Subject: CVS commit: pkgsrc/devel/opa
From: Leonardo Taccari
Date: 2024-03-24 19:34:00
Message id: 20240324183400.541FEFA2C@cvs.NetBSD.org

Log Message:
opa: Update to 0.62.1

Changes:
v0.62.1
-------
This is a security fix release for the fixes published in Go
1.22.1.

OPA servers using `--authentication=tls` would be affected: crafted
malicious client certificates could cause a panic in the server.

Also, crafted server certificates could panic OPA's HTTP clients, in
bundle plugin, status and decision logs; and `http.send` calls that
verify TLS.

This is CVE-2024-24783.

Note that there are other security fixes in this Golang release, but
whether or not OPA is affected is harder to assess. An update is
advised.

v0.62.0
-------
This release contains a mix of improvements and bugfixes.

Files:
RevisionActionfile
1.43modifypkgsrc/devel/opa/Makefile
1.20modifypkgsrc/devel/opa/distinfo
1.20modifypkgsrc/devel/opa/go-modules.mk