-
Notifications
You must be signed in to change notification settings - Fork 704
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Backport TUF security bugfix to < 3.10 #9451
Comments
Just to be clear: 3.10.2.0 is recommended on platforms besides windows, right? Also, is there a full inventory of the windows regressions that we need to look into? |
No, 'recommended' is across all platforms. We can't recommend a version that works on only some platforms. Teams should be confident to get the exact same versions of tools when they install 'recommended'. Everything else is calling for confusion. The regression is described here: #9334 |
There is no plan for either a 3.6 or 3.8 release. See https://mail.haskell.org/pipermail/cabal-devel/2023-November/010578.html. The fix is included in 3.10+. |
Since 3.10.2.0 has major regressions on windows, this would leave the 'recommended' version in GHCup vulnerable.
Bumping 'recommended' to 3.10.2.0 is not an option at this time.
The text was updated successfully, but these errors were encountered: