github mattrobinsonsre/terrapod v1.8.1

latest release: v1.7.6
3 hours ago

Security patch for the v1.8 line, clearing the findings the scheduled re-scan raised against v1.8.0.

Security

  • OpenSSL updated in the published images. openssl, libssl3t64 and openssl-provider-legacy move from 3.5.7-1deb13u2 to 3.5.7-1deb13u3. Nothing in Terrapod changed — the fix arrives by rebuilding against the refreshed Debian base. The re-scan named the two HIGH advisories, CVE-2026-75804 and CVE-2026-84782, but u3 clears 13 in total: also CVE-2026-35189, CVE-2026-35191, CVE-2026-42772, CVE-2026-54872, CVE-2026-54873, CVE-2026-54875, CVE-2026-72897, CVE-2026-75805, CVE-2026-75806, CVE-2026-77696 and CVE-2026-84784.

  • brace-expansion raised to 2.1.7, clearing three DoS advisories against 2.0.0–2.1.6: GHSA-6j4f-fj2g-mc7p, GHSA-q2hr-2g5m-vwhr and GHSA-qhr7-859c-m2p7. Stated plainly: this is a build-time dependency. It is dev in the lockfile and is not present in the published terrapod-web image, so no released image ever carried it — the exposure was to the build, not to a running deployment.

An accepted risk was re-examined and kept: CVE-2025-69720 (ncurses infocmp) is still unfixed in Debian trixie, and the package is still present in the images, so there is nothing to bump to. Terrapod never invokes infocmp and no attacker-controlled terminfo reaches it.

Upgrading

Drop-in. No configuration, schema, API or wire changes; no migrations.

Status

Stable.

Full Changelog: v1.8.0...v1.8.1

Don't miss a new terrapod release

NewReleases is sending notifications on new releases.