[OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
14 messages Options
Reply | Threaded
Open this post in threaded view
|

[OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
 

You can view, comment on, or merge this pull request online at:

  https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386

Commit Summary

  • third-party: Stop building/using vulnerable software

File Changes

Patch Links:


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/OpenSmalltalk/opensmalltalk-vm","title":"OpenSmalltalk/opensmalltalk-vm","subtitle":"GitHub repository","main_image_url":"https://github.githubassets.com/images/email/message_cards/header.png","avatar_image_url":"https://github.githubassets.com/images/email/message_cards/avatar.png","action":{"name":"Open in GitHub","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm"}},"updates":{"snippets":[{"icon":"DESCRIPTION","message":"third-party: Stop building/using vulnerable software (#386)"}],"action":{"name":"View Pull Request","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386"}}}</script> <script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
 

I have difficulties building the VM so this is not tested locally. We need to have a look at iceberg before merging it.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/OpenSmalltalk/opensmalltalk-vm","title":"OpenSmalltalk/opensmalltalk-vm","subtitle":"GitHub repository","main_image_url":"https://github.githubassets.com/images/email/message_cards/header.png","avatar_image_url":"https://github.githubassets.com/images/email/message_cards/avatar.png","action":{"name":"Open in GitHub","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm"}},"updates":{"snippets":[{"icon":"PERSON","message":"@zecke in #386: I have difficulties building the VM so this is not tested locally. We need to have a look at iceberg before merging it."}],"action":{"name":"View Pull Request","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-477472243"}}}</script> <script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-477472243", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-477472243", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
In reply to this post by David T Lewis
 

@zecke pushed 1 commit.

  • 68c1865 Make it use the OpenSSL we built, let it find libssh2


You are receiving this because you are subscribed to this thread.
View it on GitHub or mute the thread.

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/OpenSmalltalk/opensmalltalk-vm","title":"OpenSmalltalk/opensmalltalk-vm","subtitle":"GitHub repository","main_image_url":"https://github.githubassets.com/images/email/message_cards/header.png","avatar_image_url":"https://github.githubassets.com/images/email/message_cards/avatar.png","action":{"name":"Open in GitHub","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm"}},"updates":{"snippets":[{"icon":"PERSON","message":"@zecke pushed 1 commit in #386"}],"action":{"name":"View Pull Request","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386/files/9db3e055ba50f3cd3773de987cd7b146455fb420..68c1865a87d7f4ab750bda1bc98d3588cd61ff74"}}}</script> <script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386/files/9db3e055ba50f3cd3773de987cd7b146455fb420..68c1865a87d7f4ab750bda1bc98d3588cd61ff74", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386/files/9db3e055ba50f3cd3773de987cd7b146455fb420..68c1865a87d7f4ab750bda1bc98d3588cd61ff74", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
In reply to this post by David T Lewis
 

@zecke pushed 1 commit.

  • 798af3e update n code clones and deal with their speciality


You are receiving this because you are subscribed to this thread.
View it on GitHub or mute the thread.

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/OpenSmalltalk/opensmalltalk-vm","title":"OpenSmalltalk/opensmalltalk-vm","subtitle":"GitHub repository","main_image_url":"https://github.githubassets.com/images/email/message_cards/header.png","avatar_image_url":"https://github.githubassets.com/images/email/message_cards/avatar.png","action":{"name":"Open in GitHub","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm"}},"updates":{"snippets":[{"icon":"PERSON","message":"@zecke pushed 1 commit in #386"}],"action":{"name":"View Pull Request","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386/files/68c1865a87d7f4ab750bda1bc98d3588cd61ff74..798af3eeb30c988051c450116f064eec40f46049"}}}</script> <script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386/files/68c1865a87d7f4ab750bda1bc98d3588cd61ff74..798af3eeb30c988051c450116f064eec40f46049", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386/files/68c1865a87d7f4ab750bda1bc98d3588cd61ff74..798af3eeb30c988051c450116f064eec40f46049", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
In reply to this post by David T Lewis
 

@zecke pushed 1 commit.

  • 4e9b6c6 WIP.. move libpng16 forward for real..


You are receiving this because you are subscribed to this thread.
View it on GitHub or mute the thread.

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/OpenSmalltalk/opensmalltalk-vm","title":"OpenSmalltalk/opensmalltalk-vm","subtitle":"GitHub repository","main_image_url":"https://github.githubassets.com/images/email/message_cards/header.png","avatar_image_url":"https://github.githubassets.com/images/email/message_cards/avatar.png","action":{"name":"Open in GitHub","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm"}},"updates":{"snippets":[{"icon":"PERSON","message":"@zecke pushed 1 commit in #386"}],"action":{"name":"View Pull Request","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386/files/4bc3d72ffe6adf42695eeae1acc7f2ea16bd72ed..4e9b6c6de51e16d7e7c65b36d7438e373cd6f039"}}}</script> <script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386/files/4bc3d72ffe6adf42695eeae1acc7f2ea16bd72ed..4e9b6c6de51e16d7e7c65b36d7438e373cd6f039", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386/files/4bc3d72ffe6adf42695eeae1acc7f2ea16bd72ed..4e9b6c6de51e16d7e7c65b36d7438e373cd6f039", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
In reply to this post by David T Lewis
 

@zecke pushed 1 commit.


You are receiving this because you are subscribed to this thread.
View it on GitHub or mute the thread.

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/OpenSmalltalk/opensmalltalk-vm","title":"OpenSmalltalk/opensmalltalk-vm","subtitle":"GitHub repository","main_image_url":"https://github.githubassets.com/images/email/message_cards/header.png","avatar_image_url":"https://github.githubassets.com/images/email/message_cards/avatar.png","action":{"name":"Open in GitHub","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm"}},"updates":{"snippets":[{"icon":"PERSON","message":"@zecke pushed 1 commit in #386"}],"action":{"name":"View Pull Request","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386/files/4e9b6c6de51e16d7e7c65b36d7438e373cd6f039..929b31da40e603281ab11e1df1948794cf330936"}}}</script> <script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386/files/4e9b6c6de51e16d7e7c65b36d7438e373cd6f039..929b31da40e603281ab11e1df1948794cf330936", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386/files/4e9b6c6de51e16d7e7c65b36d7438e373cd6f039..929b31da40e603281ab11e1df1948794cf330936", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
In reply to this post by David T Lewis
 

Hi Holger,

I have difficulties building the VM so this is not tested locally. We need to have a look at iceberg before merging it.

I've built this on Ubuntu 16.04 and haven't seen any issues with iceberg (or anything else).

HTH,
Alistair


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/OpenSmalltalk/opensmalltalk-vm","title":"OpenSmalltalk/opensmalltalk-vm","subtitle":"GitHub repository","main_image_url":"https://github.githubassets.com/images/email/message_cards/header.png","avatar_image_url":"https://github.githubassets.com/images/email/message_cards/avatar.png","action":{"name":"Open in GitHub","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm"}},"updates":{"snippets":[{"icon":"PERSON","message":"@akgrant43 in #386: Hi Holger,\r\n\r\n\u003e I have difficulties building the VM so this is not tested locally. We need to have a look at iceberg before merging it.\r\n\r\nI've built this on Ubuntu 16.04 and haven't seen any issues with iceberg (or anything else).\r\n\r\nHTH,\r\nAlistair"}],"action":{"name":"View Pull Request","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-478351308"}}}</script> <script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-478351308", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-478351308", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
In reply to this post by David T Lewis
 

I'm supporting this PR from the sidelines! :)

I've downloaded the release version of Pharo 7.0 and noticed there were linker resolution errors on my CentOS: libcurl-gnutls.so does not exist on Fedora/CentOS, only the openSSL flavor.

Plus the linker wasn't able to resolve libssl.so.1.0.0 and libcrypto.so.1.0.0.

Both are fixed by this PR (I built it in a Xenial docker container), and the third parties are brought up to date, so really, two birds with one stone.

It seems Travis only has issues building the macOS versions.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/OpenSmalltalk/opensmalltalk-vm","title":"OpenSmalltalk/opensmalltalk-vm","subtitle":"GitHub repository","main_image_url":"https://github.githubassets.com/images/email/message_cards/header.png","avatar_image_url":"https://github.githubassets.com/images/email/message_cards/avatar.png","action":{"name":"Open in GitHub","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm"}},"updates":{"snippets":[{"icon":"PERSON","message":"@niquis7 in #386: I'm supporting this PR from the sidelines! :)\r\n\r\nI've downloaded the release version of Pharo 7.0 and noticed there were linker resolution errors on my CentOS: `libcurl-gnutls.so` does not exist on Fedora/CentOS, only the openSSL flavor.\r\n\r\nPlus the linker wasn't able to resolve `libssl.so.1.0.0` and `libcrypto.so.1.0.0`.\r\n\r\nBoth are fixed by this PR (I built it in a Xenial docker container), and the third parties are brought up to date, so really, two birds with one stone.\r\n\r\nIt seems Travis only has issues building the macOS versions."}],"action":{"name":"View Pull Request","url":"https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-486225909"}}}</script> <script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-486225909", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-486225909", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
In reply to this post by David T Lewis
 

Hi Holger, I heartily agree with you that this is an important issue. In talking with @ronsaldo this morning he wrote

"The painful change is building all of these third party dependencies with cmake. And cmake is not suitable at all for doing this. I would like to remove these third party dependencies on the near future, but for doing this we need a server for holding them."

and I replied

I think the best thing to do is to
a) have a directory in each build.foo* which includes the pre-built support libraries
b) have a separate repository to build the support libraries
c) a workflow where when a new version of a library is needed one checks out repository b) and builds, and then replaces the libraries in a) and commits. That is what I'm doing with Terf. See terf-cogvm/platforms/Cross/third-party/lib.macos32x86 & lib.macos64x64.

And he agrees.

So was soon as possible we should split the repository to create e.g. opensmalltalk-third-party and stop rebuilding third-party software unnecessarily. We do have to decide where the products live on opensmalltalk-vm. I propose that they live in build.*/third-party/lib


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

<script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386?email_source=notifications\u0026email_token=AIJPEW7JBHTB3NE452CMWPTP4O4KLA5CNFSM4HB5W2J2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGODYUQHII#issuecomment-506004385", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386?email_source=notifications\u0026email_token=AIJPEW7JBHTB3NE452CMWPTP4O4KLA5CNFSM4HB5W2J2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGODYUQHII#issuecomment-506004385", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
In reply to this post by David T Lewis
 

Sounds reasonable. I'm not sure how big those libraries would be, but if we do decide to commit them to a Git repository alongside instructions to generate them, we could include them as Git submodules. This would allow us to control which version of which library comes with which version of the main repository.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

<script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386?email_source=notifications\u0026email_token=AIJPEW5BP6U7RGLYWY45A7DP4PCN5A5CNFSM4HB5W2J2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGODYUULGY#issuecomment-506021275", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386?email_source=notifications\u0026email_token=AIJPEW5BP6U7RGLYWY45A7DP4PCN5A5CNFSM4HB5W2J2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGODYUULGY#issuecomment-506021275", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
In reply to this post by David T Lewis
 
On Thu, 27 Jun 2019 at 03:01, Eliot Miranda <[hidden email]>
wrote:

> @ronsaldo <https://github.com/ronsaldo> this morning wrote:
>
> "need a server for holding them."
>
Could use github "releases" (
https://help.github.com/en/articles/creating-releases)
It won't change too often so doesn't need something high volume like
BinTray.


> and I replied
>
> I think the best thing to do is to
> a) have a directory in each build.foo* which includes the pre-built
> support libraries
> b) have a separate repository to build the support libraries
>
Consider having a separate mirror-repo for each third-party library.

Libraries that are github hosted can just be forked.
e.g. https://github.com/freedesktop/cairo

Libraries that are git based by hosted elsewhere can be cloned and pushed
to opensmalltalk-vm account with full history e.g.
https://www.freetype.org/developer.html

Libraries with a git repo can just be untar'ed locally and pushed via git
to opensmalltalk-vm account
(I only spot checked, but didn't bump into a library not using git)

The thing I'm not clear on is whether there are inter-dependencies between
third-party libraries to be kept in sync.
But anyway this can be done via the library.spec files.

cheers -ben

c) a workflow where when a new version of a library is needed one checks
> out repository b) and builds, and then replaces the libraries in a) and
> commits. That is what I'm doing with Terf. See
> terf-cogvm/platforms/Cross/third-party/lib.macos32x86 & lib.macos64x64.
>
> And he agrees.
>
> So was soon as possible we should split the repository to create e.g.
> opensmalltalk-third-party and stop rebuilding third-party software
> unnecessarily. We do have to decide where the products live on
> opensmalltalk-vm. I propose that they live in build.*/third-party/lib
>


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

<script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386?email_source=notifications\u0026email_token=AIJPEW6OBN3RYT7NDJMA7KTP4TMM3A5CNFSM4HB5W2J2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGODYXPYIQ#issuecomment-506395682", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386?email_source=notifications\u0026email_token=AIJPEW6OBN3RYT7NDJMA7KTP4TMM3A5CNFSM4HB5W2J2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGODYXPYIQ#issuecomment-506395682", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
In reply to this post by David T Lewis
 

Can this be closed in favor of #482 ?


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or unsubscribe.

<script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-617624338", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-617624338", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
In reply to this post by David T Lewis
 

:shipit: 🤷


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or unsubscribe.

<script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-690601266", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#issuecomment-690601266", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>
Reply | Threaded
Open this post in threaded view
|

Re: [OpenSmalltalk/opensmalltalk-vm] third-party: Stop building/using vulnerable software (#386)

David T Lewis
In reply to this post by David T Lewis
 

Merged #386 into Cog.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or unsubscribe.

<script type="application/ld+json">[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#event-3752511275", "url": "https://github.com/OpenSmalltalk/opensmalltalk-vm/pull/386#event-3752511275", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]</script>