Skip to content

Commit

Permalink
Release v28
Browse files Browse the repository at this point in the history
  • Loading branch information
rickynils committed May 2, 2024
1 parent 2eeac83 commit 60e9c39
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 21 deletions.
26 changes: 6 additions & 20 deletions RELEASE
Original file line number Diff line number Diff line change
@@ -1,25 +1,11 @@
v27

## Security Notice

This release (and previous releases) includes Nix versions that are vulnerable to [CVE-2024-27297](https://www.cve.org/CVERecord?id=CVE-2024-27297). The current default Nix version, 2.19.3, is not vulnerable. If you select another Nix version you should use your own judgement to decide if CVE-2024-27297 is applicable to your usage of Nix in your GitHub Actions workflow.

The following Nix versions that are packaged with this action are **not** vulnerable:

* 2.19.3 (the default version)
* 2.18.1
* 2.3.17

The above versions have been explicitly patched by the `nixpkgs` maintainers.

The rest of the Nix versions provided by this action **are vulnerable** to CVE-2024-27297.

In the next release of this action (v28), all vulnerable Nix versions will be removed.
v28

## Changes

* Bump minor Nix versions: 2.3.16 -> 2.3.17
* Remove all Nix versions that are vulnerable to [CVE-2024-27297](https://www.cve.org/CVERecord?id=CVE-2024-27297).

* Bump minor Nix versions: 2.18.1 -> 2.18.2

* Add Nix versions: 2.17.1, 2.18.1, 2.19.3
* Add Nix versions: 2.20.5, 2.21.0

* Bump default Nix version: 2.16.2 -> 2.19.3
* Bump default Nix version: 2.19.3 -> 2.21.0
2 changes: 1 addition & 1 deletion action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ inputs:

nix_version:
required: true
default: "2.19.3"
default: "2.21.0"
description: |
The version of Nix that should be installed
Expand Down

0 comments on commit 60e9c39

Please sign in to comment.