-
Notifications
You must be signed in to change notification settings - Fork 53
Bump Perl versions to fix various CVE's in perl 5.3[468] #149
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
Not quite yet, waiting for Perl/perl5#21671 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Will need updated SHA256s per http://nntp.perl.org/group/perl.perl5.porters/267365 (once they're available at the primary CPAN site, they're currently hosted at Paul's server.)
|
It seems we go to: 5.34.3, 5.36.3 and 5.38.2. See https://www.nntp.perl.org/group/perl.perl5.porters/2023/11/msg267372.html |
Signed-off-by: Wesley Schwengle <waterkip@cpan.org>
|
We have the updated SHA's and version numbers from https://www.nntp.perl.org/group/perl.perl5.porters/2023/11/msg267400.html but we cannot download them yet from cpan.org: |
0a12f4f to
98679ec
Compare
Signed-off-by: Wesley Schwengle <waterkip@cpan.org>
zakame
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, will drop eol changes in next commit
See:
5.34.2: https://www.nntp.perl.org/group/perl.perl5.porters/2023/11/msg267352.html
5.36.2:https://www.nntp.perl.org/group/perl.perl5.porters/2023/11/msg267353.html
5.38.1: https://www.nntp.perl.org/group/perl.perl5.porters/2023/11/msg267354.html