Re: [LFS Trac] #5685: expat-2.7.1

"LFS Trac" ([email protected] via lfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#5685: expat-2.7.1
-------------------------+-----------------------
 Reporter:  Bruce Dubbs  |       Owner:  lfs-book
     Type:  enhancement  |      Status:  new
 Priority:  normal       |   Milestone:  12.4
Component:  Book         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-----------------------
Comment (by Bruce Dubbs):

 Release 2.7.1 Thu March 27 2025

 Bug fixes:
 - Restore event pointer behavior from Expat 2.6.4
   (that the fix to CVE-2024-8176 changed in 2.7.0);

   Affected API functions are:
   - XML_GetCurrentByteCount
   - XML_GetCurrentByteIndex
   - XML_GetCurrentColumnNumber
   - XML_GetCurrentLineNumber
   - XML_GetInputContext

 Other changes:
    - Autotools: Integrate files "fuzz/xml_lpm_fuzzer.{cpp,proto}"
      with Automake that were missing from 2.7.0 release tarballs
    - Fix printf format specifiers for 32bit Emscripten
    - docs: Promote OpenSSF Best Practices self-certification
    - tests/benchmark: Resolve mistaken double close
    - Address compiler warnings
    - Version info bumped from 11:1:10 (libexpat*.so.1.10.1)
      to 11:2:10 (libexpat*.so.1.10.2); see https://verbump.de/
      for what these numbers do

 Infrastructure:
 - CI: Start running Perl XML::Parser integration tests
 - CI: Enforce Clang Static Analyzer clean code
 - CI: Re-enable warning clang-analyzer-valist.Uninitialized
   for clang-tidy
 - CI: Cover compilation with musl
 - CI: Cover compilation with 32bit Emscripten
 - CI: Protect against fuzzer files missing from future
   release archives
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5685#comment:1>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.