Skip to content

Upgrade zlib to version 1.2.12 #15386

@jsharpe

Description

@jsharpe

Description of the bug:

Bazel embeds zlib version 1.2.11 which is subject to know vulenerabilities. 1.2.12 has been released which addresses these vulnerabilites and so the version used in bazel should be updated.

What's the simplest, easiest way to reproduce this bug? Please provide a minimal example if possible.

No response

Which operating system are you running Bazel on?

No response

What is the output of bazel info release?

No response

If bazel info release returns development version or (@non-git), tell us how you built Bazel.

No response

What's the output of git remote get-url origin; git rev-parse master; git rev-parse HEAD ?

No response

Have you found anything relevant by searching the web?

No response

Any other information, logs, or outputs that you want to share?

I believe that this should be addressed before the release of 5.2. zlib 1.2.12 should be a drop in replacement.
@bazel-io flag

Metadata

Metadata

Assignees

Labels

P1I'll work on this now. (Assignee required)team-ExternalDepsExternal dependency handling, remote repositiories, WORKSPACE file.type: bug

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions