Description of the patch:
This update for yq fixes the following issues:
Update to v4.53.3.
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation
bypass and privilege escalation (bsc#1267199).
- CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of input containing invalid UTF-8 bytes can lead
to infinite loop (bsc#1271994).
Changes for yq:
- v4.53.3:
- Add --ini-preserve-quotes flag for INI round-trip quote preservation.
- Fix: reset INI decoder state on init.
- Fix: decode properties array bracket paths.
- Fix: preserve floats with trailing zero when encoding YAML to JSON.
- Fix: JSON to TOML root scope and null handling.
- Fix: reset TOML decoder finished flag on Init for multi-doc evaluation.
- Fix: reset TOML decoder between files when evaluating all at once.
- Fix: preserve TOML inline table array scope.
- Fix: preserve empty TOML arrays in tables
- Fix: TOML encoder uses inline tables for YAML FlowStyle mappings.
- Fix nested inline YAML merge explode.
- Fix repeatString overflow test on 32-bit platforms.