Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New security release #94

Closed
gaby opened this issue Dec 18, 2024 · 8 comments · Fixed by #95
Closed

New security release #94

gaby opened this issue Dec 18, 2024 · 8 comments · Fixed by #95

Comments

@gaby
Copy link

gaby commented Dec 18, 2024

@woodruffw A new release of rage is coming out today, there was a CVE found, which means a new pyrage release is needed.

See: GHSA-4fg7-vxc8-qx5w

Releases: https://github.com/str4d/rage/releases

@woodruffw
Copy link
Owner

Thanks for letting me know -- I'll look into making a new release tonight.

@gaby
Copy link
Author

gaby commented Dec 19, 2024

@woodruffw Thanks, new release is out https://github.com/str4d/rage/releases/tag/v0.11.1

@woodruffw
Copy link
Owner

#95 performs the bump. Once merged and cut, I'll do a GHSA for the current range of releases to encourage people to upgrade.

@gaby
Copy link
Author

gaby commented Dec 19, 2024

Sounds good 💪

@woodruffw
Copy link
Owner

1.2.3 has been cut and should be live on PyPI shortly. Thanks for bringing this to my attention @gaby! You should get a notification soon about being invited to a draft GHSA (I'll assign you as the reporter so you get credit).

@gaby
Copy link
Author

gaby commented Dec 19, 2024

💪 Thanks for the quick fix on this.

@woodruffw
Copy link
Owner

1.2.3 should be live now, and you've received an invite to the GHSA. Please give that a quick look and if it LGTY I'll publish it 🙂

@gaby
Copy link
Author

gaby commented Dec 19, 2024

1.2.3 should be live now, and you've received an invite to the GHSA. Please give that a quick look and if it LGTY I'll publish it 🙂

Looks good to me, I'd say to add a section like the original cve

An equivalent issue was fixed in [the reference Go implementation of age](https://github.com/FiloSottile/age), see advisory [GHSA-32gq-x56h-299c](https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c).

Thanks to ⬡-49016 for reporting this issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants