Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[qtbase] add official patch for CVE-2024-25580 #36822

Merged
merged 3 commits into from
Feb 21, 2024

Conversation

carsten-grimm
Copy link
Contributor

Fixes #36821.

  • Changes comply with the maintainer guide.
  • SHA512s are updated for each updated download.
  • The "supports" clause reflects platforms that may be fixed by this new version.
  • Any fixed CI baseline entries are removed from that file.
  • Any patches that are no longer applied are deleted from the port's directory.
  • The version database is fixed by rerunning ./vcpkg x-add-version --all and committing the result.
  • Only one version is added to each modified port's versions file.

@carsten-grimm
Copy link
Contributor Author

Building port qtinterfaceframework fails, because code.qt.io is offline at the moment. I will retry later, when it is available again.

@LilyWangLL LilyWangLL added the category:port-bug The issue is with a library, which is something the port should already support label Feb 18, 2024
@carsten-grimm
Copy link
Contributor Author

Qt is aware that code.qt.io is offline and is working on the issue: https://forum.qt.io/topic/154616/unable-to-reach-to-https-code-qt-io

@carsten-grimm carsten-grimm marked this pull request as ready for review February 18, 2024 20:06
@LilyWangLL LilyWangLL added the info:reviewed Pull Request changes follow basic guidelines label Feb 19, 2024
@vicroms vicroms merged commit 4bee3f5 into microsoft:master Feb 21, 2024
16 checks passed
TomKatom pushed a commit to TomKatom/vcpkg that referenced this pull request Feb 23, 2024
Fixes microsoft#36821.

- [x] Changes comply with the [maintainer
guide](https://github.com/microsoft/vcpkg-docs/blob/main/vcpkg/contributing/maintainer-guide.md).
- [x] SHA512s are updated for each updated download.
- [x] The "supports" clause reflects platforms that may be fixed by this
new version.
- [x] Any fixed [CI
baseline](https://github.com/microsoft/vcpkg/blob/master/scripts/ci.baseline.txt)
entries are removed from that file.
- [x] Any patches that are no longer applied are deleted from the port's
directory.
- [x] The version database is fixed by rerunning `./vcpkg x-add-version
--all` and committing the result.
- [x] Only one version is added to each modified port's versions file.
Osyotr pushed a commit to Osyotr/vcpkg that referenced this pull request Feb 26, 2024
Fixes microsoft#36821.

- [x] Changes comply with the [maintainer
guide](https://github.com/microsoft/vcpkg-docs/blob/main/vcpkg/contributing/maintainer-guide.md).
- [x] SHA512s are updated for each updated download.
- [x] The "supports" clause reflects platforms that may be fixed by this
new version.
- [x] Any fixed [CI
baseline](https://github.com/microsoft/vcpkg/blob/master/scripts/ci.baseline.txt)
entries are removed from that file.
- [x] Any patches that are no longer applied are deleted from the port's
directory.
- [x] The version database is fixed by rerunning `./vcpkg x-add-version
--all` and committing the result.
- [x] Only one version is added to each modified port's versions file.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:port-bug The issue is with a library, which is something the port should already support info:reviewed Pull Request changes follow basic guidelines
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[qtbase] add official patch for CVE-2024-25580
3 participants