Repository navigation
Upgrade bundled expat to 2.5.0 #98739
Copy link
Copy link
Closed
Labels
3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of liferelease-blockertype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or errortype-securityA security issueA security issue
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Oct 26, 2022 - added a commit that references this issue
on Oct 27, 2022 - added 5 commits that reference this issue
on Oct 27, 2022 Thanks for making the PR! Release branch merges will happen but are pending figuring out why the CLA bot is mistakenly not accepting those on our end.
Reacted by Shaun Walbridge- added3.9 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.7 (EOL)end of lifeend of life
on Oct 27, 2022 I believe all the backports have been merged and thus we can close this issue.
- Repository owner moved this from In Progress to Done in Release and Deferred blockers 🚫
on Dec 5, 2022
Metadata
Metadata
Labels
3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of liferelease-blockertype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or errortype-securityA security issueA security issue
Projects
- StatusShow more project fieldsDone
Upgrade the bundled libexpat version to 2.5.0 which includes a fix for CVE-2022-43680. I haven't evaluated whether CPython is directly impacted by this CVE, but can confirm that it is detected by binary analysis tools such as Black Duck.
Related libexpat changelog includes additional fixes and details.