Backport CVE-2024-43368 to trix v1 and update advisory
Open
- Dominant language
- JavaScript
- Stars
- 20k
- Forks
- 1.1k
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 13
Description
Hello,
is there by any chance the possibility to backport the fix for [CVE-2024-43368](https://github.com/advisories/GHSA-qm2q-9f3q-2vcv) to v1 and release a new version?
Follow up:
- #1150
- #1153
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reading the CVE-2024-43368 advisory and the follow-up issues #1150 and #1153 to identify the existing fix and the v1 backport scope. Then locate the v1 release and advisory metadata in the repository. Done means the fix is backported, the advisory is updated, and a new v1 version is released.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- release, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100