Control: tags -1 + pending
On Mon, 14 Sep 2026 at 13:36:25 +0100, Simon McVittie wrote:
https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv
If flatpak-builder is run against an untrusted manifest and the manifest
specifies `use-git-am: true`, a malicious module source can trigger
arbitrary code execution on the host system by adding a
`post-applypatch` hook.
I'll try to upload 1.4.11 soon to fix this in unstable (although I'd be
grateful if someone who uses flatpak-builder more regularly than I do
can take responsibility).
smcv