Skip to content

[Release] Cut a new release to address CVE-2025-29787 #824

Closed
@AlecRosenbaum

Description

@AlecRosenbaum

The version of the rust sdk in the most recent release includes a version of the zip crate affected by CVE-2025-29787.

While I don't suspect from an application-usage perspective that the temporal core sdk is extracting untrusted zip files, automated vulnerability scanning tools still pick up on the vulnerable version and prompt us to respond in some form.

Current master of this repository already has the core sdk bumped to a version that is not vulnerable, there just hasn't been a release uploaded to pypi since it was patched. The zip patch was included with #802 I think just as a side-effect of the other work done in that change.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions