Add: port the security patches we have for CVEs #165
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Instead of running on its own site, it now integrates with the
main website. This avoids copying the Jekyll website and maintaining
two instances of it. The main website and the CVE listing are similar
enough that this shouldn't be an issue.
The data is imported from the current security listing we have,
including the patches available. It is imported as-is without
modification.
NOTE : when reviewing, please run the Docker locally and test out if it is all what it should be.
Why via Docker and not via Jekyll
serve
? Otherwise.patch
files will download, instead of showing it inline. Makes it a tiny bit harder to see what is going on.The "diff" has a few files before all the
_security
related files start, and ends with 3 non-_security
files at the bottom. Keep that in mind when reviewing.