Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update gitpython #63301

Closed
wants to merge 1 commit into from
Closed

Update gitpython #63301

wants to merge 1 commit into from

Conversation

Ch3LL
Copy link
Contributor

@Ch3LL Ch3LL commented Dec 12, 2022

No description provided.

@Ch3LL Ch3LL requested a review from a team as a code owner December 12, 2022 17:28
@Ch3LL Ch3LL requested review from waynew and removed request for a team December 12, 2022 17:28
@Ch3LL Ch3LL added the Sulfur v3006.0 release code name and version label Dec 15, 2022
@eddybl
Copy link

eddybl commented Dec 16, 2022

I am a bit confused due to this advisory: GHSA-hcpj-qp55-gfph
(also with the 3005.1-3 security update), since the actual issue with GitPython is not fixed in 3.1.29

gitpython-developers/GitPython#1515

@Ch3LL
Copy link
Contributor Author

Ch3LL commented Dec 16, 2022

When the notice was originally published it stated "<=3.1.20" was the last affected. If you look at the history of the advisory, this was just updated yesterday: github/advisory-database@5c478f4 to be <= 3.1.29 . Looks like there is not even a patched version yet from what I can see on pypi.

@Ch3LL Ch3LL removed the Sulfur v3006.0 release code name and version label Dec 16, 2022
@eddybl
Copy link

eddybl commented Dec 16, 2022

Ok, I see. I didn't notice that!

@eddybl
Copy link

eddybl commented Jan 3, 2023

Version 3.1.30 was released to fix the CVE:
https://gitpython.readthedocs.io/en/stable/changes.html#id1

@Ch3LL
Copy link
Contributor Author

Ch3LL commented Jan 3, 2023

Thanks :) I'm going to close this one in favor of this merge #63394

We are working on updating our packaging.

@Ch3LL Ch3LL closed this Jan 3, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants