2022-12-16 03:06:18 the current long-term branch of mbedtls is 2.28, currently at 2.28.2 2022-12-16 03:06:50 however, alpine 3.14-stable and 3.15-stable are still at the last release of the previous long-term branch 2022-12-16 03:07:43 (just mentioning here too, so it doesn't get lost in the other channel) 2022-12-26 17:58:09 Multiple vulnerabilities in WebKitGTK: https://www.openwall.com/lists/oss-security/2022/12/26/1 2022-12-26 18:02:22 isn't WebKitGTK the project that should never be used or something? 2022-12-26 18:03:37 other way around 2022-12-26 18:03:59 you're thinking of chromium /ducks 2022-12-26 18:04:06 (but what you're actually thinking of is webkitqt) 2022-12-26 18:04:37 ((it was dropped in favor of qtwebengine)) 2022-12-26 20:42:42 (thanks) 2022-12-27 11:25:22 !42647 !42648 2022-12-27 11:25:49 for 3.16-stable and 3.17-stable 2022-12-27 16:03:51 Max version is wrong here https://security.alpinelinux.org/vuln/CVE-2022-42919 2022-12-27 16:04:12 should be <3.10.9 2022-12-27 16:04:31 fixed in 3.10.9: https://docs.python.org/3.10/whatsnew/changelog.html#python-3-10-9-final 2022-12-27 16:04:42 not sure if we care enough to do anything about it 2022-12-27 16:05:03 The data comes from NVD 2022-12-27 16:05:16 Not sure if it will be fixed there eventually 2022-12-27 16:31:20 seeing an actual correct version range there is a unicorn 2022-12-27 16:31:35 i think i've only seen it for curl lol 2022-12-27 16:34:38 (the vast majority of these do with Intel CET becoming more and more available, any plans to make use of it in Alpine? 2022-12-27 23:08:48 Ubuntu has it enabled since 20.04 iirc 2022-12-31 04:35:31 ignore ping please. sry