Skip to content

Update caddy to 2.11.4#234

Open
gominimal-pkgmgr-mgr[bot] wants to merge 1 commit into
mainfrom
update-caddy-2.11.4
Open

Update caddy to 2.11.4#234
gominimal-pkgmgr-mgr[bot] wants to merge 1 commit into
mainfrom
update-caddy-2.11.4

Conversation

@gominimal-pkgmgr-mgr

Copy link
Copy Markdown
Contributor

Update caddy 2.11.32.11.4

Source: github:caddyserver/caddy
Release: https://github.com/caddyserver/caddy/releases/tag/v2.11.4
Changelog: caddyserver/caddy@v2.11.3...v2.11.4
Released: 6 days ago (2026-06-03)

Pkgscan: clean — diff against the prior version surfaced no newly-introduced suspicious patterns.

Vulnerability impact

Partition analysis at 2.11.4 (uses each advisory's fixed-version, vulnerable-range, affected-ranges, and fix-commit ancestry to decide):

  • 3 cleared — the new version is outside the advisory's affected range, OR the tag's lineage includes a known fix-commit. These will drop off the next scan.

Vulnerabilities fixed (3)

This update clears 3 vulnerabilities affecting 2.11.3:

CVE / GHSA CPE Severity Fixed in
GHSA-f59h-q822-g45g (caddyserver, caddy) HIGH 2.11.4
GHSA-qrp7-cvwr-j2c6 (caddyserver, caddy) HIGH 2.11.4
GHSA-vcc4-2c75-vc9v (caddyserver, caddy) MEDIUM via range: <= 2.11.3
Advisory summaries
  • GHSA-f59h-q822-g45g — FastCGI header normalization bypass in forward_auth copy_headers (Published 2026-06-08)
  • GHSA-qrp7-cvwr-j2c6 — Windows file_server path authorization bypass via encoded backslash (Published 2026-06-08)
  • GHSA-vcc4-2c75-vc9v — stripHTML template function bypass in github.com/caddyserver/caddy (Published 2026-06-08)

Components changed

CycloneDX component delta (declared materials — the package's own version, not a dependency-tree diff)
Component Old New
~ caddy 2.11.3 2.11.4
~ caddy-upstream 2.11.3 2.11.4

Changes

Old New
Version 2.11.3 2.11.4
SHA256 de751e6b7ca769f0... 2c3d02078286a628...
Size 835 KB 844 KB
Source gs://minimal-staging-archives/caddyserver/caddy/v2.11.3.tar.gz gs://minimal-staging-archives/caddyserver/caddy/v2.11.4.tar.gz
  • License: Apache-2.0 (source: GitHub + tarball)

Quality suggestions

  • Missing tests block. This package has no standalone tests, so the buildbot will only verify compilation — not functional correctness. Consider adding a minimal smoke test (e.g., a --version or small round-trip invocation) as part of this PR so future bumps catch regressions. See packages/python/build.ncl for a simple example.

Created by pkgmgr

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants