-
Notifications
You must be signed in to change notification settings - Fork 190
jazzy: Backport Patch CVE-2024-42002 #998
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Signed-off-by: Florencia <[email protected]> Signed-off-by: Michael Carroll <[email protected]>
This comment was marked as outdated.
This comment was marked as outdated.
Pulls: #998 |
Signed-off-by: Michael Carroll <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@mjcarroll can you share more context or background here? i am not sure where this is come from, and why we are targeting jazzy but rolling?
@fujitatomoya This was reported a little while back and was landed in It sort of looks like it came from nowhere because of the way that Github does security advisories. You can see the rest of the context here: GHSA-xgqj-p3j3-8jw4 Basically, we iterated in a private fork and did the reviews there before merging to |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@mjcarroll i see, thanks for the explanation.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just documenting some findings here for #1002
This reverts commit f037c19.
This reverts commit f037c19. Signed-off-by: Christophe Bedard <[email protected]>
This reverts commit f037c19. Signed-off-by: Christophe Bedard <[email protected]>
No description provided.