Skip to content

Conversation

@Kami
Copy link
Member

@Kami Kami commented Jan 27, 2019

This pull request updates python-gnugpg dependency we use to the latest version.

Previous version contains a security vulnerability - https://blog.hackeriet.no/cve-2019-6690-python-gnupg-vulnerability/, https://mail.python.org/pipermail/python-announce-list/2019-January/012154.html.

NOTE: This security vulnerability itself doesn't affect us because we only this library in an isolated scenario (encrypting debug tarball without using a passphrase), but it's still a good idea to upgrade it.

Thanks to @jfunction for reporting this.

(https://blog.hackeriet.no/cve-2019-6690-python-gnupg-vulnerability/).

NOTE: This security vulnerability doesn't affect us because we only this
library in an isolated scenario (encrypting debug tarball without using
a passphrase).
@Kami Kami added this to the 2.10.2 milestone Jan 27, 2019
@Kami Kami requested a review from blag January 29, 2019 10:05
@Kami Kami merged commit 21c01c7 into master Jan 30, 2019
@Kami Kami deleted the upgrade_gnupg_dep branch January 30, 2019 09:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants