-
Story
-
Resolution: Done-Errata
-
Undefined
-
rhel-8.8.0
-
flatpak-builder-1.2.3-1.el8
-
None
-
Rebase
-
rhel-sst-display-productivity
-
ssg_display
-
11
-
12
-
None
-
False
-
-
Yes
-
None
-
None
We are already shipping Git >= 2.38.1, which disables the file protocol by default due to CVE-2022-39253. This breaks builds with Git submodules:
https://github.com/flatpak/flatpak-builder/issues/495
This is fixed in flatpak-builder-1.2.3:
https://github.com/flatpak/flatpak-builder/commit/1d3e9043a7c6f05d
Other than that, this is part of the rebase of the Flatpak stack to 1.12.x in RHEL 8.
- links to
-
RHBA-2023:124257 flatpak-builder bug fix and enhancement update
- mentioned on