Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bundles vulnerable copy of Expat - please update to 2.2.5 #535

Open
hartwork opened this issue Jun 19, 2017 · 5 comments
Open

Bundles vulnerable copy of Expat - please update to 2.2.5 #535

hartwork opened this issue Jun 19, 2017 · 5 comments

Comments

@hartwork
Copy link

hartwork commented Jun 19, 2017

Hi!

This repository bundles an outdated vulnerable copy of Expat 2.0.1. Please update your copy to version 2.2.4 with the latest security fixes. A change log with details is available at https://github.com/libexpat/libexpat/blob/master/expat/Changes . Thank you!

Best

 
Sebastian

@hartwork
Copy link
Author

hartwork commented Jul 1, 2017

Any news or issues with updating?

@RemiArnaud
Copy link
Contributor

Is there a pull request?

@hartwork
Copy link
Author

hartwork commented Jul 11, 2017

Not that I knew, no. For someone to make some, understanding of OpenCOLLADAs build system, the list of supported platforms and compilers, and a bit of time is needed.

@RemiArnaud
Copy link
Contributor

Nope you don't need to compile anything yourself.

You can submit a PR and jenkins will build for us. It would be way to much work for anybody to compile for all those versions of all those tools for all those platforms....

Hopefully upgrading the library won't break the build. Otherwise, we'd have something to start with.

@hartwork
Copy link
Author

You would still need to inspect the build system so that detection of high entropy sources like getrandom is done somewhere if you don't use nested configure and so on, the new EXPAT_ENTROPY_DEBUG=1 may be handy for debugging. I'm happy to help with any issues or questions that you run into in the process.

@hartwork hartwork changed the title Bundles vulnerable copy of Expat - please update to 2.2.1 Bundles vulnerable copy of Expat - please update to 2.2.2 Jul 14, 2017
@hartwork hartwork changed the title Bundles vulnerable copy of Expat - please update to 2.2.2 Bundles vulnerable copy of Expat - please update to 2.2.4 Aug 20, 2017
@hartwork hartwork changed the title Bundles vulnerable copy of Expat - please update to 2.2.4 Bundles vulnerable copy of Expat - please update to 2.2.5 Nov 15, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants