saltstack / saltstack/salt

[BUG] A non-cve affected version of m2crypto is not available on centos or fedora

Open
#59,253 2 comments 0 reactions 3 assignees View on GitHub

@smokeytheblair is already working on this.

Since Jul 13, 2021.

bug Packaging pending-discussion Upstream-Bug
Dominant language
Python
Stars
15.7k
Forks
5.6k
Avg merge
2d 44m
Merged PRs (30d)
80

Description

https://saltstackcommunity.slack.com/archives/C7K04SEJC/p1609979124164800

how critical is this library to salt-stack https://bugzilla.redhat.com/show_activity.cgi?id=1889823
it appears there is no update on. this - open issue

It appears that the latest version of m2crypto in fedora and centos are vulnerable to a cve, it doesn't look like they've upgraded versions in about a year. Do we need to do anything? Should we move away from m2crypto? Should we see if we can help maintain the packaging of m2crypto on centos/fedora ourselves?

It often messes with peoples dependencies to provide newer versions of packages ourselves than what is available in epel so I'm not sure we can just patch it ourselves and provide it via our repos with a newer version number.

We should discuss what the right thing to do here is.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.