Skip to content

GOV: write up policy on not updating req for CVEs in dependencies #28127

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Apr 29, 2024

Conversation

tacaswell
Copy link
Member

This comes up about every other month.

inspired by #28110

SC should sign off on this @timhoffm @dopplershift @efiring

@tacaswell tacaswell added this to the v3.10.0 milestone Apr 24, 2024
@github-actions github-actions bot added the Documentation: devdocs files in doc/devel label Apr 24, 2024
Copy link
Contributor

@dopplershift dopplershift left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great other than the minimal grammar edit.

Copy link
Member

@efiring efiring left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good (with corrections as suggested by others).

tacaswell and others added 2 commits April 29, 2024 13:36
Co-authored-by: Tim Hoffmann <2836374+timhoffm@users.noreply.github.com>
Co-authored-by: Elliott Sales de Andrade <quantum.analyst@gmail.com>
Co-authored-by: Ryan May <rmay31@gmail.com>
@timhoffm timhoffm merged commit cebc4d8 into matplotlib:main Apr 29, 2024
22 checks passed
@tacaswell tacaswell deleted the doc/dep_vulns branch April 29, 2024 20:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Documentation: devdocs files in doc/devel
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants