{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20662-1","published":"2026-04-30T16:39:09Z","modified":"2026-05-05T18:23:53.247860Z","related":["CVE-2026-24122"],"upstream":["CVE-2026-24122"],"summary":"Security update for hauler","details":"This update for hauler fixes the following issues:\n\nChanges in hauler:\n\n- update to 1.4.2 (bsc#1258614, CVE-2026-24122):\n  * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to\n    2.3.1 in the go_modules group across 1 directory\n  * fix for new helm chart features\n  * Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 in the\n    go_modules group across 1 directory\n  * Bump github.com/sigstore/sigstore from 1.10.3 to 1.10.4 in\n    the go_modules group across 1 directory\n  * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to\n    2.4.1 in the go_modules group across 1 directory\n  * update cosign fork to 3.0.4 plus dep tidy\n  * fix: Fix file:// dependency chart path resolution\n  * update github.com/olekukonko/tablewriter to v1.1.2\n  * keep registry on image rewrite if not specified\n  * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to\n    2.4.1 in the go_modules group across 1 directory\n  * fix: handling of file referenced dependencies without\n    repository field\n  * Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 in\n    the go_modules group across 1 directory\n  * dev.md file\n  * smaller changes and updates for v1.4.2 release\n","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258614"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24122"}]}