Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade wasmtime to v24.0.2 to remediate CVE-2024-51745 / GHSA-c2f5-jxjv-2hh8 #3902

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

mamccorm
Copy link

Upgrades wasmtime to v24.0.2, to remediate: GHSA-c2f5-jxjv-2hh8 (CVE-2024-51745).

Referenced previous upgrade contribution for guidance: #3685

@mamccorm mamccorm changed the title Upgrade wasmtime to v24.0.2 to remediate GHSA-c2f5-jxjv-2hh8 Upgrade wasmtime to v24.0.2 to remediate CVE-2024-51745 / GHSA-c2f5-jxjv-2hh8 Dec 30, 2024
@mamccorm mamccorm marked this pull request as ready for review December 30, 2024 16:07
@imsnif
Copy link
Member

imsnif commented Dec 30, 2024

Hi - thanks for this, but Zellij doesn't support windows. I'd rather not upgrade through 2 breaking changes if it can be avoided.

That being said, @WeepingClown13 - does this help you in your packaging efforts somehow? If it's enough of a help I might reconsider.

@WeepingClown13
Copy link

WeepingClown13 commented Dec 31, 2024

@imsnif I am still waiting for wasmtime to be available in Debian for some complicates reasons, and thus my zellij packaging is stuck. The maintainer or rust-wasmtime source package in Debian also might be thinking about bumping the wasmtime version in Debian. Do you think you could wait until I can communicate regarding whether v24 is a reasonable common ground?

@imsnif
Copy link
Member

imsnif commented Dec 31, 2024

Sure thing @WeepingClown13 !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants