-
Notifications
You must be signed in to change notification settings - Fork 48
Update CVE patches to fix CVE issues #661
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update CVE patches to fix CVE issues #661
Conversation
aa721ee to
8c6dd71
Compare
b65a6d2 to
cc62f82
Compare
|
upgrading from 1.25.1 to 1.25.5 is fine, if there is cve reported no need to change go version in caddy and rpc go and enable cgo |
cc62f82 to
d1d168d
Compare
Thank you for the review. I have reverted the changes. |
|
LGTM |
Hi @andy-vm, Thank you for review. For Jenkins Build please see On Demand Developer Build#1526. |
|
@andy-vm @liulis-sg @polmoorx kindly revisit the changes |
|
@polmoorx please double check the CVE test result and share CVE scan url |
As discussed, we rebuilt the spec locally and did not observe any issues with the current patch. |
d1d168d to
d3a804e
Compare
aaroncyew
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
+1, CVE patch and srpm build has been reviewed.
srpm build logs is attached to JIRA ticket for this fix.
d3a804e to
29186ca
Compare
- Include fix for CVE-2025-61727 and CVE-2025-61729. - Updated caddy.spec file to update release, bump version, and add changelog entries. Signed-off-by: Polmoorx Shiva Kumar <polmoorx.shiva.kumar@intel.com>
29186ca to
9b1fb0a
Compare
andy-vm
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM

Merge Checklist
All boxes should be checked before merging the PR
Description
bump version, and add changelog entries.
Any Newly Introduced Dependencies
NO
How Has This Been Tested?
Manually tested.