-
-
Notifications
You must be signed in to change notification settings - Fork 157
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: Bump z-schema 4.2.3 → 5.0.1 for ReDoS fix in validator #166
fix: Bump z-schema 4.2.3 → 5.0.1 for ReDoS fix in validator #166
Conversation
5.0.0 of |
@JamesMessinger Can you please help me figure out what else I'd need to do to get this (future) version bump released? e.g., getting |
@nicolasv - As long as all tests pass (run |
WIP because the earliest version of z-schema that would have the required bump to validator is 5.0.1. See zaggino/z-schema#265
e5c45ad
to
3fde413
Compare
From the other PR
|
@JamesMessinger After upgrading to 5.0.1 of
I noticed that |
This is what #165 fixes ;-)
|
@nicolasv Are you planning on committing this soon? Our company was hoping for the exact change you're making as it will fix a vulnerability found with the z-schema@4.2.3. |
@JamesMessinger Could you please review this? |
@JamesMessinger can you take a look at #165 to see if that can get committed? This PR #166 is dependent on that as well as a review. |
@JamesMessinger can you please take a look at both #165 and this PR #166 and merge them if they are fine.. this helps fix a vulnerability. |
Merged #170 first. |
@philsturgeon Any chance you could release a new version? |
Is there an update on when a version containing this fix will be released? Like others, we are also tracking it as it fixes a vulnerability. @philsturgeon @JamesMessinger |
WIP because the earliest version of
z-schema
that would have the required bump tovalidator
is 5.0.1. See zaggino/z-schema#265Creating this early just to see if any tests fail with the 5.x line of
z-schema
. Note, however, that onmaster
there is one failing test (see CI CD #28)I get the same single failure in this branch