usr/share/man/man8/chmem.8.gz", + "/usr/share/man/man8/findfs.8.gz", + "/usr/share/man/man8/findmnt.8.gz", + "/usr/share/man/man8/fsck.8.gz", + "/usr/share/man/man8/fsfreeze.8.gz", + "/usr/share/man/man8/fstrim.8.gz", + "/usr/share/man/man8/isosize.8.gz", + "/usr/share/man/man8/ldattach.8.gz", + "/usr/share/man/man8/lsblk.8.gz", + "/usr/share/man/man8/lslocks.8.gz", + "/usr/share/man/man8/lsns.8.gz", + "/usr/share/man/man8/mkfs.8.gz", + "/usr/share/man/man8/mkswap.8.gz", + "/usr/share/man/man8/partx.8.gz", + "/usr/share/man/man8/pivot_root.8.gz", + "/usr/share/man/man8/readprofile.8.gz", + "/usr/share/man/man8/rtcwake.8.gz", + "/usr/share/man/man8/setarch.8.gz", + "/usr/share/man/man8/sulogin.8.gz", + "/usr/share/man/man8/swaplabel.8.gz", + "/usr/share/man/man8/switch_root.8.gz", + "/usr/share/man/man8/wdctl.8.gz", + "/usr/share/man/man8/wipefs.8.gz", + "/usr/share/man/man8/zramctl.8.gz", + "/usr/share/util-linux/logcheck/ignore.d.server/util-linux" + ], + "AnalyzedBy": "dpkg" + }, + { + "ID": "zlib1g@1:1.3.dfsg+really1.3.1-1+b1", + "Name": "zlib1g", + "Identifier": { + "PURL": "pkg:deb/debian/zlib1g@1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "ff182eb2a26a8142" + }, + "Version": "1.3.dfsg+really1.3.1", + "Release": "1+b1", + "Epoch": 1, + "Arch": "amd64", + "SrcName": "zlib", + "SrcVersion": "1.3.dfsg+really1.3.1", + "SrcRelease": "1", + "SrcEpoch": 1, + "Licenses": [ + "Zlib" + ], + "Maintainer": "Mark Brown \u003cbroonie@debian.org\u003e", + "Repository": { + "Class": "official" + }, + "DependsOn": [ + "libc6@2.41-12+deb13u3" + ], + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "InstalledFiles": [ + "/usr/lib/x86_64-linux-gnu/libz.so.1.3.1", + "/usr/share/doc/zlib1g/changelog.Debian.amd64.gz", + "/usr/share/doc/zlib1g/changelog.Debian.gz", + "/usr/share/doc/zlib1g/changelog.gz", + "/usr/share/doc/zlib1g/copyright" + ], + "AnalyzedBy": "dpkg" + } + ], + "Vulnerabilities": [ + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "bsdutils@1:2.41.5-0+deb13u1", + "PkgName": "bsdutils", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/bsdutils@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "a4b47561565a3535" + }, + "InstalledVersion": "1:2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:a2d1c270226534ec916ea9249e6a0bc85a70051edfa41e592bf91fd2e2c28549", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "bsdutils@1:2.41.5-0+deb13u1", + "PkgName": "bsdutils", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/bsdutils@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "a4b47561565a3535" + }, + "InstalledVersion": "1:2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:62e7d5020a73e39a16c162b01be62526603ef020b1a059c96eaee07d1951982e", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "bsdutils@1:2.41.5-0+deb13u1", + "PkgName": "bsdutils", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/bsdutils@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "a4b47561565a3535" + }, + "InstalledVersion": "1:2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:664d5d5ceb7cb8f0a35587c84f935546fc92a7d163d920b44fa8eecdeb5f2153", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "bsdutils@1:2.41.5-0+deb13u1", + "PkgName": "bsdutils", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/bsdutils@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "a4b47561565a3535" + }, + "InstalledVersion": "1:2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:09eab25b686cdb3fd087c9ad91aebf7535c7f4c5e1ece9782b4628b5dd7e0629", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-41992", + "PkgID": "gzip@1.13-1", + "PkgName": "gzip", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/gzip@1.13-1?arch=amd64\u0026distro=debian-13.6", + "UID": "954545ce99bc687e" + }, + "InstalledVersion": "1.13-1", + "FixedVersion": "1.13-1+deb13u1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-41992", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:fdbfd173f3afe7ed330cb3dd1086db04c048785a62606ad1c79c715a25692d3b", + "Title": "gzip: gzip: Information disclosure via global buffer overflow in LZH decompression", + "Description": "GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-126" + ], + "VendorSeverity": { + "alma": 2, + "azure": 2, + "julia": 2, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 1, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", + "V3Score": 7.5, + "V40Score": 6.9 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L", + "V3Score": 3.6 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/08/23/1", + "http://www.openwall.com/lists/oss-security/2026/08/25/1", + "http://www.openwall.com/lists/oss-security/2026/08/27/2", + "https://access.redhat.com/errata/RHSA-2026:61623", + "https://access.redhat.com/errata/RHSA-2026:65998", + "https://access.redhat.com/security/cve/CVE-2026-41992", + "https://bugzilla.redhat.com/2494158", + "https://bugzilla.redhat.com/show_bug.cgi?id=2494158", + "https://bugzilla.redhat.com/show_bug.cgi?id=2494159", + "https://cert.pl/en/posts/2026/04/CVE-2026-41991", + "https://cert.pl/en/posts/2026/04/CVE-2026-41991/", + "https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681", + "https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=e7378c2d421be6a286922374425680bbe9ad8b7d", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41991", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41992", + "https://errata.almalinux.org/8/ALSA-2026-65998.html", + "https://errata.rockylinux.org/RLSA-2026:61623", + "https://github.com/advisories/GHSA-qxh4-rprf-2mmj", + "https://linux.oracle.com/cve/CVE-2026-41992.html", + "https://linux.oracle.com/errata/ELSA-2026-65998-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-41992", + "https://ubuntu.com/security/notices/USN-8512-1", + "https://ubuntu.com/security/notices/USN-8733-1", + "https://www.cve.org/CVERecord?id=CVE-2026-41992", + "https://www.gnu.org/software/gzip", + "https://www.gnu.org/software/gzip/" + ], + "PublishedDate": "2026-06-29T12:16:29.94Z", + "LastModifiedDate": "2026-08-27T13:17:57.967Z" + }, + { + "VulnerabilityID": "CVE-2026-54369", + "PkgID": "libacl1@2.3.2-2+b1", + "PkgName": "libacl1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libacl1@2.3.2-2%2Bb1?arch=amd64\u0026distro=debian-13.6", + "UID": "f9f7789d147b9636" + }, + "InstalledVersion": "2.3.2-2+b1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-54369", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:64a0b95bafcd809cbe0d97e1b99fdc8e2df495f23204b6df9363e8108408aa4f", + "Title": "acl: Symlink traversal privilege escalation via libacl functions", + "Description": "acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:34351", + "https://access.redhat.com/errata/RHSA-2026:42736", + "https://access.redhat.com/errata/RHSA-2026:42739", + "https://access.redhat.com/errata/RHSA-2026:43420", + "https://access.redhat.com/errata/RHSA-2026:44481", + "https://access.redhat.com/errata/RHSA-2026:46836", + "https://access.redhat.com/errata/RHSA-2026:50205", + "https://access.redhat.com/errata/RHSA-2026:53371", + "https://access.redhat.com/errata/RHSA-2026:54769", + "https://access.redhat.com/errata/RHSA-2026:58981", + "https://access.redhat.com/errata/RHSA-2026:64805", + "https://access.redhat.com/errata/RHSA-2026:67140", + "https://access.redhat.com/errata/RHSA-2026:67142", + "https://access.redhat.com/errata/RHSA-2026:67144", + "https://access.redhat.com/security/cve/CVE-2026-54369", + "https://bugzilla.redhat.com/2490277", + "https://bugzilla.redhat.com/2490279", + "https://bugzilla.redhat.com/show_bug.cgi?id=2490277", + "https://bugzilla.redhat.com/show_bug.cgi?id=2490279", + "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5", + "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54369", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54370", + "https://errata.almalinux.org/8/ALSA-2026-43420.html", + "https://errata.rockylinux.org/RLSA-2026:42736", + "https://linux.oracle.com/cve/CVE-2026-54369.html", + "https://linux.oracle.com/errata/ELSA-2026-43420.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-54369", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json", + "https://www.cve.org/CVERecord?id=CVE-2026-54369", + "https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions" + ], + "PublishedDate": "2026-06-29T14:16:57.487Z", + "LastModifiedDate": "2026-09-14T13:18:40.197Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "libblkid1@2.41.5-0+deb13u1", + "PkgName": "libblkid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "57ce331079f40f84" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:1067d847b465237227373f650f0f963c235dd4b05aafe802b137542b1834a4a6", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "libblkid1@2.41.5-0+deb13u1", + "PkgName": "libblkid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "57ce331079f40f84" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:d30e88b46f26f95ab15cb46c490617daadf34978372c81fe2b5b5c2436dccc93", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "libblkid1@2.41.5-0+deb13u1", + "PkgName": "libblkid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "57ce331079f40f84" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:876d56389d6c9e33a2ece93a11be7262da15e88df36d9442f7aae029ae55a3b8", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "libblkid1@2.41.5-0+deb13u1", + "PkgName": "libblkid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "57ce331079f40f84" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:15ce2e72ee15943dbf5fdd823e4d11758b1f351cdb0dc20222d573f79b50a657", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "liblastlog2-2@2.41.5-0+deb13u1", + "PkgName": "liblastlog2-2", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "9b0fe2f2c9e6f842" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:708ebfa5e70e1b8c0815786974a8fe0f4e76c08bcc9f779f28cd8ff44f3f5e80", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "liblastlog2-2@2.41.5-0+deb13u1", + "PkgName": "liblastlog2-2", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "9b0fe2f2c9e6f842" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:2adb3a31008e4d8dab28179755761a1bda94973ef36ea2061652e00496eeba9d", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "liblastlog2-2@2.41.5-0+deb13u1", + "PkgName": "liblastlog2-2", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "9b0fe2f2c9e6f842" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:8bc0f5e9f96d8eb5c6454b3d5160e63587b99013727fc0007ebe5e20d878d087", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "liblastlog2-2@2.41.5-0+deb13u1", + "PkgName": "liblastlog2-2", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "9b0fe2f2c9e6f842" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:cef8f31ae4f375b0a8b3324e3232514b1b0afbcfae19e91631c5b73de8e84cc0", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "libmount1@2.41.5-0+deb13u1", + "PkgName": "libmount1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "b26c2651b95c08c5" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:b46b307c707fdeeccaef81a5e12aa42c99fb8ae0475c165450a2acc8a2507b37", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "libmount1@2.41.5-0+deb13u1", + "PkgName": "libmount1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "b26c2651b95c08c5" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:fa5eccff045d75b7701f85d40dc37158cd48a2b40098ab5f3d4cae9fce542325", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "libmount1@2.41.5-0+deb13u1", + "PkgName": "libmount1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "b26c2651b95c08c5" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:35c674c9cb8aad4fe4821220303eddb7bbc31b593b858f20adc8dac89b9e26a7", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "libmount1@2.41.5-0+deb13u1", + "PkgName": "libmount1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "b26c2651b95c08c5" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:9efa7294283568517778067ae3112bda8cedd1eaca9178231da64eaa83fdb62a", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2025-69720", + "PkgID": "libncursesw6@6.5+20250216-2", + "PkgName": "libncursesw6", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libncursesw6@6.5%2B20250216-2?arch=amd64\u0026distro=debian-13.6", + "UID": "5efa2a2068c240d8" + }, + "InstalledVersion": "6.5+20250216-2", + "Status": "affected", + "Layer": { + "Digest": "sha256:1560cfed01dc4c72c07f789d860078d74466a1f9a26b33a2e35d887b5f90dd3f", + "DiffID": "sha256:3d664d274420a79749a26f9e5115b2120d46037264011773ca4c52e22780b2ca" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-69720", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:7de1605a2d588060f89e8af07469e2472effcc1b265f796b1fda578f7a47d6ac", + "Title": "ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.", + "Description": "The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-121", + "CWE-120" + ], + "VendorSeverity": { + "alma": 2, + "azure": 4, + "cbl-mariner": 4, + "julia": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:5913", + "https://access.redhat.com/security/cve/CVE-2025-69720", + "https://bugzilla.redhat.com/2449037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2449037", + "https://cert-portal.siemens.com/productcert/html/ssa-253495.html", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69720", + "https://errata.almalinux.org/10/ALSA-2026-5913.html", + "https://errata.rockylinux.org/RLSA-2026:5913", + "https://github.com/Cao-Wuhui/CVE-2025-69720", + "https://github.com/advisories/GHSA-9952-mrqj-h4jh", + "https://invisible-island.net/archives/ncurses/6.5", + "https://invisible-island.net/archives/ncurses/6.5/", + "https://invisible-island.net/ncurses", + "https://invisible-island.net/ncurses/", + "https://linux.oracle.com/cve/CVE-2025-69720.html", + "https://linux.oracle.com/errata/ELSA-2026-5913.html", + "https://marc.info/?l=ncurses-bug\u0026m=176539968328570\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176540731801330\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176545557728083\u0026w=2", + "https://nvd.nist.gov/vuln/detail/CVE-2025-69720", + "https://ubuntu.com/security/notices/USN-8503-1", + "https://www.cve.org/CVERecord?id=CVE-2025-69720" + ], + "PublishedDate": "2026-03-19T15:16:21.293Z", + "LastModifiedDate": "2026-06-17T10:00:50.423Z" + }, + { + "VulnerabilityID": "CVE-2026-86145", + "PkgID": "libpcre2-8-0@10.46-1~deb13u1", + "PkgName": "libpcre2-8-0", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "aa7e3a6ab471d889" + }, + "InstalledVersion": "10.46-1~deb13u1", + "FixedVersion": "10.46-1~deb13u2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-86145", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:a2bbeb1deacbeef6cadf9d56caa7077c3ffdf81f50ac1c7215dd0f4749f96b18", + "Title": "pcre2: PCRE2: Out-of-bounds write allows arbitrary code execution via crafted regular expressions", + "Description": "PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-424" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L", + "V3Score": 8.2 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/3", + "https://access.redhat.com/security/cve/CVE-2026-86145", + "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48", + "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf", + "https://nvd.nist.gov/vuln/detail/CVE-2026-86145", + "https://www.cve.org/CVERecord?id=CVE-2026-86145" + ], + "PublishedDate": "2026-09-05T06:17:10.37Z", + "LastModifiedDate": "2026-09-09T16:04:24.933Z" + }, + { + "VulnerabilityID": "CVE-2026-89161", + "PkgID": "libpcre2-8-0@10.46-1~deb13u1", + "PkgName": "libpcre2-8-0", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "aa7e3a6ab471d889" + }, + "InstalledVersion": "10.46-1~deb13u1", + "FixedVersion": "10.46-1~deb13u2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-89161", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:ea666ad3fdf871523c5e956672d623ea61ee73065f4d62a4bc63d1df4bb7b5d9", + "Title": "pcre2: PCRE2: Memory corruption vulnerability in pcre2_jit_match", + "Description": "In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-590" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-89161", + "https://github.com/PCRE2Project/pcre2/pull/937", + "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48", + "https://nvd.nist.gov/vuln/detail/CVE-2026-89161", + "https://www.cve.org/CVERecord?id=CVE-2026-89161" + ], + "PublishedDate": "2026-09-11T04:18:04.47Z", + "LastModifiedDate": "2026-09-11T20:19:22.947Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "libsmartcols1@2.41.5-0+deb13u1", + "PkgName": "libsmartcols1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "20af24e636963c71" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:822d92892b110bdb8231a52bda5b265c2687fe66eccf6842d32f2561b8d2d103", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "libsmartcols1@2.41.5-0+deb13u1", + "PkgName": "libsmartcols1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "20af24e636963c71" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:4f711f11526e4faa474e4810089423767aa8089c0e69eb727f545fc39d0f3e24", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "libsmartcols1@2.41.5-0+deb13u1", + "PkgName": "libsmartcols1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "20af24e636963c71" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:c4f1419222389da3c9d15fd02d93ffb305018b76379970546858d0168ff468ff", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "libsmartcols1@2.41.5-0+deb13u1", + "PkgName": "libsmartcols1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "20af24e636963c71" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:2b9bf71d9d1fc1e61f35eac1adce8b1fae1a6f31e8648a6bed5eacbd73802972", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-11822", + "PkgID": "libsqlite3-0@3.46.1-7+deb13u1", + "PkgName": "libsqlite3-0", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "c7da287e696e8198" + }, + "InstalledVersion": "3.46.1-7+deb13u1", + "FixedVersion": "3.46.1-7+deb13u2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-11822", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:8088dc5f80323964548541e8a4f50d70a4b923f6dbab1c1c31c2625a01bb4ced", + "Title": "sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data", + "Description": "SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-122" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:58936", + "https://access.redhat.com/errata/RHSA-2026:61242", + "https://access.redhat.com/security/cve/CVE-2026-11822", + "https://bugzilla.redhat.com/2487258", + "https://bugzilla.redhat.com/show_bug.cgi?id=2487258", + "https://bugzilla.redhat.com/show_bug.cgi?id=2487269", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11822", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11824", + "https://errata.almalinux.org/8/ALSA-2026-61242.html", + "https://errata.rockylinux.org/RLSA-2026:58936", + "https://linux.oracle.com/cve/CVE-2026-11822.html", + "https://linux.oracle.com/errata/ELSA-2026-61242-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-11822", + "https://sqlite.org/releaselog/3_53_2.html", + "https://sqlite.org/src/info/061febcf41ca", + "https://sqlite.org/src/info/4a5ad516ea93", + "https://ubuntu.com/security/notices/USN-8480-1", + "https://www.cve.org/CVERecord?id=CVE-2026-11822", + "https://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension" + ], + "PublishedDate": "2026-06-09T20:16:32.15Z", + "LastModifiedDate": "2026-07-23T09:10:00.113Z" + }, + { + "VulnerabilityID": "CVE-2026-11824", + "PkgID": "libsqlite3-0@3.46.1-7+deb13u1", + "PkgName": "libsqlite3-0", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "c7da287e696e8198" + }, + "InstalledVersion": "3.46.1-7+deb13u1", + "FixedVersion": "3.46.1-7+deb13u2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-11824", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:c6fe27d25815c9189667320416b5bc37abf321c18eb9e33aa4906a5de1a606c4", + "Title": "sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5", + "Description": "SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-122" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:58936", + "https://access.redhat.com/errata/RHSA-2026:58938", + "https://access.redhat.com/security/cve/CVE-2026-11824", + "https://bugzilla.redhat.com/show_bug.cgi?id=2487258", + "https://bugzilla.redhat.com/show_bug.cgi?id=2487269", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11822", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11824", + "https://errata.almalinux.org/8/ALSA-2026-58938.html", + "https://errata.rockylinux.org/RLSA-2026:58936", + "https://linux.oracle.com/cve/CVE-2026-11824.html", + "https://linux.oracle.com/errata/ELSA-2026-58938.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-11824", + "https://sqlite.org/releaselog/3_53_2.html", + "https://sqlite.org/src/info/061febcf41ca", + "https://sqlite.org/src/info/4a5ad516ea93", + "https://ubuntu.com/security/notices/USN-8480-1", + "https://www.cve.org/CVERecord?id=CVE-2026-11824", + "https://www.vulncheck.com/advisories/sqlite-before-heap-buffer-overflow-via-fts5-fts5chunkiterate" + ], + "PublishedDate": "2026-06-09T20:16:32.3Z", + "LastModifiedDate": "2026-07-23T09:10:00.113Z" + }, + { + "VulnerabilityID": "CVE-2026-16742", + "PkgID": "libsystemd0@257.13-1~deb13u1", + "PkgName": "libsystemd0", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "a2b4ba47389f858e" + }, + "InstalledVersion": "257.13-1~deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-16742", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:3ccf1ca2c6a0dec24df7d39f753700cd65b528fbb091c953d51db0c4cb95e306", + "Title": "systemd: systemd-homed: Local privilege escalation via missing home-record signature verification", + "Description": "systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user", + "Severity": "HIGH", + "CweIDs": [ + "CWE-269", + "CWE-347" + ], + "VendorSeverity": { + "azure": 2, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-16742", + "https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-16742", + "https://ubuntu.com/security/notices/USN-8626-1", + "https://www.cve.org/CVERecord?id=CVE-2026-16742" + ], + "PublishedDate": "2026-08-10T14:17:21.277Z", + "LastModifiedDate": "2026-09-01T20:54:51.287Z" + }, + { + "VulnerabilityID": "CVE-2025-69720", + "PkgID": "libtinfo6@6.5+20250216-2", + "PkgName": "libtinfo6", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64\u0026distro=debian-13.6", + "UID": "ba2c2b464f07108a" + }, + "InstalledVersion": "6.5+20250216-2", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-69720", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:8945a4617779a478f5dca0e98fe0cccda757bd190234c4df9d99ed9b098d168c", + "Title": "ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.", + "Description": "The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-121", + "CWE-120" + ], + "VendorSeverity": { + "alma": 2, + "azure": 4, + "cbl-mariner": 4, + "julia": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:5913", + "https://access.redhat.com/security/cve/CVE-2025-69720", + "https://bugzilla.redhat.com/2449037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2449037", + "https://cert-portal.siemens.com/productcert/html/ssa-253495.html", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69720", + "https://errata.almalinux.org/10/ALSA-2026-5913.html", + "https://errata.rockylinux.org/RLSA-2026:5913", + "https://github.com/Cao-Wuhui/CVE-2025-69720", + "https://github.com/advisories/GHSA-9952-mrqj-h4jh", + "https://invisible-island.net/archives/ncurses/6.5", + "https://invisible-island.net/archives/ncurses/6.5/", + "https://invisible-island.net/ncurses", + "https://invisible-island.net/ncurses/", + "https://linux.oracle.com/cve/CVE-2025-69720.html", + "https://linux.oracle.com/errata/ELSA-2026-5913.html", + "https://marc.info/?l=ncurses-bug\u0026m=176539968328570\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176540731801330\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176545557728083\u0026w=2", + "https://nvd.nist.gov/vuln/detail/CVE-2025-69720", + "https://ubuntu.com/security/notices/USN-8503-1", + "https://www.cve.org/CVERecord?id=CVE-2025-69720" + ], + "PublishedDate": "2026-03-19T15:16:21.293Z", + "LastModifiedDate": "2026-06-17T10:00:50.423Z" + }, + { + "VulnerabilityID": "CVE-2026-16742", + "PkgID": "libudev1@257.13-1~deb13u1", + "PkgName": "libudev1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "3b7a2f1a9ab169b" + }, + "InstalledVersion": "257.13-1~deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-16742", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:fe6dba7926aa8025ef93ae0bc23398938eadaa9072d398b9f5de60a3db9fa239", + "Title": "systemd: systemd-homed: Local privilege escalation via missing home-record signature verification", + "Description": "systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user", + "Severity": "HIGH", + "CweIDs": [ + "CWE-269", + "CWE-347" + ], + "VendorSeverity": { + "azure": 2, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 8.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-16742", + "https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-16742", + "https://ubuntu.com/security/notices/USN-8626-1", + "https://www.cve.org/CVERecord?id=CVE-2026-16742" + ], + "PublishedDate": "2026-08-10T14:17:21.277Z", + "LastModifiedDate": "2026-09-01T20:54:51.287Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "libuuid1@2.41.5-0+deb13u1", + "PkgName": "libuuid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "67cba3b022acab2f" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:3655116481a022674a1efe79b2153c042780fbfd613a95a2192727616cd34106", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "libuuid1@2.41.5-0+deb13u1", + "PkgName": "libuuid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "67cba3b022acab2f" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:70ca5009d5ac07c03abdcf053edc9110d7a11240a721199d864efed8c568d5ca", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "libuuid1@2.41.5-0+deb13u1", + "PkgName": "libuuid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "67cba3b022acab2f" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:285435ad1ec84c8eb64c07aadb7ff438f8cc6d06abc8509054cea8c1f197beb1", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "libuuid1@2.41.5-0+deb13u1", + "PkgName": "libuuid1", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "67cba3b022acab2f" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:1464a2ed03e0528566230d9c21f436b4deb11662badb68c442928fab8a9bed97", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "login@1:4.16.0-2+really2.41.5-0+deb13u1", + "PkgName": "login", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/login@4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "10626ee86f1b653f" + }, + "InstalledVersion": "1:4.16.0-2+really2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:a83c4c8dd38720ded5157641916b39919f66a47f1ab7b72907821a3545348dfb", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "login@1:4.16.0-2+really2.41.5-0+deb13u1", + "PkgName": "login", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/login@4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "10626ee86f1b653f" + }, + "InstalledVersion": "1:4.16.0-2+really2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:e9eb292127cafba35f16b26b45b03660c9cfa23257a14b1885f65e182b81404c", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "login@1:4.16.0-2+really2.41.5-0+deb13u1", + "PkgName": "login", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/login@4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "10626ee86f1b653f" + }, + "InstalledVersion": "1:4.16.0-2+really2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:144e499297f5d61a83f096c88a162911ea116753f8a6c3d2d415e8125647dba3", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "login@1:4.16.0-2+really2.41.5-0+deb13u1", + "PkgName": "login", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/login@4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6\u0026epoch=1", + "UID": "10626ee86f1b653f" + }, + "InstalledVersion": "1:4.16.0-2+really2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:72a3ab1c739ee52e2fb67eb57589dd3c881d0b159797a757fbaa6f4a99bef5e0", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "mount@2.41.5-0+deb13u1", + "PkgName": "mount", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "d781ec5616a75c78" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:8903168bbd7f286e9eac2d671da4122515ebdad94ee4d34b80787bdba8e95a80", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "mount@2.41.5-0+deb13u1", + "PkgName": "mount", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "d781ec5616a75c78" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:7ffd5ff173d50f5d3060b557841135c235de046f5d43497585cfadc78ab57827", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "mount@2.41.5-0+deb13u1", + "PkgName": "mount", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "d781ec5616a75c78" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:83821aad0cf7915dad158f2a79355e2949cb3776cb1425259ea9c55bf27ab86a", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "mount@2.41.5-0+deb13u1", + "PkgName": "mount", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "d781ec5616a75c78" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:ee6c2bbba2e5057d3d00cb989be16e50ea5eb2da6a8a4cd1acced5713570208c", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2025-69720", + "PkgID": "ncurses-base@6.5+20250216-2", + "PkgName": "ncurses-base", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all\u0026distro=debian-13.6", + "UID": "767a0231348a5cb5" + }, + "InstalledVersion": "6.5+20250216-2", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-69720", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:5e5d052aeebc94af408aec21121890ddde8e9534c0826fc385e8bd049551fa96", + "Title": "ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.", + "Description": "The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-121", + "CWE-120" + ], + "VendorSeverity": { + "alma": 2, + "azure": 4, + "cbl-mariner": 4, + "julia": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:5913", + "https://access.redhat.com/security/cve/CVE-2025-69720", + "https://bugzilla.redhat.com/2449037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2449037", + "https://cert-portal.siemens.com/productcert/html/ssa-253495.html", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69720", + "https://errata.almalinux.org/10/ALSA-2026-5913.html", + "https://errata.rockylinux.org/RLSA-2026:5913", + "https://github.com/Cao-Wuhui/CVE-2025-69720", + "https://github.com/advisories/GHSA-9952-mrqj-h4jh", + "https://invisible-island.net/archives/ncurses/6.5", + "https://invisible-island.net/archives/ncurses/6.5/", + "https://invisible-island.net/ncurses", + "https://invisible-island.net/ncurses/", + "https://linux.oracle.com/cve/CVE-2025-69720.html", + "https://linux.oracle.com/errata/ELSA-2026-5913.html", + "https://marc.info/?l=ncurses-bug\u0026m=176539968328570\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176540731801330\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176545557728083\u0026w=2", + "https://nvd.nist.gov/vuln/detail/CVE-2025-69720", + "https://ubuntu.com/security/notices/USN-8503-1", + "https://www.cve.org/CVERecord?id=CVE-2025-69720" + ], + "PublishedDate": "2026-03-19T15:16:21.293Z", + "LastModifiedDate": "2026-06-17T10:00:50.423Z" + }, + { + "VulnerabilityID": "CVE-2025-69720", + "PkgID": "ncurses-bin@6.5+20250216-2", + "PkgName": "ncurses-bin", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64\u0026distro=debian-13.6", + "UID": "5b541563cf6587e5" + }, + "InstalledVersion": "6.5+20250216-2", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-69720", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:4018b926772de11956c0329ca04237986ae9f1a9f0a6dd33e1a1f44b7004b2b3", + "Title": "ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.", + "Description": "The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-121", + "CWE-120" + ], + "VendorSeverity": { + "alma": 2, + "azure": 4, + "cbl-mariner": 4, + "julia": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:5913", + "https://access.redhat.com/security/cve/CVE-2025-69720", + "https://bugzilla.redhat.com/2449037", + "https://bugzilla.redhat.com/show_bug.cgi?id=2449037", + "https://cert-portal.siemens.com/productcert/html/ssa-253495.html", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-69720", + "https://errata.almalinux.org/10/ALSA-2026-5913.html", + "https://errata.rockylinux.org/RLSA-2026:5913", + "https://github.com/Cao-Wuhui/CVE-2025-69720", + "https://github.com/advisories/GHSA-9952-mrqj-h4jh", + "https://invisible-island.net/archives/ncurses/6.5", + "https://invisible-island.net/archives/ncurses/6.5/", + "https://invisible-island.net/ncurses", + "https://invisible-island.net/ncurses/", + "https://linux.oracle.com/cve/CVE-2025-69720.html", + "https://linux.oracle.com/errata/ELSA-2026-5913.html", + "https://marc.info/?l=ncurses-bug\u0026m=176539968328570\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176540731801330\u0026w=2", + "https://marc.info/?l=ncurses-bug\u0026m=176545557728083\u0026w=2", + "https://nvd.nist.gov/vuln/detail/CVE-2025-69720", + "https://ubuntu.com/security/notices/USN-8503-1", + "https://www.cve.org/CVERecord?id=CVE-2025-69720" + ], + "PublishedDate": "2026-03-19T15:16:21.293Z", + "LastModifiedDate": "2026-06-17T10:00:50.423Z" + }, + { + "VulnerabilityID": "CVE-2026-13221", + "PkgID": "perl-base@5.40.1-6", + "PkgName": "perl-base", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/perl-base@5.40.1-6?arch=amd64\u0026distro=debian-13.6", + "UID": "546ba1bdcd66d61" + }, + "InstalledVersion": "5.40.1-6", + "FixedVersion": "5.40.1-6+deb13u1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-13221", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:9823a4ccef510e7549b33be1e58db52773542dbfe4c9b37bd3ce86ebcfd7605f", + "Title": "perl: Perl: Incorrect regular expression processing via large regular expressions", + "Description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-190" + ], + "VendorSeverity": { + "azure": 2, + "nvd": 4, + "oracle-oval": 2, + "photon": 4, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N", + "V3Score": 5.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/07/13/5", + "https://access.redhat.com/errata/RHSA-2026:67278", + "https://access.redhat.com/security/cve/CVE-2026-13221", + "https://bugzilla.redhat.com/show_bug.cgi?id=2499727", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13221", + "https://errata.rockylinux.org/RLSA-2026:67278", + "https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch", + "https://github.com/Perl/perl5/issues/23388", + "https://linux.oracle.com/cve/CVE-2026-13221.html", + "https://linux.oracle.com/errata/ELSA-2026-67156-0.html", + "https://lists.security.metacpan.org/cve-announce/msg/41780104/", + "https://nvd.nist.gov/vuln/detail/CVE-2026-13221", + "https://ubuntu.com/security/notices/USN-8675-1", + "https://ubuntu.com/security/notices/USN-8675-2", + "https://ubuntu.com/security/notices/USN-8684-1", + "https://www.cve.org/CVERecord?id=CVE-2026-13221" + ], + "PublishedDate": "2026-07-13T17:16:48.923Z", + "LastModifiedDate": "2026-09-08T22:17:37.217Z" + }, + { + "VulnerabilityID": "CVE-2026-42496", + "PkgID": "perl-base@5.40.1-6", + "PkgName": "perl-base", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/perl-base@5.40.1-6?arch=amd64\u0026distro=debian-13.6", + "UID": "546ba1bdcd66d61" + }, + "InstalledVersion": "5.40.1-6", + "FixedVersion": "5.40.1-6+deb13u1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42496", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:1b82bde40db331610ce022931529bba92f8c18f47eddecab01fd95e5964ed44c", + "Title": "perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access", + "Description": "Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-59", + "CWE-22" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "nvd": 4, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:30851", + "https://access.redhat.com/errata/RHSA-2026:30852", + "https://access.redhat.com/errata/RHSA-2026:30856", + "https://access.redhat.com/errata/RHSA-2026:30857", + "https://access.redhat.com/security/cve/CVE-2026-42496", + "https://bugzilla.redhat.com/2481314", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481314", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42496", + "https://errata.almalinux.org/8/ALSA-2026-30852.html", + "https://errata.rockylinux.org/RLSA-2026:30856", + "https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch", + "https://linux.oracle.com/cve/CVE-2026-42496.html", + "https://linux.oracle.com/errata/ELSA-2026-30857.html", + "https://lists.security.metacpan.org/cve-announce/msg/40396459/", + "https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42496", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json", + "https://ubuntu.com/security/notices/USN-8467-1", + "https://www.cve.org/CVERecord?id=CVE-2026-42496", + "https://www.cve.org/CVERecord?id=CVE-2026-42497" + ], + "PublishedDate": "2026-05-26T02:16:40.13Z", + "LastModifiedDate": "2026-07-24T10:10:00.197Z" + }, + { + "VulnerabilityID": "CVE-2026-8376", + "PkgID": "perl-base@5.40.1-6", + "PkgName": "perl-base", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/perl-base@5.40.1-6?arch=amd64\u0026distro=debian-13.6", + "UID": "546ba1bdcd66d61" + }, + "InstalledVersion": "5.40.1-6", + "FixedVersion": "5.40.1-6+deb13u1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8376", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:c0f5e430e5def21a7219721c63c827aaaf7303f69dc732c37473a3433bf7ddeb", + "Title": "perl: Perl: Heap buffer overflow when compiling regular expressions on 32-bit builds", + "Description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-680" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 2, + "nvd": 4, + "photon": 4, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", + "V3Score": 5.7 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/05/26/1", + "https://access.redhat.com/security/cve/CVE-2026-8376", + "https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch", + "https://github.com/Perl/perl5/pull/24433", + "https://nvd.nist.gov/vuln/detail/CVE-2026-8376", + "https://ubuntu.com/security/notices/USN-8467-1", + "https://www.cve.org/CVERecord?id=CVE-2026-8376" + ], + "PublishedDate": "2026-05-26T00:16:57.15Z", + "LastModifiedDate": "2026-09-08T22:19:18.373Z" + }, + { + "VulnerabilityID": "CVE-2026-42497", + "PkgID": "perl-base@5.40.1-6", + "PkgName": "perl-base", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/perl-base@5.40.1-6?arch=amd64\u0026distro=debian-13.6", + "UID": "546ba1bdcd66d61" + }, + "InstalledVersion": "5.40.1-6", + "FixedVersion": "5.40.1-6+deb13u1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42497", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:ffef536325a41f8b68810394367a1f96a23281d85a97aee71adaa3b6d3808cd2", + "Title": "perl-Archive-Tar: perl-Archive-Tar: Arbitrary file modification via crafted hardlinks during archive extraction", + "Description": "Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59", + "CWE-732" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "nvd": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H", + "V3Score": 6.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-42497", + "https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch", + "https://lists.security.metacpan.org/cve-announce/msg/40396457/", + "https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42497", + "https://www.cve.org/CVERecord?id=CVE-2026-42496", + "https://www.cve.org/CVERecord?id=CVE-2026-42497" + ], + "PublishedDate": "2026-05-26T02:16:40.25Z", + "LastModifiedDate": "2026-07-24T11:10:00.17Z" + }, + { + "VulnerabilityID": "CVE-2026-48962", + "PkgID": "perl-base@5.40.1-6", + "PkgName": "perl-base", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/perl-base@5.40.1-6?arch=amd64\u0026distro=debian-13.6", + "UID": "546ba1bdcd66d61" + }, + "InstalledVersion": "5.40.1-6", + "FixedVersion": "5.40.1-6+deb13u1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-48962", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:01f537572c821b2cd7ddbef6f26dae823dcfc81ecdb5e5c70e50604e40e78ee0", + "Title": "perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob", + "Description": "IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-95", + "CWE-94" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/05/27/4", + "https://access.redhat.com/errata/RHSA-2026:29182", + "https://access.redhat.com/errata/RHSA-2026:29210", + "https://access.redhat.com/errata/RHSA-2026:29867", + "https://access.redhat.com/errata/RHSA-2026:29941", + "https://access.redhat.com/errata/RHSA-2026:30085", + "https://access.redhat.com/errata/RHSA-2026:30086", + "https://access.redhat.com/errata/RHSA-2026:30115", + "https://access.redhat.com/errata/RHSA-2026:30843", + "https://access.redhat.com/errata/RHSA-2026:30851", + "https://access.redhat.com/errata/RHSA-2026:30858", + "https://access.redhat.com/errata/RHSA-2026:30859", + "https://access.redhat.com/errata/RHSA-2026:30860", + "https://access.redhat.com/errata/RHSA-2026:50262", + "https://access.redhat.com/security/cve/CVE-2026-48962", + "https://bugzilla.redhat.com/2481767", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481767", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48962", + "https://errata.almalinux.org/8/ALSA-2026-30858.html", + "https://errata.rockylinux.org/RLSA-2026:30859", + "https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch", + "https://linux.oracle.com/cve/CVE-2026-48962.html", + "https://linux.oracle.com/errata/ELSA-2026-30860.html", + "https://lists.security.metacpan.org/cve-announce/msg/40434385/", + "https://metacpan.org/release/PMQS/IO-Compress-2.220/changes", + "https://nvd.nist.gov/vuln/detail/CVE-2026-48962", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json", + "https://ubuntu.com/security/notices/USN-8684-1", + "https://www.cve.org/CVERecord?id=CVE-2026-48962" + ], + "PublishedDate": "2026-05-27T04:16:31.333Z", + "LastModifiedDate": "2026-08-05T13:23:22.46Z" + }, + { + "VulnerabilityID": "CVE-2026-57432", + "PkgID": "perl-base@5.40.1-6", + "PkgName": "perl-base", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/perl-base@5.40.1-6?arch=amd64\u0026distro=debian-13.6", + "UID": "546ba1bdcd66d61" + }, + "InstalledVersion": "5.40.1-6", + "FixedVersion": "5.40.1-6+deb13u1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-57432", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:7c2037aad8db32ec0fd9cdabc66d042adfff00451807e9f1ac60dbd517873d4e", + "Title": "perl: Perl: Information disclosure via integer overflow in pack/unpack operations", + "Description": "Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-125", + "CWE-190" + ], + "VendorSeverity": { + "azure": 3, + "nvd": 3, + "photon": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.4 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N", + "V3Score": 5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/07/13/6", + "https://access.redhat.com/security/cve/CVE-2026-57432", + "https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch", + "https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch", + "https://lists.security.metacpan.org/cve-announce/msg/41780102/", + "https://nvd.nist.gov/vuln/detail/CVE-2026-57432", + "https://ubuntu.com/security/notices/USN-8675-1", + "https://ubuntu.com/security/notices/USN-8675-2", + "https://ubuntu.com/security/notices/USN-8684-1", + "https://www.cve.org/CVERecord?id=CVE-2026-57432" + ], + "PublishedDate": "2026-07-13T17:17:55.67Z", + "LastModifiedDate": "2026-09-08T22:18:30.64Z" + }, + { + "VulnerabilityID": "CVE-2026-57433", + "PkgID": "perl-base@5.40.1-6", + "PkgName": "perl-base", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/perl-base@5.40.1-6?arch=amd64\u0026distro=debian-13.6", + "UID": "546ba1bdcd66d61" + }, + "InstalledVersion": "5.40.1-6", + "FixedVersion": "5.40.1-6+deb13u1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-57433", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:491cd1610dcf81ea91d59f67a8d9aa9eb2aa83fe9fb32f66891ae7d731856577", + "Title": "Storable: Storable: Denial of Service via signed integer overflow in deserialization", + "Description": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-190" + ], + "VendorSeverity": { + "azure": 4, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/07/13/7", + "https://access.redhat.com/security/cve/CVE-2026-57433", + "https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch", + "https://lists.security.metacpan.org/cve-announce/msg/41780100/", + "https://nvd.nist.gov/vuln/detail/CVE-2026-57433", + "https://ubuntu.com/security/notices/USN-8675-1", + "https://ubuntu.com/security/notices/USN-8675-2", + "https://ubuntu.com/security/notices/USN-8684-1", + "https://www.cve.org/CVERecord?id=CVE-2026-57433" + ], + "PublishedDate": "2026-07-13T17:17:55.783Z", + "LastModifiedDate": "2026-07-14T17:47:20.473Z" + }, + { + "VulnerabilityID": "CVE-2026-9538", + "PkgID": "perl-base@5.40.1-6", + "PkgName": "perl-base", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/perl-base@5.40.1-6?arch=amd64\u0026distro=debian-13.6", + "UID": "546ba1bdcd66d61" + }, + "InstalledVersion": "5.40.1-6", + "Status": "fix_deferred", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-9538", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:f428806d3f79111cc8dadafbc098c0d2998e7f64ec31a5fd409ad436217381fe", + "Title": "perl-Archive-Tar: perl-Archive-Tar: Denial of Service via crafted tar header with large entry size", + "Description": "Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle-\u003eread($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "nvd": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/05/26/4", + "https://access.redhat.com/errata/RHSA-2026:49524", + "https://access.redhat.com/errata/RHSA-2026:49525", + "https://access.redhat.com/security/cve/CVE-2026-9538", + "https://bugzilla.redhat.com/2481315", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481315", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9538", + "https://errata.almalinux.org/8/ALSA-2026-49524.html", + "https://errata.rockylinux.org/RLSA-2026:49525", + "https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch", + "https://linux.oracle.com/cve/CVE-2026-9538.html", + "https://linux.oracle.com/errata/ELSA-2026-49525.html", + "https://lists.security.metacpan.org/cve-announce/msg/40396448/", + "https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes", + "https://nvd.nist.gov/vuln/detail/CVE-2026-9538", + "https://ubuntu.com/security/notices/USN-8684-1", + "https://www.cve.org/CVERecord?id=CVE-2026-9538" + ], + "PublishedDate": "2026-05-26T02:16:41.15Z", + "LastModifiedDate": "2026-07-23T11:10:00.12Z" + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "util-linux@2.41.5-0+deb13u1", + "PkgName": "util-linux", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "e4d9863928456765" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:8d56fbccc2f4501cc717d2eac55c24c7531ddd1e6c36b4d9811b35fa8fd72615", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "util-linux@2.41.5-0+deb13u1", + "PkgName": "util-linux", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "e4d9863928456765" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:b308be7e7bb67fff4715c218533f815f053b7f700719a7c21e9d9c0ce47653d1", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78409", + "PkgID": "util-linux@2.41.5-0+deb13u1", + "PkgName": "util-linux", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "e4d9863928456765" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78409", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:77c81c49afa4b84ea2f286fcb4bf0c6e05004c0076b2f8f410502fb775a01f58", + "Title": "util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks", + "Description": "The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-59" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78409", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522607", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78409", + "https://www.cve.org/CVERecord?id=CVE-2026-78409" + ], + "PublishedDate": "2026-09-02T16:17:23.833Z", + "LastModifiedDate": "2026-09-03T18:12:56.407Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "util-linux@2.41.5-0+deb13u1", + "PkgName": "util-linux", + "PkgIdentifier": { + "PURL": "pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64\u0026distro=debian-13.6", + "UID": "e4d9863928456765" + }, + "InstalledVersion": "2.41.5-0+deb13u1", + "Status": "affected", + "Layer": { + "Digest": "sha256:6310eb16bf4251731feab01e8f633bf5e2d75a657ccad97f420b1f83cce457be", + "DiffID": "sha256:411a86676185cb54d695a805b238194a64e9b77e0c723f3802fbb87d333ea0b3" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "debian", + "Name": "Debian Security Tracker", + "URL": "https://salsa.debian.org/security-tracker-team/security-tracker" + }, + "Fingerprint": "sha256:53c62489be4c32c7187d06871396d73b62525cb692c3b3d7150d66f65938b531", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + } + ] + }, + { + "Target": "Python", + "Class": "lang-pkgs", + "Type": "python-pkg", + "Packages": [ + { + "ID": "CacheControl@0.14.4", + "Name": "CacheControl", + "Identifier": { + "PURL": "pkg:pypi/cachecontrol@0.14.4", + "UID": "918db5f3147f4498", + "BOMRef": "pkg:pypi/CacheControl@0.14.4" + }, + "Version": "0.14.4", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "annotated-doc", + "Identifier": { + "PURL": "pkg:pypi/annotated-doc@0.0.5", + "UID": "fb6ac2c1f334acc0" + }, + "Version": "0.0.5", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/annotated_doc-0.0.5.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "annotated-types", + "Identifier": { + "PURL": "pkg:pypi/annotated-types@0.8.0", + "UID": "1847359b2b3688a4" + }, + "Version": "0.8.0", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/annotated_types-0.8.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "anyio", + "Identifier": { + "PURL": "pkg:pypi/anyio@4.15.1", + "UID": "f568878f56f7e387" + }, + "Version": "4.15.1", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/anyio-4.15.1.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "boto3", + "Identifier": { + "PURL": "pkg:pypi/boto3@1.38.23", + "UID": "5303fef458b64a5b" + }, + "Version": "1.38.23", + "Licenses": [ + "Apache-2.0" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/boto3-1.38.23.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "botocore", + "Identifier": { + "PURL": "pkg:pypi/botocore@1.38.46", + "UID": "c63f075ac8b3aefe" + }, + "Version": "1.38.46", + "Licenses": [ + "Apache-2.0" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/botocore-1.38.46.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "certifi@2026.6.17", + "Name": "certifi", + "Identifier": { + "PURL": "pkg:pypi/certifi@2026.6.17", + "UID": "4be2e2d698b876a3", + "BOMRef": "pkg:pypi/certifi@2026.6.17" + }, + "Version": "2026.6.17", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "certifi", + "Identifier": { + "PURL": "pkg:pypi/certifi@2026.7.22", + "UID": "48a7d4734aaf4881" + }, + "Version": "2026.7.22", + "Licenses": [ + "MPL-2.0" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/certifi-2026.7.22.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "click", + "Identifier": { + "PURL": "pkg:pypi/click@8.5.0", + "UID": "1726c35a3b1d5d0d" + }, + "Version": "8.5.0", + "Licenses": [ + "BSD-3-Clause" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/click-8.5.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "distlib@0.4.2", + "Name": "distlib", + "Identifier": { + "PURL": "pkg:pypi/distlib@0.4.2", + "UID": "eaa5d2119fe45ab3", + "BOMRef": "pkg:pypi/distlib@0.4.2" + }, + "Version": "0.4.2", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "distro@1.9.0", + "Name": "distro", + "Identifier": { + "PURL": "pkg:pypi/distro@1.9.0", + "UID": "b90ac562dcd78c67", + "BOMRef": "pkg:pypi/distro@1.9.0" + }, + "Version": "1.9.0", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "fastapi", + "Identifier": { + "PURL": "pkg:pypi/fastapi@0.141.1", + "UID": "723de6e031cff522" + }, + "Version": "0.141.1", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/fastapi-0.141.1.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "h11", + "Identifier": { + "PURL": "pkg:pypi/h11@0.16.0", + "UID": "2ec0fe64a8b38d3a" + }, + "Version": "0.16.0", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/h11-0.16.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "httpcore", + "Identifier": { + "PURL": "pkg:pypi/httpcore@1.0.9", + "UID": "336ebe8bbce379bb" + }, + "Version": "1.0.9", + "Licenses": [ + "BSD-3-Clause" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/httpcore-1.0.9.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "httpx", + "Identifier": { + "PURL": "pkg:pypi/httpx@0.28.1", + "UID": "e625874b858226c9" + }, + "Version": "0.28.1", + "Licenses": [ + "BSD-3-Clause" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/httpx-0.28.1.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "idna@3.18", + "Name": "idna", + "Identifier": { + "PURL": "pkg:pypi/idna@3.18", + "UID": "c584d1beb1ab5d75", + "BOMRef": "pkg:pypi/idna@3.18" + }, + "Version": "3.18", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "idna", + "Identifier": { + "PURL": "pkg:pypi/idna@3.19", + "UID": "e695a226ff219946" + }, + "Version": "3.19", + "Licenses": [ + "BSD-3-Clause" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/idna-3.19.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "jmespath", + "Identifier": { + "PURL": "pkg:pypi/jmespath@1.1.0", + "UID": "483d80446fb1b18d" + }, + "Version": "1.1.0", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/jmespath-1.1.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "msgpack@1.1.2", + "Name": "msgpack", + "Identifier": { + "PURL": "pkg:pypi/msgpack@1.1.2", + "UID": "9d7d565367050f92", + "BOMRef": "pkg:pypi/msgpack@1.1.2" + }, + "Version": "1.1.2", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "packaging@26.2", + "Name": "packaging", + "Identifier": { + "PURL": "pkg:pypi/packaging@26.2", + "UID": "831135d2638194e3", + "BOMRef": "pkg:pypi/packaging@26.2" + }, + "Version": "26.2", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "pip", + "Identifier": { + "PURL": "pkg:pypi/pip@26.2.1", + "UID": "6ecafc08becca283" + }, + "Version": "26.2.1", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/pip-26.2.1.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "platformdirs@4.10.0", + "Name": "platformdirs", + "Identifier": { + "PURL": "pkg:pypi/platformdirs@4.10.0", + "UID": "bceb43cd8faea0db", + "BOMRef": "pkg:pypi/platformdirs@4.10.0" + }, + "Version": "4.10.0", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "psycopg", + "Identifier": { + "PURL": "pkg:pypi/psycopg@3.2.9", + "UID": "5b465f1802331f69" + }, + "Version": "3.2.9", + "Licenses": [ + "LGPL-3.0-only" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/psycopg-3.2.9.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "psycopg-binary", + "Identifier": { + "PURL": "pkg:pypi/psycopg-binary@3.2.9", + "UID": "c793f12682d80d9c" + }, + "Version": "3.2.9", + "Licenses": [ + "LGPL-3.0-only" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/psycopg_binary-3.2.9.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "pydantic", + "Identifier": { + "PURL": "pkg:pypi/pydantic@2.13.5", + "UID": "e034257422817e0d" + }, + "Version": "2.13.5", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/pydantic-2.13.5.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "pydantic_core", + "Identifier": { + "PURL": "pkg:pypi/pydantic-core@2.46.5", + "UID": "ffe3dd4972d2489c" + }, + "Version": "2.46.5", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/pydantic_core-2.46.5.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "pygments@2.20.0", + "Name": "pygments", + "Identifier": { + "PURL": "pkg:pypi/pygments@2.20.0", + "UID": "1cc1d55af1817d9", + "BOMRef": "pkg:pypi/pygments@2.20.0" + }, + "Version": "2.20.0", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "pyproject-hooks@1.2.0", + "Name": "pyproject-hooks", + "Identifier": { + "PURL": "pkg:pypi/pyproject-hooks@1.2.0", + "UID": "e523f408361e0fcc", + "BOMRef": "pkg:pypi/pyproject-hooks@1.2.0" + }, + "Version": "1.2.0", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "python-dateutil", + "Identifier": { + "PURL": "pkg:pypi/python-dateutil@2.9.0.post0", + "UID": "f8462eb573af85ab" + }, + "Version": "2.9.0.post0", + "Licenses": [ + "BSD-3-Clause", + "Apache-2.0" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/python_dateutil-2.9.0.post0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "requests@2.34.2", + "Name": "requests", + "Identifier": { + "PURL": "pkg:pypi/requests@2.34.2", + "UID": "7d2a8fbdb98d5bb8", + "BOMRef": "pkg:pypi/requests@2.34.2" + }, + "Version": "2.34.2", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "resolvelib@1.2.1", + "Name": "resolvelib", + "Identifier": { + "PURL": "pkg:pypi/resolvelib@1.2.1", + "UID": "47e96669d04f0ad5", + "BOMRef": "pkg:pypi/resolvelib@1.2.1" + }, + "Version": "1.2.1", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "rich@14.2.0", + "Name": "rich", + "Identifier": { + "PURL": "pkg:pypi/rich@14.2.0", + "UID": "72917d9a472273b5", + "BOMRef": "pkg:pypi/rich@14.2.0" + }, + "Version": "14.2.0", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "s3transfer", + "Identifier": { + "PURL": "pkg:pypi/s3transfer@0.13.1", + "UID": "e2f35e3d22fa0f40" + }, + "Version": "0.13.1", + "Licenses": [ + "Apache-2.0" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/s3transfer-0.13.1.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "setuptools@70.3.0", + "Name": "setuptools", + "Identifier": { + "PURL": "pkg:pypi/setuptools@70.3.0", + "UID": "4bc74a0ad6dbc16b", + "BOMRef": "pkg:pypi/setuptools@70.3.0" + }, + "Version": "70.3.0", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "six", + "Identifier": { + "PURL": "pkg:pypi/six@1.17.0", + "UID": "3c749e9680577add" + }, + "Version": "1.17.0", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/six-1.17.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "starlette", + "Identifier": { + "PURL": "pkg:pypi/starlette@1.6.0", + "UID": "faa3f25b0d188eac" + }, + "Version": "1.6.0", + "Licenses": [ + "BSD-3-Clause" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/starlette-1.6.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "tomli@2.4.1", + "Name": "tomli", + "Identifier": { + "PURL": "pkg:pypi/tomli@2.4.1", + "UID": "2cb2a60390da1ea0", + "BOMRef": "pkg:pypi/tomli@2.4.1" + }, + "Version": "2.4.1", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "tomli-w@1.2.0", + "Name": "tomli-w", + "Identifier": { + "PURL": "pkg:pypi/tomli-w@1.2.0", + "UID": "313a1c5a485a20fb", + "BOMRef": "pkg:pypi/tomli-w@1.2.0" + }, + "Version": "1.2.0", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "ID": "truststore@0.10.4", + "Name": "truststore", + "Identifier": { + "PURL": "pkg:pypi/truststore@0.10.4", + "UID": "46df0f1b1d8069cd", + "BOMRef": "pkg:pypi/truststore@0.10.4" + }, + "Version": "0.10.4", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "typing-inspection", + "Identifier": { + "PURL": "pkg:pypi/typing-inspection@0.4.4", + "UID": "53f9ffc7d6a5637e" + }, + "Version": "0.4.4", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/typing_inspection-0.4.4.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "typing_extensions", + "Identifier": { + "PURL": "pkg:pypi/typing-extensions@4.16.0", + "UID": "723d87d1aaa6dd8" + }, + "Version": "4.16.0", + "Licenses": [ + "PSF-2.0" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/typing_extensions-4.16.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "Name": "urllib3", + "Identifier": { + "PURL": "pkg:pypi/urllib3@2.7.0", + "UID": "fd0c49cd6c1fd2de" + }, + "Version": "2.7.0", + "Licenses": [ + "MIT" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/urllib3-2.7.0.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + }, + { + "ID": "urllib3@2.7.0", + "Name": "urllib3", + "Identifier": { + "PURL": "pkg:pypi/urllib3@2.7.0", + "UID": "7471a9a22bc9de38", + "BOMRef": "pkg:pypi/urllib3@2.7.0" + }, + "Version": "2.7.0", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "AnalyzedBy": "sbom" + }, + { + "Name": "uvicorn", + "Identifier": { + "PURL": "pkg:pypi/uvicorn@0.34.2", + "UID": "36df7c4f20b1ff11" + }, + "Version": "0.34.2", + "Licenses": [ + "BSD-3-Clause" + ], + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "FilePath": "usr/local/lib/python3.12/site-packages/uvicorn-0.34.2.dist-info/METADATA", + "AnalyzedBy": "python-pkg" + } + ], + "Vulnerabilities": [ + { + "VulnerabilityID": "GHSA-6v7p-g79w-8964", + "PkgID": "msgpack@1.1.2", + "PkgName": "msgpack", + "PkgIdentifier": { + "PURL": "pkg:pypi/msgpack@1.1.2", + "UID": "9d7d565367050f92", + "BOMRef": "pkg:pypi/msgpack@1.1.2" + }, + "InstalledVersion": "1.1.2", + "FixedVersion": "1.2.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://github.com/advisories/GHSA-6v7p-g79w-8964", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:e672dd6f4cee8b7939db911f801394747dab4e6f94eb8e9b061da2f43e94037b", + "Title": "MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error", + "Description": "### Impact\n\nIf the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.\n\nIf the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.\n\n### Patches\n\nv1.2.1\n\n### Workarounds\n\nUsers should create a new Unpacker instead of reusing the same Unpacker after an error occurs.\n\nApplying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct data. If an error occurs during Streaming Unpacking, the Stream and Streaming Unpacker should be discarded.\n\nTherefore, this is not just a workaround but the correct solution. The above patch only prevents crashes from incorrect usage.", + "Severity": "HIGH", + "VendorSeverity": { + "ghsa": 3 + }, + "CVSS": { + "ghsa": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://github.com/msgpack/msgpack-python", + "https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d", + "https://github.com/msgpack/msgpack-python/releases/tag/v1.2.1", + "https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964" + ], + "PublishedDate": "2026-06-19T21:42:55Z", + "LastModifiedDate": "2026-06-19T21:42:55Z" + }, + { + "VulnerabilityID": "CVE-2025-47273", + "VendorIDs": [ + "GHSA-5rjg-fvgr-3xxf" + ], + "PkgID": "setuptools@70.3.0", + "PkgName": "setuptools", + "PkgIdentifier": { + "PURL": "pkg:pypi/setuptools@70.3.0", + "UID": "4bc74a0ad6dbc16b", + "BOMRef": "pkg:pypi/setuptools@70.3.0" + }, + "InstalledVersion": "70.3.0", + "FixedVersion": "78.1.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:fabee80c4201b9d3db1e011338778fa3a1bbe2413939ebd8add1d56376ea49d5", + "DiffID": "sha256:5b31cc7916bc4fd57379d3310522e4dc63c808b89734cbe4f31be4833a8d27ce" + }, + "SeveritySource": "ghsa", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2025-47273", + "DataSource": { + "ID": "ghsa", + "Name": "GitHub Security Advisory pip", + "URL": "https://github.com/advisories?query=type%3Areviewed+ecosystem%3Apip" + }, + "Fingerprint": "sha256:80fd400a3d3332e9432e2cba6a07622b9a9989fc102e4786155c8f4d6bad0177", + "Title": "setuptools: Path Traversal Vulnerability in setuptools PackageIndex", + "Description": "setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-22" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "ghsa": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "ghsa": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P", + "V40Score": 7.7 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L", + "V3Score": 7.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2025:10407", + "https://access.redhat.com/errata/RHSA-2025:14900", + "https://access.redhat.com/security/cve/CVE-2025-47273", + "https://bugzilla.redhat.com/2366982", + "https://bugzilla.redhat.com/2384043", + "https://bugzilla.redhat.com/show_bug.cgi?id=2366982", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47273", + "https://errata.almalinux.org/8/ALSA-2025-14900.html", + "https://errata.rockylinux.org/RLSA-2025:10407", + "https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml", + "https://github.com/pypa/setuptools", + "https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88", + "https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b", + "https://github.com/pypa/setuptools/issues/4946", + "https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf", + "https://linux.oracle.com/cve/CVE-2025-47273.html", + "https://linux.oracle.com/errata/ELSA-2025-9940.html", + "https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html", + "https://nvd.nist.gov/vuln/detail/CVE-2025-47273", + "https://ubuntu.com/security/notices/USN-7544-1", + "https://ubuntu.com/security/notices/USN-8010-1", + "https://www.cve.org/CVERecord?id=CVE-2025-47273" + ], + "PublishedDate": "2025-05-17T16:15:19.11Z", + "LastModifiedDate": "2026-06-17T09:27:38.827Z" + } + ] + } + ] +} diff --git a/output/security/production-web-container-audit.json b/output/security/production-web-container-audit.json new file mode 100644 index 0000000..5126040 --- /dev/null +++ b/output/security/production-web-container-audit.json @@ -0,0 +1,7452 @@ +{ + "SchemaVersion": 2, + "Trivy": { + "Version": "0.74.0" + }, + "ReportID": "01a0a616-bfff-795c-abf3-86ee2da79ee6", + "CreatedAt": "2026-09-15T17:21:43.935616815Z", + "ArtifactID": "sha256:7e2ef2cf0963a6021bbb0428d17799b7e412657661833d57eaf85269698a2bee", + "ArtifactName": "dtf-production-web:validation", + "ArtifactType": "container_image", + "Metadata": { + "Size": 63693824, + "OS": { + "Family": "alpine", + "Name": "3.23.3" + }, + "ImageID": "sha256:c1ae962ff4d0551b3c1629aa702c89b2ad98497d2c1c808bfcba74d6bffb7ec2", + "DiffIDs": [ + "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e", + "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119", + "sha256:47a53288c3ef0ee51df84ef47d217f18c1762412532fded9af1fd88ecee14294", + "sha256:9e707aa6db4786355904a1b794c80f378b690f8f0384af56117708a23a91f1da", + "sha256:a3446cc6c821fa11b704a45811ab554675f0327307af71b3f4ff5a70c7a4eec8", + "sha256:42608b42cb5e68548abf1c71aa851acfd65816d0ceaff6ee85849c7c478463f0", + "sha256:53c769b49ca0a2f0f6cf5e4a807af8933cec6cde9302d56d91a78bc38ea407a8", + "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0", + "sha256:4a37d6822c6d388b4e3399cf15c5bd0878c71d6ec14862edd0f778b1e75b4b62", + "sha256:860dbfb02839b3b8496aae962b9fae057fd868bd09f0e6867230e80aca08260e", + "sha256:aa2935217d14946c1ebf1ccb9e1ca43fca63c86d4fe6aed723f5b3ae997762c5" + ], + "RepoTags": [ + "dtf-production-web:validation" + ], + "RepoDigests": [ + "dtf-production-web@sha256:c1ae962ff4d0551b3c1629aa702c89b2ad98497d2c1c808bfcba74d6bffb7ec2" + ], + "Reference": "dtf-production-web:validation", + "ImageConfig": { + "architecture": "amd64", + "created": "2026-09-15T14:09:15.680375581-03:00", + "history": [ + { + "created": "2026-01-28T01:18:04Z", + "created_by": "ADD alpine-minirootfs-3.23.3-x86_64.tar.gz / # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-01-28T01:18:04Z", + "created_by": "CMD [\"/bin/sh\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:24Z", + "created_by": "LABEL maintainer=NGINX Docker Maintainers \u003cdocker-maint@nginx.com\u003e", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:24Z", + "created_by": "ENV NGINX_VERSION=1.28.3", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:24Z", + "created_by": "ENV PKG_RELEASE=1", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:24Z", + "created_by": "ENV DYNPKG_RELEASE=1", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:24Z", + "created_by": "RUN /bin/sh -c set -x \u0026\u0026 addgroup -g 101 -S nginx \u0026\u0026 adduser -S -D -H -u 101 -h /var/cache/nginx -s /sbin/nologin -G nginx -g nginx nginx \u0026\u0026 apkArch=\"$(cat /etc/apk/arch)\" \u0026\u0026 nginxPackages=\" nginx=${NGINX_VERSION}-r${PKG_RELEASE} \" \u0026\u0026 apk add --no-cache --virtual .checksum-deps openssl \u0026\u0026 case \"$apkArch\" in x86_64|aarch64) set -x \u0026\u0026 KEY_SHA512=\"e09fa32f0a0eab2b879ccbbc4d0e4fb9751486eedda75e35fac65802cc9faa266425edf83e261137a2f4d16281ce2c1a5f4502930fe75154723da014214f0655\" \u0026\u0026 wget -O /tmp/nginx_signing.rsa.pub https://nginx.org/keys/nginx_signing.rsa.pub \u0026\u0026 if echo \"$KEY_SHA512 */tmp/nginx_signing.rsa.pub\" | sha512sum -c -; then echo \"key verification succeeded!\"; mv /tmp/nginx_signing.rsa.pub /etc/apk/keys/; else echo \"key verification failed!\"; exit 1; fi \u0026\u0026 DEPS=$(apk query --summarize depends --recursive --no-cache --repository \"@nginxorg https://nginx.org/packages/alpine/v$(egrep -o '^[0-9]+\\.[0-9]+' /etc/alpine-release)/main\" ${nginxPackages/=/@nginxorg=}) \u0026\u0026 apk add --no-cache $DEPS \u0026\u0026 apk add --repositories-file /dev/null -X \"https://nginx.org/packages/alpine/v$(egrep -o '^[0-9]+\\.[0-9]+' /etc/alpine-release)/main\" --no-cache $nginxPackages ;; *) set -x \u0026\u0026 tempDir=\"$(mktemp -d)\" \u0026\u0026 chown nobody:nobody $tempDir \u0026\u0026 apk add --no-cache --virtual .build-deps gcc libc-dev make openssl-dev pcre2-dev zlib-dev linux-headers bash alpine-sdk findutils curl \u0026\u0026 su nobody -s /bin/sh -c \" export HOME=${tempDir} \u0026\u0026 cd ${tempDir} \u0026\u0026 curl -f -L -O https://github.com/nginx/pkg-oss/archive/${NGINX_VERSION}-${PKG_RELEASE}.tar.gz \u0026\u0026 PKGOSSCHECKSUM=\\\"866d10a1091f34b6bd9e7dcae69653323fa98511a2b75104b54d97ef71416b9b96f10510149d9e85aa582b21b3cb5e43ea9c2b8d8f7cf0079452e8bea2c10db4 *${NGINX_VERSION}-${PKG_RELEASE}.tar.gz\\\" \u0026\u0026 if [ \\\"\\$(openssl sha512 -r ${NGINX_VERSION}-${PKG_RELEASE}.tar.gz)\\\" = \\\"\\$PKGOSSCHECKSUM\\\" ]; then echo \\\"pkg-oss tarball checksum verification succeeded!\\\"; else echo \\\"pkg-oss tarball checksum verification failed!\\\"; exit 1; fi \u0026\u0026 tar xzvf ${NGINX_VERSION}-${PKG_RELEASE}.tar.gz \u0026\u0026 cd pkg-oss-${NGINX_VERSION}-${PKG_RELEASE} \u0026\u0026 cd alpine \u0026\u0026 make base \u0026\u0026 apk index --allow-untrusted -o ${tempDir}/packages/alpine/${apkArch}/APKINDEX.tar.gz ${tempDir}/packages/alpine/${apkArch}/*.apk \u0026\u0026 abuild-sign -k ${tempDir}/.abuild/abuild-key.rsa ${tempDir}/packages/alpine/${apkArch}/APKINDEX.tar.gz \" \u0026\u0026 cp ${tempDir}/.abuild/abuild-key.rsa.pub /etc/apk/keys/ \u0026\u0026 apk del --no-network .build-deps \u0026\u0026 DEPS=$(apk query --summarize depends --recursive --no-cache --repository \"@nginxorg ${tempDir}/packages/alpine/\" ${nginxPackages/=/@nginxorg=}) \u0026\u0026 apk add --no-cache $DEPS \u0026\u0026 apk add --repositories-file /dev/null -X ${tempDir}/packages/alpine/ --no-cache $nginxPackages ;; esac \u0026\u0026 apk del --no-network .checksum-deps \u0026\u0026 if [ -n \"$tempDir\" ]; then rm -rf \"$tempDir\"; fi \u0026\u0026 if [ -f \"/etc/apk/keys/abuild-key.rsa.pub\" ]; then rm -f /etc/apk/keys/abuild-key.rsa.pub; fi \u0026\u0026 apk add --no-cache gettext-envsubst \u0026\u0026 apk add --no-cache tzdata \u0026\u0026 ln -sf /dev/stdout /var/log/nginx/access.log \u0026\u0026 ln -sf /dev/stderr /var/log/nginx/error.log \u0026\u0026 mkdir /docker-entrypoint.d # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "COPY docker-entrypoint.sh / # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "COPY 10-listen-on-ipv6-by-default.sh /docker-entrypoint.d # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "COPY 15-local-resolvers.envsh /docker-entrypoint.d # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "COPY 20-envsubst-on-templates.sh /docker-entrypoint.d # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "COPY 30-tune-worker-processes.sh /docker-entrypoint.d # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "ENTRYPOINT [\"/docker-entrypoint.sh\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "EXPOSE map[80/tcp:{}]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "STOPSIGNAL SIGQUIT", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "CMD [\"nginx\" \"-g\" \"daemon off;\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T23:11:15Z", + "created_by": "ENV NJS_VERSION=0.9.6", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T23:11:15Z", + "created_by": "ENV NJS_RELEASE=1", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T23:11:15Z", + "created_by": "ENV ACME_VERSION=0.3.1", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T23:11:15Z", + "created_by": "RUN /bin/sh -c set -x \u0026\u0026 apkArch=\"$(cat /etc/apk/arch)\" \u0026\u0026 nginxPackages=\" nginx=${NGINX_VERSION}-r${PKG_RELEASE} nginx-module-xslt=${NGINX_VERSION}-r${DYNPKG_RELEASE} nginx-module-geoip=${NGINX_VERSION}-r${DYNPKG_RELEASE} nginx-module-image-filter=${NGINX_VERSION}-r${DYNPKG_RELEASE} nginx-module-njs=${NGINX_VERSION}.${NJS_VERSION}-r${NJS_RELEASE} nginx-module-acme=${NGINX_VERSION}.${ACME_VERSION}-r${PKG_RELEASE} \" \u0026\u0026 apk add --no-cache --virtual .checksum-deps openssl \u0026\u0026 case \"$apkArch\" in x86_64|aarch64) apk add -X \"https://nginx.org/packages/alpine/v$(egrep -o '^[0-9]+\\.[0-9]+' /etc/alpine-release)/main\" --no-cache $nginxPackages ;; *) set -x \u0026\u0026 tempDir=\"$(mktemp -d)\" \u0026\u0026 chown nobody:nobody $tempDir \u0026\u0026 apk add --no-cache --virtual .build-deps gcc libc-dev make openssl-dev pcre2-dev zlib-dev linux-headers libxslt-dev gd-dev geoip-dev libedit-dev bash alpine-sdk findutils curl cargo clang-libclang \u0026\u0026 su nobody -s /bin/sh -c \" export HOME=${tempDir} \u0026\u0026 cd ${tempDir} \u0026\u0026 curl -f -L -O https://github.com/nginx/pkg-oss/archive/${NGINX_VERSION}-${PKG_RELEASE}.tar.gz \u0026\u0026 PKGOSSCHECKSUM=\\\"866d10a1091f34b6bd9e7dcae69653323fa98511a2b75104b54d97ef71416b9b96f10510149d9e85aa582b21b3cb5e43ea9c2b8d8f7cf0079452e8bea2c10db4 *${NGINX_VERSION}-${PKG_RELEASE}.tar.gz\\\" \u0026\u0026 if [ \\\"\\$(openssl sha512 -r ${NGINX_VERSION}-${PKG_RELEASE}.tar.gz)\\\" = \\\"\\$PKGOSSCHECKSUM\\\" ]; then echo \\\"pkg-oss tarball checksum verification succeeded!\\\"; else echo \\\"pkg-oss tarball checksum verification failed!\\\"; exit 1; fi \u0026\u0026 tar xzvf ${NGINX_VERSION}-${PKG_RELEASE}.tar.gz \u0026\u0026 cd pkg-oss-${NGINX_VERSION}-${PKG_RELEASE} \u0026\u0026 cd alpine \u0026\u0026 export BUILDTARGET=\\\"module-geoip module-image-filter module-njs module-xslt module-acme\\\" \u0026\u0026 if [ \\\"\\$(apk --print-arch)\\\" = \\\"armhf\\\" ]; then BUILDTARGET=\\\"\\$( echo \\$BUILDTARGET | sed 's,module-acme,,' )\\\"; fi \u0026\u0026 make \\$BUILDTARGET \u0026\u0026 apk index --allow-untrusted -o ${tempDir}/packages/alpine/${apkArch}/APKINDEX.tar.gz ${tempDir}/packages/alpine/${apkArch}/*.apk \u0026\u0026 abuild-sign -k ${tempDir}/.abuild/abuild-key.rsa ${tempDir}/packages/alpine/${apkArch}/APKINDEX.tar.gz \" \u0026\u0026 cp ${tempDir}/.abuild/abuild-key.rsa.pub /etc/apk/keys/ \u0026\u0026 apk del --no-network .build-deps \u0026\u0026 if [ \"$apkArch\" = \"armhf\" ]; then nginxPackages=\"$( echo $nginxPackages | sed 's,nginx-module-acme=.*,,')\"; fi \u0026\u0026 apk add -X ${tempDir}/packages/alpine/ --no-cache $nginxPackages ;; esac \u0026\u0026 apk del --no-network .checksum-deps \u0026\u0026 if [ -n \"$tempDir\" ]; then rm -rf \"$tempDir\"; fi \u0026\u0026 if [ -f \"/etc/apk/keys/abuild-key.rsa.pub\" ]; then rm -f /etc/apk/keys/abuild-key.rsa.pub; fi \u0026\u0026 apk add --no-cache curl ca-certificates # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-15T16:27:31Z", + "created_by": "/bin/sh -c #(nop) ARG VCS_REF=unknown", + "empty_layer": true + }, + { + "created": "2026-09-15T16:27:34Z", + "created_by": "/bin/sh -c #(nop) LABEL org.opencontainers.image.title=DTF Site and Kanban org.opencontainers.image.revision=local-validation org.opencontainers.image.source=DTF System repository", + "empty_layer": true + }, + { + "created": "2026-09-15T16:27:35Z", + "created_by": "/bin/sh -c #(nop) ENV WEB_INDEX=index.html PUBLIC_HOST=invalid.example S3_PUBLIC_ENDPOINT=https://invalid.example", + "empty_layer": true + }, + { + "created": "2026-09-15T16:27:37Z", + "created_by": "/bin/sh -c #(nop) COPY file:20fe34ab76ccd30979b464bdd4e734819f8249f24e5498a44c5d04b3778448ad in /etc/nginx/templates/default.conf.template " + }, + { + "created": "2026-09-15T16:27:38Z", + "created_by": "/bin/sh -c #(nop) COPY file:250b223b4392e692fcbffe99098e39467952f288ef8b682d85553e0190850b97 in /usr/share/nginx/html/index.html " + }, + { + "created": "2026-09-15T16:27:39Z", + "created_by": "/bin/sh -c #(nop) COPY dir:7a567fb1a37cda0230a25ad002e176756991ed408b4b3db7deb5c2a2a0c42e1b in /usr/share/nginx/html/ " + }, + { + "created": "2026-09-15T17:09:14Z", + "created_by": "/bin/sh -c #(nop) USER 101:101", + "empty_layer": true + }, + { + "created": "2026-09-15T17:09:15Z", + "created_by": "/bin/sh -c #(nop) EXPOSE 8080", + "empty_layer": true + } + ], + "os": "linux", + "rootfs": { + "type": "layers", + "diff_ids": [ + "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e", + "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119", + "sha256:47a53288c3ef0ee51df84ef47d217f18c1762412532fded9af1fd88ecee14294", + "sha256:9e707aa6db4786355904a1b794c80f378b690f8f0384af56117708a23a91f1da", + "sha256:a3446cc6c821fa11b704a45811ab554675f0327307af71b3f4ff5a70c7a4eec8", + "sha256:42608b42cb5e68548abf1c71aa851acfd65816d0ceaff6ee85849c7c478463f0", + "sha256:53c769b49ca0a2f0f6cf5e4a807af8933cec6cde9302d56d91a78bc38ea407a8", + "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0", + "sha256:4a37d6822c6d388b4e3399cf15c5bd0878c71d6ec14862edd0f778b1e75b4b62", + "sha256:860dbfb02839b3b8496aae962b9fae057fd868bd09f0e6867230e80aca08260e", + "sha256:aa2935217d14946c1ebf1ccb9e1ca43fca63c86d4fe6aed723f5b3ae997762c5" + ] + }, + "config": { + "Cmd": [ + "nginx", + "-g", + "daemon off;" + ], + "Entrypoint": [ + "/docker-entrypoint.sh" + ], + "Env": [ + "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", + "NGINX_VERSION=1.28.3", + "PKG_RELEASE=1", + "DYNPKG_RELEASE=1", + "NJS_VERSION=0.9.6", + "NJS_RELEASE=1", + "ACME_VERSION=0.3.1", + "WEB_INDEX=index.html", + "PUBLIC_HOST=invalid.example", + "S3_PUBLIC_ENDPOINT=https://invalid.example" + ], + "Labels": { + "maintainer": "NGINX Docker Maintainers \u003cdocker-maint@nginx.com\u003e", + "org.opencontainers.image.revision": "local-validation", + "org.opencontainers.image.source": "DTF System repository", + "org.opencontainers.image.title": "DTF Site and Kanban" + }, + "User": "101:101", + "WorkingDir": "/", + "ExposedPorts": { + "80/tcp": {}, + "8080/tcp": {} + }, + "StopSignal": "SIGQUIT" + } + }, + "Layers": [ + { + "Size": 8724480, + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + { + "Size": 4654592, + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + { + "Size": 3584, + "Digest": "sha256:e914c6e98e37815624beb8c5043be292f121898059d4d50c0709bc4da661f685", + "DiffID": "sha256:47a53288c3ef0ee51df84ef47d217f18c1762412532fded9af1fd88ecee14294" + }, + { + "Size": 4608, + "Digest": "sha256:d631a49fb4f72e5bc609d0af4ce6d3ed054498068dc16c730be6b4e37c4a7f6c", + "DiffID": "sha256:9e707aa6db4786355904a1b794c80f378b690f8f0384af56117708a23a91f1da" + }, + { + "Size": 2560, + "Digest": "sha256:8f7c784e247120771f7bdb83b2ab8e17af75af4858332b63e0ed40610f5a9b59", + "DiffID": "sha256:a3446cc6c821fa11b704a45811ab554675f0327307af71b3f4ff5a70c7a4eec8" + }, + { + "Size": 5120, + "Digest": "sha256:44fa0a5a779fdf3b85972e8dfb3b2755a72a97290b682794f57212d88fa3a631", + "DiffID": "sha256:42608b42cb5e68548abf1c71aa851acfd65816d0ceaff6ee85849c7c478463f0" + }, + { + "Size": 7168, + "Digest": "sha256:98104829f3fe8d2ead9a69b1f56c1f98955fd2b5933f089301331bb1f349683b", + "DiffID": "sha256:53c769b49ca0a2f0f6cf5e4a807af8933cec6cde9302d56d91a78bc38ea407a8" + }, + { + "Size": 50089984, + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + { + "Size": 5120, + "Digest": "sha256:4509de44e3385a343f9ac0f76f43c70be9f9394508d0acdc7d383511f09f91d7", + "DiffID": "sha256:4a37d6822c6d388b4e3399cf15c5bd0878c71d6ec14862edd0f778b1e75b4b62" + }, + { + "Size": 152576, + "Digest": "sha256:297df280b12814cec0cbc0bad18c01b96c5774db590a64e33867e8a6e255a888", + "DiffID": "sha256:860dbfb02839b3b8496aae962b9fae057fd868bd09f0e6867230e80aca08260e" + }, + { + "Size": 44032, + "Digest": "sha256:5f5be02e32912d8d4243b79a370d86e36576137c36046a82f89397cdb44cdf75", + "DiffID": "sha256:aa2935217d14946c1ebf1ccb9e1ca43fca63c86d4fe6aed723f5b3ae997762c5" + } + ] + }, + "Results": [ + { + "Target": "dtf-production-web:validation (alpine 3.23.3)", + "Class": "os-pkgs", + "Type": "alpine", + "Packages": [ + { + "ID": "alpine-baselayout@3.7.1-r8", + "Name": "alpine-baselayout", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-baselayout@3.7.1-r8?arch=x86_64\u0026distro=3.23.3", + "UID": "dc092fc47b5d9e05" + }, + "Version": "3.7.1-r8", + "Arch": "x86_64", + "SrcName": "alpine-baselayout", + "SrcVersion": "3.7.1-r8", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "alpine-baselayout-data@3.7.1-r8", + "busybox-binsh@1.37.0-r30" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:9a137c3c8e738bcabac13326c9fc5472fa58aaf4", + "InstalledFiles": [ + "etc/motd", + "etc/crontabs/root", + "etc/modprobe.d/aliases.conf", + "etc/modprobe.d/blacklist.conf", + "etc/modprobe.d/i386.conf", + "etc/profile.d/20locale.sh", + "etc/profile.d/README", + "etc/profile.d/color_prompt.sh.disabled", + "usr/lib/sysctl.d/00-alpine.conf", + "var/lock", + "var/run", + "var/spool/mail", + "var/spool/cron/crontabs" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-baselayout-data@3.7.1-r8", + "Name": "alpine-baselayout-data", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-baselayout-data@3.7.1-r8?arch=x86_64\u0026distro=3.23.3", + "UID": "6542463feabe92df" + }, + "Version": "3.7.1-r8", + "Arch": "x86_64", + "SrcName": "alpine-baselayout", + "SrcVersion": "3.7.1-r8", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:9a60b0edb4559ab279cf004b7e685cfd78dd0c15", + "InstalledFiles": [ + "etc/fstab", + "etc/group", + "etc/hostname", + "etc/hosts", + "etc/inittab", + "etc/modules", + "etc/mtab", + "etc/nsswitch.conf", + "etc/passwd", + "etc/profile", + "etc/protocols", + "etc/services", + "etc/shadow", + "etc/shells", + "etc/sysctl.conf" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-keys@2.6-r0", + "Name": "alpine-keys", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-keys@2.6-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "2c7cb90de388aa7d" + }, + "Version": "2.6-r0", + "Arch": "x86_64", + "SrcName": "alpine-keys", + "SrcVersion": "2.6-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:5c45a821cd6b84d543bbd7ff12a7de1855c5cd13", + "InstalledFiles": [ + "etc/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "etc/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", + "etc/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub", + "usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub", + "usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub", + "usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", + "usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub", + "usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", + "usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub", + "usr/share/apk/keys/loongarch64/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub", + "usr/share/apk/keys/mips64/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub", + "usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub", + "usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub", + "usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub", + "usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub", + "usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub", + "usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub", + "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub", + "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub", + "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", + "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-release@3.23.3-r0", + "Name": "alpine-release", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-release@3.23.3-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "4820d6f0afb6a834" + }, + "Version": "3.23.3-r0", + "Arch": "x86_64", + "SrcName": "alpine-base", + "SrcVersion": "3.23.3-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "alpine-keys@2.6-r0" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:e71144a1a35c4844507cd1a3281a7189049f3522", + "InstalledFiles": [ + "etc/alpine-release", + "etc/issue", + "etc/os-release", + "etc/secfixes.d/alpine", + "usr/lib/os-release" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "aom-libs@3.13.1-r1", + "Name": "aom-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/aom-libs@3.13.1-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8324fd8055cbd635" + }, + "Version": "3.13.1-r1", + "Arch": "x86_64", + "SrcName": "aom", + "SrcVersion": "3.13.1-r1", + "Licenses": [ + "BSD-2-Clause", + "custom" + ], + "Maintainer": "Oleg Titov \u003coleg.titov@gmail.com\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:97b0c2dffcef97a0253876d015ca217de10b216a", + "InstalledFiles": [ + "usr/lib/libaom.so.3", + "usr/lib/libaom.so.3.13.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "apk-tools@3.0.3-r1", + "Name": "apk-tools", + "Identifier": { + "PURL": "pkg:apk/alpine/apk-tools@3.0.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "135e6dc8dcafde4f" + }, + "Version": "3.0.3-r1", + "Arch": "x86_64", + "SrcName": "apk-tools", + "SrcVersion": "3.0.3-r1", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "ca-certificates-bundle@20251003-r0", + "libapk@3.0.3-r1", + "libcrypto3@3.5.5-r0", + "musl@1.2.5-r21", + "zlib@1.3.1-r2" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:b2f877e6c9fb945c185cf36ed546064b8b374245", + "InstalledFiles": [ + "sbin/apk" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "brotli-libs@1.2.0-r0", + "Name": "brotli-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/brotli-libs@1.2.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "18708ffc8b6c1544" + }, + "Version": "1.2.0-r0", + "Arch": "x86_64", + "SrcName": "brotli", + "SrcVersion": "1.2.0-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "prspkt \u003cprspkt@protonmail.com\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:0814694602f35d2741e916fdcb4c9a1e0ec50b42", + "InstalledFiles": [ + "usr/lib/libbrotlicommon.so.1", + "usr/lib/libbrotlicommon.so.1.2.0", + "usr/lib/libbrotlidec.so.1", + "usr/lib/libbrotlidec.so.1.2.0", + "usr/lib/libbrotlienc.so.1", + "usr/lib/libbrotlienc.so.1.2.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "busybox@1.37.0-r30", + "Name": "busybox", + "Identifier": { + "PURL": "pkg:apk/alpine/busybox@1.37.0-r30?arch=x86_64\u0026distro=3.23.3", + "UID": "1701a73d4be0e35a" + }, + "Version": "1.37.0-r30", + "Arch": "x86_64", + "SrcName": "busybox", + "SrcVersion": "1.37.0-r30", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:f1347801bb96b1aa40d17f82237c3f4ff02a4725", + "InstalledFiles": [ + "bin/busybox", + "etc/securetty", + "etc/busybox-paths.d/busybox", + "etc/logrotate.d/acpid", + "etc/network/if-up.d/dad", + "etc/udhcpc/udhcpc.conf", + "usr/share/udhcpc/default.script" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "busybox-binsh@1.37.0-r30", + "Name": "busybox-binsh", + "Identifier": { + "PURL": "pkg:apk/alpine/busybox-binsh@1.37.0-r30?arch=x86_64\u0026distro=3.23.3", + "UID": "3e18d05d46a6f46f" + }, + "Version": "1.37.0-r30", + "Arch": "x86_64", + "SrcName": "busybox", + "SrcVersion": "1.37.0-r30", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", + "DependsOn": [ + "busybox@1.37.0-r30" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:188d2d0110afa58e8a3e3e5fd424b2d996df7a09", + "InstalledFiles": [ + "bin/sh" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "c-ares@1.34.6-r0", + "Name": "c-ares", + "Identifier": { + "PURL": "pkg:apk/alpine/c-ares@1.34.6-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "2fc69dd6afab16ae" + }, + "Version": "1.34.6-r0", + "Arch": "x86_64", + "SrcName": "c-ares", + "SrcVersion": "1.34.6-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:e3bb3ff47a277ff9409b8c4bb825099cfe2bcbe2", + "InstalledFiles": [ + "usr/lib/libcares.so.2", + "usr/lib/libcares.so.2.19.5" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ca-certificates@20251003-r0", + "Name": "ca-certificates", + "Identifier": { + "PURL": "pkg:apk/alpine/ca-certificates@20251003-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "209bcc6fdf94c4a5" + }, + "Version": "20251003-r0", + "Arch": "x86_64", + "SrcName": "ca-certificates", + "SrcVersion": "20251003-r0", + "Licenses": [ + "MPL-2.0", + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "libcrypto3@3.5.5-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:3b10fd335b2af819c4fd3562900e76fd6ea304c5", + "InstalledFiles": [ + "etc/ca-certificates.conf", + "etc/apk/protected_paths.d/ca-certificates.list", + "etc/ca-certificates/update.d/certhash", + "usr/bin/c_rehash", + "usr/sbin/update-ca-certificates", + "usr/share/ca-certificates/mozilla/ACCVRAIZ1.crt", + "usr/share/ca-certificates/mozilla/AC_RAIZ_FNMT-RCM.crt", + "usr/share/ca-certificates/mozilla/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.crt", + "usr/share/ca-certificates/mozilla/ANF_Secure_Server_Root_CA.crt", + "usr/share/ca-certificates/mozilla/Actalis_Authentication_Root_CA.crt", + "usr/share/ca-certificates/mozilla/AffirmTrust_Commercial.crt", + "usr/share/ca-certificates/mozilla/AffirmTrust_Networking.crt", + "usr/share/ca-certificates/mozilla/AffirmTrust_Premium.crt", + "usr/share/ca-certificates/mozilla/AffirmTrust_Premium_ECC.crt", + "usr/share/ca-certificates/mozilla/Amazon_Root_CA_1.crt", + "usr/share/ca-certificates/mozilla/Amazon_Root_CA_2.crt", + "usr/share/ca-certificates/mozilla/Amazon_Root_CA_3.crt", + "usr/share/ca-certificates/mozilla/Amazon_Root_CA_4.crt", + "usr/share/ca-certificates/mozilla/Atos_TrustedRoot_2011.crt", + "usr/share/ca-certificates/mozilla/Atos_TrustedRoot_Root_CA_ECC_TLS_2021.crt", + "usr/share/ca-certificates/mozilla/Atos_TrustedRoot_Root_CA_RSA_TLS_2021.crt", + "usr/share/ca-certificates/mozilla/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.crt", + "usr/share/ca-certificates/mozilla/BJCA_Global_Root_CA1.crt", + "usr/share/ca-certificates/mozilla/BJCA_Global_Root_CA2.crt", + "usr/share/ca-certificates/mozilla/Buypass_Class_2_Root_CA.crt", + "usr/share/ca-certificates/mozilla/Buypass_Class_3_Root_CA.crt", + "usr/share/ca-certificates/mozilla/CA_Disig_Root_R2.crt", + "usr/share/ca-certificates/mozilla/CFCA_EV_ROOT.crt", + "usr/share/ca-certificates/mozilla/COMODO_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/COMODO_ECC_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/COMODO_RSA_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/Certainly_Root_E1.crt", + "usr/share/ca-certificates/mozilla/Certainly_Root_R1.crt", + "usr/share/ca-certificates/mozilla/Certigna.crt", + "usr/share/ca-certificates/mozilla/Certigna_Root_CA.crt", + "usr/share/ca-certificates/mozilla/Certum_EC-384_CA.crt", + "usr/share/ca-certificates/mozilla/Certum_Trusted_Network_CA.crt", + "usr/share/ca-certificates/mozilla/Certum_Trusted_Network_CA_2.crt", + "usr/share/ca-certificates/mozilla/Certum_Trusted_Root_CA.crt", + "usr/share/ca-certificates/mozilla/CommScope_Public_Trust_ECC_Root-01.crt", + "usr/share/ca-certificates/mozilla/CommScope_Public_Trust_ECC_Root-02.crt", + "usr/share/ca-certificates/mozilla/CommScope_Public_Trust_RSA_Root-01.crt", + "usr/share/ca-certificates/mozilla/CommScope_Public_Trust_RSA_Root-02.crt", + "usr/share/ca-certificates/mozilla/D-TRUST_BR_Root_CA_1_2020.crt", + "usr/share/ca-certificates/mozilla/D-TRUST_BR_Root_CA_2_2023.crt", + "usr/share/ca-certificates/mozilla/D-TRUST_EV_Root_CA_1_2020.crt", + "usr/share/ca-certificates/mozilla/D-TRUST_EV_Root_CA_2_2023.crt", + "usr/share/ca-certificates/mozilla/D-TRUST_Root_Class_3_CA_2_2009.crt", + "usr/share/ca-certificates/mozilla/D-TRUST_Root_Class_3_CA_2_EV_2009.crt", + "usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_CA.crt", + "usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_G2.crt", + "usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_G3.crt", + "usr/share/ca-certificates/mozilla/DigiCert_Global_Root_CA.crt", + "usr/share/ca-certificates/mozilla/DigiCert_Global_Root_G2.crt", + "usr/share/ca-certificates/mozilla/DigiCert_Global_Root_G3.crt", + "usr/share/ca-certificates/mozilla/DigiCert_High_Assurance_EV_Root_CA.crt", + "usr/share/ca-certificates/mozilla/DigiCert_TLS_ECC_P384_Root_G5.crt", + "usr/share/ca-certificates/mozilla/DigiCert_TLS_RSA4096_Root_G5.crt", + "usr/share/ca-certificates/mozilla/DigiCert_Trusted_Root_G4.crt", + "usr/share/ca-certificates/mozilla/Entrust_Root_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/Entrust_Root_Certification_Authority_-_EC1.crt", + "usr/share/ca-certificates/mozilla/Entrust_Root_Certification_Authority_-_G2.crt", + "usr/share/ca-certificates/mozilla/FIRMAPROFESIONAL_CA_ROOT-A_WEB.crt", + "usr/share/ca-certificates/mozilla/GDCA_TrustAUTH_R5_ROOT.crt", + "usr/share/ca-certificates/mozilla/GLOBALTRUST_2020.crt", + "usr/share/ca-certificates/mozilla/GTS_Root_R1.crt", + "usr/share/ca-certificates/mozilla/GTS_Root_R2.crt", + "usr/share/ca-certificates/mozilla/GTS_Root_R3.crt", + "usr/share/ca-certificates/mozilla/GTS_Root_R4.crt", + "usr/share/ca-certificates/mozilla/GlobalSign_ECC_Root_CA_-_R4.crt", + "usr/share/ca-certificates/mozilla/GlobalSign_ECC_Root_CA_-_R5.crt", + "usr/share/ca-certificates/mozilla/GlobalSign_Root_CA_-_R3.crt", + "usr/share/ca-certificates/mozilla/GlobalSign_Root_CA_-_R6.crt", + "usr/share/ca-certificates/mozilla/GlobalSign_Root_E46.crt", + "usr/share/ca-certificates/mozilla/GlobalSign_Root_R46.crt", + "usr/share/ca-certificates/mozilla/Go_Daddy_Root_Certificate_Authority_-_G2.crt", + "usr/share/ca-certificates/mozilla/HARICA_TLS_ECC_Root_CA_2021.crt", + "usr/share/ca-certificates/mozilla/HARICA_TLS_RSA_Root_CA_2021.crt", + "usr/share/ca-certificates/mozilla/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.crt", + "usr/share/ca-certificates/mozilla/Hellenic_Academic_and_Research_Institutions_RootCA_2015.crt", + "usr/share/ca-certificates/mozilla/HiPKI_Root_CA_-_G1.crt", + "usr/share/ca-certificates/mozilla/Hongkong_Post_Root_CA_3.crt", + "usr/share/ca-certificates/mozilla/ISRG_Root_X1.crt", + "usr/share/ca-certificates/mozilla/ISRG_Root_X2.crt", + "usr/share/ca-certificates/mozilla/IdenTrust_Commercial_Root_CA_1.crt", + "usr/share/ca-certificates/mozilla/IdenTrust_Public_Sector_Root_CA_1.crt", + "usr/share/ca-certificates/mozilla/Izenpe.com.crt", + "usr/share/ca-certificates/mozilla/Microsec_e-Szigno_Root_CA_2009.crt", + "usr/share/ca-certificates/mozilla/Microsoft_ECC_Root_Certificate_Authority_2017.crt", + "usr/share/ca-certificates/mozilla/Microsoft_RSA_Root_Certificate_Authority_2017.crt", + "usr/share/ca-certificates/mozilla/NAVER_Global_Root_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/NetLock_Arany_=Class_Gold=_Főtanúsítvány.crt", + "usr/share/ca-certificates/mozilla/OISTE_Server_Root_ECC_G1.crt", + "usr/share/ca-certificates/mozilla/OISTE_Server_Root_RSA_G1.crt", + "usr/share/ca-certificates/mozilla/OISTE_WISeKey_Global_Root_GB_CA.crt", + "usr/share/ca-certificates/mozilla/OISTE_WISeKey_Global_Root_GC_CA.crt", + "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_1_G3.crt", + "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_2.crt", + "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_2_G3.crt", + "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_3.crt", + "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_3_G3.crt", + "usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_ECC.crt", + "usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_RSA_R2.crt", + "usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_ECC.crt", + "usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_RSA.crt", + "usr/share/ca-certificates/mozilla/SSL.com_TLS_ECC_Root_CA_2022.crt", + "usr/share/ca-certificates/mozilla/SSL.com_TLS_RSA_Root_CA_2022.crt", + "usr/share/ca-certificates/mozilla/SZAFIR_ROOT_CA2.crt", + "usr/share/ca-certificates/mozilla/Sectigo_Public_Server_Authentication_Root_E46.crt", + "usr/share/ca-certificates/mozilla/Sectigo_Public_Server_Authentication_Root_R46.crt", + "usr/share/ca-certificates/mozilla/SecureSign_Root_CA12.crt", + "usr/share/ca-certificates/mozilla/SecureSign_Root_CA14.crt", + "usr/share/ca-certificates/mozilla/SecureSign_Root_CA15.crt", + "usr/share/ca-certificates/mozilla/SecureTrust_CA.crt", + "usr/share/ca-certificates/mozilla/Secure_Global_CA.crt", + "usr/share/ca-certificates/mozilla/Security_Communication_ECC_RootCA1.crt", + "usr/share/ca-certificates/mozilla/Security_Communication_RootCA2.crt", + "usr/share/ca-certificates/mozilla/Starfield_Root_Certificate_Authority_-_G2.crt", + "usr/share/ca-certificates/mozilla/Starfield_Services_Root_Certificate_Authority_-_G2.crt", + "usr/share/ca-certificates/mozilla/SwissSign_Gold_CA_-_G2.crt", + "usr/share/ca-certificates/mozilla/SwissSign_RSA_TLS_Root_CA_2022_-_1.crt", + "usr/share/ca-certificates/mozilla/T-TeleSec_GlobalRoot_Class_2.crt", + "usr/share/ca-certificates/mozilla/T-TeleSec_GlobalRoot_Class_3.crt", + "usr/share/ca-certificates/mozilla/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.crt", + "usr/share/ca-certificates/mozilla/TWCA_CYBER_Root_CA.crt", + "usr/share/ca-certificates/mozilla/TWCA_Global_Root_CA.crt", + "usr/share/ca-certificates/mozilla/TWCA_Root_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/Telekom_Security_TLS_ECC_Root_2020.crt", + "usr/share/ca-certificates/mozilla/Telekom_Security_TLS_RSA_Root_2023.crt", + "usr/share/ca-certificates/mozilla/TeliaSonera_Root_CA_v1.crt", + "usr/share/ca-certificates/mozilla/Telia_Root_CA_v2.crt", + "usr/share/ca-certificates/mozilla/TrustAsia_Global_Root_CA_G3.crt", + "usr/share/ca-certificates/mozilla/TrustAsia_Global_Root_CA_G4.crt", + "usr/share/ca-certificates/mozilla/TrustAsia_TLS_ECC_Root_CA.crt", + "usr/share/ca-certificates/mozilla/TrustAsia_TLS_RSA_Root_CA.crt", + "usr/share/ca-certificates/mozilla/Trustwave_Global_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/Trustwave_Global_ECC_P256_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/Trustwave_Global_ECC_P384_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/TunTrust_Root_CA.crt", + "usr/share/ca-certificates/mozilla/UCA_Extended_Validation_Root.crt", + "usr/share/ca-certificates/mozilla/UCA_Global_G2_Root.crt", + "usr/share/ca-certificates/mozilla/USERTrust_ECC_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/USERTrust_RSA_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/certSIGN_ROOT_CA.crt", + "usr/share/ca-certificates/mozilla/certSIGN_Root_CA_G2.crt", + "usr/share/ca-certificates/mozilla/e-Szigno_Root_CA_2017.crt", + "usr/share/ca-certificates/mozilla/ePKI_Root_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/emSign_ECC_Root_CA_-_C3.crt", + "usr/share/ca-certificates/mozilla/emSign_ECC_Root_CA_-_G3.crt", + "usr/share/ca-certificates/mozilla/emSign_Root_CA_-_C1.crt", + "usr/share/ca-certificates/mozilla/emSign_Root_CA_-_G1.crt", + "usr/share/ca-certificates/mozilla/vTrus_ECC_Root_CA.crt", + "usr/share/ca-certificates/mozilla/vTrus_Root_CA.crt" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ca-certificates-bundle@20251003-r0", + "Name": "ca-certificates-bundle", + "Identifier": { + "PURL": "pkg:apk/alpine/ca-certificates-bundle@20251003-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "f667a2210d1d97c1" + }, + "Version": "20251003-r0", + "Arch": "x86_64", + "SrcName": "ca-certificates", + "SrcVersion": "20251003-r0", + "Licenses": [ + "MPL-2.0", + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:63ebe72ba79f548b6cdc8a9894e16a90d80f42b0", + "InstalledFiles": [ + "etc/ssl/cert.pem", + "etc/ssl/certs/ca-certificates.crt", + "etc/ssl1.1/cert.pem", + "etc/ssl1.1/certs" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "curl@8.17.0-r1", + "Name": "curl", + "Identifier": { + "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c4e4a99c2363a971" + }, + "Version": "8.17.0-r1", + "Arch": "x86_64", + "SrcName": "curl", + "SrcVersion": "8.17.0-r1", + "Licenses": [ + "curl" + ], + "Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e", + "DependsOn": [ + "libcurl@8.17.0-r1", + "musl@1.2.5-r21", + "zlib@1.3.1-r2" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:c467d4938a8ffc55afe3b1a6223787e0ecd60036", + "InstalledFiles": [ + "usr/bin/curl", + "usr/bin/wcurl" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "fontconfig@2.17.1-r0", + "Name": "fontconfig", + "Identifier": { + "PURL": "pkg:apk/alpine/fontconfig@2.17.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "70f3d175fa20e060" + }, + "Version": "2.17.1-r0", + "Arch": "x86_64", + "SrcName": "fontconfig", + "SrcVersion": "2.17.1-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "freetype@2.14.1-r0", + "libexpat@2.7.5-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:8037b007516a65d246442a781a05f627073394d0", + "InstalledFiles": [ + "etc/fonts/fonts.conf", + "etc/fonts/conf.d/10-hinting-slight.conf", + "etc/fonts/conf.d/10-scale-bitmap-fonts.conf", + "etc/fonts/conf.d/10-sub-pixel-none.conf", + "etc/fonts/conf.d/10-yes-antialias.conf", + "etc/fonts/conf.d/11-lcdfilter-default.conf", + "etc/fonts/conf.d/20-unhint-small-vera.conf", + "etc/fonts/conf.d/30-metric-aliases.conf", + "etc/fonts/conf.d/40-nonlatin.conf", + "etc/fonts/conf.d/45-generic.conf", + "etc/fonts/conf.d/45-latin.conf", + "etc/fonts/conf.d/48-spacing.conf", + "etc/fonts/conf.d/49-sansserif.conf", + "etc/fonts/conf.d/50-user.conf", + "etc/fonts/conf.d/51-local.conf", + "etc/fonts/conf.d/60-generic.conf", + "etc/fonts/conf.d/60-latin.conf", + "etc/fonts/conf.d/65-fonts-persian.conf", + "etc/fonts/conf.d/65-nonlatin.conf", + "etc/fonts/conf.d/69-unifont.conf", + "etc/fonts/conf.d/70-no-bitmaps-except-emoji.conf", + "etc/fonts/conf.d/80-delicious.conf", + "etc/fonts/conf.d/90-synthetic.conf", + "etc/fonts/conf.d/README", + "usr/bin/fc-cache", + "usr/bin/fc-cat", + "usr/bin/fc-conflist", + "usr/bin/fc-list", + "usr/bin/fc-match", + "usr/bin/fc-pattern", + "usr/bin/fc-query", + "usr/bin/fc-scan", + "usr/bin/fc-validate", + "usr/lib/libfontconfig.so.1", + "usr/lib/libfontconfig.so.1.16.1", + "usr/share/fontconfig/conf.avail/05-reset-dirs-sample.conf", + "usr/share/fontconfig/conf.avail/09-autohint-if-no-hinting.conf", + "usr/share/fontconfig/conf.avail/10-autohint.conf", + "usr/share/fontconfig/conf.avail/10-hinting-full.conf", + "usr/share/fontconfig/conf.avail/10-hinting-medium.conf", + "usr/share/fontconfig/conf.avail/10-hinting-none.conf", + "usr/share/fontconfig/conf.avail/10-hinting-slight.conf", + "usr/share/fontconfig/conf.avail/10-no-antialias.conf", + "usr/share/fontconfig/conf.avail/10-scale-bitmap-fonts.conf", + "usr/share/fontconfig/conf.avail/10-sub-pixel-bgr.conf", + "usr/share/fontconfig/conf.avail/10-sub-pixel-none.conf", + "usr/share/fontconfig/conf.avail/10-sub-pixel-rgb.conf", + "usr/share/fontconfig/conf.avail/10-sub-pixel-vbgr.conf", + "usr/share/fontconfig/conf.avail/10-sub-pixel-vrgb.conf", + "usr/share/fontconfig/conf.avail/10-unhinted.conf", + "usr/share/fontconfig/conf.avail/10-yes-antialias.conf", + "usr/share/fontconfig/conf.avail/11-lcdfilter-default.conf", + "usr/share/fontconfig/conf.avail/11-lcdfilter-legacy.conf", + "usr/share/fontconfig/conf.avail/11-lcdfilter-light.conf", + "usr/share/fontconfig/conf.avail/11-lcdfilter-none.conf", + "usr/share/fontconfig/conf.avail/20-unhint-small-vera.conf", + "usr/share/fontconfig/conf.avail/25-unhint-nonlatin.conf", + "usr/share/fontconfig/conf.avail/30-metric-aliases.conf", + "usr/share/fontconfig/conf.avail/35-lang-normalize.conf", + "usr/share/fontconfig/conf.avail/40-nonlatin.conf", + "usr/share/fontconfig/conf.avail/45-generic.conf", + "usr/share/fontconfig/conf.avail/45-latin.conf", + "usr/share/fontconfig/conf.avail/48-guessfamily.conf", + "usr/share/fontconfig/conf.avail/48-spacing.conf", + "usr/share/fontconfig/conf.avail/49-sansserif.conf", + "usr/share/fontconfig/conf.avail/50-user.conf", + "usr/share/fontconfig/conf.avail/51-local.conf", + "usr/share/fontconfig/conf.avail/60-generic.conf", + "usr/share/fontconfig/conf.avail/60-latin.conf", + "usr/share/fontconfig/conf.avail/65-fonts-persian.conf", + "usr/share/fontconfig/conf.avail/65-khmer.conf", + "usr/share/fontconfig/conf.avail/65-nonlatin.conf", + "usr/share/fontconfig/conf.avail/69-unifont.conf", + "usr/share/fontconfig/conf.avail/70-no-bitmaps-and-emoji.conf", + "usr/share/fontconfig/conf.avail/70-no-bitmaps-except-emoji.conf", + "usr/share/fontconfig/conf.avail/70-no-bitmaps.conf", + "usr/share/fontconfig/conf.avail/70-yes-bitmaps.conf", + "usr/share/fontconfig/conf.avail/80-delicious.conf", + "usr/share/fontconfig/conf.avail/90-synthetic.conf", + "usr/share/xml/fontconfig/fonts.dtd" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "freetype@2.14.1-r0", + "Name": "freetype", + "Identifier": { + "PURL": "pkg:apk/alpine/freetype@2.14.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "21ab81867b035d6b" + }, + "Version": "2.14.1-r0", + "Arch": "x86_64", + "SrcName": "freetype", + "SrcVersion": "2.14.1-r0", + "Licenses": [ + "FTL", + "GPL-2.0-or-later" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "brotli-libs@1.2.0-r0", + "libbz2@1.0.8-r6", + "libpng@1.6.55-r0", + "musl@1.2.5-r21", + "zlib@1.3.1-r2" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:e227f29a00edd7ed5b1e62a050da6532183e60be", + "InstalledFiles": [ + "usr/lib/libfreetype.so.6", + "usr/lib/libfreetype.so.6.20.4" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "geoip@1.6.12-r6", + "Name": "geoip", + "Identifier": { + "PURL": "pkg:apk/alpine/geoip@1.6.12-r6?arch=x86_64\u0026distro=3.23.3", + "UID": "a40f515e64af4e00" + }, + "Version": "1.6.12-r6", + "Arch": "x86_64", + "SrcName": "geoip", + "SrcVersion": "1.6.12-r6", + "Licenses": [ + "LGPL-2.1-or-later" + ], + "Maintainer": "Leonardo Arena \u003crnalrd@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:8f2ea64ecb173949f03ec2371db4b534f142450f", + "InstalledFiles": [ + "usr/bin/geoiplookup", + "usr/bin/geoiplookup6", + "usr/lib/libGeoIP.so.1", + "usr/lib/libGeoIP.so.1.6.12" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "gettext-envsubst@0.24.1-r1", + "Name": "gettext-envsubst", + "Identifier": { + "PURL": "pkg:apk/alpine/gettext-envsubst@0.24.1-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "7fc5d88562c27ca2" + }, + "Version": "0.24.1-r1", + "Arch": "x86_64", + "SrcName": "gettext", + "SrcVersion": "0.24.1-r1", + "Licenses": [ + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "MIT" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "libintl@0.24.1-r1", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "Digest": "sha1:7593f7d82a7c943f0114a5f700788c53afb8a554", + "InstalledFiles": [ + "usr/bin/envsubst" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libapk@3.0.3-r1", + "Name": "libapk", + "Identifier": { + "PURL": "pkg:apk/alpine/libapk@3.0.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "d8a4dac06126e84f" + }, + "Version": "3.0.3-r1", + "Arch": "x86_64", + "SrcName": "apk-tools", + "SrcVersion": "3.0.3-r1", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libcrypto3@3.5.5-r0", + "libssl3@3.5.5-r0", + "musl@1.2.5-r21", + "zlib@1.3.1-r2" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:17d0c18e379eb411aaa3e07392343a2dd6e098cc", + "InstalledFiles": [ + "usr/lib/libapk.so.3.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libavif@1.3.0-r0", + "Name": "libavif", + "Identifier": { + "PURL": "pkg:apk/alpine/libavif@1.3.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "a92c4af89456638d" + }, + "Version": "1.3.0-r0", + "Arch": "x86_64", + "SrcName": "libavif", + "SrcVersion": "1.3.0-r0", + "Licenses": [ + "BSD-2-Clause" + ], + "Maintainer": "Bart Ribbers \u003cbribbers@disroot.org\u003e", + "DependsOn": [ + "aom-libs@3.13.1-r1", + "libdav1d@1.5.2-r0", + "libyuv@0.0.1887.20251502-r1", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:6e0e61c8a9d1cb5a4a5f3faa64fb597844614f93", + "InstalledFiles": [ + "usr/lib/libavif.so.16", + "usr/lib/libavif.so.16.3.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libbsd@0.12.2-r0", + "Name": "libbsd", + "Identifier": { + "PURL": "pkg:apk/alpine/libbsd@0.12.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "e8223f0f48326233" + }, + "Version": "0.12.2-r0", + "Arch": "x86_64", + "SrcName": "libbsd", + "SrcVersion": "0.12.2-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libmd@1.1.0-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:33970b157edad359d05a2c3e6f3460e725549c8b", + "InstalledFiles": [ + "usr/lib/libbsd.so.0", + "usr/lib/libbsd.so.0.12.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libbz2@1.0.8-r6", + "Name": "libbz2", + "Identifier": { + "PURL": "pkg:apk/alpine/libbz2@1.0.8-r6?arch=x86_64\u0026distro=3.23.3", + "UID": "74d7fef128d53896" + }, + "Version": "1.0.8-r6", + "Arch": "x86_64", + "SrcName": "bzip2", + "SrcVersion": "1.0.8-r6", + "Licenses": [ + "bzip-2-1.0.6" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:864d363da11ee24c7920e0d052d2da7f8429251e", + "InstalledFiles": [ + "usr/lib/libbz2.so.1", + "usr/lib/libbz2.so.1.0.8" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libcrypto3@3.5.5-r0", + "Name": "libcrypto3", + "Identifier": { + "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "6778a588f2cebd48" + }, + "Version": "3.5.5-r0", + "Arch": "x86_64", + "SrcName": "openssl", + "SrcVersion": "3.5.5-r0", + "Licenses": [ + "Apache-2.0" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:9ebf6995e814bacff0c04a868b0b27c3e82090f4", + "InstalledFiles": [ + "etc/ssl/ct_log_list.cnf", + "etc/ssl/ct_log_list.cnf.dist", + "etc/ssl/openssl.cnf", + "etc/ssl/openssl.cnf.dist", + "usr/lib/libcrypto.so.3", + "usr/lib/engines-3/afalg.so", + "usr/lib/engines-3/capi.so", + "usr/lib/engines-3/loader_attic.so", + "usr/lib/engines-3/padlock.so", + "usr/lib/ossl-modules/legacy.so" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libcurl@8.17.0-r1", + "Name": "libcurl", + "Identifier": { + "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "85c7760f5617ed48" + }, + "Version": "8.17.0-r1", + "Arch": "x86_64", + "SrcName": "curl", + "SrcVersion": "8.17.0-r1", + "Licenses": [ + "curl" + ], + "Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e", + "DependsOn": [ + "brotli-libs@1.2.0-r0", + "c-ares@1.34.6-r0", + "ca-certificates-bundle@20251003-r0", + "libcrypto3@3.5.5-r0", + "libidn2@2.3.8-r0", + "libpsl@0.21.5-r3", + "libssl3@3.5.5-r0", + "musl@1.2.5-r21", + "nghttp2-libs@1.68.0-r0", + "nghttp3@1.13.1-r0", + "zlib@1.3.1-r2", + "zstd-libs@1.5.7-r2" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:4018e686de80aa87659e95c1e62a3539c1d2542f", + "InstalledFiles": [ + "usr/lib/libcurl.so.4", + "usr/lib/libcurl.so.4.8.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libdav1d@1.5.2-r0", + "Name": "libdav1d", + "Identifier": { + "PURL": "pkg:apk/alpine/libdav1d@1.5.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "b65a4cd7ff34a143" + }, + "Version": "1.5.2-r0", + "Arch": "x86_64", + "SrcName": "dav1d", + "SrcVersion": "1.5.2-r0", + "Licenses": [ + "BSD-2-Clause" + ], + "Maintainer": "Bart Ribbers \u003cbribbers@disroot.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:62a9676453a8b99cfb42148cfd26df3b964bcc1b", + "InstalledFiles": [ + "usr/lib/libdav1d.so.7", + "usr/lib/libdav1d.so.7.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libedit@20251016.3.1-r0", + "Name": "libedit", + "Identifier": { + "PURL": "pkg:apk/alpine/libedit@20251016.3.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "c13fb208e3c71d28" + }, + "Version": "20251016.3.1-r0", + "Arch": "x86_64", + "SrcName": "libedit", + "SrcVersion": "20251016.3.1-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Celeste \u003ccielesti@protonmail.com\u003e", + "DependsOn": [ + "libncursesw@6.5_p20251123-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:463f69335a3223b1ce6856ce3bef5c03fee721bf", + "InstalledFiles": [ + "usr/lib/libedit.so.0", + "usr/lib/libedit.so.0.0.76" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libexpat@2.7.5-r0", + "Name": "libexpat", + "Identifier": { + "PURL": "pkg:apk/alpine/libexpat@2.7.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "60ae354914fcce6c" + }, + "Version": "2.7.5-r0", + "Arch": "x86_64", + "SrcName": "expat", + "SrcVersion": "2.7.5-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:5760d53ddd7cca8a742c672e4e00a475718eacaa", + "InstalledFiles": [ + "usr/lib/libexpat.so.1", + "usr/lib/libexpat.so.1.11.3" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libgcc@15.2.0-r2", + "Name": "libgcc", + "Identifier": { + "PURL": "pkg:apk/alpine/libgcc@15.2.0-r2?arch=x86_64\u0026distro=3.23.3", + "UID": "fe01204cb80c388d" + }, + "Version": "15.2.0-r2", + "Arch": "x86_64", + "SrcName": "gcc", + "SrcVersion": "15.2.0-r2", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-2.1-or-later" + ], + "Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:57fccbe9eebf23f2c4f38ee2a24f8b0bdd508ff7", + "InstalledFiles": [ + "usr/lib/libgcc_s.so.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libgd@2.3.3-r10", + "Name": "libgd", + "Identifier": { + "PURL": "pkg:apk/alpine/libgd@2.3.3-r10?arch=x86_64\u0026distro=3.23.3", + "UID": "65b22f80adc66176" + }, + "Version": "2.3.3-r10", + "Arch": "x86_64", + "SrcName": "gd", + "SrcVersion": "2.3.3-r10", + "Licenses": [ + "GD" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "fontconfig@2.17.1-r0", + "freetype@2.14.1-r0", + "libavif@1.3.0-r0", + "libjpeg-turbo@3.1.2-r0", + "libpng@1.6.55-r0", + "libwebp@1.6.0-r0", + "libxpm@3.5.17-r0", + "musl@1.2.5-r21", + "tiff@4.7.1-r0", + "zlib@1.3.1-r2" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:948454e00c660b6ddf1338a857959222f0888336", + "InstalledFiles": [ + "usr/lib/libgd.so.3", + "usr/lib/libgd.so.3.0.11" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libice@1.1.2-r0", + "Name": "libice", + "Identifier": { + "PURL": "pkg:apk/alpine/libice@1.1.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "99c17cd82ccd171a" + }, + "Version": "1.1.2-r0", + "Arch": "x86_64", + "SrcName": "libice", + "SrcVersion": "1.1.2-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:997a01303f63cee0ba9773f0cd9b26b2eb5e6ace", + "InstalledFiles": [ + "usr/lib/libICE.so.6", + "usr/lib/libICE.so.6.3.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libidn2@2.3.8-r0", + "Name": "libidn2", + "Identifier": { + "PURL": "pkg:apk/alpine/libidn2@2.3.8-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "e2fcbba2f74d78bf" + }, + "Version": "2.3.8-r0", + "Arch": "x86_64", + "SrcName": "libidn2", + "SrcVersion": "2.3.8-r0", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-3.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libunistring@1.4.1-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:b8c5bfa365da5c360a01230db4d71e65af94af3d", + "InstalledFiles": [ + "usr/lib/libidn2.so.0", + "usr/lib/libidn2.so.0.4.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libintl@0.24.1-r1", + "Name": "libintl", + "Identifier": { + "PURL": "pkg:apk/alpine/libintl@0.24.1-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c90c10550691ca73" + }, + "Version": "0.24.1-r1", + "Arch": "x86_64", + "SrcName": "gettext", + "SrcVersion": "0.24.1-r1", + "Licenses": [ + "LGPL-2.1-or-later" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "Digest": "sha1:0222324bb4dfd35e8a3ec821c86eb5afbd43a3af", + "InstalledFiles": [ + "usr/lib/libintl.so.8", + "usr/lib/libintl.so.8.4.3" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libjpeg-turbo@3.1.2-r0", + "Name": "libjpeg-turbo", + "Identifier": { + "PURL": "pkg:apk/alpine/libjpeg-turbo@3.1.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "f80d15900d386c53" + }, + "Version": "3.1.2-r0", + "Arch": "x86_64", + "SrcName": "libjpeg-turbo", + "SrcVersion": "3.1.2-r0", + "Licenses": [ + "BSD-3-Clause", + "IJG", + "Zlib" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:aa025fb7ecf9bd65ef2afe47e3740639521e09ce", + "InstalledFiles": [ + "usr/lib/libjpeg.so.8", + "usr/lib/libjpeg.so.8.3.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libmd@1.1.0-r0", + "Name": "libmd", + "Identifier": { + "PURL": "pkg:apk/alpine/libmd@1.1.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "e263a6bc7bc6d7e0" + }, + "Version": "1.1.0-r0", + "Arch": "x86_64", + "SrcName": "libmd", + "SrcVersion": "1.1.0-r0", + "Licenses": [ + "BSD-3-Clause", + "BSD-2-Clause", + "ISC", + "Beerware", + "Public", + "Domain" + ], + "Maintainer": "omni \u003comni+alpine@hack.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:ce7c57bd1f6628da8ba0d3f2ac18f6d8c93c0346", + "InstalledFiles": [ + "usr/lib/libmd.so.0", + "usr/lib/libmd.so.0.1.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libncursesw@6.5_p20251123-r0", + "Name": "libncursesw", + "Identifier": { + "PURL": "pkg:apk/alpine/libncursesw@6.5_p20251123-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "6a5d130d9eac3aa5" + }, + "Version": "6.5_p20251123-r0", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.5_p20251123-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21", + "ncurses-terminfo-base@6.5_p20251123-r0" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:649d3041c52b80620fb50a98f5979d25ebbe1523", + "InstalledFiles": [ + "usr/lib/libncursesw.so.6", + "usr/lib/libncursesw.so.6.5" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libpng@1.6.55-r0", + "Name": "libpng", + "Identifier": { + "PURL": "pkg:apk/alpine/libpng@1.6.55-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "9c803c58fd4ab240" + }, + "Version": "1.6.55-r0", + "Arch": "x86_64", + "SrcName": "libpng", + "SrcVersion": "1.6.55-r0", + "Licenses": [ + "Libpng" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21", + "zlib@1.3.1-r2" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:03c56da9ef638f4eba0e4315bfa9b1966c26b328", + "InstalledFiles": [ + "usr/lib/libpng16.so.16", + "usr/lib/libpng16.so.16.55.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libpsl@0.21.5-r3", + "Name": "libpsl", + "Identifier": { + "PURL": "pkg:apk/alpine/libpsl@0.21.5-r3?arch=x86_64\u0026distro=3.23.3", + "UID": "9fb5bd2254e54a0" + }, + "Version": "0.21.5-r3", + "Arch": "x86_64", + "SrcName": "libpsl", + "SrcVersion": "0.21.5-r3", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libidn2@2.3.8-r0", + "libunistring@1.4.1-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:b663c00f920a93be49c825555aa1a212e4287393", + "InstalledFiles": [ + "usr/lib/libpsl.so.5", + "usr/lib/libpsl.so.5.3.5" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libsharpyuv@1.6.0-r0", + "Name": "libsharpyuv", + "Identifier": { + "PURL": "pkg:apk/alpine/libsharpyuv@1.6.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "8d52c69285b703" + }, + "Version": "1.6.0-r0", + "Arch": "x86_64", + "SrcName": "libwebp", + "SrcVersion": "1.6.0-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:9bbf3958ac62e163084cde753276246e56ff298b", + "InstalledFiles": [ + "usr/lib/libsharpyuv.so.0", + "usr/lib/libsharpyuv.so.0.1.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libsm@1.2.6-r0", + "Name": "libsm", + "Identifier": { + "PURL": "pkg:apk/alpine/libsm@1.2.6-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "927edab0a11162d6" + }, + "Version": "1.2.6-r0", + "Arch": "x86_64", + "SrcName": "libsm", + "SrcVersion": "1.2.6-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libice@1.1.2-r0", + "libuuid@2.41.2-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:244b3b3e68f3c6c11c6202320109d460a2498e76", + "InstalledFiles": [ + "usr/lib/libSM.so.6", + "usr/lib/libSM.so.6.0.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libssl3@3.5.5-r0", + "Name": "libssl3", + "Identifier": { + "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "bca2260902e2ef48" + }, + "Version": "3.5.5-r0", + "Arch": "x86_64", + "SrcName": "openssl", + "SrcVersion": "3.5.5-r0", + "Licenses": [ + "Apache-2.0" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libcrypto3@3.5.5-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:12234895b6577cddcbe3450406f357600e8a6951", + "InstalledFiles": [ + "usr/lib/libssl.so.3" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libstdc++@15.2.0-r2", + "Name": "libstdc++", + "Identifier": { + "PURL": "pkg:apk/alpine/libstdc%2B%2B@15.2.0-r2?arch=x86_64\u0026distro=3.23.3", + "UID": "45c1717355985287" + }, + "Version": "15.2.0-r2", + "Arch": "x86_64", + "SrcName": "gcc", + "SrcVersion": "15.2.0-r2", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-2.1-or-later" + ], + "Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e", + "DependsOn": [ + "libgcc@15.2.0-r2", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:528d77417a16706468af852f2859ad00f176e266", + "InstalledFiles": [ + "usr/lib/libstdc++.so.6", + "usr/lib/libstdc++.so.6.0.34" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libunistring@1.4.1-r0", + "Name": "libunistring", + "Identifier": { + "PURL": "pkg:apk/alpine/libunistring@1.4.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "4e0ee8fa7d9a5823" + }, + "Version": "1.4.1-r0", + "Arch": "x86_64", + "SrcName": "libunistring", + "SrcVersion": "1.4.1-r0", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-3.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:6e56562bde456bee5971787d3d95c34e84ced797", + "InstalledFiles": [ + "usr/lib/libunistring.so.5", + "usr/lib/libunistring.so.5.2.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libuuid@2.41.2-r0", + "Name": "libuuid", + "Identifier": { + "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "509022c493029e03" + }, + "Version": "2.41.2-r0", + "Arch": "x86_64", + "SrcName": "util-linux", + "SrcVersion": "2.41.2-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:0050e9a7637cd71596beab9996afd0e335489016", + "InstalledFiles": [ + "usr/lib/libuuid.so.1", + "usr/lib/libuuid.so.1.3.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libwebp@1.6.0-r0", + "Name": "libwebp", + "Identifier": { + "PURL": "pkg:apk/alpine/libwebp@1.6.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "3a5205b94800cfd5" + }, + "Version": "1.6.0-r0", + "Arch": "x86_64", + "SrcName": "libwebp", + "SrcVersion": "1.6.0-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libsharpyuv@1.6.0-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:46f79fe406ce611058a6c0ce995ebe85f7b73c7a", + "InstalledFiles": [ + "usr/lib/libwebp.so.7", + "usr/lib/libwebp.so.7.2.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libx11@1.8.12-r1", + "Name": "libx11", + "Identifier": { + "PURL": "pkg:apk/alpine/libx11@1.8.12-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "a425120d26ddc2d8" + }, + "Version": "1.8.12-r1", + "Arch": "x86_64", + "SrcName": "libx11", + "SrcVersion": "1.8.12-r1", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libxcb@1.17.0-r1", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:689b36ec47d6c9abb9cbd0c7067ba4636568dbd5", + "InstalledFiles": [ + "usr/lib/libX11-xcb.so.1", + "usr/lib/libX11-xcb.so.1.0.0", + "usr/lib/libX11.so.6", + "usr/lib/libX11.so.6.4.0", + "usr/share/X11/XErrorDB", + "usr/share/X11/Xcms.txt", + "usr/share/X11/locale/compose.dir", + "usr/share/X11/locale/locale.alias", + "usr/share/X11/locale/locale.dir", + "usr/share/X11/locale/C/Compose", + "usr/share/X11/locale/C/XI18N_OBJS", + "usr/share/X11/locale/C/XLC_LOCALE", + "usr/share/X11/locale/am_ET.UTF-8/Compose", + "usr/share/X11/locale/am_ET.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/am_ET.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/armscii-8/Compose", + "usr/share/X11/locale/armscii-8/XI18N_OBJS", + "usr/share/X11/locale/armscii-8/XLC_LOCALE", + "usr/share/X11/locale/cs_CZ.UTF-8/Compose", + "usr/share/X11/locale/cs_CZ.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/cs_CZ.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/el_GR.UTF-8/Compose", + "usr/share/X11/locale/el_GR.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/el_GR.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/en_US.UTF-8/Compose", + "usr/share/X11/locale/en_US.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/en_US.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/fi_FI.UTF-8/Compose", + "usr/share/X11/locale/fi_FI.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/fi_FI.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/georgian-academy/Compose", + "usr/share/X11/locale/georgian-academy/XI18N_OBJS", + "usr/share/X11/locale/georgian-academy/XLC_LOCALE", + "usr/share/X11/locale/georgian-ps/Compose", + "usr/share/X11/locale/georgian-ps/XI18N_OBJS", + "usr/share/X11/locale/georgian-ps/XLC_LOCALE", + "usr/share/X11/locale/ibm-cp1133/Compose", + "usr/share/X11/locale/ibm-cp1133/XI18N_OBJS", + "usr/share/X11/locale/ibm-cp1133/XLC_LOCALE", + "usr/share/X11/locale/iscii-dev/Compose", + "usr/share/X11/locale/iscii-dev/XI18N_OBJS", + "usr/share/X11/locale/iscii-dev/XLC_LOCALE", + "usr/share/X11/locale/isiri-3342/Compose", + "usr/share/X11/locale/isiri-3342/XI18N_OBJS", + "usr/share/X11/locale/isiri-3342/XLC_LOCALE", + "usr/share/X11/locale/iso8859-1/Compose", + "usr/share/X11/locale/iso8859-1/XI18N_OBJS", + "usr/share/X11/locale/iso8859-1/XLC_LOCALE", + "usr/share/X11/locale/iso8859-10/Compose", + "usr/share/X11/locale/iso8859-10/XI18N_OBJS", + "usr/share/X11/locale/iso8859-10/XLC_LOCALE", + "usr/share/X11/locale/iso8859-11/Compose", + "usr/share/X11/locale/iso8859-11/XI18N_OBJS", + "usr/share/X11/locale/iso8859-11/XLC_LOCALE", + "usr/share/X11/locale/iso8859-13/Compose", + "usr/share/X11/locale/iso8859-13/XI18N_OBJS", + "usr/share/X11/locale/iso8859-13/XLC_LOCALE", + "usr/share/X11/locale/iso8859-14/Compose", + "usr/share/X11/locale/iso8859-14/XI18N_OBJS", + "usr/share/X11/locale/iso8859-14/XLC_LOCALE", + "usr/share/X11/locale/iso8859-15/Compose", + "usr/share/X11/locale/iso8859-15/XI18N_OBJS", + "usr/share/X11/locale/iso8859-15/XLC_LOCALE", + "usr/share/X11/locale/iso8859-2/Compose", + "usr/share/X11/locale/iso8859-2/XI18N_OBJS", + "usr/share/X11/locale/iso8859-2/XLC_LOCALE", + "usr/share/X11/locale/iso8859-3/Compose", + "usr/share/X11/locale/iso8859-3/XI18N_OBJS", + "usr/share/X11/locale/iso8859-3/XLC_LOCALE", + "usr/share/X11/locale/iso8859-4/Compose", + "usr/share/X11/locale/iso8859-4/XI18N_OBJS", + "usr/share/X11/locale/iso8859-4/XLC_LOCALE", + "usr/share/X11/locale/iso8859-5/Compose", + "usr/share/X11/locale/iso8859-5/XI18N_OBJS", + "usr/share/X11/locale/iso8859-5/XLC_LOCALE", + "usr/share/X11/locale/iso8859-6/Compose", + "usr/share/X11/locale/iso8859-6/XI18N_OBJS", + "usr/share/X11/locale/iso8859-6/XLC_LOCALE", + "usr/share/X11/locale/iso8859-7/Compose", + "usr/share/X11/locale/iso8859-7/XI18N_OBJS", + "usr/share/X11/locale/iso8859-7/XLC_LOCALE", + "usr/share/X11/locale/iso8859-8/Compose", + "usr/share/X11/locale/iso8859-8/XI18N_OBJS", + "usr/share/X11/locale/iso8859-8/XLC_LOCALE", + "usr/share/X11/locale/iso8859-9/Compose", + "usr/share/X11/locale/iso8859-9/XI18N_OBJS", + "usr/share/X11/locale/iso8859-9/XLC_LOCALE", + "usr/share/X11/locale/iso8859-9e/Compose", + "usr/share/X11/locale/iso8859-9e/XI18N_OBJS", + "usr/share/X11/locale/iso8859-9e/XLC_LOCALE", + "usr/share/X11/locale/ja/Compose", + "usr/share/X11/locale/ja/XI18N_OBJS", + "usr/share/X11/locale/ja/XLC_LOCALE", + "usr/share/X11/locale/ja.JIS/Compose", + "usr/share/X11/locale/ja.JIS/XI18N_OBJS", + "usr/share/X11/locale/ja.JIS/XLC_LOCALE", + "usr/share/X11/locale/ja.SJIS/Compose", + "usr/share/X11/locale/ja.SJIS/XI18N_OBJS", + "usr/share/X11/locale/ja.SJIS/XLC_LOCALE", + "usr/share/X11/locale/ja_JP.UTF-8/Compose", + "usr/share/X11/locale/ja_JP.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/ja_JP.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/km_KH.UTF-8/Compose", + "usr/share/X11/locale/km_KH.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/km_KH.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/ko/Compose", + "usr/share/X11/locale/ko/XI18N_OBJS", + "usr/share/X11/locale/ko/XLC_LOCALE", + "usr/share/X11/locale/ko_KR.UTF-8/Compose", + "usr/share/X11/locale/ko_KR.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/ko_KR.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/koi8-c/Compose", + "usr/share/X11/locale/koi8-c/XI18N_OBJS", + "usr/share/X11/locale/koi8-c/XLC_LOCALE", + "usr/share/X11/locale/koi8-r/Compose", + "usr/share/X11/locale/koi8-r/XI18N_OBJS", + "usr/share/X11/locale/koi8-r/XLC_LOCALE", + "usr/share/X11/locale/koi8-u/Compose", + "usr/share/X11/locale/koi8-u/XI18N_OBJS", + "usr/share/X11/locale/koi8-u/XLC_LOCALE", + "usr/share/X11/locale/microsoft-cp1251/Compose", + "usr/share/X11/locale/microsoft-cp1251/XI18N_OBJS", + "usr/share/X11/locale/microsoft-cp1251/XLC_LOCALE", + "usr/share/X11/locale/microsoft-cp1255/Compose", + "usr/share/X11/locale/microsoft-cp1255/XI18N_OBJS", + "usr/share/X11/locale/microsoft-cp1255/XLC_LOCALE", + "usr/share/X11/locale/microsoft-cp1256/Compose", + "usr/share/X11/locale/microsoft-cp1256/XI18N_OBJS", + "usr/share/X11/locale/microsoft-cp1256/XLC_LOCALE", + "usr/share/X11/locale/mulelao-1/Compose", + "usr/share/X11/locale/mulelao-1/XI18N_OBJS", + "usr/share/X11/locale/mulelao-1/XLC_LOCALE", + "usr/share/X11/locale/nokhchi-1/Compose", + "usr/share/X11/locale/nokhchi-1/XI18N_OBJS", + "usr/share/X11/locale/nokhchi-1/XLC_LOCALE", + "usr/share/X11/locale/pt_BR.UTF-8/Compose", + "usr/share/X11/locale/pt_BR.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/pt_BR.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/pt_PT.UTF-8/Compose", + "usr/share/X11/locale/pt_PT.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/pt_PT.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/ru_RU.UTF-8/Compose", + "usr/share/X11/locale/ru_RU.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/ru_RU.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/sr_RS.UTF-8/Compose", + "usr/share/X11/locale/sr_RS.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/sr_RS.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/tatar-cyr/Compose", + "usr/share/X11/locale/tatar-cyr/XI18N_OBJS", + "usr/share/X11/locale/tatar-cyr/XLC_LOCALE", + "usr/share/X11/locale/th_TH/Compose", + "usr/share/X11/locale/th_TH/XI18N_OBJS", + "usr/share/X11/locale/th_TH/XLC_LOCALE", + "usr/share/X11/locale/th_TH.UTF-8/Compose", + "usr/share/X11/locale/th_TH.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/th_TH.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/tscii-0/Compose", + "usr/share/X11/locale/tscii-0/XI18N_OBJS", + "usr/share/X11/locale/tscii-0/XLC_LOCALE", + "usr/share/X11/locale/vi_VN.tcvn/Compose", + "usr/share/X11/locale/vi_VN.tcvn/XI18N_OBJS", + "usr/share/X11/locale/vi_VN.tcvn/XLC_LOCALE", + "usr/share/X11/locale/vi_VN.viscii/Compose", + "usr/share/X11/locale/vi_VN.viscii/XI18N_OBJS", + "usr/share/X11/locale/vi_VN.viscii/XLC_LOCALE", + "usr/share/X11/locale/zh_CN/Compose", + "usr/share/X11/locale/zh_CN/XI18N_OBJS", + "usr/share/X11/locale/zh_CN/XLC_LOCALE", + "usr/share/X11/locale/zh_CN.UTF-8/Compose", + "usr/share/X11/locale/zh_CN.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/zh_CN.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/zh_CN.gb18030/Compose", + "usr/share/X11/locale/zh_CN.gb18030/XI18N_OBJS", + "usr/share/X11/locale/zh_CN.gb18030/XLC_LOCALE", + "usr/share/X11/locale/zh_CN.gbk/Compose", + "usr/share/X11/locale/zh_CN.gbk/XI18N_OBJS", + "usr/share/X11/locale/zh_CN.gbk/XLC_LOCALE", + "usr/share/X11/locale/zh_HK.UTF-8/Compose", + "usr/share/X11/locale/zh_HK.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/zh_HK.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/zh_HK.big5/Compose", + "usr/share/X11/locale/zh_HK.big5/XI18N_OBJS", + "usr/share/X11/locale/zh_HK.big5/XLC_LOCALE", + "usr/share/X11/locale/zh_HK.big5hkscs/Compose", + "usr/share/X11/locale/zh_HK.big5hkscs/XI18N_OBJS", + "usr/share/X11/locale/zh_HK.big5hkscs/XLC_LOCALE", + "usr/share/X11/locale/zh_TW/Compose", + "usr/share/X11/locale/zh_TW/XI18N_OBJS", + "usr/share/X11/locale/zh_TW/XLC_LOCALE", + "usr/share/X11/locale/zh_TW.UTF-8/Compose", + "usr/share/X11/locale/zh_TW.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/zh_TW.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/zh_TW.big5/Compose", + "usr/share/X11/locale/zh_TW.big5/XI18N_OBJS", + "usr/share/X11/locale/zh_TW.big5/XLC_LOCALE" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxau@1.0.12-r0", + "Name": "libxau", + "Identifier": { + "PURL": "pkg:apk/alpine/libxau@1.0.12-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "aa0bb8a98c218213" + }, + "Version": "1.0.12-r0", + "Arch": "x86_64", + "SrcName": "libxau", + "SrcVersion": "1.0.12-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:89d2bc9daae3cb0e2ae095db6866357b7653f341", + "InstalledFiles": [ + "usr/lib/libXau.so.6", + "usr/lib/libXau.so.6.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxcb@1.17.0-r1", + "Name": "libxcb", + "Identifier": { + "PURL": "pkg:apk/alpine/libxcb@1.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "6f6901ad7b331681" + }, + "Version": "1.17.0-r1", + "Arch": "x86_64", + "SrcName": "libxcb", + "SrcVersion": "1.17.0-r1", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libxau@1.0.12-r0", + "libxdmcp@1.1.5-r1", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:61b06f883e8f8d2d8ee360e4dac04ac037fcca13", + "InstalledFiles": [ + "usr/lib/libxcb-composite.so.0", + "usr/lib/libxcb-composite.so.0.0.0", + "usr/lib/libxcb-damage.so.0", + "usr/lib/libxcb-damage.so.0.0.0", + "usr/lib/libxcb-dbe.so.0", + "usr/lib/libxcb-dbe.so.0.0.0", + "usr/lib/libxcb-dpms.so.0", + "usr/lib/libxcb-dpms.so.0.0.0", + "usr/lib/libxcb-dri2.so.0", + "usr/lib/libxcb-dri2.so.0.0.0", + "usr/lib/libxcb-dri3.so.0", + "usr/lib/libxcb-dri3.so.0.1.0", + "usr/lib/libxcb-glx.so.0", + "usr/lib/libxcb-glx.so.0.0.0", + "usr/lib/libxcb-present.so.0", + "usr/lib/libxcb-present.so.0.0.0", + "usr/lib/libxcb-randr.so.0", + "usr/lib/libxcb-randr.so.0.1.0", + "usr/lib/libxcb-record.so.0", + "usr/lib/libxcb-record.so.0.0.0", + "usr/lib/libxcb-render.so.0", + "usr/lib/libxcb-render.so.0.0.0", + "usr/lib/libxcb-res.so.0", + "usr/lib/libxcb-res.so.0.0.0", + "usr/lib/libxcb-screensaver.so.0", + "usr/lib/libxcb-screensaver.so.0.0.0", + "usr/lib/libxcb-shape.so.0", + "usr/lib/libxcb-shape.so.0.0.0", + "usr/lib/libxcb-shm.so.0", + "usr/lib/libxcb-shm.so.0.0.0", + "usr/lib/libxcb-sync.so.1", + "usr/lib/libxcb-sync.so.1.0.0", + "usr/lib/libxcb-xf86dri.so.0", + "usr/lib/libxcb-xf86dri.so.0.0.0", + "usr/lib/libxcb-xfixes.so.0", + "usr/lib/libxcb-xfixes.so.0.0.0", + "usr/lib/libxcb-xinerama.so.0", + "usr/lib/libxcb-xinerama.so.0.0.0", + "usr/lib/libxcb-xinput.so.0", + "usr/lib/libxcb-xinput.so.0.1.0", + "usr/lib/libxcb-xkb.so.1", + "usr/lib/libxcb-xkb.so.1.0.0", + "usr/lib/libxcb-xtest.so.0", + "usr/lib/libxcb-xtest.so.0.0.0", + "usr/lib/libxcb-xv.so.0", + "usr/lib/libxcb-xv.so.0.0.0", + "usr/lib/libxcb-xvmc.so.0", + "usr/lib/libxcb-xvmc.so.0.0.0", + "usr/lib/libxcb.so.1", + "usr/lib/libxcb.so.1.1.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxdmcp@1.1.5-r1", + "Name": "libxdmcp", + "Identifier": { + "PURL": "pkg:apk/alpine/libxdmcp@1.1.5-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "4fca0d7ff08ca578" + }, + "Version": "1.1.5-r1", + "Arch": "x86_64", + "SrcName": "libxdmcp", + "SrcVersion": "1.1.5-r1", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libbsd@0.12.2-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:99a24c0fa12282b5ef89a6e732a8d494b7696d9d", + "InstalledFiles": [ + "usr/lib/libXdmcp.so.6", + "usr/lib/libXdmcp.so.6.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxext@1.3.6-r2", + "Name": "libxext", + "Identifier": { + "PURL": "pkg:apk/alpine/libxext@1.3.6-r2?arch=x86_64\u0026distro=3.23.3", + "UID": "57ff00875e99d22c" + }, + "Version": "1.3.6-r2", + "Arch": "x86_64", + "SrcName": "libxext", + "SrcVersion": "1.3.6-r2", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libx11@1.8.12-r1", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:92fb4f12c2170403d6a48c7485ecaee40c84bee2", + "InstalledFiles": [ + "usr/lib/libXext.so.6", + "usr/lib/libXext.so.6.4.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxml2@2.13.9-r0", + "Name": "libxml2", + "Identifier": { + "PURL": "pkg:apk/alpine/libxml2@2.13.9-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "ce9ff006e72f7256" + }, + "Version": "2.13.9-r0", + "Arch": "x86_64", + "SrcName": "libxml2", + "SrcVersion": "2.13.9-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21", + "xz-libs@5.8.2-r0", + "zlib@1.3.1-r2" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:9fb56eb6e62b7b6658a8abe14cded8d87a47ebc7", + "InstalledFiles": [ + "usr/lib/libxml2.so.2", + "usr/lib/libxml2.so.2.13.9" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxpm@3.5.17-r0", + "Name": "libxpm", + "Identifier": { + "PURL": "pkg:apk/alpine/libxpm@3.5.17-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "eb108d14a7e73e9c" + }, + "Version": "3.5.17-r0", + "Arch": "x86_64", + "SrcName": "libxpm", + "SrcVersion": "3.5.17-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libx11@1.8.12-r1", + "libxext@1.3.6-r2", + "libxt@1.3.1-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:50af3a739664e6d3dc92b94be46d3b96c0b11da8", + "InstalledFiles": [ + "usr/bin/cxpm", + "usr/bin/sxpm", + "usr/lib/libXpm.so.4", + "usr/lib/libXpm.so.4.11.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxslt@1.1.43-r3", + "Name": "libxslt", + "Identifier": { + "PURL": "pkg:apk/alpine/libxslt@1.1.43-r3?arch=x86_64\u0026distro=3.23.3", + "UID": "3a1c588b7ca6e66a" + }, + "Version": "1.1.43-r3", + "Arch": "x86_64", + "SrcName": "libxslt", + "SrcVersion": "1.1.43-r3", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libxml2@2.13.9-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:7d73182371fbf2141e137329e5432b94551bdd1b", + "InstalledFiles": [ + "usr/bin/xsltproc", + "usr/lib/libexslt.so.0", + "usr/lib/libexslt.so.0.8.24", + "usr/lib/libxslt.so.1", + "usr/lib/libxslt.so.1.1.43" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxt@1.3.1-r0", + "Name": "libxt", + "Identifier": { + "PURL": "pkg:apk/alpine/libxt@1.3.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "d94c77e6d9f596b4" + }, + "Version": "1.3.1-r0", + "Arch": "x86_64", + "SrcName": "libxt", + "SrcVersion": "1.3.1-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libice@1.1.2-r0", + "libsm@1.2.6-r0", + "libx11@1.8.12-r1", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:1cffd892c392dcaac9ad017c999f9e268b5f8ee1", + "InstalledFiles": [ + "usr/lib/libXt.so.6", + "usr/lib/libXt.so.6.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libyuv@0.0.1887.20251502-r1", + "Name": "libyuv", + "Identifier": { + "PURL": "pkg:apk/alpine/libyuv@0.0.1887.20251502-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "7fa232d8c24a770f" + }, + "Version": "0.0.1887.20251502-r1", + "Arch": "x86_64", + "SrcName": "libyuv", + "SrcVersion": "0.0.1887.20251502-r1", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Andy Postnikov \u003capostnikov@gmail.com\u003e", + "DependsOn": [ + "libgcc@15.2.0-r2", + "libjpeg-turbo@3.1.2-r0", + "libstdc++@15.2.0-r2", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:8335fd57f5a479534322e6ac74968fdc7564d8d0", + "InstalledFiles": [ + "usr/bin/yuvconvert", + "usr/lib/libyuv.so" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "musl@1.2.5-r21", + "Name": "musl", + "Identifier": { + "PURL": "pkg:apk/alpine/musl@1.2.5-r21?arch=x86_64\u0026distro=3.23.3", + "UID": "750ab06f52f2bfe9" + }, + "Version": "1.2.5-r21", + "Arch": "x86_64", + "SrcName": "musl", + "SrcVersion": "1.2.5-r21", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:d05a75ec13e1a7a8bab56ce7cd3dc79bd727e698", + "InstalledFiles": [ + "lib/ld-musl-x86_64.so.1", + "lib/libc.musl-x86_64.so.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "musl-utils@1.2.5-r21", + "Name": "musl-utils", + "Identifier": { + "PURL": "pkg:apk/alpine/musl-utils@1.2.5-r21?arch=x86_64\u0026distro=3.23.3", + "UID": "9dadd6d4093981ad" + }, + "Version": "1.2.5-r21", + "Arch": "x86_64", + "SrcName": "musl", + "SrcVersion": "1.2.5-r21", + "Licenses": [ + "MIT", + "BSD-2-Clause", + "GPL-2.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21", + "scanelf@1.3.8-r2" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:daa79528d2cf877f6d656207a818d43c8dea9a30", + "InstalledFiles": [ + "sbin/ldconfig", + "usr/bin/getconf", + "usr/bin/getent", + "usr/bin/iconv", + "usr/bin/ldd" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ncurses-terminfo-base@6.5_p20251123-r0", + "Name": "ncurses-terminfo-base", + "Identifier": { + "PURL": "pkg:apk/alpine/ncurses-terminfo-base@6.5_p20251123-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "5acf10991828fa7a" + }, + "Version": "6.5_p20251123-r0", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.5_p20251123-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:57bd1d8124ec957eefea2314bdf45b0ed1068cee", + "InstalledFiles": [ + "etc/terminfo/a/alacritty", + "etc/terminfo/a/ansi", + "etc/terminfo/d/dumb", + "etc/terminfo/g/gnome", + "etc/terminfo/g/gnome-256color", + "etc/terminfo/k/konsole", + "etc/terminfo/k/konsole-256color", + "etc/terminfo/k/konsole-linux", + "etc/terminfo/l/linux", + "etc/terminfo/p/putty", + "etc/terminfo/p/putty-256color", + "etc/terminfo/r/rxvt", + "etc/terminfo/r/rxvt-256color", + "etc/terminfo/s/screen", + "etc/terminfo/s/screen-256color", + "etc/terminfo/s/st-0.6", + "etc/terminfo/s/st-0.7", + "etc/terminfo/s/st-0.8", + "etc/terminfo/s/st-0.8.5", + "etc/terminfo/s/st-16color", + "etc/terminfo/s/st-256color", + "etc/terminfo/s/st-direct", + "etc/terminfo/s/sun", + "etc/terminfo/t/terminator", + "etc/terminfo/t/terminology", + "etc/terminfo/t/terminology-0.6.1", + "etc/terminfo/t/terminology-1.0.0", + "etc/terminfo/t/terminology-1.8.1", + "etc/terminfo/t/tmux", + "etc/terminfo/t/tmux-256color", + "etc/terminfo/v/vt100", + "etc/terminfo/v/vt102", + "etc/terminfo/v/vt200", + "etc/terminfo/v/vt220", + "etc/terminfo/v/vt52", + "etc/terminfo/v/vte", + "etc/terminfo/v/vte-256color", + "etc/terminfo/x/xterm", + "etc/terminfo/x/xterm-256color", + "etc/terminfo/x/xterm-color", + "etc/terminfo/x/xterm-xfree86" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nghttp2-libs@1.68.0-r0", + "Name": "nghttp2-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/nghttp2-libs@1.68.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "802c936f9e7891b2" + }, + "Version": "1.68.0-r0", + "Arch": "x86_64", + "SrcName": "nghttp2", + "SrcVersion": "1.68.0-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:584b6a1b0aed58a3f543bfd77729b0d8a8b1745b", + "InstalledFiles": [ + "usr/lib/libnghttp2.so.14", + "usr/lib/libnghttp2.so.14.29.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nghttp3@1.13.1-r0", + "Name": "nghttp3", + "Identifier": { + "PURL": "pkg:apk/alpine/nghttp3@1.13.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "7999d360d1276f40" + }, + "Version": "1.13.1-r0", + "Arch": "x86_64", + "SrcName": "nghttp3", + "SrcVersion": "1.13.1-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Jakub Jirutka \u003cjakub@jirutka.cz\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:e48fcb3e81f7e46a42e3926d8513c83b7798774b", + "InstalledFiles": [ + "usr/lib/libnghttp3.so.9", + "usr/lib/libnghttp3.so.9.5.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nginx@1.28.3-r1", + "Name": "nginx", + "Identifier": { + "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8bdce2a9d53051b3" + }, + "Version": "1.28.3-r1", + "Arch": "x86_64", + "SrcName": "nginx", + "SrcVersion": "1.28.3-r1", + "Licenses": [ + "2-clause", + "BSD-3-Clause", + "license" + ], + "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "libcrypto3@3.5.5-r0", + "libssl3@3.5.5-r0", + "musl@1.2.5-r21", + "pcre2@10.47-r0", + "zlib@1.3.1-r2" + ], + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "Digest": "sha1:dea6a746d0881ec71c3ec7bd2e9e57640da2235f", + "InstalledFiles": [ + "etc/init.d/nginx", + "etc/init.d/nginx-debug", + "etc/logrotate.d/nginx", + "etc/nginx/fastcgi.conf", + "etc/nginx/fastcgi_params", + "etc/nginx/mime.types", + "etc/nginx/modules", + "etc/nginx/nginx.conf", + "etc/nginx/scgi_params", + "etc/nginx/uwsgi_params", + "etc/nginx/conf.d/default.conf", + "usr/sbin/nginx", + "usr/sbin/nginx-debug", + "usr/share/licenses/nginx/COPYRIGHT", + "usr/share/man/man8/nginx.8.gz", + "usr/share/nginx/html/50x.html", + "usr/share/nginx/html/index.html" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nginx-module-acme@1.28.3.0.3.1-r1", + "Name": "nginx-module-acme", + "Identifier": { + "PURL": "pkg:apk/alpine/nginx-module-acme@1.28.3.0.3.1-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "bb37055f6eef4ca8" + }, + "Version": "1.28.3.0.3.1-r1", + "Arch": "x86_64", + "SrcName": "nginx-module-acme", + "SrcVersion": "1.28.3.0.3.1-r1", + "Licenses": [ + "2-clause", + "BSD-3-Clause", + "license" + ], + "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "libgcc@15.2.0-r2", + "musl@1.2.5-r21", + "nginx@1.28.3-r1" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:b108c1a13c4b8b83c6a784405dbbad1f91c757c2", + "InstalledFiles": [ + "usr/lib/nginx/modules/ngx_http_acme_module-debug.so", + "usr/lib/nginx/modules/ngx_http_acme_module.so", + "usr/share/licenses/nginx-module-acme/COPYRIGHT" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nginx-module-geoip@1.28.3-r1", + "Name": "nginx-module-geoip", + "Identifier": { + "PURL": "pkg:apk/alpine/nginx-module-geoip@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "db1b1d0252bc58df" + }, + "Version": "1.28.3-r1", + "Arch": "x86_64", + "SrcName": "nginx-module-geoip", + "SrcVersion": "1.28.3-r1", + "Licenses": [ + "2-clause", + "BSD-3-Clause", + "license" + ], + "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "geoip@1.6.12-r6", + "musl@1.2.5-r21", + "nginx@1.28.3-r1" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:bacb3265dfe077670e913138a0c21da9fb929d90", + "InstalledFiles": [ + "usr/lib/nginx/modules/ngx_http_geoip_module-debug.so", + "usr/lib/nginx/modules/ngx_http_geoip_module.so", + "usr/lib/nginx/modules/ngx_stream_geoip_module-debug.so", + "usr/lib/nginx/modules/ngx_stream_geoip_module.so", + "usr/share/licenses/nginx-module-geoip/COPYRIGHT" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nginx-module-image-filter@1.28.3-r1", + "Name": "nginx-module-image-filter", + "Identifier": { + "PURL": "pkg:apk/alpine/nginx-module-image-filter@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "d51155adfd3ac0fa" + }, + "Version": "1.28.3-r1", + "Arch": "x86_64", + "SrcName": "nginx-module-image-filter", + "SrcVersion": "1.28.3-r1", + "Licenses": [ + "2-clause", + "BSD-3-Clause", + "license" + ], + "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "libgd@2.3.3-r10", + "musl@1.2.5-r21", + "nginx@1.28.3-r1" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:60b0b0c575765646982023c66f7bb95ad4670307", + "InstalledFiles": [ + "usr/lib/nginx/modules/ngx_http_image_filter_module-debug.so", + "usr/lib/nginx/modules/ngx_http_image_filter_module.so", + "usr/share/licenses/nginx-module-image-filter/COPYRIGHT" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nginx-module-njs@1.28.3.0.9.6-r1", + "Name": "nginx-module-njs", + "Identifier": { + "PURL": "pkg:apk/alpine/nginx-module-njs@1.28.3.0.9.6-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "f336ec3ee9c2ec8f" + }, + "Version": "1.28.3.0.9.6-r1", + "Arch": "x86_64", + "SrcName": "nginx-module-njs", + "SrcVersion": "1.28.3.0.9.6-r1", + "Licenses": [ + "2-clause", + "BSD-3-Clause", + "license" + ], + "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "libcrypto3@3.5.5-r0", + "libedit@20251016.3.1-r0", + "libxml2@2.13.9-r0", + "musl@1.2.5-r21", + "nginx@1.28.3-r1", + "pcre2@10.47-r0", + "zlib@1.3.1-r2" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:a24eaada9c23702c483244875e7336738bc5a815", + "InstalledFiles": [ + "usr/bin/njs", + "usr/lib/nginx/modules/ngx_http_js_module-debug.so", + "usr/lib/nginx/modules/ngx_http_js_module.so", + "usr/lib/nginx/modules/ngx_stream_js_module-debug.so", + "usr/lib/nginx/modules/ngx_stream_js_module.so", + "usr/share/doc/nginx-module-njs/CHANGES", + "usr/share/licenses/nginx-module-njs/COPYRIGHT" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nginx-module-xslt@1.28.3-r1", + "Name": "nginx-module-xslt", + "Identifier": { + "PURL": "pkg:apk/alpine/nginx-module-xslt@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "4c6b1502eaa20cef" + }, + "Version": "1.28.3-r1", + "Arch": "x86_64", + "SrcName": "nginx-module-xslt", + "SrcVersion": "1.28.3-r1", + "Licenses": [ + "2-clause", + "BSD-3-Clause", + "license" + ], + "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "libxml2@2.13.9-r0", + "libxslt@1.1.43-r3", + "musl@1.2.5-r21", + "nginx@1.28.3-r1" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:0e3a923995439eea4163e4d6b8f80a5748ef2bdb", + "InstalledFiles": [ + "usr/lib/nginx/modules/ngx_http_xslt_filter_module-debug.so", + "usr/lib/nginx/modules/ngx_http_xslt_filter_module.so", + "usr/share/licenses/nginx-module-xslt/COPYRIGHT" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "pcre2@10.47-r0", + "Name": "pcre2", + "Identifier": { + "PURL": "pkg:apk/alpine/pcre2@10.47-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "84da847bec967f4e" + }, + "Version": "10.47-r0", + "Arch": "x86_64", + "SrcName": "pcre2", + "SrcVersion": "10.47-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Jakub Jirutka \u003cjakub@jirutka.cz\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "Digest": "sha1:549059958151627bb0f5469bded945988b1bc24b", + "InstalledFiles": [ + "usr/lib/libpcre2-8.so.0", + "usr/lib/libpcre2-8.so.0.15.0", + "usr/lib/libpcre2-posix.so.3", + "usr/lib/libpcre2-posix.so.3.0.7" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "scanelf@1.3.8-r2", + "Name": "scanelf", + "Identifier": { + "PURL": "pkg:apk/alpine/scanelf@1.3.8-r2?arch=x86_64\u0026distro=3.23.3", + "UID": "948b35f6525ae462" + }, + "Version": "1.3.8-r2", + "Arch": "x86_64", + "SrcName": "pax-utils", + "SrcVersion": "1.3.8-r2", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:6ea36dd44ef9f6364f0cdfabe09ea15d2fdbe229", + "InstalledFiles": [ + "usr/bin/scanelf" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ssl_client@1.37.0-r30", + "Name": "ssl_client", + "Identifier": { + "PURL": "pkg:apk/alpine/ssl_client@1.37.0-r30?arch=x86_64\u0026distro=3.23.3", + "UID": "260f15056a81cadb" + }, + "Version": "1.37.0-r30", + "Arch": "x86_64", + "SrcName": "busybox", + "SrcVersion": "1.37.0-r30", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", + "DependsOn": [ + "libcrypto3@3.5.5-r0", + "libssl3@3.5.5-r0", + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:5b6ec0939cfc9be47d9677a3152c547cc18b5edd", + "InstalledFiles": [ + "usr/bin/ssl_client" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "tiff@4.7.1-r0", + "Name": "tiff", + "Identifier": { + "PURL": "pkg:apk/alpine/tiff@4.7.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "2726c1d2741c571e" + }, + "Version": "4.7.1-r0", + "Arch": "x86_64", + "SrcName": "tiff", + "SrcVersion": "4.7.1-r0", + "Licenses": [ + "libtiff" + ], + "Maintainer": "Michael Mason \u003cms13sp@gmail.com\u003e", + "DependsOn": [ + "libjpeg-turbo@3.1.2-r0", + "libwebp@1.6.0-r0", + "musl@1.2.5-r21", + "zlib@1.3.1-r2", + "zstd-libs@1.5.7-r2" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:b92c3394d281f51345a9375da14f347b6c1619a6", + "InstalledFiles": [ + "usr/lib/libtiff.so.6", + "usr/lib/libtiff.so.6.2.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "tzdata@2026a-r0", + "Name": "tzdata", + "Identifier": { + "PURL": "pkg:apk/alpine/tzdata@2026a-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "a7ad329b0644c5d6" + }, + "Version": "2026a-r0", + "Arch": "x86_64", + "SrcName": "tzdata", + "SrcVersion": "2026a-r0", + "Licenses": [ + "Public-Domain" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "Digest": "sha1:82f6ca3f827e313572fc0cd15bed4a040f7d515c", + "InstalledFiles": [ + "usr/share/zoneinfo/CET", + "usr/share/zoneinfo/CST6CDT", + "usr/share/zoneinfo/Cuba", + "usr/share/zoneinfo/EET", + "usr/share/zoneinfo/EST", + "usr/share/zoneinfo/EST5EDT", + "usr/share/zoneinfo/Egypt", + "usr/share/zoneinfo/Eire", + "usr/share/zoneinfo/Factory", + "usr/share/zoneinfo/GB", + "usr/share/zoneinfo/GB-Eire", + "usr/share/zoneinfo/GMT", + "usr/share/zoneinfo/GMT+0", + "usr/share/zoneinfo/GMT-0", + "usr/share/zoneinfo/GMT0", + "usr/share/zoneinfo/Greenwich", + "usr/share/zoneinfo/HST", + "usr/share/zoneinfo/Hongkong", + "usr/share/zoneinfo/Iceland", + "usr/share/zoneinfo/Iran", + "usr/share/zoneinfo/Israel", + "usr/share/zoneinfo/Jamaica", + "usr/share/zoneinfo/Japan", + "usr/share/zoneinfo/Kwajalein", + "usr/share/zoneinfo/Libya", + "usr/share/zoneinfo/MET", + "usr/share/zoneinfo/MST", + "usr/share/zoneinfo/MST7MDT", + "usr/share/zoneinfo/NZ", + "usr/share/zoneinfo/NZ-CHAT", + "usr/share/zoneinfo/Navajo", + "usr/share/zoneinfo/PRC", + "usr/share/zoneinfo/PST8PDT", + "usr/share/zoneinfo/Poland", + "usr/share/zoneinfo/Portugal", + "usr/share/zoneinfo/ROC", + "usr/share/zoneinfo/ROK", + "usr/share/zoneinfo/Singapore", + "usr/share/zoneinfo/Turkey", + "usr/share/zoneinfo/UCT", + "usr/share/zoneinfo/UTC", + "usr/share/zoneinfo/Universal", + "usr/share/zoneinfo/W-SU", + "usr/share/zoneinfo/WET", + "usr/share/zoneinfo/Zulu", + "usr/share/zoneinfo/iso3166.tab", + "usr/share/zoneinfo/leap-seconds.list", + "usr/share/zoneinfo/posixrules", + "usr/share/zoneinfo/zone.tab", + "usr/share/zoneinfo/zone1970.tab", + "usr/share/zoneinfo/Africa/Abidjan", + "usr/share/zoneinfo/Africa/Accra", + "usr/share/zoneinfo/Africa/Addis_Ababa", + "usr/share/zoneinfo/Africa/Algiers", + "usr/share/zoneinfo/Africa/Asmara", + "usr/share/zoneinfo/Africa/Asmera", + "usr/share/zoneinfo/Africa/Bamako", + "usr/share/zoneinfo/Africa/Bangui", + "usr/share/zoneinfo/Africa/Banjul", + "usr/share/zoneinfo/Africa/Bissau", + "usr/share/zoneinfo/Africa/Blantyre", + "usr/share/zoneinfo/Africa/Brazzaville", + "usr/share/zoneinfo/Africa/Bujumbura", + "usr/share/zoneinfo/Africa/Cairo", + "usr/share/zoneinfo/Africa/Casablanca", + "usr/share/zoneinfo/Africa/Ceuta", + "usr/share/zoneinfo/Africa/Conakry", + "usr/share/zoneinfo/Africa/Dakar", + "usr/share/zoneinfo/Africa/Dar_es_Salaam", + "usr/share/zoneinfo/Africa/Djibouti", + "usr/share/zoneinfo/Africa/Douala", + "usr/share/zoneinfo/Africa/El_Aaiun", + "usr/share/zoneinfo/Africa/Freetown", + "usr/share/zoneinfo/Africa/Gaborone", + "usr/share/zoneinfo/Africa/Harare", + "usr/share/zoneinfo/Africa/Johannesburg", + "usr/share/zoneinfo/Africa/Juba", + "usr/share/zoneinfo/Africa/Kampala", + "usr/share/zoneinfo/Africa/Khartoum", + "usr/share/zoneinfo/Africa/Kigali", + "usr/share/zoneinfo/Africa/Kinshasa", + "usr/share/zoneinfo/Africa/Lagos", + "usr/share/zoneinfo/Africa/Libreville", + "usr/share/zoneinfo/Africa/Lome", + "usr/share/zoneinfo/Africa/Luanda", + "usr/share/zoneinfo/Africa/Lubumbashi", + "usr/share/zoneinfo/Africa/Lusaka", + "usr/share/zoneinfo/Africa/Malabo", + "usr/share/zoneinfo/Africa/Maputo", + "usr/share/zoneinfo/Africa/Maseru", + "usr/share/zoneinfo/Africa/Mbabane", + "usr/share/zoneinfo/Africa/Mogadishu", + "usr/share/zoneinfo/Africa/Monrovia", + "usr/share/zoneinfo/Africa/Nairobi", + "usr/share/zoneinfo/Africa/Ndjamena", + "usr/share/zoneinfo/Africa/Niamey", + "usr/share/zoneinfo/Africa/Nouakchott", + "usr/share/zoneinfo/Africa/Ouagadougou", + "usr/share/zoneinfo/Africa/Porto-Novo", + "usr/share/zoneinfo/Africa/Sao_Tome", + "usr/share/zoneinfo/Africa/Timbuktu", + "usr/share/zoneinfo/Africa/Tripoli", + "usr/share/zoneinfo/Africa/Tunis", + "usr/share/zoneinfo/Africa/Windhoek", + "usr/share/zoneinfo/America/Adak", + "usr/share/zoneinfo/America/Anchorage", + "usr/share/zoneinfo/America/Anguilla", + "usr/share/zoneinfo/America/Antigua", + "usr/share/zoneinfo/America/Araguaina", + "usr/share/zoneinfo/America/Aruba", + "usr/share/zoneinfo/America/Asuncion", + "usr/share/zoneinfo/America/Atikokan", + "usr/share/zoneinfo/America/Atka", + "usr/share/zoneinfo/America/Bahia", + "usr/share/zoneinfo/America/Bahia_Banderas", + "usr/share/zoneinfo/America/Barbados", + "usr/share/zoneinfo/America/Belem", + "usr/share/zoneinfo/America/Belize", + "usr/share/zoneinfo/America/Blanc-Sablon", + "usr/share/zoneinfo/America/Boa_Vista", + "usr/share/zoneinfo/America/Bogota", + "usr/share/zoneinfo/America/Boise", + "usr/share/zoneinfo/America/Buenos_Aires", + "usr/share/zoneinfo/America/Cambridge_Bay", + "usr/share/zoneinfo/America/Campo_Grande", + "usr/share/zoneinfo/America/Cancun", + "usr/share/zoneinfo/America/Caracas", + "usr/share/zoneinfo/America/Catamarca", + "usr/share/zoneinfo/America/Cayenne", + "usr/share/zoneinfo/America/Cayman", + "usr/share/zoneinfo/America/Chicago", + "usr/share/zoneinfo/America/Chihuahua", + "usr/share/zoneinfo/America/Ciudad_Juarez", + "usr/share/zoneinfo/America/Coral_Harbour", + "usr/share/zoneinfo/America/Cordoba", + "usr/share/zoneinfo/America/Costa_Rica", + "usr/share/zoneinfo/America/Coyhaique", + "usr/share/zoneinfo/America/Creston", + "usr/share/zoneinfo/America/Cuiaba", + "usr/share/zoneinfo/America/Curacao", + "usr/share/zoneinfo/America/Danmarkshavn", + "usr/share/zoneinfo/America/Dawson", + "usr/share/zoneinfo/America/Dawson_Creek", + "usr/share/zoneinfo/America/Denver", + "usr/share/zoneinfo/America/Detroit", + "usr/share/zoneinfo/America/Dominica", + "usr/share/zoneinfo/America/Edmonton", + "usr/share/zoneinfo/America/Eirunepe", + "usr/share/zoneinfo/America/El_Salvador", + "usr/share/zoneinfo/America/Ensenada", + "usr/share/zoneinfo/America/Fort_Nelson", + "usr/share/zoneinfo/America/Fort_Wayne", + "usr/share/zoneinfo/America/Fortaleza", + "usr/share/zoneinfo/America/Glace_Bay", + "usr/share/zoneinfo/America/Godthab", + "usr/share/zoneinfo/America/Goose_Bay", + "usr/share/zoneinfo/America/Grand_Turk", + "usr/share/zoneinfo/America/Grenada", + "usr/share/zoneinfo/America/Guadeloupe", + "usr/share/zoneinfo/America/Guatemala", + "usr/share/zoneinfo/America/Guayaquil", + "usr/share/zoneinfo/America/Guyana", + "usr/share/zoneinfo/America/Halifax", + "usr/share/zoneinfo/America/Havana", + "usr/share/zoneinfo/America/Hermosillo", + "usr/share/zoneinfo/America/Indianapolis", + "usr/share/zoneinfo/America/Inuvik", + "usr/share/zoneinfo/America/Iqaluit", + "usr/share/zoneinfo/America/Jamaica", + "usr/share/zoneinfo/America/Jujuy", + "usr/share/zoneinfo/America/Juneau", + "usr/share/zoneinfo/America/Knox_IN", + "usr/share/zoneinfo/America/Kralendijk", + "usr/share/zoneinfo/America/La_Paz", + "usr/share/zoneinfo/America/Lima", + "usr/share/zoneinfo/America/Los_Angeles", + "usr/share/zoneinfo/America/Louisville", + "usr/share/zoneinfo/America/Lower_Princes", + "usr/share/zoneinfo/America/Maceio", + "usr/share/zoneinfo/America/Managua", + "usr/share/zoneinfo/America/Manaus", + "usr/share/zoneinfo/America/Marigot", + "usr/share/zoneinfo/America/Martinique", + "usr/share/zoneinfo/America/Matamoros", + "usr/share/zoneinfo/America/Mazatlan", + "usr/share/zoneinfo/America/Mendoza", + "usr/share/zoneinfo/America/Menominee", + "usr/share/zoneinfo/America/Merida", + "usr/share/zoneinfo/America/Metlakatla", + "usr/share/zoneinfo/America/Mexico_City", + "usr/share/zoneinfo/America/Miquelon", + "usr/share/zoneinfo/America/Moncton", + "usr/share/zoneinfo/America/Monterrey", + "usr/share/zoneinfo/America/Montevideo", + "usr/share/zoneinfo/America/Montreal", + "usr/share/zoneinfo/America/Montserrat", + "usr/share/zoneinfo/America/Nassau", + "usr/share/zoneinfo/America/New_York", + "usr/share/zoneinfo/America/Nipigon", + "usr/share/zoneinfo/America/Nome", + "usr/share/zoneinfo/America/Noronha", + "usr/share/zoneinfo/America/Nuuk", + "usr/share/zoneinfo/America/Ojinaga", + "usr/share/zoneinfo/America/Panama", + "usr/share/zoneinfo/America/Pangnirtung", + "usr/share/zoneinfo/America/Paramaribo", + "usr/share/zoneinfo/America/Phoenix", + "usr/share/zoneinfo/America/Port-au-Prince", + "usr/share/zoneinfo/America/Port_of_Spain", + "usr/share/zoneinfo/America/Porto_Acre", + "usr/share/zoneinfo/America/Porto_Velho", + "usr/share/zoneinfo/America/Puerto_Rico", + "usr/share/zoneinfo/America/Punta_Arenas", + "usr/share/zoneinfo/America/Rainy_River", + "usr/share/zoneinfo/America/Rankin_Inlet", + "usr/share/zoneinfo/America/Recife", + "usr/share/zoneinfo/America/Regina", + "usr/share/zoneinfo/America/Resolute", + "usr/share/zoneinfo/America/Rio_Branco", + "usr/share/zoneinfo/America/Rosario", + "usr/share/zoneinfo/America/Santa_Isabel", + "usr/share/zoneinfo/America/Santarem", + "usr/share/zoneinfo/America/Santiago", + "usr/share/zoneinfo/America/Santo_Domingo", + "usr/share/zoneinfo/America/Sao_Paulo", + "usr/share/zoneinfo/America/Scoresbysund", + "usr/share/zoneinfo/America/Shiprock", + "usr/share/zoneinfo/America/Sitka", + "usr/share/zoneinfo/America/St_Barthelemy", + "usr/share/zoneinfo/America/St_Johns", + "usr/share/zoneinfo/America/St_Kitts", + "usr/share/zoneinfo/America/St_Lucia", + "usr/share/zoneinfo/America/St_Thomas", + "usr/share/zoneinfo/America/St_Vincent", + "usr/share/zoneinfo/America/Swift_Current", + "usr/share/zoneinfo/America/Tegucigalpa", + "usr/share/zoneinfo/America/Thule", + "usr/share/zoneinfo/America/Thunder_Bay", + "usr/share/zoneinfo/America/Tijuana", + "usr/share/zoneinfo/America/Toronto", + "usr/share/zoneinfo/America/Tortola", + "usr/share/zoneinfo/America/Vancouver", + "usr/share/zoneinfo/America/Virgin", + "usr/share/zoneinfo/America/Whitehorse", + "usr/share/zoneinfo/America/Winnipeg", + "usr/share/zoneinfo/America/Yakutat", + "usr/share/zoneinfo/America/Yellowknife", + "usr/share/zoneinfo/America/Argentina/Buenos_Aires", + "usr/share/zoneinfo/America/Argentina/Catamarca", + "usr/share/zoneinfo/America/Argentina/ComodRivadavia", + "usr/share/zoneinfo/America/Argentina/Cordoba", + "usr/share/zoneinfo/America/Argentina/Jujuy", + "usr/share/zoneinfo/America/Argentina/La_Rioja", + "usr/share/zoneinfo/America/Argentina/Mendoza", + "usr/share/zoneinfo/America/Argentina/Rio_Gallegos", + "usr/share/zoneinfo/America/Argentina/Salta", + "usr/share/zoneinfo/America/Argentina/San_Juan", + "usr/share/zoneinfo/America/Argentina/San_Luis", + "usr/share/zoneinfo/America/Argentina/Tucuman", + "usr/share/zoneinfo/America/Argentina/Ushuaia", + "usr/share/zoneinfo/America/Indiana/Indianapolis", + "usr/share/zoneinfo/America/Indiana/Knox", + "usr/share/zoneinfo/America/Indiana/Marengo", + "usr/share/zoneinfo/America/Indiana/Petersburg", + "usr/share/zoneinfo/America/Indiana/Tell_City", + "usr/share/zoneinfo/America/Indiana/Vevay", + "usr/share/zoneinfo/America/Indiana/Vincennes", + "usr/share/zoneinfo/America/Indiana/Winamac", + "usr/share/zoneinfo/America/Kentucky/Louisville", + "usr/share/zoneinfo/America/Kentucky/Monticello", + "usr/share/zoneinfo/America/North_Dakota/Beulah", + "usr/share/zoneinfo/America/North_Dakota/Center", + "usr/share/zoneinfo/America/North_Dakota/New_Salem", + "usr/share/zoneinfo/Antarctica/Casey", + "usr/share/zoneinfo/Antarctica/Davis", + "usr/share/zoneinfo/Antarctica/DumontDUrville", + "usr/share/zoneinfo/Antarctica/Macquarie", + "usr/share/zoneinfo/Antarctica/Mawson", + "usr/share/zoneinfo/Antarctica/McMurdo", + "usr/share/zoneinfo/Antarctica/Palmer", + "usr/share/zoneinfo/Antarctica/Rothera", + "usr/share/zoneinfo/Antarctica/South_Pole", + "usr/share/zoneinfo/Antarctica/Syowa", + "usr/share/zoneinfo/Antarctica/Troll", + "usr/share/zoneinfo/Antarctica/Vostok", + "usr/share/zoneinfo/Arctic/Longyearbyen", + "usr/share/zoneinfo/Asia/Aden", + "usr/share/zoneinfo/Asia/Almaty", + "usr/share/zoneinfo/Asia/Amman", + "usr/share/zoneinfo/Asia/Anadyr", + "usr/share/zoneinfo/Asia/Aqtau", + "usr/share/zoneinfo/Asia/Aqtobe", + "usr/share/zoneinfo/Asia/Ashgabat", + "usr/share/zoneinfo/Asia/Ashkhabad", + "usr/share/zoneinfo/Asia/Atyrau", + "usr/share/zoneinfo/Asia/Baghdad", + "usr/share/zoneinfo/Asia/Bahrain", + "usr/share/zoneinfo/Asia/Baku", + "usr/share/zoneinfo/Asia/Bangkok", + "usr/share/zoneinfo/Asia/Barnaul", + "usr/share/zoneinfo/Asia/Beirut", + "usr/share/zoneinfo/Asia/Bishkek", + "usr/share/zoneinfo/Asia/Brunei", + "usr/share/zoneinfo/Asia/Calcutta", + "usr/share/zoneinfo/Asia/Chita", + "usr/share/zoneinfo/Asia/Choibalsan", + "usr/share/zoneinfo/Asia/Chongqing", + "usr/share/zoneinfo/Asia/Chungking", + "usr/share/zoneinfo/Asia/Colombo", + "usr/share/zoneinfo/Asia/Dacca", + "usr/share/zoneinfo/Asia/Damascus", + "usr/share/zoneinfo/Asia/Dhaka", + "usr/share/zoneinfo/Asia/Dili", + "usr/share/zoneinfo/Asia/Dubai", + "usr/share/zoneinfo/Asia/Dushanbe", + "usr/share/zoneinfo/Asia/Famagusta", + "usr/share/zoneinfo/Asia/Gaza", + "usr/share/zoneinfo/Asia/Harbin", + "usr/share/zoneinfo/Asia/Hebron", + "usr/share/zoneinfo/Asia/Ho_Chi_Minh", + "usr/share/zoneinfo/Asia/Hong_Kong", + "usr/share/zoneinfo/Asia/Hovd", + "usr/share/zoneinfo/Asia/Irkutsk", + "usr/share/zoneinfo/Asia/Istanbul", + "usr/share/zoneinfo/Asia/Jakarta", + "usr/share/zoneinfo/Asia/Jayapura", + "usr/share/zoneinfo/Asia/Jerusalem", + "usr/share/zoneinfo/Asia/Kabul", + "usr/share/zoneinfo/Asia/Kamchatka", + "usr/share/zoneinfo/Asia/Karachi", + "usr/share/zoneinfo/Asia/Kashgar", + "usr/share/zoneinfo/Asia/Kathmandu", + "usr/share/zoneinfo/Asia/Katmandu", + "usr/share/zoneinfo/Asia/Khandyga", + "usr/share/zoneinfo/Asia/Kolkata", + "usr/share/zoneinfo/Asia/Krasnoyarsk", + "usr/share/zoneinfo/Asia/Kuala_Lumpur", + "usr/share/zoneinfo/Asia/Kuching", + "usr/share/zoneinfo/Asia/Kuwait", + "usr/share/zoneinfo/Asia/Macao", + "usr/share/zoneinfo/Asia/Macau", + "usr/share/zoneinfo/Asia/Magadan", + "usr/share/zoneinfo/Asia/Makassar", + "usr/share/zoneinfo/Asia/Manila", + "usr/share/zoneinfo/Asia/Muscat", + "usr/share/zoneinfo/Asia/Nicosia", + "usr/share/zoneinfo/Asia/Novokuznetsk", + "usr/share/zoneinfo/Asia/Novosibirsk", + "usr/share/zoneinfo/Asia/Omsk", + "usr/share/zoneinfo/Asia/Oral", + "usr/share/zoneinfo/Asia/Phnom_Penh", + "usr/share/zoneinfo/Asia/Pontianak", + "usr/share/zoneinfo/Asia/Pyongyang", + "usr/share/zoneinfo/Asia/Qatar", + "usr/share/zoneinfo/Asia/Qostanay", + "usr/share/zoneinfo/Asia/Qyzylorda", + "usr/share/zoneinfo/Asia/Rangoon", + "usr/share/zoneinfo/Asia/Riyadh", + "usr/share/zoneinfo/Asia/Saigon", + "usr/share/zoneinfo/Asia/Sakhalin", + "usr/share/zoneinfo/Asia/Samarkand", + "usr/share/zoneinfo/Asia/Seoul", + "usr/share/zoneinfo/Asia/Shanghai", + "usr/share/zoneinfo/Asia/Singapore", + "usr/share/zoneinfo/Asia/Srednekolymsk", + "usr/share/zoneinfo/Asia/Taipei", + "usr/share/zoneinfo/Asia/Tashkent", + "usr/share/zoneinfo/Asia/Tbilisi", + "usr/share/zoneinfo/Asia/Tehran", + "usr/share/zoneinfo/Asia/Tel_Aviv", + "usr/share/zoneinfo/Asia/Thimbu", + "usr/share/zoneinfo/Asia/Thimphu", + "usr/share/zoneinfo/Asia/Tokyo", + "usr/share/zoneinfo/Asia/Tomsk", + "usr/share/zoneinfo/Asia/Ujung_Pandang", + "usr/share/zoneinfo/Asia/Ulaanbaatar", + "usr/share/zoneinfo/Asia/Ulan_Bator", + "usr/share/zoneinfo/Asia/Urumqi", + "usr/share/zoneinfo/Asia/Ust-Nera", + "usr/share/zoneinfo/Asia/Vientiane", + "usr/share/zoneinfo/Asia/Vladivostok", + "usr/share/zoneinfo/Asia/Yakutsk", + "usr/share/zoneinfo/Asia/Yangon", + "usr/share/zoneinfo/Asia/Yekaterinburg", + "usr/share/zoneinfo/Asia/Yerevan", + "usr/share/zoneinfo/Atlantic/Azores", + "usr/share/zoneinfo/Atlantic/Bermuda", + "usr/share/zoneinfo/Atlantic/Canary", + "usr/share/zoneinfo/Atlantic/Cape_Verde", + "usr/share/zoneinfo/Atlantic/Faeroe", + "usr/share/zoneinfo/Atlantic/Faroe", + "usr/share/zoneinfo/Atlantic/Jan_Mayen", + "usr/share/zoneinfo/Atlantic/Madeira", + "usr/share/zoneinfo/Atlantic/Reykjavik", + "usr/share/zoneinfo/Atlantic/South_Georgia", + "usr/share/zoneinfo/Atlantic/St_Helena", + "usr/share/zoneinfo/Atlantic/Stanley", + "usr/share/zoneinfo/Australia/ACT", + "usr/share/zoneinfo/Australia/Adelaide", + "usr/share/zoneinfo/Australia/Brisbane", + "usr/share/zoneinfo/Australia/Broken_Hill", + "usr/share/zoneinfo/Australia/Canberra", + "usr/share/zoneinfo/Australia/Currie", + "usr/share/zoneinfo/Australia/Darwin", + "usr/share/zoneinfo/Australia/Eucla", + "usr/share/zoneinfo/Australia/Hobart", + "usr/share/zoneinfo/Australia/LHI", + "usr/share/zoneinfo/Australia/Lindeman", + "usr/share/zoneinfo/Australia/Lord_Howe", + "usr/share/zoneinfo/Australia/Melbourne", + "usr/share/zoneinfo/Australia/NSW", + "usr/share/zoneinfo/Australia/North", + "usr/share/zoneinfo/Australia/Perth", + "usr/share/zoneinfo/Australia/Queensland", + "usr/share/zoneinfo/Australia/South", + "usr/share/zoneinfo/Australia/Sydney", + "usr/share/zoneinfo/Australia/Tasmania", + "usr/share/zoneinfo/Australia/Victoria", + "usr/share/zoneinfo/Australia/West", + "usr/share/zoneinfo/Australia/Yancowinna", + "usr/share/zoneinfo/Brazil/Acre", + "usr/share/zoneinfo/Brazil/DeNoronha", + "usr/share/zoneinfo/Brazil/East", + "usr/share/zoneinfo/Brazil/West", + "usr/share/zoneinfo/Canada/Atlantic", + "usr/share/zoneinfo/Canada/Central", + "usr/share/zoneinfo/Canada/Eastern", + "usr/share/zoneinfo/Canada/Mountain", + "usr/share/zoneinfo/Canada/Newfoundland", + "usr/share/zoneinfo/Canada/Pacific", + "usr/share/zoneinfo/Canada/Saskatchewan", + "usr/share/zoneinfo/Canada/Yukon", + "usr/share/zoneinfo/Chile/Continental", + "usr/share/zoneinfo/Chile/EasterIsland", + "usr/share/zoneinfo/Etc/GMT", + "usr/share/zoneinfo/Etc/GMT+0", + "usr/share/zoneinfo/Etc/GMT+1", + "usr/share/zoneinfo/Etc/GMT+10", + "usr/share/zoneinfo/Etc/GMT+11", + "usr/share/zoneinfo/Etc/GMT+12", + "usr/share/zoneinfo/Etc/GMT+2", + "usr/share/zoneinfo/Etc/GMT+3", + "usr/share/zoneinfo/Etc/GMT+4", + "usr/share/zoneinfo/Etc/GMT+5", + "usr/share/zoneinfo/Etc/GMT+6", + "usr/share/zoneinfo/Etc/GMT+7", + "usr/share/zoneinfo/Etc/GMT+8", + "usr/share/zoneinfo/Etc/GMT+9", + "usr/share/zoneinfo/Etc/GMT-0", + "usr/share/zoneinfo/Etc/GMT-1", + "usr/share/zoneinfo/Etc/GMT-10", + "usr/share/zoneinfo/Etc/GMT-11", + "usr/share/zoneinfo/Etc/GMT-12", + "usr/share/zoneinfo/Etc/GMT-13", + "usr/share/zoneinfo/Etc/GMT-14", + "usr/share/zoneinfo/Etc/GMT-2", + "usr/share/zoneinfo/Etc/GMT-3", + "usr/share/zoneinfo/Etc/GMT-4", + "usr/share/zoneinfo/Etc/GMT-5", + "usr/share/zoneinfo/Etc/GMT-6", + "usr/share/zoneinfo/Etc/GMT-7", + "usr/share/zoneinfo/Etc/GMT-8", + "usr/share/zoneinfo/Etc/GMT-9", + "usr/share/zoneinfo/Etc/GMT0", + "usr/share/zoneinfo/Etc/Greenwich", + "usr/share/zoneinfo/Etc/UCT", + "usr/share/zoneinfo/Etc/UTC", + "usr/share/zoneinfo/Etc/Universal", + "usr/share/zoneinfo/Etc/Zulu", + "usr/share/zoneinfo/Europe/Amsterdam", + "usr/share/zoneinfo/Europe/Andorra", + "usr/share/zoneinfo/Europe/Astrakhan", + "usr/share/zoneinfo/Europe/Athens", + "usr/share/zoneinfo/Europe/Belfast", + "usr/share/zoneinfo/Europe/Belgrade", + "usr/share/zoneinfo/Europe/Berlin", + "usr/share/zoneinfo/Europe/Bratislava", + "usr/share/zoneinfo/Europe/Brussels", + "usr/share/zoneinfo/Europe/Bucharest", + "usr/share/zoneinfo/Europe/Budapest", + "usr/share/zoneinfo/Europe/Busingen", + "usr/share/zoneinfo/Europe/Chisinau", + "usr/share/zoneinfo/Europe/Copenhagen", + "usr/share/zoneinfo/Europe/Dublin", + "usr/share/zoneinfo/Europe/Gibraltar", + "usr/share/zoneinfo/Europe/Guernsey", + "usr/share/zoneinfo/Europe/Helsinki", + "usr/share/zoneinfo/Europe/Isle_of_Man", + "usr/share/zoneinfo/Europe/Istanbul", + "usr/share/zoneinfo/Europe/Jersey", + "usr/share/zoneinfo/Europe/Kaliningrad", + "usr/share/zoneinfo/Europe/Kiev", + "usr/share/zoneinfo/Europe/Kirov", + "usr/share/zoneinfo/Europe/Kyiv", + "usr/share/zoneinfo/Europe/Lisbon", + "usr/share/zoneinfo/Europe/Ljubljana", + "usr/share/zoneinfo/Europe/London", + "usr/share/zoneinfo/Europe/Luxembourg", + "usr/share/zoneinfo/Europe/Madrid", + "usr/share/zoneinfo/Europe/Malta", + "usr/share/zoneinfo/Europe/Mariehamn", + "usr/share/zoneinfo/Europe/Minsk", + "usr/share/zoneinfo/Europe/Monaco", + "usr/share/zoneinfo/Europe/Moscow", + "usr/share/zoneinfo/Europe/Nicosia", + "usr/share/zoneinfo/Europe/Oslo", + "usr/share/zoneinfo/Europe/Paris", + "usr/share/zoneinfo/Europe/Podgorica", + "usr/share/zoneinfo/Europe/Prague", + "usr/share/zoneinfo/Europe/Riga", + "usr/share/zoneinfo/Europe/Rome", + "usr/share/zoneinfo/Europe/Samara", + "usr/share/zoneinfo/Europe/San_Marino", + "usr/share/zoneinfo/Europe/Sarajevo", + "usr/share/zoneinfo/Europe/Saratov", + "usr/share/zoneinfo/Europe/Simferopol", + "usr/share/zoneinfo/Europe/Skopje", + "usr/share/zoneinfo/Europe/Sofia", + "usr/share/zoneinfo/Europe/Stockholm", + "usr/share/zoneinfo/Europe/Tallinn", + "usr/share/zoneinfo/Europe/Tirane", + "usr/share/zoneinfo/Europe/Tiraspol", + "usr/share/zoneinfo/Europe/Ulyanovsk", + "usr/share/zoneinfo/Europe/Uzhgorod", + "usr/share/zoneinfo/Europe/Vaduz", + "usr/share/zoneinfo/Europe/Vatican", + "usr/share/zoneinfo/Europe/Vienna", + "usr/share/zoneinfo/Europe/Vilnius", + "usr/share/zoneinfo/Europe/Volgograd", + "usr/share/zoneinfo/Europe/Warsaw", + "usr/share/zoneinfo/Europe/Zagreb", + "usr/share/zoneinfo/Europe/Zaporozhye", + "usr/share/zoneinfo/Europe/Zurich", + "usr/share/zoneinfo/Indian/Antananarivo", + "usr/share/zoneinfo/Indian/Chagos", + "usr/share/zoneinfo/Indian/Christmas", + "usr/share/zoneinfo/Indian/Cocos", + "usr/share/zoneinfo/Indian/Comoro", + "usr/share/zoneinfo/Indian/Kerguelen", + "usr/share/zoneinfo/Indian/Mahe", + "usr/share/zoneinfo/Indian/Maldives", + "usr/share/zoneinfo/Indian/Mauritius", + "usr/share/zoneinfo/Indian/Mayotte", + "usr/share/zoneinfo/Indian/Reunion", + "usr/share/zoneinfo/Mexico/BajaNorte", + "usr/share/zoneinfo/Mexico/BajaSur", + "usr/share/zoneinfo/Mexico/General", + "usr/share/zoneinfo/Pacific/Apia", + "usr/share/zoneinfo/Pacific/Auckland", + "usr/share/zoneinfo/Pacific/Bougainville", + "usr/share/zoneinfo/Pacific/Chatham", + "usr/share/zoneinfo/Pacific/Chuuk", + "usr/share/zoneinfo/Pacific/Easter", + "usr/share/zoneinfo/Pacific/Efate", + "usr/share/zoneinfo/Pacific/Enderbury", + "usr/share/zoneinfo/Pacific/Fakaofo", + "usr/share/zoneinfo/Pacific/Fiji", + "usr/share/zoneinfo/Pacific/Funafuti", + "usr/share/zoneinfo/Pacific/Galapagos", + "usr/share/zoneinfo/Pacific/Gambier", + "usr/share/zoneinfo/Pacific/Guadalcanal", + "usr/share/zoneinfo/Pacific/Guam", + "usr/share/zoneinfo/Pacific/Honolulu", + "usr/share/zoneinfo/Pacific/Johnston", + "usr/share/zoneinfo/Pacific/Kanton", + "usr/share/zoneinfo/Pacific/Kiritimati", + "usr/share/zoneinfo/Pacific/Kosrae", + "usr/share/zoneinfo/Pacific/Kwajalein", + "usr/share/zoneinfo/Pacific/Majuro", + "usr/share/zoneinfo/Pacific/Marquesas", + "usr/share/zoneinfo/Pacific/Midway", + "usr/share/zoneinfo/Pacific/Nauru", + "usr/share/zoneinfo/Pacific/Niue", + "usr/share/zoneinfo/Pacific/Norfolk", + "usr/share/zoneinfo/Pacific/Noumea", + "usr/share/zoneinfo/Pacific/Pago_Pago", + "usr/share/zoneinfo/Pacific/Palau", + "usr/share/zoneinfo/Pacific/Pitcairn", + "usr/share/zoneinfo/Pacific/Pohnpei", + "usr/share/zoneinfo/Pacific/Ponape", + "usr/share/zoneinfo/Pacific/Port_Moresby", + "usr/share/zoneinfo/Pacific/Rarotonga", + "usr/share/zoneinfo/Pacific/Saipan", + "usr/share/zoneinfo/Pacific/Samoa", + "usr/share/zoneinfo/Pacific/Tahiti", + "usr/share/zoneinfo/Pacific/Tarawa", + "usr/share/zoneinfo/Pacific/Tongatapu", + "usr/share/zoneinfo/Pacific/Truk", + "usr/share/zoneinfo/Pacific/Wake", + "usr/share/zoneinfo/Pacific/Wallis", + "usr/share/zoneinfo/Pacific/Yap", + "usr/share/zoneinfo/US/Alaska", + "usr/share/zoneinfo/US/Aleutian", + "usr/share/zoneinfo/US/Arizona", + "usr/share/zoneinfo/US/Central", + "usr/share/zoneinfo/US/East-Indiana", + "usr/share/zoneinfo/US/Eastern", + "usr/share/zoneinfo/US/Hawaii", + "usr/share/zoneinfo/US/Indiana-Starke", + "usr/share/zoneinfo/US/Michigan", + "usr/share/zoneinfo/US/Mountain", + "usr/share/zoneinfo/US/Pacific", + "usr/share/zoneinfo/US/Samoa" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "xz-libs@5.8.2-r0", + "Name": "xz-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/xz-libs@5.8.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "3c1589b6a5aafd51" + }, + "Version": "5.8.2-r0", + "Arch": "x86_64", + "SrcName": "xz", + "SrcVersion": "5.8.2-r0", + "Licenses": [ + "GPL-2.0-or-later", + "0BSD", + "Public-Domain", + "LGPL-2.1-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:d3eb4807f74650a151b4463266ecd1b507f3c49f", + "InstalledFiles": [ + "usr/lib/liblzma.so.5", + "usr/lib/liblzma.so.5.8.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "zlib@1.3.1-r2", + "Name": "zlib", + "Identifier": { + "PURL": "pkg:apk/alpine/zlib@1.3.1-r2?arch=x86_64\u0026distro=3.23.3", + "UID": "792cdc69bc59d880" + }, + "Version": "1.3.1-r2", + "Arch": "x86_64", + "SrcName": "zlib", + "SrcVersion": "1.3.1-r2", + "Licenses": [ + "Zlib" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:3e8e8e76dfefb4efd27658ada6d792e66ba2775e", + "InstalledFiles": [ + "usr/lib/libz.so.1", + "usr/lib/libz.so.1.3.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "zstd-libs@1.5.7-r2", + "Name": "zstd-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/zstd-libs@1.5.7-r2?arch=x86_64\u0026distro=3.23.3", + "UID": "8146f1dd71a6e601" + }, + "Version": "1.5.7-r2", + "Arch": "x86_64", + "SrcName": "zstd", + "SrcVersion": "1.5.7-r2", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r21" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:d507b8ac3c4335a40405ac20e49bac9d43642be6", + "InstalledFiles": [ + "usr/lib/libzstd.so.1", + "usr/lib/libzstd.so.1.5.7" + ], + "AnalyzedBy": "apk" + } + ], + "Vulnerabilities": [ + { + "VulnerabilityID": "CVE-2026-33630", + "PkgID": "c-ares@1.34.6-r0", + "PkgName": "c-ares", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/c-ares@1.34.6-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "2fc69dd6afab16ae" + }, + "InstalledVersion": "1.34.6-r0", + "FixedVersion": "1.34.8-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-33630", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:d9285fd73f7e1ba4205068c1a17a3c88a2207aa83fe9dc1a5ee265912dd88d0b", + "Title": "c-ares: c-ares: Use-after-free / double-free in query-completion handling", + "Description": "c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, or for ares_getaddrinfo() the owning host_query, is freed as a side effect of that callback, it is then accessed and/or freed a second time. This vulnerability is fixed in ver 1.34.7.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415", + "CWE-416" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "oracle-oval": 3, + "redhat": 3, + "rocky": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:42096", + "https://access.redhat.com/security/cve/CVE-2026-33630", + "https://bugzilla.redhat.com/2497686", + "https://bugzilla.redhat.com/show_bug.cgi?id=2497686", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33630", + "https://errata.almalinux.org/10/ALSA-2026-42096.html", + "https://errata.rockylinux.org/RLSA-2026:42096", + "https://github.com/c-ares/c-ares/commit/1fa3b86a0b8d18fe7b60f3228a01d770feb026bc", + "https://github.com/c-ares/c-ares/commit/d823199b688052dcdc1646f2ab4cb8c16b1c644a", + "https://github.com/c-ares/c-ares/pull/1237", + "https://github.com/c-ares/c-ares/releases/tag/v1.34.7", + "https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542", + "https://linux.oracle.com/cve/CVE-2026-33630.html", + "https://linux.oracle.com/errata/ELSA-2026-42096.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-33630", + "https://www.cve.org/CVERecord?id=CVE-2026-33630" + ], + "PublishedDate": "2026-09-03T19:17:27.42Z", + "LastModifiedDate": "2026-09-09T21:09:13.08Z" + }, + { + "VulnerabilityID": "CVE-2026-11352", + "PkgID": "curl@8.17.0-r1", + "PkgName": "curl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c4e4a99c2363a971" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-11352", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:c5a7996455e5abe2f73f0bc9cfd31708f763449a7ca938a4958bca6ab1b659ec", + "Title": "curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability", + "Description": "An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server\nto trigger a remote denial of service against a curl or libcurl client.\nBecause the helper function discards zero-length UDP datagrams before counting\nthem toward the per-call packet budget, a connected QUIC peer can continuously\nstream empty datagrams to indefinitely stall the client.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "julia": 3, + "redhat": 3, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-11352", + "https://curl.se/L7HzKXisfJ/CVE-2026-11352.md", + "https://curl.se/docs/CVE-2026-11352.html", + "https://curl.se/docs/CVE-2026-11352.json", + "https://github.com/advisories/GHSA-qxwx-hr5v-h5q4", + "https://hackerone.com/reports/3783438", + "https://nvd.nist.gov/vuln/detail/CVE-2026-11352", + "https://ubuntu.com/security/notices/USN-8525-1", + "https://www.cve.org/CVERecord?id=CVE-2026-11352" + ], + "PublishedDate": "2026-07-03T07:16:23.693Z", + "LastModifiedDate": "2026-09-15T07:16:25.353Z" + }, + { + "VulnerabilityID": "CVE-2026-11586", + "PkgID": "curl@8.17.0-r1", + "PkgName": "curl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c4e4a99c2363a971" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-11586", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:bc7b43b547a2565b4607dc3593d90e2a9bc8360f6b27b3286ac7b4d7b20c68c3", + "Title": "curl: curl: Denial of Service via WebSocket PING flood", + "Description": "By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "amazon": 2, + "julia": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-11586", + "https://curl.se/L7HzKXisfJ/CVE-2026-11586.md", + "https://curl.se/docs/CVE-2026-11586.html", + "https://curl.se/docs/CVE-2026-11586.json", + "https://github.com/advisories/GHSA-c68q-h477-5646", + "https://hackerone.com/reports/3788931", + "https://nvd.nist.gov/vuln/detail/CVE-2026-11586", + "https://ubuntu.com/security/notices/USN-8525-1", + "https://www.cve.org/CVERecord?id=CVE-2026-11586" + ], + "PublishedDate": "2026-07-03T07:16:23.883Z", + "LastModifiedDate": "2026-09-15T07:16:25.7Z" + }, + { + "VulnerabilityID": "CVE-2026-12064", + "PkgID": "curl@8.17.0-r1", + "PkgName": "curl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c4e4a99c2363a971" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-12064", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:793bbbf4ce77ae94363cb62edd580c9591a91f15bfb0e26fbd87e4075bbf47e7", + "Title": "curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP", + "Description": "When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-297", + "CWE-295" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 3, + "julia": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-12064", + "https://curl.se/L7HzKXisfJ/CVE-2026-12064.md", + "https://curl.se/docs/CVE-2026-12064.html", + "https://curl.se/docs/CVE-2026-12064.json", + "https://github.com/advisories/GHSA-jm94-9f7h-36pr", + "https://hackerone.com/reports/3797526", + "https://linux.oracle.com/cve/CVE-2026-12064.html", + "https://linux.oracle.com/errata/ELSA-2026-55450.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-12064", + "https://ubuntu.com/security/notices/USN-8525-1", + "https://www.cve.org/CVERecord?id=CVE-2026-12064" + ], + "PublishedDate": "2026-07-03T07:16:24.217Z", + "LastModifiedDate": "2026-09-15T07:16:26.15Z" + }, + { + "VulnerabilityID": "CVE-2026-5773", + "PkgID": "curl@8.17.0-r1", + "PkgName": "curl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c4e4a99c2363a971" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.20.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-5773", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:1acc9c31ac9ea826f308e75b534e8333b6fb5a4e5cd6aae6a71c691b06a79924", + "Title": "curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse", + "Description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-488", + "CWE-918" + ], + "VendorSeverity": { + "julia": 3, + "nvd": 3, + "photon": 3, + "redhat": 2, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", + "V3Score": 6.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/04/29/9", + "https://access.redhat.com/security/cve/CVE-2026-5773", + "https://curl.se/docs/CVE-2026-5773.html", + "https://curl.se/docs/CVE-2026-5773.json", + "https://github.com/advisories/GHSA-rp9q-8q5w-ch44", + "https://hackerone.com/reports/3650689", + "https://nvd.nist.gov/vuln/detail/CVE-2026-5773", + "https://ubuntu.com/security/notices/USN-8227-1", + "https://ubuntu.com/security/notices/USN-8525-1", + "https://www.cve.org/CVERecord?id=CVE-2026-5773" + ], + "PublishedDate": "2026-05-13T13:01:56.307Z", + "LastModifiedDate": "2026-09-15T07:16:28.82Z" + }, + { + "VulnerabilityID": "CVE-2026-6276", + "PkgID": "curl@8.17.0-r1", + "PkgName": "curl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c4e4a99c2363a971" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.20.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-6276", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:bb1da73213b0678dacf9c6d1fbb816aacac82d9b2c5d0fdbcf8c84e6d1cee38d", + "Title": "curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers", + "Description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-346", + "CWE-319" + ], + "VendorSeverity": { + "azure": 2, + "julia": 3, + "nvd": 3, + "photon": 3, + "redhat": 1, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V3Score": 3.7 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/04/29/13", + "https://access.redhat.com/security/cve/CVE-2026-6276", + "https://curl.se/docs/CVE-2026-6276.html", + "https://curl.se/docs/CVE-2026-6276.json", + "https://github.com/advisories/GHSA-2jc6-hc33-hv48", + "https://hackerone.com/reports/3671818", + "https://nvd.nist.gov/vuln/detail/CVE-2026-6276", + "https://ubuntu.com/security/notices/USN-8227-1", + "https://www.cve.org/CVERecord?id=CVE-2026-6276" + ], + "PublishedDate": "2026-05-13T13:01:56.8Z", + "LastModifiedDate": "2026-09-15T07:16:29.343Z" + }, + { + "VulnerabilityID": "CVE-2026-8286", + "PkgID": "curl@8.17.0-r1", + "PkgName": "curl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c4e4a99c2363a971" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8286", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:6441208109db6f17f86e53be7856b8f45aecbef9792b49f40fff0f9dc980d5c5", + "Title": "curl: curl: Insecure connection establishment due to TLS configuration mismatch", + "Description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "julia": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:55439", + "https://access.redhat.com/errata/RHSA-2026:57462", + "https://access.redhat.com/security/cve/CVE-2026-8286", + "https://bugzilla.redhat.com/2496763", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446448", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446450", + "https://bugzilla.redhat.com/show_bug.cgi?id=2496758", + "https://bugzilla.redhat.com/show_bug.cgi?id=2496763", + "https://creativecommons.org/licenses/by/4.0/", + "https://curl.se/L7HzKXisfJ/CVE-2026-8286.md", + "https://curl.se/docs/CVE-2026-8286.html", + "https://curl.se/docs/CVE-2026-8286.json", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547", + "https://errata.almalinux.org/8/ALSA-2026-57462.html", + "https://errata.rockylinux.org/RLSA-2026:55439", + "https://github.com/advisories/GHSA-32xh-3x3c-6g6h", + "https://hackerone.com/reports/3718195", + "https://linux.oracle.com/cve/CVE-2026-8286.html", + "https://linux.oracle.com/errata/ELSA-2026-57462.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-8286", + "https://ubuntu.com/security/notices/USN-8487-1", + "https://www.cve.org/CVERecord?id=CVE-2026-8286" + ], + "PublishedDate": "2026-07-03T07:16:24.453Z", + "LastModifiedDate": "2026-09-15T07:16:31.617Z" + }, + { + "VulnerabilityID": "CVE-2026-8458", + "PkgID": "curl@8.17.0-r1", + "PkgName": "curl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c4e4a99c2363a971" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8458", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:de0928ee55bf721148ed577b0e2e717084dcd109e80d479e2248f2a8ccabbaab", + "Title": "curl: libcurl: Unauthorized connection reuse due to a logical error", + "Description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-488" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 2, + "julia": 2, + "photon": 2, + "redhat": 3, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 6.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-8458", + "https://curl.se/L7HzKXisfJ/CVE-2026-8458.md", + "https://curl.se/docs/CVE-2026-8458.html", + "https://curl.se/docs/CVE-2026-8458.json", + "https://github.com/advisories/GHSA-88c6-6jfq-mm4q", + "https://hackerone.com/reports/3721183", + "https://nvd.nist.gov/vuln/detail/CVE-2026-8458", + "https://ubuntu.com/security/notices/USN-8487-1", + "https://www.cve.org/CVERecord?id=CVE-2026-8458" + ], + "PublishedDate": "2026-07-03T07:16:24.63Z", + "LastModifiedDate": "2026-09-15T07:16:32.327Z" + }, + { + "VulnerabilityID": "CVE-2026-8925", + "PkgID": "curl@8.17.0-r1", + "PkgName": "curl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c4e4a99c2363a971" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8925", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:908932d0c505f02e788f0f48b293fb356087e87e1e0015ef5a5c06b6d60f1730", + "Title": "curl: curl: Double-free vulnerability in SASL authentication", + "Description": "The curl logic that works with SASL authentication could end up cleaning up\nthe GSASL context *twice* without clearing the pointer in between, making it\n`free()` the same pointer twice.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415" + ], + "VendorSeverity": { + "amazon": 2, + "julia": 4, + "photon": 4, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-8925", + "https://curl.se/L7HzKXisfJ/CVE-2026-8925.md", + "https://curl.se/docs/CVE-2026-8925.html", + "https://curl.se/docs/CVE-2026-8925.json", + "https://github.com/advisories/GHSA-p8x5-c6c9-8cwx", + "https://hackerone.com/reports/3735193", + "https://nvd.nist.gov/vuln/detail/CVE-2026-8925", + "https://ubuntu.com/security/notices/USN-8487-1", + "https://www.cve.org/CVERecord?id=CVE-2026-8925" + ], + "PublishedDate": "2026-07-03T07:16:24.95Z", + "LastModifiedDate": "2026-09-15T07:16:32.8Z" + }, + { + "VulnerabilityID": "CVE-2026-8927", + "PkgID": "curl@8.17.0-r1", + "PkgName": "curl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c4e4a99c2363a971" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8927", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:b158f4cf7def44df3301af1431f24ec3c72e83ce08484944a0fceccf30937d10", + "Title": "curl: Information disclosure due to uncleared proxy authentication state", + "Description": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-294" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "julia": 4, + "oracle-oval": 3, + "photon": 4, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:55432", + "https://access.redhat.com/security/cve/CVE-2026-8927", + "https://bugzilla.redhat.com/2496769", + "https://bugzilla.redhat.com/show_bug.cgi?id=2496769", + "https://creativecommons.org/licenses/by/4.0/", + "https://curl.se/L7HzKXisfJ/CVE-2026-8927.md", + "https://curl.se/docs/CVE-2026-8927.html", + "https://curl.se/docs/CVE-2026-8927.json", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8927", + "https://errata.almalinux.org/10/ALSA-2026-55432.html", + "https://errata.rockylinux.org/RLSA-2026:55432", + "https://github.com/advisories/GHSA-jr4f-4564-w3mr", + "https://hackerone.com/reports/3744543", + "https://linux.oracle.com/cve/CVE-2026-8927.html", + "https://linux.oracle.com/errata/ELSA-2026-55432.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-8927", + "https://ubuntu.com/security/notices/USN-8487-1", + "https://www.cve.org/CVERecord?id=CVE-2026-8927" + ], + "PublishedDate": "2026-07-03T07:16:25.123Z", + "LastModifiedDate": "2026-09-15T07:16:33.157Z" + }, + { + "VulnerabilityID": "CVE-2026-9547", + "PkgID": "curl@8.17.0-r1", + "PkgName": "curl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/curl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c4e4a99c2363a971" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-9547", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:1cafe58ac3ef9667652d91660e01a5fed38fba86ecdc8954932bd47f8092230c", + "Title": "curl: curl: Man-in-the-middle attack via SSH host key bypass", + "Description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-297" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "julia": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:55439", + "https://access.redhat.com/security/cve/CVE-2026-9547", + "https://bugzilla.redhat.com/2446448", + "https://bugzilla.redhat.com/2446450", + "https://bugzilla.redhat.com/2496758", + "https://bugzilla.redhat.com/2496763", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446448", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446450", + "https://bugzilla.redhat.com/show_bug.cgi?id=2496758", + "https://bugzilla.redhat.com/show_bug.cgi?id=2496763", + "https://creativecommons.org/licenses/by/4.0/", + "https://curl.se/L7HzKXisfJ/CVE-2026-9547.md", + "https://curl.se/docs/CVE-2026-9547.html", + "https://curl.se/docs/CVE-2026-9547.json", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547", + "https://errata.almalinux.org/9/ALSA-2026-55439.html", + "https://errata.rockylinux.org/RLSA-2026:55439", + "https://github.com/advisories/GHSA-xq9p-gxg6-f7q6", + "https://hackerone.com/reports/3751712", + "https://linux.oracle.com/cve/CVE-2026-9547.html", + "https://linux.oracle.com/errata/ELSA-2026-55450.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-9547", + "https://ubuntu.com/security/notices/USN-8487-1", + "https://www.cve.org/CVERecord?id=CVE-2026-9547" + ], + "PublishedDate": "2026-07-03T07:16:25.99Z", + "LastModifiedDate": "2026-09-15T07:16:35.31Z" + }, + { + "VulnerabilityID": "CVE-2026-31789", + "PkgID": "libcrypto3@3.5.5-r0", + "PkgName": "libcrypto3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "6778a588f2cebd48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-31789", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:7bf2c442a9419b41bc691833b980d4fa12130e8b82d1207c4ae76f2f8be6e8f4", + "Title": "openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing", + "Description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "azure": 2, + "julia": 4, + "nvd": 4, + "photon": 4, + "redhat": 1, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H", + "V3Score": 5.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-31789", + "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", + "https://github.com/advisories/GHSA-j79m-9jxq-788r", + "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde", + "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf", + "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49", + "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9", + "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521", + "https://nvd.nist.gov/vuln/detail/CVE-2026-31789", + "https://openssl-library.org/news/secadv/20260407.txt", + "https://ubuntu.com/security/notices/USN-8155-1", + "https://www.cve.org/CVERecord?id=CVE-2026-31789", + "https://www.openwall.com/lists/oss-security/2026/04/07/11" + ], + "PublishedDate": "2026-04-07T22:16:21.617Z", + "LastModifiedDate": "2026-07-24T23:10:00.563Z" + }, + { + "VulnerabilityID": "CVE-2026-14456", + "PkgID": "libcrypto3@3.5.5-r0", + "PkgName": "libcrypto3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "6778a588f2cebd48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.8-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-14456", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:8507d921256f647a5b9079077494639909fd9e3b51749200c7f9400293e2d105", + "Title": "openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server", + "Description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/08/13/4", + "https://access.redhat.com/security/cve/CVE-2026-14456", + "https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9", + "https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b", + "https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139", + "https://linux.oracle.com/cve/CVE-2026-14456.html", + "https://linux.oracle.com/errata/ELSA-2026-67165-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-14456", + "https://openssl-library.org/news/secadv/20260813.txt", + "https://ubuntu.com/security/notices/USN-8678-1", + "https://www.cve.org/CVERecord?id=CVE-2026-14456" + ], + "PublishedDate": "2026-08-13T15:19:31.82Z", + "LastModifiedDate": "2026-08-28T19:46:29.323Z" + }, + { + "VulnerabilityID": "CVE-2026-28387", + "PkgID": "libcrypto3@3.5.5-r0", + "PkgName": "libcrypto3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "6778a588f2cebd48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28387", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:b0190ab2642810a6089f1ff172803c0e42d45e8efc211805b891e5d7e36abcd2", + "Title": "openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication", + "Description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages. These SMTP (or other similar) clients are not vulnerable\nto this issue. Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-416" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 1, + "julia": 3, + "nvd": 3, + "photon": 3, + "redhat": 1, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", + "V3Score": 3.7 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-28387", + "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", + "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", + "https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b", + "https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe", + "https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3", + "https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7", + "https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177", + "https://nvd.nist.gov/vuln/detail/CVE-2026-28387", + "https://openssl-library.org/news/secadv/20260407.txt", + "https://ubuntu.com/security/notices/USN-8155-1", + "https://ubuntu.com/security/notices/USN-8155-2", + "https://www.cve.org/CVERecord?id=CVE-2026-28387", + "https://www.openwall.com/lists/oss-security/2026/04/07/11" + ], + "PublishedDate": "2026-04-07T22:16:20.7Z", + "LastModifiedDate": "2026-07-24T23:10:00.563Z" + }, + { + "VulnerabilityID": "CVE-2026-28388", + "PkgID": "libcrypto3@3.5.5-r0", + "PkgName": "libcrypto3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "6778a588f2cebd48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28388", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:a645fcf6ec5bc8a2ef3da2e32ac68d75ea181be65a5f4f5e15bb7bfe8ca93365", + "Title": "openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing", + "Description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "julia": 3, + "nvd": 3, + "photon": 3, + "redhat": 1, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-28388", + "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", + "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", + "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e", + "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139", + "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3", + "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8", + "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726", + "https://nvd.nist.gov/vuln/detail/CVE-2026-28388", + "https://openssl-library.org/news/secadv/20260407.txt", + "https://ubuntu.com/security/notices/USN-8155-1", + "https://ubuntu.com/security/notices/USN-8155-2", + "https://www.cve.org/CVERecord?id=CVE-2026-28388", + "https://www.openwall.com/lists/oss-security/2026/04/07/11" + ], + "PublishedDate": "2026-04-07T22:16:20.863Z", + "LastModifiedDate": "2026-07-24T23:10:00.563Z" + }, + { + "VulnerabilityID": "CVE-2026-28389", + "PkgID": "libcrypto3@3.5.5-r0", + "PkgName": "libcrypto3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "6778a588f2cebd48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28389", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:496ad76e8296a02bab42c4a14de6182a3630367e087d8a9f8ccadccb29fffc54", + "Title": "openssl: OpenSSL: Denial of Service vulnerability in CMS processing", + "Description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "julia": 3, + "nvd": 3, + "photon": 3, + "redhat": 1, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-28389", + "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", + "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", + "https://github.com/advisories/GHSA-7x88-9hgc-69gf", + "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5", + "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616", + "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f", + "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a", + "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686", + "https://nvd.nist.gov/vuln/detail/CVE-2026-28389", + "https://openssl-library.org/news/secadv/20260407.txt", + "https://ubuntu.com/security/notices/USN-8155-1", + "https://ubuntu.com/security/notices/USN-8155-2", + "https://www.cve.org/CVERecord?id=CVE-2026-28389", + "https://www.openwall.com/lists/oss-security/2026/04/07/11" + ], + "PublishedDate": "2026-04-07T22:16:21.03Z", + "LastModifiedDate": "2026-07-24T23:10:00.563Z" + }, + { + "VulnerabilityID": "CVE-2026-28390", + "PkgID": "libcrypto3@3.5.5-r0", + "PkgName": "libcrypto3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "6778a588f2cebd48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28390", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:70c833c28a24a3236952fc029c28e1723c2ef84fd1df3e2ea5664be91e746d48", + "Title": "openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing", + "Description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 2, + "julia": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22312", + "https://access.redhat.com/errata/RHSA-2026:38503", + "https://access.redhat.com/security/cve/CVE-2026-28390", + "https://bugzilla.redhat.com/2456314", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456314", + "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", + "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28390", + "https://errata.almalinux.org/8/ALSA-2026-38503.html", + "https://errata.rockylinux.org/RLSA-2026:22312", + "https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc", + "https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6", + "https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4", + "https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788", + "https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75", + "https://linux.oracle.com/cve/CVE-2026-28390.html", + "https://linux.oracle.com/errata/ELSA-2026-50345.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-28390", + "https://openssl-library.org/news/secadv/20260407.txt", + "https://ubuntu.com/security/notices/USN-8155-1", + "https://ubuntu.com/security/notices/USN-8155-2", + "https://www.cve.org/CVERecord?id=CVE-2026-28390", + "https://www.openwall.com/lists/oss-security/2026/04/07/11" + ], + "PublishedDate": "2026-04-07T22:16:21.19Z", + "LastModifiedDate": "2026-07-24T23:10:00.563Z" + }, + { + "VulnerabilityID": "CVE-2026-45447", + "PkgID": "libcrypto3@3.5.5-r0", + "PkgName": "libcrypto3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcrypto3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "6778a588f2cebd48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.7-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-45447", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:1fac74a0b529ec2ff72d7655c158c79f473b9ad9cda7c663eaf580f5d269bf01", + "Title": "openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()", + "Description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-416", + "CWE-825" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "julia": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 3 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:25237", + "https://access.redhat.com/errata/RHSA-2026:25239", + "https://access.redhat.com/errata/RHSA-2026:26275", + "https://access.redhat.com/errata/RHSA-2026:26319", + "https://access.redhat.com/errata/RHSA-2026:29197", + "https://access.redhat.com/errata/RHSA-2026:34102", + "https://access.redhat.com/errata/RHSA-2026:35869", + "https://access.redhat.com/errata/RHSA-2026:36215", + "https://access.redhat.com/errata/RHSA-2026:36217", + "https://access.redhat.com/errata/RHSA-2026:39009", + "https://access.redhat.com/errata/RHSA-2026:39012", + "https://access.redhat.com/errata/RHSA-2026:39981", + "https://access.redhat.com/errata/RHSA-2026:44438", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:58563", + "https://access.redhat.com/errata/RHSA-2026:58981", + "https://access.redhat.com/errata/RHSA-2026:59831", + "https://access.redhat.com/errata/RHSA-2026:66524", + "https://access.redhat.com/security/cve/CVE-2026-45447", + "https://bugzilla.redhat.com/2481898", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481879", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481880", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481881", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481882", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481885", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481887", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481890", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481891", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481892", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481893", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481894", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481896", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481897", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481898", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076", + "https://errata.almalinux.org/8/ALSA-2026-36215.html", + "https://errata.rockylinux.org/RLSA-2026:25239", + "https://github.com/advisories/GHSA-f684-cpcq-j565", + "https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c", + "https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8", + "https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54", + "https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c", + "https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e", + "https://github.com/openssl/security/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c", + "https://github.com/openssl/security/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8", + "https://github.com/openssl/security/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54", + "https://github.com/openssl/security/commit/a541ae8bfe849a30cc885e8780715c0f488e496c", + "https://github.com/openssl/security/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e", + "https://linux.oracle.com/cve/CVE-2026-45447.html", + "https://linux.oracle.com/errata/ELSA-2026-50379.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-45447", + "https://openssl-library.org/news/secadv/20260609.txt", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json", + "https://ubuntu.com/security/notices/USN-8414-1", + "https://ubuntu.com/security/notices/USN-8414-2", + "https://www.cve.org/CVERecord?id=CVE-2026-45447" + ], + "PublishedDate": "2026-06-09T17:17:19.277Z", + "LastModifiedDate": "2026-09-11T13:18:10.853Z" + }, + { + "VulnerabilityID": "CVE-2026-11352", + "PkgID": "libcurl@8.17.0-r1", + "PkgName": "libcurl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "85c7760f5617ed48" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-11352", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:6f80d7483e4bd52959711d0c7172c0ed75361987e1606fc001619a48e5615ad0", + "Title": "curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability", + "Description": "An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server\nto trigger a remote denial of service against a curl or libcurl client.\nBecause the helper function discards zero-length UDP datagrams before counting\nthem toward the per-call packet budget, a connected QUIC peer can continuously\nstream empty datagrams to indefinitely stall the client.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-835" + ], + "VendorSeverity": { + "julia": 3, + "redhat": 3, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-11352", + "https://curl.se/L7HzKXisfJ/CVE-2026-11352.md", + "https://curl.se/docs/CVE-2026-11352.html", + "https://curl.se/docs/CVE-2026-11352.json", + "https://github.com/advisories/GHSA-qxwx-hr5v-h5q4", + "https://hackerone.com/reports/3783438", + "https://nvd.nist.gov/vuln/detail/CVE-2026-11352", + "https://ubuntu.com/security/notices/USN-8525-1", + "https://www.cve.org/CVERecord?id=CVE-2026-11352" + ], + "PublishedDate": "2026-07-03T07:16:23.693Z", + "LastModifiedDate": "2026-09-15T07:16:25.353Z" + }, + { + "VulnerabilityID": "CVE-2026-11586", + "PkgID": "libcurl@8.17.0-r1", + "PkgName": "libcurl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "85c7760f5617ed48" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-11586", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:9adc54fad5fcbe0cb3f68ad1a8b876d9a29d938c9d3ca8318458114a5d4aceb5", + "Title": "curl: curl: Denial of Service via WebSocket PING flood", + "Description": "By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "amazon": 2, + "julia": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-11586", + "https://curl.se/L7HzKXisfJ/CVE-2026-11586.md", + "https://curl.se/docs/CVE-2026-11586.html", + "https://curl.se/docs/CVE-2026-11586.json", + "https://github.com/advisories/GHSA-c68q-h477-5646", + "https://hackerone.com/reports/3788931", + "https://nvd.nist.gov/vuln/detail/CVE-2026-11586", + "https://ubuntu.com/security/notices/USN-8525-1", + "https://www.cve.org/CVERecord?id=CVE-2026-11586" + ], + "PublishedDate": "2026-07-03T07:16:23.883Z", + "LastModifiedDate": "2026-09-15T07:16:25.7Z" + }, + { + "VulnerabilityID": "CVE-2026-12064", + "PkgID": "libcurl@8.17.0-r1", + "PkgName": "libcurl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "85c7760f5617ed48" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-12064", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:c75e1d44bf742f10d17a692714a5cac51f4729b0e8179b0513d7706cb9f85435", + "Title": "curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP", + "Description": "When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-297", + "CWE-295" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 3, + "julia": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-12064", + "https://curl.se/L7HzKXisfJ/CVE-2026-12064.md", + "https://curl.se/docs/CVE-2026-12064.html", + "https://curl.se/docs/CVE-2026-12064.json", + "https://github.com/advisories/GHSA-jm94-9f7h-36pr", + "https://hackerone.com/reports/3797526", + "https://linux.oracle.com/cve/CVE-2026-12064.html", + "https://linux.oracle.com/errata/ELSA-2026-55450.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-12064", + "https://ubuntu.com/security/notices/USN-8525-1", + "https://www.cve.org/CVERecord?id=CVE-2026-12064" + ], + "PublishedDate": "2026-07-03T07:16:24.217Z", + "LastModifiedDate": "2026-09-15T07:16:26.15Z" + }, + { + "VulnerabilityID": "CVE-2026-5773", + "PkgID": "libcurl@8.17.0-r1", + "PkgName": "libcurl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "85c7760f5617ed48" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.20.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-5773", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:f5c61c3807f257cf19fe2f0154c9a646e0a599113d1770fc2c582808bf383c07", + "Title": "curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse", + "Description": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-488", + "CWE-918" + ], + "VendorSeverity": { + "julia": 3, + "nvd": 3, + "photon": 3, + "redhat": 2, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", + "V3Score": 6.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/04/29/9", + "https://access.redhat.com/security/cve/CVE-2026-5773", + "https://curl.se/docs/CVE-2026-5773.html", + "https://curl.se/docs/CVE-2026-5773.json", + "https://github.com/advisories/GHSA-rp9q-8q5w-ch44", + "https://hackerone.com/reports/3650689", + "https://nvd.nist.gov/vuln/detail/CVE-2026-5773", + "https://ubuntu.com/security/notices/USN-8227-1", + "https://ubuntu.com/security/notices/USN-8525-1", + "https://www.cve.org/CVERecord?id=CVE-2026-5773" + ], + "PublishedDate": "2026-05-13T13:01:56.307Z", + "LastModifiedDate": "2026-09-15T07:16:28.82Z" + }, + { + "VulnerabilityID": "CVE-2026-6276", + "PkgID": "libcurl@8.17.0-r1", + "PkgName": "libcurl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "85c7760f5617ed48" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.20.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-6276", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:3f46c72f692ad56b69bebd81875a83a7406c5b1503cd90fe336d15904aa01168", + "Title": "curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers", + "Description": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-346", + "CWE-319" + ], + "VendorSeverity": { + "azure": 2, + "julia": 3, + "nvd": 3, + "photon": 3, + "redhat": 1, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", + "V3Score": 3.7 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/04/29/13", + "https://access.redhat.com/security/cve/CVE-2026-6276", + "https://curl.se/docs/CVE-2026-6276.html", + "https://curl.se/docs/CVE-2026-6276.json", + "https://github.com/advisories/GHSA-2jc6-hc33-hv48", + "https://hackerone.com/reports/3671818", + "https://nvd.nist.gov/vuln/detail/CVE-2026-6276", + "https://ubuntu.com/security/notices/USN-8227-1", + "https://www.cve.org/CVERecord?id=CVE-2026-6276" + ], + "PublishedDate": "2026-05-13T13:01:56.8Z", + "LastModifiedDate": "2026-09-15T07:16:29.343Z" + }, + { + "VulnerabilityID": "CVE-2026-8286", + "PkgID": "libcurl@8.17.0-r1", + "PkgName": "libcurl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "85c7760f5617ed48" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8286", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:121a41985c9da40cb5aba7e2ddb430ec1266d853cbfcea27598c67f2e00fdc36", + "Title": "curl: curl: Insecure connection establishment due to TLS configuration mismatch", + "Description": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-295" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 3, + "julia": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:55439", + "https://access.redhat.com/errata/RHSA-2026:57462", + "https://access.redhat.com/security/cve/CVE-2026-8286", + "https://bugzilla.redhat.com/2496763", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446448", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446450", + "https://bugzilla.redhat.com/show_bug.cgi?id=2496758", + "https://bugzilla.redhat.com/show_bug.cgi?id=2496763", + "https://creativecommons.org/licenses/by/4.0/", + "https://curl.se/L7HzKXisfJ/CVE-2026-8286.md", + "https://curl.se/docs/CVE-2026-8286.html", + "https://curl.se/docs/CVE-2026-8286.json", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547", + "https://errata.almalinux.org/8/ALSA-2026-57462.html", + "https://errata.rockylinux.org/RLSA-2026:55439", + "https://github.com/advisories/GHSA-32xh-3x3c-6g6h", + "https://hackerone.com/reports/3718195", + "https://linux.oracle.com/cve/CVE-2026-8286.html", + "https://linux.oracle.com/errata/ELSA-2026-57462.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-8286", + "https://ubuntu.com/security/notices/USN-8487-1", + "https://www.cve.org/CVERecord?id=CVE-2026-8286" + ], + "PublishedDate": "2026-07-03T07:16:24.453Z", + "LastModifiedDate": "2026-09-15T07:16:31.617Z" + }, + { + "VulnerabilityID": "CVE-2026-8458", + "PkgID": "libcurl@8.17.0-r1", + "PkgName": "libcurl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "85c7760f5617ed48" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8458", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:fcd8b8c3b654561673146fd1225760e31042d59052cb3453a62dd648146652cc", + "Title": "curl: libcurl: Unauthorized connection reuse due to a logical error", + "Description": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-488" + ], + "VendorSeverity": { + "amazon": 2, + "azure": 2, + "julia": 2, + "photon": 2, + "redhat": 3, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", + "V3Score": 6.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-8458", + "https://curl.se/L7HzKXisfJ/CVE-2026-8458.md", + "https://curl.se/docs/CVE-2026-8458.html", + "https://curl.se/docs/CVE-2026-8458.json", + "https://github.com/advisories/GHSA-88c6-6jfq-mm4q", + "https://hackerone.com/reports/3721183", + "https://nvd.nist.gov/vuln/detail/CVE-2026-8458", + "https://ubuntu.com/security/notices/USN-8487-1", + "https://www.cve.org/CVERecord?id=CVE-2026-8458" + ], + "PublishedDate": "2026-07-03T07:16:24.63Z", + "LastModifiedDate": "2026-09-15T07:16:32.327Z" + }, + { + "VulnerabilityID": "CVE-2026-8925", + "PkgID": "libcurl@8.17.0-r1", + "PkgName": "libcurl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "85c7760f5617ed48" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8925", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:c590f69f57cd74439affbdb3326fa5bc10ae4435f37c33555f3e6834eaa55603", + "Title": "curl: curl: Double-free vulnerability in SASL authentication", + "Description": "The curl logic that works with SASL authentication could end up cleaning up\nthe GSASL context *twice* without clearing the pointer in between, making it\n`free()` the same pointer twice.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-415" + ], + "VendorSeverity": { + "amazon": 2, + "julia": 4, + "photon": 4, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-8925", + "https://curl.se/L7HzKXisfJ/CVE-2026-8925.md", + "https://curl.se/docs/CVE-2026-8925.html", + "https://curl.se/docs/CVE-2026-8925.json", + "https://github.com/advisories/GHSA-p8x5-c6c9-8cwx", + "https://hackerone.com/reports/3735193", + "https://nvd.nist.gov/vuln/detail/CVE-2026-8925", + "https://ubuntu.com/security/notices/USN-8487-1", + "https://www.cve.org/CVERecord?id=CVE-2026-8925" + ], + "PublishedDate": "2026-07-03T07:16:24.95Z", + "LastModifiedDate": "2026-09-15T07:16:32.8Z" + }, + { + "VulnerabilityID": "CVE-2026-8927", + "PkgID": "libcurl@8.17.0-r1", + "PkgName": "libcurl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "85c7760f5617ed48" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-8927", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:a5d7961b9014e46fd3e2fe9fbb3bc180e6552fcb770627f0868212993ae97c42", + "Title": "curl: Information disclosure due to uncleared proxy authentication state", + "Description": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-294" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "azure": 2, + "julia": 4, + "oracle-oval": 3, + "photon": 4, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 9.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:55432", + "https://access.redhat.com/security/cve/CVE-2026-8927", + "https://bugzilla.redhat.com/2496769", + "https://bugzilla.redhat.com/show_bug.cgi?id=2496769", + "https://creativecommons.org/licenses/by/4.0/", + "https://curl.se/L7HzKXisfJ/CVE-2026-8927.md", + "https://curl.se/docs/CVE-2026-8927.html", + "https://curl.se/docs/CVE-2026-8927.json", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8927", + "https://errata.almalinux.org/10/ALSA-2026-55432.html", + "https://errata.rockylinux.org/RLSA-2026:55432", + "https://github.com/advisories/GHSA-jr4f-4564-w3mr", + "https://hackerone.com/reports/3744543", + "https://linux.oracle.com/cve/CVE-2026-8927.html", + "https://linux.oracle.com/errata/ELSA-2026-55432.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-8927", + "https://ubuntu.com/security/notices/USN-8487-1", + "https://www.cve.org/CVERecord?id=CVE-2026-8927" + ], + "PublishedDate": "2026-07-03T07:16:25.123Z", + "LastModifiedDate": "2026-09-15T07:16:33.157Z" + }, + { + "VulnerabilityID": "CVE-2026-9547", + "PkgID": "libcurl@8.17.0-r1", + "PkgName": "libcurl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libcurl@8.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "85c7760f5617ed48" + }, + "InstalledVersion": "8.17.0-r1", + "FixedVersion": "8.22.0-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-9547", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:68f2b1b38e685a494a50efdcabf044195303599e5636b3dbbda5c9b9b5568dde", + "Title": "curl: curl: Man-in-the-middle attack via SSH host key bypass", + "Description": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-297" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 2, + "julia": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", + "V3Score": 7.4 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:55439", + "https://access.redhat.com/security/cve/CVE-2026-9547", + "https://bugzilla.redhat.com/2446448", + "https://bugzilla.redhat.com/2446450", + "https://bugzilla.redhat.com/2496758", + "https://bugzilla.redhat.com/2496763", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446448", + "https://bugzilla.redhat.com/show_bug.cgi?id=2446450", + "https://bugzilla.redhat.com/show_bug.cgi?id=2496758", + "https://bugzilla.redhat.com/show_bug.cgi?id=2496763", + "https://creativecommons.org/licenses/by/4.0/", + "https://curl.se/L7HzKXisfJ/CVE-2026-9547.md", + "https://curl.se/docs/CVE-2026-9547.html", + "https://curl.se/docs/CVE-2026-9547.json", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1965", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3783", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8286", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9547", + "https://errata.almalinux.org/9/ALSA-2026-55439.html", + "https://errata.rockylinux.org/RLSA-2026:55439", + "https://github.com/advisories/GHSA-xq9p-gxg6-f7q6", + "https://hackerone.com/reports/3751712", + "https://linux.oracle.com/cve/CVE-2026-9547.html", + "https://linux.oracle.com/errata/ELSA-2026-55450.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-9547", + "https://ubuntu.com/security/notices/USN-8487-1", + "https://www.cve.org/CVERecord?id=CVE-2026-9547" + ], + "PublishedDate": "2026-07-03T07:16:25.99Z", + "LastModifiedDate": "2026-09-15T07:16:35.31Z" + }, + { + "VulnerabilityID": "CVE-2026-45186", + "PkgID": "libexpat@2.7.5-r0", + "PkgName": "libexpat", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libexpat@2.7.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "60ae354914fcce6c" + }, + "InstalledVersion": "2.7.5-r0", + "FixedVersion": "2.8.1-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-45186", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:0d8a86967d8fa15637f654b06c8497d3f4f6bc48eb5cffb16a308a085413c924", + "Title": "libexpat: denial of service via crafted XML input", + "Description": "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-407" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 1, + "julia": 3, + "nvd": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/05/11/16", + "https://access.redhat.com/errata/RHSA-2026:22715", + "https://access.redhat.com/errata/RHSA-2026:22721", + "https://access.redhat.com/errata/RHSA-2026:23230", + "https://access.redhat.com/errata/RHSA-2026:26319", + "https://access.redhat.com/errata/RHSA-2026:27201", + "https://access.redhat.com/errata/RHSA-2026:29197", + "https://access.redhat.com/errata/RHSA-2026:58981", + "https://access.redhat.com/security/cve/CVE-2026-45186", + "https://bugzilla.redhat.com/2468575", + "https://bugzilla.redhat.com/show_bug.cgi?id=2468575", + "https://cert-portal.siemens.com/productcert/html/ssa-082556.html", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45186", + "https://errata.almalinux.org/8/ALSA-2026-22721.html", + "https://errata.rockylinux.org/RLSA-2026:23230", + "https://github.com/libexpat/libexpat/pull/1216", + "https://linux.oracle.com/cve/CVE-2026-45186.html", + "https://linux.oracle.com/errata/ELSA-2026-23230.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-45186", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json", + "https://www.cve.org/CVERecord?id=CVE-2026-45186" + ], + "PublishedDate": "2026-05-10T07:16:07.883Z", + "LastModifiedDate": "2026-08-25T13:19:12.733Z" + }, + { + "VulnerabilityID": "CVE-2026-76956", + "PkgID": "libexpat@2.7.5-r0", + "PkgName": "libexpat", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libexpat@2.7.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "60ae354914fcce6c" + }, + "InstalledVersion": "2.7.5-r0", + "FixedVersion": "2.8.4-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76956", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:643f929dd150a9f84e0f8f90df116ae6ed41ac3517b73329f9b4ae6137322fee", + "Title": "libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML", + "Description": "In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-394" + ], + "VendorSeverity": { + "azure": 2, + "nvd": 3, + "redhat": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76956", + "https://github.com/libexpat/libexpat/pull/1326", + "https://github.com/libexpat/libexpat/pull/1329", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76956", + "https://www.cve.org/CVERecord?id=CVE-2026-76956" + ], + "PublishedDate": "2026-08-20T05:16:29.61Z", + "LastModifiedDate": "2026-09-08T21:08:20.697Z" + }, + { + "VulnerabilityID": "CVE-2026-76957", + "PkgID": "libexpat@2.7.5-r0", + "PkgName": "libexpat", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libexpat@2.7.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "60ae354914fcce6c" + }, + "InstalledVersion": "2.7.5-r0", + "FixedVersion": "2.8.4-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76957", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:81d7c0687cae5b008df63250a49df443831c48fd7532df7889fd28adcd84e646", + "Title": "libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service", + "Description": "libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-416" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "nvd": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", + "V3Score": 4.9 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76957", + "https://github.com/libexpat/libexpat/pull/1322", + "https://github.com/libexpat/libexpat/pull/1329", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76957", + "https://www.cve.org/CVERecord?id=CVE-2026-76957" + ], + "PublishedDate": "2026-08-20T05:16:29.747Z", + "LastModifiedDate": "2026-09-08T20:56:31.86Z" + }, + { + "VulnerabilityID": "CVE-2026-31789", + "PkgID": "libssl3@3.5.5-r0", + "PkgName": "libssl3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "bca2260902e2ef48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-31789", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:1ed7188257cd36ad2de434165f52910df869991d0efa7d88f0869ea1e74f85d5", + "Title": "openssl: OpenSSL: Heap buffer overflow on 32-bit systems from large X.509 certificate processing", + "Description": "Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", + "Severity": "CRITICAL", + "CweIDs": [ + "CWE-787" + ], + "VendorSeverity": { + "azure": 2, + "julia": 4, + "nvd": 4, + "photon": 4, + "redhat": 1, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 9.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H", + "V3Score": 5.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-31789", + "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", + "https://github.com/advisories/GHSA-j79m-9jxq-788r", + "https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde", + "https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf", + "https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49", + "https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9", + "https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521", + "https://nvd.nist.gov/vuln/detail/CVE-2026-31789", + "https://openssl-library.org/news/secadv/20260407.txt", + "https://ubuntu.com/security/notices/USN-8155-1", + "https://www.cve.org/CVERecord?id=CVE-2026-31789", + "https://www.openwall.com/lists/oss-security/2026/04/07/11" + ], + "PublishedDate": "2026-04-07T22:16:21.617Z", + "LastModifiedDate": "2026-07-24T23:10:00.563Z" + }, + { + "VulnerabilityID": "CVE-2026-14456", + "PkgID": "libssl3@3.5.5-r0", + "PkgName": "libssl3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "bca2260902e2ef48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.8-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-14456", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:788f2b3335228ab2fb9361761262ebb89c47f5b5eb385ca3766d79e010bbfc26", + "Title": "openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server", + "Description": "Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-770" + ], + "VendorSeverity": { + "amazon": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/08/13/4", + "https://access.redhat.com/security/cve/CVE-2026-14456", + "https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9", + "https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b", + "https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139", + "https://linux.oracle.com/cve/CVE-2026-14456.html", + "https://linux.oracle.com/errata/ELSA-2026-67165-0.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-14456", + "https://openssl-library.org/news/secadv/20260813.txt", + "https://ubuntu.com/security/notices/USN-8678-1", + "https://www.cve.org/CVERecord?id=CVE-2026-14456" + ], + "PublishedDate": "2026-08-13T15:19:31.82Z", + "LastModifiedDate": "2026-08-28T19:46:29.323Z" + }, + { + "VulnerabilityID": "CVE-2026-28387", + "PkgID": "libssl3@3.5.5-r0", + "PkgName": "libssl3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "bca2260902e2ef48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28387", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:34c25f043d8bec73580478120cea20d30f407dea733211611d0035b96159fbda", + "Title": "openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLSA authentication", + "Description": "Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages. These SMTP (or other similar) clients are not vulnerable\nto this issue. Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-416" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 1, + "julia": 3, + "nvd": 3, + "photon": 3, + "redhat": 1, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", + "V3Score": 3.7 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-28387", + "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", + "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", + "https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b", + "https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe", + "https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3", + "https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7", + "https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177", + "https://nvd.nist.gov/vuln/detail/CVE-2026-28387", + "https://openssl-library.org/news/secadv/20260407.txt", + "https://ubuntu.com/security/notices/USN-8155-1", + "https://ubuntu.com/security/notices/USN-8155-2", + "https://www.cve.org/CVERecord?id=CVE-2026-28387", + "https://www.openwall.com/lists/oss-security/2026/04/07/11" + ], + "PublishedDate": "2026-04-07T22:16:20.7Z", + "LastModifiedDate": "2026-07-24T23:10:00.563Z" + }, + { + "VulnerabilityID": "CVE-2026-28388", + "PkgID": "libssl3@3.5.5-r0", + "PkgName": "libssl3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "bca2260902e2ef48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28388", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:0b9e8688d3d089e44f6afa0038e3d461d4df29095381f896d59a0f80ee73e265", + "Title": "openssl: OpenSSL: Denial of Service due to NULL pointer dereference in delta CRL processing", + "Description": "Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "julia": 3, + "nvd": 3, + "photon": 3, + "redhat": 1, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-28388", + "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", + "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", + "https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e", + "https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139", + "https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3", + "https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8", + "https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726", + "https://nvd.nist.gov/vuln/detail/CVE-2026-28388", + "https://openssl-library.org/news/secadv/20260407.txt", + "https://ubuntu.com/security/notices/USN-8155-1", + "https://ubuntu.com/security/notices/USN-8155-2", + "https://www.cve.org/CVERecord?id=CVE-2026-28388", + "https://www.openwall.com/lists/oss-security/2026/04/07/11" + ], + "PublishedDate": "2026-04-07T22:16:20.863Z", + "LastModifiedDate": "2026-07-24T23:10:00.563Z" + }, + { + "VulnerabilityID": "CVE-2026-28389", + "PkgID": "libssl3@3.5.5-r0", + "PkgName": "libssl3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "bca2260902e2ef48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28389", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:ca77ec59988da1821209c669e656b0097d03fa827294cd33475b020c0e96f8a1", + "Title": "openssl: OpenSSL: Denial of Service vulnerability in CMS processing", + "Description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "amazon": 3, + "azure": 2, + "julia": 3, + "nvd": 3, + "photon": 3, + "redhat": 1, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 5.9 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-28389", + "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", + "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", + "https://github.com/advisories/GHSA-7x88-9hgc-69gf", + "https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5", + "https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616", + "https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f", + "https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a", + "https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686", + "https://nvd.nist.gov/vuln/detail/CVE-2026-28389", + "https://openssl-library.org/news/secadv/20260407.txt", + "https://ubuntu.com/security/notices/USN-8155-1", + "https://ubuntu.com/security/notices/USN-8155-2", + "https://www.cve.org/CVERecord?id=CVE-2026-28389", + "https://www.openwall.com/lists/oss-security/2026/04/07/11" + ], + "PublishedDate": "2026-04-07T22:16:21.03Z", + "LastModifiedDate": "2026-07-24T23:10:00.563Z" + }, + { + "VulnerabilityID": "CVE-2026-28390", + "PkgID": "libssl3@3.5.5-r0", + "PkgName": "libssl3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "bca2260902e2ef48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-28390", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:ad39877058ae8a1d4104b7f4ba55e2cd0c746173b2f65a819625b03b8d142115", + "Title": "openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing", + "Description": "Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-476" + ], + "VendorSeverity": { + "alma": 2, + "amazon": 3, + "azure": 2, + "julia": 3, + "nvd": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 2, + "rocky": 2, + "ubuntu": 1 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:22312", + "https://access.redhat.com/errata/RHSA-2026:38503", + "https://access.redhat.com/security/cve/CVE-2026-28390", + "https://bugzilla.redhat.com/2456314", + "https://bugzilla.redhat.com/show_bug.cgi?id=2456314", + "https://cert-portal.siemens.com/productcert/html/ssa-032379.html", + "https://cert-portal.siemens.com/productcert/html/ssa-265688.html", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28390", + "https://errata.almalinux.org/8/ALSA-2026-38503.html", + "https://errata.rockylinux.org/RLSA-2026:22312", + "https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc", + "https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6", + "https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4", + "https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788", + "https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75", + "https://linux.oracle.com/cve/CVE-2026-28390.html", + "https://linux.oracle.com/errata/ELSA-2026-50345.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-28390", + "https://openssl-library.org/news/secadv/20260407.txt", + "https://ubuntu.com/security/notices/USN-8155-1", + "https://ubuntu.com/security/notices/USN-8155-2", + "https://www.cve.org/CVERecord?id=CVE-2026-28390", + "https://www.openwall.com/lists/oss-security/2026/04/07/11" + ], + "PublishedDate": "2026-04-07T22:16:21.19Z", + "LastModifiedDate": "2026-07-24T23:10:00.563Z" + }, + { + "VulnerabilityID": "CVE-2026-45447", + "PkgID": "libssl3@3.5.5-r0", + "PkgName": "libssl3", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libssl3@3.5.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "bca2260902e2ef48" + }, + "InstalledVersion": "3.5.5-r0", + "FixedVersion": "3.5.7-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-45447", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:65b8831d28e97cb2ad71066d8a5510cc57b87e45dcd390a81cf4b5345bad2e25", + "Title": "openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()", + "Description": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-416", + "CWE-825" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "julia": 3, + "oracle-oval": 2, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 3 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:25237", + "https://access.redhat.com/errata/RHSA-2026:25239", + "https://access.redhat.com/errata/RHSA-2026:26275", + "https://access.redhat.com/errata/RHSA-2026:26319", + "https://access.redhat.com/errata/RHSA-2026:29197", + "https://access.redhat.com/errata/RHSA-2026:34102", + "https://access.redhat.com/errata/RHSA-2026:35869", + "https://access.redhat.com/errata/RHSA-2026:36215", + "https://access.redhat.com/errata/RHSA-2026:36217", + "https://access.redhat.com/errata/RHSA-2026:39009", + "https://access.redhat.com/errata/RHSA-2026:39012", + "https://access.redhat.com/errata/RHSA-2026:39981", + "https://access.redhat.com/errata/RHSA-2026:44438", + "https://access.redhat.com/errata/RHSA-2026:47735", + "https://access.redhat.com/errata/RHSA-2026:47737", + "https://access.redhat.com/errata/RHSA-2026:58563", + "https://access.redhat.com/errata/RHSA-2026:58981", + "https://access.redhat.com/errata/RHSA-2026:59831", + "https://access.redhat.com/errata/RHSA-2026:66524", + "https://access.redhat.com/security/cve/CVE-2026-45447", + "https://bugzilla.redhat.com/2481898", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481879", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481880", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481881", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481882", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481884", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481885", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481887", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481890", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481891", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481892", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481893", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481894", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481896", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481897", + "https://bugzilla.redhat.com/show_bug.cgi?id=2481898", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34180", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34181", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34182", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34183", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42764", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42766", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42767", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42768", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42769", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42770", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45445", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45446", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45447", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7383", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9076", + "https://errata.almalinux.org/8/ALSA-2026-36215.html", + "https://errata.rockylinux.org/RLSA-2026:25239", + "https://github.com/advisories/GHSA-f684-cpcq-j565", + "https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c", + "https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8", + "https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54", + "https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c", + "https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e", + "https://github.com/openssl/security/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c", + "https://github.com/openssl/security/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8", + "https://github.com/openssl/security/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54", + "https://github.com/openssl/security/commit/a541ae8bfe849a30cc885e8780715c0f488e496c", + "https://github.com/openssl/security/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e", + "https://linux.oracle.com/cve/CVE-2026-45447.html", + "https://linux.oracle.com/errata/ELSA-2026-50379.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-45447", + "https://openssl-library.org/news/secadv/20260609.txt", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json", + "https://ubuntu.com/security/notices/USN-8414-1", + "https://ubuntu.com/security/notices/USN-8414-2", + "https://www.cve.org/CVERecord?id=CVE-2026-45447" + ], + "PublishedDate": "2026-06-09T17:17:19.277Z", + "LastModifiedDate": "2026-09-11T13:18:10.853Z" + }, + { + "VulnerabilityID": "CVE-2026-53612", + "PkgID": "libuuid@2.41.2-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "509022c493029e03" + }, + "InstalledVersion": "2.41.2-r0", + "FixedVersion": "2.41.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53612", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:66e0c191ce5607dcc196942aba290c9b467bc46156fdb0b3f5c55c415060b094", + "Title": "util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes", + "Description": "A flaw was found in util-linux. When an /etc/fstab entry uses the user option together with X-mount.owner, X-mount.group, or X-mount.mode, mount(8) changes ownership or permissions on the mount target after mounting without re-verifying the path. A local unprivileged user can exploit this Time-of-Check-Time-of-Use (TOCTOU) window by swapping the target directory, redirecting the ownership/permission change to an arbitrary file and potentially escalating privileges to root.", + "Severity": "HIGH", + "VendorSeverity": { + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-53612", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-g8wm-75wr-g2vh", + "https://nvd.nist.gov/vuln/detail/CVE-2026-53612", + "https://ubuntu.com/security/notices/USN-8702-1", + "https://www.cve.org/CVERecord?id=CVE-2026-53612" + ] + }, + { + "VulnerabilityID": "CVE-2026-53613", + "PkgID": "libuuid@2.41.2-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "509022c493029e03" + }, + "InstalledVersion": "2.41.2-r0", + "FixedVersion": "2.41.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53613", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:cb1ca22b1a0c6ab3c5692eb2ec1833f0970646f1e5a13be1de1eff43aab0ec4a", + "Title": "util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path", + "Description": "When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root.", + "Severity": "HIGH", + "VendorSeverity": { + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-53613", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g", + "https://nvd.nist.gov/vuln/detail/CVE-2026-53613", + "https://ubuntu.com/security/notices/USN-8702-1", + "https://www.cve.org/CVERecord?id=CVE-2026-53613" + ] + }, + { + "VulnerabilityID": "CVE-2026-53614", + "PkgID": "libuuid@2.41.2-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "509022c493029e03" + }, + "InstalledVersion": "2.41.2-r0", + "FixedVersion": "2.41.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-53614", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:e558ead5205cca32ae1243f8df104ee7e9129f0f79d1359a95e6fdda9ea2f852", + "Title": "util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2", + "Description": "A flaw was found in util-linux. The mount(8) SUID binary does not sanitize the LIBMOUNT_FORCE_MOUNT2 environment variable before use. A local unprivileged user can set this variable to force mount(8) to use the legacy two-step mount(2) code path, which applies security restrictions such as nosuid and noexec after the mount is already active. During this window, an attacker can execute a SUID binary from the mounted filesystem, allowing local privilege escalation to root.", + "Severity": "HIGH", + "VendorSeverity": { + "redhat": 3, + "ubuntu": 2 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-53614", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-67r7-8m5w-22wx", + "https://nvd.nist.gov/vuln/detail/CVE-2026-53614", + "https://ubuntu.com/security/notices/USN-8702-1", + "https://www.cve.org/CVERecord?id=CVE-2026-53614" + ] + }, + { + "VulnerabilityID": "CVE-2026-76642", + "PkgID": "libuuid@2.41.2-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "509022c493029e03" + }, + "InstalledVersion": "2.41.2-r0", + "FixedVersion": "2.41.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-76642", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:a7207f52f6bc2c43c87c21fd16a856b2b3e8ee94b8a18ec7c9c7124c47617b23", + "Title": "util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks", + "Description": "util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-390" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-76642", + "https://github.com/util-linux/util-linux", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476", + "https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892", + "https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a", + "https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc", + "https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f", + "https://nvd.nist.gov/vuln/detail/CVE-2026-76642", + "https://www.cve.org/CVERecord?id=CVE-2026-76642", + "https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper" + ], + "PublishedDate": "2026-09-03T13:06:08.44Z", + "LastModifiedDate": "2026-09-03T15:17:33.49Z" + }, + { + "VulnerabilityID": "CVE-2026-78408", + "PkgID": "libuuid@2.41.2-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "509022c493029e03" + }, + "InstalledVersion": "2.41.2-r0", + "FixedVersion": "2.41.6-r1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78408", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:49a185af463fd19e31d6cb4c71b19fdb6b04e1a8db216ff3eb68fc76bc2893d6", + "Title": "util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority", + "Description": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-775" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H", + "V3Score": 7.9 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/09/05/2", + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78408", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522497", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78408", + "https://www.cve.org/CVERecord?id=CVE-2026-78408" + ], + "PublishedDate": "2026-09-02T16:17:23.687Z", + "LastModifiedDate": "2026-09-05T14:17:23.727Z" + }, + { + "VulnerabilityID": "CVE-2026-78410", + "PkgID": "libuuid@2.41.2-r0", + "PkgName": "libuuid", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libuuid@2.41.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "509022c493029e03" + }, + "InstalledVersion": "2.41.2-r0", + "FixedVersion": "2.41.6-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-78410", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:754f422d26b7ff55fd2436be9fc93b9e81857e3c6995e0e202e9c970f2f8165e", + "Title": "util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection", + "Description": "A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-367" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:63162", + "https://access.redhat.com/security/cve/CVE-2026-78410", + "https://bugzilla.redhat.com/show_bug.cgi?id=2522684", + "https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m", + "https://nvd.nist.gov/vuln/detail/CVE-2026-78410", + "https://www.cve.org/CVERecord?id=CVE-2026-78410" + ], + "PublishedDate": "2026-09-02T16:17:23.983Z", + "LastModifiedDate": "2026-09-04T19:17:27.567Z" + }, + { + "VulnerabilityID": "CVE-2026-6732", + "PkgID": "libxml2@2.13.9-r0", + "PkgName": "libxml2", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/libxml2@2.13.9-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "ce9ff006e72f7256" + }, + "InstalledVersion": "2.13.9-r0", + "FixedVersion": "2.13.9-r1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-6732", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:cd01b1e873db5f860089e03849367417ca8307d68879438d902abc1d56cbaec4", + "Title": "libxml2: libxml2: Denial of Service via crafted XSD-validated document", + "Description": "A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-843" + ], + "VendorSeverity": { + "julia": 3, + "nvd": 3, + "photon": 3, + "redhat": 2, + "ubuntu": 2 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "nvd": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 6.5 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:11503", + "https://access.redhat.com/security/cve/CVE-2026-6732", + "https://bugzilla.redhat.com/show_bug.cgi?id=2461300", + "https://gitlab.gnome.org/GNOME/libxml2/-/issues/1097", + "https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411", + "https://nvd.nist.gov/vuln/detail/CVE-2026-6732", + "https://ubuntu.com/security/notices/USN-8460-1", + "https://www.cve.org/CVERecord?id=CVE-2026-6732" + ], + "PublishedDate": "2026-04-23T23:16:16.443Z", + "LastModifiedDate": "2026-08-31T12:17:56.307Z" + }, + { + "VulnerabilityID": "CVE-2026-40200", + "PkgID": "musl@1.2.5-r21", + "PkgName": "musl", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/musl@1.2.5-r21?arch=x86_64\u0026distro=3.23.3", + "UID": "750ab06f52f2bfe9" + }, + "InstalledVersion": "1.2.5-r21", + "FixedVersion": "1.2.5-r23", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40200", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:9b867e6735969cfb16b8c627270d67cca6bb6530a716721259dbada8e5564aad", + "Title": "musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort", + "Description": "An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-670" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/04/10/13", + "https://access.redhat.com/security/cve/CVE-2026-40200", + "https://musl.libc.org/releases.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40200", + "https://www.cve.org/CVERecord?id=CVE-2026-40200", + "https://www.openwall.com/lists/oss-security/2026/04/10/13" + ], + "PublishedDate": "2026-04-10T17:17:14.107Z", + "LastModifiedDate": "2026-06-17T10:44:51.887Z" + }, + { + "VulnerabilityID": "CVE-2026-40200", + "PkgID": "musl-utils@1.2.5-r21", + "PkgName": "musl-utils", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/musl-utils@1.2.5-r21?arch=x86_64\u0026distro=3.23.3", + "UID": "9dadd6d4093981ad" + }, + "InstalledVersion": "1.2.5-r21", + "FixedVersion": "1.2.5-r23", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-40200", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:2baaca9b049c4e9a17b9bc14dbfcc7e3710b270c7f25b326818bb881c547cfef", + "Title": "musl: musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort", + "Description": "An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).", + "Severity": "HIGH", + "CweIDs": [ + "CWE-670" + ], + "VendorSeverity": { + "redhat": 3 + }, + "CVSS": { + "redhat": { + "V3Vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H", + "V3Score": 7.8 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/04/10/13", + "https://access.redhat.com/security/cve/CVE-2026-40200", + "https://musl.libc.org/releases.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-40200", + "https://www.cve.org/CVERecord?id=CVE-2026-40200", + "https://www.openwall.com/lists/oss-security/2026/04/10/13" + ], + "PublishedDate": "2026-04-10T17:17:14.107Z", + "LastModifiedDate": "2026-06-17T10:44:51.887Z" + }, + { + "VulnerabilityID": "CVE-2026-27135", + "PkgID": "nghttp2-libs@1.68.0-r0", + "PkgName": "nghttp2-libs", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/nghttp2-libs@1.68.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "802c936f9e7891b2" + }, + "InstalledVersion": "1.68.0-r0", + "FixedVersion": "1.68.1", + "Status": "fixed", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-27135", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:14217fd5f5725adca855befd93725d4d3a4495c388f539f8e4386b48fe007647", + "Title": "nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination", + "Description": "nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-617" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "cbl-mariner": 3, + "julia": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "julia": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/03/20/3", + "https://access.redhat.com/errata/RHSA-2026:10065", + "https://access.redhat.com/errata/RHSA-2026:11768", + "https://access.redhat.com/errata/RHSA-2026:13812", + "https://access.redhat.com/errata/RHSA-2026:14773", + "https://access.redhat.com/errata/RHSA-2026:14937", + "https://access.redhat.com/errata/RHSA-2026:15087", + "https://access.redhat.com/errata/RHSA-2026:16008", + "https://access.redhat.com/errata/RHSA-2026:16009", + "https://access.redhat.com/errata/RHSA-2026:16030", + "https://access.redhat.com/errata/RHSA-2026:16174", + "https://access.redhat.com/errata/RHSA-2026:17596", + "https://access.redhat.com/errata/RHSA-2026:19724", + "https://access.redhat.com/errata/RHSA-2026:19725", + "https://access.redhat.com/errata/RHSA-2026:20040", + "https://access.redhat.com/errata/RHSA-2026:20087", + "https://access.redhat.com/errata/RHSA-2026:21656", + "https://access.redhat.com/errata/RHSA-2026:21690", + "https://access.redhat.com/errata/RHSA-2026:21695", + "https://access.redhat.com/errata/RHSA-2026:25096", + "https://access.redhat.com/errata/RHSA-2026:27200", + "https://access.redhat.com/errata/RHSA-2026:27201", + "https://access.redhat.com/errata/RHSA-2026:6190", + "https://access.redhat.com/errata/RHSA-2026:7080", + "https://access.redhat.com/errata/RHSA-2026:7123", + "https://access.redhat.com/errata/RHSA-2026:7302", + "https://access.redhat.com/errata/RHSA-2026:7310", + "https://access.redhat.com/errata/RHSA-2026:7350", + "https://access.redhat.com/errata/RHSA-2026:7666", + "https://access.redhat.com/errata/RHSA-2026:7667", + "https://access.redhat.com/errata/RHSA-2026:7668", + "https://access.redhat.com/errata/RHSA-2026:7670", + "https://access.redhat.com/errata/RHSA-2026:7675", + "https://access.redhat.com/errata/RHSA-2026:7896", + "https://access.redhat.com/errata/RHSA-2026:7983", + "https://access.redhat.com/errata/RHSA-2026:8339", + "https://access.redhat.com/errata/RHSA-2026:8538", + "https://access.redhat.com/errata/RHSA-2026:8539", + "https://access.redhat.com/errata/RHSA-2026:8540", + "https://access.redhat.com/errata/RHSA-2026:8541", + "https://access.redhat.com/errata/RHSA-2026:8545", + "https://access.redhat.com/errata/RHSA-2026:8546", + "https://access.redhat.com/errata/RHSA-2026:8547", + "https://access.redhat.com/errata/RHSA-2026:8548", + "https://access.redhat.com/errata/RHSA-2026:8868", + "https://access.redhat.com/errata/RHSA-2026:9711", + "https://access.redhat.com/errata/RHSA-2026:9832", + "https://access.redhat.com/errata/RHSA-2026:9874", + "https://access.redhat.com/security/cve/CVE-2026-27135", + "https://bugzilla.redhat.com/2441268", + "https://bugzilla.redhat.com/2442922", + "https://bugzilla.redhat.com/2448754", + "https://bugzilla.redhat.com/2453151", + "https://bugzilla.redhat.com/show_bug.cgi?id=2448754", + "https://cert-portal.siemens.com/productcert/html/ssa-019113.html", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27135", + "https://errata.almalinux.org/8/ALSA-2026-8339.html", + "https://errata.rockylinux.org/RLSA-2026:7668", + "https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1", + "https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6", + "https://linux.oracle.com/cve/CVE-2026-27135.html", + "https://linux.oracle.com/errata/ELSA-2026-8339.html", + "https://lists.debian.org/debian-lts-announce/2026/05/msg00025.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-27135", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json", + "https://ubuntu.com/security/notices/USN-8233-1", + "https://ubuntu.com/security/notices/USN-8233-2", + "https://www.cve.org/CVERecord?id=CVE-2026-27135" + ], + "PublishedDate": "2026-03-18T18:16:26.723Z", + "LastModifiedDate": "2026-07-15T02:19:03.367Z" + }, + { + "VulnerabilityID": "CVE-2026-42055", + "PkgID": "nginx@1.28.3-r1", + "PkgName": "nginx", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8bdce2a9d53051b3" + }, + "InstalledVersion": "1.28.3-r1", + "FixedVersion": "1.28.3-r4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42055", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:cf24340681d84f61ec55cba943ff98b324600671ea8e30214601fccbb1da0b03", + "Title": "nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers", + "Description": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-122", + "CWE-787", + "CWE-131" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 4, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 9.2 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:27197", + "https://access.redhat.com/errata/RHSA-2026:36331", + "https://access.redhat.com/errata/RHSA-2026:36364", + "https://access.redhat.com/errata/RHSA-2026:36618", + "https://access.redhat.com/errata/RHSA-2026:36639", + "https://access.redhat.com/errata/RHSA-2026:38847", + "https://access.redhat.com/errata/RHSA-2026:44481", + "https://access.redhat.com/errata/RHSA-2026:46836", + "https://access.redhat.com/errata/RHSA-2026:58981", + "https://access.redhat.com/security/cve/CVE-2026-42055", + "https://bugzilla.redhat.com/2489866", + "https://bugzilla.redhat.com/show_bug.cgi?id=2489866", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42055", + "https://errata.almalinux.org/8/ALSA-2026-38847.html", + "https://errata.rockylinux.org/RLSA-2026:36639", + "https://linux.oracle.com/cve/CVE-2026-42055.html", + "https://linux.oracle.com/errata/ELSA-2026-38847.html", + "https://my.f5.com/manage/s/article/K000161584", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42055", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42055.json", + "https://ubuntu.com/security/notices/USN-8458-1", + "https://www.cve.org/CVERecord?id=CVE-2026-42055" + ], + "PublishedDate": "2026-06-17T15:16:50.353Z", + "LastModifiedDate": "2026-09-14T13:18:34.69Z" + }, + { + "VulnerabilityID": "CVE-2026-42533", + "PkgID": "nginx@1.28.3-r1", + "PkgName": "nginx", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8bdce2a9d53051b3" + }, + "InstalledVersion": "1.28.3-r1", + "FixedVersion": "1.28.3-r6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42533", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:15a804ee01ab6b8edeb9cf66a74400174ccbb23556bfb9084042d656a99b6e38", + "Title": "nginx: NGINX: Arbitrary code execution via crafted HTTP requests", + "Description": "A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.\n\nImpact:\nThis vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.\n\n\n\n\n Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-122" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "bitnami": 4, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 9.2 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:66542", + "https://access.redhat.com/security/cve/CVE-2026-42533", + "https://bugzilla.redhat.com/2500967", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500967", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42533", + "https://cyberstan.co.uk/nginx-rce/", + "https://errata.almalinux.org/9/ALSA-2026-66542.html", + "https://errata.rockylinux.org/RLSA-2026:66542", + "https://github.com/imbas007/cve-2026-42533", + "https://linux.oracle.com/cve/CVE-2026-42533.html", + "https://linux.oracle.com/errata/ELSA-2026-66542-0.html", + "https://my.f5.com/manage/s/article/K000162097", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42533", + "https://ubuntu.com/security/notices/USN-8563-1", + "https://ubuntu.com/security/notices/USN-8563-2", + "https://ubuntu.com/security/notices/USN-8563-3", + "https://ubuntu.com/security/notices/USN-8563-4", + "https://ubuntu.com/security/notices/USN-8563-5", + "https://www.cve.org/CVERecord?id=CVE-2026-42533" + ], + "PublishedDate": "2026-07-15T15:16:33.48Z", + "LastModifiedDate": "2026-08-10T15:28:01.94Z" + }, + { + "VulnerabilityID": "CVE-2026-49975", + "PkgID": "nginx@1.28.3-r1", + "PkgName": "nginx", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8bdce2a9d53051b3" + }, + "InstalledVersion": "1.28.3-r1", + "FixedVersion": "1.28.3-r3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49975", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:86b0fce9ba1ec6603a72210fde7aedd3fc4e0ed042e7d25b1649797cf86c05b5", + "Title": "httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack", + "Description": "Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.\n\nThis issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789", + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/06/03/3", + "http://www.openwall.com/lists/oss-security/2026/06/08/16", + "https://access.redhat.com/errata/RHSA-2026:25042", + "https://access.redhat.com/errata/RHSA-2026:25057", + "https://access.redhat.com/errata/RHSA-2026:25090", + "https://access.redhat.com/errata/RHSA-2026:25225", + "https://access.redhat.com/errata/RHSA-2026:27114", + "https://access.redhat.com/errata/RHSA-2026:27200", + "https://access.redhat.com/errata/RHSA-2026:27201", + "https://access.redhat.com/errata/RHSA-2026:36373", + "https://access.redhat.com/errata/RHSA-2026:36831", + "https://access.redhat.com/errata/RHSA-2026:36846", + "https://access.redhat.com/errata/RHSA-2026:50538", + "https://access.redhat.com/errata/RHSA-2026:50572", + "https://access.redhat.com/errata/RHSA-2026:55930", + "https://access.redhat.com/errata/RHSA-2026:55992", + "https://access.redhat.com/security/cve/CVE-2026-49975", + "https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb", + "https://bugzilla.redhat.com/2485371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2485371", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-49975", + "https://errata.almalinux.org/8/ALSA-2026-25090.html", + "https://errata.rockylinux.org/RLSA-2026:25057", + "https://github.com/EQSTLab/CVE-2026-49975", + "https://github.com/icing/mod_h2/pull/324", + "https://httpd.apache.org/security/vulnerabilities_24.html", + "https://linux.oracle.com/cve/CVE-2026-49975.html", + "https://linux.oracle.com/errata/ELSA-2026-25225.html", + "https://lists.debian.org/debian-lts-announce/2026/06/msg00009.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-49975", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49975.json", + "https://ubuntu.com/security/notices/USN-8384-1", + "https://ubuntu.com/security/notices/USN-8398-1", + "https://ubuntu.com/security/notices/USN-8398-2", + "https://ubuntu.com/security/notices/USN-8398-3", + "https://ubuntu.com/security/notices/USN-8398-4", + "https://ubuntu.com/security/notices/USN-8571-1", + "https://www.cve.org/CVERecord?id=CVE-2026-49975" + ], + "PublishedDate": "2026-06-08T16:16:44.223Z", + "LastModifiedDate": "2026-08-19T12:18:28.65Z" + }, + { + "VulnerabilityID": "CVE-2026-60005", + "PkgID": "nginx@1.28.3-r1", + "PkgName": "nginx", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8bdce2a9d53051b3" + }, + "InstalledVersion": "1.28.3-r1", + "FixedVersion": "1.28.3-r6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-60005", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:d56fb689e95df1ae318f0dc04af52c804243e06a168776bb9576c0a4f5d152dd", + "Title": "nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module", + "Description": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart.\n\nImpact:\nThis vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.\nNote: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-908" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:59216", + "https://access.redhat.com/errata/RHSA-2026:59496", + "https://access.redhat.com/security/cve/CVE-2026-60005", + "https://bugzilla.redhat.com/2500960", + "https://bugzilla.redhat.com/2500992", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500960", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500992", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56434", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-60005", + "https://errata.almalinux.org/8/ALSA-2026-59216.html", + "https://errata.rockylinux.org/RLSA-2026:59496", + "https://linux.oracle.com/cve/CVE-2026-60005.html", + "https://linux.oracle.com/errata/ELSA-2026-59496.html", + "https://my.f5.com/manage/s/article/K000162100", + "https://nvd.nist.gov/vuln/detail/CVE-2026-60005", + "https://ubuntu.com/security/notices/USN-8563-1", + "https://www.cve.org/CVERecord?id=CVE-2026-60005" + ], + "PublishedDate": "2026-07-15T16:16:49.82Z", + "LastModifiedDate": "2026-08-11T15:09:03.683Z" + }, + { + "VulnerabilityID": "CVE-2026-9256", + "PkgID": "nginx@1.28.3-r1", + "PkgName": "nginx", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8bdce2a9d53051b3" + }, + "InstalledVersion": "1.28.3-r1", + "FixedVersion": "1.28.3-r2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-9256", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:b58ba119794ad177b9d4f3dc55b60ca326d73b9fd8336dc260c84c9c4fd3029e", + "Title": "nginx: ngx_http_rewrite_module: code execution and denial of service", + "Description": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-122" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 4, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 9.2 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/05/22/14", + "https://access.redhat.com/errata/RHSA-2026:20351", + "https://access.redhat.com/errata/RHSA-2026:28212", + "https://access.redhat.com/errata/RHSA-2026:28921", + "https://access.redhat.com/errata/RHSA-2026:28973", + "https://access.redhat.com/errata/RHSA-2026:29151", + "https://access.redhat.com/errata/RHSA-2026:29874", + "https://access.redhat.com/errata/RHSA-2026:33313", + "https://access.redhat.com/errata/RHSA-2026:44481", + "https://access.redhat.com/errata/RHSA-2026:58981", + "https://access.redhat.com/security/cve/CVE-2026-9256", + "https://bugzilla.redhat.com/2480746", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480746", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9256", + "https://errata.almalinux.org/8/ALSA-2026-28921.html", + "https://errata.rockylinux.org/RLSA-2026:29151", + "https://linux.oracle.com/cve/CVE-2026-9256.html", + "https://linux.oracle.com/errata/ELSA-2026-29874.html", + "https://lists.debian.org/debian-lts-announce/2026/06/msg00023.html", + "https://my.f5.com/manage/s/article/K000161377", + "https://nvd.nist.gov/vuln/detail/CVE-2026-9256", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9256.json", + "https://ubuntu.com/security/notices/USN-8354-1", + "https://ubuntu.com/security/notices/USN-8375-1", + "https://www.cve.org/CVERecord?id=CVE-2026-9256" + ], + "PublishedDate": "2026-05-22T15:16:27.073Z", + "LastModifiedDate": "2026-08-25T13:19:33.4Z" + }, + { + "VulnerabilityID": "CVE-2026-22184", + "PkgID": "zlib@1.3.1-r2", + "PkgName": "zlib", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/zlib@1.3.1-r2?arch=x86_64\u0026distro=3.23.3", + "UID": "792cdc69bc59d880" + }, + "InstalledVersion": "1.3.1-r2", + "FixedVersion": "1.3.2-r0", + "Status": "fixed", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "SeveritySource": "nvd", + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-22184", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:635e1ed2b82ba940b100fd7b9963aa7ba3db5ba6bfedce83256ddf5097a66e62", + "Title": "zlib: zlib: Arbitrary code execution via buffer overflow in untgz utility", + "Description": "zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-787", + "CWE-120" + ], + "VendorSeverity": { + "nvd": 3, + "redhat": 3 + }, + "CVSS": { + "nvd": { + "V3Vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 7.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", + "V3Score": 8.6 + } + }, + "References": [ + "https://access.redhat.com/security/cve/CVE-2026-22184", + "https://bugzilla.redhat.com/show_bug.cgi?id=2427688", + "https://cert-portal.siemens.com/productcert/html/ssa-470355.html", + "https://github.com/madler/zlib", + "https://github.com/madler/zlib/issues/1142", + "https://nvd.nist.gov/vuln/detail/CVE-2026-22184", + "https://seclists.org/fulldisclosure/2026/Jan/3", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22184.json", + "https://www.cve.org/CVERecord?id=CVE-2026-22184", + "https://www.vulncheck.com/advisories/zlib-untgz-global-buffer-overflow-in-tgzfname", + "https://zlib.net/" + ], + "PublishedDate": "2026-01-07T21:16:01.563Z", + "LastModifiedDate": "2026-09-01T13:18:19.867Z" + } + ] + } + ] +} diff --git a/output/security/python-audit.json b/output/security/python-audit.json new file mode 100644 index 0000000..ae42de8 --- /dev/null +++ b/output/security/python-audit.json @@ -0,0 +1 @@ +{"dependencies": [{"name": "annotated-doc", "version": "0.0.5", "vulns": []}, {"name": "annotated-types", "version": "0.8.0", "vulns": []}, {"name": "anyio", "version": "4.15.1", "vulns": []}, {"name": "boto3", "version": "1.38.23", "vulns": []}, {"name": "botocore", "version": "1.38.46", "vulns": []}, {"name": "certifi", "version": "2026.7.22", "vulns": []}, {"name": "click", "version": "8.5.0", "vulns": []}, {"name": "fastapi", "version": "0.141.1", "vulns": []}, {"name": "h11", "version": "0.16.0", "vulns": []}, {"name": "httpcore", "version": "1.0.9", "vulns": []}, {"name": "httpx", "version": "0.28.1", "vulns": []}, {"name": "idna", "version": "3.19", "vulns": []}, {"name": "jmespath", "version": "1.1.0", "vulns": []}, {"name": "pip", "version": "26.2.1", "vulns": []}, {"name": "psycopg", "version": "3.2.9", "vulns": []}, {"name": "psycopg-binary", "version": "3.2.9", "vulns": []}, {"name": "pydantic", "version": "2.13.5", "vulns": []}, {"name": "pydantic-core", "version": "2.46.5", "vulns": []}, {"name": "python-dateutil", "version": "2.9.0.post0", "vulns": []}, {"name": "s3transfer", "version": "0.13.1", "vulns": []}, {"name": "six", "version": "1.17.0", "vulns": []}, {"name": "starlette", "version": "1.6.0", "vulns": []}, {"name": "typing-extensions", "version": "4.16.0", "vulns": []}, {"name": "typing-inspection", "version": "0.4.4", "vulns": []}, {"name": "urllib3", "version": "2.7.0", "vulns": []}, {"name": "uvicorn", "version": "0.34.2", "vulns": []}], "fixes": []} diff --git a/output/security/runtime-requirements.txt b/output/security/runtime-requirements.txt new file mode 100644 index 0000000..65b1f1b --- /dev/null +++ b/output/security/runtime-requirements.txt @@ -0,0 +1,26 @@ +annotated-doc==0.0.5 +annotated-types==0.8.0 +anyio==4.15.1 +boto3==1.38.23 +botocore==1.38.46 +certifi==2026.7.22 +click==8.5.0 +fastapi==0.141.1 +h11==0.16.0 +httpcore==1.0.9 +httpx==0.28.1 +idna==3.19 +jmespath==1.1.0 +pip==26.2.1 +psycopg==3.2.9 +psycopg-binary==3.2.9 +pydantic==2.13.5 +pydantic_core==2.46.5 +python-dateutil==2.9.0.post0 +s3transfer==0.13.1 +six==1.17.0 +starlette==1.6.0 +typing_extensions==4.16.0 +typing-inspection==0.4.4 +urllib3==2.7.0 +uvicorn==0.34.2 diff --git a/output/security/scanner-container-audit.json b/output/security/scanner-container-audit.json new file mode 100644 index 0000000..2aa3361 --- /dev/null +++ b/output/security/scanner-container-audit.json @@ -0,0 +1,2138 @@ +{ + "SchemaVersion": 2, + "Trivy": { + "Version": "0.74.0" + }, + "ReportID": "01a0a01c-db82-797c-b48f-adfe11589fc8", + "CreatedAt": "2026-09-14T13:30:40.898624828Z", + "ArtifactID": "sha256:3b2edb9ee83cdf23badea847504678ebd7c561a36988bc03e827c072aadac949", + "ArtifactName": "clamav/clamav@sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4", + "ArtifactType": "container_image", + "Metadata": { + "Size": 240750080, + "OS": { + "Family": "alpine", + "Name": "3.24.1" + }, + "ImageID": "sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4", + "DiffIDs": [ + "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c", + "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7", + "sha256:4459f6dc24d6db4632f7ee5bfb9c3473ed7e5b630ab302fbe66f69a30244f47a", + "sha256:fc0892d9da47f70fccf9016b25373f9a7e78dbcddc1851d2ed304026841b7a3c", + "sha256:7ac13e439a31bc6b63533c83c17ab406fd31b429fd368c5abf14a01ad4e9282b", + "sha256:7559486ef7d48013a5c4b036be2266ab1e0b677544d28ce934a61ebbe415d876", + "sha256:10b9fff222976a828dd747c1f343c6bc05dc3badc792b4613cf47a1705acef57" + ], + "RepoTags": [ + "clamav/clamav:stable" + ], + "RepoDigests": [ + "clamav/clamav@sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4" + ], + "Reference": "clamav/clamav@sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4", + "ImageConfig": { + "architecture": "amd64", + "created": "2026-09-14T01:48:30.838455143Z", + "history": [ + { + "created": "2026-06-16T00:01:29Z", + "created_by": "ADD alpine-minirootfs-3.24.1-x86_64.tar.gz / # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-06-16T00:01:29Z", + "created_by": "CMD [\"/bin/sh\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-14T01:40:57Z", + "created_by": "LABEL maintainer=ClamAV bugs \u003cclamav-bugs@external.cisco.com\u003e", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-14T01:40:57Z", + "created_by": "EXPOSE \u0026{[{{91 0} {91 0}}] 0xc0229e6a80}", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-14T01:40:57Z", + "created_by": "EXPOSE \u0026{[{{92 0} {92 0}}] 0xc0229e6a80}", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-14T01:40:57Z", + "created_by": "ENV TZ=Etc/UTC", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-14T01:40:57Z", + "created_by": "RUN /bin/sh -c apk update \u0026\u0026 apk upgrade \u0026\u0026 apk add fts libstdc++ tini tzdata json-c libbz2 libcurl libmilter libxml2 ncurses-libs pcre2 zlib \u0026\u0026 rm -rf /var/cache/apk/* \u0026\u0026 addgroup -S \"clamav\" \u0026\u0026 adduser -D -G \"clamav\" -h \"/var/lib/clamav\" -s \"/bin/false\" -u 100 -S \"clamav\" \u0026\u0026 install -d -m 755 -g \"clamav\" -o \"clamav\" \"/var/log/clamav\" \u0026\u0026 chown -R clamav:clamav /var/lib/clamav # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-14T01:47:25Z", + "created_by": "COPY /clamav / # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-14T01:47:25Z", + "created_by": "COPY ./scripts/clamdcheck.sh /usr/local/bin/ # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-14T01:47:26Z", + "created_by": "COPY ./scripts/docker-entrypoint.sh /init # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-14T01:47:26Z", + "created_by": "COPY ./scripts/docker-entrypoint-unprivileged.sh /init-unprivileged # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-14T01:47:26Z", + "created_by": "HEALTHCHECK \u0026{[\"CMD-SHELL\" \"clamdcheck.sh\"] \"0s\" \"0s\" \"6m0s\" \"0s\" '\\x00'}", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-14T01:47:26Z", + "created_by": "ENTRYPOINT [\"/init\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-09-14T01:48:30Z", + "created_by": "RUN /bin/sh -c freshclam --foreground --stdout || true \u0026\u0026 rm -f /var/lib/clamav/freshclam.dat /var/lib/clamav/mirrors.dat || true # buildkit", + "comment": "buildkit.dockerfile.v0" + } + ], + "os": "linux", + "rootfs": { + "type": "layers", + "diff_ids": [ + "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c", + "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7", + "sha256:4459f6dc24d6db4632f7ee5bfb9c3473ed7e5b630ab302fbe66f69a30244f47a", + "sha256:fc0892d9da47f70fccf9016b25373f9a7e78dbcddc1851d2ed304026841b7a3c", + "sha256:7ac13e439a31bc6b63533c83c17ab406fd31b429fd368c5abf14a01ad4e9282b", + "sha256:7559486ef7d48013a5c4b036be2266ab1e0b677544d28ce934a61ebbe415d876", + "sha256:10b9fff222976a828dd747c1f343c6bc05dc3badc792b4613cf47a1705acef57" + ] + }, + "config": { + "Healthcheck": { + "Test": [ + "CMD-SHELL", + "clamdcheck.sh" + ], + "StartPeriod": 360000000000 + }, + "Entrypoint": [ + "/init" + ], + "Env": [ + "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", + "TZ=Etc/UTC" + ], + "Labels": { + "maintainer": "ClamAV bugs \u003cclamav-bugs@external.cisco.com\u003e" + }, + "WorkingDir": "/", + "ExposedPorts": { + "3310/tcp": {}, + "7357/tcp": {} + } + } + }, + "Layers": [ + { + "Size": 8697856, + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + { + "Size": 18357760, + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + { + "Size": 100858368, + "Digest": "sha256:3d0cb1b31a2d663b00745f42c6d9444d16fdff9dda9ddd97c1b7bbb9ca586c94", + "DiffID": "sha256:4459f6dc24d6db4632f7ee5bfb9c3473ed7e5b630ab302fbe66f69a30244f47a" + }, + { + "Size": 3584, + "Digest": "sha256:993330f20f6a4f6a7cd6fab94844001afb7598b694a8b255589ac717075ee055", + "DiffID": "sha256:fc0892d9da47f70fccf9016b25373f9a7e78dbcddc1851d2ed304026841b7a3c" + }, + { + "Size": 5120, + "Digest": "sha256:43b170505880698a6bfd85a9e95e9864a55bf6d319b7c43af1e090b76a3db634", + "DiffID": "sha256:7ac13e439a31bc6b63533c83c17ab406fd31b429fd368c5abf14a01ad4e9282b" + }, + { + "Size": 4096, + "Digest": "sha256:2a6e58dbc09eaa3fbebdbf09898eaeb0b0bb903cd4f469f54922bb3d409d17d2", + "DiffID": "sha256:7559486ef7d48013a5c4b036be2266ab1e0b677544d28ce934a61ebbe415d876" + }, + { + "Size": 112823296, + "Digest": "sha256:07e8de1a91e9973fd32055f3933d215d85c511abf582b44aaa471d42f92cd7fe", + "DiffID": "sha256:10b9fff222976a828dd747c1f343c6bc05dc3badc792b4613cf47a1705acef57" + } + ] + }, + "Results": [ + { + "Target": "clamav/clamav@sha256:9cb27d7660bdf66e9878c832cb433dd8aa152cfbe16f3c2c0084c80b04ae22b4 (alpine 3.24.1)", + "Class": "os-pkgs", + "Type": "alpine", + "Packages": [ + { + "ID": "alpine-baselayout@3.7.2-r1", + "Name": "alpine-baselayout", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-baselayout@3.7.2-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "1b9c543300f8073e" + }, + "Version": "3.7.2-r1", + "Arch": "x86_64", + "SrcName": "alpine-baselayout", + "SrcVersion": "3.7.2-r1", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "alpine-baselayout-data@3.7.2-r1", + "busybox-binsh@1.37.0-r31" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:f0fcfdc2f4da058af6473bc45c4eab62916225b2", + "InstalledFiles": [ + "etc/motd", + "etc/crontabs/root", + "etc/modprobe.d/aliases.conf", + "etc/modprobe.d/blacklist.conf", + "etc/modprobe.d/i386.conf", + "etc/profile.d/20locale.sh", + "etc/profile.d/README", + "etc/profile.d/color_prompt.sh.disabled", + "usr/lib/sysctl.d/00-alpine.conf", + "var/lock", + "var/run", + "var/spool/mail", + "var/spool/cron/crontabs" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-baselayout-data@3.7.2-r1", + "Name": "alpine-baselayout-data", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-baselayout-data@3.7.2-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "fcc3cd90122d8aa7" + }, + "Version": "3.7.2-r1", + "Arch": "x86_64", + "SrcName": "alpine-baselayout", + "SrcVersion": "3.7.2-r1", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:c6f9bded17d844b6f1b0bb5766d2c35c0d5c8508", + "InstalledFiles": [ + "etc/fstab", + "etc/group", + "etc/hostname", + "etc/hosts", + "etc/inittab", + "etc/modules", + "etc/mtab", + "etc/nsswitch.conf", + "etc/passwd", + "etc/profile", + "etc/protocols", + "etc/services", + "etc/shadow", + "etc/shells", + "etc/sysctl.conf" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-keys@2.6-r0", + "Name": "alpine-keys", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-keys@2.6-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "cb1f6c8fa74713e0" + }, + "Version": "2.6-r0", + "Arch": "x86_64", + "SrcName": "alpine-keys", + "SrcVersion": "2.6-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:d8d6b80e53c059a77e4915da78ba964f3ffea240", + "InstalledFiles": [ + "etc/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "etc/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", + "etc/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub", + "usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub", + "usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub", + "usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", + "usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub", + "usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", + "usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub", + "usr/share/apk/keys/loongarch64/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub", + "usr/share/apk/keys/mips64/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub", + "usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub", + "usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub", + "usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub", + "usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub", + "usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub", + "usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub", + "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub", + "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub", + "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", + "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-release@3.24.1-r0", + "Name": "alpine-release", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-release@3.24.1-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "6cfad6f36e1f31aa" + }, + "Version": "3.24.1-r0", + "Arch": "x86_64", + "SrcName": "alpine-base", + "SrcVersion": "3.24.1-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "alpine-keys@2.6-r0" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:bc6912a25cdc7733e0035ed509eceaa4026946e3", + "InstalledFiles": [ + "etc/alpine-release", + "etc/issue", + "etc/os-release", + "etc/secfixes.d/alpine", + "usr/lib/os-release" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "apk-tools@3.0.8-r0", + "Name": "apk-tools", + "Identifier": { + "PURL": "pkg:apk/alpine/apk-tools@3.0.8-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "5c76cd931e2a8e18" + }, + "Version": "3.0.8-r0", + "Arch": "x86_64", + "SrcName": "apk-tools", + "SrcVersion": "3.0.8-r0", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "ca-certificates-bundle@20260611-r0", + "libapk@3.0.8-r0", + "libcrypto3@3.5.8-r0", + "musl@1.2.6-r2", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:786130a8f2d3ac69fc316118757b7e8151b8b8c3", + "InstalledFiles": [ + "sbin/apk" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "brotli-libs@1.2.0-r1", + "Name": "brotli-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/brotli-libs@1.2.0-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "34680ab8e4de744b" + }, + "Version": "1.2.0-r1", + "Arch": "x86_64", + "SrcName": "brotli", + "SrcVersion": "1.2.0-r1", + "Licenses": [ + "MIT" + ], + "Maintainer": "prspkt \u003cprspkt@protonmail.com\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:82f881516c045f06f22d7dc0a83cc64ca554ef10", + "InstalledFiles": [ + "usr/lib/libbrotlicommon.so.1", + "usr/lib/libbrotlicommon.so.1.2.0", + "usr/lib/libbrotlidec.so.1", + "usr/lib/libbrotlidec.so.1.2.0", + "usr/lib/libbrotlienc.so.1", + "usr/lib/libbrotlienc.so.1.2.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "busybox@1.37.0-r31", + "Name": "busybox", + "Identifier": { + "PURL": "pkg:apk/alpine/busybox@1.37.0-r31?arch=x86_64\u0026distro=3.24.1", + "UID": "771020c43c8440bf" + }, + "Version": "1.37.0-r31", + "Arch": "x86_64", + "SrcName": "busybox", + "SrcVersion": "1.37.0-r31", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:b5405ebc02f7dd8be95b6265c54b243d5456ab8f", + "InstalledFiles": [ + "bin/busybox", + "etc/securetty", + "etc/busybox-paths.d/busybox", + "etc/logrotate.d/acpid", + "etc/network/if-up.d/dad", + "etc/udhcpc/udhcpc.conf", + "usr/share/udhcpc/default.script" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "busybox-binsh@1.37.0-r31", + "Name": "busybox-binsh", + "Identifier": { + "PURL": "pkg:apk/alpine/busybox-binsh@1.37.0-r31?arch=x86_64\u0026distro=3.24.1", + "UID": "1ec8a3d5d2b63297" + }, + "Version": "1.37.0-r31", + "Arch": "x86_64", + "SrcName": "busybox", + "SrcVersion": "1.37.0-r31", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", + "DependsOn": [ + "busybox@1.37.0-r31" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:5cbd14acc6f1804c5bac6c77dc2c492f010b0fc7", + "InstalledFiles": [ + "bin/sh" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "c-ares@1.34.8-r0", + "Name": "c-ares", + "Identifier": { + "PURL": "pkg:apk/alpine/c-ares@1.34.8-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "4f18515d5a0852d6" + }, + "Version": "1.34.8-r0", + "Arch": "x86_64", + "SrcName": "c-ares", + "SrcVersion": "1.34.8-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:640a28ff6245f701d464fba53a05b1bc657c37a7", + "InstalledFiles": [ + "usr/lib/libcares.so.2", + "usr/lib/libcares.so.2.19.7" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ca-certificates-bundle@20260611-r0", + "Name": "ca-certificates-bundle", + "Identifier": { + "PURL": "pkg:apk/alpine/ca-certificates-bundle@20260611-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "20337c2ea28bef28" + }, + "Version": "20260611-r0", + "Arch": "x86_64", + "SrcName": "ca-certificates", + "SrcVersion": "20260611-r0", + "Licenses": [ + "MPL-2.0", + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:c9534a03750bdfae341f10969016090fc11febbd", + "InstalledFiles": [ + "etc/ssl/cert.pem", + "etc/ssl/certs/ca-certificates.crt", + "etc/ssl1.1/cert.pem", + "etc/ssl1.1/certs" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "json-c@0.18-r1", + "Name": "json-c", + "Identifier": { + "PURL": "pkg:apk/alpine/json-c@0.18-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "c514b819a5d1f182" + }, + "Version": "0.18-r1", + "Arch": "x86_64", + "SrcName": "json-c", + "SrcVersion": "0.18-r1", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:db0d2649faf8a52414df8a9d6e4acdb60303b403", + "InstalledFiles": [ + "usr/lib/libjson-c.so.5", + "usr/lib/libjson-c.so.5.4.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libapk@3.0.8-r0", + "Name": "libapk", + "Identifier": { + "PURL": "pkg:apk/alpine/libapk@3.0.8-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "3bc45fb01b4ba719" + }, + "Version": "3.0.8-r0", + "Arch": "x86_64", + "SrcName": "apk-tools", + "SrcVersion": "3.0.8-r0", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libcrypto3@3.5.8-r0", + "libssl3@3.5.8-r0", + "musl@1.2.6-r2", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:b93ce9573c1d0db3eea7ce32841ad0857abc4a54", + "InstalledFiles": [ + "usr/lib/libapk.so.3.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libbz2@1.0.8-r6", + "Name": "libbz2", + "Identifier": { + "PURL": "pkg:apk/alpine/libbz2@1.0.8-r6?arch=x86_64\u0026distro=3.24.1", + "UID": "48e17539404e2d56" + }, + "Version": "1.0.8-r6", + "Arch": "x86_64", + "SrcName": "bzip2", + "SrcVersion": "1.0.8-r6", + "Licenses": [ + "bzip-2-1.0.6" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:08566ba5c7af97c25474be8b24e8b48f0116b67d", + "InstalledFiles": [ + "usr/lib/libbz2.so.1", + "usr/lib/libbz2.so.1.0.8" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libcrypto3@3.5.8-r0", + "Name": "libcrypto3", + "Identifier": { + "PURL": "pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "4299bba2ba9c96aa" + }, + "Version": "3.5.8-r0", + "Arch": "x86_64", + "SrcName": "openssl", + "SrcVersion": "3.5.8-r0", + "Licenses": [ + "Apache-2.0" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:1b3b9fc0c136f4936932bcb2ec21499f0ae5dfd3", + "InstalledFiles": [ + "etc/ssl/ct_log_list.cnf", + "etc/ssl/ct_log_list.cnf.dist", + "etc/ssl/openssl.cnf", + "etc/ssl/openssl.cnf.dist", + "usr/lib/libcrypto.so.3", + "usr/lib/engines-3/afalg.so", + "usr/lib/engines-3/capi.so", + "usr/lib/engines-3/loader_attic.so", + "usr/lib/engines-3/padlock.so", + "usr/lib/ossl-modules/legacy.so" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libcurl@8.22.0-r0", + "Name": "libcurl", + "Identifier": { + "PURL": "pkg:apk/alpine/libcurl@8.22.0-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "736e3492c660e462" + }, + "Version": "8.22.0-r0", + "Arch": "x86_64", + "SrcName": "curl", + "SrcVersion": "8.22.0-r0", + "Licenses": [ + "curl" + ], + "Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e", + "DependsOn": [ + "brotli-libs@1.2.0-r1", + "c-ares@1.34.8-r0", + "ca-certificates-bundle@20260611-r0", + "libcrypto3@3.5.8-r0", + "libidn2@2.3.8-r0", + "libpsl@0.21.5-r3", + "libssl3@3.5.8-r0", + "musl@1.2.6-r2", + "nghttp2-libs@1.69.0-r0", + "zlib@1.3.2-r0", + "zstd-libs@1.5.7-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:7816006b6af2270ab6e7e85f74adb94c16bdc48b", + "InstalledFiles": [ + "usr/lib/libcurl.so.4", + "usr/lib/libcurl.so.4.8.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libformw@6.6_p20260516-r0", + "Name": "libformw", + "Identifier": { + "PURL": "pkg:apk/alpine/libformw@6.6_p20260516-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "44b586b24722492d" + }, + "Version": "6.6_p20260516-r0", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.6_p20260516-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Milan P. Stanić \u003cmps@arvanta.net\u003e", + "DependsOn": [ + "libncursesw@6.6_p20260516-r0", + "musl@1.2.6-r2", + "ncurses-terminfo-base@6.6_p20260516-r0" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:534e218e2d7a16d5dbeeb54b703a63379b2beeb3", + "InstalledFiles": [ + "usr/lib/libformw.so.6", + "usr/lib/libformw.so.6.6" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libgcc@15.2.0-r5", + "Name": "libgcc", + "Identifier": { + "PURL": "pkg:apk/alpine/libgcc@15.2.0-r5?arch=x86_64\u0026distro=3.24.1", + "UID": "8cf3d813d20beeee" + }, + "Version": "15.2.0-r5", + "Arch": "x86_64", + "SrcName": "gcc", + "SrcVersion": "15.2.0-r5", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-2.1-or-later" + ], + "Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:379c156c53e0cc140e87c79c0a3dd22b6ee51552", + "InstalledFiles": [ + "usr/lib/libgcc_s.so.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libidn2@2.3.8-r0", + "Name": "libidn2", + "Identifier": { + "PURL": "pkg:apk/alpine/libidn2@2.3.8-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "bff421f953b410b7" + }, + "Version": "2.3.8-r0", + "Arch": "x86_64", + "SrcName": "libidn2", + "SrcVersion": "2.3.8-r0", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-3.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libunistring@1.4.2-r0", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:5800d14ce89e16148f4ccc2df74235ce7aedf800", + "InstalledFiles": [ + "usr/lib/libidn2.so.0", + "usr/lib/libidn2.so.0.4.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libmenuw@6.6_p20260516-r0", + "Name": "libmenuw", + "Identifier": { + "PURL": "pkg:apk/alpine/libmenuw@6.6_p20260516-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "ca08b39b5412771b" + }, + "Version": "6.6_p20260516-r0", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.6_p20260516-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Milan P. Stanić \u003cmps@arvanta.net\u003e", + "DependsOn": [ + "libncursesw@6.6_p20260516-r0", + "musl@1.2.6-r2", + "ncurses-terminfo-base@6.6_p20260516-r0" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:36e0fa0c969c285aa424919d2729343baa3a38a2", + "InstalledFiles": [ + "usr/lib/libmenuw.so.6", + "usr/lib/libmenuw.so.6.6" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libmilter@1.0.2-r11", + "Name": "libmilter", + "Identifier": { + "PURL": "pkg:apk/alpine/libmilter@1.0.2-r11?arch=x86_64\u0026distro=3.24.1", + "UID": "6e5a005b59d39a14" + }, + "Version": "1.0.2-r11", + "Arch": "x86_64", + "SrcName": "libmilter", + "SrcVersion": "1.0.2-r11", + "Licenses": [ + "Sendmail" + ], + "Maintainer": "Valery Kartel \u003cvalery.kartel@gmail.com\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:f2903cf1d030f960c35bbbbd73dc5abf1b2025b8", + "InstalledFiles": [ + "usr/lib/libmilter.so.1.0.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libncursesw@6.6_p20260516-r0", + "Name": "libncursesw", + "Identifier": { + "PURL": "pkg:apk/alpine/libncursesw@6.6_p20260516-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "e8939f45e2191bcc" + }, + "Version": "6.6_p20260516-r0", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.6_p20260516-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Milan P. Stanić \u003cmps@arvanta.net\u003e", + "DependsOn": [ + "musl@1.2.6-r2", + "ncurses-terminfo-base@6.6_p20260516-r0" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:9f318e6e324d6827274829194cf6ac6afbaded12", + "InstalledFiles": [ + "usr/lib/libncursesw.so.6", + "usr/lib/libncursesw.so.6.6" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libpanelw@6.6_p20260516-r0", + "Name": "libpanelw", + "Identifier": { + "PURL": "pkg:apk/alpine/libpanelw@6.6_p20260516-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "ef1ad9bb256b373" + }, + "Version": "6.6_p20260516-r0", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.6_p20260516-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Milan P. Stanić \u003cmps@arvanta.net\u003e", + "DependsOn": [ + "libncursesw@6.6_p20260516-r0", + "musl@1.2.6-r2", + "ncurses-terminfo-base@6.6_p20260516-r0" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:149bdc434232ed11fc5bb975ba519a07154a6f56", + "InstalledFiles": [ + "usr/lib/libpanelw.so.6", + "usr/lib/libpanelw.so.6.6" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libpsl@0.21.5-r3", + "Name": "libpsl", + "Identifier": { + "PURL": "pkg:apk/alpine/libpsl@0.21.5-r3?arch=x86_64\u0026distro=3.24.1", + "UID": "7879224d01df05c2" + }, + "Version": "0.21.5-r3", + "Arch": "x86_64", + "SrcName": "libpsl", + "SrcVersion": "0.21.5-r3", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libidn2@2.3.8-r0", + "libunistring@1.4.2-r0", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:a551ddd5d6cb3913e1a1f47b02f21ae068b5e90a", + "InstalledFiles": [ + "usr/lib/libpsl.so.5", + "usr/lib/libpsl.so.5.3.5" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libssl3@3.5.8-r0", + "Name": "libssl3", + "Identifier": { + "PURL": "pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "f290ab59b88b1c4a" + }, + "Version": "3.5.8-r0", + "Arch": "x86_64", + "SrcName": "openssl", + "SrcVersion": "3.5.8-r0", + "Licenses": [ + "Apache-2.0" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libcrypto3@3.5.8-r0", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:5f9b1e55d821953d2e2b1db322dad70a3b5041ea", + "InstalledFiles": [ + "usr/lib/libssl.so.3" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libstdc++@15.2.0-r5", + "Name": "libstdc++", + "Identifier": { + "PURL": "pkg:apk/alpine/libstdc%2B%2B@15.2.0-r5?arch=x86_64\u0026distro=3.24.1", + "UID": "2eed307edf277aae" + }, + "Version": "15.2.0-r5", + "Arch": "x86_64", + "SrcName": "gcc", + "SrcVersion": "15.2.0-r5", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-2.1-or-later" + ], + "Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e", + "DependsOn": [ + "libgcc@15.2.0-r5", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:5f7a2ad7646128ba02cc0d6fb94672b6845648d5", + "InstalledFiles": [ + "usr/lib/libstdc++.so.6", + "usr/lib/libstdc++.so.6.0.34" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libunistring@1.4.2-r0", + "Name": "libunistring", + "Identifier": { + "PURL": "pkg:apk/alpine/libunistring@1.4.2-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "b5ad22f7f34d881f" + }, + "Version": "1.4.2-r0", + "Arch": "x86_64", + "SrcName": "libunistring", + "SrcVersion": "1.4.2-r0", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-3.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:f509c801d070f8ea9f7400d5093c888ff1fee02e", + "InstalledFiles": [ + "usr/lib/libunistring.so.5", + "usr/lib/libunistring.so.5.2.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxml2@2.13.9-r2", + "Name": "libxml2", + "Identifier": { + "PURL": "pkg:apk/alpine/libxml2@2.13.9-r2?arch=x86_64\u0026distro=3.24.1", + "UID": "e7d78ec6037db97c" + }, + "Version": "2.13.9-r2", + "Arch": "x86_64", + "SrcName": "libxml2", + "SrcVersion": "2.13.9-r2", + "Licenses": [ + "MIT" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2", + "xz-libs@5.8.4-r0", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:c2c2cb44647ddc8c82ae78c8aca9bd4ad5a736da", + "InstalledFiles": [ + "usr/lib/libxml2.so.2", + "usr/lib/libxml2.so.2.13.9" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "musl@1.2.6-r2", + "Name": "musl", + "Identifier": { + "PURL": "pkg:apk/alpine/musl@1.2.6-r2?arch=x86_64\u0026distro=3.24.1", + "UID": "1f8cb44befe503d4" + }, + "Version": "1.2.6-r2", + "Arch": "x86_64", + "SrcName": "musl", + "SrcVersion": "1.2.6-r2", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:0f7e5827e4e1a73631beda27b78431a8ba240e05", + "InstalledFiles": [ + "lib/ld-musl-x86_64.so.1", + "lib/libc.musl-x86_64.so.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "musl-fts@1.2.7-r7", + "Name": "musl-fts", + "Identifier": { + "PURL": "pkg:apk/alpine/musl-fts@1.2.7-r7?arch=x86_64\u0026distro=3.24.1", + "UID": "1b173f6db36c8c93" + }, + "Version": "1.2.7-r7", + "Arch": "x86_64", + "SrcName": "musl-fts", + "SrcVersion": "1.2.7-r7", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:b85f004a36494b7ac166853be30926234514e5ad", + "InstalledFiles": [ + "usr/lib/libfts.so.0", + "usr/lib/libfts.so.0.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "musl-utils@1.2.6-r2", + "Name": "musl-utils", + "Identifier": { + "PURL": "pkg:apk/alpine/musl-utils@1.2.6-r2?arch=x86_64\u0026distro=3.24.1", + "UID": "4497482ec1d943e1" + }, + "Version": "1.2.6-r2", + "Arch": "x86_64", + "SrcName": "musl", + "SrcVersion": "1.2.6-r2", + "Licenses": [ + "MIT", + "BSD-2-Clause", + "GPL-2.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2", + "scanelf@1.3.9-r1" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:75ada3c48d63ec5d87c42fdf934a3fdd11298dc5", + "InstalledFiles": [ + "sbin/ldconfig", + "usr/bin/getconf", + "usr/bin/getent", + "usr/bin/iconv", + "usr/bin/ldd" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ncurses-libs@6.6_p20260516-r0", + "Name": "ncurses-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/ncurses-libs@6.6_p20260516-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "ba25901f3fc6be90" + }, + "Version": "6.6_p20260516-r0", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.6_p20260516-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Milan P. Stanić \u003cmps@arvanta.net\u003e", + "DependsOn": [ + "libformw@6.6_p20260516-r0", + "libmenuw@6.6_p20260516-r0", + "libncursesw@6.6_p20260516-r0", + "libpanelw@6.6_p20260516-r0" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:2b3e4642e8f1b6d1f1b6bd071a1c4657d55b74ba", + "AnalyzedBy": "apk" + }, + { + "ID": "ncurses-terminfo-base@6.6_p20260516-r0", + "Name": "ncurses-terminfo-base", + "Identifier": { + "PURL": "pkg:apk/alpine/ncurses-terminfo-base@6.6_p20260516-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "e7fac5c6a6e9ae8" + }, + "Version": "6.6_p20260516-r0", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.6_p20260516-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Milan P. Stanić \u003cmps@arvanta.net\u003e", + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:9d551d828e9c8ee52c5801c1d6046828ebf15752", + "InstalledFiles": [ + "etc/terminfo/a/alacritty", + "etc/terminfo/a/ansi", + "etc/terminfo/d/dumb", + "etc/terminfo/g/gnome", + "etc/terminfo/g/gnome-256color", + "etc/terminfo/k/konsole", + "etc/terminfo/k/konsole-256color", + "etc/terminfo/k/konsole-linux", + "etc/terminfo/l/linux", + "etc/terminfo/p/putty", + "etc/terminfo/p/putty-256color", + "etc/terminfo/r/rxvt", + "etc/terminfo/r/rxvt-256color", + "etc/terminfo/s/screen", + "etc/terminfo/s/screen-256color", + "etc/terminfo/s/st-0.6", + "etc/terminfo/s/st-0.7", + "etc/terminfo/s/st-0.8", + "etc/terminfo/s/st-0.8.5", + "etc/terminfo/s/st-16color", + "etc/terminfo/s/st-256color", + "etc/terminfo/s/st-direct", + "etc/terminfo/s/sun", + "etc/terminfo/t/terminator", + "etc/terminfo/t/terminology", + "etc/terminfo/t/terminology-0.6.1", + "etc/terminfo/t/terminology-1.0.0", + "etc/terminfo/t/terminology-1.8.1", + "etc/terminfo/t/tmux", + "etc/terminfo/t/tmux-256color", + "etc/terminfo/v/vt100", + "etc/terminfo/v/vt102", + "etc/terminfo/v/vt200", + "etc/terminfo/v/vt220", + "etc/terminfo/v/vt52", + "etc/terminfo/v/vte", + "etc/terminfo/v/vte-256color", + "etc/terminfo/x/xterm", + "etc/terminfo/x/xterm-256color", + "etc/terminfo/x/xterm-color", + "etc/terminfo/x/xterm-xfree86" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nghttp2-libs@1.69.0-r0", + "Name": "nghttp2-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/nghttp2-libs@1.69.0-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "cdceee5bd778a45c" + }, + "Version": "1.69.0-r0", + "Arch": "x86_64", + "SrcName": "nghttp2", + "SrcVersion": "1.69.0-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:5331b8c641f7a9091ce2f43dad2a99851c4f4b12", + "InstalledFiles": [ + "usr/lib/libnghttp2.so.14", + "usr/lib/libnghttp2.so.14.29.4" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "pcre2@10.48-r0", + "Name": "pcre2", + "Identifier": { + "PURL": "pkg:apk/alpine/pcre2@10.48-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "253522084e232a57" + }, + "Version": "10.48-r0", + "Arch": "x86_64", + "SrcName": "pcre2", + "SrcVersion": "10.48-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Jakub Jirutka \u003cjakub@jirutka.cz\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:47c5cee73bff18ce31bb501043c628f04d2af94a", + "InstalledFiles": [ + "usr/lib/libpcre2-8.so.0", + "usr/lib/libpcre2-8.so.0.16.0", + "usr/lib/libpcre2-posix.so.3", + "usr/lib/libpcre2-posix.so.3.0.8" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "scanelf@1.3.9-r1", + "Name": "scanelf", + "Identifier": { + "PURL": "pkg:apk/alpine/scanelf@1.3.9-r1?arch=x86_64\u0026distro=3.24.1", + "UID": "936394657a1626fb" + }, + "Version": "1.3.9-r1", + "Arch": "x86_64", + "SrcName": "pax-utils", + "SrcVersion": "1.3.9-r1", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:013f903d0ba219673aebbdd04f74bb5ed82b01f0", + "InstalledFiles": [ + "usr/bin/scanelf" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ssl_client@1.37.0-r31", + "Name": "ssl_client", + "Identifier": { + "PURL": "pkg:apk/alpine/ssl_client@1.37.0-r31?arch=x86_64\u0026distro=3.24.1", + "UID": "d42e31f15a4ce47a" + }, + "Version": "1.37.0-r31", + "Arch": "x86_64", + "SrcName": "busybox", + "SrcVersion": "1.37.0-r31", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", + "DependsOn": [ + "libcrypto3@3.5.8-r0", + "libssl3@3.5.8-r0", + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:c220f4a5125a313af733e98def94132bb1e9d40d", + "InstalledFiles": [ + "usr/bin/ssl_client" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "tini@0.19.0-r3", + "Name": "tini", + "Identifier": { + "PURL": "pkg:apk/alpine/tini@0.19.0-r3?arch=x86_64\u0026distro=3.24.1", + "UID": "2849609c2deb58d" + }, + "Version": "0.19.0-r3", + "Arch": "x86_64", + "SrcName": "tini", + "SrcVersion": "0.19.0-r3", + "Licenses": [ + "MIT" + ], + "Maintainer": "Danilo Bürger \u003cdanilo@feastr.de\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:4f4b8d99a5423eec5753f7cdd0a94d291bc8b782", + "InstalledFiles": [ + "sbin/tini" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "tzdata@2026c-r0", + "Name": "tzdata", + "Identifier": { + "PURL": "pkg:apk/alpine/tzdata@2026c-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "52c6b50eff629f9d" + }, + "Version": "2026c-r0", + "Arch": "x86_64", + "SrcName": "tzdata", + "SrcVersion": "2026c-r0", + "Licenses": [ + "Public-Domain" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:61f7544ecd8dd63eac23fe3e645702fda92ef02a", + "InstalledFiles": [ + "usr/share/zoneinfo/CET", + "usr/share/zoneinfo/CST6CDT", + "usr/share/zoneinfo/Cuba", + "usr/share/zoneinfo/EET", + "usr/share/zoneinfo/EST", + "usr/share/zoneinfo/EST5EDT", + "usr/share/zoneinfo/Egypt", + "usr/share/zoneinfo/Eire", + "usr/share/zoneinfo/Factory", + "usr/share/zoneinfo/GB", + "usr/share/zoneinfo/GB-Eire", + "usr/share/zoneinfo/GMT", + "usr/share/zoneinfo/GMT+0", + "usr/share/zoneinfo/GMT-0", + "usr/share/zoneinfo/GMT0", + "usr/share/zoneinfo/Greenwich", + "usr/share/zoneinfo/HST", + "usr/share/zoneinfo/Hongkong", + "usr/share/zoneinfo/Iceland", + "usr/share/zoneinfo/Iran", + "usr/share/zoneinfo/Israel", + "usr/share/zoneinfo/Jamaica", + "usr/share/zoneinfo/Japan", + "usr/share/zoneinfo/Kwajalein", + "usr/share/zoneinfo/Libya", + "usr/share/zoneinfo/MET", + "usr/share/zoneinfo/MST", + "usr/share/zoneinfo/MST7MDT", + "usr/share/zoneinfo/NZ", + "usr/share/zoneinfo/NZ-CHAT", + "usr/share/zoneinfo/Navajo", + "usr/share/zoneinfo/PRC", + "usr/share/zoneinfo/PST8PDT", + "usr/share/zoneinfo/Poland", + "usr/share/zoneinfo/Portugal", + "usr/share/zoneinfo/ROC", + "usr/share/zoneinfo/ROK", + "usr/share/zoneinfo/Singapore", + "usr/share/zoneinfo/Turkey", + "usr/share/zoneinfo/UCT", + "usr/share/zoneinfo/UTC", + "usr/share/zoneinfo/Universal", + "usr/share/zoneinfo/W-SU", + "usr/share/zoneinfo/WET", + "usr/share/zoneinfo/Zulu", + "usr/share/zoneinfo/iso3166.tab", + "usr/share/zoneinfo/leap-seconds.list", + "usr/share/zoneinfo/posixrules", + "usr/share/zoneinfo/zone.tab", + "usr/share/zoneinfo/zone1970.tab", + "usr/share/zoneinfo/Africa/Abidjan", + "usr/share/zoneinfo/Africa/Accra", + "usr/share/zoneinfo/Africa/Addis_Ababa", + "usr/share/zoneinfo/Africa/Algiers", + "usr/share/zoneinfo/Africa/Asmara", + "usr/share/zoneinfo/Africa/Asmera", + "usr/share/zoneinfo/Africa/Bamako", + "usr/share/zoneinfo/Africa/Bangui", + "usr/share/zoneinfo/Africa/Banjul", + "usr/share/zoneinfo/Africa/Bissau", + "usr/share/zoneinfo/Africa/Blantyre", + "usr/share/zoneinfo/Africa/Brazzaville", + "usr/share/zoneinfo/Africa/Bujumbura", + "usr/share/zoneinfo/Africa/Cairo", + "usr/share/zoneinfo/Africa/Casablanca", + "usr/share/zoneinfo/Africa/Ceuta", + "usr/share/zoneinfo/Africa/Conakry", + "usr/share/zoneinfo/Africa/Dakar", + "usr/share/zoneinfo/Africa/Dar_es_Salaam", + "usr/share/zoneinfo/Africa/Djibouti", + "usr/share/zoneinfo/Africa/Douala", + "usr/share/zoneinfo/Africa/El_Aaiun", + "usr/share/zoneinfo/Africa/Freetown", + "usr/share/zoneinfo/Africa/Gaborone", + "usr/share/zoneinfo/Africa/Harare", + "usr/share/zoneinfo/Africa/Johannesburg", + "usr/share/zoneinfo/Africa/Juba", + "usr/share/zoneinfo/Africa/Kampala", + "usr/share/zoneinfo/Africa/Khartoum", + "usr/share/zoneinfo/Africa/Kigali", + "usr/share/zoneinfo/Africa/Kinshasa", + "usr/share/zoneinfo/Africa/Lagos", + "usr/share/zoneinfo/Africa/Libreville", + "usr/share/zoneinfo/Africa/Lome", + "usr/share/zoneinfo/Africa/Luanda", + "usr/share/zoneinfo/Africa/Lubumbashi", + "usr/share/zoneinfo/Africa/Lusaka", + "usr/share/zoneinfo/Africa/Malabo", + "usr/share/zoneinfo/Africa/Maputo", + "usr/share/zoneinfo/Africa/Maseru", + "usr/share/zoneinfo/Africa/Mbabane", + "usr/share/zoneinfo/Africa/Mogadishu", + "usr/share/zoneinfo/Africa/Monrovia", + "usr/share/zoneinfo/Africa/Nairobi", + "usr/share/zoneinfo/Africa/Ndjamena", + "usr/share/zoneinfo/Africa/Niamey", + "usr/share/zoneinfo/Africa/Nouakchott", + "usr/share/zoneinfo/Africa/Ouagadougou", + "usr/share/zoneinfo/Africa/Porto-Novo", + "usr/share/zoneinfo/Africa/Sao_Tome", + "usr/share/zoneinfo/Africa/Timbuktu", + "usr/share/zoneinfo/Africa/Tripoli", + "usr/share/zoneinfo/Africa/Tunis", + "usr/share/zoneinfo/Africa/Windhoek", + "usr/share/zoneinfo/America/Adak", + "usr/share/zoneinfo/America/Anchorage", + "usr/share/zoneinfo/America/Anguilla", + "usr/share/zoneinfo/America/Antigua", + "usr/share/zoneinfo/America/Araguaina", + "usr/share/zoneinfo/America/Aruba", + "usr/share/zoneinfo/America/Asuncion", + "usr/share/zoneinfo/America/Atikokan", + "usr/share/zoneinfo/America/Atka", + "usr/share/zoneinfo/America/Bahia", + "usr/share/zoneinfo/America/Bahia_Banderas", + "usr/share/zoneinfo/America/Barbados", + "usr/share/zoneinfo/America/Belem", + "usr/share/zoneinfo/America/Belize", + "usr/share/zoneinfo/America/Blanc-Sablon", + "usr/share/zoneinfo/America/Boa_Vista", + "usr/share/zoneinfo/America/Bogota", + "usr/share/zoneinfo/America/Boise", + "usr/share/zoneinfo/America/Buenos_Aires", + "usr/share/zoneinfo/America/Cambridge_Bay", + "usr/share/zoneinfo/America/Campo_Grande", + "usr/share/zoneinfo/America/Cancun", + "usr/share/zoneinfo/America/Caracas", + "usr/share/zoneinfo/America/Catamarca", + "usr/share/zoneinfo/America/Cayenne", + "usr/share/zoneinfo/America/Cayman", + "usr/share/zoneinfo/America/Chicago", + "usr/share/zoneinfo/America/Chihuahua", + "usr/share/zoneinfo/America/Ciudad_Juarez", + "usr/share/zoneinfo/America/Coral_Harbour", + "usr/share/zoneinfo/America/Cordoba", + "usr/share/zoneinfo/America/Costa_Rica", + "usr/share/zoneinfo/America/Coyhaique", + "usr/share/zoneinfo/America/Creston", + "usr/share/zoneinfo/America/Cuiaba", + "usr/share/zoneinfo/America/Curacao", + "usr/share/zoneinfo/America/Danmarkshavn", + "usr/share/zoneinfo/America/Dawson", + "usr/share/zoneinfo/America/Dawson_Creek", + "usr/share/zoneinfo/America/Denver", + "usr/share/zoneinfo/America/Detroit", + "usr/share/zoneinfo/America/Dominica", + "usr/share/zoneinfo/America/Edmonton", + "usr/share/zoneinfo/America/Eirunepe", + "usr/share/zoneinfo/America/El_Salvador", + "usr/share/zoneinfo/America/Ensenada", + "usr/share/zoneinfo/America/Fort_Nelson", + "usr/share/zoneinfo/America/Fort_Wayne", + "usr/share/zoneinfo/America/Fortaleza", + "usr/share/zoneinfo/America/Glace_Bay", + "usr/share/zoneinfo/America/Godthab", + "usr/share/zoneinfo/America/Goose_Bay", + "usr/share/zoneinfo/America/Grand_Turk", + "usr/share/zoneinfo/America/Grenada", + "usr/share/zoneinfo/America/Guadeloupe", + "usr/share/zoneinfo/America/Guatemala", + "usr/share/zoneinfo/America/Guayaquil", + "usr/share/zoneinfo/America/Guyana", + "usr/share/zoneinfo/America/Halifax", + "usr/share/zoneinfo/America/Havana", + "usr/share/zoneinfo/America/Hermosillo", + "usr/share/zoneinfo/America/Indianapolis", + "usr/share/zoneinfo/America/Inuvik", + "usr/share/zoneinfo/America/Iqaluit", + "usr/share/zoneinfo/America/Jamaica", + "usr/share/zoneinfo/America/Jujuy", + "usr/share/zoneinfo/America/Juneau", + "usr/share/zoneinfo/America/Knox_IN", + "usr/share/zoneinfo/America/Kralendijk", + "usr/share/zoneinfo/America/La_Paz", + "usr/share/zoneinfo/America/Lima", + "usr/share/zoneinfo/America/Los_Angeles", + "usr/share/zoneinfo/America/Louisville", + "usr/share/zoneinfo/America/Lower_Princes", + "usr/share/zoneinfo/America/Maceio", + "usr/share/zoneinfo/America/Managua", + "usr/share/zoneinfo/America/Manaus", + "usr/share/zoneinfo/America/Marigot", + "usr/share/zoneinfo/America/Martinique", + "usr/share/zoneinfo/America/Matamoros", + "usr/share/zoneinfo/America/Mazatlan", + "usr/share/zoneinfo/America/Mendoza", + "usr/share/zoneinfo/America/Menominee", + "usr/share/zoneinfo/America/Merida", + "usr/share/zoneinfo/America/Metlakatla", + "usr/share/zoneinfo/America/Mexico_City", + "usr/share/zoneinfo/America/Miquelon", + "usr/share/zoneinfo/America/Moncton", + "usr/share/zoneinfo/America/Monterrey", + "usr/share/zoneinfo/America/Montevideo", + "usr/share/zoneinfo/America/Montreal", + "usr/share/zoneinfo/America/Montserrat", + "usr/share/zoneinfo/America/Nassau", + "usr/share/zoneinfo/America/New_York", + "usr/share/zoneinfo/America/Nipigon", + "usr/share/zoneinfo/America/Nome", + "usr/share/zoneinfo/America/Noronha", + "usr/share/zoneinfo/America/Nuuk", + "usr/share/zoneinfo/America/Ojinaga", + "usr/share/zoneinfo/America/Panama", + "usr/share/zoneinfo/America/Pangnirtung", + "usr/share/zoneinfo/America/Paramaribo", + "usr/share/zoneinfo/America/Phoenix", + "usr/share/zoneinfo/America/Port-au-Prince", + "usr/share/zoneinfo/America/Port_of_Spain", + "usr/share/zoneinfo/America/Porto_Acre", + "usr/share/zoneinfo/America/Porto_Velho", + "usr/share/zoneinfo/America/Puerto_Rico", + "usr/share/zoneinfo/America/Punta_Arenas", + "usr/share/zoneinfo/America/Rainy_River", + "usr/share/zoneinfo/America/Rankin_Inlet", + "usr/share/zoneinfo/America/Recife", + "usr/share/zoneinfo/America/Regina", + "usr/share/zoneinfo/America/Resolute", + "usr/share/zoneinfo/America/Rio_Branco", + "usr/share/zoneinfo/America/Rosario", + "usr/share/zoneinfo/America/Santa_Isabel", + "usr/share/zoneinfo/America/Santarem", + "usr/share/zoneinfo/America/Santiago", + "usr/share/zoneinfo/America/Santo_Domingo", + "usr/share/zoneinfo/America/Sao_Paulo", + "usr/share/zoneinfo/America/Scoresbysund", + "usr/share/zoneinfo/America/Shiprock", + "usr/share/zoneinfo/America/Sitka", + "usr/share/zoneinfo/America/St_Barthelemy", + "usr/share/zoneinfo/America/St_Johns", + "usr/share/zoneinfo/America/St_Kitts", + "usr/share/zoneinfo/America/St_Lucia", + "usr/share/zoneinfo/America/St_Thomas", + "usr/share/zoneinfo/America/St_Vincent", + "usr/share/zoneinfo/America/Swift_Current", + "usr/share/zoneinfo/America/Tegucigalpa", + "usr/share/zoneinfo/America/Thule", + "usr/share/zoneinfo/America/Thunder_Bay", + "usr/share/zoneinfo/America/Tijuana", + "usr/share/zoneinfo/America/Toronto", + "usr/share/zoneinfo/America/Tortola", + "usr/share/zoneinfo/America/Vancouver", + "usr/share/zoneinfo/America/Virgin", + "usr/share/zoneinfo/America/Whitehorse", + "usr/share/zoneinfo/America/Winnipeg", + "usr/share/zoneinfo/America/Yakutat", + "usr/share/zoneinfo/America/Yellowknife", + "usr/share/zoneinfo/America/Argentina/Buenos_Aires", + "usr/share/zoneinfo/America/Argentina/Catamarca", + "usr/share/zoneinfo/America/Argentina/ComodRivadavia", + "usr/share/zoneinfo/America/Argentina/Cordoba", + "usr/share/zoneinfo/America/Argentina/Jujuy", + "usr/share/zoneinfo/America/Argentina/La_Rioja", + "usr/share/zoneinfo/America/Argentina/Mendoza", + "usr/share/zoneinfo/America/Argentina/Rio_Gallegos", + "usr/share/zoneinfo/America/Argentina/Salta", + "usr/share/zoneinfo/America/Argentina/San_Juan", + "usr/share/zoneinfo/America/Argentina/San_Luis", + "usr/share/zoneinfo/America/Argentina/Tucuman", + "usr/share/zoneinfo/America/Argentina/Ushuaia", + "usr/share/zoneinfo/America/Indiana/Indianapolis", + "usr/share/zoneinfo/America/Indiana/Knox", + "usr/share/zoneinfo/America/Indiana/Marengo", + "usr/share/zoneinfo/America/Indiana/Petersburg", + "usr/share/zoneinfo/America/Indiana/Tell_City", + "usr/share/zoneinfo/America/Indiana/Vevay", + "usr/share/zoneinfo/America/Indiana/Vincennes", + "usr/share/zoneinfo/America/Indiana/Winamac", + "usr/share/zoneinfo/America/Kentucky/Louisville", + "usr/share/zoneinfo/America/Kentucky/Monticello", + "usr/share/zoneinfo/America/North_Dakota/Beulah", + "usr/share/zoneinfo/America/North_Dakota/Center", + "usr/share/zoneinfo/America/North_Dakota/New_Salem", + "usr/share/zoneinfo/Antarctica/Casey", + "usr/share/zoneinfo/Antarctica/Davis", + "usr/share/zoneinfo/Antarctica/DumontDUrville", + "usr/share/zoneinfo/Antarctica/Macquarie", + "usr/share/zoneinfo/Antarctica/Mawson", + "usr/share/zoneinfo/Antarctica/McMurdo", + "usr/share/zoneinfo/Antarctica/Palmer", + "usr/share/zoneinfo/Antarctica/Rothera", + "usr/share/zoneinfo/Antarctica/South_Pole", + "usr/share/zoneinfo/Antarctica/Syowa", + "usr/share/zoneinfo/Antarctica/Troll", + "usr/share/zoneinfo/Antarctica/Vostok", + "usr/share/zoneinfo/Arctic/Longyearbyen", + "usr/share/zoneinfo/Asia/Aden", + "usr/share/zoneinfo/Asia/Almaty", + "usr/share/zoneinfo/Asia/Amman", + "usr/share/zoneinfo/Asia/Anadyr", + "usr/share/zoneinfo/Asia/Aqtau", + "usr/share/zoneinfo/Asia/Aqtobe", + "usr/share/zoneinfo/Asia/Ashgabat", + "usr/share/zoneinfo/Asia/Ashkhabad", + "usr/share/zoneinfo/Asia/Atyrau", + "usr/share/zoneinfo/Asia/Baghdad", + "usr/share/zoneinfo/Asia/Bahrain", + "usr/share/zoneinfo/Asia/Baku", + "usr/share/zoneinfo/Asia/Bangkok", + "usr/share/zoneinfo/Asia/Barnaul", + "usr/share/zoneinfo/Asia/Beirut", + "usr/share/zoneinfo/Asia/Bishkek", + "usr/share/zoneinfo/Asia/Brunei", + "usr/share/zoneinfo/Asia/Calcutta", + "usr/share/zoneinfo/Asia/Chita", + "usr/share/zoneinfo/Asia/Choibalsan", + "usr/share/zoneinfo/Asia/Chongqing", + "usr/share/zoneinfo/Asia/Chungking", + "usr/share/zoneinfo/Asia/Colombo", + "usr/share/zoneinfo/Asia/Dacca", + "usr/share/zoneinfo/Asia/Damascus", + "usr/share/zoneinfo/Asia/Dhaka", + "usr/share/zoneinfo/Asia/Dili", + "usr/share/zoneinfo/Asia/Dubai", + "usr/share/zoneinfo/Asia/Dushanbe", + "usr/share/zoneinfo/Asia/Famagusta", + "usr/share/zoneinfo/Asia/Gaza", + "usr/share/zoneinfo/Asia/Harbin", + "usr/share/zoneinfo/Asia/Hebron", + "usr/share/zoneinfo/Asia/Ho_Chi_Minh", + "usr/share/zoneinfo/Asia/Hong_Kong", + "usr/share/zoneinfo/Asia/Hovd", + "usr/share/zoneinfo/Asia/Irkutsk", + "usr/share/zoneinfo/Asia/Istanbul", + "usr/share/zoneinfo/Asia/Jakarta", + "usr/share/zoneinfo/Asia/Jayapura", + "usr/share/zoneinfo/Asia/Jerusalem", + "usr/share/zoneinfo/Asia/Kabul", + "usr/share/zoneinfo/Asia/Kamchatka", + "usr/share/zoneinfo/Asia/Karachi", + "usr/share/zoneinfo/Asia/Kashgar", + "usr/share/zoneinfo/Asia/Kathmandu", + "usr/share/zoneinfo/Asia/Katmandu", + "usr/share/zoneinfo/Asia/Khandyga", + "usr/share/zoneinfo/Asia/Kolkata", + "usr/share/zoneinfo/Asia/Krasnoyarsk", + "usr/share/zoneinfo/Asia/Kuala_Lumpur", + "usr/share/zoneinfo/Asia/Kuching", + "usr/share/zoneinfo/Asia/Kuwait", + "usr/share/zoneinfo/Asia/Macao", + "usr/share/zoneinfo/Asia/Macau", + "usr/share/zoneinfo/Asia/Magadan", + "usr/share/zoneinfo/Asia/Makassar", + "usr/share/zoneinfo/Asia/Manila", + "usr/share/zoneinfo/Asia/Muscat", + "usr/share/zoneinfo/Asia/Nicosia", + "usr/share/zoneinfo/Asia/Novokuznetsk", + "usr/share/zoneinfo/Asia/Novosibirsk", + "usr/share/zoneinfo/Asia/Omsk", + "usr/share/zoneinfo/Asia/Oral", + "usr/share/zoneinfo/Asia/Phnom_Penh", + "usr/share/zoneinfo/Asia/Pontianak", + "usr/share/zoneinfo/Asia/Pyongyang", + "usr/share/zoneinfo/Asia/Qatar", + "usr/share/zoneinfo/Asia/Qostanay", + "usr/share/zoneinfo/Asia/Qyzylorda", + "usr/share/zoneinfo/Asia/Rangoon", + "usr/share/zoneinfo/Asia/Riyadh", + "usr/share/zoneinfo/Asia/Saigon", + "usr/share/zoneinfo/Asia/Sakhalin", + "usr/share/zoneinfo/Asia/Samarkand", + "usr/share/zoneinfo/Asia/Seoul", + "usr/share/zoneinfo/Asia/Shanghai", + "usr/share/zoneinfo/Asia/Singapore", + "usr/share/zoneinfo/Asia/Srednekolymsk", + "usr/share/zoneinfo/Asia/Taipei", + "usr/share/zoneinfo/Asia/Tashkent", + "usr/share/zoneinfo/Asia/Tbilisi", + "usr/share/zoneinfo/Asia/Tehran", + "usr/share/zoneinfo/Asia/Tel_Aviv", + "usr/share/zoneinfo/Asia/Thimbu", + "usr/share/zoneinfo/Asia/Thimphu", + "usr/share/zoneinfo/Asia/Tokyo", + "usr/share/zoneinfo/Asia/Tomsk", + "usr/share/zoneinfo/Asia/Ujung_Pandang", + "usr/share/zoneinfo/Asia/Ulaanbaatar", + "usr/share/zoneinfo/Asia/Ulan_Bator", + "usr/share/zoneinfo/Asia/Urumqi", + "usr/share/zoneinfo/Asia/Ust-Nera", + "usr/share/zoneinfo/Asia/Vientiane", + "usr/share/zoneinfo/Asia/Vladivostok", + "usr/share/zoneinfo/Asia/Yakutsk", + "usr/share/zoneinfo/Asia/Yangon", + "usr/share/zoneinfo/Asia/Yekaterinburg", + "usr/share/zoneinfo/Asia/Yerevan", + "usr/share/zoneinfo/Atlantic/Azores", + "usr/share/zoneinfo/Atlantic/Bermuda", + "usr/share/zoneinfo/Atlantic/Canary", + "usr/share/zoneinfo/Atlantic/Cape_Verde", + "usr/share/zoneinfo/Atlantic/Faeroe", + "usr/share/zoneinfo/Atlantic/Faroe", + "usr/share/zoneinfo/Atlantic/Jan_Mayen", + "usr/share/zoneinfo/Atlantic/Madeira", + "usr/share/zoneinfo/Atlantic/Reykjavik", + "usr/share/zoneinfo/Atlantic/South_Georgia", + "usr/share/zoneinfo/Atlantic/St_Helena", + "usr/share/zoneinfo/Atlantic/Stanley", + "usr/share/zoneinfo/Australia/ACT", + "usr/share/zoneinfo/Australia/Adelaide", + "usr/share/zoneinfo/Australia/Brisbane", + "usr/share/zoneinfo/Australia/Broken_Hill", + "usr/share/zoneinfo/Australia/Canberra", + "usr/share/zoneinfo/Australia/Currie", + "usr/share/zoneinfo/Australia/Darwin", + "usr/share/zoneinfo/Australia/Eucla", + "usr/share/zoneinfo/Australia/Hobart", + "usr/share/zoneinfo/Australia/LHI", + "usr/share/zoneinfo/Australia/Lindeman", + "usr/share/zoneinfo/Australia/Lord_Howe", + "usr/share/zoneinfo/Australia/Melbourne", + "usr/share/zoneinfo/Australia/NSW", + "usr/share/zoneinfo/Australia/North", + "usr/share/zoneinfo/Australia/Perth", + "usr/share/zoneinfo/Australia/Queensland", + "usr/share/zoneinfo/Australia/South", + "usr/share/zoneinfo/Australia/Sydney", + "usr/share/zoneinfo/Australia/Tasmania", + "usr/share/zoneinfo/Australia/Victoria", + "usr/share/zoneinfo/Australia/West", + "usr/share/zoneinfo/Australia/Yancowinna", + "usr/share/zoneinfo/Brazil/Acre", + "usr/share/zoneinfo/Brazil/DeNoronha", + "usr/share/zoneinfo/Brazil/East", + "usr/share/zoneinfo/Brazil/West", + "usr/share/zoneinfo/Canada/Atlantic", + "usr/share/zoneinfo/Canada/Central", + "usr/share/zoneinfo/Canada/Eastern", + "usr/share/zoneinfo/Canada/Mountain", + "usr/share/zoneinfo/Canada/Newfoundland", + "usr/share/zoneinfo/Canada/Pacific", + "usr/share/zoneinfo/Canada/Saskatchewan", + "usr/share/zoneinfo/Canada/Yukon", + "usr/share/zoneinfo/Chile/Continental", + "usr/share/zoneinfo/Chile/EasterIsland", + "usr/share/zoneinfo/Etc/GMT", + "usr/share/zoneinfo/Etc/GMT+0", + "usr/share/zoneinfo/Etc/GMT+1", + "usr/share/zoneinfo/Etc/GMT+10", + "usr/share/zoneinfo/Etc/GMT+11", + "usr/share/zoneinfo/Etc/GMT+12", + "usr/share/zoneinfo/Etc/GMT+2", + "usr/share/zoneinfo/Etc/GMT+3", + "usr/share/zoneinfo/Etc/GMT+4", + "usr/share/zoneinfo/Etc/GMT+5", + "usr/share/zoneinfo/Etc/GMT+6", + "usr/share/zoneinfo/Etc/GMT+7", + "usr/share/zoneinfo/Etc/GMT+8", + "usr/share/zoneinfo/Etc/GMT+9", + "usr/share/zoneinfo/Etc/GMT-0", + "usr/share/zoneinfo/Etc/GMT-1", + "usr/share/zoneinfo/Etc/GMT-10", + "usr/share/zoneinfo/Etc/GMT-11", + "usr/share/zoneinfo/Etc/GMT-12", + "usr/share/zoneinfo/Etc/GMT-13", + "usr/share/zoneinfo/Etc/GMT-14", + "usr/share/zoneinfo/Etc/GMT-2", + "usr/share/zoneinfo/Etc/GMT-3", + "usr/share/zoneinfo/Etc/GMT-4", + "usr/share/zoneinfo/Etc/GMT-5", + "usr/share/zoneinfo/Etc/GMT-6", + "usr/share/zoneinfo/Etc/GMT-7", + "usr/share/zoneinfo/Etc/GMT-8", + "usr/share/zoneinfo/Etc/GMT-9", + "usr/share/zoneinfo/Etc/GMT0", + "usr/share/zoneinfo/Etc/Greenwich", + "usr/share/zoneinfo/Etc/UCT", + "usr/share/zoneinfo/Etc/UTC", + "usr/share/zoneinfo/Etc/Universal", + "usr/share/zoneinfo/Etc/Zulu", + "usr/share/zoneinfo/Europe/Amsterdam", + "usr/share/zoneinfo/Europe/Andorra", + "usr/share/zoneinfo/Europe/Astrakhan", + "usr/share/zoneinfo/Europe/Athens", + "usr/share/zoneinfo/Europe/Belfast", + "usr/share/zoneinfo/Europe/Belgrade", + "usr/share/zoneinfo/Europe/Berlin", + "usr/share/zoneinfo/Europe/Bratislava", + "usr/share/zoneinfo/Europe/Brussels", + "usr/share/zoneinfo/Europe/Bucharest", + "usr/share/zoneinfo/Europe/Budapest", + "usr/share/zoneinfo/Europe/Busingen", + "usr/share/zoneinfo/Europe/Chisinau", + "usr/share/zoneinfo/Europe/Copenhagen", + "usr/share/zoneinfo/Europe/Dublin", + "usr/share/zoneinfo/Europe/Gibraltar", + "usr/share/zoneinfo/Europe/Guernsey", + "usr/share/zoneinfo/Europe/Helsinki", + "usr/share/zoneinfo/Europe/Isle_of_Man", + "usr/share/zoneinfo/Europe/Istanbul", + "usr/share/zoneinfo/Europe/Jersey", + "usr/share/zoneinfo/Europe/Kaliningrad", + "usr/share/zoneinfo/Europe/Kiev", + "usr/share/zoneinfo/Europe/Kirov", + "usr/share/zoneinfo/Europe/Kyiv", + "usr/share/zoneinfo/Europe/Lisbon", + "usr/share/zoneinfo/Europe/Ljubljana", + "usr/share/zoneinfo/Europe/London", + "usr/share/zoneinfo/Europe/Luxembourg", + "usr/share/zoneinfo/Europe/Madrid", + "usr/share/zoneinfo/Europe/Malta", + "usr/share/zoneinfo/Europe/Mariehamn", + "usr/share/zoneinfo/Europe/Minsk", + "usr/share/zoneinfo/Europe/Monaco", + "usr/share/zoneinfo/Europe/Moscow", + "usr/share/zoneinfo/Europe/Nicosia", + "usr/share/zoneinfo/Europe/Oslo", + "usr/share/zoneinfo/Europe/Paris", + "usr/share/zoneinfo/Europe/Podgorica", + "usr/share/zoneinfo/Europe/Prague", + "usr/share/zoneinfo/Europe/Riga", + "usr/share/zoneinfo/Europe/Rome", + "usr/share/zoneinfo/Europe/Samara", + "usr/share/zoneinfo/Europe/San_Marino", + "usr/share/zoneinfo/Europe/Sarajevo", + "usr/share/zoneinfo/Europe/Saratov", + "usr/share/zoneinfo/Europe/Simferopol", + "usr/share/zoneinfo/Europe/Skopje", + "usr/share/zoneinfo/Europe/Sofia", + "usr/share/zoneinfo/Europe/Stockholm", + "usr/share/zoneinfo/Europe/Tallinn", + "usr/share/zoneinfo/Europe/Tirane", + "usr/share/zoneinfo/Europe/Tiraspol", + "usr/share/zoneinfo/Europe/Ulyanovsk", + "usr/share/zoneinfo/Europe/Uzhgorod", + "usr/share/zoneinfo/Europe/Vaduz", + "usr/share/zoneinfo/Europe/Vatican", + "usr/share/zoneinfo/Europe/Vienna", + "usr/share/zoneinfo/Europe/Vilnius", + "usr/share/zoneinfo/Europe/Volgograd", + "usr/share/zoneinfo/Europe/Warsaw", + "usr/share/zoneinfo/Europe/Zagreb", + "usr/share/zoneinfo/Europe/Zaporozhye", + "usr/share/zoneinfo/Europe/Zurich", + "usr/share/zoneinfo/Indian/Antananarivo", + "usr/share/zoneinfo/Indian/Chagos", + "usr/share/zoneinfo/Indian/Christmas", + "usr/share/zoneinfo/Indian/Cocos", + "usr/share/zoneinfo/Indian/Comoro", + "usr/share/zoneinfo/Indian/Kerguelen", + "usr/share/zoneinfo/Indian/Mahe", + "usr/share/zoneinfo/Indian/Maldives", + "usr/share/zoneinfo/Indian/Mauritius", + "usr/share/zoneinfo/Indian/Mayotte", + "usr/share/zoneinfo/Indian/Reunion", + "usr/share/zoneinfo/Mexico/BajaNorte", + "usr/share/zoneinfo/Mexico/BajaSur", + "usr/share/zoneinfo/Mexico/General", + "usr/share/zoneinfo/Pacific/Apia", + "usr/share/zoneinfo/Pacific/Auckland", + "usr/share/zoneinfo/Pacific/Bougainville", + "usr/share/zoneinfo/Pacific/Chatham", + "usr/share/zoneinfo/Pacific/Chuuk", + "usr/share/zoneinfo/Pacific/Easter", + "usr/share/zoneinfo/Pacific/Efate", + "usr/share/zoneinfo/Pacific/Enderbury", + "usr/share/zoneinfo/Pacific/Fakaofo", + "usr/share/zoneinfo/Pacific/Fiji", + "usr/share/zoneinfo/Pacific/Funafuti", + "usr/share/zoneinfo/Pacific/Galapagos", + "usr/share/zoneinfo/Pacific/Gambier", + "usr/share/zoneinfo/Pacific/Guadalcanal", + "usr/share/zoneinfo/Pacific/Guam", + "usr/share/zoneinfo/Pacific/Honolulu", + "usr/share/zoneinfo/Pacific/Johnston", + "usr/share/zoneinfo/Pacific/Kanton", + "usr/share/zoneinfo/Pacific/Kiritimati", + "usr/share/zoneinfo/Pacific/Kosrae", + "usr/share/zoneinfo/Pacific/Kwajalein", + "usr/share/zoneinfo/Pacific/Majuro", + "usr/share/zoneinfo/Pacific/Marquesas", + "usr/share/zoneinfo/Pacific/Midway", + "usr/share/zoneinfo/Pacific/Nauru", + "usr/share/zoneinfo/Pacific/Niue", + "usr/share/zoneinfo/Pacific/Norfolk", + "usr/share/zoneinfo/Pacific/Noumea", + "usr/share/zoneinfo/Pacific/Pago_Pago", + "usr/share/zoneinfo/Pacific/Palau", + "usr/share/zoneinfo/Pacific/Pitcairn", + "usr/share/zoneinfo/Pacific/Pohnpei", + "usr/share/zoneinfo/Pacific/Ponape", + "usr/share/zoneinfo/Pacific/Port_Moresby", + "usr/share/zoneinfo/Pacific/Rarotonga", + "usr/share/zoneinfo/Pacific/Saipan", + "usr/share/zoneinfo/Pacific/Samoa", + "usr/share/zoneinfo/Pacific/Tahiti", + "usr/share/zoneinfo/Pacific/Tarawa", + "usr/share/zoneinfo/Pacific/Tongatapu", + "usr/share/zoneinfo/Pacific/Truk", + "usr/share/zoneinfo/Pacific/Wake", + "usr/share/zoneinfo/Pacific/Wallis", + "usr/share/zoneinfo/Pacific/Yap", + "usr/share/zoneinfo/US/Alaska", + "usr/share/zoneinfo/US/Aleutian", + "usr/share/zoneinfo/US/Arizona", + "usr/share/zoneinfo/US/Central", + "usr/share/zoneinfo/US/East-Indiana", + "usr/share/zoneinfo/US/Eastern", + "usr/share/zoneinfo/US/Hawaii", + "usr/share/zoneinfo/US/Indiana-Starke", + "usr/share/zoneinfo/US/Michigan", + "usr/share/zoneinfo/US/Mountain", + "usr/share/zoneinfo/US/Pacific", + "usr/share/zoneinfo/US/Samoa" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "xz-libs@5.8.4-r0", + "Name": "xz-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/xz-libs@5.8.4-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "3b273a00dbecf01f" + }, + "Version": "5.8.4-r0", + "Arch": "x86_64", + "SrcName": "xz", + "SrcVersion": "5.8.4-r0", + "Licenses": [ + "GPL-2.0-or-later", + "0BSD", + "Public-Domain", + "LGPL-2.1-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:8501065b1862821630174c663b45974462c296e1", + "InstalledFiles": [ + "usr/lib/liblzma.so.5", + "usr/lib/liblzma.so.5.8.4" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "zlib@1.3.2-r0", + "Name": "zlib", + "Identifier": { + "PURL": "pkg:apk/alpine/zlib@1.3.2-r0?arch=x86_64\u0026distro=3.24.1", + "UID": "e37054a2982d6c16" + }, + "Version": "1.3.2-r0", + "Arch": "x86_64", + "SrcName": "zlib", + "SrcVersion": "1.3.2-r0", + "Licenses": [ + "Zlib" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:55afa1ecc21d2bb5e5045f32dafee56272ffd89860bac26f6c32123439af26a4", + "DiffID": "sha256:34884abbe92863fce933ed7c39c0e045631af0ed86d5cc0dfbdf9fdca426ce3c" + }, + "Digest": "sha1:dd4c3d102acaef2a71a1495951d55fabc8680613", + "InstalledFiles": [ + "usr/lib/libz.so.1", + "usr/lib/libz.so.1.3.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "zstd-libs@1.5.7-r2", + "Name": "zstd-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/zstd-libs@1.5.7-r2?arch=x86_64\u0026distro=3.24.1", + "UID": "b33716e8bc222f1f" + }, + "Version": "1.5.7-r2", + "Arch": "x86_64", + "SrcName": "zstd", + "SrcVersion": "1.5.7-r2", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.6-r2" + ], + "Layer": { + "Digest": "sha256:442c85d09879310ea1b3c60465b9ca867735e5e5aae2f8f5eafdb214cd2c3e08", + "DiffID": "sha256:be768a1d5859f4339b3088346fc3c912053b856bddba8c1ea1fe965eda941ec7" + }, + "Digest": "sha1:9569ce3a97c4109e8e53ddde9f3e1bd272613540", + "InstalledFiles": [ + "usr/lib/libzstd.so.1", + "usr/lib/libzstd.so.1.5.7" + ], + "AnalyzedBy": "apk" + } + ] + } + ] +} diff --git a/output/security/site-container-audit.json b/output/security/site-container-audit.json new file mode 100644 index 0000000..e5c59b9 --- /dev/null +++ b/output/security/site-container-audit.json @@ -0,0 +1,4081 @@ +{ + "SchemaVersion": 2, + "Trivy": { + "Version": "0.74.0" + }, + "ReportID": "01a0a028-fd44-7886-a5f2-bb92915669ad", + "CreatedAt": "2026-09-14T13:43:55.972561744Z", + "ArtifactID": "sha256:a77b296460063164bddc8d298b9f95b7ed9e79ae72b4fe89bd8f3f7323137057", + "ArtifactName": "dtf-cloud-site:latest", + "ArtifactType": "container_image", + "Metadata": { + "Size": 85616128, + "OS": { + "Family": "alpine", + "Name": "3.23.3" + }, + "ImageID": "sha256:5d0940deb74c961e790a995b18c75fac88869d42f40dca42bc7296d2de25a09f", + "DiffIDs": [ + "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e", + "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119", + "sha256:47a53288c3ef0ee51df84ef47d217f18c1762412532fded9af1fd88ecee14294", + "sha256:9e707aa6db4786355904a1b794c80f378b690f8f0384af56117708a23a91f1da", + "sha256:a3446cc6c821fa11b704a45811ab554675f0327307af71b3f4ff5a70c7a4eec8", + "sha256:42608b42cb5e68548abf1c71aa851acfd65816d0ceaff6ee85849c7c478463f0", + "sha256:53c769b49ca0a2f0f6cf5e4a807af8933cec6cde9302d56d91a78bc38ea407a8", + "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0", + "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2", + "sha256:41c2fd8d692e28bfe7765fefc3693f7b02fa8e551cb00568deb499ea265bc52e", + "sha256:4ad39d95be0cffca43c6095d0062242bd9adc7670c5848fc2d3ae76d70d730a9", + "sha256:083266cf1311f6d77ff92becbdb6e23ac460b471fc679cccf1b3260993feead8" + ], + "RepoTags": [ + "dtf-cloud-site:latest" + ], + "RepoDigests": [ + "dtf-cloud-site@sha256:5d0940deb74c961e790a995b18c75fac88869d42f40dca42bc7296d2de25a09f" + ], + "Reference": "dtf-cloud-site:latest", + "ImageConfig": { + "architecture": "amd64", + "created": "2026-09-14T10:43:00.337418845-03:00", + "history": [ + { + "created": "2026-01-28T01:18:04Z", + "created_by": "ADD alpine-minirootfs-3.23.3-x86_64.tar.gz / # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-01-28T01:18:04Z", + "created_by": "CMD [\"/bin/sh\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:24Z", + "created_by": "LABEL maintainer=NGINX Docker Maintainers \u003cdocker-maint@nginx.com\u003e", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:24Z", + "created_by": "ENV NGINX_VERSION=1.28.3", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:24Z", + "created_by": "ENV PKG_RELEASE=1", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:24Z", + "created_by": "ENV DYNPKG_RELEASE=1", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:24Z", + "created_by": "RUN /bin/sh -c set -x \u0026\u0026 addgroup -g 101 -S nginx \u0026\u0026 adduser -S -D -H -u 101 -h /var/cache/nginx -s /sbin/nologin -G nginx -g nginx nginx \u0026\u0026 apkArch=\"$(cat /etc/apk/arch)\" \u0026\u0026 nginxPackages=\" nginx=${NGINX_VERSION}-r${PKG_RELEASE} \" \u0026\u0026 apk add --no-cache --virtual .checksum-deps openssl \u0026\u0026 case \"$apkArch\" in x86_64|aarch64) set -x \u0026\u0026 KEY_SHA512=\"e09fa32f0a0eab2b879ccbbc4d0e4fb9751486eedda75e35fac65802cc9faa266425edf83e261137a2f4d16281ce2c1a5f4502930fe75154723da014214f0655\" \u0026\u0026 wget -O /tmp/nginx_signing.rsa.pub https://nginx.org/keys/nginx_signing.rsa.pub \u0026\u0026 if echo \"$KEY_SHA512 */tmp/nginx_signing.rsa.pub\" | sha512sum -c -; then echo \"key verification succeeded!\"; mv /tmp/nginx_signing.rsa.pub /etc/apk/keys/; else echo \"key verification failed!\"; exit 1; fi \u0026\u0026 DEPS=$(apk query --summarize depends --recursive --no-cache --repository \"@nginxorg https://nginx.org/packages/alpine/v$(egrep -o '^[0-9]+\\.[0-9]+' /etc/alpine-release)/main\" ${nginxPackages/=/@nginxorg=}) \u0026\u0026 apk add --no-cache $DEPS \u0026\u0026 apk add --repositories-file /dev/null -X \"https://nginx.org/packages/alpine/v$(egrep -o '^[0-9]+\\.[0-9]+' /etc/alpine-release)/main\" --no-cache $nginxPackages ;; *) set -x \u0026\u0026 tempDir=\"$(mktemp -d)\" \u0026\u0026 chown nobody:nobody $tempDir \u0026\u0026 apk add --no-cache --virtual .build-deps gcc libc-dev make openssl-dev pcre2-dev zlib-dev linux-headers bash alpine-sdk findutils curl \u0026\u0026 su nobody -s /bin/sh -c \" export HOME=${tempDir} \u0026\u0026 cd ${tempDir} \u0026\u0026 curl -f -L -O https://github.com/nginx/pkg-oss/archive/${NGINX_VERSION}-${PKG_RELEASE}.tar.gz \u0026\u0026 PKGOSSCHECKSUM=\\\"866d10a1091f34b6bd9e7dcae69653323fa98511a2b75104b54d97ef71416b9b96f10510149d9e85aa582b21b3cb5e43ea9c2b8d8f7cf0079452e8bea2c10db4 *${NGINX_VERSION}-${PKG_RELEASE}.tar.gz\\\" \u0026\u0026 if [ \\\"\\$(openssl sha512 -r ${NGINX_VERSION}-${PKG_RELEASE}.tar.gz)\\\" = \\\"\\$PKGOSSCHECKSUM\\\" ]; then echo \\\"pkg-oss tarball checksum verification succeeded!\\\"; else echo \\\"pkg-oss tarball checksum verification failed!\\\"; exit 1; fi \u0026\u0026 tar xzvf ${NGINX_VERSION}-${PKG_RELEASE}.tar.gz \u0026\u0026 cd pkg-oss-${NGINX_VERSION}-${PKG_RELEASE} \u0026\u0026 cd alpine \u0026\u0026 make base \u0026\u0026 apk index --allow-untrusted -o ${tempDir}/packages/alpine/${apkArch}/APKINDEX.tar.gz ${tempDir}/packages/alpine/${apkArch}/*.apk \u0026\u0026 abuild-sign -k ${tempDir}/.abuild/abuild-key.rsa ${tempDir}/packages/alpine/${apkArch}/APKINDEX.tar.gz \" \u0026\u0026 cp ${tempDir}/.abuild/abuild-key.rsa.pub /etc/apk/keys/ \u0026\u0026 apk del --no-network .build-deps \u0026\u0026 DEPS=$(apk query --summarize depends --recursive --no-cache --repository \"@nginxorg ${tempDir}/packages/alpine/\" ${nginxPackages/=/@nginxorg=}) \u0026\u0026 apk add --no-cache $DEPS \u0026\u0026 apk add --repositories-file /dev/null -X ${tempDir}/packages/alpine/ --no-cache $nginxPackages ;; esac \u0026\u0026 apk del --no-network .checksum-deps \u0026\u0026 if [ -n \"$tempDir\" ]; then rm -rf \"$tempDir\"; fi \u0026\u0026 if [ -f \"/etc/apk/keys/abuild-key.rsa.pub\" ]; then rm -f /etc/apk/keys/abuild-key.rsa.pub; fi \u0026\u0026 apk add --no-cache gettext-envsubst \u0026\u0026 apk add --no-cache tzdata \u0026\u0026 ln -sf /dev/stdout /var/log/nginx/access.log \u0026\u0026 ln -sf /dev/stderr /var/log/nginx/error.log \u0026\u0026 mkdir /docker-entrypoint.d # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "COPY docker-entrypoint.sh / # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "COPY 10-listen-on-ipv6-by-default.sh /docker-entrypoint.d # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "COPY 15-local-resolvers.envsh /docker-entrypoint.d # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "COPY 20-envsubst-on-templates.sh /docker-entrypoint.d # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "COPY 30-tune-worker-processes.sh /docker-entrypoint.d # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "ENTRYPOINT [\"/docker-entrypoint.sh\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "EXPOSE map[80/tcp:{}]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "STOPSIGNAL SIGQUIT", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T22:12:25Z", + "created_by": "CMD [\"nginx\" \"-g\" \"daemon off;\"]", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T23:11:15Z", + "created_by": "ENV NJS_VERSION=0.9.6", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T23:11:15Z", + "created_by": "ENV NJS_RELEASE=1", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T23:11:15Z", + "created_by": "ENV ACME_VERSION=0.3.1", + "comment": "buildkit.dockerfile.v0", + "empty_layer": true + }, + { + "created": "2026-03-24T23:11:15Z", + "created_by": "RUN /bin/sh -c set -x \u0026\u0026 apkArch=\"$(cat /etc/apk/arch)\" \u0026\u0026 nginxPackages=\" nginx=${NGINX_VERSION}-r${PKG_RELEASE} nginx-module-xslt=${NGINX_VERSION}-r${DYNPKG_RELEASE} nginx-module-geoip=${NGINX_VERSION}-r${DYNPKG_RELEASE} nginx-module-image-filter=${NGINX_VERSION}-r${DYNPKG_RELEASE} nginx-module-njs=${NGINX_VERSION}.${NJS_VERSION}-r${NJS_RELEASE} nginx-module-acme=${NGINX_VERSION}.${ACME_VERSION}-r${PKG_RELEASE} \" \u0026\u0026 apk add --no-cache --virtual .checksum-deps openssl \u0026\u0026 case \"$apkArch\" in x86_64|aarch64) apk add -X \"https://nginx.org/packages/alpine/v$(egrep -o '^[0-9]+\\.[0-9]+' /etc/alpine-release)/main\" --no-cache $nginxPackages ;; *) set -x \u0026\u0026 tempDir=\"$(mktemp -d)\" \u0026\u0026 chown nobody:nobody $tempDir \u0026\u0026 apk add --no-cache --virtual .build-deps gcc libc-dev make openssl-dev pcre2-dev zlib-dev linux-headers libxslt-dev gd-dev geoip-dev libedit-dev bash alpine-sdk findutils curl cargo clang-libclang \u0026\u0026 su nobody -s /bin/sh -c \" export HOME=${tempDir} \u0026\u0026 cd ${tempDir} \u0026\u0026 curl -f -L -O https://github.com/nginx/pkg-oss/archive/${NGINX_VERSION}-${PKG_RELEASE}.tar.gz \u0026\u0026 PKGOSSCHECKSUM=\\\"866d10a1091f34b6bd9e7dcae69653323fa98511a2b75104b54d97ef71416b9b96f10510149d9e85aa582b21b3cb5e43ea9c2b8d8f7cf0079452e8bea2c10db4 *${NGINX_VERSION}-${PKG_RELEASE}.tar.gz\\\" \u0026\u0026 if [ \\\"\\$(openssl sha512 -r ${NGINX_VERSION}-${PKG_RELEASE}.tar.gz)\\\" = \\\"\\$PKGOSSCHECKSUM\\\" ]; then echo \\\"pkg-oss tarball checksum verification succeeded!\\\"; else echo \\\"pkg-oss tarball checksum verification failed!\\\"; exit 1; fi \u0026\u0026 tar xzvf ${NGINX_VERSION}-${PKG_RELEASE}.tar.gz \u0026\u0026 cd pkg-oss-${NGINX_VERSION}-${PKG_RELEASE} \u0026\u0026 cd alpine \u0026\u0026 export BUILDTARGET=\\\"module-geoip module-image-filter module-njs module-xslt module-acme\\\" \u0026\u0026 if [ \\\"\\$(apk --print-arch)\\\" = \\\"armhf\\\" ]; then BUILDTARGET=\\\"\\$( echo \\$BUILDTARGET | sed 's,module-acme,,' )\\\"; fi \u0026\u0026 make \\$BUILDTARGET \u0026\u0026 apk index --allow-untrusted -o ${tempDir}/packages/alpine/${apkArch}/APKINDEX.tar.gz ${tempDir}/packages/alpine/${apkArch}/*.apk \u0026\u0026 abuild-sign -k ${tempDir}/.abuild/abuild-key.rsa ${tempDir}/packages/alpine/${apkArch}/APKINDEX.tar.gz \" \u0026\u0026 cp ${tempDir}/.abuild/abuild-key.rsa.pub /etc/apk/keys/ \u0026\u0026 apk del --no-network .build-deps \u0026\u0026 if [ \"$apkArch\" = \"armhf\" ]; then nginxPackages=\"$( echo $nginxPackages | sed 's,nginx-module-acme=.*,,')\"; fi \u0026\u0026 apk add -X ${tempDir}/packages/alpine/ --no-cache $nginxPackages ;; esac \u0026\u0026 apk del --no-network .checksum-deps \u0026\u0026 if [ -n \"$tempDir\" ]; then rm -rf \"$tempDir\"; fi \u0026\u0026 if [ -f \"/etc/apk/keys/abuild-key.rsa.pub\" ]; then rm -f /etc/apk/keys/abuild-key.rsa.pub; fi \u0026\u0026 apk add --no-cache curl ca-certificates # buildkit", + "comment": "buildkit.dockerfile.v0" + }, + { + "created": "2026-09-14T13:42:12Z", + "created_by": "/bin/sh -c apk upgrade --no-cache" + }, + { + "created": "2026-09-14T13:42:26Z", + "created_by": "/bin/sh -c #(nop) ENV WEB_INDEX=index.html", + "empty_layer": true + }, + { + "created": "2026-09-14T13:42:36Z", + "created_by": "/bin/sh -c #(nop) COPY file:9ada5ed5fea0c34c473d335145ae4a6aa00d261f46b5b3d3bd18ca5c0690e558 in /etc/nginx/templates/default.conf.template " + }, + { + "created": "2026-09-14T13:42:42Z", + "created_by": "/bin/sh -c #(nop) ENV S3_PUBLIC_ENDPOINT=http://localhost:9000", + "empty_layer": true + }, + { + "created": "2026-09-14T13:42:53Z", + "created_by": "/bin/sh -c #(nop) COPY file:250b223b4392e692fcbffe99098e39467952f288ef8b682d85553e0190850b97 in /usr/share/nginx/html/index.html " + }, + { + "created": "2026-09-14T13:42:57Z", + "created_by": "/bin/sh -c #(nop) COPY dir:7a567fb1a37cda0230a25ad002e176756991ed408b4b3db7deb5c2a2a0c42e1b in /usr/share/nginx/html/ " + }, + { + "created": "2026-09-14T13:43:00Z", + "created_by": "/bin/sh -c #(nop) LABEL com.docker.compose.image.builder=classic", + "empty_layer": true + } + ], + "os": "linux", + "rootfs": { + "type": "layers", + "diff_ids": [ + "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e", + "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119", + "sha256:47a53288c3ef0ee51df84ef47d217f18c1762412532fded9af1fd88ecee14294", + "sha256:9e707aa6db4786355904a1b794c80f378b690f8f0384af56117708a23a91f1da", + "sha256:a3446cc6c821fa11b704a45811ab554675f0327307af71b3f4ff5a70c7a4eec8", + "sha256:42608b42cb5e68548abf1c71aa851acfd65816d0ceaff6ee85849c7c478463f0", + "sha256:53c769b49ca0a2f0f6cf5e4a807af8933cec6cde9302d56d91a78bc38ea407a8", + "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0", + "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2", + "sha256:41c2fd8d692e28bfe7765fefc3693f7b02fa8e551cb00568deb499ea265bc52e", + "sha256:4ad39d95be0cffca43c6095d0062242bd9adc7670c5848fc2d3ae76d70d730a9", + "sha256:083266cf1311f6d77ff92becbdb6e23ac460b471fc679cccf1b3260993feead8" + ] + }, + "config": { + "Cmd": [ + "nginx", + "-g", + "daemon off;" + ], + "Entrypoint": [ + "/docker-entrypoint.sh" + ], + "Env": [ + "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", + "NGINX_VERSION=1.28.3", + "PKG_RELEASE=1", + "DYNPKG_RELEASE=1", + "NJS_VERSION=0.9.6", + "NJS_RELEASE=1", + "ACME_VERSION=0.3.1", + "WEB_INDEX=index.html", + "S3_PUBLIC_ENDPOINT=http://localhost:9000" + ], + "Labels": { + "com.docker.compose.image.builder": "classic", + "maintainer": "NGINX Docker Maintainers \u003cdocker-maint@nginx.com\u003e" + }, + "WorkingDir": "/", + "ExposedPorts": { + "80/tcp": {} + }, + "StopSignal": "SIGQUIT" + } + }, + "Layers": [ + { + "Size": 8724480, + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + { + "Size": 4654592, + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + { + "Size": 3584, + "Digest": "sha256:e914c6e98e37815624beb8c5043be292f121898059d4d50c0709bc4da661f685", + "DiffID": "sha256:47a53288c3ef0ee51df84ef47d217f18c1762412532fded9af1fd88ecee14294" + }, + { + "Size": 4608, + "Digest": "sha256:d631a49fb4f72e5bc609d0af4ce6d3ed054498068dc16c730be6b4e37c4a7f6c", + "DiffID": "sha256:9e707aa6db4786355904a1b794c80f378b690f8f0384af56117708a23a91f1da" + }, + { + "Size": 2560, + "Digest": "sha256:8f7c784e247120771f7bdb83b2ab8e17af75af4858332b63e0ed40610f5a9b59", + "DiffID": "sha256:a3446cc6c821fa11b704a45811ab554675f0327307af71b3f4ff5a70c7a4eec8" + }, + { + "Size": 5120, + "Digest": "sha256:44fa0a5a779fdf3b85972e8dfb3b2755a72a97290b682794f57212d88fa3a631", + "DiffID": "sha256:42608b42cb5e68548abf1c71aa851acfd65816d0ceaff6ee85849c7c478463f0" + }, + { + "Size": 7168, + "Digest": "sha256:98104829f3fe8d2ead9a69b1f56c1f98955fd2b5933f089301331bb1f349683b", + "DiffID": "sha256:53c769b49ca0a2f0f6cf5e4a807af8933cec6cde9302d56d91a78bc38ea407a8" + }, + { + "Size": 50089984, + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + { + "Size": 21922304, + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + { + "Size": 5120, + "Digest": "sha256:a7bdcdd65608dd042981c8d1015edd51f81d182bf87e73f70e4fd517ac77d8e0", + "DiffID": "sha256:41c2fd8d692e28bfe7765fefc3693f7b02fa8e551cb00568deb499ea265bc52e" + }, + { + "Size": 152576, + "Digest": "sha256:0e163e36a9a122ed64ba4834c523e45fa11dc14c640c4262f53d03c150b97653", + "DiffID": "sha256:4ad39d95be0cffca43c6095d0062242bd9adc7670c5848fc2d3ae76d70d730a9" + }, + { + "Size": 44032, + "Digest": "sha256:4586a4896f9f2bff3042ac5f88df5df66bc9d2ba2337c120a208297fc26e56ee", + "DiffID": "sha256:083266cf1311f6d77ff92becbdb6e23ac460b471fc679cccf1b3260993feead8" + } + ] + }, + "Results": [ + { + "Target": "dtf-cloud-site:latest (alpine 3.23.3)", + "Class": "os-pkgs", + "Type": "alpine", + "Packages": [ + { + "ID": "alpine-baselayout@3.7.2-r0", + "Name": "alpine-baselayout", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-baselayout@3.7.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "ff3090489ca40326" + }, + "Version": "3.7.2-r0", + "Arch": "x86_64", + "SrcName": "alpine-baselayout", + "SrcVersion": "3.7.2-r0", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "alpine-baselayout-data@3.7.2-r0", + "busybox-binsh@1.37.0-r30" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:545aa6f291209af89932b761d9e422c2778596cc", + "InstalledFiles": [ + "etc/motd", + "etc/crontabs/root", + "etc/modprobe.d/aliases.conf", + "etc/modprobe.d/blacklist.conf", + "etc/modprobe.d/i386.conf", + "etc/profile.d/20locale.sh", + "etc/profile.d/README", + "etc/profile.d/color_prompt.sh.disabled", + "usr/lib/sysctl.d/00-alpine.conf", + "var/lock", + "var/run", + "var/spool/mail", + "var/spool/cron/crontabs" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-baselayout-data@3.7.2-r0", + "Name": "alpine-baselayout-data", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-baselayout-data@3.7.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "78c0ed61d7df9a7e" + }, + "Version": "3.7.2-r0", + "Arch": "x86_64", + "SrcName": "alpine-baselayout", + "SrcVersion": "3.7.2-r0", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:85816632dbce07ba7e9e7a629fa59eddbd1687fb", + "InstalledFiles": [ + "etc/fstab", + "etc/group", + "etc/hostname", + "etc/hosts", + "etc/inittab", + "etc/modules", + "etc/mtab", + "etc/nsswitch.conf", + "etc/passwd", + "etc/profile", + "etc/protocols", + "etc/services", + "etc/shadow", + "etc/shells", + "etc/sysctl.conf" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-keys@2.6-r0", + "Name": "alpine-keys", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-keys@2.6-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "2c7cb90de388aa7d" + }, + "Version": "2.6-r0", + "Arch": "x86_64", + "SrcName": "alpine-keys", + "SrcVersion": "2.6-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:5c45a821cd6b84d543bbd7ff12a7de1855c5cd13", + "InstalledFiles": [ + "etc/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "etc/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", + "etc/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub", + "usr/share/apk/keys/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub", + "usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-58199dcc.rsa.pub", + "usr/share/apk/keys/aarch64/alpine-devel@lists.alpinelinux.org-616ae350.rsa.pub", + "usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", + "usr/share/apk/keys/armhf/alpine-devel@lists.alpinelinux.org-616a9724.rsa.pub", + "usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-524d27bb.rsa.pub", + "usr/share/apk/keys/armv7/alpine-devel@lists.alpinelinux.org-616adfeb.rsa.pub", + "usr/share/apk/keys/loongarch64/alpine-devel@lists.alpinelinux.org-66ba20fe.rsa.pub", + "usr/share/apk/keys/mips64/alpine-devel@lists.alpinelinux.org-5e69ca50.rsa.pub", + "usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-58cbb476.rsa.pub", + "usr/share/apk/keys/ppc64le/alpine-devel@lists.alpinelinux.org-616abc23.rsa.pub", + "usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-60ac2099.rsa.pub", + "usr/share/apk/keys/riscv64/alpine-devel@lists.alpinelinux.org-616db30d.rsa.pub", + "usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-58e4f17d.rsa.pub", + "usr/share/apk/keys/s390x/alpine-devel@lists.alpinelinux.org-616ac3bc.rsa.pub", + "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-5243ef4b.rsa.pub", + "usr/share/apk/keys/x86/alpine-devel@lists.alpinelinux.org-61666e3f.rsa.pub", + "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-4a6a0840.rsa.pub", + "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-5261cecb.rsa.pub", + "usr/share/apk/keys/x86_64/alpine-devel@lists.alpinelinux.org-6165ee59.rsa.pub" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "alpine-release@3.23.5-r0", + "Name": "alpine-release", + "Identifier": { + "PURL": "pkg:apk/alpine/alpine-release@3.23.5-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "58b001445238c53e" + }, + "Version": "3.23.5-r0", + "Arch": "x86_64", + "SrcName": "alpine-base", + "SrcVersion": "3.23.5-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "alpine-keys@2.6-r0" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:37f737cfc477560795ce10cbe468fb86e9e7aabb", + "InstalledFiles": [ + "etc/alpine-release", + "etc/issue", + "etc/os-release", + "etc/secfixes.d/alpine", + "usr/lib/os-release" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "aom-libs@3.14.1-r0", + "Name": "aom-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/aom-libs@3.14.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "eb2e6f75bcc81836" + }, + "Version": "3.14.1-r0", + "Arch": "x86_64", + "SrcName": "aom", + "SrcVersion": "3.14.1-r0", + "Licenses": [ + "BSD-2-Clause", + "custom" + ], + "Maintainer": "Oleg Titov \u003coleg.titov@gmail.com\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:124de479f4f0b2b730dda3d0aa46d3fcefdeda01", + "InstalledFiles": [ + "usr/lib/libaom.so.3", + "usr/lib/libaom.so.3.14.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "apk-tools@3.0.8-r0", + "Name": "apk-tools", + "Identifier": { + "PURL": "pkg:apk/alpine/apk-tools@3.0.8-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "124879d7195ff875" + }, + "Version": "3.0.8-r0", + "Arch": "x86_64", + "SrcName": "apk-tools", + "SrcVersion": "3.0.8-r0", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "ca-certificates-bundle@20260611-r0", + "libapk@3.0.8-r0", + "libcrypto3@3.5.8-r0", + "musl@1.2.5-r23", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:fa7a8422abbbb5e179033cee5455124007817b22", + "InstalledFiles": [ + "sbin/apk" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "brotli-libs@1.2.0-r0", + "Name": "brotli-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/brotli-libs@1.2.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "234da2b3c350083b" + }, + "Version": "1.2.0-r0", + "Arch": "x86_64", + "SrcName": "brotli", + "SrcVersion": "1.2.0-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "prspkt \u003cprspkt@protonmail.com\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:0814694602f35d2741e916fdcb4c9a1e0ec50b42", + "InstalledFiles": [ + "usr/lib/libbrotlicommon.so.1", + "usr/lib/libbrotlicommon.so.1.2.0", + "usr/lib/libbrotlidec.so.1", + "usr/lib/libbrotlidec.so.1.2.0", + "usr/lib/libbrotlienc.so.1", + "usr/lib/libbrotlienc.so.1.2.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "busybox@1.37.0-r30", + "Name": "busybox", + "Identifier": { + "PURL": "pkg:apk/alpine/busybox@1.37.0-r30?arch=x86_64\u0026distro=3.23.3", + "UID": "9647681d0b54db77" + }, + "Version": "1.37.0-r30", + "Arch": "x86_64", + "SrcName": "busybox", + "SrcVersion": "1.37.0-r30", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:f1347801bb96b1aa40d17f82237c3f4ff02a4725", + "InstalledFiles": [ + "bin/busybox", + "etc/securetty", + "etc/busybox-paths.d/busybox", + "etc/logrotate.d/acpid", + "etc/network/if-up.d/dad", + "etc/udhcpc/udhcpc.conf", + "usr/share/udhcpc/default.script" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "busybox-binsh@1.37.0-r30", + "Name": "busybox-binsh", + "Identifier": { + "PURL": "pkg:apk/alpine/busybox-binsh@1.37.0-r30?arch=x86_64\u0026distro=3.23.3", + "UID": "3e18d05d46a6f46f" + }, + "Version": "1.37.0-r30", + "Arch": "x86_64", + "SrcName": "busybox", + "SrcVersion": "1.37.0-r30", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", + "DependsOn": [ + "busybox@1.37.0-r30" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:188d2d0110afa58e8a3e3e5fd424b2d996df7a09", + "InstalledFiles": [ + "bin/sh" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "c-ares@1.34.8-r0", + "Name": "c-ares", + "Identifier": { + "PURL": "pkg:apk/alpine/c-ares@1.34.8-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "96e855f6d4141cce" + }, + "Version": "1.34.8-r0", + "Arch": "x86_64", + "SrcName": "c-ares", + "SrcVersion": "1.34.8-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:3d8d4ee098f26a523244e9e6eb3d802307ae3948", + "InstalledFiles": [ + "usr/lib/libcares.so.2", + "usr/lib/libcares.so.2.19.7" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ca-certificates@20260611-r0", + "Name": "ca-certificates", + "Identifier": { + "PURL": "pkg:apk/alpine/ca-certificates@20260611-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "c136f6748ab58163" + }, + "Version": "20260611-r0", + "Arch": "x86_64", + "SrcName": "ca-certificates", + "SrcVersion": "20260611-r0", + "Licenses": [ + "MPL-2.0", + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "libcrypto3@3.5.8-r0", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:99993992c0b045c9914c5148257c33eb74993615", + "InstalledFiles": [ + "etc/ca-certificates.conf", + "etc/apk/protected_paths.d/ca-certificates.list", + "etc/ca-certificates/update.d/certhash", + "usr/bin/c_rehash", + "usr/sbin/update-ca-certificates", + "usr/share/ca-certificates/mozilla/ACCVRAIZ1.crt", + "usr/share/ca-certificates/mozilla/AC_RAIZ_FNMT-RCM.crt", + "usr/share/ca-certificates/mozilla/AC_RAIZ_FNMT-RCM_SERVIDORES_SEGUROS.crt", + "usr/share/ca-certificates/mozilla/ANF_Secure_Server_Root_CA.crt", + "usr/share/ca-certificates/mozilla/Actalis_Authentication_Root_CA.crt", + "usr/share/ca-certificates/mozilla/Amazon_Root_CA_1.crt", + "usr/share/ca-certificates/mozilla/Amazon_Root_CA_2.crt", + "usr/share/ca-certificates/mozilla/Amazon_Root_CA_3.crt", + "usr/share/ca-certificates/mozilla/Amazon_Root_CA_4.crt", + "usr/share/ca-certificates/mozilla/Atos_TrustedRoot_2011.crt", + "usr/share/ca-certificates/mozilla/Atos_TrustedRoot_Root_CA_ECC_TLS_2021.crt", + "usr/share/ca-certificates/mozilla/Atos_TrustedRoot_Root_CA_RSA_TLS_2021.crt", + "usr/share/ca-certificates/mozilla/Autoridad_de_Certificacion_Firmaprofesional_CIF_A62634068.crt", + "usr/share/ca-certificates/mozilla/BJCA_Global_Root_CA1.crt", + "usr/share/ca-certificates/mozilla/BJCA_Global_Root_CA2.crt", + "usr/share/ca-certificates/mozilla/Buypass_Class_2_Root_CA.crt", + "usr/share/ca-certificates/mozilla/Buypass_Class_3_Root_CA.crt", + "usr/share/ca-certificates/mozilla/CA_Disig_Root_R2.crt", + "usr/share/ca-certificates/mozilla/CFCA_EV_ROOT.crt", + "usr/share/ca-certificates/mozilla/COMODO_ECC_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/COMODO_RSA_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/Certainly_Root_E1.crt", + "usr/share/ca-certificates/mozilla/Certainly_Root_R1.crt", + "usr/share/ca-certificates/mozilla/Certigna_Root_CA.crt", + "usr/share/ca-certificates/mozilla/Certum_EC-384_CA.crt", + "usr/share/ca-certificates/mozilla/Certum_Trusted_Network_CA.crt", + "usr/share/ca-certificates/mozilla/Certum_Trusted_Network_CA_2.crt", + "usr/share/ca-certificates/mozilla/Certum_Trusted_Root_CA.crt", + "usr/share/ca-certificates/mozilla/D-TRUST_BR_Root_CA_1_2020.crt", + "usr/share/ca-certificates/mozilla/D-TRUST_BR_Root_CA_2_2023.crt", + "usr/share/ca-certificates/mozilla/D-TRUST_EV_Root_CA_1_2020.crt", + "usr/share/ca-certificates/mozilla/D-TRUST_EV_Root_CA_2_2023.crt", + "usr/share/ca-certificates/mozilla/D-TRUST_Root_Class_3_CA_2_2009.crt", + "usr/share/ca-certificates/mozilla/D-TRUST_Root_Class_3_CA_2_EV_2009.crt", + "usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_G2.crt", + "usr/share/ca-certificates/mozilla/DigiCert_Assured_ID_Root_G3.crt", + "usr/share/ca-certificates/mozilla/DigiCert_Global_Root_G2.crt", + "usr/share/ca-certificates/mozilla/DigiCert_Global_Root_G3.crt", + "usr/share/ca-certificates/mozilla/DigiCert_TLS_ECC_P384_Root_G5.crt", + "usr/share/ca-certificates/mozilla/DigiCert_TLS_RSA4096_Root_G5.crt", + "usr/share/ca-certificates/mozilla/DigiCert_Trusted_Root_G4.crt", + "usr/share/ca-certificates/mozilla/GDCA_TrustAUTH_R5_ROOT.crt", + "usr/share/ca-certificates/mozilla/GTS_Root_R1.crt", + "usr/share/ca-certificates/mozilla/GTS_Root_R3.crt", + "usr/share/ca-certificates/mozilla/GTS_Root_R4.crt", + "usr/share/ca-certificates/mozilla/GlobalSign_ECC_Root_CA_-_R4.crt", + "usr/share/ca-certificates/mozilla/GlobalSign_ECC_Root_CA_-_R5.crt", + "usr/share/ca-certificates/mozilla/GlobalSign_Root_CA_-_R3.crt", + "usr/share/ca-certificates/mozilla/GlobalSign_Root_CA_-_R6.crt", + "usr/share/ca-certificates/mozilla/GlobalSign_Root_E46.crt", + "usr/share/ca-certificates/mozilla/GlobalSign_Root_R46.crt", + "usr/share/ca-certificates/mozilla/Go_Daddy_Root_Certificate_Authority_-_G2.crt", + "usr/share/ca-certificates/mozilla/HARICA_TLS_ECC_Root_CA_2021.crt", + "usr/share/ca-certificates/mozilla/HARICA_TLS_RSA_Root_CA_2021.crt", + "usr/share/ca-certificates/mozilla/Hellenic_Academic_and_Research_Institutions_ECC_RootCA_2015.crt", + "usr/share/ca-certificates/mozilla/Hellenic_Academic_and_Research_Institutions_RootCA_2015.crt", + "usr/share/ca-certificates/mozilla/HiPKI_Root_CA_-_G1.crt", + "usr/share/ca-certificates/mozilla/Hongkong_Post_Root_CA_3.crt", + "usr/share/ca-certificates/mozilla/ISRG_Root_X1.crt", + "usr/share/ca-certificates/mozilla/ISRG_Root_X2.crt", + "usr/share/ca-certificates/mozilla/IdenTrust_Commercial_Root_CA_1.crt", + "usr/share/ca-certificates/mozilla/IdenTrust_Public_Sector_Root_CA_1.crt", + "usr/share/ca-certificates/mozilla/Izenpe.com.crt", + "usr/share/ca-certificates/mozilla/Microsec_e-Szigno_Root_CA_2009.crt", + "usr/share/ca-certificates/mozilla/Microsoft_ECC_Root_Certificate_Authority_2017.crt", + "usr/share/ca-certificates/mozilla/Microsoft_RSA_Root_Certificate_Authority_2017.crt", + "usr/share/ca-certificates/mozilla/NAVER_Global_Root_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/NetLock_Arany_=Class_Gold=_Főtanúsítvány.crt", + "usr/share/ca-certificates/mozilla/OISTE_Server_Root_ECC_G1.crt", + "usr/share/ca-certificates/mozilla/OISTE_Server_Root_RSA_G1.crt", + "usr/share/ca-certificates/mozilla/OISTE_WISeKey_Global_Root_GB_CA.crt", + "usr/share/ca-certificates/mozilla/OISTE_WISeKey_Global_Root_GC_CA.crt", + "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_1_G3.crt", + "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_2_G3.crt", + "usr/share/ca-certificates/mozilla/QuoVadis_Root_CA_3_G3.crt", + "usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_ECC.crt", + "usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_RSA_R2.crt", + "usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_ECC.crt", + "usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_RSA.crt", + "usr/share/ca-certificates/mozilla/SSL.com_TLS_ECC_Root_CA_2022.crt", + "usr/share/ca-certificates/mozilla/SSL.com_TLS_RSA_Root_CA_2022.crt", + "usr/share/ca-certificates/mozilla/SZAFIR_ROOT_CA2.crt", + "usr/share/ca-certificates/mozilla/Sectigo_Public_Server_Authentication_Root_E46.crt", + "usr/share/ca-certificates/mozilla/Sectigo_Public_Server_Authentication_Root_R46.crt", + "usr/share/ca-certificates/mozilla/SecureSign_Root_CA14.crt", + "usr/share/ca-certificates/mozilla/SecureSign_Root_CA15.crt", + "usr/share/ca-certificates/mozilla/Security_Communication_ECC_RootCA1.crt", + "usr/share/ca-certificates/mozilla/Security_Communication_RootCA2.crt", + "usr/share/ca-certificates/mozilla/Starfield_Root_Certificate_Authority_-_G2.crt", + "usr/share/ca-certificates/mozilla/Starfield_Services_Root_Certificate_Authority_-_G2.crt", + "usr/share/ca-certificates/mozilla/SwissSign_RSA_TLS_Root_CA_2022_-_1.crt", + "usr/share/ca-certificates/mozilla/T-TeleSec_GlobalRoot_Class_2.crt", + "usr/share/ca-certificates/mozilla/T-TeleSec_GlobalRoot_Class_3.crt", + "usr/share/ca-certificates/mozilla/TUBITAK_Kamu_SM_SSL_Kok_Sertifikasi_-_Surum_1.crt", + "usr/share/ca-certificates/mozilla/TWCA_CYBER_Root_CA.crt", + "usr/share/ca-certificates/mozilla/TWCA_Global_Root_CA.crt", + "usr/share/ca-certificates/mozilla/TWCA_Root_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/Telekom_Security_TLS_ECC_Root_2020.crt", + "usr/share/ca-certificates/mozilla/Telekom_Security_TLS_RSA_Root_2023.crt", + "usr/share/ca-certificates/mozilla/Telia_Root_CA_v2.crt", + "usr/share/ca-certificates/mozilla/TrustAsia_Global_Root_CA_G3.crt", + "usr/share/ca-certificates/mozilla/TrustAsia_Global_Root_CA_G4.crt", + "usr/share/ca-certificates/mozilla/TrustAsia_TLS_ECC_Root_CA.crt", + "usr/share/ca-certificates/mozilla/TrustAsia_TLS_RSA_Root_CA.crt", + "usr/share/ca-certificates/mozilla/TunTrust_Root_CA.crt", + "usr/share/ca-certificates/mozilla/UCA_Extended_Validation_Root.crt", + "usr/share/ca-certificates/mozilla/UCA_Global_G2_Root.crt", + "usr/share/ca-certificates/mozilla/USERTrust_ECC_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/USERTrust_RSA_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/certSIGN_Root_CA_G2.crt", + "usr/share/ca-certificates/mozilla/e-Szigno_Root_CA_2017.crt", + "usr/share/ca-certificates/mozilla/e-Szigno_TLS_Root_CA_2023.crt", + "usr/share/ca-certificates/mozilla/ePKI_Root_Certification_Authority.crt", + "usr/share/ca-certificates/mozilla/emSign_ECC_Root_CA_-_C3.crt", + "usr/share/ca-certificates/mozilla/emSign_ECC_Root_CA_-_G3.crt", + "usr/share/ca-certificates/mozilla/emSign_Root_CA_-_C1.crt", + "usr/share/ca-certificates/mozilla/emSign_Root_CA_-_G1.crt", + "usr/share/ca-certificates/mozilla/vTrus_ECC_Root_CA.crt", + "usr/share/ca-certificates/mozilla/vTrus_Root_CA.crt" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ca-certificates-bundle@20260611-r0", + "Name": "ca-certificates-bundle", + "Identifier": { + "PURL": "pkg:apk/alpine/ca-certificates-bundle@20260611-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "a9a37912fbf01124" + }, + "Version": "20260611-r0", + "Arch": "x86_64", + "SrcName": "ca-certificates", + "SrcVersion": "20260611-r0", + "Licenses": [ + "MPL-2.0", + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:41204225abcd63eeb1a73766e6a2e8e894b7423b", + "InstalledFiles": [ + "etc/ssl/cert.pem", + "etc/ssl/certs/ca-certificates.crt", + "etc/ssl1.1/cert.pem", + "etc/ssl1.1/certs" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "curl@8.22.0-r0", + "Name": "curl", + "Identifier": { + "PURL": "pkg:apk/alpine/curl@8.22.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "7c8d8c74d6b68a0d" + }, + "Version": "8.22.0-r0", + "Arch": "x86_64", + "SrcName": "curl", + "SrcVersion": "8.22.0-r0", + "Licenses": [ + "curl" + ], + "Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e", + "DependsOn": [ + "libcurl@8.22.0-r0", + "musl@1.2.5-r23", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:25ef42c2de0e984ca2486586b587ce542aef8161", + "InstalledFiles": [ + "usr/bin/curl", + "usr/bin/wcurl" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "fontconfig@2.17.1-r0", + "Name": "fontconfig", + "Identifier": { + "PURL": "pkg:apk/alpine/fontconfig@2.17.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "8e3e067d10028d76" + }, + "Version": "2.17.1-r0", + "Arch": "x86_64", + "SrcName": "fontconfig", + "SrcVersion": "2.17.1-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "freetype@2.14.3-r0", + "libexpat@2.8.4-r0", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:8037b007516a65d246442a781a05f627073394d0", + "InstalledFiles": [ + "etc/fonts/fonts.conf", + "etc/fonts/conf.d/10-hinting-slight.conf", + "etc/fonts/conf.d/10-scale-bitmap-fonts.conf", + "etc/fonts/conf.d/10-sub-pixel-none.conf", + "etc/fonts/conf.d/10-yes-antialias.conf", + "etc/fonts/conf.d/11-lcdfilter-default.conf", + "etc/fonts/conf.d/20-unhint-small-vera.conf", + "etc/fonts/conf.d/30-metric-aliases.conf", + "etc/fonts/conf.d/40-nonlatin.conf", + "etc/fonts/conf.d/45-generic.conf", + "etc/fonts/conf.d/45-latin.conf", + "etc/fonts/conf.d/48-spacing.conf", + "etc/fonts/conf.d/49-sansserif.conf", + "etc/fonts/conf.d/50-user.conf", + "etc/fonts/conf.d/51-local.conf", + "etc/fonts/conf.d/60-generic.conf", + "etc/fonts/conf.d/60-latin.conf", + "etc/fonts/conf.d/65-fonts-persian.conf", + "etc/fonts/conf.d/65-nonlatin.conf", + "etc/fonts/conf.d/69-unifont.conf", + "etc/fonts/conf.d/70-no-bitmaps-except-emoji.conf", + "etc/fonts/conf.d/80-delicious.conf", + "etc/fonts/conf.d/90-synthetic.conf", + "etc/fonts/conf.d/README", + "usr/bin/fc-cache", + "usr/bin/fc-cat", + "usr/bin/fc-conflist", + "usr/bin/fc-list", + "usr/bin/fc-match", + "usr/bin/fc-pattern", + "usr/bin/fc-query", + "usr/bin/fc-scan", + "usr/bin/fc-validate", + "usr/lib/libfontconfig.so.1", + "usr/lib/libfontconfig.so.1.16.1", + "usr/share/fontconfig/conf.avail/05-reset-dirs-sample.conf", + "usr/share/fontconfig/conf.avail/09-autohint-if-no-hinting.conf", + "usr/share/fontconfig/conf.avail/10-autohint.conf", + "usr/share/fontconfig/conf.avail/10-hinting-full.conf", + "usr/share/fontconfig/conf.avail/10-hinting-medium.conf", + "usr/share/fontconfig/conf.avail/10-hinting-none.conf", + "usr/share/fontconfig/conf.avail/10-hinting-slight.conf", + "usr/share/fontconfig/conf.avail/10-no-antialias.conf", + "usr/share/fontconfig/conf.avail/10-scale-bitmap-fonts.conf", + "usr/share/fontconfig/conf.avail/10-sub-pixel-bgr.conf", + "usr/share/fontconfig/conf.avail/10-sub-pixel-none.conf", + "usr/share/fontconfig/conf.avail/10-sub-pixel-rgb.conf", + "usr/share/fontconfig/conf.avail/10-sub-pixel-vbgr.conf", + "usr/share/fontconfig/conf.avail/10-sub-pixel-vrgb.conf", + "usr/share/fontconfig/conf.avail/10-unhinted.conf", + "usr/share/fontconfig/conf.avail/10-yes-antialias.conf", + "usr/share/fontconfig/conf.avail/11-lcdfilter-default.conf", + "usr/share/fontconfig/conf.avail/11-lcdfilter-legacy.conf", + "usr/share/fontconfig/conf.avail/11-lcdfilter-light.conf", + "usr/share/fontconfig/conf.avail/11-lcdfilter-none.conf", + "usr/share/fontconfig/conf.avail/20-unhint-small-vera.conf", + "usr/share/fontconfig/conf.avail/25-unhint-nonlatin.conf", + "usr/share/fontconfig/conf.avail/30-metric-aliases.conf", + "usr/share/fontconfig/conf.avail/35-lang-normalize.conf", + "usr/share/fontconfig/conf.avail/40-nonlatin.conf", + "usr/share/fontconfig/conf.avail/45-generic.conf", + "usr/share/fontconfig/conf.avail/45-latin.conf", + "usr/share/fontconfig/conf.avail/48-guessfamily.conf", + "usr/share/fontconfig/conf.avail/48-spacing.conf", + "usr/share/fontconfig/conf.avail/49-sansserif.conf", + "usr/share/fontconfig/conf.avail/50-user.conf", + "usr/share/fontconfig/conf.avail/51-local.conf", + "usr/share/fontconfig/conf.avail/60-generic.conf", + "usr/share/fontconfig/conf.avail/60-latin.conf", + "usr/share/fontconfig/conf.avail/65-fonts-persian.conf", + "usr/share/fontconfig/conf.avail/65-khmer.conf", + "usr/share/fontconfig/conf.avail/65-nonlatin.conf", + "usr/share/fontconfig/conf.avail/69-unifont.conf", + "usr/share/fontconfig/conf.avail/70-no-bitmaps-and-emoji.conf", + "usr/share/fontconfig/conf.avail/70-no-bitmaps-except-emoji.conf", + "usr/share/fontconfig/conf.avail/70-no-bitmaps.conf", + "usr/share/fontconfig/conf.avail/70-yes-bitmaps.conf", + "usr/share/fontconfig/conf.avail/80-delicious.conf", + "usr/share/fontconfig/conf.avail/90-synthetic.conf", + "usr/share/xml/fontconfig/fonts.dtd" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "freetype@2.14.3-r0", + "Name": "freetype", + "Identifier": { + "PURL": "pkg:apk/alpine/freetype@2.14.3-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "bfc9b8cf530ca476" + }, + "Version": "2.14.3-r0", + "Arch": "x86_64", + "SrcName": "freetype", + "SrcVersion": "2.14.3-r0", + "Licenses": [ + "FTL", + "GPL-2.0-or-later" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "brotli-libs@1.2.0-r0", + "libbz2@1.0.8-r6", + "libpng@1.6.58-r1", + "musl@1.2.5-r23", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:830add7bff72b4656dbe08b5b5704ddbc162660a", + "InstalledFiles": [ + "usr/lib/libfreetype.so.6", + "usr/lib/libfreetype.so.6.20.6" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "geoip@1.6.12-r6", + "Name": "geoip", + "Identifier": { + "PURL": "pkg:apk/alpine/geoip@1.6.12-r6?arch=x86_64\u0026distro=3.23.3", + "UID": "e21c96f348abf9a7" + }, + "Version": "1.6.12-r6", + "Arch": "x86_64", + "SrcName": "geoip", + "SrcVersion": "1.6.12-r6", + "Licenses": [ + "LGPL-2.1-or-later" + ], + "Maintainer": "Leonardo Arena \u003crnalrd@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:8f2ea64ecb173949f03ec2371db4b534f142450f", + "InstalledFiles": [ + "usr/bin/geoiplookup", + "usr/bin/geoiplookup6", + "usr/lib/libGeoIP.so.1", + "usr/lib/libGeoIP.so.1.6.12" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "gettext-envsubst@0.24.1-r1", + "Name": "gettext-envsubst", + "Identifier": { + "PURL": "pkg:apk/alpine/gettext-envsubst@0.24.1-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "74b745a88adcfea9" + }, + "Version": "0.24.1-r1", + "Arch": "x86_64", + "SrcName": "gettext", + "SrcVersion": "0.24.1-r1", + "Licenses": [ + "GPL-3.0-or-later", + "LGPL-2.1-or-later", + "MIT" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "libintl@0.24.1-r1", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "Digest": "sha1:7593f7d82a7c943f0114a5f700788c53afb8a554", + "InstalledFiles": [ + "usr/bin/envsubst" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libapk@3.0.8-r0", + "Name": "libapk", + "Identifier": { + "PURL": "pkg:apk/alpine/libapk@3.0.8-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "fb5e89a1747d84c2" + }, + "Version": "3.0.8-r0", + "Arch": "x86_64", + "SrcName": "apk-tools", + "SrcVersion": "3.0.8-r0", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libcrypto3@3.5.8-r0", + "libssl3@3.5.8-r0", + "musl@1.2.5-r23", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:2913286d1d02641d392289ba525850be6856df11", + "InstalledFiles": [ + "usr/lib/libapk.so.3.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libavif@1.3.0-r0", + "Name": "libavif", + "Identifier": { + "PURL": "pkg:apk/alpine/libavif@1.3.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "63a8e18964f69181" + }, + "Version": "1.3.0-r0", + "Arch": "x86_64", + "SrcName": "libavif", + "SrcVersion": "1.3.0-r0", + "Licenses": [ + "BSD-2-Clause" + ], + "Maintainer": "Bart Ribbers \u003cbribbers@disroot.org\u003e", + "DependsOn": [ + "aom-libs@3.14.1-r0", + "libdav1d@1.5.2-r0", + "libyuv@0.0.1887.20251502-r1", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:6e0e61c8a9d1cb5a4a5f3faa64fb597844614f93", + "InstalledFiles": [ + "usr/lib/libavif.so.16", + "usr/lib/libavif.so.16.3.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libbsd@0.12.2-r0", + "Name": "libbsd", + "Identifier": { + "PURL": "pkg:apk/alpine/libbsd@0.12.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "dd77a74c79623bb3" + }, + "Version": "0.12.2-r0", + "Arch": "x86_64", + "SrcName": "libbsd", + "SrcVersion": "0.12.2-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libmd@1.1.0-r0", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:33970b157edad359d05a2c3e6f3460e725549c8b", + "InstalledFiles": [ + "usr/lib/libbsd.so.0", + "usr/lib/libbsd.so.0.12.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libbz2@1.0.8-r6", + "Name": "libbz2", + "Identifier": { + "PURL": "pkg:apk/alpine/libbz2@1.0.8-r6?arch=x86_64\u0026distro=3.23.3", + "UID": "d5d1649d0ebe2b41" + }, + "Version": "1.0.8-r6", + "Arch": "x86_64", + "SrcName": "bzip2", + "SrcVersion": "1.0.8-r6", + "Licenses": [ + "bzip-2-1.0.6" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:864d363da11ee24c7920e0d052d2da7f8429251e", + "InstalledFiles": [ + "usr/lib/libbz2.so.1", + "usr/lib/libbz2.so.1.0.8" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libcrypto3@3.5.8-r0", + "Name": "libcrypto3", + "Identifier": { + "PURL": "pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "6f720d761ae51746" + }, + "Version": "3.5.8-r0", + "Arch": "x86_64", + "SrcName": "openssl", + "SrcVersion": "3.5.8-r0", + "Licenses": [ + "Apache-2.0" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:c5d20a5036bd12c5130652879054be658429c1d5", + "InstalledFiles": [ + "etc/ssl/ct_log_list.cnf", + "etc/ssl/ct_log_list.cnf.dist", + "etc/ssl/openssl.cnf", + "etc/ssl/openssl.cnf.dist", + "usr/lib/libcrypto.so.3", + "usr/lib/engines-3/afalg.so", + "usr/lib/engines-3/capi.so", + "usr/lib/engines-3/loader_attic.so", + "usr/lib/engines-3/padlock.so", + "usr/lib/ossl-modules/legacy.so" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libcurl@8.22.0-r0", + "Name": "libcurl", + "Identifier": { + "PURL": "pkg:apk/alpine/libcurl@8.22.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "fc33b9b1e80345a1" + }, + "Version": "8.22.0-r0", + "Arch": "x86_64", + "SrcName": "curl", + "SrcVersion": "8.22.0-r0", + "Licenses": [ + "curl" + ], + "Maintainer": "Achill Gilgenast \u003cachill@achill.org\u003e", + "DependsOn": [ + "brotli-libs@1.2.0-r0", + "c-ares@1.34.8-r0", + "ca-certificates-bundle@20260611-r0", + "libcrypto3@3.5.8-r0", + "libidn2@2.3.8-r0", + "libpsl@0.21.5-r3", + "libssl3@3.5.8-r0", + "musl@1.2.5-r23", + "nghttp2-libs@1.69.0-r0", + "zlib@1.3.2-r0", + "zstd-libs@1.5.7-r2" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:fc3080d93055dbae559652788738922fde5146b4", + "InstalledFiles": [ + "usr/lib/libcurl.so.4", + "usr/lib/libcurl.so.4.8.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libdav1d@1.5.2-r0", + "Name": "libdav1d", + "Identifier": { + "PURL": "pkg:apk/alpine/libdav1d@1.5.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "470e133c6bf6f9c4" + }, + "Version": "1.5.2-r0", + "Arch": "x86_64", + "SrcName": "dav1d", + "SrcVersion": "1.5.2-r0", + "Licenses": [ + "BSD-2-Clause" + ], + "Maintainer": "Bart Ribbers \u003cbribbers@disroot.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:62a9676453a8b99cfb42148cfd26df3b964bcc1b", + "InstalledFiles": [ + "usr/lib/libdav1d.so.7", + "usr/lib/libdav1d.so.7.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libedit@20251016.3.1-r0", + "Name": "libedit", + "Identifier": { + "PURL": "pkg:apk/alpine/libedit@20251016.3.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "4cd9b43219994542" + }, + "Version": "20251016.3.1-r0", + "Arch": "x86_64", + "SrcName": "libedit", + "SrcVersion": "20251016.3.1-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Celeste \u003ccielesti@protonmail.com\u003e", + "DependsOn": [ + "libncursesw@6.5_p20251123-r0", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:463f69335a3223b1ce6856ce3bef5c03fee721bf", + "InstalledFiles": [ + "usr/lib/libedit.so.0", + "usr/lib/libedit.so.0.0.76" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libexpat@2.8.4-r0", + "Name": "libexpat", + "Identifier": { + "PURL": "pkg:apk/alpine/libexpat@2.8.4-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "51a3d1625fce6c46" + }, + "Version": "2.8.4-r0", + "Arch": "x86_64", + "SrcName": "expat", + "SrcVersion": "2.8.4-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:210a2cb0f4e47680c45eafd7d5902e9003640e1f", + "InstalledFiles": [ + "usr/lib/libexpat.so.1", + "usr/lib/libexpat.so.1.12.4" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libgcc@15.2.0-r2", + "Name": "libgcc", + "Identifier": { + "PURL": "pkg:apk/alpine/libgcc@15.2.0-r2?arch=x86_64\u0026distro=3.23.3", + "UID": "89fff20701e56ab7" + }, + "Version": "15.2.0-r2", + "Arch": "x86_64", + "SrcName": "gcc", + "SrcVersion": "15.2.0-r2", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-2.1-or-later" + ], + "Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:57fccbe9eebf23f2c4f38ee2a24f8b0bdd508ff7", + "InstalledFiles": [ + "usr/lib/libgcc_s.so.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libgd@2.3.3-r10", + "Name": "libgd", + "Identifier": { + "PURL": "pkg:apk/alpine/libgd@2.3.3-r10?arch=x86_64\u0026distro=3.23.3", + "UID": "d394b5e6ac1c196f" + }, + "Version": "2.3.3-r10", + "Arch": "x86_64", + "SrcName": "gd", + "SrcVersion": "2.3.3-r10", + "Licenses": [ + "GD" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "fontconfig@2.17.1-r0", + "freetype@2.14.3-r0", + "libavif@1.3.0-r0", + "libjpeg-turbo@3.1.2-r0", + "libpng@1.6.58-r1", + "libwebp@1.6.0-r0", + "libxpm@3.5.19-r0", + "musl@1.2.5-r23", + "tiff@4.7.1-r0", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:948454e00c660b6ddf1338a857959222f0888336", + "InstalledFiles": [ + "usr/lib/libgd.so.3", + "usr/lib/libgd.so.3.0.11" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libice@1.1.2-r0", + "Name": "libice", + "Identifier": { + "PURL": "pkg:apk/alpine/libice@1.1.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "3348caa25e2ecdc4" + }, + "Version": "1.1.2-r0", + "Arch": "x86_64", + "SrcName": "libice", + "SrcVersion": "1.1.2-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:997a01303f63cee0ba9773f0cd9b26b2eb5e6ace", + "InstalledFiles": [ + "usr/lib/libICE.so.6", + "usr/lib/libICE.so.6.3.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libidn2@2.3.8-r0", + "Name": "libidn2", + "Identifier": { + "PURL": "pkg:apk/alpine/libidn2@2.3.8-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "f2e21ad261c22630" + }, + "Version": "2.3.8-r0", + "Arch": "x86_64", + "SrcName": "libidn2", + "SrcVersion": "2.3.8-r0", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-3.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libunistring@1.4.1-r0", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:b8c5bfa365da5c360a01230db4d71e65af94af3d", + "InstalledFiles": [ + "usr/lib/libidn2.so.0", + "usr/lib/libidn2.so.0.4.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libintl@0.24.1-r1", + "Name": "libintl", + "Identifier": { + "PURL": "pkg:apk/alpine/libintl@0.24.1-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "6b922bec7f8abaa" + }, + "Version": "0.24.1-r1", + "Arch": "x86_64", + "SrcName": "gettext", + "SrcVersion": "0.24.1-r1", + "Licenses": [ + "LGPL-2.1-or-later" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "Digest": "sha1:0222324bb4dfd35e8a3ec821c86eb5afbd43a3af", + "InstalledFiles": [ + "usr/lib/libintl.so.8", + "usr/lib/libintl.so.8.4.3" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libjpeg-turbo@3.1.2-r0", + "Name": "libjpeg-turbo", + "Identifier": { + "PURL": "pkg:apk/alpine/libjpeg-turbo@3.1.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "76e9eea31b92641e" + }, + "Version": "3.1.2-r0", + "Arch": "x86_64", + "SrcName": "libjpeg-turbo", + "SrcVersion": "3.1.2-r0", + "Licenses": [ + "BSD-3-Clause", + "IJG", + "Zlib" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:aa025fb7ecf9bd65ef2afe47e3740639521e09ce", + "InstalledFiles": [ + "usr/lib/libjpeg.so.8", + "usr/lib/libjpeg.so.8.3.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libmd@1.1.0-r0", + "Name": "libmd", + "Identifier": { + "PURL": "pkg:apk/alpine/libmd@1.1.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "53cb33d88e504fac" + }, + "Version": "1.1.0-r0", + "Arch": "x86_64", + "SrcName": "libmd", + "SrcVersion": "1.1.0-r0", + "Licenses": [ + "BSD-3-Clause", + "BSD-2-Clause", + "ISC", + "Beerware", + "Public", + "Domain" + ], + "Maintainer": "omni \u003comni+alpine@hack.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:ce7c57bd1f6628da8ba0d3f2ac18f6d8c93c0346", + "InstalledFiles": [ + "usr/lib/libmd.so.0", + "usr/lib/libmd.so.0.1.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libncursesw@6.5_p20251123-r0", + "Name": "libncursesw", + "Identifier": { + "PURL": "pkg:apk/alpine/libncursesw@6.5_p20251123-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "edc30eb15f442d49" + }, + "Version": "6.5_p20251123-r0", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.5_p20251123-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23", + "ncurses-terminfo-base@6.5_p20251123-r0" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:649d3041c52b80620fb50a98f5979d25ebbe1523", + "InstalledFiles": [ + "usr/lib/libncursesw.so.6", + "usr/lib/libncursesw.so.6.5" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libpng@1.6.58-r1", + "Name": "libpng", + "Identifier": { + "PURL": "pkg:apk/alpine/libpng@1.6.58-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "f22fca42d750ae4d" + }, + "Version": "1.6.58-r1", + "Arch": "x86_64", + "SrcName": "libpng", + "SrcVersion": "1.6.58-r1", + "Licenses": [ + "Libpng" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:2dce71ea975aa82cbbcfcaac80af209bc84dd3c8", + "InstalledFiles": [ + "usr/lib/libpng16.so.16", + "usr/lib/libpng16.so.16.58.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libpsl@0.21.5-r3", + "Name": "libpsl", + "Identifier": { + "PURL": "pkg:apk/alpine/libpsl@0.21.5-r3?arch=x86_64\u0026distro=3.23.3", + "UID": "3b2044e446534821" + }, + "Version": "0.21.5-r3", + "Arch": "x86_64", + "SrcName": "libpsl", + "SrcVersion": "0.21.5-r3", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libidn2@2.3.8-r0", + "libunistring@1.4.1-r0", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:b663c00f920a93be49c825555aa1a212e4287393", + "InstalledFiles": [ + "usr/lib/libpsl.so.5", + "usr/lib/libpsl.so.5.3.5" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libsharpyuv@1.6.0-r0", + "Name": "libsharpyuv", + "Identifier": { + "PURL": "pkg:apk/alpine/libsharpyuv@1.6.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "73fb52723f19371d" + }, + "Version": "1.6.0-r0", + "Arch": "x86_64", + "SrcName": "libwebp", + "SrcVersion": "1.6.0-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:9bbf3958ac62e163084cde753276246e56ff298b", + "InstalledFiles": [ + "usr/lib/libsharpyuv.so.0", + "usr/lib/libsharpyuv.so.0.1.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libsm@1.2.6-r0", + "Name": "libsm", + "Identifier": { + "PURL": "pkg:apk/alpine/libsm@1.2.6-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "a4bc0187229253de" + }, + "Version": "1.2.6-r0", + "Arch": "x86_64", + "SrcName": "libsm", + "SrcVersion": "1.2.6-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libice@1.1.2-r0", + "libuuid@2.41.6-r1", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:244b3b3e68f3c6c11c6202320109d460a2498e76", + "InstalledFiles": [ + "usr/lib/libSM.so.6", + "usr/lib/libSM.so.6.0.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libssl3@3.5.8-r0", + "Name": "libssl3", + "Identifier": { + "PURL": "pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "1aafb9a42f29e87a" + }, + "Version": "3.5.8-r0", + "Arch": "x86_64", + "SrcName": "openssl", + "SrcVersion": "3.5.8-r0", + "Licenses": [ + "Apache-2.0" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libcrypto3@3.5.8-r0", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:07184887491e0feffa57184419b1387450047bb9", + "InstalledFiles": [ + "usr/lib/libssl.so.3" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libstdc++@15.2.0-r2", + "Name": "libstdc++", + "Identifier": { + "PURL": "pkg:apk/alpine/libstdc%2B%2B@15.2.0-r2?arch=x86_64\u0026distro=3.23.3", + "UID": "3ff8ae215a6a54a6" + }, + "Version": "15.2.0-r2", + "Arch": "x86_64", + "SrcName": "gcc", + "SrcVersion": "15.2.0-r2", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-2.1-or-later" + ], + "Maintainer": "Ariadne Conill \u003cariadne@dereferenced.org\u003e", + "DependsOn": [ + "libgcc@15.2.0-r2", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:528d77417a16706468af852f2859ad00f176e266", + "InstalledFiles": [ + "usr/lib/libstdc++.so.6", + "usr/lib/libstdc++.so.6.0.34" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libunistring@1.4.1-r0", + "Name": "libunistring", + "Identifier": { + "PURL": "pkg:apk/alpine/libunistring@1.4.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "97a3c9b2cf3d0f9e" + }, + "Version": "1.4.1-r0", + "Arch": "x86_64", + "SrcName": "libunistring", + "SrcVersion": "1.4.1-r0", + "Licenses": [ + "GPL-2.0-or-later", + "LGPL-3.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:6e56562bde456bee5971787d3d95c34e84ced797", + "InstalledFiles": [ + "usr/lib/libunistring.so.5", + "usr/lib/libunistring.so.5.2.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libuuid@2.41.6-r1", + "Name": "libuuid", + "Identifier": { + "PURL": "pkg:apk/alpine/libuuid@2.41.6-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "17f473e7cd8823e2" + }, + "Version": "2.41.6-r1", + "Arch": "x86_64", + "SrcName": "util-linux", + "SrcVersion": "2.41.6-r1", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:a2dcd48efc3d21580bb39ad31aff67562ff5cdbc", + "InstalledFiles": [ + "usr/lib/libuuid.so.1", + "usr/lib/libuuid.so.1.3.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libwebp@1.6.0-r0", + "Name": "libwebp", + "Identifier": { + "PURL": "pkg:apk/alpine/libwebp@1.6.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "cf3db5e019392979" + }, + "Version": "1.6.0-r0", + "Arch": "x86_64", + "SrcName": "libwebp", + "SrcVersion": "1.6.0-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libsharpyuv@1.6.0-r0", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:46f79fe406ce611058a6c0ce995ebe85f7b73c7a", + "InstalledFiles": [ + "usr/lib/libwebp.so.7", + "usr/lib/libwebp.so.7.2.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libx11@1.8.12-r1", + "Name": "libx11", + "Identifier": { + "PURL": "pkg:apk/alpine/libx11@1.8.12-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "e8538d9e85dca6bf" + }, + "Version": "1.8.12-r1", + "Arch": "x86_64", + "SrcName": "libx11", + "SrcVersion": "1.8.12-r1", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libxcb@1.17.0-r1", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:689b36ec47d6c9abb9cbd0c7067ba4636568dbd5", + "InstalledFiles": [ + "usr/lib/libX11-xcb.so.1", + "usr/lib/libX11-xcb.so.1.0.0", + "usr/lib/libX11.so.6", + "usr/lib/libX11.so.6.4.0", + "usr/share/X11/XErrorDB", + "usr/share/X11/Xcms.txt", + "usr/share/X11/locale/compose.dir", + "usr/share/X11/locale/locale.alias", + "usr/share/X11/locale/locale.dir", + "usr/share/X11/locale/C/Compose", + "usr/share/X11/locale/C/XI18N_OBJS", + "usr/share/X11/locale/C/XLC_LOCALE", + "usr/share/X11/locale/am_ET.UTF-8/Compose", + "usr/share/X11/locale/am_ET.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/am_ET.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/armscii-8/Compose", + "usr/share/X11/locale/armscii-8/XI18N_OBJS", + "usr/share/X11/locale/armscii-8/XLC_LOCALE", + "usr/share/X11/locale/cs_CZ.UTF-8/Compose", + "usr/share/X11/locale/cs_CZ.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/cs_CZ.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/el_GR.UTF-8/Compose", + "usr/share/X11/locale/el_GR.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/el_GR.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/en_US.UTF-8/Compose", + "usr/share/X11/locale/en_US.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/en_US.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/fi_FI.UTF-8/Compose", + "usr/share/X11/locale/fi_FI.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/fi_FI.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/georgian-academy/Compose", + "usr/share/X11/locale/georgian-academy/XI18N_OBJS", + "usr/share/X11/locale/georgian-academy/XLC_LOCALE", + "usr/share/X11/locale/georgian-ps/Compose", + "usr/share/X11/locale/georgian-ps/XI18N_OBJS", + "usr/share/X11/locale/georgian-ps/XLC_LOCALE", + "usr/share/X11/locale/ibm-cp1133/Compose", + "usr/share/X11/locale/ibm-cp1133/XI18N_OBJS", + "usr/share/X11/locale/ibm-cp1133/XLC_LOCALE", + "usr/share/X11/locale/iscii-dev/Compose", + "usr/share/X11/locale/iscii-dev/XI18N_OBJS", + "usr/share/X11/locale/iscii-dev/XLC_LOCALE", + "usr/share/X11/locale/isiri-3342/Compose", + "usr/share/X11/locale/isiri-3342/XI18N_OBJS", + "usr/share/X11/locale/isiri-3342/XLC_LOCALE", + "usr/share/X11/locale/iso8859-1/Compose", + "usr/share/X11/locale/iso8859-1/XI18N_OBJS", + "usr/share/X11/locale/iso8859-1/XLC_LOCALE", + "usr/share/X11/locale/iso8859-10/Compose", + "usr/share/X11/locale/iso8859-10/XI18N_OBJS", + "usr/share/X11/locale/iso8859-10/XLC_LOCALE", + "usr/share/X11/locale/iso8859-11/Compose", + "usr/share/X11/locale/iso8859-11/XI18N_OBJS", + "usr/share/X11/locale/iso8859-11/XLC_LOCALE", + "usr/share/X11/locale/iso8859-13/Compose", + "usr/share/X11/locale/iso8859-13/XI18N_OBJS", + "usr/share/X11/locale/iso8859-13/XLC_LOCALE", + "usr/share/X11/locale/iso8859-14/Compose", + "usr/share/X11/locale/iso8859-14/XI18N_OBJS", + "usr/share/X11/locale/iso8859-14/XLC_LOCALE", + "usr/share/X11/locale/iso8859-15/Compose", + "usr/share/X11/locale/iso8859-15/XI18N_OBJS", + "usr/share/X11/locale/iso8859-15/XLC_LOCALE", + "usr/share/X11/locale/iso8859-2/Compose", + "usr/share/X11/locale/iso8859-2/XI18N_OBJS", + "usr/share/X11/locale/iso8859-2/XLC_LOCALE", + "usr/share/X11/locale/iso8859-3/Compose", + "usr/share/X11/locale/iso8859-3/XI18N_OBJS", + "usr/share/X11/locale/iso8859-3/XLC_LOCALE", + "usr/share/X11/locale/iso8859-4/Compose", + "usr/share/X11/locale/iso8859-4/XI18N_OBJS", + "usr/share/X11/locale/iso8859-4/XLC_LOCALE", + "usr/share/X11/locale/iso8859-5/Compose", + "usr/share/X11/locale/iso8859-5/XI18N_OBJS", + "usr/share/X11/locale/iso8859-5/XLC_LOCALE", + "usr/share/X11/locale/iso8859-6/Compose", + "usr/share/X11/locale/iso8859-6/XI18N_OBJS", + "usr/share/X11/locale/iso8859-6/XLC_LOCALE", + "usr/share/X11/locale/iso8859-7/Compose", + "usr/share/X11/locale/iso8859-7/XI18N_OBJS", + "usr/share/X11/locale/iso8859-7/XLC_LOCALE", + "usr/share/X11/locale/iso8859-8/Compose", + "usr/share/X11/locale/iso8859-8/XI18N_OBJS", + "usr/share/X11/locale/iso8859-8/XLC_LOCALE", + "usr/share/X11/locale/iso8859-9/Compose", + "usr/share/X11/locale/iso8859-9/XI18N_OBJS", + "usr/share/X11/locale/iso8859-9/XLC_LOCALE", + "usr/share/X11/locale/iso8859-9e/Compose", + "usr/share/X11/locale/iso8859-9e/XI18N_OBJS", + "usr/share/X11/locale/iso8859-9e/XLC_LOCALE", + "usr/share/X11/locale/ja/Compose", + "usr/share/X11/locale/ja/XI18N_OBJS", + "usr/share/X11/locale/ja/XLC_LOCALE", + "usr/share/X11/locale/ja.JIS/Compose", + "usr/share/X11/locale/ja.JIS/XI18N_OBJS", + "usr/share/X11/locale/ja.JIS/XLC_LOCALE", + "usr/share/X11/locale/ja.SJIS/Compose", + "usr/share/X11/locale/ja.SJIS/XI18N_OBJS", + "usr/share/X11/locale/ja.SJIS/XLC_LOCALE", + "usr/share/X11/locale/ja_JP.UTF-8/Compose", + "usr/share/X11/locale/ja_JP.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/ja_JP.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/km_KH.UTF-8/Compose", + "usr/share/X11/locale/km_KH.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/km_KH.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/ko/Compose", + "usr/share/X11/locale/ko/XI18N_OBJS", + "usr/share/X11/locale/ko/XLC_LOCALE", + "usr/share/X11/locale/ko_KR.UTF-8/Compose", + "usr/share/X11/locale/ko_KR.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/ko_KR.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/koi8-c/Compose", + "usr/share/X11/locale/koi8-c/XI18N_OBJS", + "usr/share/X11/locale/koi8-c/XLC_LOCALE", + "usr/share/X11/locale/koi8-r/Compose", + "usr/share/X11/locale/koi8-r/XI18N_OBJS", + "usr/share/X11/locale/koi8-r/XLC_LOCALE", + "usr/share/X11/locale/koi8-u/Compose", + "usr/share/X11/locale/koi8-u/XI18N_OBJS", + "usr/share/X11/locale/koi8-u/XLC_LOCALE", + "usr/share/X11/locale/microsoft-cp1251/Compose", + "usr/share/X11/locale/microsoft-cp1251/XI18N_OBJS", + "usr/share/X11/locale/microsoft-cp1251/XLC_LOCALE", + "usr/share/X11/locale/microsoft-cp1255/Compose", + "usr/share/X11/locale/microsoft-cp1255/XI18N_OBJS", + "usr/share/X11/locale/microsoft-cp1255/XLC_LOCALE", + "usr/share/X11/locale/microsoft-cp1256/Compose", + "usr/share/X11/locale/microsoft-cp1256/XI18N_OBJS", + "usr/share/X11/locale/microsoft-cp1256/XLC_LOCALE", + "usr/share/X11/locale/mulelao-1/Compose", + "usr/share/X11/locale/mulelao-1/XI18N_OBJS", + "usr/share/X11/locale/mulelao-1/XLC_LOCALE", + "usr/share/X11/locale/nokhchi-1/Compose", + "usr/share/X11/locale/nokhchi-1/XI18N_OBJS", + "usr/share/X11/locale/nokhchi-1/XLC_LOCALE", + "usr/share/X11/locale/pt_BR.UTF-8/Compose", + "usr/share/X11/locale/pt_BR.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/pt_BR.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/pt_PT.UTF-8/Compose", + "usr/share/X11/locale/pt_PT.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/pt_PT.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/ru_RU.UTF-8/Compose", + "usr/share/X11/locale/ru_RU.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/ru_RU.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/sr_RS.UTF-8/Compose", + "usr/share/X11/locale/sr_RS.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/sr_RS.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/tatar-cyr/Compose", + "usr/share/X11/locale/tatar-cyr/XI18N_OBJS", + "usr/share/X11/locale/tatar-cyr/XLC_LOCALE", + "usr/share/X11/locale/th_TH/Compose", + "usr/share/X11/locale/th_TH/XI18N_OBJS", + "usr/share/X11/locale/th_TH/XLC_LOCALE", + "usr/share/X11/locale/th_TH.UTF-8/Compose", + "usr/share/X11/locale/th_TH.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/th_TH.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/tscii-0/Compose", + "usr/share/X11/locale/tscii-0/XI18N_OBJS", + "usr/share/X11/locale/tscii-0/XLC_LOCALE", + "usr/share/X11/locale/vi_VN.tcvn/Compose", + "usr/share/X11/locale/vi_VN.tcvn/XI18N_OBJS", + "usr/share/X11/locale/vi_VN.tcvn/XLC_LOCALE", + "usr/share/X11/locale/vi_VN.viscii/Compose", + "usr/share/X11/locale/vi_VN.viscii/XI18N_OBJS", + "usr/share/X11/locale/vi_VN.viscii/XLC_LOCALE", + "usr/share/X11/locale/zh_CN/Compose", + "usr/share/X11/locale/zh_CN/XI18N_OBJS", + "usr/share/X11/locale/zh_CN/XLC_LOCALE", + "usr/share/X11/locale/zh_CN.UTF-8/Compose", + "usr/share/X11/locale/zh_CN.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/zh_CN.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/zh_CN.gb18030/Compose", + "usr/share/X11/locale/zh_CN.gb18030/XI18N_OBJS", + "usr/share/X11/locale/zh_CN.gb18030/XLC_LOCALE", + "usr/share/X11/locale/zh_CN.gbk/Compose", + "usr/share/X11/locale/zh_CN.gbk/XI18N_OBJS", + "usr/share/X11/locale/zh_CN.gbk/XLC_LOCALE", + "usr/share/X11/locale/zh_HK.UTF-8/Compose", + "usr/share/X11/locale/zh_HK.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/zh_HK.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/zh_HK.big5/Compose", + "usr/share/X11/locale/zh_HK.big5/XI18N_OBJS", + "usr/share/X11/locale/zh_HK.big5/XLC_LOCALE", + "usr/share/X11/locale/zh_HK.big5hkscs/Compose", + "usr/share/X11/locale/zh_HK.big5hkscs/XI18N_OBJS", + "usr/share/X11/locale/zh_HK.big5hkscs/XLC_LOCALE", + "usr/share/X11/locale/zh_TW/Compose", + "usr/share/X11/locale/zh_TW/XI18N_OBJS", + "usr/share/X11/locale/zh_TW/XLC_LOCALE", + "usr/share/X11/locale/zh_TW.UTF-8/Compose", + "usr/share/X11/locale/zh_TW.UTF-8/XI18N_OBJS", + "usr/share/X11/locale/zh_TW.UTF-8/XLC_LOCALE", + "usr/share/X11/locale/zh_TW.big5/Compose", + "usr/share/X11/locale/zh_TW.big5/XI18N_OBJS", + "usr/share/X11/locale/zh_TW.big5/XLC_LOCALE" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxau@1.0.12-r0", + "Name": "libxau", + "Identifier": { + "PURL": "pkg:apk/alpine/libxau@1.0.12-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "d485bce96f246b42" + }, + "Version": "1.0.12-r0", + "Arch": "x86_64", + "SrcName": "libxau", + "SrcVersion": "1.0.12-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:89d2bc9daae3cb0e2ae095db6866357b7653f341", + "InstalledFiles": [ + "usr/lib/libXau.so.6", + "usr/lib/libXau.so.6.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxcb@1.17.0-r1", + "Name": "libxcb", + "Identifier": { + "PURL": "pkg:apk/alpine/libxcb@1.17.0-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "9257eaebc5b55b2" + }, + "Version": "1.17.0-r1", + "Arch": "x86_64", + "SrcName": "libxcb", + "SrcVersion": "1.17.0-r1", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libxau@1.0.12-r0", + "libxdmcp@1.1.5-r1", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:61b06f883e8f8d2d8ee360e4dac04ac037fcca13", + "InstalledFiles": [ + "usr/lib/libxcb-composite.so.0", + "usr/lib/libxcb-composite.so.0.0.0", + "usr/lib/libxcb-damage.so.0", + "usr/lib/libxcb-damage.so.0.0.0", + "usr/lib/libxcb-dbe.so.0", + "usr/lib/libxcb-dbe.so.0.0.0", + "usr/lib/libxcb-dpms.so.0", + "usr/lib/libxcb-dpms.so.0.0.0", + "usr/lib/libxcb-dri2.so.0", + "usr/lib/libxcb-dri2.so.0.0.0", + "usr/lib/libxcb-dri3.so.0", + "usr/lib/libxcb-dri3.so.0.1.0", + "usr/lib/libxcb-glx.so.0", + "usr/lib/libxcb-glx.so.0.0.0", + "usr/lib/libxcb-present.so.0", + "usr/lib/libxcb-present.so.0.0.0", + "usr/lib/libxcb-randr.so.0", + "usr/lib/libxcb-randr.so.0.1.0", + "usr/lib/libxcb-record.so.0", + "usr/lib/libxcb-record.so.0.0.0", + "usr/lib/libxcb-render.so.0", + "usr/lib/libxcb-render.so.0.0.0", + "usr/lib/libxcb-res.so.0", + "usr/lib/libxcb-res.so.0.0.0", + "usr/lib/libxcb-screensaver.so.0", + "usr/lib/libxcb-screensaver.so.0.0.0", + "usr/lib/libxcb-shape.so.0", + "usr/lib/libxcb-shape.so.0.0.0", + "usr/lib/libxcb-shm.so.0", + "usr/lib/libxcb-shm.so.0.0.0", + "usr/lib/libxcb-sync.so.1", + "usr/lib/libxcb-sync.so.1.0.0", + "usr/lib/libxcb-xf86dri.so.0", + "usr/lib/libxcb-xf86dri.so.0.0.0", + "usr/lib/libxcb-xfixes.so.0", + "usr/lib/libxcb-xfixes.so.0.0.0", + "usr/lib/libxcb-xinerama.so.0", + "usr/lib/libxcb-xinerama.so.0.0.0", + "usr/lib/libxcb-xinput.so.0", + "usr/lib/libxcb-xinput.so.0.1.0", + "usr/lib/libxcb-xkb.so.1", + "usr/lib/libxcb-xkb.so.1.0.0", + "usr/lib/libxcb-xtest.so.0", + "usr/lib/libxcb-xtest.so.0.0.0", + "usr/lib/libxcb-xv.so.0", + "usr/lib/libxcb-xv.so.0.0.0", + "usr/lib/libxcb-xvmc.so.0", + "usr/lib/libxcb-xvmc.so.0.0.0", + "usr/lib/libxcb.so.1", + "usr/lib/libxcb.so.1.1.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxdmcp@1.1.5-r1", + "Name": "libxdmcp", + "Identifier": { + "PURL": "pkg:apk/alpine/libxdmcp@1.1.5-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "4ce7671300ab208e" + }, + "Version": "1.1.5-r1", + "Arch": "x86_64", + "SrcName": "libxdmcp", + "SrcVersion": "1.1.5-r1", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libbsd@0.12.2-r0", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:99a24c0fa12282b5ef89a6e732a8d494b7696d9d", + "InstalledFiles": [ + "usr/lib/libXdmcp.so.6", + "usr/lib/libXdmcp.so.6.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxext@1.3.6-r2", + "Name": "libxext", + "Identifier": { + "PURL": "pkg:apk/alpine/libxext@1.3.6-r2?arch=x86_64\u0026distro=3.23.3", + "UID": "6995b5d26ca62497" + }, + "Version": "1.3.6-r2", + "Arch": "x86_64", + "SrcName": "libxext", + "SrcVersion": "1.3.6-r2", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libx11@1.8.12-r1", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:92fb4f12c2170403d6a48c7485ecaee40c84bee2", + "InstalledFiles": [ + "usr/lib/libXext.so.6", + "usr/lib/libXext.so.6.4.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxml2@2.13.9-r1", + "Name": "libxml2", + "Identifier": { + "PURL": "pkg:apk/alpine/libxml2@2.13.9-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "2941a74d1cbf0aeb" + }, + "Version": "2.13.9-r1", + "Arch": "x86_64", + "SrcName": "libxml2", + "SrcVersion": "2.13.9-r1", + "Licenses": [ + "MIT" + ], + "Maintainer": "Carlo Landmeter \u003cclandmeter@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23", + "xz-libs@5.8.4-r0", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:a980eed10c29299eeb02ffb3aa8bd4c34ebe822f", + "InstalledFiles": [ + "usr/lib/libxml2.so.2", + "usr/lib/libxml2.so.2.13.9" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxpm@3.5.19-r0", + "Name": "libxpm", + "Identifier": { + "PURL": "pkg:apk/alpine/libxpm@3.5.19-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "9eb303ee5fb7801a" + }, + "Version": "3.5.19-r0", + "Arch": "x86_64", + "SrcName": "libxpm", + "SrcVersion": "3.5.19-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libx11@1.8.12-r1", + "libxext@1.3.6-r2", + "libxt@1.3.1-r0", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:0c1b2467462bd516e1f3b514854ccca30e0e59c0", + "InstalledFiles": [ + "usr/bin/cxpm", + "usr/bin/sxpm", + "usr/lib/libXpm.so.4", + "usr/lib/libXpm.so.4.11.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxslt@1.1.43-r3", + "Name": "libxslt", + "Identifier": { + "PURL": "pkg:apk/alpine/libxslt@1.1.43-r3?arch=x86_64\u0026distro=3.23.3", + "UID": "e2008f246b5ab005" + }, + "Version": "1.1.43-r3", + "Arch": "x86_64", + "SrcName": "libxslt", + "SrcVersion": "1.1.43-r3", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libxml2@2.13.9-r1", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:7d73182371fbf2141e137329e5432b94551bdd1b", + "InstalledFiles": [ + "usr/bin/xsltproc", + "usr/lib/libexslt.so.0", + "usr/lib/libexslt.so.0.8.24", + "usr/lib/libxslt.so.1", + "usr/lib/libxslt.so.1.1.43" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libxt@1.3.1-r0", + "Name": "libxt", + "Identifier": { + "PURL": "pkg:apk/alpine/libxt@1.3.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "3def3ac035093072" + }, + "Version": "1.3.1-r0", + "Arch": "x86_64", + "SrcName": "libxt", + "SrcVersion": "1.3.1-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "libice@1.1.2-r0", + "libsm@1.2.6-r0", + "libx11@1.8.12-r1", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:1cffd892c392dcaac9ad017c999f9e268b5f8ee1", + "InstalledFiles": [ + "usr/lib/libXt.so.6", + "usr/lib/libXt.so.6.0.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "libyuv@0.0.1887.20251502-r1", + "Name": "libyuv", + "Identifier": { + "PURL": "pkg:apk/alpine/libyuv@0.0.1887.20251502-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "85b1ea36bf9f477d" + }, + "Version": "0.0.1887.20251502-r1", + "Arch": "x86_64", + "SrcName": "libyuv", + "SrcVersion": "0.0.1887.20251502-r1", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Andy Postnikov \u003capostnikov@gmail.com\u003e", + "DependsOn": [ + "libgcc@15.2.0-r2", + "libjpeg-turbo@3.1.2-r0", + "libstdc++@15.2.0-r2", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:8335fd57f5a479534322e6ac74968fdc7564d8d0", + "InstalledFiles": [ + "usr/bin/yuvconvert", + "usr/lib/libyuv.so" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "musl@1.2.5-r23", + "Name": "musl", + "Identifier": { + "PURL": "pkg:apk/alpine/musl@1.2.5-r23?arch=x86_64\u0026distro=3.23.3", + "UID": "dca30b3fd6708a32" + }, + "Version": "1.2.5-r23", + "Arch": "x86_64", + "SrcName": "musl", + "SrcVersion": "1.2.5-r23", + "Licenses": [ + "MIT" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:1b6c50426d3c0656e9c5a567a5a59601c7f4307a", + "InstalledFiles": [ + "lib/ld-musl-x86_64.so.1", + "lib/libc.musl-x86_64.so.1" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "musl-utils@1.2.5-r23", + "Name": "musl-utils", + "Identifier": { + "PURL": "pkg:apk/alpine/musl-utils@1.2.5-r23?arch=x86_64\u0026distro=3.23.3", + "UID": "ffcf7198a9776c5f" + }, + "Version": "1.2.5-r23", + "Arch": "x86_64", + "SrcName": "musl", + "SrcVersion": "1.2.5-r23", + "Licenses": [ + "MIT", + "BSD-2-Clause", + "GPL-2.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23", + "scanelf@1.3.8-r2" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:92fdbe96d25f13fe3a3d297ada56e4fb907aacec", + "InstalledFiles": [ + "sbin/ldconfig", + "usr/bin/getconf", + "usr/bin/getent", + "usr/bin/iconv", + "usr/bin/ldd" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ncurses-terminfo-base@6.5_p20251123-r0", + "Name": "ncurses-terminfo-base", + "Identifier": { + "PURL": "pkg:apk/alpine/ncurses-terminfo-base@6.5_p20251123-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "5acf10991828fa7a" + }, + "Version": "6.5_p20251123-r0", + "Arch": "x86_64", + "SrcName": "ncurses", + "SrcVersion": "6.5_p20251123-r0", + "Licenses": [ + "X-11" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:57bd1d8124ec957eefea2314bdf45b0ed1068cee", + "InstalledFiles": [ + "etc/terminfo/a/alacritty", + "etc/terminfo/a/ansi", + "etc/terminfo/d/dumb", + "etc/terminfo/g/gnome", + "etc/terminfo/g/gnome-256color", + "etc/terminfo/k/konsole", + "etc/terminfo/k/konsole-256color", + "etc/terminfo/k/konsole-linux", + "etc/terminfo/l/linux", + "etc/terminfo/p/putty", + "etc/terminfo/p/putty-256color", + "etc/terminfo/r/rxvt", + "etc/terminfo/r/rxvt-256color", + "etc/terminfo/s/screen", + "etc/terminfo/s/screen-256color", + "etc/terminfo/s/st-0.6", + "etc/terminfo/s/st-0.7", + "etc/terminfo/s/st-0.8", + "etc/terminfo/s/st-0.8.5", + "etc/terminfo/s/st-16color", + "etc/terminfo/s/st-256color", + "etc/terminfo/s/st-direct", + "etc/terminfo/s/sun", + "etc/terminfo/t/terminator", + "etc/terminfo/t/terminology", + "etc/terminfo/t/terminology-0.6.1", + "etc/terminfo/t/terminology-1.0.0", + "etc/terminfo/t/terminology-1.8.1", + "etc/terminfo/t/tmux", + "etc/terminfo/t/tmux-256color", + "etc/terminfo/v/vt100", + "etc/terminfo/v/vt102", + "etc/terminfo/v/vt200", + "etc/terminfo/v/vt220", + "etc/terminfo/v/vt52", + "etc/terminfo/v/vte", + "etc/terminfo/v/vte-256color", + "etc/terminfo/x/xterm", + "etc/terminfo/x/xterm-256color", + "etc/terminfo/x/xterm-color", + "etc/terminfo/x/xterm-xfree86" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nghttp2-libs@1.69.0-r0", + "Name": "nghttp2-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/nghttp2-libs@1.69.0-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "1d18d06a4faec59f" + }, + "Version": "1.69.0-r0", + "Arch": "x86_64", + "SrcName": "nghttp2", + "SrcVersion": "1.69.0-r0", + "Licenses": [ + "MIT" + ], + "Maintainer": "Francesco Colista \u003cfcolista@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:6b8651227dd3f9155ded30ddc171757a7f5b91a5", + "InstalledFiles": [ + "usr/lib/libnghttp2.so.14", + "usr/lib/libnghttp2.so.14.29.4" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nginx@1.28.3-r1", + "Name": "nginx", + "Identifier": { + "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8e6ca21a785dbb9c" + }, + "Version": "1.28.3-r1", + "Arch": "x86_64", + "SrcName": "nginx", + "SrcVersion": "1.28.3-r1", + "Licenses": [ + "2-clause", + "BSD-3-Clause", + "license" + ], + "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "libcrypto3@3.5.8-r0", + "libssl3@3.5.8-r0", + "musl@1.2.5-r23", + "pcre2@10.48-r0", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "Digest": "sha1:dea6a746d0881ec71c3ec7bd2e9e57640da2235f", + "InstalledFiles": [ + "etc/init.d/nginx", + "etc/init.d/nginx-debug", + "etc/logrotate.d/nginx", + "etc/nginx/fastcgi.conf", + "etc/nginx/fastcgi_params", + "etc/nginx/mime.types", + "etc/nginx/modules", + "etc/nginx/nginx.conf", + "etc/nginx/scgi_params", + "etc/nginx/uwsgi_params", + "etc/nginx/conf.d/default.conf", + "usr/sbin/nginx", + "usr/sbin/nginx-debug", + "usr/share/licenses/nginx/COPYRIGHT", + "usr/share/man/man8/nginx.8.gz", + "usr/share/nginx/html/50x.html", + "usr/share/nginx/html/index.html" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nginx-module-acme@1.28.3.0.3.1-r1", + "Name": "nginx-module-acme", + "Identifier": { + "PURL": "pkg:apk/alpine/nginx-module-acme@1.28.3.0.3.1-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c71336bbbfad7943" + }, + "Version": "1.28.3.0.3.1-r1", + "Arch": "x86_64", + "SrcName": "nginx-module-acme", + "SrcVersion": "1.28.3.0.3.1-r1", + "Licenses": [ + "2-clause", + "BSD-3-Clause", + "license" + ], + "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "libgcc@15.2.0-r2", + "musl@1.2.5-r23", + "nginx@1.28.3-r1" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:b108c1a13c4b8b83c6a784405dbbad1f91c757c2", + "InstalledFiles": [ + "usr/lib/nginx/modules/ngx_http_acme_module-debug.so", + "usr/lib/nginx/modules/ngx_http_acme_module.so", + "usr/share/licenses/nginx-module-acme/COPYRIGHT" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nginx-module-geoip@1.28.3-r1", + "Name": "nginx-module-geoip", + "Identifier": { + "PURL": "pkg:apk/alpine/nginx-module-geoip@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "af63b053d0b0f94a" + }, + "Version": "1.28.3-r1", + "Arch": "x86_64", + "SrcName": "nginx-module-geoip", + "SrcVersion": "1.28.3-r1", + "Licenses": [ + "2-clause", + "BSD-3-Clause", + "license" + ], + "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "geoip@1.6.12-r6", + "musl@1.2.5-r23", + "nginx@1.28.3-r1" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:bacb3265dfe077670e913138a0c21da9fb929d90", + "InstalledFiles": [ + "usr/lib/nginx/modules/ngx_http_geoip_module-debug.so", + "usr/lib/nginx/modules/ngx_http_geoip_module.so", + "usr/lib/nginx/modules/ngx_stream_geoip_module-debug.so", + "usr/lib/nginx/modules/ngx_stream_geoip_module.so", + "usr/share/licenses/nginx-module-geoip/COPYRIGHT" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nginx-module-image-filter@1.28.3-r1", + "Name": "nginx-module-image-filter", + "Identifier": { + "PURL": "pkg:apk/alpine/nginx-module-image-filter@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "fe070e0889702ce0" + }, + "Version": "1.28.3-r1", + "Arch": "x86_64", + "SrcName": "nginx-module-image-filter", + "SrcVersion": "1.28.3-r1", + "Licenses": [ + "2-clause", + "BSD-3-Clause", + "license" + ], + "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "libgd@2.3.3-r10", + "musl@1.2.5-r23", + "nginx@1.28.3-r1" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:60b0b0c575765646982023c66f7bb95ad4670307", + "InstalledFiles": [ + "usr/lib/nginx/modules/ngx_http_image_filter_module-debug.so", + "usr/lib/nginx/modules/ngx_http_image_filter_module.so", + "usr/share/licenses/nginx-module-image-filter/COPYRIGHT" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nginx-module-njs@1.28.3.0.9.6-r1", + "Name": "nginx-module-njs", + "Identifier": { + "PURL": "pkg:apk/alpine/nginx-module-njs@1.28.3.0.9.6-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "c460d6b01308ec2d" + }, + "Version": "1.28.3.0.9.6-r1", + "Arch": "x86_64", + "SrcName": "nginx-module-njs", + "SrcVersion": "1.28.3.0.9.6-r1", + "Licenses": [ + "2-clause", + "BSD-3-Clause", + "license" + ], + "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "libcrypto3@3.5.8-r0", + "libedit@20251016.3.1-r0", + "libxml2@2.13.9-r1", + "musl@1.2.5-r23", + "nginx@1.28.3-r1", + "pcre2@10.48-r0", + "zlib@1.3.2-r0" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:a24eaada9c23702c483244875e7336738bc5a815", + "InstalledFiles": [ + "usr/bin/njs", + "usr/lib/nginx/modules/ngx_http_js_module-debug.so", + "usr/lib/nginx/modules/ngx_http_js_module.so", + "usr/lib/nginx/modules/ngx_stream_js_module-debug.so", + "usr/lib/nginx/modules/ngx_stream_js_module.so", + "usr/share/doc/nginx-module-njs/CHANGES", + "usr/share/licenses/nginx-module-njs/COPYRIGHT" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "nginx-module-xslt@1.28.3-r1", + "Name": "nginx-module-xslt", + "Identifier": { + "PURL": "pkg:apk/alpine/nginx-module-xslt@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "fd88a03b765b4f91" + }, + "Version": "1.28.3-r1", + "Arch": "x86_64", + "SrcName": "nginx-module-xslt", + "SrcVersion": "1.28.3-r1", + "Licenses": [ + "2-clause", + "BSD-3-Clause", + "license" + ], + "Maintainer": "NGINX Packaging \u003cnginx-packaging@f5.com\u003e", + "DependsOn": [ + "busybox-binsh@1.37.0-r30", + "libxml2@2.13.9-r1", + "libxslt@1.1.43-r3", + "musl@1.2.5-r23", + "nginx@1.28.3-r1" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:0e3a923995439eea4163e4d6b8f80a5748ef2bdb", + "InstalledFiles": [ + "usr/lib/nginx/modules/ngx_http_xslt_filter_module-debug.so", + "usr/lib/nginx/modules/ngx_http_xslt_filter_module.so", + "usr/share/licenses/nginx-module-xslt/COPYRIGHT" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "pcre2@10.48-r0", + "Name": "pcre2", + "Identifier": { + "PURL": "pkg:apk/alpine/pcre2@10.48-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "ff67ef0177db70c5" + }, + "Version": "10.48-r0", + "Arch": "x86_64", + "SrcName": "pcre2", + "SrcVersion": "10.48-r0", + "Licenses": [ + "BSD-3-Clause" + ], + "Maintainer": "Jakub Jirutka \u003cjakub@jirutka.cz\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:a7915ddb709497cf2ebcb53ef7fed908eb32d0d6", + "InstalledFiles": [ + "usr/lib/libpcre2-8.so.0", + "usr/lib/libpcre2-8.so.0.16.0", + "usr/lib/libpcre2-posix.so.3", + "usr/lib/libpcre2-posix.so.3.0.8" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "scanelf@1.3.8-r2", + "Name": "scanelf", + "Identifier": { + "PURL": "pkg:apk/alpine/scanelf@1.3.8-r2?arch=x86_64\u0026distro=3.23.3", + "UID": "4efd612ed6f16dca" + }, + "Version": "1.3.8-r2", + "Arch": "x86_64", + "SrcName": "pax-utils", + "SrcVersion": "1.3.8-r2", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:6ea36dd44ef9f6364f0cdfabe09ea15d2fdbe229", + "InstalledFiles": [ + "usr/bin/scanelf" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "ssl_client@1.37.0-r30", + "Name": "ssl_client", + "Identifier": { + "PURL": "pkg:apk/alpine/ssl_client@1.37.0-r30?arch=x86_64\u0026distro=3.23.3", + "UID": "92299c558ff421b3" + }, + "Version": "1.37.0-r30", + "Arch": "x86_64", + "SrcName": "busybox", + "SrcVersion": "1.37.0-r30", + "Licenses": [ + "GPL-2.0-only" + ], + "Maintainer": "Sören Tempel \u003csoeren+alpine@soeren-tempel.net\u003e", + "DependsOn": [ + "libcrypto3@3.5.8-r0", + "libssl3@3.5.8-r0", + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:589002ba0eaed121a1dbf42f6648f29e5be55d5c8a6ee0f8eaa0285cc21ac153", + "DiffID": "sha256:989e799e634906e94dc9a5ee2ee26fc92ad260522990f26e707861a5f52bf64e" + }, + "Digest": "sha1:5b6ec0939cfc9be47d9677a3152c547cc18b5edd", + "InstalledFiles": [ + "usr/bin/ssl_client" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "tiff@4.7.1-r0", + "Name": "tiff", + "Identifier": { + "PURL": "pkg:apk/alpine/tiff@4.7.1-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "551adcb8b716f210" + }, + "Version": "4.7.1-r0", + "Arch": "x86_64", + "SrcName": "tiff", + "SrcVersion": "4.7.1-r0", + "Licenses": [ + "libtiff" + ], + "Maintainer": "Michael Mason \u003cms13sp@gmail.com\u003e", + "DependsOn": [ + "libjpeg-turbo@3.1.2-r0", + "libwebp@1.6.0-r0", + "musl@1.2.5-r23", + "zlib@1.3.2-r0", + "zstd-libs@1.5.7-r2" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:b92c3394d281f51345a9375da14f347b6c1619a6", + "InstalledFiles": [ + "usr/lib/libtiff.so.6", + "usr/lib/libtiff.so.6.2.0" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "tzdata@2026c-r0", + "Name": "tzdata", + "Identifier": { + "PURL": "pkg:apk/alpine/tzdata@2026c-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "e471ecd044c6763" + }, + "Version": "2026c-r0", + "Arch": "x86_64", + "SrcName": "tzdata", + "SrcVersion": "2026c-r0", + "Licenses": [ + "Public-Domain" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:5449aeb87c78a380a49320e1f98f67b13b1828a7", + "InstalledFiles": [ + "usr/share/zoneinfo/CET", + "usr/share/zoneinfo/CST6CDT", + "usr/share/zoneinfo/Cuba", + "usr/share/zoneinfo/EET", + "usr/share/zoneinfo/EST", + "usr/share/zoneinfo/EST5EDT", + "usr/share/zoneinfo/Egypt", + "usr/share/zoneinfo/Eire", + "usr/share/zoneinfo/Factory", + "usr/share/zoneinfo/GB", + "usr/share/zoneinfo/GB-Eire", + "usr/share/zoneinfo/GMT", + "usr/share/zoneinfo/GMT+0", + "usr/share/zoneinfo/GMT-0", + "usr/share/zoneinfo/GMT0", + "usr/share/zoneinfo/Greenwich", + "usr/share/zoneinfo/HST", + "usr/share/zoneinfo/Hongkong", + "usr/share/zoneinfo/Iceland", + "usr/share/zoneinfo/Iran", + "usr/share/zoneinfo/Israel", + "usr/share/zoneinfo/Jamaica", + "usr/share/zoneinfo/Japan", + "usr/share/zoneinfo/Kwajalein", + "usr/share/zoneinfo/Libya", + "usr/share/zoneinfo/MET", + "usr/share/zoneinfo/MST", + "usr/share/zoneinfo/MST7MDT", + "usr/share/zoneinfo/NZ", + "usr/share/zoneinfo/NZ-CHAT", + "usr/share/zoneinfo/Navajo", + "usr/share/zoneinfo/PRC", + "usr/share/zoneinfo/PST8PDT", + "usr/share/zoneinfo/Poland", + "usr/share/zoneinfo/Portugal", + "usr/share/zoneinfo/ROC", + "usr/share/zoneinfo/ROK", + "usr/share/zoneinfo/Singapore", + "usr/share/zoneinfo/Turkey", + "usr/share/zoneinfo/UCT", + "usr/share/zoneinfo/UTC", + "usr/share/zoneinfo/Universal", + "usr/share/zoneinfo/W-SU", + "usr/share/zoneinfo/WET", + "usr/share/zoneinfo/Zulu", + "usr/share/zoneinfo/iso3166.tab", + "usr/share/zoneinfo/leap-seconds.list", + "usr/share/zoneinfo/posixrules", + "usr/share/zoneinfo/zone.tab", + "usr/share/zoneinfo/zone1970.tab", + "usr/share/zoneinfo/Africa/Abidjan", + "usr/share/zoneinfo/Africa/Accra", + "usr/share/zoneinfo/Africa/Addis_Ababa", + "usr/share/zoneinfo/Africa/Algiers", + "usr/share/zoneinfo/Africa/Asmara", + "usr/share/zoneinfo/Africa/Asmera", + "usr/share/zoneinfo/Africa/Bamako", + "usr/share/zoneinfo/Africa/Bangui", + "usr/share/zoneinfo/Africa/Banjul", + "usr/share/zoneinfo/Africa/Bissau", + "usr/share/zoneinfo/Africa/Blantyre", + "usr/share/zoneinfo/Africa/Brazzaville", + "usr/share/zoneinfo/Africa/Bujumbura", + "usr/share/zoneinfo/Africa/Cairo", + "usr/share/zoneinfo/Africa/Casablanca", + "usr/share/zoneinfo/Africa/Ceuta", + "usr/share/zoneinfo/Africa/Conakry", + "usr/share/zoneinfo/Africa/Dakar", + "usr/share/zoneinfo/Africa/Dar_es_Salaam", + "usr/share/zoneinfo/Africa/Djibouti", + "usr/share/zoneinfo/Africa/Douala", + "usr/share/zoneinfo/Africa/El_Aaiun", + "usr/share/zoneinfo/Africa/Freetown", + "usr/share/zoneinfo/Africa/Gaborone", + "usr/share/zoneinfo/Africa/Harare", + "usr/share/zoneinfo/Africa/Johannesburg", + "usr/share/zoneinfo/Africa/Juba", + "usr/share/zoneinfo/Africa/Kampala", + "usr/share/zoneinfo/Africa/Khartoum", + "usr/share/zoneinfo/Africa/Kigali", + "usr/share/zoneinfo/Africa/Kinshasa", + "usr/share/zoneinfo/Africa/Lagos", + "usr/share/zoneinfo/Africa/Libreville", + "usr/share/zoneinfo/Africa/Lome", + "usr/share/zoneinfo/Africa/Luanda", + "usr/share/zoneinfo/Africa/Lubumbashi", + "usr/share/zoneinfo/Africa/Lusaka", + "usr/share/zoneinfo/Africa/Malabo", + "usr/share/zoneinfo/Africa/Maputo", + "usr/share/zoneinfo/Africa/Maseru", + "usr/share/zoneinfo/Africa/Mbabane", + "usr/share/zoneinfo/Africa/Mogadishu", + "usr/share/zoneinfo/Africa/Monrovia", + "usr/share/zoneinfo/Africa/Nairobi", + "usr/share/zoneinfo/Africa/Ndjamena", + "usr/share/zoneinfo/Africa/Niamey", + "usr/share/zoneinfo/Africa/Nouakchott", + "usr/share/zoneinfo/Africa/Ouagadougou", + "usr/share/zoneinfo/Africa/Porto-Novo", + "usr/share/zoneinfo/Africa/Sao_Tome", + "usr/share/zoneinfo/Africa/Timbuktu", + "usr/share/zoneinfo/Africa/Tripoli", + "usr/share/zoneinfo/Africa/Tunis", + "usr/share/zoneinfo/Africa/Windhoek", + "usr/share/zoneinfo/America/Adak", + "usr/share/zoneinfo/America/Anchorage", + "usr/share/zoneinfo/America/Anguilla", + "usr/share/zoneinfo/America/Antigua", + "usr/share/zoneinfo/America/Araguaina", + "usr/share/zoneinfo/America/Aruba", + "usr/share/zoneinfo/America/Asuncion", + "usr/share/zoneinfo/America/Atikokan", + "usr/share/zoneinfo/America/Atka", + "usr/share/zoneinfo/America/Bahia", + "usr/share/zoneinfo/America/Bahia_Banderas", + "usr/share/zoneinfo/America/Barbados", + "usr/share/zoneinfo/America/Belem", + "usr/share/zoneinfo/America/Belize", + "usr/share/zoneinfo/America/Blanc-Sablon", + "usr/share/zoneinfo/America/Boa_Vista", + "usr/share/zoneinfo/America/Bogota", + "usr/share/zoneinfo/America/Boise", + "usr/share/zoneinfo/America/Buenos_Aires", + "usr/share/zoneinfo/America/Cambridge_Bay", + "usr/share/zoneinfo/America/Campo_Grande", + "usr/share/zoneinfo/America/Cancun", + "usr/share/zoneinfo/America/Caracas", + "usr/share/zoneinfo/America/Catamarca", + "usr/share/zoneinfo/America/Cayenne", + "usr/share/zoneinfo/America/Cayman", + "usr/share/zoneinfo/America/Chicago", + "usr/share/zoneinfo/America/Chihuahua", + "usr/share/zoneinfo/America/Ciudad_Juarez", + "usr/share/zoneinfo/America/Coral_Harbour", + "usr/share/zoneinfo/America/Cordoba", + "usr/share/zoneinfo/America/Costa_Rica", + "usr/share/zoneinfo/America/Coyhaique", + "usr/share/zoneinfo/America/Creston", + "usr/share/zoneinfo/America/Cuiaba", + "usr/share/zoneinfo/America/Curacao", + "usr/share/zoneinfo/America/Danmarkshavn", + "usr/share/zoneinfo/America/Dawson", + "usr/share/zoneinfo/America/Dawson_Creek", + "usr/share/zoneinfo/America/Denver", + "usr/share/zoneinfo/America/Detroit", + "usr/share/zoneinfo/America/Dominica", + "usr/share/zoneinfo/America/Edmonton", + "usr/share/zoneinfo/America/Eirunepe", + "usr/share/zoneinfo/America/El_Salvador", + "usr/share/zoneinfo/America/Ensenada", + "usr/share/zoneinfo/America/Fort_Nelson", + "usr/share/zoneinfo/America/Fort_Wayne", + "usr/share/zoneinfo/America/Fortaleza", + "usr/share/zoneinfo/America/Glace_Bay", + "usr/share/zoneinfo/America/Godthab", + "usr/share/zoneinfo/America/Goose_Bay", + "usr/share/zoneinfo/America/Grand_Turk", + "usr/share/zoneinfo/America/Grenada", + "usr/share/zoneinfo/America/Guadeloupe", + "usr/share/zoneinfo/America/Guatemala", + "usr/share/zoneinfo/America/Guayaquil", + "usr/share/zoneinfo/America/Guyana", + "usr/share/zoneinfo/America/Halifax", + "usr/share/zoneinfo/America/Havana", + "usr/share/zoneinfo/America/Hermosillo", + "usr/share/zoneinfo/America/Indianapolis", + "usr/share/zoneinfo/America/Inuvik", + "usr/share/zoneinfo/America/Iqaluit", + "usr/share/zoneinfo/America/Jamaica", + "usr/share/zoneinfo/America/Jujuy", + "usr/share/zoneinfo/America/Juneau", + "usr/share/zoneinfo/America/Knox_IN", + "usr/share/zoneinfo/America/Kralendijk", + "usr/share/zoneinfo/America/La_Paz", + "usr/share/zoneinfo/America/Lima", + "usr/share/zoneinfo/America/Los_Angeles", + "usr/share/zoneinfo/America/Louisville", + "usr/share/zoneinfo/America/Lower_Princes", + "usr/share/zoneinfo/America/Maceio", + "usr/share/zoneinfo/America/Managua", + "usr/share/zoneinfo/America/Manaus", + "usr/share/zoneinfo/America/Marigot", + "usr/share/zoneinfo/America/Martinique", + "usr/share/zoneinfo/America/Matamoros", + "usr/share/zoneinfo/America/Mazatlan", + "usr/share/zoneinfo/America/Mendoza", + "usr/share/zoneinfo/America/Menominee", + "usr/share/zoneinfo/America/Merida", + "usr/share/zoneinfo/America/Metlakatla", + "usr/share/zoneinfo/America/Mexico_City", + "usr/share/zoneinfo/America/Miquelon", + "usr/share/zoneinfo/America/Moncton", + "usr/share/zoneinfo/America/Monterrey", + "usr/share/zoneinfo/America/Montevideo", + "usr/share/zoneinfo/America/Montreal", + "usr/share/zoneinfo/America/Montserrat", + "usr/share/zoneinfo/America/Nassau", + "usr/share/zoneinfo/America/New_York", + "usr/share/zoneinfo/America/Nipigon", + "usr/share/zoneinfo/America/Nome", + "usr/share/zoneinfo/America/Noronha", + "usr/share/zoneinfo/America/Nuuk", + "usr/share/zoneinfo/America/Ojinaga", + "usr/share/zoneinfo/America/Panama", + "usr/share/zoneinfo/America/Pangnirtung", + "usr/share/zoneinfo/America/Paramaribo", + "usr/share/zoneinfo/America/Phoenix", + "usr/share/zoneinfo/America/Port-au-Prince", + "usr/share/zoneinfo/America/Port_of_Spain", + "usr/share/zoneinfo/America/Porto_Acre", + "usr/share/zoneinfo/America/Porto_Velho", + "usr/share/zoneinfo/America/Puerto_Rico", + "usr/share/zoneinfo/America/Punta_Arenas", + "usr/share/zoneinfo/America/Rainy_River", + "usr/share/zoneinfo/America/Rankin_Inlet", + "usr/share/zoneinfo/America/Recife", + "usr/share/zoneinfo/America/Regina", + "usr/share/zoneinfo/America/Resolute", + "usr/share/zoneinfo/America/Rio_Branco", + "usr/share/zoneinfo/America/Rosario", + "usr/share/zoneinfo/America/Santa_Isabel", + "usr/share/zoneinfo/America/Santarem", + "usr/share/zoneinfo/America/Santiago", + "usr/share/zoneinfo/America/Santo_Domingo", + "usr/share/zoneinfo/America/Sao_Paulo", + "usr/share/zoneinfo/America/Scoresbysund", + "usr/share/zoneinfo/America/Shiprock", + "usr/share/zoneinfo/America/Sitka", + "usr/share/zoneinfo/America/St_Barthelemy", + "usr/share/zoneinfo/America/St_Johns", + "usr/share/zoneinfo/America/St_Kitts", + "usr/share/zoneinfo/America/St_Lucia", + "usr/share/zoneinfo/America/St_Thomas", + "usr/share/zoneinfo/America/St_Vincent", + "usr/share/zoneinfo/America/Swift_Current", + "usr/share/zoneinfo/America/Tegucigalpa", + "usr/share/zoneinfo/America/Thule", + "usr/share/zoneinfo/America/Thunder_Bay", + "usr/share/zoneinfo/America/Tijuana", + "usr/share/zoneinfo/America/Toronto", + "usr/share/zoneinfo/America/Tortola", + "usr/share/zoneinfo/America/Vancouver", + "usr/share/zoneinfo/America/Virgin", + "usr/share/zoneinfo/America/Whitehorse", + "usr/share/zoneinfo/America/Winnipeg", + "usr/share/zoneinfo/America/Yakutat", + "usr/share/zoneinfo/America/Yellowknife", + "usr/share/zoneinfo/America/Argentina/Buenos_Aires", + "usr/share/zoneinfo/America/Argentina/Catamarca", + "usr/share/zoneinfo/America/Argentina/ComodRivadavia", + "usr/share/zoneinfo/America/Argentina/Cordoba", + "usr/share/zoneinfo/America/Argentina/Jujuy", + "usr/share/zoneinfo/America/Argentina/La_Rioja", + "usr/share/zoneinfo/America/Argentina/Mendoza", + "usr/share/zoneinfo/America/Argentina/Rio_Gallegos", + "usr/share/zoneinfo/America/Argentina/Salta", + "usr/share/zoneinfo/America/Argentina/San_Juan", + "usr/share/zoneinfo/America/Argentina/San_Luis", + "usr/share/zoneinfo/America/Argentina/Tucuman", + "usr/share/zoneinfo/America/Argentina/Ushuaia", + "usr/share/zoneinfo/America/Indiana/Indianapolis", + "usr/share/zoneinfo/America/Indiana/Knox", + "usr/share/zoneinfo/America/Indiana/Marengo", + "usr/share/zoneinfo/America/Indiana/Petersburg", + "usr/share/zoneinfo/America/Indiana/Tell_City", + "usr/share/zoneinfo/America/Indiana/Vevay", + "usr/share/zoneinfo/America/Indiana/Vincennes", + "usr/share/zoneinfo/America/Indiana/Winamac", + "usr/share/zoneinfo/America/Kentucky/Louisville", + "usr/share/zoneinfo/America/Kentucky/Monticello", + "usr/share/zoneinfo/America/North_Dakota/Beulah", + "usr/share/zoneinfo/America/North_Dakota/Center", + "usr/share/zoneinfo/America/North_Dakota/New_Salem", + "usr/share/zoneinfo/Antarctica/Casey", + "usr/share/zoneinfo/Antarctica/Davis", + "usr/share/zoneinfo/Antarctica/DumontDUrville", + "usr/share/zoneinfo/Antarctica/Macquarie", + "usr/share/zoneinfo/Antarctica/Mawson", + "usr/share/zoneinfo/Antarctica/McMurdo", + "usr/share/zoneinfo/Antarctica/Palmer", + "usr/share/zoneinfo/Antarctica/Rothera", + "usr/share/zoneinfo/Antarctica/South_Pole", + "usr/share/zoneinfo/Antarctica/Syowa", + "usr/share/zoneinfo/Antarctica/Troll", + "usr/share/zoneinfo/Antarctica/Vostok", + "usr/share/zoneinfo/Arctic/Longyearbyen", + "usr/share/zoneinfo/Asia/Aden", + "usr/share/zoneinfo/Asia/Almaty", + "usr/share/zoneinfo/Asia/Amman", + "usr/share/zoneinfo/Asia/Anadyr", + "usr/share/zoneinfo/Asia/Aqtau", + "usr/share/zoneinfo/Asia/Aqtobe", + "usr/share/zoneinfo/Asia/Ashgabat", + "usr/share/zoneinfo/Asia/Ashkhabad", + "usr/share/zoneinfo/Asia/Atyrau", + "usr/share/zoneinfo/Asia/Baghdad", + "usr/share/zoneinfo/Asia/Bahrain", + "usr/share/zoneinfo/Asia/Baku", + "usr/share/zoneinfo/Asia/Bangkok", + "usr/share/zoneinfo/Asia/Barnaul", + "usr/share/zoneinfo/Asia/Beirut", + "usr/share/zoneinfo/Asia/Bishkek", + "usr/share/zoneinfo/Asia/Brunei", + "usr/share/zoneinfo/Asia/Calcutta", + "usr/share/zoneinfo/Asia/Chita", + "usr/share/zoneinfo/Asia/Choibalsan", + "usr/share/zoneinfo/Asia/Chongqing", + "usr/share/zoneinfo/Asia/Chungking", + "usr/share/zoneinfo/Asia/Colombo", + "usr/share/zoneinfo/Asia/Dacca", + "usr/share/zoneinfo/Asia/Damascus", + "usr/share/zoneinfo/Asia/Dhaka", + "usr/share/zoneinfo/Asia/Dili", + "usr/share/zoneinfo/Asia/Dubai", + "usr/share/zoneinfo/Asia/Dushanbe", + "usr/share/zoneinfo/Asia/Famagusta", + "usr/share/zoneinfo/Asia/Gaza", + "usr/share/zoneinfo/Asia/Harbin", + "usr/share/zoneinfo/Asia/Hebron", + "usr/share/zoneinfo/Asia/Ho_Chi_Minh", + "usr/share/zoneinfo/Asia/Hong_Kong", + "usr/share/zoneinfo/Asia/Hovd", + "usr/share/zoneinfo/Asia/Irkutsk", + "usr/share/zoneinfo/Asia/Istanbul", + "usr/share/zoneinfo/Asia/Jakarta", + "usr/share/zoneinfo/Asia/Jayapura", + "usr/share/zoneinfo/Asia/Jerusalem", + "usr/share/zoneinfo/Asia/Kabul", + "usr/share/zoneinfo/Asia/Kamchatka", + "usr/share/zoneinfo/Asia/Karachi", + "usr/share/zoneinfo/Asia/Kashgar", + "usr/share/zoneinfo/Asia/Kathmandu", + "usr/share/zoneinfo/Asia/Katmandu", + "usr/share/zoneinfo/Asia/Khandyga", + "usr/share/zoneinfo/Asia/Kolkata", + "usr/share/zoneinfo/Asia/Krasnoyarsk", + "usr/share/zoneinfo/Asia/Kuala_Lumpur", + "usr/share/zoneinfo/Asia/Kuching", + "usr/share/zoneinfo/Asia/Kuwait", + "usr/share/zoneinfo/Asia/Macao", + "usr/share/zoneinfo/Asia/Macau", + "usr/share/zoneinfo/Asia/Magadan", + "usr/share/zoneinfo/Asia/Makassar", + "usr/share/zoneinfo/Asia/Manila", + "usr/share/zoneinfo/Asia/Muscat", + "usr/share/zoneinfo/Asia/Nicosia", + "usr/share/zoneinfo/Asia/Novokuznetsk", + "usr/share/zoneinfo/Asia/Novosibirsk", + "usr/share/zoneinfo/Asia/Omsk", + "usr/share/zoneinfo/Asia/Oral", + "usr/share/zoneinfo/Asia/Phnom_Penh", + "usr/share/zoneinfo/Asia/Pontianak", + "usr/share/zoneinfo/Asia/Pyongyang", + "usr/share/zoneinfo/Asia/Qatar", + "usr/share/zoneinfo/Asia/Qostanay", + "usr/share/zoneinfo/Asia/Qyzylorda", + "usr/share/zoneinfo/Asia/Rangoon", + "usr/share/zoneinfo/Asia/Riyadh", + "usr/share/zoneinfo/Asia/Saigon", + "usr/share/zoneinfo/Asia/Sakhalin", + "usr/share/zoneinfo/Asia/Samarkand", + "usr/share/zoneinfo/Asia/Seoul", + "usr/share/zoneinfo/Asia/Shanghai", + "usr/share/zoneinfo/Asia/Singapore", + "usr/share/zoneinfo/Asia/Srednekolymsk", + "usr/share/zoneinfo/Asia/Taipei", + "usr/share/zoneinfo/Asia/Tashkent", + "usr/share/zoneinfo/Asia/Tbilisi", + "usr/share/zoneinfo/Asia/Tehran", + "usr/share/zoneinfo/Asia/Tel_Aviv", + "usr/share/zoneinfo/Asia/Thimbu", + "usr/share/zoneinfo/Asia/Thimphu", + "usr/share/zoneinfo/Asia/Tokyo", + "usr/share/zoneinfo/Asia/Tomsk", + "usr/share/zoneinfo/Asia/Ujung_Pandang", + "usr/share/zoneinfo/Asia/Ulaanbaatar", + "usr/share/zoneinfo/Asia/Ulan_Bator", + "usr/share/zoneinfo/Asia/Urumqi", + "usr/share/zoneinfo/Asia/Ust-Nera", + "usr/share/zoneinfo/Asia/Vientiane", + "usr/share/zoneinfo/Asia/Vladivostok", + "usr/share/zoneinfo/Asia/Yakutsk", + "usr/share/zoneinfo/Asia/Yangon", + "usr/share/zoneinfo/Asia/Yekaterinburg", + "usr/share/zoneinfo/Asia/Yerevan", + "usr/share/zoneinfo/Atlantic/Azores", + "usr/share/zoneinfo/Atlantic/Bermuda", + "usr/share/zoneinfo/Atlantic/Canary", + "usr/share/zoneinfo/Atlantic/Cape_Verde", + "usr/share/zoneinfo/Atlantic/Faeroe", + "usr/share/zoneinfo/Atlantic/Faroe", + "usr/share/zoneinfo/Atlantic/Jan_Mayen", + "usr/share/zoneinfo/Atlantic/Madeira", + "usr/share/zoneinfo/Atlantic/Reykjavik", + "usr/share/zoneinfo/Atlantic/South_Georgia", + "usr/share/zoneinfo/Atlantic/St_Helena", + "usr/share/zoneinfo/Atlantic/Stanley", + "usr/share/zoneinfo/Australia/ACT", + "usr/share/zoneinfo/Australia/Adelaide", + "usr/share/zoneinfo/Australia/Brisbane", + "usr/share/zoneinfo/Australia/Broken_Hill", + "usr/share/zoneinfo/Australia/Canberra", + "usr/share/zoneinfo/Australia/Currie", + "usr/share/zoneinfo/Australia/Darwin", + "usr/share/zoneinfo/Australia/Eucla", + "usr/share/zoneinfo/Australia/Hobart", + "usr/share/zoneinfo/Australia/LHI", + "usr/share/zoneinfo/Australia/Lindeman", + "usr/share/zoneinfo/Australia/Lord_Howe", + "usr/share/zoneinfo/Australia/Melbourne", + "usr/share/zoneinfo/Australia/NSW", + "usr/share/zoneinfo/Australia/North", + "usr/share/zoneinfo/Australia/Perth", + "usr/share/zoneinfo/Australia/Queensland", + "usr/share/zoneinfo/Australia/South", + "usr/share/zoneinfo/Australia/Sydney", + "usr/share/zoneinfo/Australia/Tasmania", + "usr/share/zoneinfo/Australia/Victoria", + "usr/share/zoneinfo/Australia/West", + "usr/share/zoneinfo/Australia/Yancowinna", + "usr/share/zoneinfo/Brazil/Acre", + "usr/share/zoneinfo/Brazil/DeNoronha", + "usr/share/zoneinfo/Brazil/East", + "usr/share/zoneinfo/Brazil/West", + "usr/share/zoneinfo/Canada/Atlantic", + "usr/share/zoneinfo/Canada/Central", + "usr/share/zoneinfo/Canada/Eastern", + "usr/share/zoneinfo/Canada/Mountain", + "usr/share/zoneinfo/Canada/Newfoundland", + "usr/share/zoneinfo/Canada/Pacific", + "usr/share/zoneinfo/Canada/Saskatchewan", + "usr/share/zoneinfo/Canada/Yukon", + "usr/share/zoneinfo/Chile/Continental", + "usr/share/zoneinfo/Chile/EasterIsland", + "usr/share/zoneinfo/Etc/GMT", + "usr/share/zoneinfo/Etc/GMT+0", + "usr/share/zoneinfo/Etc/GMT+1", + "usr/share/zoneinfo/Etc/GMT+10", + "usr/share/zoneinfo/Etc/GMT+11", + "usr/share/zoneinfo/Etc/GMT+12", + "usr/share/zoneinfo/Etc/GMT+2", + "usr/share/zoneinfo/Etc/GMT+3", + "usr/share/zoneinfo/Etc/GMT+4", + "usr/share/zoneinfo/Etc/GMT+5", + "usr/share/zoneinfo/Etc/GMT+6", + "usr/share/zoneinfo/Etc/GMT+7", + "usr/share/zoneinfo/Etc/GMT+8", + "usr/share/zoneinfo/Etc/GMT+9", + "usr/share/zoneinfo/Etc/GMT-0", + "usr/share/zoneinfo/Etc/GMT-1", + "usr/share/zoneinfo/Etc/GMT-10", + "usr/share/zoneinfo/Etc/GMT-11", + "usr/share/zoneinfo/Etc/GMT-12", + "usr/share/zoneinfo/Etc/GMT-13", + "usr/share/zoneinfo/Etc/GMT-14", + "usr/share/zoneinfo/Etc/GMT-2", + "usr/share/zoneinfo/Etc/GMT-3", + "usr/share/zoneinfo/Etc/GMT-4", + "usr/share/zoneinfo/Etc/GMT-5", + "usr/share/zoneinfo/Etc/GMT-6", + "usr/share/zoneinfo/Etc/GMT-7", + "usr/share/zoneinfo/Etc/GMT-8", + "usr/share/zoneinfo/Etc/GMT-9", + "usr/share/zoneinfo/Etc/GMT0", + "usr/share/zoneinfo/Etc/Greenwich", + "usr/share/zoneinfo/Etc/UCT", + "usr/share/zoneinfo/Etc/UTC", + "usr/share/zoneinfo/Etc/Universal", + "usr/share/zoneinfo/Etc/Zulu", + "usr/share/zoneinfo/Europe/Amsterdam", + "usr/share/zoneinfo/Europe/Andorra", + "usr/share/zoneinfo/Europe/Astrakhan", + "usr/share/zoneinfo/Europe/Athens", + "usr/share/zoneinfo/Europe/Belfast", + "usr/share/zoneinfo/Europe/Belgrade", + "usr/share/zoneinfo/Europe/Berlin", + "usr/share/zoneinfo/Europe/Bratislava", + "usr/share/zoneinfo/Europe/Brussels", + "usr/share/zoneinfo/Europe/Bucharest", + "usr/share/zoneinfo/Europe/Budapest", + "usr/share/zoneinfo/Europe/Busingen", + "usr/share/zoneinfo/Europe/Chisinau", + "usr/share/zoneinfo/Europe/Copenhagen", + "usr/share/zoneinfo/Europe/Dublin", + "usr/share/zoneinfo/Europe/Gibraltar", + "usr/share/zoneinfo/Europe/Guernsey", + "usr/share/zoneinfo/Europe/Helsinki", + "usr/share/zoneinfo/Europe/Isle_of_Man", + "usr/share/zoneinfo/Europe/Istanbul", + "usr/share/zoneinfo/Europe/Jersey", + "usr/share/zoneinfo/Europe/Kaliningrad", + "usr/share/zoneinfo/Europe/Kiev", + "usr/share/zoneinfo/Europe/Kirov", + "usr/share/zoneinfo/Europe/Kyiv", + "usr/share/zoneinfo/Europe/Lisbon", + "usr/share/zoneinfo/Europe/Ljubljana", + "usr/share/zoneinfo/Europe/London", + "usr/share/zoneinfo/Europe/Luxembourg", + "usr/share/zoneinfo/Europe/Madrid", + "usr/share/zoneinfo/Europe/Malta", + "usr/share/zoneinfo/Europe/Mariehamn", + "usr/share/zoneinfo/Europe/Minsk", + "usr/share/zoneinfo/Europe/Monaco", + "usr/share/zoneinfo/Europe/Moscow", + "usr/share/zoneinfo/Europe/Nicosia", + "usr/share/zoneinfo/Europe/Oslo", + "usr/share/zoneinfo/Europe/Paris", + "usr/share/zoneinfo/Europe/Podgorica", + "usr/share/zoneinfo/Europe/Prague", + "usr/share/zoneinfo/Europe/Riga", + "usr/share/zoneinfo/Europe/Rome", + "usr/share/zoneinfo/Europe/Samara", + "usr/share/zoneinfo/Europe/San_Marino", + "usr/share/zoneinfo/Europe/Sarajevo", + "usr/share/zoneinfo/Europe/Saratov", + "usr/share/zoneinfo/Europe/Simferopol", + "usr/share/zoneinfo/Europe/Skopje", + "usr/share/zoneinfo/Europe/Sofia", + "usr/share/zoneinfo/Europe/Stockholm", + "usr/share/zoneinfo/Europe/Tallinn", + "usr/share/zoneinfo/Europe/Tirane", + "usr/share/zoneinfo/Europe/Tiraspol", + "usr/share/zoneinfo/Europe/Ulyanovsk", + "usr/share/zoneinfo/Europe/Uzhgorod", + "usr/share/zoneinfo/Europe/Vaduz", + "usr/share/zoneinfo/Europe/Vatican", + "usr/share/zoneinfo/Europe/Vienna", + "usr/share/zoneinfo/Europe/Vilnius", + "usr/share/zoneinfo/Europe/Volgograd", + "usr/share/zoneinfo/Europe/Warsaw", + "usr/share/zoneinfo/Europe/Zagreb", + "usr/share/zoneinfo/Europe/Zaporozhye", + "usr/share/zoneinfo/Europe/Zurich", + "usr/share/zoneinfo/Indian/Antananarivo", + "usr/share/zoneinfo/Indian/Chagos", + "usr/share/zoneinfo/Indian/Christmas", + "usr/share/zoneinfo/Indian/Cocos", + "usr/share/zoneinfo/Indian/Comoro", + "usr/share/zoneinfo/Indian/Kerguelen", + "usr/share/zoneinfo/Indian/Mahe", + "usr/share/zoneinfo/Indian/Maldives", + "usr/share/zoneinfo/Indian/Mauritius", + "usr/share/zoneinfo/Indian/Mayotte", + "usr/share/zoneinfo/Indian/Reunion", + "usr/share/zoneinfo/Mexico/BajaNorte", + "usr/share/zoneinfo/Mexico/BajaSur", + "usr/share/zoneinfo/Mexico/General", + "usr/share/zoneinfo/Pacific/Apia", + "usr/share/zoneinfo/Pacific/Auckland", + "usr/share/zoneinfo/Pacific/Bougainville", + "usr/share/zoneinfo/Pacific/Chatham", + "usr/share/zoneinfo/Pacific/Chuuk", + "usr/share/zoneinfo/Pacific/Easter", + "usr/share/zoneinfo/Pacific/Efate", + "usr/share/zoneinfo/Pacific/Enderbury", + "usr/share/zoneinfo/Pacific/Fakaofo", + "usr/share/zoneinfo/Pacific/Fiji", + "usr/share/zoneinfo/Pacific/Funafuti", + "usr/share/zoneinfo/Pacific/Galapagos", + "usr/share/zoneinfo/Pacific/Gambier", + "usr/share/zoneinfo/Pacific/Guadalcanal", + "usr/share/zoneinfo/Pacific/Guam", + "usr/share/zoneinfo/Pacific/Honolulu", + "usr/share/zoneinfo/Pacific/Johnston", + "usr/share/zoneinfo/Pacific/Kanton", + "usr/share/zoneinfo/Pacific/Kiritimati", + "usr/share/zoneinfo/Pacific/Kosrae", + "usr/share/zoneinfo/Pacific/Kwajalein", + "usr/share/zoneinfo/Pacific/Majuro", + "usr/share/zoneinfo/Pacific/Marquesas", + "usr/share/zoneinfo/Pacific/Midway", + "usr/share/zoneinfo/Pacific/Nauru", + "usr/share/zoneinfo/Pacific/Niue", + "usr/share/zoneinfo/Pacific/Norfolk", + "usr/share/zoneinfo/Pacific/Noumea", + "usr/share/zoneinfo/Pacific/Pago_Pago", + "usr/share/zoneinfo/Pacific/Palau", + "usr/share/zoneinfo/Pacific/Pitcairn", + "usr/share/zoneinfo/Pacific/Pohnpei", + "usr/share/zoneinfo/Pacific/Ponape", + "usr/share/zoneinfo/Pacific/Port_Moresby", + "usr/share/zoneinfo/Pacific/Rarotonga", + "usr/share/zoneinfo/Pacific/Saipan", + "usr/share/zoneinfo/Pacific/Samoa", + "usr/share/zoneinfo/Pacific/Tahiti", + "usr/share/zoneinfo/Pacific/Tarawa", + "usr/share/zoneinfo/Pacific/Tongatapu", + "usr/share/zoneinfo/Pacific/Truk", + "usr/share/zoneinfo/Pacific/Wake", + "usr/share/zoneinfo/Pacific/Wallis", + "usr/share/zoneinfo/Pacific/Yap", + "usr/share/zoneinfo/US/Alaska", + "usr/share/zoneinfo/US/Aleutian", + "usr/share/zoneinfo/US/Arizona", + "usr/share/zoneinfo/US/Central", + "usr/share/zoneinfo/US/East-Indiana", + "usr/share/zoneinfo/US/Eastern", + "usr/share/zoneinfo/US/Hawaii", + "usr/share/zoneinfo/US/Indiana-Starke", + "usr/share/zoneinfo/US/Michigan", + "usr/share/zoneinfo/US/Mountain", + "usr/share/zoneinfo/US/Pacific", + "usr/share/zoneinfo/US/Samoa" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "xz-libs@5.8.4-r0", + "Name": "xz-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/xz-libs@5.8.4-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "245155576ea8d096" + }, + "Version": "5.8.4-r0", + "Arch": "x86_64", + "SrcName": "xz", + "SrcVersion": "5.8.4-r0", + "Licenses": [ + "GPL-2.0-or-later", + "0BSD", + "Public-Domain", + "LGPL-2.1-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:3b41b5237609db5d4d90f8f852d7826d6114aff8", + "InstalledFiles": [ + "usr/lib/liblzma.so.5", + "usr/lib/liblzma.so.5.8.4" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "zlib@1.3.2-r0", + "Name": "zlib", + "Identifier": { + "PURL": "pkg:apk/alpine/zlib@1.3.2-r0?arch=x86_64\u0026distro=3.23.3", + "UID": "23a5a7d167a86311" + }, + "Version": "1.3.2-r0", + "Arch": "x86_64", + "SrcName": "zlib", + "SrcVersion": "1.3.2-r0", + "Licenses": [ + "Zlib" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:8fabd1323466a7cf0bd0950b25882ffbf4d84859148e9f53eeaaf45deb9a8ba8", + "DiffID": "sha256:d48654974e1c33b1be893159479112cd50e241dda9bded54ed20320ac9a000d2" + }, + "Digest": "sha1:68bb97ea5255e77aa974e65476d64832ad56288a", + "InstalledFiles": [ + "usr/lib/libz.so.1", + "usr/lib/libz.so.1.3.2" + ], + "AnalyzedBy": "apk" + }, + { + "ID": "zstd-libs@1.5.7-r2", + "Name": "zstd-libs", + "Identifier": { + "PURL": "pkg:apk/alpine/zstd-libs@1.5.7-r2?arch=x86_64\u0026distro=3.23.3", + "UID": "3653bba6b6680fed" + }, + "Version": "1.5.7-r2", + "Arch": "x86_64", + "SrcName": "zstd", + "SrcVersion": "1.5.7-r2", + "Licenses": [ + "BSD-3-Clause", + "GPL-2.0-or-later" + ], + "Maintainer": "Natanael Copa \u003cncopa@alpinelinux.org\u003e", + "DependsOn": [ + "musl@1.2.5-r23" + ], + "Layer": { + "Digest": "sha256:0151c82f84a9c78800cb330f93f88d6ffe39f030ec9a60dbc0a12c4c7109536c", + "DiffID": "sha256:f76f397f2ce6b266573b70eb60ef1335e9984a1941eedd2a3505af4870c3afa0" + }, + "Digest": "sha1:d507b8ac3c4335a40405ac20e49bac9d43642be6", + "InstalledFiles": [ + "usr/lib/libzstd.so.1", + "usr/lib/libzstd.so.1.5.7" + ], + "AnalyzedBy": "apk" + } + ], + "Vulnerabilities": [ + { + "VulnerabilityID": "CVE-2026-42055", + "PkgID": "nginx@1.28.3-r1", + "PkgName": "nginx", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8e6ca21a785dbb9c" + }, + "InstalledVersion": "1.28.3-r1", + "FixedVersion": "1.28.3-r4", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42055", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:dc8c7d93524c7dbf9eab464b604e31a3ff0d843aa664652275ef67cb197deccb", + "Title": "nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers", + "Description": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-122", + "CWE-787", + "CWE-131" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 4, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 9.2 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:27197", + "https://access.redhat.com/errata/RHSA-2026:36331", + "https://access.redhat.com/errata/RHSA-2026:36364", + "https://access.redhat.com/errata/RHSA-2026:36618", + "https://access.redhat.com/errata/RHSA-2026:36639", + "https://access.redhat.com/errata/RHSA-2026:38847", + "https://access.redhat.com/errata/RHSA-2026:44481", + "https://access.redhat.com/errata/RHSA-2026:46836", + "https://access.redhat.com/errata/RHSA-2026:58981", + "https://access.redhat.com/security/cve/CVE-2026-42055", + "https://bugzilla.redhat.com/2489866", + "https://bugzilla.redhat.com/show_bug.cgi?id=2489866", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42055", + "https://errata.almalinux.org/9/ALSA-2026-36639.html", + "https://errata.rockylinux.org/RLSA-2026:36639", + "https://linux.oracle.com/cve/CVE-2026-42055.html", + "https://linux.oracle.com/errata/ELSA-2026-38847.html", + "https://my.f5.com/manage/s/article/K000161584", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42055", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42055.json", + "https://ubuntu.com/security/notices/USN-8458-1", + "https://www.cve.org/CVERecord?id=CVE-2026-42055" + ], + "PublishedDate": "2026-06-17T15:16:50.353Z", + "LastModifiedDate": "2026-08-25T13:19:00.073Z" + }, + { + "VulnerabilityID": "CVE-2026-42533", + "PkgID": "nginx@1.28.3-r1", + "PkgName": "nginx", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8e6ca21a785dbb9c" + }, + "InstalledVersion": "1.28.3-r1", + "FixedVersion": "1.28.3-r6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-42533", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:c2401c49af3ebf648486409caaeb540bf1de66b1045e7044bbcaff16997b0612", + "Title": "nginx: NGINX: Arbitrary code execution via crafted HTTP requests", + "Description": "A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.\n\nImpact:\nThis vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.\n\n\n\n\n Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-122" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 4, + "bitnami": 4, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 9.2 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H", + "V3Score": 7 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:66542", + "https://access.redhat.com/security/cve/CVE-2026-42533", + "https://bugzilla.redhat.com/2500967", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500967", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42533", + "https://cyberstan.co.uk/nginx-rce/", + "https://errata.almalinux.org/9/ALSA-2026-66542.html", + "https://errata.rockylinux.org/RLSA-2026:66542", + "https://github.com/imbas007/cve-2026-42533", + "https://linux.oracle.com/cve/CVE-2026-42533.html", + "https://linux.oracle.com/errata/ELSA-2026-66542-0.html", + "https://my.f5.com/manage/s/article/K000162097", + "https://nvd.nist.gov/vuln/detail/CVE-2026-42533", + "https://ubuntu.com/security/notices/USN-8563-1", + "https://ubuntu.com/security/notices/USN-8563-2", + "https://ubuntu.com/security/notices/USN-8563-3", + "https://ubuntu.com/security/notices/USN-8563-4", + "https://www.cve.org/CVERecord?id=CVE-2026-42533" + ], + "PublishedDate": "2026-07-15T15:16:33.48Z", + "LastModifiedDate": "2026-08-10T15:28:01.94Z" + }, + { + "VulnerabilityID": "CVE-2026-49975", + "PkgID": "nginx@1.28.3-r1", + "PkgName": "nginx", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8e6ca21a785dbb9c" + }, + "InstalledVersion": "1.28.3-r1", + "FixedVersion": "1.28.3-r3", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-49975", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:83632a4d5106ad8f9b162bd05e81b861e429ad701a369d55fab6bf4fb0cf5345", + "Title": "httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack", + "Description": "Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.\n\nThis issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-789", + "CWE-409" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "V3Score": 7.5 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/06/03/3", + "http://www.openwall.com/lists/oss-security/2026/06/08/16", + "https://access.redhat.com/errata/RHSA-2026:25042", + "https://access.redhat.com/errata/RHSA-2026:25057", + "https://access.redhat.com/errata/RHSA-2026:25090", + "https://access.redhat.com/errata/RHSA-2026:25225", + "https://access.redhat.com/errata/RHSA-2026:27114", + "https://access.redhat.com/errata/RHSA-2026:27200", + "https://access.redhat.com/errata/RHSA-2026:27201", + "https://access.redhat.com/errata/RHSA-2026:36373", + "https://access.redhat.com/errata/RHSA-2026:36831", + "https://access.redhat.com/errata/RHSA-2026:36846", + "https://access.redhat.com/errata/RHSA-2026:50538", + "https://access.redhat.com/errata/RHSA-2026:50572", + "https://access.redhat.com/errata/RHSA-2026:55930", + "https://access.redhat.com/errata/RHSA-2026:55992", + "https://access.redhat.com/security/cve/CVE-2026-49975", + "https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb", + "https://bugzilla.redhat.com/2485371", + "https://bugzilla.redhat.com/show_bug.cgi?id=2485371", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-49975", + "https://errata.almalinux.org/9/ALSA-2026-25057.html", + "https://errata.rockylinux.org/RLSA-2026:25057", + "https://github.com/EQSTLab/CVE-2026-49975", + "https://github.com/icing/mod_h2/pull/324", + "https://httpd.apache.org/security/vulnerabilities_24.html", + "https://linux.oracle.com/cve/CVE-2026-49975.html", + "https://linux.oracle.com/errata/ELSA-2026-25225.html", + "https://lists.debian.org/debian-lts-announce/2026/06/msg00009.html", + "https://nvd.nist.gov/vuln/detail/CVE-2026-49975", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49975.json", + "https://ubuntu.com/security/notices/USN-8384-1", + "https://ubuntu.com/security/notices/USN-8398-1", + "https://ubuntu.com/security/notices/USN-8398-2", + "https://ubuntu.com/security/notices/USN-8398-3", + "https://ubuntu.com/security/notices/USN-8398-4", + "https://ubuntu.com/security/notices/USN-8571-1", + "https://www.cve.org/CVERecord?id=CVE-2026-49975" + ], + "PublishedDate": "2026-06-08T16:16:44.223Z", + "LastModifiedDate": "2026-08-19T12:18:28.65Z" + }, + { + "VulnerabilityID": "CVE-2026-60005", + "PkgID": "nginx@1.28.3-r1", + "PkgName": "nginx", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8e6ca21a785dbb9c" + }, + "InstalledVersion": "1.28.3-r1", + "FixedVersion": "1.28.3-r6", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-60005", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:151c2e896fe0d907bbe7fb718e7e067c0ba3d4c4d4f52fdc02408d67b9d7045e", + "Title": "nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module", + "Description": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart.\n\nImpact:\nThis vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.\nNote: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-908" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "bitnami": 3, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N", + "V40Score": 8.8 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", + "V3Score": 8.2 + } + }, + "References": [ + "https://access.redhat.com/errata/RHSA-2026:59496", + "https://access.redhat.com/security/cve/CVE-2026-60005", + "https://bugzilla.redhat.com/2500960", + "https://bugzilla.redhat.com/2500992", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500960", + "https://bugzilla.redhat.com/show_bug.cgi?id=2500992", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-56434", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-60005", + "https://errata.almalinux.org/9/ALSA-2026-59496.html", + "https://errata.rockylinux.org/RLSA-2026:59496", + "https://linux.oracle.com/cve/CVE-2026-60005.html", + "https://linux.oracle.com/errata/ELSA-2026-59496.html", + "https://my.f5.com/manage/s/article/K000162100", + "https://nvd.nist.gov/vuln/detail/CVE-2026-60005", + "https://ubuntu.com/security/notices/USN-8563-1", + "https://www.cve.org/CVERecord?id=CVE-2026-60005" + ], + "PublishedDate": "2026-07-15T16:16:49.82Z", + "LastModifiedDate": "2026-08-11T15:09:03.683Z" + }, + { + "VulnerabilityID": "CVE-2026-9256", + "PkgID": "nginx@1.28.3-r1", + "PkgName": "nginx", + "PkgIdentifier": { + "PURL": "pkg:apk/alpine/nginx@1.28.3-r1?arch=x86_64\u0026distro=3.23.3", + "UID": "8e6ca21a785dbb9c" + }, + "InstalledVersion": "1.28.3-r1", + "FixedVersion": "1.28.3-r2", + "Status": "fixed", + "Layer": { + "Digest": "sha256:1d9cbdb003be4f77dc59400a5eb400afcac245934b539c7bffe52abae7720f3c", + "DiffID": "sha256:a2738b08d7114c9d5581dd5482d3b5cc297fcf73b8d330c3ba38d24c43939119" + }, + "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2026-9256", + "DataSource": { + "ID": "alpine", + "Name": "Alpine Secdb", + "URL": "https://secdb.alpinelinux.org/" + }, + "Fingerprint": "sha256:86697b5ac6e618b7f0ce96b385080e9ab64917c6aa98fd2de84b200468b72b3f", + "Title": "nginx: ngx_http_rewrite_module: code execution and denial of service", + "Description": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "Severity": "HIGH", + "CweIDs": [ + "CWE-122" + ], + "VendorSeverity": { + "alma": 3, + "amazon": 3, + "azure": 3, + "bitnami": 4, + "oracle-oval": 3, + "photon": 3, + "redhat": 3, + "rocky": 3, + "ubuntu": 2 + }, + "CVSS": { + "bitnami": { + "V40Vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", + "V40Score": 9.2 + }, + "redhat": { + "V3Vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", + "V3Score": 8.1 + } + }, + "References": [ + "http://www.openwall.com/lists/oss-security/2026/05/22/14", + "https://access.redhat.com/errata/RHSA-2026:20351", + "https://access.redhat.com/errata/RHSA-2026:28212", + "https://access.redhat.com/errata/RHSA-2026:28921", + "https://access.redhat.com/errata/RHSA-2026:28973", + "https://access.redhat.com/errata/RHSA-2026:29151", + "https://access.redhat.com/errata/RHSA-2026:29874", + "https://access.redhat.com/errata/RHSA-2026:33313", + "https://access.redhat.com/errata/RHSA-2026:44481", + "https://access.redhat.com/errata/RHSA-2026:58981", + "https://access.redhat.com/security/cve/CVE-2026-9256", + "https://bugzilla.redhat.com/2480746", + "https://bugzilla.redhat.com/show_bug.cgi?id=2480746", + "https://creativecommons.org/licenses/by/4.0/", + "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9256", + "https://errata.almalinux.org/9/ALSA-2026-29151.html", + "https://errata.rockylinux.org/RLSA-2026:29151", + "https://linux.oracle.com/cve/CVE-2026-9256.html", + "https://linux.oracle.com/errata/ELSA-2026-29874.html", + "https://lists.debian.org/debian-lts-announce/2026/06/msg00023.html", + "https://my.f5.com/manage/s/article/K000161377", + "https://nvd.nist.gov/vuln/detail/CVE-2026-9256", + "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9256.json", + "https://ubuntu.com/security/notices/USN-8354-1", + "https://ubuntu.com/security/notices/USN-8375-1", + "https://www.cve.org/CVERecord?id=CVE-2026-9256" + ], + "PublishedDate": "2026-05-22T15:16:27.073Z", + "LastModifiedDate": "2026-08-25T13:19:33.4Z" + } + ] + } + ] +} diff --git a/portal/main.py b/portal/main.py new file mode 100644 index 0000000..8687dad --- /dev/null +++ b/portal/main.py @@ -0,0 +1,322 @@ +""" +Portal de recebimento de arte — roda na nuvem, aberto 24 horas. + +Fluxo: + 0. Tiny avisa por webhook que nasceu um pedido de DTF + 1. portal cria token e manda o link no WhatsApp + 2. cliente abre o link e pede uma URL pré-assinada + 3. o navegador envia o arquivo DIRETO para o storage (não passa por aqui) + 4. cliente avisa que terminou -> robô valida, repete, fatia e carimba + 5. o agente da fábrica busca o que foi aprovado + +Rodar: + uvicorn main:app --host 0.0.0.0 --port 8000 +""" + +from __future__ import annotations + +import os +import uuid +from datetime import datetime, timedelta, timezone + +import boto3 +from fastapi import BackgroundTasks, Depends, FastAPI, Header, HTTPException +from fastapi.responses import HTMLResponse +from pydantic import BaseModel +from sqlmodel import Field, Session, SQLModel, create_engine, select + +import preflight +import tiny +import whats + +# -------------------------------------------------------------------------- +DB = os.environ["DATABASE_URL"] +BUCKET = os.environ["S3_BUCKET"] +BASE_PORTAL = os.environ["BASE_PORTAL"] # https://arte.dropstaratacado.com.br +BASE_KANBAN = os.environ["BASE_KANBAN"] # http://servidor:8080 +TOKEN_TINY = os.environ["WEBHOOK_TOKEN"] # segredo combinado com o Tiny +TOKEN_AGENTE = os.environ["AGENTE_TOKEN"] +VALIDADE_TOKEN_DIAS = 7 +MAX_GB = 5 # limite do que os PCs da sala aguentam abrir +MAX_ARQUIVOS = 10 + +engine = create_engine(DB) +s3 = boto3.client("s3", endpoint_url=os.environ["S3_ENDPOINT"]) +app = FastAPI(title="Portal de arte DTF") + + +# -------------------------------------------------------------------------- +# Tabelas +# -------------------------------------------------------------------------- +class Pedido(SQLModel, table=True): + id: int | None = Field(default=None, primary_key=True) + numero_tiny: str = Field(index=True, unique=True) + cliente: str + metros: float # metros comprados por arte + token: str = Field(index=True, unique=True) + token_expira: datetime + criado_em: datetime = Field(default_factory=lambda: datetime.now(timezone.utc)) + + +class Arte(SQLModel, table=True): + id: int | None = Field(default=None, primary_key=True) + pedido_id: int = Field(foreign_key="pedido.id", index=True) + arquivo: str + bytes: int = 0 + repeticoes: int = 1 + status: str = "recebida" # recebida | aprovada | recusada + motivo: str = "" + avisos: str = "" + dpi_efetivo: float = 0 + largura_cm: float = 0 + metros_totais: float = 0 + baixada: bool = False + criado_em: datetime = Field(default_factory=lambda: datetime.now(timezone.utc)) + + +class Parte(SQLModel, table=True): + id: int | None = Field(default=None, primary_key=True) + arte_id: int = Field(foreign_key="arte.id", index=True) + ordem: int + metros: float + arquivo: str + carimbada: bool = False + + +SQLModel.metadata.create_all(engine) + + +def sessao(): + with Session(engine) as s: + yield s + + +# -------------------------------------------------------------------------- +# 0. Webhook do Tiny — pedido novo +# -------------------------------------------------------------------------- +class PedidoTiny(BaseModel): + numero: str + cliente: str + telefone: str + metros: float + + +@app.post("/webhook/tiny") +def pedido_novo( + p: PedidoTiny, + background: BackgroundTasks, + x_token: str = Header(default=""), + s: Session = Depends(sessao), +): + if x_token != TOKEN_TINY: + raise HTTPException(401, "token inválido") + + existente = s.exec(select(Pedido).where(Pedido.numero_tiny == p.numero)).first() + if existente: + return {"ok": True, "ja_existia": True} + + pedido = Pedido( + numero_tiny=p.numero, + cliente=p.cliente, + metros=p.metros, + token=uuid.uuid4().hex, + token_expira=datetime.now(timezone.utc) + timedelta(days=VALIDADE_TOKEN_DIAS), + ) + s.add(pedido) + s.commit() + s.refresh(pedido) + + link = f"{BASE_PORTAL}/arte/{pedido.token}" + background.add_task(whats.enviar_link, p.telefone, p.numero, link) + return {"ok": True, "link": link} + + +# -------------------------------------------------------------------------- +# 1 e 2. Página e URL pré-assinada +# -------------------------------------------------------------------------- +def _pedido_por_token(token: str, s: Session) -> Pedido: + p = s.exec(select(Pedido).where(Pedido.token == token)).first() + if not p: + raise HTTPException(404, "link inválido") + if p.token_expira < datetime.now(timezone.utc): + raise HTTPException(410, "link expirado — fale com o atendimento") + return p + + +@app.get("/arte/{token}", response_class=HTMLResponse) +def pagina(token: str, s: Session = Depends(sessao)): + _pedido_por_token(token, s) + return open("static/portal.html", encoding="utf-8").read() + + +@app.get("/api/arte/{token}") +def dados(token: str, s: Session = Depends(sessao)): + p = _pedido_por_token(token, s) + return { + "pedido": p.numero_tiny, + "cliente": p.cliente, + "metros": p.metros, + "area_util_cm": preflight.AREA_UTIL_CM, + "limite_arquivo_m": preflight.LIMITE_ARQUIVO_M, + "max_gb": MAX_GB, + } + + +@app.post("/api/arte/{token}/url") +def url_upload(token: str, nome: str, s: Session = Depends(sessao)): + p = _pedido_por_token(token, s) + n = len(s.exec(select(Arte).where(Arte.pedido_id == p.id)).all()) + if n >= MAX_ARQUIVOS: + raise HTTPException(400, f"máximo de {MAX_ARQUIVOS} arquivos por pedido") + + chave = f"{p.numero_tiny}/{uuid.uuid4().hex}_{nome}" + url = s3.generate_presigned_url( + "put_object", + Params={"Bucket": BUCKET, "Key": chave}, + ExpiresIn=3600, + ) + return {"url": url, "chave": chave} + + +# -------------------------------------------------------------------------- +# 4. Terminou o upload -> roda o pré-flight +# -------------------------------------------------------------------------- +class Pronto(BaseModel): + chave: str + repeticoes: int = 1 + + +@app.post("/api/arte/{token}/pronto") +def pronto( + token: str, + body: Pronto, + background: BackgroundTasks, + s: Session = Depends(sessao), +): + p = _pedido_por_token(token, s) + arte = Arte(pedido_id=p.id, arquivo=body.chave, repeticoes=max(1, body.repeticoes)) + s.add(arte) + s.commit() + s.refresh(arte) + background.add_task(processar, arte.id) + return {"arte_id": arte.id, "status": "processando"} + + +def processar(arte_id: int): + """Baixa do storage, valida, repete, fatia, carimba e devolve as partes.""" + with Session(engine) as s: + arte = s.get(Arte, arte_id) + pedido = s.get(Pedido, arte.pedido_id) + + local = f"/tmp/{arte.id}.png" + s3.download_file(BUCKET, arte.arquivo, local) + arte.bytes = os.path.getsize(local) + + r = preflight.processar( + caminho=local, + cm_comprados=pedido.metros * 100, + repeticoes=arte.repeticoes, + pedido=pedido.numero_tiny, + base_kanban=BASE_KANBAN, + pasta_saida="/tmp", + ) + + arte.dpi_efetivo = r.dpi_efetivo + arte.largura_cm = r.largura_cm + arte.metros_totais = r.metros_totais + arte.avisos = " | ".join(r.avisos) + + if not r.aprovado: + arte.status, arte.motivo = "recusada", r.motivo + s.add(arte) + s.commit() + whats.enviar_recusa(pedido, arte.motivo) + return + + for i, caminho in enumerate(r.partes, start=1): + chave = f"{pedido.numero_tiny}/partes/{os.path.basename(caminho)}" + s3.upload_file(caminho, BUCKET, chave) + s.add(Parte( + arte_id=arte.id, + ordem=i, + metros=min(preflight.LIMITE_ARQUIVO_M, + r.metros_totais - preflight.LIMITE_ARQUIVO_M * (i - 1)), + arquivo=chave, + carimbada=(i == len(r.partes)), + )) + + arte.status = "aprovada" + s.add(arte) + s.commit() + + tiny.marcador(pedido.numero_tiny, "DTF-RECEBIDA") + whats.enviar_aprovacao(pedido, r) + avisar_agente() + + +# -------------------------------------------------------------------------- +# 5. O agente busca o que foi aprovado +# -------------------------------------------------------------------------- +@app.get("/api/artes") +def para_baixar(x_token: str = Header(default=""), s: Session = Depends(sessao)): + if x_token != TOKEN_AGENTE: + raise HTTPException(401, "token inválido") + + artes = s.exec( + select(Arte).where(Arte.status == "aprovada", Arte.baixada == False) # noqa: E712 + ).all() + saida = [] + for a in artes: + p = s.get(Pedido, a.pedido_id) + partes = s.exec(select(Parte).where(Parte.arte_id == a.id)).all() + saida.append({ + "arte_id": a.id, + "pedido": p.numero_tiny, + "cliente": p.cliente, + "metros": a.metros_totais, + "partes": [ + { + "ordem": pt.ordem, + "metros": pt.metros, + "url": s3.generate_presigned_url( + "get_object", + Params={"Bucket": BUCKET, "Key": pt.arquivo}, + ExpiresIn=3600, + ), + "nome": os.path.basename(pt.arquivo), + } + for pt in sorted(partes, key=lambda x: x.ordem) + ], + }) + return saida + + +@app.post("/api/artes/{arte_id}/baixada") +def marcar_baixada( + arte_id: int, x_token: str = Header(default=""), s: Session = Depends(sessao) +): + if x_token != TOKEN_AGENTE: + raise HTTPException(401, "token inválido") + a = s.get(Arte, arte_id) + a.baixada = True + s.add(a) + s.commit() + return {"ok": True} + + +def avisar_agente(): + """Webhook para o agente na fábrica. O polling de 60s é a rede de segurança.""" + import httpx + + url = os.environ.get("AGENTE_WEBHOOK") + if not url: + return + try: + httpx.post(url, timeout=5, headers={"x-token": TOKEN_AGENTE}) + except Exception: + pass # o polling pega + + +@app.get("/saude") +def saude(): + return {"ok": True, "em": datetime.now(timezone.utc).isoformat()} diff --git a/portal/preflight.py b/portal/preflight.py new file mode 100644 index 0000000..c2cd327 --- /dev/null +++ b/portal/preflight.py @@ -0,0 +1,415 @@ +""" +Pré-flight do DTF: valida a arte, repete, fatia e carimba. + +Regras acordadas com Marcus em 29/08/2026: + - unidade de venda: 57 x 100 cm + - faixa reservada no rodapé: 30 mm -> área útil 57 x 97 cm + - carimbo: QR de 20 mm + texto na mesma altura, só canal preto + - limite por arquivo gerado: 15 metros + - o carimbo vai apenas na ÚLTIMA parte do pedido + +Dependências: pyvips, qrcode, pillow + apt install libvips-tools + pip install pyvips qrcode pillow +""" + +from __future__ import annotations + +import math +import os +import shutil +import subprocess +from dataclasses import dataclass, field +from datetime import datetime + +import pyvips +import qrcode + +# -------------------------------------------------------------------------- +# Constantes do processo +# -------------------------------------------------------------------------- +LARGURA_MAX_CM = 57.0 +FAIXA_RODAPE_MM = 30.0 # reservada para o carimbo +ALTURA_UNIDADE_CM = 100.0 +AREA_UTIL_CM = ALTURA_UNIDADE_CM - FAIXA_RODAPE_MM / 10 # 97 cm + +DPI_MINIMO = 150 # abaixo disso recusa +DPI_IDEAL = 300 # entre 150 e 300 aceita com aviso +LIMITE_ARQUIVO_M = 20.0 # nenhum arquivo gerado passa disso + +QR_MM = 20.0 # leitura por celular +ZONA_LIMPA_MM = 3.0 # margem branca ao redor do QR + +FORMATOS_OK = {".png", ".tif", ".tiff", ".psd", ".psb", ".pdf", ".ai", ".svg", ".eps"} + +# -------------------------------------------------------------------------- +# Normalização — o cliente manda o que quiser, o designer recebe padronizado +# -------------------------------------------------------------------------- +# Não existe "formato certo" único: normalizar tudo para um só jogaria fora o +# melhor de cada tipo. A regra é por NATUREZA do conteúdo. +# +# vetor -> PDF, mantendo vetor (rasterizar aqui é perder qualidade) +# pixel -> TIF com transparência (é o que a sala já usa) +# +# Isso resolve o vai-e-volta que os designers relatam hoje: abrir PDF no Corel +# para não rasterizar, exportar, abrir no Photoshop, e esbarrar no limite de +# 5 metros do PSD. +# +# O limite de 5 m NÃO é do Photoshop: é do formato PSD, que trava em 30.000 px +# por dimensão — a 150 DPI dá 5,08 m. PSB vai a 300.000 px, ou 50 metros. +# Em PDF vetorial não há esse limite; em TIF o teto é 4 GB por arquivo. +VETORIAIS = {".pdf", ".ai", ".svg", ".eps"} +RASTER = {".png", ".tif", ".tiff", ".psd", ".psb"} +FORMATOS_RECUSA = {".jpg", ".jpeg", ".gif", ".bmp", ".webp"} +# CDR entra com etiqueta "conferir": pula o pré-flight e vai direto ao designer. +# A licença do CorelDRAW é de estação, não cobre servidor processando arquivo. +FORMATOS_SEM_VALIDACAO = {".cdr"} + +CM_POR_POLEGADA = 2.54 + + +# -------------------------------------------------------------------------- +# Resultado +# -------------------------------------------------------------------------- +@dataclass +class Resultado: + aprovado: bool + motivo: str = "" # mensagem ao cliente quando recusado + avisos: list[str] = field(default_factory=list) + dpi_efetivo: float = 0.0 + largura_cm: float = 0.0 + altura_cm: float = 0.0 + metros_totais: float = 0.0 + conferir_manual: bool = False # CDR: entra sem validar + natureza: str = "" # vetor | raster | conferir + partes: list[str] = field(default_factory=list) # caminhos gerados + + +# -------------------------------------------------------------------------- +# 1. Validação +# -------------------------------------------------------------------------- +def validar(caminho: str, cm_comprados: float) -> Resultado: + """ + cm_comprados = altura em centímetros que o cliente pagou por UMA arte. + Ex.: comprou 1 metro -> 100. + """ + r = Resultado(aprovado=False) + ext = os.path.splitext(caminho)[1].lower() + + if ext in FORMATOS_SEM_VALIDACAO: + r.aprovado = True + r.conferir_manual = True + r.avisos.append("CDR não passa pelo pré-flight — vai direto para o designer.") + return r + + if ext in FORMATOS_RECUSA: + r.motivo = ( + f"Arquivo {ext.upper().lstrip('.')} não guarda transparência. " + "Envie PNG ou TIFF com fundo transparente." + ) + return r + + if ext not in FORMATOS_OK: + r.motivo = "Formato não aceito. Envie PNG ou TIFF com fundo transparente." + return r + + try: + # access sequential: lê em streaming, não carrega 200 MB na memória + img = pyvips.Image.new_from_file(caminho, access="sequential") + except Exception: + r.motivo = "Não conseguimos abrir o arquivo. Ele pode estar corrompido." + return r + + # --- canal alfa --- + if img.bands < 4 or not img.hasalpha(): + r.motivo = ( + "A arte está sem fundo transparente. Todo fundo não removido " + "sai impresso em branco na estampa." + ) + return r + + # --- DPI efetivo: a regra que mais pega arquivo ruim --- + # O DPI gravado no cabeçalho mente com frequência (o cliente escala a + # imagem e o programa mantém "300"). O que vale é pixel dividido pela + # medida que ele comprou. + area_util_cm = cm_comprados - FAIXA_RODAPE_MM / 10 + r.dpi_efetivo = img.height / (area_util_cm / CM_POR_POLEGADA) + r.altura_cm = area_util_cm + r.largura_cm = img.width / r.dpi_efetivo * CM_POR_POLEGADA + + if r.dpi_efetivo < DPI_MINIMO: + r.motivo = ( + f"A resolução real da arte é de {r.dpi_efetivo:.0f} DPI no tamanho " + f"que você comprou. Precisamos de pelo menos {DPI_MINIMO} DPI — " + "o ideal é 300. Reenvie em maior resolução." + ) + return r + + if r.dpi_efetivo < DPI_IDEAL: + r.avisos.append( + f"Resolução de {r.dpi_efetivo:.0f} DPI. Funciona, mas detalhes " + "finos podem perder definição." + ) + + # --- largura física --- + if r.largura_cm > LARGURA_MAX_CM + 0.2: # 2 mm de tolerância + r.motivo = ( + f"A arte tem {r.largura_cm:.1f} cm de largura. O máximo é " + f"{LARGURA_MAX_CM:.0f} cm. Use o gabarito 57 × 97 cm." + ) + return r + + # --- bordas com alfa parcial (sombras suaves) --- + alfa = img[img.bands - 1] + parcial = ((alfa > 10) & (alfa < 245)).avg() / 255.0 + if parcial > 0.15: + r.avisos.append( + "A arte tem muitas bordas suaves. O branco de apoio pode sair " + "irregular nessas áreas." + ) + + r.aprovado = True + return r + + +# -------------------------------------------------------------------------- +# 1b. Normalização +# -------------------------------------------------------------------------- +def normalizar(caminho: str, pasta_saida: str, pedido: str) -> tuple[str, str]: + """ + Converte o que o cliente mandou para o formato de trabalho da sala. + + Devolve (caminho_normalizado, natureza). + + O ORIGINAL É SEMPRE PRESERVADO. Se a conversão sair ruim num caso + específico, o designer volta ao arquivo do cliente — pedido dos próprios + designers, e é barato perto de refazer o trabalho. + """ + ext = os.path.splitext(caminho)[1].lower() + + if ext in FORMATOS_SEM_VALIDACAO: # CDR: sem Corel no servidor + return caminho, "conferir" + + if ext in VETORIAIS: + # mantém vetor: nada de rasterizar. O FlexiPRINT rasteriza na resolução + # da máquina, na hora de imprimir — melhor que qualquer caminho manual. + destino = os.path.join(pasta_saida, f"{pedido}_norm.pdf") + if ext == ".pdf": + shutil.copy(caminho, destino) + else: + # AI, SVG e EPS convertem para PDF preservando o vetor + subprocess.run( + ["inkscape", caminho, "--export-type=pdf", + f"--export-filename={destino}", "--export-text-to-path"], + check=True, capture_output=True, + ) + return destino, "vetor" + + # raster: TIF com alfa, sem compressão com perda + destino = os.path.join(pasta_saida, f"{pedido}_norm.tif") + img = pyvips.Image.new_from_file(caminho, access="sequential") + if not img.hasalpha(): + img = img.bandjoin(255) + img = _para_rgb(img) + img.tiffsave(destino, compression="lzw", predictor="horizontal") + return destino, "raster" + + +def _para_rgb(img: pyvips.Image) -> pyvips.Image: + """ + CMYK vira RGB. Arquivo em CMYK é uma das causas de cor errada no DTF — + o cliente monta em CMYK, a máquina trabalha em RGB, e a cor muda. + """ + if img.interpretation in ("cmyk", "b-w"): + return img.colourspace("srgb") + return img + + +# -------------------------------------------------------------------------- +# 2. Repetição +# -------------------------------------------------------------------------- +def empilhar(caminho: str, repeticoes: int, destino: str) -> str: + """Concatena N cópias da arte na vertical, sem espaço entre elas.""" + if repeticoes <= 1: + return caminho + img = pyvips.Image.new_from_file(caminho, access="sequential") + empilhado = pyvips.Image.arrayjoin([img] * repeticoes, across=1) + empilhado.write_to_file(destino) + return destino + + +def montar_folha(caminhos: list[str], destino: str) -> str: + """ + Junta vários arquivos numa folha só, EMPILHADOS na ordem que subiram. + + Decisão de 30/08/2026: empilhamento simples, sem encaixe lado a lado. + São artes de 1 metro em sequência — não é arte única e não há otimização + de largura. O cliente vê a prévia antes de fechar o pedido. + """ + if len(caminhos) == 1: + return caminhos[0] + imgs = [pyvips.Image.new_from_file(c, access="sequential") for c in caminhos] + largura = max(i.width for i in imgs) + # centraliza as artes mais estreitas, mantendo a largura da folha + ajustadas = [ + i if i.width == largura + else i.embed((largura - i.width) // 2, 0, largura, i.height) + for i in imgs + ] + pyvips.Image.arrayjoin(ajustadas, across=1).write_to_file(destino) + return destino + + +# -------------------------------------------------------------------------- +# 3. Fatiamento +# -------------------------------------------------------------------------- +def quantas_partes(metros_totais: float) -> int: + return max(1, math.ceil(metros_totais / LIMITE_ARQUIVO_M)) + + +def fatiar(caminho: str, metros_totais: float, prefixo: str) -> list[str]: + """ + Corta em partes de no máximo 15 metros. + 1 m x 20 -> 15 + 5 (2 arquivos) + 100 m -> 15 x 6 + 10 (7 arquivos) + """ + n = quantas_partes(metros_totais) + if n == 1: + return [caminho] + + img = pyvips.Image.new_from_file(caminho, access="random") + px_por_metro = img.height / metros_totais + partes, topo, restante = [], 0, metros_totais + + for i in range(n): + m = min(LIMITE_ARQUIVO_M, restante) + altura = int(round(m * px_por_metro)) + altura = min(altura, img.height - topo) + saida = f"{prefixo}_p{i + 1}.png" + img.crop(0, topo, img.width, altura).write_to_file(saida) + partes.append(saida) + topo += altura + restante -= m + + return partes + + +# -------------------------------------------------------------------------- +# 4. Carimbo +# -------------------------------------------------------------------------- +def _qr_vips(conteudo: str, lado_px: int) -> pyvips.Image: + qr = qrcode.QRCode( + version=None, + error_correction=qrcode.constants.ERROR_CORRECT_M, # aguenta 15% de dano + box_size=1, + border=0, + ) + qr.add_data(conteudo) + qr.make(fit=True) + m = qr.get_matrix() + n = len(m) + + # matriz -> imagem 1 bit -> escala para o tamanho pedido + dados = bytes(0 if v else 255 for linha in m for v in linha) + img = pyvips.Image.new_from_memory(dados, n, n, 1, "uchar") + return img.resize(lado_px / n, kernel="nearest") + + +def carimbar( + caminho: str, + pedido: str, + metros: float, + url_kanban: str, + dpi: float = 300.0, + quando: datetime | None = None, +) -> str: + """ + Escreve o carimbo na faixa de 30 mm do rodapé. + QR de 20 mm com a URL do card + número, metragem e data ao lado. + Só canal preto — sem branco de apoio, para não gastar a tinta mais cara. + """ + quando = quando or datetime.now() + img = pyvips.Image.new_from_file(caminho, access="random") + px_mm = dpi / CM_POR_POLEGADA / 10 + + qr_px = int(QR_MM * px_mm) + margem = int(ZONA_LIMPA_MM * px_mm) + faixa_px = int(FAIXA_RODAPE_MM * px_mm) + + # fundo branco só sob o QR, para o celular ler com contraste + fundo = pyvips.Image.black(qr_px + margem * 2, qr_px + margem * 2) + 255 + qr = _qr_vips(url_kanban, qr_px) + bloco = fundo.insert(qr, margem, margem) + + # texto alinhado à altura do QR + texto = ( + f"{pedido}\n" + f"{metros:.2f} m\n" + f"" + f"{quando:%d/%m · %H:%M}" + ).replace(".", ",") + txt = pyvips.Image.text(texto, dpi=int(dpi), align="low") + + # base da faixa: transparente, o carimbo entra em preto + base = pyvips.Image.black(img.width, faixa_px, bands=4) + y_qr = max(0, (faixa_px - bloco.height) // 2) + base = base.insert(bloco.bandjoin(255), margem, y_qr, expand=False) + base = base.insert( + txt.bandjoin(255) if txt.bands < 4 else txt, + margem * 2 + bloco.width, + max(0, (faixa_px - txt.height) // 2), + expand=False, + ) + + final = pyvips.Image.arrayjoin([img, base], across=1) + saida = caminho.replace(".png", "_carimbado.png") + final.write_to_file(saida) + return saida + + +# -------------------------------------------------------------------------- +# 5. Orquestração — é isso que o portal chama +# -------------------------------------------------------------------------- +def processar( + caminho: str, + cm_comprados: float, + repeticoes: int, + pedido: str, + base_kanban: str, + pasta_saida: str, +) -> Resultado: + # 0. normaliza antes de tudo: o designer nunca mais converte à mão + caminho, natureza = normalizar(caminho, pasta_saida, pedido) + if natureza == "conferir": + r = Resultado(aprovado=True, conferir_manual=True) + r.avisos.append("CDR: sem validação automática, vai direto ao designer.") + r.partes = [caminho] + return r + + r = validar(caminho, cm_comprados) + r.natureza = natureza + if not r.aprovado: + return r + + r.metros_totais = cm_comprados / 100 * repeticoes + prefixo = os.path.join(pasta_saida, pedido) + + empilhado = empilhar(caminho, repeticoes, f"{prefixo}_full.png") + partes = fatiar(empilhado, r.metros_totais, prefixo) + + # o carimbo vai só na última parte: é ela que fecha o pedido + partes[-1] = carimbar( + partes[-1], + pedido=pedido, + metros=r.metros_totais, + url_kanban=f"{base_kanban}/p/{pedido}", + dpi=r.dpi_efetivo, + ) + r.partes = partes + return r + + +if __name__ == "__main__": + # conferência rápida da regra de fatiamento + for m in (20, 15, 16, 45, 100): + print(f"{m:>4} m -> {quantas_partes(m)} arquivo(s)") diff --git a/portal/tiny.py b/portal/tiny.py new file mode 100644 index 0000000..8e737d2 --- /dev/null +++ b/portal/tiny.py @@ -0,0 +1,89 @@ +""" +Cliente da API do Tiny (Olist) — v3, OAuth2 client credentials. + +ATENÇÃO Wagner: confirmar na documentação oficial antes de subir: + - o endpoint exato de marcadores do pedido + - o limite de requisições por minuto (dimensiona o worker) + - se o refresh token expira e com que frequência +Este módulo isola a API: se o endpoint mudar, muda só aqui. +""" +from __future__ import annotations + +import os +import time + +import httpx + +BASE = os.environ.get("TINY_BASE", "https://api.tiny.com.br/public-api/v3") +CLIENT_ID = os.environ["TINY_CLIENT_ID"] +CLIENT_SECRET = os.environ["TINY_CLIENT_SECRET"] +TOKEN_URL = os.environ["TINY_TOKEN_URL"] + +_token: dict = {"valor": None, "expira": 0.0} + + +def _acesso() -> str: + if _token["valor"] and time.time() < _token["expira"] - 60: + return _token["valor"] + r = httpx.post(TOKEN_URL, data={ + "grant_type": "client_credentials", + "client_id": CLIENT_ID, + "client_secret": CLIENT_SECRET, + }, timeout=20) + r.raise_for_status() + d = r.json() + _token["valor"] = d["access_token"] + _token["expira"] = time.time() + d.get("expires_in", 3600) + return _token["valor"] + + +def _headers() -> dict: + return {"Authorization": f"Bearer {_acesso()}", "Content-Type": "application/json"} + + +def buscar_pedido(numero: str) -> dict: + r = httpx.get(f"{BASE}/pedidos", params={"numero": numero}, + headers=_headers(), timeout=20) + r.raise_for_status() + itens = r.json().get("itens") or [] + if not itens: + raise LookupError(f"pedido {numero} não encontrado no Tiny") + return itens[0] + + +def transferido_para_deposito(sku: str, deposito: str, dias: int) -> float: + """ + Soma o que foi transferido para o depósito de impressão no período. + + A Altus já faz essa transferência hoje, porque também revende insumo — o + depósito separa consumo interno de revenda. Por isso o aproveitamento sai + de graça: nenhum apontamento novo na sala. + + ATENÇÃO Wagner: confirmar o endpoint de movimentações de estoque por + depósito na API v3 e o nome exato do depósito no cadastro. + """ + r = httpx.get( + f"{BASE}/estoque/movimentacoes", + params={"codigo": sku, "deposito": deposito, "dias": dias, "tipo": "E"}, + headers=_headers(), timeout=30, + ) + r.raise_for_status() + return sum(float(m.get("quantidade", 0)) for m in r.json().get("itens", [])) + + +def marcador(numero: str, marcador: str) -> None: + """ + Troca o marcador do pedido. Substitui os marcadores de etapa do DTF, + preservando marcadores de outra natureza (multiempresa, VALE, Troca...). + """ + pedido = buscar_pedido(numero) + atuais = [m["descricao"] for m in pedido.get("marcadores", [])] + # só três marcadores de etapa vivem no Tiny; o resto do fluxo é do kanban + ETAPAS = {"DTF-RECEBIDA", "DTF-PRODUCAO", "CORRECAO DTF", "DTF-PRONTO"} + mantem = [m for m in atuais if m not in ETAPAS] + novos = mantem + [marcador] + + r = httpx.put(f"{BASE}/pedidos/{pedido['id']}/marcadores", + json={"marcadores": [{"descricao": m} for m in novos]}, + headers=_headers(), timeout=20) + r.raise_for_status() diff --git a/portal/whats.py b/portal/whats.py new file mode 100644 index 0000000..6b4e630 --- /dev/null +++ b/portal/whats.py @@ -0,0 +1,68 @@ +""" +Envio de WhatsApp. Três avisos ao cliente, não sete: + aprovada · em produção · finalizada (+ correção, a única que pede resposta) + +Provedor definido por WHATS_PROVEDOR = meta | zapi +A API oficial da Meta exige template aprovado para mensagem iniciada por nós. +""" +from __future__ import annotations + +import os + +import httpx + +PROVEDOR = os.environ.get("WHATS_PROVEDOR", "meta") +TOKEN = os.environ.get("WHATS_TOKEN", "") +NUMERO_ID = os.environ.get("WHATS_NUMERO_ID", "") +ZAPI_URL = os.environ.get("ZAPI_URL", "") + +TEXTOS = { + "prova_cor": ("Antes de imprimir o pedido {pedido} inteiro, fizemos uma amostra " + "de cor. Confira a foto e responda APROVO para seguirmos. A cor no " + "filme pode variar em relação ao seu monitor."), + "producao": "Seu pedido {pedido} entrou em produção. Avisamos quando ficar pronto.", + "concluido": "Pedido {pedido} finalizado e pronto para retirada ou envio.", + "correcao": "Precisamos de um ajuste na arte do pedido {pedido}: {motivo}", +} + + +def _enviar(telefone: str, texto: str) -> None: + if PROVEDOR == "zapi": + httpx.post(ZAPI_URL, json={"phone": telefone, "message": texto}, timeout=20) + return + httpx.post( + f"https://graph.facebook.com/v20.0/{NUMERO_ID}/messages", + headers={"Authorization": f"Bearer {TOKEN}"}, + json={"messaging_product": "whatsapp", "to": telefone, + "type": "text", "text": {"body": texto}}, + timeout=20, + ).raise_for_status() + + +def enviar_link(telefone: str, pedido: str, link: str) -> None: + _enviar(telefone, + f"Pedido {pedido} confirmado. Envie sua arte por aqui: {link}\n" + "O link vale por 7 dias. Gabarito 57 × 97 cm, PNG 300 DPI com fundo " + "transparente.") + + +def enviar_aprovacao(pedido, r) -> None: + n = len(r.partes) + _enviar(pedido.telefone if hasattr(pedido, "telefone") else "", + f"Arte do pedido {pedido.numero_tiny} aprovada. " + f"{r.metros_totais:.2f} m em {n} arquivo{'s' if n > 1 else ''}. " + "Entrou na fila de impressão.".replace(".", ",", 1)) + + +def enviar_recusa(pedido, motivo: str) -> None: + _enviar(getattr(pedido, "telefone", ""), + f"A arte do pedido {pedido.numero_tiny} precisa de ajuste: {motivo}\n" + "O prazo só começa a contar depois que a arte for aprovada.") + + +def avisar(pedido: str, tipo: str, motivo: str = "") -> None: + # o telefone vem do cadastro do pedido no Tiny + import tiny + p = tiny.buscar_pedido(pedido) + telefone = (p.get("cliente") or {}).get("fone", "") + _enviar(telefone, TEXTOS[tipo].format(pedido=pedido, motivo=motivo)) diff --git a/requirements.txt b/requirements.txt new file mode 100644 index 0000000..329e014 --- /dev/null +++ b/requirements.txt @@ -0,0 +1,10 @@ +fastapi==0.115.* +uvicorn[standard]==0.32.* +sqlmodel==0.0.22 +psycopg[binary]==3.2.* +boto3==1.35.* +httpx==0.27.* +pyvips==2.2.* +qrcode==7.4.* +pillow==10.4.* +python-multipart==0.0.12 diff --git a/schema.sql b/schema.sql new file mode 100644 index 0000000..ccb5b4c --- /dev/null +++ b/schema.sql @@ -0,0 +1,222 @@ +-- ===================================================================== +-- Módulo DTF — schema completo +-- ===================================================================== +-- Duas bases: +-- NUVEM (PostgreSQL, no VPS) → pedido, arte, parte, job, agente +-- LOCAL (SQLite, na fábrica) → card, movimento, retrabalho, job_local +-- +-- A separação é proposital: o kanban precisa funcionar com a internet fora. +-- ===================================================================== + + +-- ===================================================================== +-- NUVEM · PostgreSQL +-- ===================================================================== + +CREATE TABLE pedido ( + id BIGSERIAL PRIMARY KEY, + numero_tiny TEXT NOT NULL UNIQUE, -- chave de tudo + cliente TEXT NOT NULL, + telefone TEXT NOT NULL, + metros NUMERIC(10,2) NOT NULL, -- metros comprados por arte + cliente_novo BOOLEAN NOT NULL DEFAULT false,-- dispara prova de cor + token TEXT NOT NULL UNIQUE, -- UUID v4 do link + token_expira TIMESTAMPTZ NOT NULL, -- 7 dias + lembrete_em TIMESTAMPTZ, -- 1h sem arte → cobra + criado_em TIMESTAMPTZ NOT NULL DEFAULT now() +); +CREATE INDEX ix_pedido_token ON pedido(token); +CREATE INDEX ix_pedido_semarte ON pedido(criado_em) + WHERE NOT EXISTS (SELECT 1 FROM arte WHERE arte.pedido_id = pedido.id); + + +CREATE TABLE arte ( + id BIGSERIAL PRIMARY KEY, + pedido_id BIGINT NOT NULL REFERENCES pedido(id), + arquivo TEXT NOT NULL, -- chave no storage + arquivo_orig TEXT, -- original preservado + bytes BIGINT NOT NULL DEFAULT 0, + formato_orig TEXT, -- png, pdf, psd, cdr... + natureza TEXT, -- vetor | raster | conferir + repeticoes INT NOT NULL DEFAULT 1, + status TEXT NOT NULL DEFAULT 'recebida', + -- recebida | processando | aprovada | recusada + conferir_manual BOOLEAN NOT NULL DEFAULT false,-- CDR + motivo TEXT, -- por que foi recusada + avisos TEXT, -- aceitou mas com ressalva + dpi_efetivo NUMERIC(8,2), + largura_cm NUMERIC(8,2), + metros_totais NUMERIC(10,2), + minutos_maquina INT, -- estimativa; vira campo no card + cores_tensas TEXT, -- fora do gamut, se houver + virus_ok BOOLEAN NOT NULL DEFAULT false,-- ClamAV liberou + baixada BOOLEAN NOT NULL DEFAULT false,-- o agente já trouxe + criado_em TIMESTAMPTZ NOT NULL DEFAULT now() +); +CREATE INDEX ix_arte_pedido ON arte(pedido_id); +CREATE INDEX ix_arte_baixar ON arte(status, baixada, virus_ok); + + +CREATE TABLE parte ( + id BIGSERIAL PRIMARY KEY, + arte_id BIGINT NOT NULL REFERENCES arte(id), + ordem INT NOT NULL, + metros NUMERIC(10,2) NOT NULL, + arquivo TEXT NOT NULL, + carimbada BOOLEAN NOT NULL DEFAULT false,-- só a última leva carimbo + UNIQUE (arte_id, ordem) +); + + +-- Fila de jobs. Tabela, não broker: no volume da Altus (algumas centenas de +-- pedidos/dia) Redis e Celery são complexidade sem retorno. +-- Consumir com: SELECT ... FOR UPDATE SKIP LOCKED +CREATE TABLE job ( + id BIGSERIAL PRIMARY KEY, + tipo TEXT NOT NULL, -- preflight | whats | tiny | limpeza + payload JSONB NOT NULL, + tentativas INT NOT NULL DEFAULT 0, + proxima_em TIMESTAMPTZ NOT NULL DEFAULT now(), + erro TEXT, + feito BOOLEAN NOT NULL DEFAULT false, + criado_em TIMESTAMPTZ NOT NULL DEFAULT now() +); +CREATE INDEX ix_job_fila ON job(feito, proxima_em) WHERE NOT feito; + + +CREATE TABLE agente_heartbeat ( + id SERIAL PRIMARY KEY, + visto_em TIMESTAMPTZ NOT NULL DEFAULT now() +); +-- sem sinal por 15 min → alertar o TI + + +-- Artes guardadas para recompra. Prefixo separado no storage, retenção 12 meses. +CREATE TABLE arte_cliente ( + id BIGSERIAL PRIMARY KEY, + numero_cliente TEXT NOT NULL, + token_cliente TEXT NOT NULL, -- link permanente + arte_id BIGINT REFERENCES arte(id), + arquivo TEXT NOT NULL, -- só a arte tratada + descricao TEXT, + criado_em TIMESTAMPTZ NOT NULL DEFAULT now(), + expira_em TIMESTAMPTZ NOT NULL +); +CREATE INDEX ix_arte_cliente ON arte_cliente(numero_cliente, token_cliente); + + +-- ===================================================================== +-- LOCAL · SQLite (na fábrica) +-- ===================================================================== + +CREATE TABLE card ( + arte_id INTEGER PRIMARY KEY, + pedido TEXT NOT NULL, + cliente TEXT NOT NULL, + metros REAL NOT NULL, + minutos_maquina INTEGER, -- estimativa. Herda os marcadores 30min/1h/3h + -- do Tiny. Sugerida por metros/20*60; quem + -- trata a arte ajusta só quando foge do normal + partes INTEGER NOT NULL DEFAULT 1, + coluna TEXT NOT NULL DEFAULT 'rec', + -- rec | tra | apc | fil | imp | cor | fin + -- NÃO existe coluna de aplicação: a sala só imprime o filme + desde TEXT NOT NULL, -- entrada na coluna atual (ISO) + maquina TEXT, -- 'Maq 1' … 'Maq 6' + reservado_por TEXT, -- máquina que puxou + reservado_em TEXT, -- expira em 3 min (ajuste da sala) + conferir_manual INTEGER NOT NULL DEFAULT 0 +); +CREATE INDEX ix_card_coluna ON card(coluna, desde); + + +-- A tabela mais importante do sistema. Dela saem TODOS os números que hoje +-- não existem: tempo por etapa, fila por máquina, retrabalho, ocupação real. +CREATE TABLE movimento ( + id INTEGER PRIMARY KEY AUTOINCREMENT, + arte_id INTEGER NOT NULL, + pedido TEXT NOT NULL, + de TEXT NOT NULL, + para TEXT NOT NULL, + entrou_em TEXT NOT NULL, + saiu_em TEXT NOT NULL, + segundos INTEGER NOT NULL, + usuario TEXT NOT NULL, -- login do PCP. Se o PC tiver login + -- compartilhado, o indicador de retrabalho + -- por pessoa fica sem dono + maquina TEXT +); +CREATE INDEX ix_mov_arte ON movimento(arte_id); +CREATE INDEX ix_mov_saiu ON movimento(saiu_em); +CREATE INDEX ix_mov_etapa ON movimento(de, saiu_em); + + +CREATE TABLE retrabalho ( + id INTEGER PRIMARY KEY AUTOINCREMENT, + pedido_origem TEXT NOT NULL, + pedido_novo TEXT, + metros REAL NOT NULL, + causa TEXT NOT NULL, + -- arte_cliente | tratamento | impressao | perfil_cor | pedido + -- TRAVADA depois de aberta: com o indicador atrelado a bônus, + -- haveria incentivo para reclassificar falha de máquina como + -- culpa do cliente + aberto_por TEXT NOT NULL, -- Mayana: conhece o cliente e a reclamação + aberto_em TEXT NOT NULL, + vez INTEGER NOT NULL DEFAULT 1, -- 2ª sobe alçada, 3ª trava + alcada TEXT NOT NULL, -- sala | financeiro | diretoria + autorizado_por TEXT, -- Thales ou Alexandre: entra na meta deles + autorizado_em TEXT, + contestado_por TEXT, -- discorda da causa mas não pode mudá-la + contestado_em TEXT, + contestacao TEXT, + evidencia TEXT -- foto ou print da reclamação +); +CREATE INDEX ix_retra_data ON retrabalho(aberto_em); +CREATE INDEX ix_retra_causa ON retrabalho(causa, aberto_em); + + +CREATE TABLE job_local ( + id INTEGER PRIMARY KEY AUTOINCREMENT, + tipo TEXT NOT NULL, -- tiny_marcador | whats + payload TEXT NOT NULL, + tentativas INTEGER NOT NULL DEFAULT 0, + proxima_em REAL NOT NULL, -- 1, 5 e 30 min + erro TEXT, + feito INTEGER NOT NULL DEFAULT 0 +); +CREATE INDEX ix_joblocal ON job_local(feito, proxima_em); + + +-- Consumo de filme, para o aproveitamento. NÃO exige apontamento novo: +-- lê as transferências para o depósito de impressão no Tiny. +CREATE TABLE consumo_filme ( + id INTEGER PRIMARY KEY AUTOINCREMENT, + em TEXT NOT NULL, + metros REAL NOT NULL, + origem TEXT NOT NULL DEFAULT 'tiny' -- transferência de depósito +); + + +-- ===================================================================== +-- Consultas que o painel usa +-- ===================================================================== + +-- Tempo médio por etapa nos últimos N dias +-- SELECT de, COUNT(*) n, AVG(segundos)/60 media_min, MAX(segundos)/60 pior_min +-- FROM movimento WHERE saiu_em >= date('now','-7 days') GROUP BY de; + +-- Velocidade real por máquina — é o número que valida ou derruba os 20 m/h +-- SELECT m.maquina, SUM(c.metros) metros, SUM(m.segundos)/3600.0 horas, +-- SUM(c.metros)/(SUM(m.segundos)/3600.0) m_por_hora +-- FROM movimento m JOIN card c ON c.arte_id = m.arte_id +-- WHERE m.de='imp' AND m.saiu_em >= date('now','-7 days') GROUP BY m.maquina; + +-- Retrabalho por causa, com responsável +-- SELECT causa, COUNT(*) n, SUM(metros) m FROM retrabalho +-- WHERE aberto_em >= date('now','-30 days') GROUP BY causa; + +-- Aproveitamento do filme +-- faturado = SELECT SUM(metros) FROM card WHERE coluna='fin' AND desde >= ... +-- consumido = SELECT SUM(metros) FROM consumo_filme WHERE em >= ... +-- aproveitamento = faturado / consumido diff --git a/staging/README.md b/staging/README.md new file mode 100644 index 0000000..d1cc439 --- /dev/null +++ b/staging/README.md @@ -0,0 +1,24 @@ +# Staging readiness gate + +This directory does not contain a staging deployment and does not authorize any +real integration. It provides a separate, network-disabled validation root for +the non-secret decisions in `PRODUCTION_INPUTS.md`. + +1. Complete the business and technical decisions in `PRODUCTION_INPUTS.md`. +2. Copy `staging.env.example` to `staging.env` and replace the `TBD` values with + non-secret metadata only. `staging.env` is ignored by Git and Docker builds. +3. Run: + + ```bash + docker compose -f compose.staging.yaml run --rm readiness + ``` + +The gate rejects incomplete values, local endpoints, fake provider selections, +embedded secret-like settings, and unsafe secret-source choices. The readiness +container has no network. A pass means only that the required non-secret inputs +are structurally complete; it does not prove provider access, security, business +approval, compatibility, or production readiness. + +The actual staging application composition must be created only after these +inputs and provider contracts are approved. Secrets must be injected from the +approved external mechanism and must never be copied into this repository. diff --git a/staging/staging.env.example b/staging/staging.env.example new file mode 100644 index 0000000..211c730 --- /dev/null +++ b/staging/staging.env.example @@ -0,0 +1,17 @@ +# NON-SECRET METADATA ONLY. Copy to staging/staging.env after decisions are made. +# The copied file is ignored. Never put tokens, passwords, access keys, webhook +# secrets, private keys, credentials, or customer information in either file. +APP_ENV=staging +STAGING_APPROVED_BY=TBD +STAGING_PUBLIC_ORIGIN=TBD +STAGING_S3_ENDPOINT=TBD +STAGING_S3_BUCKET=TBD +STAGING_DATABASE_MODE=TBD +STAGING_SECRET_SOURCE=TBD +STAGING_BACKUP_DESTINATION=TBD +STAGING_FREIGHT_PROVIDER=TBD +STAGING_PAYMENT_PROVIDER=TBD +STAGING_ERP_PROVIDER=TBD +STAGING_WHATSAPP_PROVIDER=TBD +STAGING_ALERT_OWNER=TBD +STAGING_ROLLBACK_OWNER=TBD diff --git a/tmp/pdfs/current-roadmap.txt b/tmp/pdfs/current-roadmap.txt new file mode 100644 index 0000000..a7f6ffe --- /dev/null +++ b/tmp/pdfs/current-roadmap.txt @@ -0,0 +1,329 @@ +PLANO DE ENTREGA + + + +Sistema DTF +Plano de entrega +Uma operação em que o cliente envia a arte, recebe análise, paga e +acompanha a produção sem depender de WhatsApp, pastas ou repasse +manual. + + + + OBJETIVO DECISÃO DE ARQUITETURA + + + Portal e Kanban online + + Transformar capacidade ociosa Cloudflare R2 + VPS existente. A + em atendimento e produção 24 impressão continua manual na + horas. fábrica. + + + +Consolidação das discussões técnicas e comerciais - setembro de 2026 + DTF Dropstar - plano de entrega + + + + CONTEXTO + + + O problema que vamos resolver + A sala de DTF tem capacidade instalada muito maior que a produção atual. O gargalo não é a máquina: + é o fluxo entre o pedido, a arte, o designer e a sala. Hoje o cliente envia arquivo no WhatsApp, o + atendimento repassa, o designer descobre problemas tarde e o status fica escondido em pastas de rede. + + O projeto resolve quatro falhas do processo: + • Recebimento limitado pelo horário: um cliente que chega no fim do dia espera até o turno seguinte. + • Arquivo sem rastreabilidade: WhatsApp e nomes digitados manualmente facilitam perda e erro. + • Arquivo ruim chega tarde ao designer: qualidade, dimensão e transparência são verificadas depois de + consumir tempo humano. + • Produção sem números: não há registro confiável de espera, velocidade real, fila ou retrabalho. + + + ANTES DEPOIS + + + Pedido e arte circulam por WhatsApp e pastas. Site DTF recebe a arte, analisa, precifica e registra o + fluxo. + + + Designer corrige indiscriminadamente. Arte pronta segue rápido; exceções vão para atendimento + humano. + + + Sala não enxerga fila real nem tempos. Kanban online organiza a fila e registra cada movimento + manualmente. + + + + + Página 2 + DTF Dropstar - plano de entrega + + + + MODELO OPERACIONAL + + + Como será a jornada do pedido + + Escolhe o produto, envia a arte e vê o valor conforme as regras comerciais + Cliente entra no site DTF + 1 já configuradas. + + + Calcula a metragem e prepara o pedido. O pré-flight automático será + Sistema registra a arte + 2 validado depois da entrega, com arquivos reais. + + + O checkout é do Mercado Pago; os dados do cartão não passam pelo nosso + Cliente paga + 3 servidor. + + + Depois da confirmação do pagamento, o pedido é criado no Tiny e aparece + Pedido entra no sistema + 4 no Kanban. + + + O operador baixa o arquivo final no Kanban, importa no FlexiPRINT e + Equipe baixa e imprime + 5 atualiza o card. + + + + + Onde o WhatsApp entra + O WhatsApp deixa de ser o lugar onde a arte é enviada. Ele serve para avisar o cliente: pagamento + aprovado, pedido em produção, pedido pronto ou necessidade de correção. Quando houver problema, a + mensagem leva o cliente de volta para o site. + + Cuidados na automação: se Mercado Pago, Tiny ou WhatsApp reenviar um aviso por falha, o sistema confere antes de + agir. Assim, não cria dois pedidos nem manda a mesma mensagem duas vezes. + + + + + Página 3 + DTF Dropstar - plano de entrega + + + + PRODUÇÃO + + + Arquitetura de software e infraestrutura + Todo o sistema roda na nuvem: recebe, processa, integra e disponibiliza o arquivo final. A fábrica acessa + o Kanban pelo navegador e baixa o arquivo quando for produzir; não há componente instalado na rede + interna. + + CLIENTE E INTEGRAÇÕES NUVEM / VPS EQUIPE DA FÁBRICA + + + + + Site DTF API FastAPI R2 Kanban online + arte, preço e checkout pedido, upload originais e fila, status e + acompanhamento do pedido e integrações arte final privada download seguro + + + + + Integrações externas Worker PostgreSQL Operador + Mercado Pago · Tiny/Olist antivírus e pedidos, jobs baixa e importa + WhatsApp Business pré-flight e histórico no FlexiPRINT + + + + + NUVEM Site DTF, Kanban online, API FastAPI, worker, ClamAV, PostgreSQL e Cloudflare R2. + + + FÁBRICA Navegador, operador e FlexiPRINT atual. O arquivo é baixado e importado manualmente. + + + TERCEIROS Mercado Pago, Tiny/Olist e WhatsApp Business API. + + + • Upload grande: o navegador manda o arquivo direto para o R2, em partes. O VPS não precisa receber 5 + GB de uma vez. + • Fila: o banco guarda o que precisa ser analisado, enviado ao Tiny, avisado no WhatsApp ou apagado no + prazo certo. + • Segurança: o arquivo entra em quarentena, passa pelo antivírus e só depois é analisado e liberado no + Kanban. + • Se a fábrica ficar sem internet: o site continua no ar. A equipe apenas não consegue baixar arquivo + novo ou atualizar o Kanban até a conexão voltar. + + + + + Página 4 + DTF Dropstar - plano de entrega + + + + CLOUDFLARE + + + R2: custos e retenção + O R2 é onde os arquivos ficam guardados. Ele é privado: o operador só baixa pelo Kanban, com link + temporário. O custo vem principalmente da média de GB guardados no mês; leitura e gravação + costumam pesar bem menos. O download não tem cobrança de saída de dados. + + + MÉDIA ARMAZENADA R2 / MÊS APROX. EM R$* + + + 100 GB US$ 1,35 R$ 7 + + + 500 GB US$ 7,35 R$ 38 + + + 1 TB US$ 14,85 R$ 76 + + + 3 TB US$ 44,85 R$ 230 + + * Referência de US$ 1 = R$ 5,13; câmbio, impostos e tarifas do meio de pagamento podem variar. + + + ARTEFATO PRAZO REGRA + + + Upload multipart incompleto 1 dia Abortado automaticamente. + + + Recusado ou infectado 3 dias Suporte pode conferir; depois apaga. + + + Original do cliente até 7 dias Após aprovação, não fica guardado sem necessidade. + + + Arte pronta para impressão máx. 30 dias Prazo conta do primeiro upload; permite correção ou + reimpressão recente. + + + Histórico e métricas banco Sem manter a imagem. + + + Decisão: não haverá biblioteca infinita de artes. Após o prazo, o cliente reenvia o arquivo; o pedido e sua + rastreabilidade permanecem registrados. + + + + + Página 5 + DTF Dropstar - plano de entrega + + + + OPERAÇÃO, PUBLICAÇÃO E CONTINUIDADE + + + Como fica em produção + A primeira entrega será operada como uma única aplicação na VPS. Portal, Kanban, processamento e + banco seguem o mesmo ciclo de publicação, com acesso da fábrica exclusivamente pelo navegador. + Isso reduz pontos de manutenção e mantém a operação independente da rede interna. + + + AMBIENTE COMPONENTES OPERAÇÃO + + + Sistema DTF site DTF, Kanban online, API, processamento, antivírus, banco VPS com armazenamento + de dados e cópia diária de segurança persistente; operação e + acompanhamento + centralizados + + + + + Publicação com controle + • Toda alteração passa por testes automáticos antes de poder chegar ao ambiente de produção. + • Cada publicação fica identificada pela versão do código, permitindo restaurar rapidamente a versão + anterior se houver qualquer problema. + • As mudanças são conferidas primeiro em ambiente de validação e só então liberadas para a operação. + • Ao final da publicação, uma verificação confirma que os serviços essenciais voltaram a responder antes + de encerrar o processo. + • Credenciais de storage, pagamentos, integrações e banco permanecem fora do código e são tratadas + como dados restritos do ambiente. + + + Acompanhamento operacional + A rotina de operação acompanha disponibilidade do site e do Kanban, andamento da fila de processamento, falhas de + integração e resultado das cópias de segurança. Assim, qualquer desvio é identificado antes de interromper o + atendimento ou a produção. + + + + + Página 6 + DTF Dropstar - plano de entrega + + + + MVP EM ATÉ 3 SEMANAS + + + Roadmap de implementação + O cronograma considera a base de código existente e dedicação integral. A prioridade é concluir o fluxo + completo - envio, pagamento, frete, pedido e acompanhamento - antes de qualquer integração com as + máquinas. As regras comerciais seguem exatamente o que já está configurado no Site DTF. + + + QUANDO ENTREGA RESULTADO + + + Sem. 1 Infraestrutura e upload VPS, domínio, banco, R2, upload multipart, antivírus e base do + serviço. + + + Sem. 2 Pagamento, frete e pedido Mercado Pago, cotação de frete, criação idempotente no Tiny, + geração do arquivo final e estados principais do Kanban. + + + Sem. 3 Kanban e entrega Kanban online, download seguro, mensagens de status no WhatsApp, + retenção de 30 dias e orientação à operação. + + + + + Fora da primeira entrega + A primeira entrega termina no download do arquivo final pelo Kanban e na orientação de uso à operação. Integração + direta com FlexiPRINT, agente dentro da fábrica, pasta monitorada, painel de sala e relatórios avançados não fazem + parte deste prazo. O pré-flight automático será validado depois da entrega, com arquivos e impressão reais. A fábrica + mantém esses recursos no ambiente atual; após a entrega, damos suporte e avaliamos mudanças conforme a + necessidade. + + + O que fica com a operação + • Acessar o Kanban, baixar o arquivo final e importá-lo manualmente no FlexiPRINT atual. + • Realizar os testes de impressão e informar qualquer diferença encontrada no arquivo ou no resultado + impresso. + • Manter computadores, FlexiPRINT, perfis de impressão, impressoras e eventuais pastas internas + funcionando. + • A conexão local é necessária apenas para a equipe acessar o Kanban e baixar o arquivo na fábrica. Se + ela cair, portal, pagamentos, uploads e fila continuam ativos na nuvem; a produção retoma quando o + acesso local voltar. + • Comunicar mudanças de preços, frete ou regras operacionais que precisem ser refletidas no sistema. + + + O que precisamos para começar + • Credenciais do Mercado Pago, incluindo a configuração do webhook para confirmação de pagamento. + • Dados da integração de frete: plataforma(s) já utilizada(s), acesso à API, CEP de origem, serviços + oferecidos, regra de cobrança e referência de peso e dimensões por pacote. + + + Antes de começar + Com esses acessos e dados liberados, a primeira semana pode começar. A tabela, os descontos e as regras comerciais + já existentes no Site DTF serão mantidos. Tiny/Olist e WhatsApp já estão disponíveis; durante o desenvolvimento será + definida a ligação técnica dessas integrações com os eventos do pedido. A fábrica valida a impressão depois, baixando + o arquivo final pelo Kanban. + + + + + Página 7 + \ No newline at end of file diff --git a/tmp/pdfs/generate_dtf_report.py b/tmp/pdfs/generate_dtf_report.py new file mode 100644 index 0000000..3173da0 --- /dev/null +++ b/tmp/pdfs/generate_dtf_report.py @@ -0,0 +1,438 @@ +from pathlib import Path +import math + +from reportlab.lib import colors +from reportlab.lib.enums import TA_CENTER, TA_LEFT +from reportlab.lib.pagesizes import A4 +from reportlab.lib.styles import ParagraphStyle, getSampleStyleSheet +from reportlab.lib.units import cm +from reportlab.pdfbase import pdfmetrics +from reportlab.pdfbase.ttfonts import TTFont +from reportlab.platypus import ( + BaseDocTemplate, Frame, PageBreak, PageTemplate, Paragraph, Spacer, + Table, TableStyle, KeepTogether, Flowable, +) + + +ROOT = Path(__file__).resolve().parents[2] +OUT = ROOT / "output/pdf/dtf-plano-producao-e-roadmap.pdf" +FONT = "/usr/share/fonts/TTF/DejaVuSans.ttf" +FONT_BOLD = "/usr/share/fonts/TTF/DejaVuSans-Bold.ttf" + +pdfmetrics.registerFont(TTFont("DejaVu", FONT)) +pdfmetrics.registerFont(TTFont("DejaVu-Bold", FONT_BOLD)) + +NAVY = colors.HexColor("#071426") +BLUE = colors.HexColor("#1463D8") +SKY = colors.HexColor("#EAF2FF") +ORANGE = colors.HexColor("#FF8A1F") +GREEN = colors.HexColor("#16825B") +RED = colors.HexColor("#B83737") +INK = colors.HexColor("#162235") +MUTED = colors.HexColor("#607085") +LINE = colors.HexColor("#D9E1EA") +PALE = colors.HexColor("#F6F8FB") +WHITE = colors.white + + +class Rule(Flowable): + def __init__(self, color=ORANGE, width=4.0, length=54): + Flowable.__init__(self) + self.color, self.thickness, self.length = color, width, length + self.width, self.height = length, width + + def draw(self): + self.canv.setStrokeColor(self.color) + self.canv.setLineWidth(self.thickness) + self.canv.line(0, self.thickness / 2, self.length, self.thickness / 2) + + +class ArchitectureDiagram(Flowable): + """Small three-zone diagram drawn in vector primitives.""" + def __init__(self): + Flowable.__init__(self) + self.width, self.height = 17.0 * cm, 7.2 * cm + + def box(self, x, y, w, h, title, sub, fill, accent): + c = self.canv + c.setFillColor(fill) + c.setStrokeColor(accent) + c.setLineWidth(1) + c.roundRect(x, y, w, h, 7, fill=1, stroke=1) + c.setFillColor(INK) + c.setFont("DejaVu-Bold", 8.3) + c.drawString(x + 8, y + h - 16, title) + c.setFillColor(MUTED) + c.setFont("DejaVu", 6.6) + for i, line in enumerate(sub.split("\n")): + c.drawString(x + 8, y + h - 29 - 9 * i, line) + + def _arrowhead(self, tip_x, tip_y, from_x, from_y): + c = self.canv + dx, dy = from_x - tip_x, from_y - tip_y + distance = math.hypot(dx, dy) + if not distance: + return + ux, uy = dx / distance, dy / distance + angle = math.radians(28) + arm = 5 + for sign in (-1, 1): + vx = ux * math.cos(angle) - sign * uy * math.sin(angle) + vy = uy * math.cos(angle) + sign * ux * math.sin(angle) + c.line(tip_x, tip_y, tip_x + arm * vx, tip_y + arm * vy) + + def arrow(self, x1, y1, x2, y2, label=None): + c = self.canv + c.setStrokeColor(colors.HexColor("#8BA0B8")) + c.setFillColor(colors.HexColor("#8BA0B8")) + c.setLineWidth(1.1) + c.line(x1, y1, x2, y2) + self._arrowhead(x2, y2, x1, y1) + if label: + c.setFillColor(MUTED) + c.setFont("DejaVu", 5.9) + c.drawCentredString((x1 + x2) / 2, (y1 + y2) / 2 + 4, label) + + def double_arrow(self, x1, y1, x2, y2, label=None): + c = self.canv + c.setStrokeColor(colors.HexColor("#8BA0B8")) + c.setFillColor(colors.HexColor("#8BA0B8")) + c.setLineWidth(1.1) + c.line(x1, y1, x2, y2) + self._arrowhead(x1, y1, x2, y2) + self._arrowhead(x2, y2, x1, y1) + if label: + c.setFillColor(MUTED) + c.setFont("DejaVu", 5.9) + c.drawCentredString((x1 + x2) / 2, (y1 + y2) / 2 + 4, label) + + def draw(self): + c = self.canv + zones = [(0, 0, 142, "CLIENTE E INTEGRAÇÕES"), (152, 0, 214, "NUVEM / VPS"), + (376, 0, 106, "EQUIPE DA FÁBRICA")] + for x, y, w, name in zones: + c.setFillColor(PALE) + c.setStrokeColor(LINE) + c.roundRect(x, 0, w, self.height, 8, fill=1, stroke=1) + c.setFillColor(MUTED) + c.setFont("DejaVu-Bold", 6.4) + c.drawString(x + 9, self.height - 13, name) + self.box(12, 117, 120, 40, "Site DTF", "arte, preço e checkout\nacompanhamento do pedido", WHITE, ORANGE) + self.box(12, 48, 120, 40, "Integrações externas", "Mercado Pago · Tiny/Olist\nWhatsApp Business", WHITE, BLUE) + self.box(162, 117, 88, 40, "API FastAPI", "pedido, upload\ne integrações", SKY, BLUE) + self.box(258, 117, 92, 40, "R2", "originais e\narte final privada", SKY, BLUE) + self.box(162, 48, 88, 40, "Worker", "antivírus e\npré-flight", SKY, GREEN) + self.box(258, 48, 92, 40, "PostgreSQL", "pedidos, jobs\ne histórico", SKY, BLUE) + self.box(388, 117, 82, 40, "Kanban online", "fila, status e\ndownload seguro", WHITE, colors.HexColor("#7650B8")) + self.box(388, 48, 82, 40, "Operador", "baixa e importa\nno FlexiPRINT", WHITE, colors.HexColor("#7650B8")) + self.arrow(132, 137, 162, 137) + self.double_arrow(132, 88, 162, 117) + self.arrow(250, 137, 258, 137) + self.arrow(206, 117, 206, 88) + self.double_arrow(250, 117, 258, 88) + self.double_arrow(250, 68, 258, 68) + self.arrow(350, 137, 388, 137) + self.arrow(429, 117, 429, 88) + + +def paragraph(text, style): + return Paragraph(text, style) + + +def bullet(text, styles): + return Paragraph(f"•  {text}", styles["bullet"]) + + +def section_title(text, styles, kicker=None): + blocks = [] + if kicker: + blocks.append(Paragraph(kicker.upper(), styles["kicker"])) + blocks.append(Spacer(1, 3)) + blocks += [Paragraph(text, styles["dtf_h1"]), Spacer(1, 7), Rule(), Spacer(1, 12)] + return blocks + + +def on_page(canvas, doc): + if doc.page == 1: + return + canvas.saveState() + canvas.setStrokeColor(LINE) + canvas.line(doc.leftMargin, A4[1] - 1.25 * cm, A4[0] - doc.rightMargin, A4[1] - 1.25 * cm) + canvas.setFont("DejaVu", 7.4) + canvas.setFillColor(MUTED) + canvas.drawString(doc.leftMargin, A4[1] - 1.05 * cm, "DTF Dropstar - plano de entrega") + canvas.drawRightString(A4[0] - doc.rightMargin, 0.82 * cm, f"Página {doc.page}") + canvas.restoreState() + + +def build_pdf(): + styles = getSampleStyleSheet() + styles.add(ParagraphStyle(name="cover_kicker", fontName="DejaVu-Bold", fontSize=10, + leading=13, textColor=ORANGE, spaceAfter=10, letterSpacing=0.6)) + styles.add(ParagraphStyle(name="cover_title", fontName="DejaVu-Bold", fontSize=30, + leading=35, textColor=WHITE, spaceAfter=11)) + styles.add(ParagraphStyle(name="cover_text", fontName="DejaVu", fontSize=12, + leading=17, textColor=colors.HexColor("#D6E0EF"))) + styles.add(ParagraphStyle(name="kicker", fontName="DejaVu-Bold", fontSize=8, + leading=10, textColor=ORANGE, letterSpacing=0.7)) + styles.add(ParagraphStyle(name="dtf_h1", fontName="DejaVu-Bold", fontSize=20, + leading=24, textColor=NAVY, spaceAfter=0)) + styles.add(ParagraphStyle(name="dtf_h2", fontName="DejaVu-Bold", fontSize=12, + leading=15, textColor=INK, spaceBefore=6, spaceAfter=5)) + styles.add(ParagraphStyle(name="body", fontName="DejaVu", fontSize=9.3, + leading=14, textColor=INK, spaceAfter=8)) + styles.add(ParagraphStyle(name="bullet", fontName="DejaVu", fontSize=9.1, + leading=13, textColor=INK, leftIndent=2, spaceAfter=4)) + styles.add(ParagraphStyle(name="small", fontName="DejaVu", fontSize=7.6, + leading=10.5, textColor=MUTED)) + styles.add(ParagraphStyle(name="cell", fontName="DejaVu", fontSize=7.7, + leading=10, textColor=INK)) + styles.add(ParagraphStyle(name="cell_bold", fontName="DejaVu-Bold", fontSize=7.7, + leading=10, textColor=INK)) + styles.add(ParagraphStyle(name="cell_white", fontName="DejaVu-Bold", fontSize=7.7, + leading=10, textColor=WHITE)) + styles.add(ParagraphStyle(name="note", fontName="DejaVu", fontSize=8.2, + leading=12, textColor=INK, backColor=colors.HexColor("#FFF4E7"), + borderColor=colors.HexColor("#F7D2A5"), borderWidth=0.5, + borderPadding=8, borderRadius=4)) + + doc = BaseDocTemplate(str(OUT), pagesize=A4, leftMargin=1.65 * cm, rightMargin=1.65 * cm, + topMargin=1.7 * cm, bottomMargin=1.45 * cm) + frame = Frame(doc.leftMargin, doc.bottomMargin, doc.width, doc.height, id="main") + doc.addPageTemplates([PageTemplate(id="main", frames=[frame], onPage=on_page)]) + story = [] + + # Cover + story.append(Spacer(1, 2.4 * cm)) + cover = [ + Paragraph("PLANO DE ENTREGA", styles["cover_kicker"]), + Paragraph("Sistema DTF
Plano de entrega", styles["cover_title"]), + Paragraph("Uma operação em que o cliente envia a arte, recebe análise, paga e acompanha a produção sem depender de WhatsApp, pastas ou repasse manual.", styles["cover_text"]), + Spacer(1, 28), + Table([[paragraph("OBJETIVO", styles["cover_kicker"]), paragraph("DECISÃO DE ARQUITETURA", styles["cover_kicker"])], + [paragraph("Transformar capacidade ociosa em atendimento e produção 24 horas.", styles["cover_text"]), + paragraph("Portal e Kanban online + Cloudflare R2 + VPS existente. A impressão continua manual na fábrica.", styles["cover_text"])]], + colWidths=[8.1 * cm, 8.1 * cm], style=TableStyle([ + ("BACKGROUND", (0, 0), (-1, -1), NAVY), + ("BOX", (0, 0), (-1, -1), 0.6, colors.HexColor("#40516B")), + ("INNERGRID", (0, 0), (-1, -1), 0.4, colors.HexColor("#40516B")), + ("LEFTPADDING", (0, 0), (-1, -1), 13), ("RIGHTPADDING", (0, 0), (-1, -1), 13), + ("TOPPADDING", (0, 0), (-1, -1), 11), ("BOTTOMPADDING", (0, 0), (-1, -1), 12), + ])), + Spacer(1, 0.7 * cm), + Paragraph("Consolidação das discussões técnicas e comerciais - setembro de 2026", styles["cover_text"]), + ] + cover_table = Table([[cover]], colWidths=[17.7 * cm], rowHeights=[23.6 * cm], style=TableStyle([ + ("BACKGROUND", (0, 0), (-1, -1), NAVY), + ("LEFTPADDING", (0, 0), (-1, -1), 1.15 * cm), + ("RIGHTPADDING", (0, 0), (-1, -1), 1.15 * cm), + ("TOPPADDING", (0, 0), (-1, -1), 1.05 * cm), + ("BOTTOMPADDING", (0, 0), (-1, -1), 1.05 * cm), + ])) + story.append(cover_table) + story.append(PageBreak()) + + # Context + story += section_title("O problema que vamos resolver", styles, "Contexto") + story.append(paragraph( + "A sala de DTF tem capacidade instalada muito maior que a produção atual. O gargalo não é a máquina: é o fluxo entre o pedido, a arte, o designer e a sala. Hoje o cliente envia arquivo no WhatsApp, o atendimento repassa, o designer descobre problemas tarde e o status fica escondido em pastas de rede.", + styles["body"])) + story.append(paragraph("O projeto resolve quatro falhas do processo:", styles["dtf_h2"])) + for item in [ + "Recebimento limitado pelo horário: um cliente que chega no fim do dia espera até o turno seguinte.", + "Arquivo sem rastreabilidade: WhatsApp e nomes digitados manualmente facilitam perda e erro.", + "Arquivo ruim chega tarde ao designer: qualidade, dimensão e transparência são verificadas depois de consumir tempo humano.", + "Produção sem números: não há registro confiável de espera, velocidade real, fila ou retrabalho.", + ]: + story.append(bullet(item, styles)) + story.append(Spacer(1, 7)) + decision = Table([ + [paragraph("ANTES", styles["cell_bold"]), paragraph("DEPOIS", styles["cell_bold"])], + [paragraph("Pedido e arte circulam por WhatsApp e pastas.", styles["cell"]), paragraph("Site DTF recebe a arte, analisa, precifica e registra o fluxo.", styles["cell"])], + [paragraph("Designer corrige indiscriminadamente.", styles["cell"]), paragraph("Arte pronta segue rápido; exceções vão para atendimento humano.", styles["cell"])], + [paragraph("Sala não enxerga fila real nem tempos.", styles["cell"]), paragraph("Kanban online organiza a fila e registra cada movimento manualmente.", styles["cell"])], + ], colWidths=[8.6 * cm, 8.6 * cm], style=TableStyle([ + ("BACKGROUND", (0, 0), (-1, 0), SKY), ("GRID", (0, 0), (-1, -1), 0.45, LINE), + ("VALIGN", (0, 0), (-1, -1), "TOP"), ("LEFTPADDING", (0, 0), (-1, -1), 9), + ("RIGHTPADDING", (0, 0), (-1, -1), 9), ("TOPPADDING", (0, 0), (-1, -1), 8), + ("BOTTOMPADDING", (0, 0), (-1, -1), 8), + ])) + story.append(decision) + story.append(PageBreak()) + + # Flow + story += section_title("Como será a jornada do pedido", styles, "Modelo operacional") + steps = [ + ("1", "Cliente entra no site DTF", "Escolhe o produto, envia a arte e vê o valor conforme as regras comerciais já configuradas."), + ("2", "Sistema registra a arte", "Calcula a metragem e prepara o pedido. O pré-flight automático será validado depois da entrega, com arquivos reais."), + ("3", "Cliente paga", "O checkout é do Mercado Pago; os dados do cartão não passam pelo nosso servidor."), + ("4", "Pedido entra no sistema", "Depois da confirmação do pagamento, o pedido é criado no Tiny e aparece no Kanban."), + ("5", "Equipe baixa e imprime", "O operador baixa o arquivo final no Kanban, importa no FlexiPRINT e atualiza o card."), + ] + rows = [] + for n, title, text in steps: + rows.append([ + paragraph(n, ParagraphStyle("num" + n, parent=styles["cell_bold"], fontSize=13, textColor=ORANGE, alignment=TA_CENTER)), + paragraph(title, styles["cell_bold"]), + paragraph(text, styles["cell"]), + ]) + story.append(Table(rows, colWidths=[1.0 * cm, 5.3 * cm, 10.9 * cm], style=TableStyle([ + ("GRID", (0, 0), (-1, -1), 0.45, LINE), ("VALIGN", (0, 0), (-1, -1), "MIDDLE"), + ("BACKGROUND", (0, 0), (0, -1), PALE), ("LEFTPADDING", (0, 0), (-1, -1), 9), + ("RIGHTPADDING", (0, 0), (-1, -1), 9), ("TOPPADDING", (0, 0), (-1, -1), 10), + ("BOTTOMPADDING", (0, 0), (-1, -1), 10), + ]))) + story.append(Spacer(1, 15)) + story.append(paragraph("Onde o WhatsApp entra", styles["dtf_h2"])) + story.append(paragraph( + "O WhatsApp deixa de ser o lugar onde a arte é enviada. Ele serve para avisar o cliente: pagamento aprovado, pedido em produção, pedido pronto ou necessidade de correção. Quando houver problema, a mensagem leva o cliente de volta para o site.", styles["body"])) + story.append(paragraph( + "Cuidados na automação: se Mercado Pago, Tiny ou WhatsApp reenviar um aviso por falha, o sistema confere antes de agir. Assim, não cria dois pedidos nem manda a mesma mensagem duas vezes.", styles["note"])) + story.append(PageBreak()) + + # Architecture + story += section_title("Arquitetura de software e infraestrutura", styles, "Produção") + story.append(paragraph( + "Todo o sistema roda na nuvem: recebe, processa, integra e disponibiliza o arquivo final. A fábrica acessa o Kanban pelo navegador e baixa o arquivo quando for produzir; não há componente instalado na rede interna.", styles["body"])) + story.append(ArchitectureDiagram()) + story.append(Spacer(1, 12)) + columns = [ + [paragraph("NUVEM", styles["cell_bold"]), paragraph("Site DTF, Kanban online, API FastAPI, worker, ClamAV, PostgreSQL e Cloudflare R2.", styles["cell"])], + [paragraph("FÁBRICA", styles["cell_bold"]), paragraph("Navegador, operador e FlexiPRINT atual. O arquivo é baixado e importado manualmente.", styles["cell"])], + [paragraph("TERCEIROS", styles["cell_bold"]), paragraph("Mercado Pago, Tiny/Olist e WhatsApp Business API.", styles["cell"])], + ] + story.append(Table(columns, colWidths=[3.0 * cm, 14.2 * cm], style=TableStyle([ + ("GRID", (0, 0), (-1, -1), 0.45, LINE), ("VALIGN", (0, 0), (-1, -1), "TOP"), + ("BACKGROUND", (0, 0), (0, -1), SKY), ("LEFTPADDING", (0, 0), (-1, -1), 8), + ("RIGHTPADDING", (0, 0), (-1, -1), 8), ("TOPPADDING", (0, 0), (-1, -1), 8), + ("BOTTOMPADDING", (0, 0), (-1, -1), 8), + ]))) + story.append(Spacer(1, 10)) + for item in [ + "Upload grande: o navegador manda o arquivo direto para o R2, em partes. O VPS não precisa receber 5 GB de uma vez.", + "Fila: o banco guarda o que precisa ser analisado, enviado ao Tiny, avisado no WhatsApp ou apagado no prazo certo.", + "Segurança: o arquivo entra em quarentena, passa pelo antivírus e só depois é analisado e liberado no Kanban.", + "Se a fábrica ficar sem internet: o site continua no ar. A equipe apenas não consegue baixar arquivo novo ou atualizar o Kanban até a conexão voltar.", + ]: + story.append(bullet(item, styles)) + story.append(PageBreak()) + + # Storage/costs + story += section_title("R2: custos e retenção", styles, "Cloudflare") + story.append(paragraph( + "O R2 é onde os arquivos ficam guardados. Ele é privado: o operador só baixa pelo Kanban, com link temporário. O custo vem principalmente da média de GB guardados no mês; leitura e gravação costumam pesar bem menos. O download não tem cobrança de saída de dados.", styles["body"])) + cost = [ + [paragraph("MÉDIA ARMAZENADA", styles["cell_white"]), paragraph("R2 / MÊS", styles["cell_white"]), paragraph("APROX. EM R$*", styles["cell_white"])], + [paragraph("100 GB", styles["cell"]), paragraph("US$ 1,35", styles["cell"]), paragraph("R$ 7", styles["cell"])], + [paragraph("500 GB", styles["cell"]), paragraph("US$ 7,35", styles["cell"]), paragraph("R$ 38", styles["cell"])], + [paragraph("1 TB", styles["cell"]), paragraph("US$ 14,85", styles["cell"]), paragraph("R$ 76", styles["cell"])], + [paragraph("3 TB", styles["cell"]), paragraph("US$ 44,85", styles["cell"]), paragraph("R$ 230", styles["cell"])], + ] + story.append(Table(cost, colWidths=[6.0 * cm, 5.2 * cm, 6.0 * cm], style=TableStyle([ + ("BACKGROUND", (0, 0), (-1, 0), NAVY), ("TEXTCOLOR", (0, 0), (-1, 0), WHITE), + ("GRID", (0, 0), (-1, -1), 0.45, LINE), ("ALIGN", (1, 0), (-1, -1), "RIGHT"), + ("VALIGN", (0, 0), (-1, -1), "MIDDLE"), ("LEFTPADDING", (0, 0), (-1, -1), 9), + ("RIGHTPADDING", (0, 0), (-1, -1), 9), ("TOPPADDING", (0, 0), (-1, -1), 8), + ("BOTTOMPADDING", (0, 0), (-1, -1), 8), + ]))) + story.append(Spacer(1, 5)) + story.append(paragraph("* Referência de US$ 1 = R$ 5,13; câmbio, impostos e tarifas do meio de pagamento podem variar.", styles["small"])) + story.append(Spacer(1, 10)) + retention = [ + [paragraph("ARTEFATO", styles["cell_bold"]), paragraph("PRAZO", styles["cell_bold"]), paragraph("REGRA", styles["cell_bold"])], + [paragraph("Upload multipart incompleto", styles["cell"]), paragraph("1 dia", styles["cell"]), paragraph("Abortado automaticamente.", styles["cell"])], + [paragraph("Recusado ou infectado", styles["cell"]), paragraph("3 dias", styles["cell"]), paragraph("Suporte pode conferir; depois apaga.", styles["cell"])], + [paragraph("Original do cliente", styles["cell"]), paragraph("até 7 dias", styles["cell"]), paragraph("Após aprovação, não fica guardado sem necessidade.", styles["cell"])], + [paragraph("Arte pronta para impressão", styles["cell"]), paragraph("máx. 30 dias", styles["cell"]), paragraph("Prazo conta do primeiro upload; permite correção ou reimpressão recente.", styles["cell"])], + [paragraph("Histórico e métricas", styles["cell"]), paragraph("banco", styles["cell"]), paragraph("Sem manter a imagem.", styles["cell"])], + ] + story.append(Table(retention, colWidths=[5.2 * cm, 2.8 * cm, 9.2 * cm], style=TableStyle([ + ("BACKGROUND", (0, 0), (-1, 0), SKY), ("GRID", (0, 0), (-1, -1), 0.45, LINE), + ("VALIGN", (0, 0), (-1, -1), "TOP"), ("LEFTPADDING", (0, 0), (-1, -1), 8), + ("RIGHTPADDING", (0, 0), (-1, -1), 8), ("TOPPADDING", (0, 0), (-1, -1), 7), + ("BOTTOMPADDING", (0, 0), (-1, -1), 7), + ]))) + story.append(Spacer(1, 9)) + story.append(paragraph("Decisão: não haverá biblioteca infinita de artes. Após o prazo, o cliente reenvia o arquivo; o pedido e sua rastreabilidade permanecem registrados.", styles["note"])) + story.append(PageBreak()) + + # Production / CI CD + story += section_title("Como fica em produção", styles, "Operação, publicação e continuidade") + story.append(paragraph( + "A primeira entrega será operada como uma única aplicação na VPS. Portal, Kanban, processamento e banco seguem o mesmo ciclo de publicação, com acesso da fábrica exclusivamente pelo navegador. Isso reduz pontos de manutenção e mantém a operação independente da rede interna.", styles["body"])) + stacks = [ + [paragraph("AMBIENTE", styles["cell_white"]), paragraph("COMPONENTES", styles["cell_white"]), paragraph("OPERAÇÃO", styles["cell_white"])], + [paragraph("Sistema DTF", styles["cell_bold"]), paragraph("site DTF, Kanban online, API, processamento, antivírus, banco de dados e cópia diária de segurança", styles["cell"]), paragraph("VPS com armazenamento persistente; operação e acompanhamento centralizados", styles["cell"])], + ] + story.append(Table(stacks, colWidths=[3.7 * cm, 9.1 * cm, 4.4 * cm], style=TableStyle([ + ("BACKGROUND", (0, 0), (-1, 0), NAVY), ("TEXTCOLOR", (0, 0), (-1, 0), WHITE), + ("GRID", (0, 0), (-1, -1), 0.45, LINE), ("VALIGN", (0, 0), (-1, -1), "TOP"), + ("LEFTPADDING", (0, 0), (-1, -1), 8), ("RIGHTPADDING", (0, 0), (-1, -1), 8), + ("TOPPADDING", (0, 0), (-1, -1), 8), ("BOTTOMPADDING", (0, 0), (-1, -1), 8), + ]))) + story.append(Spacer(1, 13)) + story.append(paragraph("Publicação com controle", styles["dtf_h2"])) + for item in [ + "Toda alteração passa por testes automáticos antes de poder chegar ao ambiente de produção.", + "Cada publicação fica identificada pela versão do código, permitindo restaurar rapidamente a versão anterior se houver qualquer problema.", + "As mudanças são conferidas primeiro em ambiente de validação e só então liberadas para a operação.", + "Ao final da publicação, uma verificação confirma que os serviços essenciais voltaram a responder antes de encerrar o processo.", + "Credenciais de storage, pagamentos, integrações e banco permanecem fora do código e são tratadas como dados restritos do ambiente.", + ]: + story.append(bullet(item, styles)) + story.append(Spacer(1, 9)) + story.append(paragraph("Acompanhamento operacional", styles["dtf_h2"])) + story.append(Spacer(1, 5)) + story.append(paragraph( + "A rotina de operação acompanha disponibilidade do site e do Kanban, andamento da fila de processamento, falhas de integração e resultado das cópias de segurança. Assim, qualquer desvio é identificado antes de interromper o atendimento ou a produção.", styles["note"])) + story.append(PageBreak()) + + # Roadmap + story += section_title("Roadmap de implementação", styles, "MVP em até 3 semanas") + story.append(paragraph("O cronograma considera a base de código existente e dedicação integral. A prioridade é concluir o fluxo completo - envio, pagamento, frete, pedido e acompanhamento - antes de qualquer integração com as máquinas. As regras comerciais seguem exatamente o que já está configurado no Site DTF.", styles["body"])) + roadmap = [ + [paragraph("QUANDO", styles["cell_white"]), paragraph("ENTREGA", styles["cell_white"]), paragraph("RESULTADO", styles["cell_white"])], + [paragraph("Sem. 1", styles["cell_bold"]), paragraph("Infraestrutura e upload", styles["cell"]), paragraph("VPS, domínio, banco, R2, upload multipart, antivírus e base do serviço.", styles["cell"])], + [paragraph("Sem. 2", styles["cell_bold"]), paragraph("Pagamento, frete e pedido", styles["cell"]), paragraph("Mercado Pago, cotação de frete, criação idempotente no Tiny, geração do arquivo final e estados principais do Kanban.", styles["cell"])], + [paragraph("Sem. 3", styles["cell_bold"]), paragraph("Kanban e entrega", styles["cell"]), paragraph("Kanban online, download seguro, mensagens de status no WhatsApp, retenção de 30 dias e orientação à operação.", styles["cell"])], + ] + story.append(Table(roadmap, colWidths=[2.1 * cm, 5.0 * cm, 10.1 * cm], style=TableStyle([ + ("BACKGROUND", (0, 0), (-1, 0), NAVY), ("TEXTCOLOR", (0, 0), (-1, 0), WHITE), + ("GRID", (0, 0), (-1, -1), 0.45, LINE), ("VALIGN", (0, 0), (-1, -1), "TOP"), + ("BACKGROUND", (0, 1), (0, -1), PALE), ("LEFTPADDING", (0, 0), (-1, -1), 8), + ("RIGHTPADDING", (0, 0), (-1, -1), 8), ("TOPPADDING", (0, 0), (-1, -1), 8), + ("BOTTOMPADDING", (0, 0), (-1, -1), 8), + ]))) + story.append(Spacer(1, 14)) + story.append(paragraph("Fora da primeira entrega", styles["dtf_h2"])) + story.append(Spacer(1, 5)) + story.append(paragraph("A primeira entrega termina no download do arquivo final pelo Kanban e na orientação de uso à operação. Integração direta com FlexiPRINT, agente dentro da fábrica, pasta monitorada, painel de sala e relatórios avançados não fazem parte deste prazo. O pré-flight automático será validado depois da entrega, com arquivos e impressão reais. A fábrica mantém esses recursos no ambiente atual; após a entrega, damos suporte e avaliamos mudanças conforme a necessidade.", styles["note"])) + story.append(Spacer(1, 10)) + story.append(paragraph("O que fica com a operação", styles["dtf_h2"])) + for item in [ + "Acessar o Kanban, baixar o arquivo final e importá-lo manualmente no FlexiPRINT atual.", + "Realizar os testes de impressão e informar qualquer diferença encontrada no arquivo ou no resultado impresso.", + "Manter computadores, FlexiPRINT, perfis de impressão, impressoras e eventuais pastas internas funcionando.", + "A conexão local é necessária apenas para a equipe acessar o Kanban e baixar o arquivo na fábrica. Se ela cair, portal, pagamentos, uploads e fila continuam ativos na nuvem; a produção retoma quando o acesso local voltar.", + "Comunicar mudanças de preços, frete ou regras operacionais que precisem ser refletidas no sistema.", + ]: + story.append(bullet(item, styles)) + story.append(Spacer(1, 7)) + story.append(paragraph("O que precisamos para começar", styles["dtf_h2"])) + for item in [ + "Credenciais do Mercado Pago, incluindo a configuração do webhook para confirmação de pagamento.", + "Dados da integração de frete: plataforma(s) já utilizada(s), acesso à API, CEP de origem, serviços oferecidos, regra de cobrança e referência de peso e dimensões por pacote.", + ]: + story.append(bullet(item, styles)) + story.append(Spacer(1, 7)) + story.append(paragraph("Antes de começar", styles["dtf_h2"])) + story.append(Spacer(1, 5)) + story.append(paragraph("Com esses acessos e dados liberados, a primeira semana pode começar. A tabela, os descontos e as regras comerciais já existentes no Site DTF serão mantidos. Tiny/Olist e WhatsApp já estão disponíveis; durante o desenvolvimento será definida a ligação técnica dessas integrações com os eventos do pedido. A fábrica valida a impressão depois, baixando o arquivo final pelo Kanban.", styles["note"])) + + doc.build(story) + + +if __name__ == "__main__": + OUT.parent.mkdir(parents=True, exist_ok=True) + build_pdf() + print(OUT) diff --git a/tmp/pdfs/rendered-arrowfix/page-4.png b/tmp/pdfs/rendered-arrowfix/page-4.png new file mode 100644 index 0000000..c465bcd Binary files /dev/null and b/tmp/pdfs/rendered-arrowfix/page-4.png differ diff --git a/tmp/pdfs/rendered-arrowfix/page-7.png b/tmp/pdfs/rendered-arrowfix/page-7.png new file mode 100644 index 0000000..c5f7729 Binary files /dev/null and b/tmp/pdfs/rendered-arrowfix/page-7.png differ diff --git a/tmp/pdfs/rendered-dbfix/page-4.png b/tmp/pdfs/rendered-dbfix/page-4.png new file mode 100644 index 0000000..182106a Binary files /dev/null and b/tmp/pdfs/rendered-dbfix/page-4.png differ diff --git a/tmp/pdfs/rendered-final/page-4.png b/tmp/pdfs/rendered-final/page-4.png new file mode 100644 index 0000000..5c0ba1e Binary files /dev/null and b/tmp/pdfs/rendered-final/page-4.png differ diff --git a/tmp/pdfs/rendered-human/page-1.png b/tmp/pdfs/rendered-human/page-1.png new file mode 100644 index 0000000..d725da5 Binary files /dev/null and b/tmp/pdfs/rendered-human/page-1.png differ diff --git a/tmp/pdfs/rendered-human/page-2.png b/tmp/pdfs/rendered-human/page-2.png new file mode 100644 index 0000000..5f325fa Binary files /dev/null and b/tmp/pdfs/rendered-human/page-2.png differ diff --git a/tmp/pdfs/rendered-human/page-3.png b/tmp/pdfs/rendered-human/page-3.png new file mode 100644 index 0000000..941eccd Binary files /dev/null and b/tmp/pdfs/rendered-human/page-3.png differ diff --git a/tmp/pdfs/rendered-human/page-4.png b/tmp/pdfs/rendered-human/page-4.png new file mode 100644 index 0000000..5d277a5 Binary files /dev/null and b/tmp/pdfs/rendered-human/page-4.png differ diff --git a/tmp/pdfs/rendered-human/page-5.png b/tmp/pdfs/rendered-human/page-5.png new file mode 100644 index 0000000..4faa513 Binary files /dev/null and b/tmp/pdfs/rendered-human/page-5.png differ diff --git a/tmp/pdfs/rendered-human/page-6.png b/tmp/pdfs/rendered-human/page-6.png new file mode 100644 index 0000000..a96df19 Binary files /dev/null and b/tmp/pdfs/rendered-human/page-6.png differ diff --git a/tmp/pdfs/rendered-human/page-7.png b/tmp/pdfs/rendered-human/page-7.png new file mode 100644 index 0000000..fccf967 Binary files /dev/null and b/tmp/pdfs/rendered-human/page-7.png differ diff --git a/tmp/pdfs/rendered-human2/page-1.png b/tmp/pdfs/rendered-human2/page-1.png new file mode 100644 index 0000000..dbc5f04 Binary files /dev/null and b/tmp/pdfs/rendered-human2/page-1.png differ diff --git a/tmp/pdfs/rendered-human2/page-2.png b/tmp/pdfs/rendered-human2/page-2.png new file mode 100644 index 0000000..fc6140c Binary files /dev/null and b/tmp/pdfs/rendered-human2/page-2.png differ diff --git a/tmp/pdfs/rendered-human2/page-3.png b/tmp/pdfs/rendered-human2/page-3.png new file mode 100644 index 0000000..c2f6790 Binary files /dev/null and b/tmp/pdfs/rendered-human2/page-3.png differ diff --git a/tmp/pdfs/rendered-human2/page-4.png b/tmp/pdfs/rendered-human2/page-4.png new file mode 100644 index 0000000..cec7d1f Binary files /dev/null and b/tmp/pdfs/rendered-human2/page-4.png differ diff --git a/tmp/pdfs/rendered-human2/page-5.png b/tmp/pdfs/rendered-human2/page-5.png new file mode 100644 index 0000000..74858f6 Binary files /dev/null and b/tmp/pdfs/rendered-human2/page-5.png differ diff --git a/tmp/pdfs/rendered-human2/page-6.png b/tmp/pdfs/rendered-human2/page-6.png new file mode 100644 index 0000000..d9f9153 Binary files /dev/null and b/tmp/pdfs/rendered-human2/page-6.png differ diff --git a/tmp/pdfs/rendered-human2/page-7.png b/tmp/pdfs/rendered-human2/page-7.png new file mode 100644 index 0000000..2bfdb1e Binary files /dev/null and b/tmp/pdfs/rendered-human2/page-7.png differ diff --git a/tmp/pdfs/rendered-level1/page-1.png b/tmp/pdfs/rendered-level1/page-1.png new file mode 100644 index 0000000..e6d6a2a Binary files /dev/null and b/tmp/pdfs/rendered-level1/page-1.png differ diff --git a/tmp/pdfs/rendered-level1/page-2.png b/tmp/pdfs/rendered-level1/page-2.png new file mode 100644 index 0000000..5240156 Binary files /dev/null and b/tmp/pdfs/rendered-level1/page-2.png differ diff --git a/tmp/pdfs/rendered-level1/page-3.png b/tmp/pdfs/rendered-level1/page-3.png new file mode 100644 index 0000000..ba60d94 Binary files /dev/null and b/tmp/pdfs/rendered-level1/page-3.png differ diff --git a/tmp/pdfs/rendered-level1/page-4.png b/tmp/pdfs/rendered-level1/page-4.png new file mode 100644 index 0000000..2025f46 Binary files /dev/null and b/tmp/pdfs/rendered-level1/page-4.png differ diff --git a/tmp/pdfs/rendered-level1/page-5.png b/tmp/pdfs/rendered-level1/page-5.png new file mode 100644 index 0000000..e3ee35b Binary files /dev/null and b/tmp/pdfs/rendered-level1/page-5.png differ diff --git a/tmp/pdfs/rendered-level1/page-6.png b/tmp/pdfs/rendered-level1/page-6.png new file mode 100644 index 0000000..16d8b30 Binary files /dev/null and b/tmp/pdfs/rendered-level1/page-6.png differ diff --git a/tmp/pdfs/rendered-level1/page-7.png b/tmp/pdfs/rendered-level1/page-7.png new file mode 100644 index 0000000..66b3dbf Binary files /dev/null and b/tmp/pdfs/rendered-level1/page-7.png differ diff --git a/tmp/pdfs/rendered-professional-final/page-5.png b/tmp/pdfs/rendered-professional-final/page-5.png new file mode 100644 index 0000000..5d16185 Binary files /dev/null and b/tmp/pdfs/rendered-professional-final/page-5.png differ diff --git a/tmp/pdfs/rendered-professional-final/page-6.png b/tmp/pdfs/rendered-professional-final/page-6.png new file mode 100644 index 0000000..6f9f316 Binary files /dev/null and b/tmp/pdfs/rendered-professional-final/page-6.png differ diff --git a/tmp/pdfs/rendered-professional-final/page-7.png b/tmp/pdfs/rendered-professional-final/page-7.png new file mode 100644 index 0000000..341c1d5 Binary files /dev/null and b/tmp/pdfs/rendered-professional-final/page-7.png differ diff --git a/tmp/pdfs/rendered-professional/page-1.png b/tmp/pdfs/rendered-professional/page-1.png new file mode 100644 index 0000000..b5eef45 Binary files /dev/null and b/tmp/pdfs/rendered-professional/page-1.png differ diff --git a/tmp/pdfs/rendered-professional/page-2.png b/tmp/pdfs/rendered-professional/page-2.png new file mode 100644 index 0000000..a53c7a0 Binary files /dev/null and b/tmp/pdfs/rendered-professional/page-2.png differ diff --git a/tmp/pdfs/rendered-professional/page-3.png b/tmp/pdfs/rendered-professional/page-3.png new file mode 100644 index 0000000..0c3e217 Binary files /dev/null and b/tmp/pdfs/rendered-professional/page-3.png differ diff --git a/tmp/pdfs/rendered-professional/page-4.png b/tmp/pdfs/rendered-professional/page-4.png new file mode 100644 index 0000000..6c9b34a Binary files /dev/null and b/tmp/pdfs/rendered-professional/page-4.png differ diff --git a/tmp/pdfs/rendered-professional/page-5.png b/tmp/pdfs/rendered-professional/page-5.png new file mode 100644 index 0000000..97a979d Binary files /dev/null and b/tmp/pdfs/rendered-professional/page-5.png differ diff --git a/tmp/pdfs/rendered-professional/page-6.png b/tmp/pdfs/rendered-professional/page-6.png new file mode 100644 index 0000000..6f9f316 Binary files /dev/null and b/tmp/pdfs/rendered-professional/page-6.png differ diff --git a/tmp/pdfs/rendered-professional/page-7.png b/tmp/pdfs/rendered-professional/page-7.png new file mode 100644 index 0000000..0223733 Binary files /dev/null and b/tmp/pdfs/rendered-professional/page-7.png differ diff --git a/tmp/pdfs/rendered-targeted/page-4.png b/tmp/pdfs/rendered-targeted/page-4.png new file mode 100644 index 0000000..88082be Binary files /dev/null and b/tmp/pdfs/rendered-targeted/page-4.png differ diff --git a/tmp/pdfs/rendered-targeted/page-7.png b/tmp/pdfs/rendered-targeted/page-7.png new file mode 100644 index 0000000..ef448d5 Binary files /dev/null and b/tmp/pdfs/rendered-targeted/page-7.png differ diff --git a/tmp/pdfs/rendered/freight-prereqs-7.png b/tmp/pdfs/rendered/freight-prereqs-7.png new file mode 100644 index 0000000..42e56c6 Binary files /dev/null and b/tmp/pdfs/rendered/freight-prereqs-7.png differ diff --git a/tmp/pdfs/rendered/journey-after-preflight-3.png b/tmp/pdfs/rendered/journey-after-preflight-3.png new file mode 100644 index 0000000..72e4f46 Binary files /dev/null and b/tmp/pdfs/rendered/journey-after-preflight-3.png differ diff --git a/tmp/pdfs/rendered/local-internet-clarified-7.png b/tmp/pdfs/rendered/local-internet-clarified-7.png new file mode 100644 index 0000000..2d2a946 Binary files /dev/null and b/tmp/pdfs/rendered/local-internet-clarified-7.png differ diff --git a/tmp/pdfs/rendered/operation-responsibilities-7.png b/tmp/pdfs/rendered/operation-responsibilities-7.png new file mode 100644 index 0000000..6163b4a Binary files /dev/null and b/tmp/pdfs/rendered/operation-responsibilities-7.png differ diff --git a/tmp/pdfs/rendered/page-1.png b/tmp/pdfs/rendered/page-1.png new file mode 100644 index 0000000..02c3118 Binary files /dev/null and b/tmp/pdfs/rendered/page-1.png differ diff --git a/tmp/pdfs/rendered/page-2.png b/tmp/pdfs/rendered/page-2.png new file mode 100644 index 0000000..37dc431 Binary files /dev/null and b/tmp/pdfs/rendered/page-2.png differ diff --git a/tmp/pdfs/rendered/page-3.png b/tmp/pdfs/rendered/page-3.png new file mode 100644 index 0000000..bde1b77 Binary files /dev/null and b/tmp/pdfs/rendered/page-3.png differ diff --git a/tmp/pdfs/rendered/page-4.png b/tmp/pdfs/rendered/page-4.png new file mode 100644 index 0000000..d98b0b2 Binary files /dev/null and b/tmp/pdfs/rendered/page-4.png differ diff --git a/tmp/pdfs/rendered/page-5.png b/tmp/pdfs/rendered/page-5.png new file mode 100644 index 0000000..baf5f7c Binary files /dev/null and b/tmp/pdfs/rendered/page-5.png differ diff --git a/tmp/pdfs/rendered/page-6.png b/tmp/pdfs/rendered/page-6.png new file mode 100644 index 0000000..9a01b44 Binary files /dev/null and b/tmp/pdfs/rendered/page-6.png differ diff --git a/tmp/pdfs/rendered/page-7.png b/tmp/pdfs/rendered/page-7.png new file mode 100644 index 0000000..eac15a8 Binary files /dev/null and b/tmp/pdfs/rendered/page-7.png differ diff --git a/tmp/pdfs/rendered/problem-title-2.png b/tmp/pdfs/rendered/problem-title-2.png new file mode 100644 index 0000000..a8c3af1 Binary files /dev/null and b/tmp/pdfs/rendered/problem-title-2.png differ diff --git a/tmp/pdfs/rendered/production-6.png b/tmp/pdfs/rendered/production-6.png new file mode 100644 index 0000000..8a5f65d Binary files /dev/null and b/tmp/pdfs/rendered/production-6.png differ diff --git a/tmp/pdfs/rendered/production-final-6.png b/tmp/pdfs/rendered/production-final-6.png new file mode 100644 index 0000000..2421426 Binary files /dev/null and b/tmp/pdfs/rendered/production-final-6.png differ diff --git a/tmp/pdfs/rendered/production-spacing-6.png b/tmp/pdfs/rendered/production-spacing-6.png new file mode 100644 index 0000000..03ddf16 Binary files /dev/null and b/tmp/pdfs/rendered/production-spacing-6.png differ diff --git a/tmp/pdfs/rendered/start-dependencies-7.png b/tmp/pdfs/rendered/start-dependencies-7.png new file mode 100644 index 0000000..b15416c Binary files /dev/null and b/tmp/pdfs/rendered/start-dependencies-7.png differ diff --git a/tmp/pdfs/rendered/three-week-final-7.png b/tmp/pdfs/rendered/three-week-final-7.png new file mode 100644 index 0000000..52ef04d Binary files /dev/null and b/tmp/pdfs/rendered/three-week-final-7.png differ diff --git a/tmp/pdfs/rendered/whatsapp-available-7.png b/tmp/pdfs/rendered/whatsapp-available-7.png new file mode 100644 index 0000000..1a7a4c1 Binary files /dev/null and b/tmp/pdfs/rendered/whatsapp-available-7.png differ diff --git a/tmp/pdfs/reuniao.txt b/tmp/pdfs/reuniao.txt new file mode 100644 index 0000000..401fea0 --- /dev/null +++ b/tmp/pdfs/reuniao.txt @@ -0,0 +1,141 @@ +set. 9, 2026 + + + +Reunião em 9 de set. de 2026 +às 09:39 GMT-03:00 +Registros da reunião Gravação + + + + +Resumo +Reunião de planejamento com foco na automação de processos via portal +dedicado e melhoria produtiva.​ +​ +Automacao do DTF e Checkout​ +Portal automatizado reconhece arquivos e valida parâmetros. Checkout via +Mercado Pago aprova pedidos automaticamente.​ +​ +Gestao de Pedidos e Precos​ +Sistema Kanban organiza fluxo de trabalho e rastreabilidade. Clientes com arquivos +prontos recebem 20 porcento de desconto.​ +​ +Priorizacao e Viabilidade Tecnica​ +Projeto DTF ganha prioridade sobre o PCP para ganhos rápidos. Servidor externo e +FTP suportam uploads pesados. + + + + +Decisões +Precisa de mais conversa + ●​ Definição de solução para arquivos pesados Ficou pendente de estudo + técnico a viabilidade de envio de arquivos grandes para evitar problemas no + navegador. + Alinhada + ●​ Estruturação de portal e subdomínio DTF Ficou alinhada a criação de um + novo subdomínio dedicado ao DTF com checkout transparente e fila de + impressão. + + ●​ Priorização do projeto DTF sobre PCP Ficou acordado pausar o PCP e + definir o desenvolvimento do módulo DTF como prioridade máxima. + + + + +Próximas etapas + ​ [Marcus Fernandes] Enviar referencias: Enviar para Jorge e Cauê os links de + referência do site para o novo módulo DTF. + ​ [Jorge Faleiros, Cauê Faleiros] Criar roadmap: Estruturar o plano de + desenvolvimento do sistema após analisar os requisitos e gargalos técnicos. + ​ [Jorge Faleiros, Cauê Faleiros] Estudar infraestrutura: Avaliar custos de + hospedagem e soluções técnicas para viabilizar o upload de arquivos + grandes no servidor externo. + + + + +Detalhes + ●​ Problema de Processo no DTF e Solução Proposta: Marcus Fernandes + identifica um gargalo na produção de DTF (Direct to Film), onde designers + perdem tempo corrigindo arquivos mal formatados ou despadronizados + enviados pelos clientes. A solução proposta consiste em criar um portal + automatizado que reconhece os arquivos, verifica parâmetros de qualidade + e metragem, e cria filas de impressão automaticamente, evitando a + dependência constante do atendimento manual e permitindo a + escalabilidade do negócio. + + ●​ Arquitetura do Sistema e Servidor Externo: Para garantir a continuidade + da operação mesmo em casos de falhas de energia ou conexão local, a + equipe planeja utilizar um servidor externo para o recebimento inicial dos + arquivos. O sistema deve conectar-se tanto a servidores internos quanto + externos, com um painel de identificação para monitorar a movimentação + dos arquivos, integrando-se aos processos já existentes. + ●​ Automação do Pagamento e Checkout: O processo atual de aprovação + manual de pagamentos impede que a sala de impressão opere 24 horas por + dia. Marcus Fernandes propõe a criação de um novo domínio exclusivo para + o módulo DTF, utilizando um sistema de checkout transparente via Mercado + Pago, o que permitirá a aprovação automática dos pedidos e a liberação + imediata para a fila de produção. + +●​ Gestão de Pedidos e Integração com Kanban: O fluxo de trabalho será + gerido por meio de um sistema Kanban para evitar a perda de arquivos e + garantir uma ordem de chegada linear, resolvendo o problema de pedidos + esquecidos. Este sistema deve se integrar com o Tine para gerar tags nos + pedidos, utilizar o número do pedido para rastreabilidade na expedição e + calcular correios ou transportadoras para o cliente. + +●​ Interface do Site e Estrutura de Preços: O site contará com uma interface + intuitiva onde os clientes poderão fazer upload de arquivos e receber + feedback imediato sobre a qualidade. Será implementado um modelo de + precificação diferenciado: clientes que enviarem arquivos prontos e dentro + dos parâmetros ideais receberão um desconto de 20%, enquanto aqueles + que exigirem suporte de design pagarão um valor maior, incentivando o + envio de arquivos de qualidade. + +●​ Fluxo de Trabalho do Design: Mesmo com a automação, os designers + continuarão a realizar um trabalho ativo, ajudando clientes que possuem + dificuldades, mas com uma carga de trabalho mais otimizada. Os designers + utilizarão pastas específicas no servidor interno para tratar os arquivos, + garantindo que o fluxo de conversão (por exemplo, para PDF) seja + padronizado antes da impressão. + +●​ Segmentação de Clientes e Proposta de Valor: Marcus Fernandes + enfatiza a necessidade de distinguir entre clientes que enviam artes prontas + e clientes que precisam de auxílio, evitando que a empresa perca margem ou + produtividade ao misturar ambos os perfis. A automação visa permitir que a + equipe foque o trabalho de design onde ele é realmente necessário, + aumentando a capacidade produtiva de 10.000 para 25.000 metros + mensais. + +●​ Viabilidade Técnica e Dashboard de Produção: A equipe discute a + viabilidade técnica de criar um painel (dashboard) para a sala de impressão, + que exibirá dados das máquinas, metragem produzida e retrabalhos, + conectando-se ao software de impressão (Flexprint). Cauê Faleiros e Jorge + Faleiros validam que o projeto é executável, dependendo apenas da + verificação das capacidades da API do sistema Tine. + ●​ Priorização do Projeto DTF sobre o PCP: Marcus Fernandes propõe pausar + parcialmente o projeto de PCP (Planejamento e Controle da Produção) para + priorizar a implementação do módulo DTF, visto que este último possui um + escopo mais definido, um ciclo de entrega claro e promete ganhos + imediatos de produtividade e redução de pessoal. + + ●​ Desafios Técnicos e Próximos Passos: Jorge Faleiros levanta + preocupações sobre o upload de arquivos pesados (que podem chegar a 5 + GB) via navegador, sugerindo a necessidade de estudar soluções + alternativas como FTP. Como próximos passos, Jorge Faleiros e Cauê + Faleiros definirão um roadmap, avaliarão custos de hospedagem e a + infraestrutura necessária para suportar os uploads, enquanto Marcus + Fernandes enviará sites de referência para análise da lógica de + funcionamento. + + + + +Revise as anotações do Gemini para checar se estão corretas. Confira dicas e saiba +como o Gemini faz anotações +Como está a qualidade de destas observações? Responda a uma breve pesquisa +para nos dar seu feedback, incluindo o quanto as observações foram úteis para o +que você precisa. + \ No newline at end of file diff --git a/tmp/pdfs/roadmap-review-1.png b/tmp/pdfs/roadmap-review-1.png new file mode 100644 index 0000000..c0cf5ab Binary files /dev/null and b/tmp/pdfs/roadmap-review-1.png differ diff --git a/tmp/pdfs/roadmap-review-2.png b/tmp/pdfs/roadmap-review-2.png new file mode 100644 index 0000000..374d0b8 Binary files /dev/null and b/tmp/pdfs/roadmap-review-2.png differ diff --git a/tmp/pdfs/roadmap-review-3.png b/tmp/pdfs/roadmap-review-3.png new file mode 100644 index 0000000..cff0c50 Binary files /dev/null and b/tmp/pdfs/roadmap-review-3.png differ diff --git a/tmp/pdfs/roadmap-review-4.png b/tmp/pdfs/roadmap-review-4.png new file mode 100644 index 0000000..5627691 Binary files /dev/null and b/tmp/pdfs/roadmap-review-4.png differ diff --git a/tmp/pdfs/roadmap-review-5.png b/tmp/pdfs/roadmap-review-5.png new file mode 100644 index 0000000..122347b Binary files /dev/null and b/tmp/pdfs/roadmap-review-5.png differ diff --git a/tmp/pdfs/roadmap-review-6.png b/tmp/pdfs/roadmap-review-6.png new file mode 100644 index 0000000..d356e19 Binary files /dev/null and b/tmp/pdfs/roadmap-review-6.png differ diff --git a/tmp/pdfs/roadmap-review-7.png b/tmp/pdfs/roadmap-review-7.png new file mode 100644 index 0000000..53aaf6b Binary files /dev/null and b/tmp/pdfs/roadmap-review-7.png differ