-
-
Notifications
You must be signed in to change notification settings - Fork 2.5k
libs: expat bump from 2.6.0 to 2.7.1 #8571
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
|
|
Thanks @LeSuisse! Did you do any testing to verify things are still working as expected? We just discussed in office hours and think the relevant tables are |
|
I did make a quick functional tests with libexpat/libexpat#980 (comment) I'm putting the PR in draft until then and I will test again with the new version. |
|
FYI the bump from 2.6.0 to 2.7.0 also fixes CVE-2024-50602. |
|
I see they merged the linked PR in the expat repo. Please lmk when this is ready for review again! |
|
@zwass FYI release Expat 2.7.1 is coming up in the next few hours |
|
Expat 2.7.1 with a fix has been released. |
8d20478 to
3ba2609
Compare
|
Bumped to 2.7.1, I played a bit with |
3ba2609 to
9d07cd8
Compare
9d07cd8 to
87722e9
Compare
zwass
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@LeSuisse can you please merge/rebase master? That will fix the mdfind CI issue.
87722e9 to
6b87d0c
Compare
|
Sorry for the noise, it looks like I failed to push the appropriate branch and it closed the PR without giving me the possibility to re-open it. See #8595 for the rebased change. |
Was #8571. Fixes #8557 Fixes CVE-2024-50602, CVE-2024-28757 and CVE-2024-8176.
Fixes #8557
CVE-2024-50602, CVE-2024-28757 and CVE-2024-8176.
https://github.com/libexpat/libexpat/blob/R_2_7_1/expat/Changes