Skip to content

Changelog v1.23.0 - #2681

Merged
mAAdhaTTah merged 4 commits into
masterfrom
changelog/v1.23.0
Dec 31, 2020
Merged

mAAdhaTTah merged 4 commits into
masterfrom
changelog/v1.23.0

Conversation

@RunDevelopment

Copy link
Copy Markdown
Member

No description provided.

@github-actions

github-actions Bot commented Dec 30, 2020 •

Copy link
Copy Markdown

No JS Changes

Generated by 🚫 dangerJS against 0cc0239

@mAAdhaTTah

Copy link
Copy Markdown
Member

@RunDevelopment Oh, that reminds me: Did we include a fix for the regex we were notified about?

@RunDevelopment

Copy link
Copy Markdown
Member Author

@mAAdhaTTah Now that you mention it. The fix is trivial, so I'll just make a quick PR and merge it. We can decide on a security advisory later.

@RunDevelopment

Copy link
Copy Markdown
Member Author

Done. The changelog has been updated accordingly.

@RunDevelopment

Copy link
Copy Markdown
Member Author

@mAAdhaTTah After this comment, I am currently implementing an improvement for the detector, so that it will check (hopefully) all of Prism's regexes. I have already found that half of Latte is unchecked due to the nature of markup templating. Other languages that use markup templating (e.g. PHP) might also be affected.

Let's please hold the release until I have verified that there are no other detectable cases of exponential backtracking in Prism's code base.

@RunDevelopment

Copy link
Copy Markdown
Member Author

@mAAdhaTTah I found one more with exponential backtracking. I'll make separate PRs for the fix and the improved test suite.

@RunDevelopment

Copy link
Copy Markdown
Member Author

@mAAdhaTTah I merged the fix. The PR for the improved test suite and be dealt with after the release. I think there's nothing holding up the release now.

@mAAdhaTTah mAAdhaTTah left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@RunDevelopment Thanks for doing this! Gonna publish this now.

This was referenced Mar 15, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants