Patched HIGH CVE-2022-38725 for syslog-ng#6431
Conversation
b4f7958 to
565a236
Compare
|
/AzurePipelines run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
|
@mbykhovtsev-ms, just a heads-up: all PRs against |
a4d54fa to
92ee41d
Compare
92ee41d to
01fd252
Compare
|
Wondering if I can do bbeb322? Here's what happened:
Passing fasttrack build without |
I took a look at the It seems, that I believe this is the Criterion project these lines are about. After a brief search I wasn't able to find a Fedora package building this project, so maybe that's why it's not enabled for them. Since we don't have it as well, we'd need to investigate further what it would take to light it up. For instance, it seems that Red Hat might have something. With all of that considered, I think it is fine to move enabling tests for this package to a later date. However, let's keep the |
0xba1a
left a comment
There was a problem hiding this comment.
As Pawel mentioned, please create P1 bug and provide the link in this PR for reference
|
Created P1 bug and linked back to this PR. Also added back the |
Co-authored-by: Saul Paredes <saulparedes@microsoft.com> (cherry picked from commit 6012b9a)
|
Auto cherry-pick results: Auto cherry-pick pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=458187&view=results |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./SPECS/LICENSES-AND-NOTICES/data/licenses.json,./SPECS/LICENSES-AND-NOTICES/LICENSES-MAP.md,./SPECS/LICENSES-AND-NOTICES/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
Patched high CVE-2022-38725 for
syslog-ng. Patch found at syslog-ng/syslog-ng#4110Change Log
syslog-ngDoes this affect the toolchain?
NO
Links to CVEs
Test Methodology