From: Peter Korsgaard <peter@korsgaard.com>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH RESEND] package/icu: bump to version 68-1
Date: Mon, 23 Nov 2020 13:20:20 +0100 [thread overview]
Message-ID: <87y2istgcb.fsf@dell.be.48ers.dk> (raw)
In-Reply-To: <20201123100751.4095539-1-heiko@sntech.de> (Heiko Stuebner's message of "Mon, 23 Nov 2020 11:07:51 +0100")
>>>>> "Heiko" == Heiko Stuebner <heiko@sntech.de> writes:
> From: Heiko Stuebner <heiko.stuebner@theobroma-systems.com>
> This includes the fix [0] for CVE-2020-10531 .
> [0] https://github.com/unicode-org/icu/commit/b7d08bc04a4296982fcef8b6b8a354a9e4e7afca
> Signed-off-by: Heiko Stuebner <heiko.stuebner@theobroma-systems.com>
> ---
> I'm not sure if I did something wrong in the initial submission,
> but so far got no response at all, so am including some more
> people who recently committed changes to icu.
> As this fixes a CVE, I guess this might need some sort of priority.
There is quite some pending patches. It would be good to explicitly mark
it as a security fix, E.G. 'package/icu: security bump to version 68-1',
to make sure it isn't missed for master, as package bumps otherwise now
only go to next as we are busy getting 2020.11 stablized and released.
How much have you tested this? New icu releases unfortunately have a
tendency to cause various breakage? Would it be an option to backport
this fix to the 67-1 release for 2020.11 / 2020.02 and only bump to 68-1
for next?
--
Bye, Peter Korsgaard
next prev parent reply other threads:[~2020-11-23 12:20 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-11-23 10:07 [Buildroot] [PATCH RESEND] package/icu: bump to version 68-1 Heiko Stuebner
2020-11-23 12:20 ` Peter Korsgaard [this message]
2020-11-23 14:25 ` Heiko Stübner
2020-11-23 15:11 ` Peter Korsgaard
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87y2istgcb.fsf@dell.be.48ers.dk \
--to=peter@korsgaard.com \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox