drupalwxt / wxt

Drupal 10 variant of the Web Experience Toolkit (WxT).
https://drupalwxt.github.io
GNU General Public License v2.0
26 stars 27 forks source link

Drupal Security Advisory Security risk: Critical #233

Closed PCH-TanB closed 3 years ago

PCH-TanB commented 3 years ago

Hello, it seems that the latest version of drupalwxt 3.0.17(drupal core 8.8.10) is affected. When is the patch available? See details here https://cyber.gc.ca/en/alerts/drupal-security-advisory-10 and https://www.drupal.org/sa-core-2020-012. Thanks a lot! Bobby

zachomedia commented 3 years ago

@PCH-TanB Can you elaborate where you're seeing 8.8.10? https://github.com/drupalwxt/wxt/blob/3.0.17/composer.json#L19 points to 8.8.11 and the lock file that was auto-generated by the release (https://github.com/drupalwxt/site-wxt/blob/8.x/composer.lock#L3614) also has 8.8.11.

PCH-TanB commented 3 years ago

image

sylus commented 3 years ago

Oh that was just an accident in the README.md I have updated that but the codebase itself is the correct version.

Fixed the README.md @PCH-TanB thanks :D