Re: [OE-core] [[kirkstone][PATCH] openssl : Upgrade OpenSSL 3.0.7 -> 3.0.8] openssl: Upgrade 3.0.7 -> 3.0.8

2023-02-19 Thread Alexandre Belloni via lists.openembedded.org
On 19/02/2023 16:05:11+0100, Martin Jansa wrote: > On Sun, Feb 19, 2023 at 3:13 PM Steve Sakoman wrote: > > > On Sun, Feb 19, 2023 at 2:36 AM Martin Jansa > > wrote: > > > > > > Hello Steve, Siddharth, > > > > > > are you waiting for PATCHv3 with commit summary update requested in > >

Re: [OE-core] [[kirkstone][PATCH] openssl : Upgrade OpenSSL 3.0.7 -> 3.0.8] openssl: Upgrade 3.0.7 -> 3.0.8

2023-02-19 Thread Martin Jansa
On Sun, Feb 19, 2023 at 3:13 PM Steve Sakoman wrote: > On Sun, Feb 19, 2023 at 2:36 AM Martin Jansa > wrote: > > > > Hello Steve, Siddharth, > > > > are you waiting for PATCHv3 with commit summary update requested in > corresponding langdale review: > > >

Re: [OE-core] [[kirkstone][PATCH] openssl : Upgrade OpenSSL 3.0.7 -> 3.0.8] openssl: Upgrade 3.0.7 -> 3.0.8

2023-02-19 Thread Steve Sakoman
On Sun, Feb 19, 2023 at 2:36 AM Martin Jansa wrote: > > Hello Steve, Siddharth, > > are you waiting for PATCHv3 with commit summary update requested in > corresponding langdale review: > https://patchwork.yoctoproject.org/project/oe-core/patch/20230209143708.20705-1-sdo...@mvista.com/? > > or is

Re: [OE-core] [[kirkstone][PATCH] openssl : Upgrade OpenSSL 3.0.7 -> 3.0.8] openssl: Upgrade 3.0.7 -> 3.0.8

2023-02-19 Thread Martin Jansa
Hello Steve, Siddharth, are you waiting for PATCHv3 with commit summary update requested in corresponding langdale review: https://patchwork.yoctoproject.org/project/oe-core/patch/20230209143708.20705-1-sdo...@mvista.com/ ? or is something else blocking this upgrade? I'm a bit surprised that

[OE-core] [[kirkstone][PATCH] openssl : Upgrade OpenSSL 3.0.7 -> 3.0.8] openssl: Upgrade 3.0.7 -> 3.0.8

2023-02-09 Thread mv
From: Siddharth Doshi OpenSSL 3.0.8 fixes 1 HIGH level security vulnerability and 7 MODERATE level security vulnerability [1]. Upgrade the recipe to point to 3.0.8. CVE-2022-3996 is reported fixed in 3.0.8, so drop the patch for that as well. [1]