Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2021-25749, CVE-2023-3676, CVE-2023-3955, CVE-2024-3177 #21

Merged
merged 1 commit into from
Apr 18, 2024

Conversation

RTann
Copy link
Collaborator

@RTann RTann commented Apr 17, 2024

New CVE from today + older CVEs which were Window-only. Decided to add them. Previously, we ignore them because we don't support Windows nodes, but I figure perhaps it's up to the end-user to determine if it's relevant or not, and not the job of the data source

Comment on lines +18 to +19
- range: ">= 1.25, < 1.25.0"
fixedBy: "1.25.0"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it worth mentioning 1.25.0 at all? Seems like 1.25 is not affected.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

eh. The issue explicitly calls out 1.25.0 as being a fixed version, so interpret that as meaning something like 1.25.0-alpha may be affected. I think it's ok as-is

@RTann RTann merged commit aa5ad11 into main Apr 18, 2024
1 check passed
@RTann RTann deleted the ross/04162024-updates branch April 18, 2024 22:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants