Skip to content

Use defusedxml as more secured xml parser (bsc#1227577) #10398

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

meaksh
Copy link
Member

@meaksh meaksh commented Jun 2, 2025

to be merged after 5.1 GM

#10398 (comment)

What does this PR change?

This PR makes use of defusedxml in rhnlib and spacewalk-backend-server to ensure more secure xml parsing.

NOTE: Since this PR is introducing new dependencies for rhnlib and spacewalk-backend-server, we need to coordinate with RelEng to provide the missing dependencies to the respective channels.

GUI diff

No difference.

  • DONE

Documentation

  • No documentation needed: only internal and user invisible changes

  • DONE

Test coverage

  • No tests: already covered

  • DONE

Links

Issue(s): https://github.com/SUSE/spacewalk/issues/24784

  • DONE

Changelogs

Make sure the changelogs entries you are adding are compliant with https://github.com/uyuni-project/uyuni/wiki/Contributing#changelogs and https://github.com/uyuni-project/uyuni/wiki/Contributing#uyuni-projectuyuni-repository

If you don't need a changelog check, please mark this checkbox:

  • No changelog needed

If you uncheck the checkbox after the PR is created, you will need to re-run changelog_test (see below)

Re-run a test

If you need to re-run a test, please mark the related checkbox, it will be unchecked automatically once it has re-run:

  • Re-run test "changelog_test"
  • Re-run test "backend_unittests_pgsql"
  • Re-run test "java_pgsql_tests"
  • Re-run test "schema_migration_test_pgsql"
  • Re-run test "susemanager_unittests"
  • Re-run test "javascript_lint"
  • Re-run test "spacecmd_unittests"

Before you merge

Check How to branch and merge properly!

@meaksh meaksh requested a review from a team as a code owner June 2, 2025 10:36
@meaksh meaksh requested review from vzhestkov and removed request for a team June 2, 2025 10:36
Copy link
Contributor

@vzhestkov vzhestkov left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

@meaksh meaksh added the merge-candidate Meaning it needs to be considered for merging when the master branch is frozen label Jun 2, 2025
@meaksh
Copy link
Member Author

meaksh commented Jun 6, 2025

Agreed with @rjmateus to postpone this after 5.1 GMC.

@deneb-alpha
Copy link
Contributor

Agreed with @rjmateus to postpone this after 5.1 GMC.

I think we should also drop the merge-candidate label right? I fear that the PR could be merged before by mistake.

@meaksh meaksh removed the merge-candidate Meaning it needs to be considered for merging when the master branch is frozen label Jun 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants