Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support for GIT v2.30.2 because of Security Vulnerability #30

Open
michal-simon opened this issue Mar 11, 2021 · 3 comments
Open

Support for GIT v2.30.2 because of Security Vulnerability #30

michal-simon opened this issue Mar 11, 2021 · 3 comments

Comments

@michal-simon
Copy link

Hi, I've noticed there is a new security vulnerability in the last few versions of GIT and there is a patch already available in version v2.30.2.

More info from GitHub: https://github.blog/2021-03-09-git-clone-vulnerability-announced/

Would you mind building the latest patched version of GIT into a new layer version so everybody can upgrade as soon as possible?

Also, deprecating the vulnerable versions would be nice.

Thank you, we appreciate your work. :)

@mhart
Copy link
Member

mhart commented Mar 11, 2021

Hey there – that vulnerability is for LFS functionality, which this layer doesn't support (though there is a PR open for it)

So I'll upgrade when I get the time, but you shouldn't need to worry about any existing versions being vulnerable to this.

@michal-simon
Copy link
Author

Thank you for the info @mhart. Take your time then :)

@RoxKilly
Copy link

RoxKilly commented Sep 5, 2023

@mhart Would you please give some guidance on how you might build a layer for a more recent version of Git? As time passes, more Git features are missing from the latest layer.

Cheers

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants