Skip to content

Upgrade package gh to version 2.97.0 - #18483

Draft
Aditya Singh (v-aaditya) wants to merge 2 commits into
microsoft:fasttrack/3.0from
Kanishk-Bansal:topic-upgrade/gh/3.0/v2.97.0
Draft

Upgrade package gh to version 2.97.0#18483
Aditya Singh (v-aaditya) wants to merge 2 commits into
microsoft:fasttrack/3.0from
Kanishk-Bansal:topic-upgrade/gh/3.0/v2.97.0

Conversation

@v-aaditya

@v-aaditya Aditya Singh (v-aaditya) commented Aug 18, 2026

Copy link
Copy Markdown
Merge Checklist

All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)

  • The toolchain has been rebuilt successfully (or no changes were made to it)
  • The toolchain/worker package manifests are up-to-date
  • Any updated packages successfully build (or no packages were changed)
  • Packages depending on static components modified in this PR (Golang, *-static subpackages, etc.) have had their Release tag incremented.
  • Package tests (%check section) have been verified with RUN_CHECK=y for existing SPEC files, or added to new SPEC files
  • All package sources are available
  • cgmanifest files are up-to-date and sorted (./cgmanifest.json, ./toolkit/scripts/toolchain/cgmanifest.json, .github/workflows/cgmanifest.json)
  • LICENSE-MAP files are up-to-date (./LICENSES-AND-NOTICES/SPECS/data/licenses.json, ./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md, ./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)
  • All source files have up-to-date hashes in the *.signatures.json files
  • sudo make go-tidy-all and sudo make go-test-coverage pass
  • Documentation has been updated to match any changes to the build system
  • Ready to merge

Summary
Change Log
Does this affect the toolchain?

NO

Test Methodology

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@microsoft-github-policy-service microsoft-github-policy-service Bot added Packaging fasttrack/3.0 PRs Destined for Azure Linux 3.0 labels Aug 18, 2026
@v-aaditya

Copy link
Copy Markdown
Author

Below CVEs are fixed by upgrading gh to v2.97.0 -

S. No. CVE ID Package Name Fixed Version Current Version in this PR Fixed (Y/N) Remarks
1 CVE-2024-54132 github.com/cli/cli/v2 (gh) 2.63.1 2.97.0 Y  
2 CVE-2024-45337 golang.org/x/crypto 0.31.0 0.54.0 Y  
3 CVE-2024-45338 golang.org/x/net/html 0.33.0 0.56.0 Y  
4 CVE-2024-53858 github.com/cli/go-gh/v2 2.11.1 2.13.0 Y  
5 CVE-2024-53859 github.com/cli/go-gh/v2 2.11.1 2.13.0 Y  
6 CVE-2025-25204 github.com/cli/cli/v2 (gh) 2.67.0 2.97.0 Y  
7 CVE-2025-27144 github.com/go-jose/go-jose/v4 4.0.5 Removed N Patching not needed.
8 CVE-2025-22869 golang.org/x/crypto 0.35.0 0.54.0 Y  
9 CVE-2025-22872 golang.org/x/net 0.38.0 0.56.0 Y  
10 CVE-2025-48938 github.com/cli/cli/v2 (gh) 2.12.1 2.97.0 Y  
11 CVE-2025-58183 tar.Reader (go) 1.26.0 1.26.5 Y golang/go@f7a68d3
12 CVE-2026-23991 github.com/theupdateframework/go-tuf/v2 2.3.1 2.4.2 Y  
13 CVE-2026-23992 github.com/theupdateframework/go-tuf/v2 2.3.1 2.4.2 Y  
14 CVE-2025-11065 github.com/go-viper/mapstructure/v2 2.4.0 2.5.0 Y  
15 CVE-2025-47911 golang.org/x/net/html 0.45.0 0.56.0 Y  
16 CVE-2025-58190 golang.org/x/net/html 0.45.0 0.56.0 Y golang/net@6ec8895
17 CVE-2026-24117 github.com/sigstore/rekor 1.5.0 1.5.3 Y  
18 CVE-2026-32288 tar.Reader (go) 1.26.2 1.26.5 Y  
19 CVE-2026-5160 github.com/yuin/goldmark/renderer/html 1.7.17 1.8.4 Y  
20 CVE-2026-39821 golang.org/x/net/idna/ 0.54.0 0.56.0 Y golang/net@8c4c965
21 CVE-2026-39829 golang.org/x/crypto 0.52.0 0.54.0 Y  
22 CVE-2026-39830 golang.org/x/crypto 0.52.0 0.54.0 Y  
23 CVE-2026-39834 golang.org/x/crypto 0.52.0 0.54.0 Y  
24 CVE-2026-42506 golang.org/x/net/html 0.55.0 0.56.0 Y html: properly check namespace in "in body" any other end tag · golang/net@0dc5b7a
25 CVE-2026-46597 golang.org/x/crypto 0.52.0 0.54.0 Y  
26 CVE-2026-27136 golang.org/x/net/html 0.55.0 0.56.0 Y html: ignore duplicate attributes during tokenization · golang/net@a452f3c
27 CVE-2026-25680 golang.org/x/net/html 0.55.0 0.56.0 Y  
28 CVE-2026-25681 golang.org/x/net/html 0.55.0 0.56.0 Y html: escape greater-than symbol in doctype identifiers · golang/net@4ece7b6
29 CVE-2026-39827 golang.org/x/crypto 0.52.0 0.54.0 Y  
30 CVE-2026-39828 golang.org/x/crypto 0.52.0 0.54.0 Y  
31 CVE-2026-39835 golang.org/x/crypto 0.52.0 0.54.0 Y  
32 CVE-2026-42502 golang.org/x/net/html 0.55.0 0.56.0 Y golang/net@a8fb2fe
33 CVE-2026-45803 github.com/cli/cli/v2 (gh) 2.92.0 2.97.0 Y  
34 CVE-2026-56852 golang.org/x/text 0.39.0 0.40.0 Y unicode/norm: avoid infinite loop on invalid input · golang/text@5ae8e57
35 CVE-2026-59831 github.com/cli/cli/v2 (gh) 2.96.0 2.97.0 Y cli/cli@b300f2e
36 CVE-2026-54787 github.com/sigstore/sigstore-go 1.2.1 1.2.2 Y  
37 CVE-2026-64652 github.com/cli/cli/v2 (gh) 2.97.0 2.97.0 Y Merge commit from fork · cli/cli@3f6a16a
38 CVE-2026-64653 github.com/cli/cli/v2 (gh) 2.97.0 2.97.0 Y cli/cli@0c2eea6
39 CVE-2026-64654 github.com/cli/cli/v2 (gh) 2.97.0 2.97.0 Y Merge commit from fork · cli/cli@2a1409f
40 CVE-2026-64655 github.com/cli/cli/v2 (gh) 2.97.0 2.97.0 Y cli/cli@55dbb4d

@v-aaditya

Aditya Singh (v-aaditya) commented Aug 18, 2026

Copy link
Copy Markdown
Author

Latest Buddy Build failed due to circular dependency issue in package unrelated to this PR.

@Kanishk-Bansal

Copy link
Copy Markdown

Patch Analysis (all 35 dropped patches verified safe)

  • 20 × golang.org/x/* — each patch's Upstream-reference: fix commit confirmed an ancestor of the pinned version (x/net v0.56.0, x/crypto v0.54.0, x/text v0.40.0). The 4 with no upstream ref (CVE-2024-45337/45338, CVE-2025-22869/22872) confirmed at code level: maxCachedPubKeys = 1, maxPendingPackets = 64, strings.EqualFold, and the nAttrs guard are all present.
  • 4 × gh's own codeCVE-2024-54132, CVE-2025-25204, CVE-2026-45803, CVE-2026-59831: fix commits are ancestors of v2.97.0; spot-confirmed in source (would result in path traversal, isJupyterServerURLValid).
  • 4 × dependency removed outright — ran go mod vendor on the real v2.97.0 tree: vbatts/tar-split (CVE-2025-58183, CVE-2026-32288), mitchellh/mapstructure (CVE-2025-11065) and go-jose (CVE-2025-27144) are absent from the vendor tree. Worth noting go.sum still carries h1: hashes for two of them, so a go.sum-based check would have wrongly flagged these — the vendor tree is the authority.
  • 6 × other vendored — go-gh v2.13.0 (CVE-2024-53859, CVE-2025-48938isPossibleProtocol present), go-tuf v2.4.2, goldmark v1.8.4, mapstructure fork v2.5.0, rekor v1.5.3 (30s timeout + SSRF note present, search_index.go has no URL support left).
  • 1 × .nopatchCVE-2024-53858 is a 0-byte marker, no fix content to lose.

Comment thread SPECS/gh/gh.spec Outdated
Co-authored-by: Kanishk Bansal <103916909+Kanishk-Bansal@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CVE-fixed-by-upgrade CVE fixed by package upgrade fasttrack/3.0 PRs Destined for Azure Linux 3.0 Packaging security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants