{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20711-1","published":"2026-05-09T08:42:06Z","modified":"2026-05-11T08:15:38.612727Z","related":["CVE-2026-34986","CVE-2026-39984"],"upstream":["CVE-2026-34986","CVE-2026-39984"],"summary":"Security update for hauler","details":"This update for hauler fixes the following issues:\n\nChanges in hauler:\n\n- update to 1.4.3 ( bsc#1262353, CVE-2026-39984, bsc#1262942, CVE-2026-34986):\n  * [1.4] Bump go.opentelemetry.io/otel/sdk from 1.40.0 to 1.43.0\n    in the go_modules group across 1 directory\n  * [1.4] Bump github.com/sigstore/timestamp-authority/v2 from\n    2.0.4 to 2.0.6 in the go_modules group across 1 directory\n  * [1.4] Bump google.golang.org/grpc from 1.78.0 to 1.79.3 in\n    the go_modules group across 1 directory\n  * fixed versions and dependencies on release/1.4\n  * [1.4] removed unnecessary rewrite flag from sync\n  * added makefile command for vulnerability checks (backport #577)\n  * remove cherrypick bot and add mergify details (backport #581)\n","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262353"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262942"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39984"}]}