Skip to content

[PR #468/bcb29d17 backport][0.8] Parse compact index more resiliant - #469

Merged
mdellweg merged 1 commit into
0.8from
patchback/backports/0.8/bcb29d178bcb247529da4b80d9b4da828e5bfffe/pr-468
Aug 26, 2026
Merged

[PR #468/bcb29d17 backport][0.8] Parse compact index more resiliant#469
mdellweg merged 1 commit into
0.8from
patchback/backports/0.8/bcb29d178bcb247529da4b80d9b4da828e5bfffe/pr-468

Conversation

@patchback

@patchback patchback Bot commented Aug 26, 2026

Copy link
Copy Markdown

This is a backport of PR #468 as merged into main (bcb29d1).

The newly introduced "created_at" field brings colons where according to the specification no colons are allowed.
For now, we just make sure pulp_gem can still read those files and ignore the value since misinterpreting or spoofing it would have security implications.

fixes: #446

📜 Checklist

  • Commits are cleanly separated with meaningful messages (simple features and bug fixes should be squashed to one commit)
  • A changelog entry or entries has been added for any significant changes
  • Follows the Pulp policy on AI Usage
  • (For new features) - User documentation and test coverage has been added

See: Pull Request Walkthrough

The newly introduced "created_at" field brings colons where according to
the specification no colons are allowed.
For now, we just make sure pulp_gem can still read those files and
ignore the value since misinterpreting or spoofing it would have
security implications.

fixes: #446
(cherry picked from commit bcb29d1)
@patchback patchback Bot mentioned this pull request Aug 26, 2026
4 tasks
@mdellweg
mdellweg enabled auto-merge (rebase) August 26, 2026 14:18
@mdellweg
mdellweg merged commit 632d811 into 0.8 Aug 26, 2026
14 checks passed
@mdellweg
mdellweg deleted the patchback/backports/0.8/bcb29d178bcb247529da4b80d9b4da828e5bfffe/pr-468 branch August 26, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant