{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20998-1","published":"2026-06-22T07:40:16Z","modified":"2026-06-30T18:24:28.059145871Z","related":["CVE-2025-5889","CVE-2025-59343"],"upstream":["CVE-2025-5889","CVE-2025-59343"],"summary":"Security update for tree-sitter-ruby","details":"This update for tree-sitter-ruby fixes the following issues\n\n- CVE-2025-5889: brace-expansion: inefficient regular expression complexity in function expand of file index.js\n  (bsc#1244345).\n- CVE-2025-59343: tar-fs: tar-fs symlink validation bypass (bsc#1250517).\n\nChanges for tree-sitter-ruby:\n\n- Use correct tree-sitter dirname instead of tree_sitter\n (bsc#1267461).\n\n- update to 0.23.1:\n\n * ci(publish): add attestations and generate parser\n * build: update bindings\n * fix: remove unnecessary empty string usage\n * chore: regenerate\n * ci: update workflows\n * fix(swift): include scanner.c\n\n- update to 0.23.0:\n\n * fix(go): correct test\n * fix: handle != operator definition\n * feat: support element references with blocks\n * fix: do not require newline after block comment =end\n * fix: parsing of multiple unicode escapes\n * fix: correct repo url\n\n- update to 0.21.0:\n\n * feat: rewrite scanner with array header and regenerate\n * build: update bindings and manifests\n * fix: reverse precedence queries\n * fix: escape braces in regex\n * docs: update badges\n\n- switch to download_files service\n- add neovim links\n- add license file to package\n","affected":[{"package":{"name":"tree-sitter-ruby","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/tree-sitter-ruby&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.23.1-160000.3.1"}]}],"ecosystem_specific":{"binaries":[{"tree-sitter-ruby":"0.23.1-160000.3.1","tree-sitter-ruby-devel":"0.23.1-160000.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20998-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1244345"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250517"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267461"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-5889"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-59343"}]}