-
Notifications
You must be signed in to change notification settings - Fork 595
[High] Upgrade reaper for CVE-2025-9288 #14614
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: fasttrack/2.0
Are you sure you want to change the base?
[High] Upgrade reaper for CVE-2025-9288 #14614
Conversation
b4a158d
to
1578639
Compare
Hi, I have removed several outdated patches after confirming that their changes are already present in the newly generated tarball. All patches have been applied cleanly. And the CVE-2025-9288 fix has already been included in the latest tarball generated by the reaper_build_script.sh script. Note: I have the below reaper.signature.json changes while this got success! And build log from the local VM: -Thank you! |
Hi, ![]() ![]() ![]() ![]() Note: Reaper web interface at http://localhost:8080 is running successfully. |
1b267e3
to
1415660
Compare
@realsdx, gentle reminder for review and sign-off if all good.! |
/azurepipelines run |
Azure Pipelines successfully started running 1 pipeline(s). |
Hi @realsdx , ![]() If there’s anything else that needs to be updated, please let me know. |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-static
subpackages, etc.) have had theirRelease
tag incremented../cgmanifest.json
,./toolkit/scripts/toolchain/cgmanifest.json
,.github/workflows/cgmanifest.json
)./LICENSES-AND-NOTICES/SPECS/data/licenses.json
,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md
,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON
)*.signatures.json
filessudo make go-tidy-all
andsudo make go-test-coverage
passSummary
[High] Upgrade reaper for CVE-2025-9288
Astrolabe reference: https://brave-ocean-0baeae310.5.azurestaticapps.net/#/cve/CVE-2025-9288
Upstream patch reference: browserify/sha.js@f2a258e
Change Log
Does this affect the toolchain?
NO
Associated issues
Links to CVEs
Test Methodology