couchdb-rpm
couchdb-rpm copied to clipboard
1.7.1 fixes critical CVEs
Hi Wendall,
Thanks again for all your work in maintaining the RPMs for CouchDB 1.x.
We had 2 critical CVEs hit recently. These have been fixed in CouchDB 1.7.1 (perhaps our last 1.x release!) and Peter Lemenkov then fixed the Fedora 26/27/28 RPMs:
https://bugzilla.redhat.com/show_bug.cgi?id=1516981
Is there any chance of updating your repo to function against 1.7.1 as well?
@wohali as a stopgap solution https://github.com/kika/couchdb17-centos7 I've rebuilt the RPMs from Fedora 28 and the rest could be taken from Erlang-Solutions repository.
@wohali Thanks
/cc @janl RPMs for Centos 7, 1.7.1, see https://github.com/kika/couchdb17-centos7/releases