Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update dnspython required versions to allow latest 2.6.1 #94

Closed
wants to merge 1 commit into from

Conversation

mjperrone
Copy link

This was similarly done in the past by @nmariz in this commit.

I chose to use < instead of <= to allow more patch versions to be picked up in the future. I think using < 3.0.0 would probably be better to allow more minor versions to be picked up.

The reason I am motivated to make this PR is because version 2.6.1 fixes CVE-2023-29483.

@mysql-oca-bot
Copy link

Hi, thank you for submitting this pull request. In order to consider your code we need you to sign the Oracle Contribution Agreement (OCA). Please review the details and follow the instructions at https://oca.opensource.oracle.com/
Please make sure to include your MySQL bug system user (email) in the returned form.
Thanks

@mjperrone
Copy link
Author

Hi, thank you for submitting this pull request. In order to consider your code we need you to sign the Oracle Contribution Agreement (OCA). Please review the details and follow the instructions at https://oca.opensource.oracle.com/ Please make sure to include your MySQL bug system user (email) in the returned form. Thanks

working on it.

@mjperrone
Copy link
Author

We submitted it. It is now "Under Review"

@mjperrone
Copy link
Author

@oscpache would you be able to take a look at this PR?

@oscpache
Copy link
Contributor

Hello @mjperrone,

Thanks for bringing this to our attention. We have considered CVE-2023-29483 and we're expecting to make the version upgrade moving forward.

Certainly, we'll use a version range where the vulnerability has been mitigated.

@mjperrone
Copy link
Author

mjperrone commented Apr 18, 2024

Hello @mjperrone,

Thanks for bringing this to our attention. We have considered CVE-2023-29483 and we're expecting to make the version upgrade moving forward.

Certainly, we'll use a version range where the vulnerability has been mitigated.

Great news Oscar. I don't particularly care if you use this PR or create a new one. Thanks for the update.

@mysql-oca-bot
Copy link

Hi, thank you for your contribution. Please confirm this code is submitted under the terms of the OCA (Oracle's Contribution Agreement) you have previously signed by cutting and pasting the following text as a comment:
"I confirm the code being submitted is offered under the terms of the OCA, and that I am authorized to contribute it."
Thanks

@mjperrone
Copy link
Author

I confirm the code being submitted is offered under the terms of the OCA, and that I am authorized to contribute it.

@mysql-oca-bot
Copy link

Hi, thank you for your contribution. Your code has been assigned to an internal queue. Please follow
bug http://bugs.mysql.com/bug.php?id=114985 for updates.
Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
3 participants