Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability roundup 51: openjpeg-2.3.0 #49788

Closed
1 task
ckauhaus opened this issue Nov 5, 2018 · 4 comments
Closed
1 task

Vulnerability roundup 51: openjpeg-2.3.0 #49788

ckauhaus opened this issue Nov 5, 2018 · 4 comments
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one 2.status: wait-for-upstream Waiting for upstream fix (or their other action).

Comments

@ckauhaus
Copy link
Contributor

ckauhaus commented Nov 5, 2018

openjpeg-2.3.0: 1 advisory

search, files

@andir andir added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Nov 5, 2018
@nlewo
Copy link
Member

nlewo commented Nov 6, 2018

There is not a fix yet.
Could we tag it with a tag such as need: upstream fix ?

@ckauhaus
Copy link
Contributor Author

ckauhaus commented Nov 6, 2018

I would appreciate this, but I'm unfortunately unable to set labels here on GH. Perhaps it's time for someone™ to grant me necessary permissions...

@7c6f434c 7c6f434c added 9.needs: upstream fix This PR needs upstream to change something 2.status: wait-for-upstream Waiting for upstream fix (or their other action). and removed 9.needs: upstream fix This PR needs upstream to change something labels Nov 6, 2018
@7c6f434c
Copy link
Member

7c6f434c commented Nov 6, 2018

@domenkozar @rbvermaa I think it is a good idea to give @ckauhaus write access

On a more local note, I created «9.needs: upstream fix», but I guess in this case we are not going to try and influence the upstream, so «2.status: wait-for-upstream» fits better. It feels like «9.needs: upstream fix» fits when we actively negotiate with upstream or prepare a patch to propose or something like that.

@ckauhaus
Copy link
Contributor Author

obsolete: 19.03 ships openjpeg-2.3.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one 2.status: wait-for-upstream Waiting for upstream fix (or their other action).
Projects
None yet
Development

No branches or pull requests

4 participants