DEV Community

Jonas Brømsø
Jonas Brømsø

Posted on

2

Release 0.25.0 of Spellcheck (GitHub) Action - a maintenance release including a security fix

I have just returned after a 3-day hike in Sweden, so some time at the computer is most welcome, since my legs are pretty worn.

The release of 0.25.0 of the GitHub Spellcheck Action consists of PRs from two bots. One bumps the base image for the Docker image, so as always to not fall too much behind on maintenance doing baby steps.

The other one is a fix to a recently discovered security issue in the Python library lxml.

The proposed fix from Snyk was to bump the required version from 4.6.5 to 4.9.1. The Snyk report is available here:

In addition there are descriptions as both CVE and CWE:

I am not sure how relevant and critical the issue is in the context of this GitHub action, but I always tend to take these things seriously - better safe than sorry.

Change Log

0.25.0, 2022-07-08, maintenance release, update recommended

AWS Security LIVE!

Join us for AWS Security LIVE!

Discover the future of cloud security. Tune in live for trends, tips, and solutions from AWS and AWS Partners.

Learn More

Top comments (0)

Billboard image

Create up to 10 Postgres Databases on Neon's free plan.

If you're starting a new project, Neon has got your databases covered. No credit cards. No trials. No getting in your way.

Try Neon for Free →

👋 Kindness is contagious

Please leave a ❤️ or a friendly comment on this post if you found it helpful!

Okay