Skip to content

Conversation

@ajtribick
Copy link
Contributor

@ajtribick ajtribick commented Dec 6, 2025

  • Changes comply with the maintainer guide.
  • SHA512s are updated for each updated download.
  • The "supports" clause reflects platforms that may be fixed by this new version.
  • Any fixed CI baseline entries are removed from that file.
  • Any patches that are no longer applied are deleted from the port's directory.
  • The version database is fixed by rerunning ./vcpkg x-add-version --all and committing the result.
  • Only one version is added to each modified port's versions file.

Recently libpng-1.6.52 was released with a fix for CVE-2025-66293. Since there is (so far) no apng patch available for this version, backport the CVE fix to 1.6.51.

pnggroup/libpng#764

vicroms
vicroms previously approved these changes Dec 6, 2025
@vicroms vicroms enabled auto-merge (squash) December 6, 2025 09:27
auto-merge was automatically disabled December 6, 2025 14:04

Head branch was pushed to by a user without write access

@ajtribick ajtribick changed the title [libpng] Backport fix for CVE-2025-66293 from 1.6.52 [libpng] Update to 1.6.53 Dec 6, 2025
@ajtribick
Copy link
Contributor Author

Version 1.6.53 is now released, plus the apng patch is now available, so update to that instead.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants