Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bison Windows executable for 3.5.4+ #58

Closed
a11apurva opened this issue Aug 26, 2020 · 4 comments
Closed

Bison Windows executable for 3.5.4+ #58

a11apurva opened this issue Aug 26, 2020 · 4 comments

Comments

@a11apurva
Copy link

Because of a CVE we are looking for Bison 3.5.4 or higher version.

I can see that version 2.5.22 (bison 3.5.0) is the last stable release. Is there any timeline for any 3.5.4+ stable release?

Thank you!

@GitMensch
Copy link
Collaborator

"soon" - see #56 which also contains a testing build of 3.7 - should be fine if your sources don't use non-ascii token literals (and don't expect the color options to be available).

@a11apurva
Copy link
Author

Okay, thank you for this information.

@a11apurva
Copy link
Author

Hi @GitMensch, @lexxmark,

All the open CVEs have been closed in Bison-3.7.2 which has been recently released.

GNU Bison NEWS

  • Noteworthy changes in release 3.7.2 (2020-09-05) [stable]

    This release of Bison fixes all known bugs reported for Bison in MITRE's
    Common Vulnerabilities and Exposures (CVE) system. These vulnerabilities
    are only about bison-the-program itself, not the generated code.

Would there be a win-bison update incorporating these changes any time soon?

@lexxmark
Copy link
Owner

Hi @a11apurva, we should definitely adopt bison 3.7.2
I cannot guarantee it will be soon.

@GitMensch GitMensch mentioned this issue Sep 13, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants