Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(weaver): address vulnerability CVE-2020-28477 and many others #2362

Merged
merged 1 commit into from
Apr 6, 2023

Conversation

Copy link
Contributor

@petermetz petermetz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sandeepnRES

  1. Please squash the commits and
  2. Make the commit subject unique if possible.
    In situations when you are fixing multiple (potentially a long list of) vulnerabilities and there's no way all the CVEs fit into the subject with the 72 character limit, then I recommend identifying the most severe one(s) as a best effort (it will still make the commit subject unique and that's what I'm after).
  3. Also recommend to identifying the component where the fixes are being applied in the commit subject, something like: fix(weaver): address vulnerability CVE-2021-23436 and many others

As always, if you need any help with the git mechanics, just let me know I'm happy to give advice or just get it done for you if that helps.

@sandeepnRES sandeepnRES changed the title fix: multiple vulnerabilities in weaver code fix(weaver): address vulnerability CVE-2020-28477 and many others Apr 4, 2023
Copy link
Contributor

@petermetz petermetz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sandeepnRES Thank you, LGTM

@sandeepnRES sandeepnRES merged commit 5fcfea3 into hyperledger-cacti:main Apr 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants