Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Possibly vulnerable packages overview #26107

Open
aparcar opened this issue Mar 6, 2025 · 2 comments
Open

Possibly vulnerable packages overview #26107

aparcar opened this issue Mar 6, 2025 · 2 comments

Comments

@aparcar
Copy link
Member

aparcar commented Mar 6, 2025

Hi all, with some recent work we got better integration in repology.org, which kindly tracks our packages and even show outdated/vulnerable packages.

Looking at the overview, it's clear that quite some packages require and upgrade or should be dropped if no longer maintained within OpenWrt. I invite everyone to have a quick look at the table below:

https://repology.org/projects/?inrepo=openwrt_24_10_x86_64&vulnerable=1

@Nmrawe
Copy link

Nmrawe commented Mar 6, 2025

curl 8.10.1 has 4 known vulnerabilities: https://curl.se/docs/vuln-8.10.1.html.
It has been updated to the latest version in Master, but not by the designated maintainer.

@feckert
Copy link
Member

feckert commented Mar 7, 2025

@aparcar I would suggest to pin this to the issue overiew page.

@aparcar aparcar pinned this issue Mar 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants