Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

community/gitea: security upgrade to 1.7.0 #6147

Closed
wants to merge 1 commit into from

Conversation

Bwko
Copy link
Contributor

@Bwko Bwko commented Jan 23, 2019

@Bwko Bwko changed the title community/gitea upgrade to 1.7.0 community/gitea: security upgrade to 1.7.0 Jan 23, 2019
@andypost andypost added the A-upgrade Upgrades an abuild label Jan 24, 2019
@andypost
Copy link
Contributor

The change go-gitea/gitea#5631 looks really critical

@clandmeter
Copy link
Member

It looks like gitea doesnt release a new patch release for older versions.
Maybe we can patch it outselfs?

@Bwko
Copy link
Contributor Author

Bwko commented Jan 30, 2019

@clandmeter I'm willing to do that. Which alpine versions need these patches? v3.8 & 3.7 ?

@clandmeter
Copy link
Member

@Bwko yes that would be nice.
I just pushed e9ae1ec to update to 1.7.1 in edge.

@clandmeter
Copy link
Member

@Bwko you can get release support information from this table:
https://wiki.alpinelinux.org/wiki/Alpine_Linux:Releases

  • pkgs in main are supported a minimum of 2 years
  • pkgs in community a supported a minimum of 6 months

This doesn't mean we only support community for 6 months, for sure if the security issue is serious.

@clandmeter clandmeter closed this Feb 1, 2019
@clandmeter
Copy link
Member

@Bwko are there any CVE's released for these security issues? If so would be nice to include them in the PR's. We can add them to our secdb.

@jonasfranz
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
A-upgrade Upgrades an abuild T-backport-it
Projects
None yet
4 participants