Skip to content

Borg 1.4.5 release for msgpack vulnerability? #9806

Description

@nijel

Do you have plans to release 1.4.5 with updated msgpack dependency? I believe the changes are already done via #9790.

msgpack versions supported by the 1.4.4 release have high severity vulnerability GHSA-6v7p-g79w-8964.

I have no clue if the vulnerability actually affects borgbackup or not, but even if not, it would be great to resolve as the security scanners do complain on this.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions