[OE-core][PATCH v2 1/1] go: ignore CVE-2023-45283 and CVE-2023-45284

2023-12-08 Thread Soumya via lists.openembedded.org
From: Soumya Sambu These CVEs affect path handling on Windows. References: https://nvd.nist.gov/vuln/detail/CVE-2023-45283 https://nvd.nist.gov/vuln/detail/CVE-2023-45284 Signed-off-by: Soumya Sambu --- meta/recipes-devtools/go/go-1.20.10.inc | 3 +++ 1 file changed, 3 insertions(+) diff --g

Re: [OE-core][PATCH v2 1/1] go: ignore CVE-2023-45283 and CVE-2023-45284

2023-12-09 Thread Alexandre Belloni via lists.openembedded.org
Hello, We had go upgrades in between, can you rebase (and check if this is still needed)? On 08/12/2023 10:42:15+, Soumya via lists.openembedded.org wrote: > From: Soumya Sambu > > These CVEs affect path handling on Windows. > > References: > https://nvd.nist.gov/vuln/detail/CVE-2023-45283

Re: [OE-core][PATCH v2 1/1] go: ignore CVE-2023-45283 and CVE-2023-45284

2023-12-11 Thread Soumya via lists.openembedded.org
@lists.openembedded.org Subject: Re: [OE-core][PATCH v2 1/1] go: ignore CVE-2023-45283 and CVE-2023-45284 CAUTION: This email comes from a non Wind River email account! Do not click links or open attachments unless you recognize the sender and know the content is safe. Hello, We had go upgrades in between