Skip to content

Tag v0.7.0 and publish the three GHSA advisories #374

Description

@rainmanjam

The release is ready; both steps are public and irreversible, so they are deliberately a human's call.

Order matters. All three advisories carry patched_versions: 0.7.0. Publishing before the tag exists tells every downstream scanner that >= 0.7.0 is remediated while giving operators nothing to install.

  1. git tag -a v0.7.0 — annotated and unsigned, matching v0.4.0–v0.6.0.
  2. Publish GHSA-7jqx-76vq-hvfc (Medium, 5.5), GHSA-wv59-5xvx-xcj8 (low), GHSA-jqc3-g54q-mh8m (low).
  3. Their prose currently says "on main and not yet in a tagged release" — that becomes "fixed in 0.7.0" as part of publishing.

State at time of filing: main green, 166 commits since v0.6.0, CHANGELOG [Unreleased] empty with 90 entries in [0.7.0], OVH acceptance 12/12 (269 checks, 0 failures) on the shipping build.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions