Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1vAJY7-00Gyy0-7y for pgsql-www@arkaria.postgresql.org; Sun, 19 Oct 2025 02:53:34 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1vAJX6-009qej-Nf for pgsql-www@arkaria.postgresql.org; Sun, 19 Oct 2025 02:52:31 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1vAJX6-009qeb-7V for pgsql-www@lists.postgresql.org; Sun, 19 Oct 2025 02:52:31 +0000 Received: from mail-pg1-x52b.google.com ([2607:f8b0:4864:20::52b]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.96) (envelope-from ) id 1vAJX2-002Y4y-0a for pgsql-www@postgresql.org; Sun, 19 Oct 2025 02:52:29 +0000 Received: by mail-pg1-x52b.google.com with SMTP id 41be03b00d2f7-b6a7d3040efso476403a12.1 for ; Sat, 18 Oct 2025 19:52:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=leadboat.com; s=google; t=1760842346; x=1761447146; darn=postgresql.org; h=user-agent:content-disposition:mime-version:message-id:subject:to :from:date:from:to:cc:subject:date:message-id:reply-to; bh=tzE6zHqbs4wFM9WCHhyZX5C1FEHOmyfRzgO4/bvAH5M=; b=B02Mqam5mJAXOt1ucZ/MZZOc1fgJwlOMgicB08xr4YKTd8Rc02GRamc/S0m3vjGE6R vBJWlshqn4FA3b7rMbIDY+/Q6h6TPrfQNzqOlqfd87lhZhOh5MYxMWP3UtWZfy87qrBS 8ndkJgFX+kB2WpnTjYdtAoNiFDmAaJmWCgxVI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1760842346; x=1761447146; h=user-agent:content-disposition:mime-version:message-id:subject:to :from:date:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=tzE6zHqbs4wFM9WCHhyZX5C1FEHOmyfRzgO4/bvAH5M=; b=bS4OEIaWLQkWi5FTNzlQY5jIjIjZK5541A+slbUr8A21+HL6B2m7BhYbHPbZ2gm9oH 566iZisyDvlW0iRJ9tHddtBsDRcy32Ynwn47JSiDyiKAhRCZWLQJP0zm0kfRETy+Bjb7 uh7yOao1dQi0217IM3PYiuA1RJBsHiU9/m/sxNs8HDZy/X3KddWU7JT/WjFTkt+mLi+z PA94rvsN7YADJW5W0lUDHWafTqah+ccXImF2kOHnHk4tIuy4VPVcJNABeeT//8uJBAAk b/Uc1zX91fOsdh5VSm8IBY6GVQWTnMQOowtIpcaQuRHNnMuXP9BBTIdoUWeTmBZf8z/I ZH1A== X-Gm-Message-State: AOJu0YzGcb3tQ7GZxeU9xkEYUU+YQF+jYyW92umqx4Vb2RBjuF3U70Bi cqjMsIl0jMM0WvAO1YpjcaCuE+GphF5Gggga6+b7rNTLxlqrn0eIcZnpuNIecs3ElqyItkIdZmt BFOY= X-Gm-Gg: ASbGnctUrzegCgc1sDi/yV513d0ZB2iTUNRNznCJmvugSm0Ms/S8rFFBghCaQd23jgf bNQTp9oHeTBXugNEb0yb0GieuTtlsc2qv7/HicyIr+KGrl8FuBHmrAp9hX/mZH8XS3xCHWLVR/U 3+4MpvhGenUNS+VBqjkgrNatx9/ghZQTQ+TBLBaepRtQR0TDGbzNSEmQ37MrjiL5OnKmnHwoG8+ ugK4T98FIWDPIOfal4Inwds/FawrO5sInBT0KoM9d3uAvJ/zpamRvq6d47dvkDkbRxig87mvVgp IIidxfi6K/3MCxUSYao8zwBZEcmeEdJfzvi9BFll5QutRMBHcHbjcVhurU9vtyeNyVxFpz5oD2c kQkrQ/zW7KkQyLo9r9HxSsCJkrvOhXYpCt9wcGKsrSwfvJ4LSfYvu2XzPkjXYtxqayXoX36SRHm HcGvZcywNqwdB4KjzDoltgjfLJ/GWKm4prnmVJe3B8xTIqNbI= X-Google-Smtp-Source: AGHT+IGHSUhWYmWMTecs2iwqOyzjbhWMCNdjiBhlXFIOF1LjowW151gIptn5EXRcYJDPJFpb9qiZTA== X-Received: by 2002:a17:903:3d0d:b0:24f:8286:9e5d with SMTP id d9443c01a7336-290d14e83ddmr98527585ad.26.1760842345784; Sat, 18 Oct 2025 19:52:25 -0700 (PDT) Received: from rfd.leadboat.com (c-73-15-160-255.hsd1.ca.comcast.net. [73.15.160.255]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-33ba9222d26sm5258112a91.0.2025.10.18.19.52.24 for (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 18 Oct 2025 19:52:24 -0700 (PDT) Date: Sat, 18 Oct 2025 19:52:23 -0700 From: Noah Misch To: pgsql-www@postgresql.org Subject: Scope change & typo in /support/security Message-ID: <20251019025223.3e@rfd.leadboat.com> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="e5j/Z1HogMC35Ltr" Content-Disposition: inline User-Agent: Mutt/2.2.12 (2023-09-09) List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk --e5j/Z1HogMC35Ltr Content-Type: text/plain; charset=us-ascii Content-Disposition: inline The first attached patch fixes grammar in /support/security. The second adds PostgreSQL Anonymizer to the CNA scope. cna@postgresql.org decided on that scope addition in 2024-03 and issued multiple CVEs[1] on the basis of that decision, but I missed updating the page. [1] https://www.cve.org/CVERecord?id=CVE-2024-2338 https://www.cve.org/CVERecord?id=CVE-2024-2339 https://www.cve.org/CVERecord?id=CVE-2025-5690 --e5j/Z1HogMC35Ltr Content-Type: text/plain; charset=us-ascii Content-Disposition: attachment; filename="0001-Fix-typo-in-support-security.patch"