Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dep: update libxml to 2.11.7 (branch 1.15.x) #3154

Merged
merged 2 commits into from
Mar 16, 2024

Conversation

flavorjones
Copy link
Member

@flavorjones flavorjones commented Mar 15, 2024

What problem is this PR intended to solve?

In #3146, @jamiemccarthy requested a security release on the v1.15.x branch to address CVE-2024-25062 which was fixed in v1.16.2 with an upgrade to libxml 2.12.5.

This PR attempts to upgrade the v1.15.x branch to libxml 2.11.7 (from 2.11.6) which also addresses that vulnerability.

Also see related GHSA-xc9x-jj77-9p9j

@flavorjones
Copy link
Member Author

flavorjones commented Mar 16, 2024

Note that the failing CI jobs are mostly related to support for newer libxml2 versions, as the failing jobs occur when building against system libraries that are libxml2 2.12.x. The fixes are specifically detailed in:

I'm not going to backport these changes, and consider those failures to be irrelevant.

Another failure is related to mutex_m no longer being a bundled gem in Ruby 3.4.0-dev, which is also not relevant.

@flavorjones
Copy link
Member Author

I'll merge this and cut a release in the morning.

@flavorjones flavorjones merged commit f8156b4 into v1.15.x Mar 16, 2024
113 of 123 checks passed
@flavorjones flavorjones deleted the flavorjones-dep-libxml-2.11.7_branch-1.15.x branch March 16, 2024 12:54
@flavorjones
Copy link
Member Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant