FlawAtlas
Search the atlas
OPENSUSE-SU-2026:20998-1 Not scored

Security update for tree-sitter-ruby

This update for tree-sitter-ruby fixes the following issues - CVE-2025-5889: brace-expansion: inefficient regular expression complexity in function expand of file index.js (bsc#1244345). - CVE-2025-59343: tar-fs: tar-fs symlink validation bypass (bsc#1250517). Changes for tree-sitter-ruby: - Use correct tree-sitter dirname instead of tree_sitter (bsc#1267461). - update to 0.23.1: * ci(publish): add attestations and generate parser * build: update bindings * fix: remove unnecessary empty string usage * chore: regenerate * ci: update workflows * fix(swift): include scanner.c - update to 0.23.0: * fix(go): correct test * fix: handle != operator definition * feat: support element references with blocks * fix: do not require newline after block comment =end * fix: parsing of multiple unicode escapes * fix: correct repo url - update to 0.21.0: * feat: rewrite scanner with array header and regenerate * build: update bindings and manifests * fix: reverse precedence queries * fix: escape braces in regex * docs: update badges - switch to download_files service - add neovim links - add license file to package

Exploit probability Not scored
Published June 22, 2026
Required by Not available
Last source change June 30, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 16.0 tree-sitter-ruby

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2026:20998-1

This update for tree-sitter-ruby fixes the following issues - CVE-2025-5889: brace-expansion: inefficient regular expression complexity in function expand of file index.js (bsc#1244345). - CVE-2025-59343: tar-fs: tar-fs symlink validation bypass (bsc#1250517). Changes for tree-sitter-ruby: - Use correct tree-sitter dirname instead of tree_sitter (bsc#1267461). - update to 0.23.1: * ci(publish): add attestations and generate parser * build: update bindings * fix: remove unnecessary empty string usage * chore: regenerate * ci: update workflows * fix(swift): include scanner.c - update to 0.23.0: * fix(go): correct test * fix: handle != operator definition * feat: support element references with blocks * fix: do not require newline after block comment =end * fix: parsing of multiple unicode escapes * fix: correct repo url - update to 0.21.0: * feat: rewrite scanner with array header and regenerate * build: update bindings and manifests * fix: reverse precedence queries * fix: escape braces in regex * docs: update badges - switch to download_files service - add neovim links - add license file to package

View original source

05 / REFERENCES

Further evidence