Skip to content

2025 Year in Review#197

Merged
sjn merged 5 commits intoCPAN-Security:mainfrom
timlegge:year-in-review
Jan 27, 2026
Merged

2025 Year in Review#197
sjn merged 5 commits intoCPAN-Security:mainfrom
timlegge:year-in-review

Conversation

@timlegge
Copy link
Copy Markdown
Contributor

Based on the content everyone added to the cryptpad document

Copy link
Copy Markdown
Contributor

@robrwo robrwo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. I've made some suggestions.

While CVEs are often specific to a single distribution, this year featured a unique coordination effort.
Three different JSON modules shared the same vulnerability, resulting in three separate CVEs.
The maintainers involved were highly responsive, allowing the CNA to coordinate the simultaneous release of the CVEs and patched versions within a short window.
We would like to thank these maintainers for their patience and diligence.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps mention them by name?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I for one think this would be nice, though last year I think we chose not to mention contributors by name i the text, didn't we? (I might be misremembering)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We had a list of CPANSec contributors. Not CPAN maintainers.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In this case it was three CPAN maintainers for the JSON modules. I am fine either way I can mention them no problem by CPAN ID?

@sjn
Copy link
Copy Markdown
Contributor

sjn commented Jan 20, 2026

Last year, we had a section about TLS in core. I think it would be good to say at least something on this also this year. @Leont, would you mind sharing a paragraph with us, so we may add it? 😸

@sjn sjn merged commit 4c9378a into CPAN-Security:main Jan 27, 2026
2 checks passed
@sjn
Copy link
Copy Markdown
Contributor

sjn commented Jan 27, 2026

Merged into main, so we can get this done before FOSDEM. If @Leont wants to share some info on TLS-in-core, we can add this, and so with the CPAN module authors.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants