| CARVIEW |
Select Language
HTTP/2 200
date: Tue, 30 Dec 2025 04:44:23 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
etag: W/"c096cd66eb3f7af9bb45e624116d23b4"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: no-referrer-when-downgrade
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com/ copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=54Hz3gRnUU9TOhCDdn1%2B9kd5lVdSQ9SgXebb3HWrDGlAOpG36QS3FkcsRHhbMwe2qk1CFLkWEWqILcslwVH0uVrtvSojedulVQqRcAUkwTa75IMlqkQn6vfEyC0SkzRGZ93oY9MP6p981qcDUZCVLZXL89Ddtx1HXSo%2FuyxyHUX9%2FUiuDpNkkagRY3DLDoGd8jN8ZD81V5edainr0M%2BUpxqwA42wMSnL2dXsswXCZjURrXj1tVvm0mV8whriR7RonxfL%2FNN8uGMT7U1dreu8TQ%3D%3D--CvqnrljR7eTAugcV--yJnYt7JRFyGqGBocOkClwg%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.854894141.1767069863; Path=/; Domain=github.com; Expires=Wed, 30 Dec 2026 04:44:23 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Wed, 30 Dec 2026 04:44:23 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: B6BA:16C3C3:6D697:7C365:695358A7
Releases · cloudfoundry/bosh · GitHub
Loading
Loading
Loading
Loading
Loading
Loading
Loading
Loading
Loading
Loading
Skip to content
Navigation Menu
{{ message }}
-
Notifications
You must be signed in to change notification settings - Fork 658
Releases: cloudfoundry/bosh
Releases · cloudfoundry/bosh
v282.1.2
Assets 2
v282.1.1
What's Changed
- CI: switch internal CIDR away from 10.0.0.0 by @aramprice in #2634
- adapt create_vm and attach_disk call for new cpi version 3 by @fmoehler in #2633
- remove duplicate ip addresses with smaller prefix by @fmoehler in #2636
Full Changelog: v282.1.0...v282.1.1
Assets 2
v282.1.0
Full Changelog: v282.0.10...v282.1.0
Same as v282.0.10 which should be a minor release update.
Fixed CVEs:
- CVE-2025-61770: rack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
- CVE-2025-61771: rack: Rack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
- CVE-2025-61772: rack: Rack memory exhaustion denial of service
- CVE-2025-61919: rubygem-rack: Unbounded read in
Rack::Requestform parsing can lead to memory exhaustion
Package Updates:
- Updates nginx from 1.29.1 to 1.29.2
What's Changed
Assets 2
v282.0.10
Fixed CVEs:
- CVE-2025-61770: rack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
- CVE-2025-61771: rack: Rack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
- CVE-2025-61772: rack: Rack memory exhaustion denial of service
- CVE-2025-61919: rubygem-rack: Unbounded read in
Rack::Requestform parsing can lead to memory exhaustion
Package Updates:
- Updates nginx from 1.29.1 to 1.29.2
What's Changed
- Bump actions/setup-go from 5 to 6 by @dependabot[bot] in #2624
- [RFC0038] Introduce prefix allocation by @fmoehler in #2611
- Fix regression issues by @fmoehler in #2626
- add missing expectations for integration tests by @fmoehler in #2628
- Update workstation_setup.md by @fmoehler in #2627
- stringify prefix for networks and not only its subnets by @fmoehler in #2629
- fix test expectation by @fmoehler in #2630
- Avoid unnecessary redeploys by @fmoehler in #2631
Full Changelog: v282.0.9...v282.0.10
Assets 2
v282.0.9
Fixed CVEs:
- CVE-2025-58767: rexml: REXML denial of service
What's Changed
- Add 'file' package to Dockerfile dependencies for intergration by @ramonskie in #2621
Full Changelog: v282.0.8...v282.0.9
Assets 2
v282.0.8
Assets 2
v282.0.7
Package Updates:
- Updates director-ruby-3.3 from 3.3.8 to 3.3.9
- Updates nginx from 1.29.0 to 1.29.1
Updates:
- Updates postgresql-13 from 13.21 to 13.22
- Updates postgresql-15 from 15.13 to 15.14
What's Changed
- Fix tags extraction from runtime config by @IvayloIvanovSAP in #2617
- CI/Dev: remove
fly syncfrom fly rake task by @mkocher in #2619 - Bump actions/checkout from 4 to 5 by @dependabot[bot] in #2620
New Contributors
- @IvayloIvanovSAP made their first contribution in #2617
- @mkocher made their first contribution in #2619
Full Changelog: v282.0.6...v282.0.7
Assets 2
v282.0.6
Assets 2
v282.0.5
Fixed CVEs:
- CVE-2025-46727: rubygem-rack: Unbounded-Parameter DoS in Rack::QueryParser
- CVE-2025-49007: rack: rubygem-rack: Rack Content-Disposition Denial of Service
Updates:
- Updates postgresql-13 from 13.20 to 13.21
- Updates postgresql-15 from 15.12 to 15.13
What's Changed
- Bump golangci/golangci-lint-action from 7 to 8 by @dependabot in #2613
Full Changelog: v282.0.4...v282.0.5
Assets 2
v282.0.4
Package Updates:
- Updates nginx from 1.27.5 to 1.28.0
Updates:
- Updates nats-server from 2.11.1 to 2.11.2
What's Changed
- Extract
bosh-templatetobosh-commonby @aramprice in #2608
Full Changelog: v282.0.3...v282.0.4
Assets 2
Previous Next
You can’t perform that action at this time.