| ID | 43797 |
| Package Name | grafana |
| Version | 10.2.6 |
| Release | 13.oc9 |
| Epoch | |
Draft | False |
| Source | git+https://gitee.com/src-opencloudos-rpms/grafana.git#e4e8b75bf48ea5bb46afe3a763292cb88a2088f7 |
| Summary |
| Description |
| Built by | oc-bot |
| State |
complete
|
| Volume |
DEFAULT |
| Started | Mon, 21 Jul 2025 19:20:16 CST |
| Completed | Mon, 21 Jul 2025 19:31:20 CST |
| Task | build (dist-oc9, /src-opencloudos-rpms/grafana.git:e4e8b75bf48ea5bb46afe3a763292cb88a2088f7) |
| Extra | {'source': {'original_url': 'git+https://gitee.com/src-opencloudos-rpms/grafana.git#e4e8b75bf48ea5bb46afe3a763292cb88a2088f7'}} |
| Tags |
|
| RPMs |
| src | |
|
grafana-10.2.6-13.oc9.src.rpm (info) (download) |
| aarch64 |
|
grafana-10.2.6-13.oc9.aarch64.rpm (info) (download)
|
|
grafana-debuginfo-10.2.6-13.oc9.aarch64.rpm (info) (download)
|
|
grafana-debugsource-10.2.6-13.oc9.aarch64.rpm (info) (download)
|
| loongarch64 |
|
grafana-10.2.6-13.oc9.loongarch64.rpm (info) (download)
|
|
grafana-debuginfo-10.2.6-13.oc9.loongarch64.rpm (info) (download)
|
|
grafana-debugsource-10.2.6-13.oc9.loongarch64.rpm (info) (download)
|
| x86_64 |
|
grafana-10.2.6-13.oc9.x86_64.rpm (info) (download)
|
|
grafana-debuginfo-10.2.6-13.oc9.x86_64.rpm (info) (download)
|
|
grafana-debugsource-10.2.6-13.oc9.x86_64.rpm (info) (download)
|
|
| Logs |
|
| Changelog |
* Fri Jul 18 2025 Chunsheng Luo <luffyluo@tencent.com> - 10.2.6-13
- bump brace expansion to v1.1.12 v2.0.2 (CVE-2025-5889)
- bump axios to 1.8.2 (CVE-2025-27152)
- bump prismjs to 1.30.0 (CVE-2024-53382)
* Thu Jul 17 2025 Chunsheng Luo <luffyluo@tencent.com> - 10.2.6-12
- Check SignedInUser OrgID in RevokeInvite (CVE-2024-10452)
- Dashboards: Prevent title longer than 5 000 characters (CVE-2025-1088)
- check user is admin when deleting from org (CVE-2025-3580)
- declare dingding url as secret (CVE-2025-3415)
* Thu Jul 17 2025 Chunsheng Luo <luffyluo@tencent.com> - 10.2.6-11
- Fix angularjs CVEs: Disable angular_support by default
- CVE-2023-26117, CVE-2022-25869, CVE-2024-8372, CVE-2024-8373, CVE-2025-0716
* Wed May 21 2025 Chunsheng Luo <luffyluo@tencent.com> - 10.2.6-10
- Fix CVE-2025-4123: Enable content_security_policy by default
* Wed May 14 2025 Chunsheng Luo <luffyluo@tencent.com> - 10.2.6-9
- Fix Insecure Temporary File usage in github.com/golang/glog (CVE-2024-45339)
- Fix net/http, x/net/http2: close connections when receiving too many headers (CVE-2023-45288)
- Fix Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)
- Fix HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net (CVE-2025-22870)
* Wed May 07 2025 Chunsheng Luo <luffyluo@tencent.com> - 10.2.6-8
- Fix Grafana Alerting: incorrect permission on POST external rule groups endpoint [CVE-2024-8118]
- Fix Grafana plugin SDK Information Leakage [CVE-2024-8986]
- Fix Grafana Alerting VictorOps integration could be exposed to users with Viewer permission [CVE-2024-11741]
- Fix Grafana Authorization bypass in data source proxy API [CVE-2025-3454]
- Fix golang.org/x/net vulnerable to Cross-site Scripting [CVE-2025-22872]
* Wed Apr 23 2025 Chunsheng Luo <luffyluo@tencent.com> - 10.2.6-7
- Fix CVE-2024-47875: dump dompurify to 2.5.0
- Fix CVE-2025-30204 CVE-2024-51744: bump jwt to v4.5.2
- Fix CVE-2024-6104: go-retryablehttp Redacted URL in logs/errors
* Mon Oct 14 2024 Chunsheng Luo <luffyluo@tencent.com> - 10.2.6-6
- add up.yaml for rpm-upgrade
* Thu Sep 26 2024 OpenCloudOS Release Engineering <releng@opencloudos.tech> - 10.2.6-5
- Rebuilt for clarifying the packages requirement in BaseOS and AppStream
* Thu Sep 19 2024 Chunsheng Luo <luffyluo@tencent.com> - 10.2.6-4
- Fix deployment issues caused by no frontend
* Fri Aug 16 2024 OpenCloudOS Release Engineering <releng@opencloudos.tech> - 10.2.6-3
- Rebuilt for loongarch release
* Tue Jul 16 2024 cunshunxia <cunshunxia@tencent.com> - 10.2.6-2
- drop requirement of go-srpm-macros, which not exist in opencloudos-rpm-config now.
* Thu Jun 27 2024 luffyluo <luffyluo@tencent.com> - 10.2.6-1
- Rebase to version 10.2.6
* Wed Apr 24 2024 luffyluo <luffyluo@tencent.com> - 10.0.2-4
- fix grafana-server.service start fail
* Fri Dec 29 2023 jackeyji <jackeyji@tencent.com> - 10.0.2-3
- Rebuilt for golang CVE-2023-39318 and CVE-2023-39319
* Fri Sep 08 2023 OpenCloudOS Release Engineering <releng@opencloudos.tech> - 10.0.2-2
- Rebuilt for OpenCloudOS Stream 23.09
* Wed Jul 12 2023 Xiaojie Chen <jackxjchen@tencent.com> - 10.0.2-1
- Upgrade to upstream version 10.0.2
* Thu May 04 2023 Wang Guodong <gordonwwang@tencent.com> - 9.0.9-4
- Rebuilt for OpenCloudOS Stream 23.05
* Fri Apr 28 2023 Shuo Wang <abushwang@tencent.com> - 9.0.9-3
- fix testsuite
* Fri Mar 31 2023 OpenCloudOS Release Engineering <releng@opencloudos.tech> - 9.0.9-2
- Rebuilt for OpenCloudOS Stream 23
* Thu Mar 23 2023 Shuo Wang <abushwang@tencent.com> - 9.0.9-1
- initial build
|