Fix ReDoS (GHSL-2024-323)
Metadata
Current evaluation
Superseded by PR #5213, which resolves the ReDoS vulnerability (GHSL-2024-323) and corrects the underlying regex logic. The original author acknowledged the improved fix and closed this pull request.
Suggested action: —
No scores available.
Issue body
- [x] Have you followed the [guidelines for contributing](https://github.com/canonical/snapcraft/blob/main/CONTRIBUTING.md)?
- [x] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [ ] Have you successfully run `tox run -m lint`?
- [ ] Have you successfully run `tox run -e test-py310`? (supported versions: `py39`, `py310`, `py311`, `py312`)
-----
Fixes a ReDoS: https://bugs.launchpad.net/snapcraft/+bug/2086622 (GHSL-2024-323)
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Superseded by PR #5213, which resolves the ReDoS vulnerability (GHSL-2024-323) and corrects the underlying regex logic. The original author acknowledged the improved fix and closed this pull request. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Superseded by PR #5213. The original pull request addressed a ReDoS vulnerability (GHSL-2024-323), but a maintainer submitted a superior fix that also corrects the underlying regex. The original PR was closed in favor of the maintainer's solution. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Superseded by PR #5213, which provides a more precise regex fix for the ReDoS vulnerability (GHSL-2024-323). The original PR was closed without merging after a maintainer identified a superior approach that also corrects incorrect duration parsing. |
Update history
No update history recorded yet.
Related issues
No related issues found above the similarity threshold.