Hi Kamil,
Firstly, apologies for dropping the ball responding to the PR.
On Wed, Nov 27, 2024 at 08:30:52AM +0100, Kamil Dudka wrote:
> On Wednesday, November 27, 2024 12:07:29 AM GMT+1 Michel Lind wrote:
> > On Tue, Nov 26, 2024 at 12:11:27PM -0300, Marco Benatto wrote:
> > > Hello all,
> > >
>
Hello Michel and Neal,
firstly Michel thanks to work on the PR.
Secondly I'm sorry to hear about the false positives. May I have your
help sending some recent examples of such cases off-list please?
I'm interested in investigating that so we can improve such
communication avoiding false positives
On Wed, Nov 27, 2024, 02:32 Kamil Dudka wrote:
> On Wednesday, November 27, 2024 12:07:29 AM GMT+1 Michel Lind wrote:
> > On Tue, Nov 26, 2024 at 12:11:27PM -0300, Marco Benatto wrote:
> > > Hello all,
> > >
> > > We recently noticed there's a couple of PRs opened to fix
> > > vulnerabilities in
On Wednesday, November 27, 2024 12:07:29 AM GMT+1 Michel Lind wrote:
> On Tue, Nov 26, 2024 at 12:11:27PM -0300, Marco Benatto wrote:
> > Hello all,
> >
> > We recently noticed there's a couple of PRs opened to fix
> > vulnerabilities in EPEL8 python-django3 with no response from the
> > maintaine
On Tue, Nov 26, 2024 at 6:08 PM Michel Lind wrote:
>
> On Tue, Nov 26, 2024 at 12:11:27PM -0300, Marco Benatto wrote:
> > Hello all,
> >
> > We recently noticed there's a couple of PRs opened to fix
> > vulnerabilities in EPEL8 python-django3 with no response from the
> > maintainer (CC'ed). This
On Tue, Nov 26, 2024 at 12:11:27PM -0300, Marco Benatto wrote:
> Hello all,
>
> We recently noticed there's a couple of PRs opened to fix
> vulnerabilities in EPEL8 python-django3 with no response from the
> maintainer (CC'ed). This is an important update as it fixes 4
> different CVEs.
>
> https
Hello all,
We recently noticed there's a couple of PRs opened to fix
vulnerabilities in EPEL8 python-django3 with no response from the
maintainer (CC'ed). This is an important update as it fixes 4
different CVEs.
https://src.fedoraproject.org/rpms/python-django3/pull-request/2
I have raised a bu