macvim-dev / macvim-dev/macvim

Reconcile version #'ing system

オープン
#1,582 コメント 16 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

主要言語
Vim Script
スター
7.9k
フォーク
691
PR マージ指標
30日以内にマージされた PR はありません

説明

Hello, my company uses an endpoint software monitoring system to ensure apps are updated to avoid vulnerabilities.

This version:

Image

Is being reported as suffering from:
https://www.cve.org/CVERecord?id=CVE-2023-41036 and
https://nvd.nist.gov/vuln/detail/CVE-2023-41036
(Both are the same.)

I believe the version reported by MacOS:

Image

Leads the endpoint monitoring software to see this as behind release 178.

I understand that the versioning may be due to “stuff”. However, this legacy practice brings extra unwanted attention. If efforts can be made to improve this, I’m sure others will be appreciative as well.

Thank you,
David Halonen

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

ファイル、テスト、エントリーポイントは指定されていません。まず、macOS が報告する MacVim のバージョンをリリース 178 と比較し、プロジェクトのバージョンがどのように定義され、公開されているかを追跡してください。完了の条件は、エンドポイント監視システムが現行リリースを CVE-2023-41036 の影響を受けるものとして識別しなくなることです。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
macos, vim
領域
desktop, release
issue の種類
バグ
難易度
5/5
見積もり時間
1週間以上
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。