logoalt Hacker News

ntauthoritytoday at 6:20 AM2 repliesview on HN

i like how this is a side effect of a bunch of assorted changes in a commit and PR solely described as "Fix path resolving" making it hard for anyone running Gitea to even know this is a security fix


Replies

wvbdmptoday at 6:37 AM

It’s explicitly listed as a security fix in the release notes, accompanied by a CVE: https://blog.gitea.com/release-of-1.25.5/

tomxortoday at 11:46 AM

I'm not completely sure if this is supposed to be sincere, but it should be.

It's not uncommon practice to omit the security implications on public facing commit messages when fixing secirity issues, so as to not to draw attention until it's ready for distribution.