Skip to content

Conversation

@labkey-tchad
Copy link
Member

Rationale

The following CVEs are for the Debian bzip2 package, not the jbzip2 package imported by the SequenceAnalysis module.
https://nvd.nist.gov/vuln/detail/CVE-2005-1260
https://nvd.nist.gov/vuln/detail/CVE-2010-0405
https://nvd.nist.gov/vuln/detail/CVE-2011-4089
https://nvd.nist.gov/vuln/detail/CVE-2019-12900

Related Pull Requests

  • N/A

Changes

  • Suppress bzip2 CVE false positives

@labkey-tchad labkey-tchad requested a review from a team October 31, 2025 18:50
Copy link
Contributor

@labkey-susanh labkey-susanh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not needed for earlier releases?

@labkey-tchad labkey-tchad merged commit 97d870a into develop Oct 31, 2025
9 of 10 checks passed
@labkey-tchad labkey-tchad deleted the fb_suppressBzipCveFalsePositive branch October 31, 2025 20:57
@labkey-tchad
Copy link
Member Author

Not needed for earlier releases?

This isn't getting hit in 25.7 for some reason.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants