Skip to content

root: add a webgui patch to address security issue#41404

Merged
wdconinc merged 1 commit intospack:backports/v0.21.1from
jmcarcell:root-patch-0.21
Dec 7, 2023
Merged

root: add a webgui patch to address security issue#41404
wdconinc merged 1 commit intospack:backports/v0.21.1from
jmcarcell:root-patch-0.21

Conversation

@jmcarcell
Copy link
Copy Markdown
Contributor

Backport of #41289

@wdconinc
Copy link
Copy Markdown
Contributor

wdconinc commented Dec 3, 2023

It is a bit problematic to do these 'partial' backports. Say I want to cherry-pick version upgrades in the root package on develop against the v0.21.1 release (I am assuming that's a fairly common workflow), that will now fail because of cherry-pick conflicts. I think the backports should attempt not to break this workflow, and we should aim to backport an entire commit into develop. That's however also problematic in this case since the PR that was merged into develop mixes this security patch with version upgrades. It would have been better to keep the security patch and the version upgrades separate. So, no concrete suggestions from my side but I just wanted to point out the problems I see with this approach in case others have ideas about how to avoid them.

@wdconinc wdconinc mentioned this pull request Dec 5, 2023
36 tasks
@wdconinc wdconinc changed the title root: add a webgui patch root: add a webgui patch to address security issue Dec 7, 2023
@wdconinc wdconinc merged commit 851fb88 into spack:backports/v0.21.1 Dec 7, 2023
alalazo pushed a commit that referenced this pull request Jan 10, 2024
haampie pushed a commit that referenced this pull request Jan 11, 2024
vjranagit pushed a commit to vjranagit/spack that referenced this pull request Jan 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants