Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sanitize lib needs update (CVE-2018-3740) #295

Closed
captn3m0 opened this issue Mar 21, 2018 · 4 comments
Closed

sanitize lib needs update (CVE-2018-3740) #295

captn3m0 opened this issue Mar 21, 2018 · 4 comments

Comments

@captn3m0
Copy link

As per rgrove/sanitize#176, the updated release is 4.6.3

rgrove added a commit to rgrove/gollum-lib that referenced this issue Mar 23, 2018
@joseluis-fw
Copy link

@dometto Any update on this security PR?

@rsov
Copy link

rsov commented Aug 22, 2018

Last commit was almost a year ago. I doubt it that this will be merged anytime soon

@dometto
Copy link
Member

dometto commented Aug 25, 2018

Was unable to work on gollum for a while due to reasons. Sorry for leaving this security issue hanging. Getting up to speed with gollum again and will try to resolve this ASAP.

@dometto
Copy link
Member

dometto commented Oct 1, 2018

Hi all, finally released v4.2.10 which relies on v2.1.1 of sanitize, which has the fix backported. gollum will also soon be updated to depend on the new gollum-lib release. Sorry for the long wait.

@dometto dometto closed this as completed Oct 1, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants