Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability roundup 67: libsass-3.5.5: 4 advisories #60842

Closed
1 of 4 tasks
ckauhaus opened this issue May 3, 2019 · 3 comments
Closed
1 of 4 tasks

Vulnerability roundup 67: libsass-3.5.5: 4 advisories #60842

ckauhaus opened this issue May 3, 2019 · 3 comments
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one

Comments

@ckauhaus
Copy link
Contributor

ckauhaus commented May 3, 2019

search, files

Scanned versions: nixos-unstable: dfd8f84; nixos-19.03: cf3e277. May contain false positives.

@ckauhaus
Copy link
Contributor Author

ckauhaus commented May 3, 2019

See also #60840, #52973, #58266, #54804, #53571. libsass did not have a new release when we checked last time.

@hedning hedning added the 1.severity: security Issues which raise a security issue, or PRs that fix one label May 3, 2019
@dsg22
Copy link
Contributor

dsg22 commented Nov 13, 2019

nixos-19.09 has libsass-3.6.1 which is not listed as vulnerable in the CVE.

nixos-19.03 still has libsass-3.5.5, but I'm not sure what the support policy is here. Do we keep issues open if they only affect the last release? This would be helpful to know as I'm currently going through the CVE roundup list to try to update the case status, and a lot of them have been fixed in unstable and 19.09.

Upstream has indicated that no further releases for 3.5 series will be made, so we can consider it EOL. If we need to support 19.03 still, libsass would have to be updated to 3.6.x.

@ckauhaus
Copy link
Contributor Author

I don't think we should upgrade libsass to 3.6. on 19.03.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one
Projects
None yet
Development

No branches or pull requests

3 participants