2026-09-01 13:17:12 !107620 !107621 !107622 2026-09-01 13:18:48 there are a couple of known regressions, that I link to in the first of those three, but perhaps better to upgrade anyway? 2026-09-01 13:19:06 I already got it in for edge and 3.24-stable 2026-09-01 13:46:54 just my opinion: 33 CVEs, yeah, worth it 2026-09-01 15:33:31 In rsync...? 2026-09-01 20:08:37 andar1an[m]: yes. most of them in rsyncd but nonetheless 2026-09-01 20:12:58 Not disagreeing. That seems highly relevant to apk repos at the very least. 2026-09-01 21:45:58 sometimes the cves are a no-op. they're not really a risk or they don't apply to us, et al 2026-09-01 22:55:20 Yes, but 33 probability is stacked haha 2026-09-01 22:56:18 Is that a typical or fairly common now? 2026-09-01 22:56:30 s/atypical 2026-09-01 23:06:44 yeah 2026-09-01 23:07:02 I'm getting the backports in 2026-09-02 14:22:54 #18425 2026-09-02 14:23:44 but I think we should also upgrade or backport patches for curl before cutting patch releases 2026-09-02 19:54:58 what else do we need in for new stable releases? 2026-09-03 21:30:18 maybe we don't need to wait for anything for 3.24.2 2026-09-03 21:30:37 I think there are additional things that could be patched, but that could go into a 3.24.3 2026-09-05 01:33:11 https://gitlab.gnome.org/GNOME/libxml2/-/blob/v2.15.4/NEWS 2026-09-05 01:33:54 several releases of security fixes (some with CVE numbers) since the version we're at 2026-09-05 01:35:04 I know that it's not an easy upgrade (will require rebuilds etc) and backports to stable branches may be even trickier 2026-09-05 13:21:07 https://www.openwall.com/lists/oss-security/2026/09/05/4 2026-09-05 13:21:18 (more on libxml2) 2026-09-05 13:31:46 is @danigm the libxml2 maintainer now? 2026-09-05 13:32:52 (i haven't been keeping track but i do remember the author forked into gpl3 last year because he was fed up)