Skip to content

Commit

Permalink
changelog: Add entry for % expansion mitigation
Browse files Browse the repository at this point in the history
  • Loading branch information
bgamari committed Sep 6, 2024
1 parent 142a7eb commit 85dabea
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions changelog.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@
* Fix command-line escaping logic on Windows when the command file ends with
a space or a dot. This is a follow-up for
[HSEC-2024-0003](https://github.com/haskell/security-advisories/tree/main/advisories/hackage/process/HSEC-2024-0003.md).
* Migitate another manifestation of the BatBadBut vulnerability via
unescaped `%` expansions. This is another follow-up for
[HSEC-2024-0003](https://github.com/haskell/security-advisories/tree/main/advisories/hackage/process/HSEC-2024-0003.md).
([#313](https://github.com/haskell/process/issues/313))

## 1.6.22.0 *August 2024*

Expand Down

0 comments on commit 85dabea

Please sign in to comment.