Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport TUF security bugfix to < 3.10 #9451

Closed
hasufell opened this issue Nov 16, 2023 · 3 comments
Closed

Backport TUF security bugfix to < 3.10 #9451

hasufell opened this issue Nov 16, 2023 · 3 comments
Labels

Comments

@hasufell
Copy link
Member

Since 3.10.2.0 has major regressions on windows, this would leave the 'recommended' version in GHCup vulnerable.

Bumping 'recommended' to 3.10.2.0 is not an option at this time.

@gbaz
Copy link
Collaborator

gbaz commented Nov 16, 2023

Just to be clear: 3.10.2.0 is recommended on platforms besides windows, right? Also, is there a full inventory of the windows regressions that we need to look into?

@hasufell
Copy link
Member Author

3.10.2.0 is recommended on platforms besides windows, right?

No, 'recommended' is across all platforms. We can't recommend a version that works on only some platforms.

Teams should be confident to get the exact same versions of tools when they install 'recommended'. Everything else is calling for confusion.

The regression is described here: #9334

@hasufell hasufell changed the title Backport TUF security bug to < 3.10 Backport TUF security bugfix to < 3.10 Nov 16, 2023
@andreabedini
Copy link
Collaborator

There is no plan for either a 3.6 or 3.8 release. See https://mail.haskell.org/pipermail/cabal-devel/2023-November/010578.html. The fix is included in 3.10+.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants