Control: tags -1 + pending

On Mon, 14 Sep 2026 at 13:36:25 +0100, Simon McVittie wrote:
https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv
If flatpak-builder is run against an untrusted manifest and the manifest
specifies `use-git-am: true`, a malicious module source can trigger
arbitrary code execution on the host system by adding a
`post-applypatch` hook.

I'll try to upload 1.4.11 soon to fix this in unstable (although I'd be grateful if someone who uses flatpak-builder more regularly than I do can take responsibility).

    smcv

Reply via email to