[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[bug#61583] [PATCH] gnu: git: Update to 2.39.2 [fixes CVE-2023-22490 & C
From: |
Josselin Poiret |
Subject: |
[bug#61583] [PATCH] gnu: git: Update to 2.39.2 [fixes CVE-2023-22490 & CVE-2023-23946]. |
Date: |
Sat, 04 Mar 2023 18:52:58 +0100 |
Hi Leo,
"Leo Famulari" <leo@famulari.name> writes:
> Changing the Git package shouldn't affect fixed-output derivations that fetch
> from Git. If they do, that's a recent and very serious bug.
Whoops, you're right, I completely ignored that. I agree with you and
Tobias about pushing to master immediately then!
Best,
--
Josselin Poiret
signature.asc
Description: PGP signature
[bug#61583] [PATCH] gnu: git: Update to 2.39.2 [fixes CVE-2023-22490 & CVE-2023-23946]., Simon Tournier, 2023/03/04