Re: Need help in understanding "by this commit"
Tomas Mraz <[email protected]>
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <[email protected]> |
Please note that openssl-3.3.3 is a git tag indicating the release commit for the 3.3.3 release, not a branch. We do not do branches for patch releases. So yes, fixed in 3.3.3 means fixed in the 3.3.3 release. Tomas Mraz On Mon, 2025-03-03 at 15:34 +0000, Prasad, PCRaghavendra wrote: > Ok Thank you Tomas for the clarification. > > Sure, will check the commit information but inside our team we were > having another understanding on this. > - which was like in 3.3.3 branch which is released on that the commit > is done and so it will be available in next version which is 3.3.4 > > So, our understanding is not correct and if it mentioned as Fixed in > -> 3.3.3 by this commit means it is already fixed and available in > the 3.3.3 version. > > Thanks once again > > > > Internal Use - Confidential > -----Original Message----- > From: Tomas Mraz <[email protected]> > Sent: Monday, March 3, 2025 9:00 PM > To: Prasad, PCRaghavendra <[email protected]>; Viktor > Dukhovni <[email protected]>; openssl-users > <[email protected]>; Wall, Stephen > <[email protected]> > Subject: Re: Need help in understanding "by this commit" > > > [EXTERNAL EMAIL] > > Hello Raghavendra, > > If you click on the links you will see that these commits are > actually present in the 3.3.3 release as the openssl-3.3.3 tag > includes them. > > Kind regards, > > Tomas Mraz, OpenSSL > > > On Mon, 2025-03-03 at 15:22 +0000, Prasad, PCRaghavendra wrote: > > > > > > Hi Team, > > > > Need one help in understanding / need clarification as we are > > having > > some confusion within the team about the fix status. > > > > We are using blackduck to check the vulnerabilities in our > > application > > and here for one of the issues it shows that fix is available and > > fixed in. > > * > > openssl-3.3 branch by this commit which is not yet included in > > any > > release This means that fix is not present in openssl 3.3.x ? why > > it > > is mentioned as not yet included in any release? > > > > And in some cases, it is mentioned as > > * openssl-3.3 branch by this commit. > > > > This also means fix is available in openssl 3.3.x ? or it will be > > available in next release? > > > > > > > > > > Thanks, > > Raghavendra > > > > > > Internal Use - Confidential > > -- > Tomáš Mráz, OpenSSL > -- Tomáš Mráz, OpenSSL -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/68ca79c53de209415a1cd8302c45577d8e18e7f4.camel%40openssl.org.