Tuleap Community Edition development and releases are no longer public. You have until September 30th to download packages and sources in Tuleap project. You can contact the team if you need further assistance.

    •  
      request #44864 Go: temporarily ignore CVE-2025-47910
    Infos
    #44864
    Joris MASSON (jmasson)
    2025-10-09 14:49
    2025-09-25 11:14
    46628
    Details
    Go: temporarily ignore CVE-2025-47910

    Security Advisory: https://pkg.go.dev/vuln/GO-2025-3955

    There is no security impact for Tuleap, because we do not use AddInsecureBypassPattern in http.CrossOriginProtection. We can temporarily ignore this and upgrade to a fixed Go version later.

    Dependencies
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Joris MASSON (jmasson)
    Closed
    2025-09-25
    Attachments
    Empty
    References
    Referenced by request #44864

    Follow-ups