- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- David Prévot
- Date:
- 2022-07-09 10:52:51 UTC
- Severity:
- normal
- Tags:
[ Reason ] I’d like to address CVE-2022-24828 that has been tagged as no-dsa. Some people may also wish to see #989315 fixed (it was reported twice), and the fix is trivial, so I’m proposing a fix for it too. [ Impact ] The security fix is worth it, the GitHub token pattern fix is useful for people using this feature. [ Tests ] I had to also checkout a file used for the updated testsuite that passes. I’m not using the Github feature, but the regex fix looks pretty obvious. [ Risks ] I’ve also provided the diffoscope output, showing probably better the trival changes. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable Regards Thanks in advance. David
Control: tags -1 + confirmed Please go ahead. Regards, Adam
package release.debian.org tags 1012047 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: composer Version: 2.0.9-2+deb11u1 Explanation: fix code injection issue [CVE-2022-24828]; update GitHub token pattern
package release.debian.org tags 1012047 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: composer Version: 2.0.9-2+deb11u1 Explanation: fix code injection issue [CVE-2022-24828]; update GitHub token pattern
(re-sending with fixed bug numbers) Hi, The updates discussed in these bugs were included in today's bullseye point release. Regards, Adam