[equinox-dev] Declare 4.27 RC1

2023-02-22 Thread Samantha Dawley
Hello, Please sign off on Issue 892 - Declare 4.27 RC1 Current Candidate Eclipse downloads: https://download.eclipse.org/eclipse/downloads/drops4/I20230222-1800 Build logs and/or test results (eventually):

Re: [equinox-dev] Security audit of the recent changes to Eclipse p2 (PGP signatures)

2023-02-22 Thread Mickael Istria
Hello, For what I'm aware of, there is currently no-one really planning to provide some fixes for the identified vulnerabilities. They're still important though. So I would suggest that we just open CVEs for those ASAP without waiting further as waiting longer isn't likely to increase the chances

Re: [equinox-dev] Security audit of the recent changes to Eclipse p2 (PGP signatures)

2023-02-22 Thread Amir Montazery
Hello everyone! I thought to follow up on this thread to see if there was any feedback or progress on remediation of the 3 major vulnerabilities reported in the audit. As soon as the Eclipse PMC members and Equinox developers are satisfied with the report and status of the fixes, OSTIF can help