New Release mitigating CVEs #3298
|
Hey, it seems like the last release of netcdf-c was about a year ago. Would it be possible to get a new release mitigating the following CVEs? |
Replies: 1 comment
|
Hey! netcdf-c is maintained by Unidata and they follow a security policy (linked in the repo). For CVE fixes, the team typically backports patches to the current stable branch and releases updates when ready. You can check the status of specific CVEs on their security advisory page (https://github.com/Unidata/.github/security/advisories). If you have patches, you can also submit a PR against the netcdf-c repository. For release timing, you might open a discussion on their Q&A to ask about a timeline — they often update the community when a release is planned. Hope that points you in the right direction! |
Hey! netcdf-c is maintained by Unidata and they follow a security policy (linked in the repo). For CVE fixes, the team typically backports patches to the current stable branch and releases updates when ready. You can check the status of specific CVEs on their security advisory page (https://github.com/Unidata/.github/security/advisories). If you have patches, you can also submit a PR against the netcdf-c repository. For release timing, you might open a discussion on their Q&A to ask about a timeline — they often update the community when a release is planned. Hope that points you in the right direction!