Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[24.05] authentik: flag with knownVulnerabilities #361884

Merged
merged 1 commit into from
Dec 5, 2024

Conversation

LeSuisse
Copy link
Contributor

@LeSuisse LeSuisse commented Dec 4, 2024

Backport of #361567

The bump to 2024.10.x is currently stalled in NixOS#345940.

The fix for CVE-2024-52289 involves a backward incompatible
API and DB change so it is also not great for a backport even
if we cherry-picks the security fixes.

Given no NixOS module is available in nixpkgs marking the package
with `knownVulnerabilities` should have a limited impact.

(cherry picked from commit 384f6f5)
@LeSuisse LeSuisse added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Dec 4, 2024
@NickCao NickCao merged commit 6f85d8a into NixOS:release-24.05 Dec 5, 2024
10 of 11 checks passed
@LeSuisse LeSuisse deleted the authentik-known-vuln-24.05 branch December 5, 2024 14:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants