conda-forge / r-base-feedstock

A conda-smithy repository for r-base.
BSD 3-Clause "New" or "Revised" License
14 stars 47 forks source link

Add patch to R versions <4.4 for CVE-2024-27322? #338

Closed fh-mthomson closed 4 months ago

fh-mthomson commented 4 months ago

As succinctly proposed by @mbargull in https://github.com/conda-forge/r-base-feedstock/pull/297#issuecomment-2127776232, inheriting a patch for CVE-2024-27322 would allow conda users to more directly address the issue by installing a patched version of r-base from conda, which would remove the need to upgrade all R code + libraries to ≥4.4.0 (non-trivial).

Examples:

Disclaimers: I'm not looking to debate the (1) severity of the CVE nor (2) the version(s) of R that should be used; instead, it's reasonable to assume that many users/organizations will want to (a) stay on a non-4.4 version of R and (b) err on the side of caution via a patched version. Thank you for the consideration!

jdblischak commented 4 months ago

I can submit the PRs

fh-mthomson commented 4 months ago

Thank you, @jdblischak!