-
-
Notifications
You must be signed in to change notification settings - Fork 1.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Confirmation of package safty regarding to recent xz vulnerability #8161
Comments
Ah, great callout! This is certainly a great topic to bring up 🙂 Re: the discussion page, I found it impossible for me to monitor as I wasn't receiving proper notifications for it any community members weren't actively contributing to it, so I deactivated it to consolidate in Issues as it was being used as previously Re: 7zip-bin, I don't manage that project so I'm not familiar with how the binaries were provided/committed. When was the For |
From what I read, the compromised
I created a ticket here: develar/app-builder#115 |
This issue is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 30 days. |
This issue was closed because it has been stalled for 30 days with no activity. |
Sorry in advance if this is not the best location to bring up this question and concern. I've noticed that the community isn't very active on Zulip, and there doesn't seem to be a discussion page on GitHub.
With the recent security vulnerability involving the
xz
backdoor (liblzma
,xz
, orlibarchive
), could you confirm if there are any concerns related to this package?I attempted to dig into this package and its dependencies to assess any potential issues but couldn't conclusively confirm.
I observed that it utilizes the
7zip-bin
package, which bundles the7zip
andp7zip
binaries, although it seems to be two years old. Perhaps this isn't an issue?Additionally, I noticed that
app-builder-bin
is used to build various packages, and I see thexz
compression flag being set. However, I presume it relies on the version ofxz
installed on the user's system.From what I could gather, we neither download, bundle or utilize a package that includes the
liblzma
,xz
, orlibarchive
binaries for any specific version of the binaries.If you could provide any additional information or confirm that there are no concerns, that would be greatly appreciated.
The text was updated successfully, but these errors were encountered: