Skip to content

Commit

Permalink
chore: prep v6.7.2
Browse files Browse the repository at this point in the history
Signed-off-by: Jan Kowalleck <jan.kowalleck@gmail.com>
  • Loading branch information
jkowalleck committed May 8, 2024
1 parent 8054a4c commit 9adb16d
Showing 1 changed file with 7 additions and 3 deletions.
10 changes: 7 additions & 3 deletions HISTORY.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,20 +6,24 @@ All notable changes to this project will be documented in this file.

<!-- add unreleased items here -->

## 6.7.2 -- 2024-05-07

* Changed
* The provided XML validation capabilities are hardened (via [#1064]; concerns [#1061])
* The provided XML validation capabilities were explicitly hardened (via [#1064]; concerns [#1061])
This is considered a security measure concerning XML external entity (XXE) injection.

[#1061]: https://github.com/CycloneDX/cyclonedx-javascript-library/issues/1061
[#1064]: https://github.com/CycloneDX/cyclonedx-javascript-library/pull/1064

## 6.7.1 -- 2024-05-07

Reverted v6.7.0, back to v6.6.1
Reverted v6.7.0, back to v6.6.1
Reason: https://github.com/CycloneDX/cyclonedx-javascript-library/security/advisories/GHSA-38gf-rh2w-gmj7

## 6.7.0 -- 2024-05-07

!! THIS VERSION GOT YANKED !!
!! THIS VERSION GOT YANKED !!
Reason: https://github.com/CycloneDX/cyclonedx-javascript-library/security/advisories/GHSA-38gf-rh2w-gmj7

* Changed
* The provided XML validation capabilities no longer supports external entities (via [#1063]; concerns [#1061])
Expand Down

0 comments on commit 9adb16d

Please sign in to comment.