Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

lua5_1: Properly name CVE patch #72076

Closed

Conversation

JohnAZoidberg
Copy link
Member

If the CVE identifier is in the patch name, vulnix knows, that this
package is not affected by the CVE anymore.

fyi @ckauhaus @bhipple

If the CVE identifier is in the patch name, vulnix knows, that this
package is not affected by the CVE anymore.
@JohnAZoidberg
Copy link
Member Author

JohnAZoidberg commented Oct 27, 2019

Should be backported to 19.09.
Edit: Actually, doesn't matter, because vulnix only ever reports a vulnerability once per release.

@ckauhaus
Copy link
Contributor

@JohnAZoidberg It matters in that respect that people run vulnix on their own systems. There they do obviously not have the global Vulnerability Roundup whitelist. Naming patches correctly helps to get better results on clean runs.

So I encourage you to rebase this PR so that it can be cleanly merged.

@JohnAZoidberg
Copy link
Member Author

Looks like it was already done in #70274.

@JohnAZoidberg JohnAZoidberg deleted the lua5.1-CVE-2014-5461 branch November 17, 2019 15:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants