Skip to content

Release v6.0.2#956

Merged
kenhys merged 12 commits intofluent-package-v6from
release-v6.0.2
Feb 27, 2026
Merged

Release v6.0.2#956
kenhys merged 12 commits intofluent-package-v6from
release-v6.0.2

Conversation

@kenhys
Copy link
Copy Markdown
Contributor

@kenhys kenhys commented Feb 13, 2026

No description provided.

@kenhys kenhys force-pushed the release-v6.0.2 branch 8 times, most recently from a5d109f to 5763070 Compare February 16, 2026 02:21
Comment thread fluent-package/Gemfile Outdated
@kenhys kenhys added this to the v6.0.2 milestone Feb 16, 2026
@kenhys kenhys force-pushed the release-v6.0.2 branch 2 times, most recently from 632467e to 5eec77d Compare February 16, 2026 03:29
@kenhys
Copy link
Copy Markdown
Contributor Author

kenhys commented Feb 16, 2026

#963
must be merged in advance.

@kenhys kenhys force-pushed the release-v6.0.2 branch 8 times, most recently from aa021e0 to b38b848 Compare February 17, 2026 08:12
@kenhys kenhys force-pushed the release-v6.0.2 branch 3 times, most recently from 1848d18 to 113a7fb Compare February 25, 2026 01:52
@kenhys
Copy link
Copy Markdown
Contributor Author

kenhys commented Feb 25, 2026

Fixed (#977 introduce new testcase, but it does not update container snapshot.)

@kenhys kenhys marked this pull request as ready for review February 25, 2026 01:54
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
There is a case that releasever is bound to old one in
incus container images. It causes mismatch of runtime API
in some libraries (e.g. OpenSSL 3.0 vs OpenSSL 3.2 for AL2023)

Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
It will fix CVE-2025-14762

  Name: aws-sdk-s3
  Version: 1.197.0
  CVE: CVE-2025-14762
  GHSA: GHSA-2xgq-q749-89fq
  Criticality: Medium
  URL: GHSA-2xgq-q749-89fq
  Title: AWS SDK for Ruby's S3 Encryption Client has a Key Commitment Issue
  Solution: update to '>= 1.208.0'

Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
  CVE: CVE-2026-25765
  GHSA: GHSA-33mh-2634-fwr2
  Criticality: Medium
  URL: GHSA-33mh-2634-fwr2
  Title: Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
  Solution: update to '~> 1.10.5', '>= 2.14.1'

Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
GitHub#977 introduce test case for update error if working directory
is missing, but it lack to update latest releasever.

  There is a case that releasever is bound to old one in
  incus container images. It causes mismatch of runtime API
  in some libraries (e.g. OpenSSL 3.0 vs OpenSSL 3.2 for AL2023)

Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
Copy link
Copy Markdown
Contributor

@Watson1978 Watson1978 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍🏻

@kenhys kenhys merged commit f6e6613 into fluent-package-v6 Feb 27, 2026
332 of 333 checks passed
@kenhys kenhys deleted the release-v6.0.2 branch February 27, 2026 01:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants