Skip to content

Backport request #21091

@claytonparnell

Description

@claytonparnell

Hello, I checked repo but don't see any process available for backporting fixes to previous minor versions. There was recently a fix (#20751) for a public GHSA (GHSA-48g7-3x6r-xfhp), But the fix was only applied in a new minor version 3.9, leaving 3.(0-8) still vulnerable.
Is there any process for backporting a fix to previous minor versions? I am happy to help raise PR adding the fix to version tags, but not sure the best way to do this and to drive new patch releases for these versions.

Thanks!

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions