https://bugzilla.suse.com/show_bug.cgi?id=1234483 https://bugzilla.suse.com/show_bug.cgi?id=1234483#c1 --- Comment #1 from Gianluca Gabrielli <gianluca.gabrielli@suse.com> --- The packages below are or contain embedded packages that are vulnerable to . Tracking as affected: - openSUSE:Backports:SLE-15-SP5/restic contains embedded package: golang.org/x/crypto/ssh (0.5.0) - openSUSE:Backports:SLE-15-SP5:Update/restic contains embedded package: golang.org/x/crypto/ssh (0.5.0) - openSUSE:Backports:SLE-15-SP6/restic contains embedded package: golang.org/x/crypto/ssh (0.11.0) - openSUSE:Backports:SLE-15-SP6:Update/restic contains embedded package: golang.org/x/crypto/ssh (0.11.0) - openSUSE:Factory/restic contains embedded package: golang.org/x/crypto/ssh (0.24.0) Please consider version bumping or patching the affected dependencies. The listed codestreams are affected. All other codestreams should not be affected, but feel free to double-check. This is a auto-generated message, please reach out to the reporter directly if you think this is incorrect. No bug-owner found for these packages, if the assignation is not correct feel free to re-assign. -- You are receiving this mail because: You are on the CC list for the bug.