Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

upgrade version of perl to evade CVE-2023-47100 #73

Merged
merged 1 commit into from
Dec 6, 2024

Conversation

yetanotheralex
Copy link
Contributor

Current and the latest version of rules_perl are using Perl version 5.36.0.

This version is affected by CVE-2023-47100: from (including) 5.30.0 up to (excluding) 5.38.2

This PR upgrades the dependency to use a version of Perl without CVE-2023-47100 vulnerability on Linux and Mac. I do not have the ability to validate windows changes so did not upgrade the perl version on windows. I did test that genhtml was working correctly on linux and mac.

@skeletonkey skeletonkey merged commit ed86ba3 into bazel-contrib:main Dec 6, 2024
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants