Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Parse Baseline in a secure way #4499

Merged
merged 1 commit into from Jan 18, 2022
Merged

Parse Baseline in a secure way #4499

merged 1 commit into from Jan 18, 2022

Conversation

BraisGabin
Copy link
Member

No description provided.

@BraisGabin BraisGabin merged commit c965a8d into main Jan 18, 2022
@BraisGabin BraisGabin deleted the secure-xml branch January 18, 2022 17:21
@cortinico cortinico added this to the 1.20.0 milestone Jan 28, 2022
@cortinico cortinico added the notable changes Marker for notable changes in the changelog label Jan 28, 2022
@cortinico
Copy link
Member

Should this be announced/documented in some special form @BraisGabin ?

@BraisGabin
Copy link
Member Author

I think so, but I don't know which would be the best way.

@chao2zhang
Copy link
Member

I think we can leverage the information from https://huntr.dev/bounties/23e37ba7-96d5-4037-a90a-8c8f4a70ce44/, such as a new section in the release notes like below:

Security

Parse Baseline in a secure way (#4499) - CWE-611

Note: The same vulnerability on other repos are not called out explicitly.

@3flex 3flex mentioned this pull request Apr 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
notable changes Marker for notable changes in the changelog
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants