Skip to content

CVE-2026-50593: graphite2 -> 1.3.14#9

Draft
jasonodoom wants to merge 2 commits into
masterfrom
trace/CVE-2026-50593--graphite2--444b06915b81d937
Draft

CVE-2026-50593: graphite2 -> 1.3.14#9
jasonodoom wants to merge 2 commits into
masterfrom
trace/CVE-2026-50593--graphite2--444b06915b81d937

Conversation

@jasonodoom

Copy link
Copy Markdown

⚠️ EXPERIMENTAL source-backport — NOT a version bump

This PR authors the upstream fix as an in-tree patch against the current nixpkgs version (no version bump). An agent generated it; a cross-family reviewer verified it transcribes the upstream commit, and a cert proved the bundled reproducer goes red→green. A human maintainer must still confirm sufficiency before merging:

  • This applies the COMPLETE upstream fix, not one of several required commits.
  • The backported hunk matches the upstream fix commit(s):
  • Reviewed the cert evidence (reproducer red→green) for CVE-2026-50593.

Opened as a draft deliberately — mark Ready-for-review only after the boxes above are checked.


Evidence: CVE-2026-50593 (human-review-required) trace bundle 444b06915b81d937

Verify locally
gh run download <run-id> --name steward-smoke-<bundle> --dir ./artifact
trace bundle verify ./artifact  # bundle_id=444b06915b81d937

Generated by trace.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant