Skip to content

Commit

Permalink
[XZ_jll] Yank compromised versions (#103876)
Browse files Browse the repository at this point in the history
It was reported builds of XZ v5.6.0 and v5.6.1 from release tarballs were compromised due to a backdoor: https://www.openwall.com/lists/oss-security/2024/03/29/4.
  • Loading branch information
giordano authored Mar 29, 2024
1 parent a72cb15 commit ae34929
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions jll/X/XZ_jll/Versions.toml
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,8 @@ git-tree-sha1 = "ac88fb95ae6447c8dda6a5503f3bafd496ae8632"

["5.6.0+0"]
git-tree-sha1 = "37195dcb94a5970397ad425b95a9a26d0befce3a"
yanked = true

["5.6.1+0"]
git-tree-sha1 = "31c421e5516a6248dfb22c194519e37effbf1f30"
yanked = true

0 comments on commit ae34929

Please sign in to comment.