Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

V3 feature/webkit2 40 41 #3467

Open
wants to merge 3 commits into
base: v3-alpha
Choose a base branch
from
Open

V3 feature/webkit2 40 41 #3467

wants to merge 3 commits into from

Conversation

tmclane
Copy link
Member

@tmclane tmclane commented May 8, 2024

V3 update to support webkit2 4.0 and 4.1.
The default in this case is 4.1.

Tags to build are identical to the ones used in v2 AFAIK.

webkit2_40 == 4.0 and soup2
webkit2_41 == 4.1 and soup3

@tmclane tmclane requested a review from leaanthony May 8, 2024 20:12
Copy link

semgrep-app bot commented May 8, 2024

Semgrep found 2 ssc-46663897-ab0c-04dc-126b-07fe2ce42fb2 findings:

  • v3/internal/assetserver/webview/webkit2.go

Risk: Affected versions of golang.org/x/net, golang.org/x/net/http2, and net/http are vulnerable to Uncontrolled Resource Consumption. An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames.

Fix: Upgrade this library to at least version 0.23.0 at wails/v3/go.mod:87.

Reference(s): GHSA-4v7x-pqxf-cx7m, CVE-2023-45288

Ignore this finding from ssc-46663897-ab0c-04dc-126b-07fe2ce42fb2.

- default to webkit2gtk-4.1 if not overridden to be 4.0
Copy link

cloudflare-pages bot commented May 8, 2024

Deploying wails with  Cloudflare Pages  Cloudflare Pages

Latest commit: 0b4c98b
Status: ✅  Deploy successful!
Preview URL: https://8be34cfb.wails.pages.dev
Branch Preview URL: https://v3-feature-webkit2-40-41.wails.pages.dev

View logs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant