Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Question] Why does nuget state that the packages have been witdrawn ? #3

Closed
Smurf-IV opened this issue Apr 24, 2023 · 5 comments
Closed
Assignees

Comments

@Smurf-IV
Copy link

image

@Smurf-IV
Copy link
Author

Note: Version downloads are still active:
image

@sgrottel
Copy link
Owner

sgrottel commented Apr 29, 2023

Thank you for bringing this to my attention.
I just saw this. No idea what triggered this.

I assume, since I am only co-authoring the package, and since it was originally started by the Coapp org, that some (automated CVE) scanning detected a vulnerability and (automatically) flagged the package accordingly. As I say, just an assumption. I really don't know.

Today I got the notification that Lua 5.4.5 popped up on the official Lua FTP site: https://www.lua.org/ftp/
But it seems to be not fully released, yet: https://www.lua.org/work/

I will now start preparing the repo for the next build and release with:

I plan to fix those within the next week, next two weeks tops, and then I will have a new nuget packet version to release. I will then remove the warning flags.

I will keep this issue open until the new package is online.

@sgrottel sgrottel self-assigned this Apr 29, 2023
@sgrottel
Copy link
Owner

Apparently the Coapp org unindexed all their packages: https://www.nuget.org/profiles/coapp

No idea what happened there. ... I plan to continue to maintain the Lua NuGet package on my own.

@sgrottel
Copy link
Owner

I did not find any very recent CVEs for Lua. Well, I found a couple, they are either addressed in recent versions, or will be addressed in version 5.4.5 and all in all seem ok-ish (your typical CVEs, nothing world-ending).

This and the fact that all Coapp org packages got unlisted makes me believe that the Coapp org did a final deprecation and house cleaning and (automatically) indiscriminated unlisted and flagged all their packets.

For that reason, I decided to remove the flags for all 5.4.x versions of the nuget package.

@sgrottel
Copy link
Owner

sgrottel commented May 4, 2023

@sgrottel sgrottel closed this as completed May 4, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants