Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

xz-utils CVE fallout broke our build #42

Closed
totaam opened this issue Mar 30, 2024 · 1 comment
Closed

xz-utils CVE fallout broke our build #42

totaam opened this issue Mar 30, 2024 · 1 comment

Comments

@totaam
Copy link
Collaborator

totaam commented Mar 30, 2024

We have a (non-vulnerable it seems) download link to xz:

<branch module="xz/xz-5.4.3.tar.bz2"
version="5.4.3"
hash="sha256:9243a04598d7a70c1f567a0143a255581ac5c64b140fd55fd5cbc1e00b0e6f90"
repo="tukaani.org" />

And when github took the whole project down because of CVE-2024-3094, this broke our builds..

I'm not saying that taking the project down was not the right thing to do.

Just a cautionary tale about reproducible builds.

@totaam totaam changed the title cx CVE fallout broke out build xz-utils CVE fallout broke out build Mar 30, 2024
@totaam totaam changed the title xz-utils CVE fallout broke out build xz-utils CVE fallout broke our build Jun 1, 2024
@totaam
Copy link
Collaborator Author

totaam commented Jun 1, 2024

Updated xz to 5.6.2 in 1050b4d

@totaam totaam closed this as completed Jun 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant