openSUSE-SU-2025:20177-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2025:20177-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2025:20177-1
Upstream
CVE (8)
Related
Published
2025-12-18T00:17:52Z
Modified
2026-03-12T02:06:47Z
Summary
Security update for cheat
Details

This update for cheat fixes the following issues:

  • Security:

  • Packaging improvements:

    • Drop Requires: golang-packaging. The recommended Go toolchain dependency expression is BuildRequires: golang(API) >= 1.x or optionally the metapackage BuildRequires: go
    • Use BuildRequires: golang(API) >= 1.19 matching go.mod
    • Build PIE with pattern that may become recommended procedure: %%ifnarch ppc64 GOFLAGS="-buildmode=pie" %%endif go build A go toolchain buildmode default config would be preferable but none exist at this time.
    • Drop mod=vendor, go1.14+ will detect vendor dir and auto-enable
    • Remove go build -o output binary location and name. Default binary has the same name as package of func main() and is placed in the top level of the build directory.
    • Add basic %check to execute binary --help
  • Packaging improvements:

References

Affected packages

openSUSE:Leap 16.0 / cheat

Package

Name
cheat
Purl
pkg:rpm/opensuse/cheat&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.4.2-bp160.2.1

Ecosystem specific

{
    "binaries":  [
        {
            "cheat":  "4.4.2-bp160.2.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2025:20177-1.json"