[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: RFS: Security patch for GitHub CLI client gh



On Wed, Jan 01, 2025 at 05:37:41PM -0800, Otto Kekäläinen wrote:
> Hi Loren!
> 
> > We can hold off on the Bookworm update for a little bit if that would
> > help. As this is my first attempt at getting a package into
> > stable-updates, I am learning a bit myself. Another developer pointed me
> > at the appropriate part of the developer reference for this so I realize
> > that I was using the wrong version suffix when publishing a package for
> > p-u to stable. Another reason why I was keeping it simple as I learn
> > this.
> 
> There is no need for *you* to hold off anything, you are not going to
> do the actual upload anyway. *I* will personally hold off doing
> uploads of the gh package until Anthony comes online, or an reasonable
> time has passed without responses.

OK, I've created a second merge request with a fix for another CVE. I've
left it as a draft as I haven't had a chance to do manual testing of the
feature yet.

The final CVE patch does not apply cleanly to 2.46.0 and will take a
little more time to complete. I can roll it into this merge request once
I get that done, or if we are satisfied with this patch before then,
I'll add it separately.

> 
> You should send any improvement suggestions whenever you have them, so
> the window of opportunity for team members to read them and give
> feedback starts.

Will do.

> 
> I will keep an eye on
> https://salsa.debian.org/go-team/packages/gh/-/merge_requests and try
> to provide you feedback within 1-2 days of you posting something.

-- 
Loren M. Lang
lorenl@north-winds.org
http://www.north-winds.org/


Public Key: http://www.north-winds.org/lorenl_pubkey.asc
Fingerprint: 7896 E099 9FC7 9F6C E0ED  E103 222D F356 A57A 98FA

Attachment: signature.asc
Description: PGP signature


Reply to: