Skip to content

Conversation

mhdawson
Copy link
Member

update security release announcement to indicate releases
are available.

update security release announcement to indicate releases
are available.
@mhdawson
Copy link
Member Author

I'm going to wait at most 1 hour to get feedback on this update as we don't want it going out too long afer the releases. It has already been reviewed by those working on the security release.

Copy link
Contributor

@MylesBorins MylesBorins left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM :shipit:

@mhdawson
Copy link
Member Author

Published to the nodejs-sec mailing list so going to go ahead and land. We can always tweak afterwards

@mhdawson
Copy link
Member Author

Landed as 5a6ae96

@jwheare
Copy link

jwheare commented Jul 12, 2017

Is it possible to get a link added to this announcement that explains the vulnerability and what sort of code might be exploitable by an attacker? Linking to a set of slides that can't be understood without a lot of missing context filled in doesn't seem adequate.

@jwheare
Copy link

jwheare commented Jul 12, 2017

This thread is a great explanation: https://twitter.com/mathias/status/884856878722842629

@gibfahn
Copy link
Member

gibfahn commented Jul 13, 2017

Discussion is happening in this thread: nodejs/node#14171

@hashseed also did a great writeup of it here

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants