Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Release 10.1.0 #728

Closed
10 tasks done
kelson42 opened this issue Mar 23, 2022 · 4 comments
Closed
10 tasks done

Release 10.1.0 #728

kelson42 opened this issue Mar 23, 2022 · 4 comments
Assignees
Milestone

Comments

@kelson42
Copy link
Collaborator

kelson42 commented Mar 23, 2022

Following remark from @legoktm at #721 (comment)


Thanks, so a597870 was only included in 10.0.0 (no released Debian versions are affected, just unstable).

Could we do a 10.0.2 release with just this cherry-picked? I note that even library.kiwix.org is vulnerable to this. Or if 10.1.0 is coming pretty soon then waiting wouldn't be too bad.

And we should also get a CVE ID assigned for this vulnerability, @kelson42 if you haven't gone through this process before I'm happy to help out.


I also believe we should not wait to much to make the release of 10.1.0.

  • Secure the CI is green on git master
  • Kiwix-Build is OK
  • Update the Changelog
  • Update version
  • Close current milestone and create new one incrementaly (a priori a minor version)
  • Create a tag on git
  • Secure new source/sbinaries are published on http://download.kiwix.org
  • Update the Github release with the Changelog
  • Create new empty entry in Changelog (placeholder for future entries)
  • Publicize these new versions
@kelson42 kelson42 self-assigned this Mar 23, 2022
@kelson42 kelson42 added this to the 10.1.0 milestone Mar 23, 2022
@kelson42
Copy link
Collaborator Author

@legoktm I never made a CVE report before indeed. If you can do one, thank you.

@legoktm
Copy link
Member

legoktm commented Mar 24, 2022

Thank you for putting out the release, I just requested a CVE ID, and will comment here when it is assigned.

@carnil
Copy link

carnil commented Mar 26, 2022

Looks CVE-2022-27920 got assigned to this issue.

@kelson42
Copy link
Collaborator Author

@carnil Thx for noticing, this shoudl be fixed in libkiwix 10.1.0 we have released a few days ago.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants