-
Notifications
You must be signed in to change notification settings - Fork 2.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
3.2.7 backports 1 #36531
3.2.7 backports 1 #36531
Conversation
Fix CVE-2023-43642 (https://access.redhat.com/security/cve/CVE-2023-43642) (cherry picked from commit c2fa034)
We shouldn't have any new lines between the header and the title. (cherry picked from commit 3b18e24)
Contains the fix for CVE-2023-44487. (cherry picked from commit e9a563f)
(cherry picked from commit b3cd2bc)
Bumps org.apache.avro:avro from 1.11.2 to 1.11.3. --- updated-dependencies: - dependency-name: org.apache.avro:avro dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]> (cherry picked from commit 1ea628a)
Fixes: quarkusio#35774 (cherry picked from commit c3479a0)
🙈 The PR is closed and the preview is expired. |
I agree with the payload, thanks @gsmet. For |
Doesn't this PR need to be set to the |
3.2.7.Final ? |
@rsvoboda Ah yes, this was created before the |
Please don't merge, I will merge it myself.
As discussed with @maxandersen , here is a very conservative attempt at preparing 3.2.7, which will be a security release (most bugfixes will be included in 3.2.8).
I included everything that was under CVE + a very small/low risk bugfix that a user was complaining about (#36498 (comment)).
@rsvoboda @aloubyansky let me know what you think.