)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"654cdc8c0d3524e2d95f9714e14b50980543ee2a","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"f74d4ec5_d14888f2","updated":"2026-08-13 19:57:52.000000000","message":"Please re-add ironic-week-prio when the full list of backports has been added. Thanks!","commit_id":"6688b9cad1f90fe3c438b1f4e62fdd754cb0dea3"},{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"9c24af4f9d4a4bbe0651d21cc14a3f4fd78553c3","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"c5e7b937_fac871fc","in_reply_to":"f74d4ec5_d14888f2","updated":"2026-08-14 20:31:19.000000000","message":"Acknowledged","commit_id":"6688b9cad1f90fe3c438b1f4e62fdd754cb0dea3"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"4dc5d74eef66f44ebca206ebb5bfcc007bad47a8","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"7b4fe056_54c78f26","updated":"2026-08-14 19:12:35.000000000","message":"Mostly looks good, some formatting suggestions noted inline.","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"bec2865f7f1f80fd3e08b4316f1867c1f30295ba","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":3,"id":"f09c1082_6e34977a","updated":"2026-08-18 14:31:34.000000000","message":"Please fix the versions list, then this should be good to go imo","commit_id":"577fbde1082880d7dfe68dc8be6541486e667c61"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"14fed3c89f2d646f912f471b299ee879bf5bf65b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"705628d7_aa025216","updated":"2026-08-19 19:15:10.000000000","message":"LGTM, thank you @cid@gr-oss.io","commit_id":"80dae90437ac479e684d39aca1f09534529f3bed"}],"ossa/OSSA-2026-008.yaml":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"0c12619a1b8ba00cfa1d08f6c4313e05229adfbb","unresolved":true,"context_lines":[{"line_number":62,"context_line":"    - https://review.opendev.org/c/openstack/ironic/+/986418"},{"line_number":63,"context_line":""},{"line_number":64,"context_line":"  master errata 2:"},{"line_number":65,"context_line":"    - https://review.opendev.org/c/openstack/ironic/+/999701"},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"notes:"},{"line_number":68,"context_line":"  - A CVE request was filed with MITRE on 2026-04-27."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"d5ad7220_f9b0fce8","line":65,"updated":"2026-08-12 22:03:21.000000000","message":"Let\u0027s get backports active for this patch to all the original brances this was advisoried for. Then maybe add them inline (e.g.: \n```\n  2026.1/gazpacho:\n    - https://review.opendev.org/c/openstack/ironic/+/986235\n    - (errata 2) https://new-patch \n   ``` \n)","commit_id":"6688b9cad1f90fe3c438b1f4e62fdd754cb0dea3"},{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"a4df85494ec0f0d380692684c769be39d8c7f58f","unresolved":false,"context_lines":[{"line_number":62,"context_line":"    - https://review.opendev.org/c/openstack/ironic/+/986418"},{"line_number":63,"context_line":""},{"line_number":64,"context_line":"  master errata 2:"},{"line_number":65,"context_line":"    - https://review.opendev.org/c/openstack/ironic/+/999701"},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"notes:"},{"line_number":68,"context_line":"  - A CVE request was filed with MITRE on 2026-04-27."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"463e157a_bf44723e","line":65,"in_reply_to":"d5ad7220_f9b0fce8","updated":"2026-08-14 17:50:41.000000000","message":"Acknowledged","commit_id":"6688b9cad1f90fe3c438b1f4e62fdd754cb0dea3"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"4dc5d74eef66f44ebca206ebb5bfcc007bad47a8","unresolved":true,"context_lines":[{"line_number":14,"context_line":"  installations which have set ``[conductor]/enabled_console_interfaces`` to"},{"line_number":15,"context_line":"  enable either ``ipmitool-shellinabox`` or ``ipmitool-socat`` are vulnerable."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"errata: \u003e"},{"line_number":18,"context_line":"  When the original advisory was published a CVE number was not assigned."},{"line_number":19,"context_line":"  CVE-2026-42510 was assigned on 2026-04-29. Further, the former fix"},{"line_number":20,"context_line":"  shell-quoted the console command, but socat executes it directly without"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"611744d8_35156c41","line":17,"range":{"start_line":17,"start_character":0,"end_line":17,"end_character":6},"updated":"2026-08-14 19:12:35.000000000","message":"You need to break this up so that it\u0027s clear what is Errata 1 and what\u0027s Errata 2.  Errata 2 are easy to find because it\u0027s noted on the patch links below, but Errata 1 has disappeared.\n\nIt\u0027s up to you how to format this but maybe do a description list:\n\n```\nerrata: \u003e\n  Errata 1\n    When the original advisory was published a CVE number was not assigned.\n    CVE-2026-42510 was assigned on 2026-04-29.\n\n  Errata 2\n    The original fix shell-quoted the console command, but socat executes\n    it directly without a shell and so treated the quoted command line as\n    a single program name.  Deployments using the ipmitool-socat console\n    interface lose console functionality entirely as a result, though the\n    vulnerability itself is not reintroduced.  The Errata 2 patches provide\n    an additional fix which escapes the command for socat\u0027s own address syntax.\n```","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"22234fa0a7b60ee6feb8e90af944fcc1b111daa4","unresolved":false,"context_lines":[{"line_number":14,"context_line":"  installations which have set ``[conductor]/enabled_console_interfaces`` to"},{"line_number":15,"context_line":"  enable either ``ipmitool-shellinabox`` or ``ipmitool-socat`` are vulnerable."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"errata: \u003e"},{"line_number":18,"context_line":"  When the original advisory was published a CVE number was not assigned."},{"line_number":19,"context_line":"  CVE-2026-42510 was assigned on 2026-04-29. Further, the former fix"},{"line_number":20,"context_line":"  shell-quoted the console command, but socat executes it directly without"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"77bb219f_69eede2e","line":17,"range":{"start_line":17,"start_character":0,"end_line":17,"end_character":6},"in_reply_to":"611744d8_35156c41","updated":"2026-08-14 20:30:24.000000000","message":"Acknowledged","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"e54e3810004bd4c1899d10ecf253149246b29d62","unresolved":true,"context_lines":[{"line_number":15,"context_line":"  enable either ``ipmitool-shellinabox`` or ``ipmitool-socat`` are vulnerable."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"errata: \u003e"},{"line_number":18,"context_line":"  When the original advisory was published a CVE number was not assigned."},{"line_number":19,"context_line":"  CVE-2026-42510 was assigned on 2026-04-29. Further, the former fix"},{"line_number":20,"context_line":"  shell-quoted the console command, but socat executes it directly without"},{"line_number":21,"context_line":"  a shell and so treated the quoted command line as a single program name."},{"line_number":22,"context_line":"  Deployments using the ipmitool-socat console interface lose console"},{"line_number":23,"context_line":"  functionality entirely as a result, though the vulnerability itself is not"},{"line_number":24,"context_line":"  reintroduced. This update provides an additional fix which escapes the"},{"line_number":25,"context_line":"  command for socat\u0027s own address syntax."},{"line_number":26,"context_line":""},{"line_number":27,"context_line":"affected-products:"},{"line_number":28,"context_line":"  - product: ironic"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"86a67492_dce68c70","line":25,"range":{"start_line":18,"start_character":2,"end_line":25,"end_character":41},"updated":"2026-08-14 18:38:27.000000000","message":"You can make this bullets too.","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"22234fa0a7b60ee6feb8e90af944fcc1b111daa4","unresolved":false,"context_lines":[{"line_number":15,"context_line":"  enable either ``ipmitool-shellinabox`` or ``ipmitool-socat`` are vulnerable."},{"line_number":16,"context_line":""},{"line_number":17,"context_line":"errata: \u003e"},{"line_number":18,"context_line":"  When the original advisory was published a CVE number was not assigned."},{"line_number":19,"context_line":"  CVE-2026-42510 was assigned on 2026-04-29. Further, the former fix"},{"line_number":20,"context_line":"  shell-quoted the console command, but socat executes it directly without"},{"line_number":21,"context_line":"  a shell and so treated the quoted command line as a single program name."},{"line_number":22,"context_line":"  Deployments using the ipmitool-socat console interface lose console"},{"line_number":23,"context_line":"  functionality entirely as a result, though the vulnerability itself is not"},{"line_number":24,"context_line":"  reintroduced. This update provides an additional fix which escapes the"},{"line_number":25,"context_line":"  command for socat\u0027s own address syntax."},{"line_number":26,"context_line":""},{"line_number":27,"context_line":"affected-products:"},{"line_number":28,"context_line":"  - product: ironic"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"39cfef67_a7004820","line":25,"range":{"start_line":18,"start_character":2,"end_line":25,"end_character":41},"in_reply_to":"86a67492_dce68c70","updated":"2026-08-14 20:30:24.000000000","message":"Acknowledged","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"e54e3810004bd4c1899d10ecf253149246b29d62","unresolved":true,"context_lines":[{"line_number":23,"context_line":"  functionality entirely as a result, though the vulnerability itself is not"},{"line_number":24,"context_line":"  reintroduced. This update provides an additional fix which escapes the"},{"line_number":25,"context_line":"  command for socat\u0027s own address syntax."},{"line_number":26,"context_line":""},{"line_number":27,"context_line":"affected-products:"},{"line_number":28,"context_line":"  - product: ironic"},{"line_number":29,"context_line":"    version: \u0027\u003e\u003d4.3.0 \u003c26.1.6, \u003e\u003d27.0.0 \u003c29.0.5, \u003e\u003d30.0.0 \u003c32.0.1, \u003e\u003d33.0.0 \u003c35.0.1\u0027"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"3be568aa_a410a157","line":26,"updated":"2026-08-14 18:38:27.000000000","message":"Some of it is pretty free-form, but, please follow the pattern established in earlier OSSAs:\n\nhttps://security.openstack.org/ossa/OSSA-2023-003\nhttps://security.openstack.org/ossa/OSSA-2017-005\nhttps://security.openstack.org/ossa/OSSA-2021-002","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"bec2865f7f1f80fd3e08b4316f1867c1f30295ba","unresolved":false,"context_lines":[{"line_number":23,"context_line":"  functionality entirely as a result, though the vulnerability itself is not"},{"line_number":24,"context_line":"  reintroduced. This update provides an additional fix which escapes the"},{"line_number":25,"context_line":"  command for socat\u0027s own address syntax."},{"line_number":26,"context_line":""},{"line_number":27,"context_line":"affected-products:"},{"line_number":28,"context_line":"  - product: ironic"},{"line_number":29,"context_line":"    version: \u0027\u003e\u003d4.3.0 \u003c26.1.6, \u003e\u003d27.0.0 \u003c29.0.5, \u003e\u003d30.0.0 \u003c32.0.1, \u003e\u003d33.0.0 \u003c35.0.1\u0027"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"44e8494c_ceafb799","line":26,"in_reply_to":"3be568aa_a410a157","updated":"2026-08-18 14:31:34.000000000","message":"Done","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"e54e3810004bd4c1899d10ecf253149246b29d62","unresolved":true,"context_lines":[{"line_number":26,"context_line":""},{"line_number":27,"context_line":"affected-products:"},{"line_number":28,"context_line":"  - product: ironic"},{"line_number":29,"context_line":"    version: \u0027\u003e\u003d4.3.0 \u003c26.1.6, \u003e\u003d27.0.0 \u003c29.0.5, \u003e\u003d30.0.0 \u003c32.0.1, \u003e\u003d33.0.0 \u003c35.0.1\u0027"},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"vulnerabilities:"},{"line_number":32,"context_line":"  - cve-id: \u0027CVE-2026-42510\u0027"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"6a9bfb4c_4f1e80b9","line":29,"range":{"start_line":29,"start_character":0,"end_line":29,"end_character":84},"updated":"2026-08-14 18:38:27.000000000","message":"Can you confirm if the fix will now be in newer releases than claimed?\nif yes, you need to fix this up too\n\n(i see your note below, but, do update this with the next anticipated releases with the fixes)","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"22234fa0a7b60ee6feb8e90af944fcc1b111daa4","unresolved":false,"context_lines":[{"line_number":26,"context_line":""},{"line_number":27,"context_line":"affected-products:"},{"line_number":28,"context_line":"  - product: ironic"},{"line_number":29,"context_line":"    version: \u0027\u003e\u003d4.3.0 \u003c26.1.6, \u003e\u003d27.0.0 \u003c29.0.5, \u003e\u003d30.0.0 \u003c32.0.1, \u003e\u003d33.0.0 \u003c35.0.1\u0027"},{"line_number":30,"context_line":""},{"line_number":31,"context_line":"vulnerabilities:"},{"line_number":32,"context_line":"  - cve-id: \u0027CVE-2026-42510\u0027"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"63cc542a_30ca7333","line":29,"range":{"start_line":29,"start_character":0,"end_line":29,"end_character":84},"in_reply_to":"6a9bfb4c_4f1e80b9","updated":"2026-08-14 20:30:24.000000000","message":"Acknowledged","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"e54e3810004bd4c1899d10ecf253149246b29d62","unresolved":true,"context_lines":[{"line_number":43,"context_line":"    - https://launchpad.net/bugs/2148331"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"reviews:"},{"line_number":46,"context_line":"  master:"},{"line_number":47,"context_line":"    - (errata 2) https://review.opendev.org/c/openstack/ironic/+/999701"},{"line_number":48,"context_line":""},{"line_number":49,"context_line":"  2026.1/gazpacho:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"50cdb42b_f13bc321","line":46,"range":{"start_line":46,"start_character":2,"end_line":46,"end_character":8},"updated":"2026-08-14 18:38:27.000000000","message":"please call this:\n\n\"2026.2/hibiscus\"","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"22234fa0a7b60ee6feb8e90af944fcc1b111daa4","unresolved":false,"context_lines":[{"line_number":43,"context_line":"    - https://launchpad.net/bugs/2148331"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"reviews:"},{"line_number":46,"context_line":"  master:"},{"line_number":47,"context_line":"    - (errata 2) https://review.opendev.org/c/openstack/ironic/+/999701"},{"line_number":48,"context_line":""},{"line_number":49,"context_line":"  2026.1/gazpacho:"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"ace8c2a9_939d536d","line":46,"range":{"start_line":46,"start_character":2,"end_line":46,"end_character":8},"in_reply_to":"50cdb42b_f13bc321","updated":"2026-08-14 20:30:24.000000000","message":"Acknowledged","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"e54e3810004bd4c1899d10ecf253149246b29d62","unresolved":true,"context_lines":[{"line_number":48,"context_line":""},{"line_number":49,"context_line":"  2026.1/gazpacho:"},{"line_number":50,"context_line":"    - https://review.opendev.org/c/openstack/ironic/+/986235"},{"line_number":51,"context_line":"    - (errata 2) https://review.opendev.org/c/openstack/ironic/+/1000984"},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"  2025.2/flamingo:"},{"line_number":54,"context_line":"    - https://review.opendev.org/c/openstack/ironic/+/986361"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"819cb64f_da98d047","line":51,"range":{"start_line":51,"start_character":65,"end_line":51,"end_character":72},"updated":"2026-08-14 18:38:27.000000000","message":"same note as above (the errata annotation came after the patch link)","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"22234fa0a7b60ee6feb8e90af944fcc1b111daa4","unresolved":false,"context_lines":[{"line_number":48,"context_line":""},{"line_number":49,"context_line":"  2026.1/gazpacho:"},{"line_number":50,"context_line":"    - https://review.opendev.org/c/openstack/ironic/+/986235"},{"line_number":51,"context_line":"    - (errata 2) https://review.opendev.org/c/openstack/ironic/+/1000984"},{"line_number":52,"context_line":""},{"line_number":53,"context_line":"  2025.2/flamingo:"},{"line_number":54,"context_line":"    - https://review.opendev.org/c/openstack/ironic/+/986361"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"74f5063e_94d1dd2b","line":51,"range":{"start_line":51,"start_character":65,"end_line":51,"end_character":72},"in_reply_to":"819cb64f_da98d047","updated":"2026-08-14 20:30:24.000000000","message":"Acknowledged","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"e54e3810004bd4c1899d10ecf253149246b29d62","unresolved":false,"context_lines":[{"line_number":70,"context_line":"    - (errata 2) https://review.opendev.org/c/openstack/ironic/+/1000990"},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"notes:"},{"line_number":73,"context_line":"  - A CVE request was filed with MITRE on 2026-04-27."},{"line_number":74,"context_line":"  - Patches for unmaintained branches are provided as a courtesy."},{"line_number":75,"context_line":"  - The console regression affects the 26.1.6, 29.0.5, 29.0.6, 32.0.1,"},{"line_number":76,"context_line":"    35.0.1, 36.0.0, 37.0.0 and 38.0.0 releases; stable/2024.2 has since"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"45a41c7b_b83dba3e","line":73,"range":{"start_line":73,"start_character":0,"end_line":73,"end_character":53},"updated":"2026-08-14 18:38:27.000000000","message":"I\u0027ve been dropping this sorta note when CVE assignment erratas came.. but that\u0027s not what you\u0027re fixing, so i\u0027d leave it alone","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"22234fa0a7b60ee6feb8e90af944fcc1b111daa4","unresolved":false,"context_lines":[{"line_number":70,"context_line":"    - (errata 2) https://review.opendev.org/c/openstack/ironic/+/1000990"},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"notes:"},{"line_number":73,"context_line":"  - A CVE request was filed with MITRE on 2026-04-27."},{"line_number":74,"context_line":"  - Patches for unmaintained branches are provided as a courtesy."},{"line_number":75,"context_line":"  - The console regression affects the 26.1.6, 29.0.5, 29.0.6, 32.0.1,"},{"line_number":76,"context_line":"    35.0.1, 36.0.0, 37.0.0 and 38.0.0 releases; stable/2024.2 has since"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"361d9d35_c8d03e15","line":73,"range":{"start_line":73,"start_character":0,"end_line":73,"end_character":53},"in_reply_to":"032e3f68_f5fb60e2","updated":"2026-08-14 20:30:24.000000000","message":"Acknowledged","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"4dc5d74eef66f44ebca206ebb5bfcc007bad47a8","unresolved":true,"context_lines":[{"line_number":70,"context_line":"    - (errata 2) https://review.opendev.org/c/openstack/ironic/+/1000990"},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"notes:"},{"line_number":73,"context_line":"  - A CVE request was filed with MITRE on 2026-04-27."},{"line_number":74,"context_line":"  - Patches for unmaintained branches are provided as a courtesy."},{"line_number":75,"context_line":"  - The console regression affects the 26.1.6, 29.0.5, 29.0.6, 32.0.1,"},{"line_number":76,"context_line":"    35.0.1, 36.0.0, 37.0.0 and 38.0.0 releases; stable/2024.2 has since"}],"source_content_type":"text/x-yaml","patch_set":2,"id":"032e3f68_f5fb60e2","line":73,"range":{"start_line":73,"start_character":0,"end_line":73,"end_character":53},"in_reply_to":"45a41c7b_b83dba3e","updated":"2026-08-14 19:12:35.000000000","message":"I think we should keep it, it\u0027s still a true statement, and I think we should be conservative in how these OSSAs are modified.  While the changes are clear in the git repo, they aren\u0027t clear in the rendered HTML, which I imagine is what many people read.","commit_id":"adce558208ddce2bdad8f202e10fbbb9b7bafa52"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"44d457455eaced02cb8eb3c88d46c18e22160ff0","unresolved":true,"context_lines":[{"line_number":28,"context_line":""},{"line_number":29,"context_line":"affected-products:"},{"line_number":30,"context_line":"  - product: ironic"},{"line_number":31,"context_line":"    version: \u0027\u003e\u003d4.3.0 \u003c26.1.6, \u003e\u003d27.0.0 \u003c29.0.7, \u003e\u003d30.0.0 \u003c32.0.2, \u003e\u003d33.0.0 \u003c35.0.2, \u003e\u003d36.0.0 \u003c39.0.0\u0027"},{"line_number":32,"context_line":""},{"line_number":33,"context_line":"vulnerabilities:"},{"line_number":34,"context_line":"  - cve-id: \u0027CVE-2026-42510\u0027"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"86de4895_07ec384c","line":31,"range":{"start_line":31,"start_character":0,"end_line":31,"end_character":102},"updated":"2026-08-17 21:48:10.000000000","message":"was chatting with the VMT about this; and Jay confirmed that the fixed versions string was correct. The IPMI console bug fix wasn\u0027t concerned with the vulnerability.. just that the fix for the vulnerability introduced a bug.","commit_id":"577fbde1082880d7dfe68dc8be6541486e667c61"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"bec2865f7f1f80fd3e08b4316f1867c1f30295ba","unresolved":true,"context_lines":[{"line_number":28,"context_line":""},{"line_number":29,"context_line":"affected-products:"},{"line_number":30,"context_line":"  - product: ironic"},{"line_number":31,"context_line":"    version: \u0027\u003e\u003d4.3.0 \u003c26.1.6, \u003e\u003d27.0.0 \u003c29.0.7, \u003e\u003d30.0.0 \u003c32.0.2, \u003e\u003d33.0.0 \u003c35.0.2, \u003e\u003d36.0.0 \u003c39.0.0\u0027"},{"line_number":32,"context_line":""},{"line_number":33,"context_line":"vulnerabilities:"},{"line_number":34,"context_line":"  - cve-id: \u0027CVE-2026-42510\u0027"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"9927af11_9e4a91b6","line":31,"range":{"start_line":31,"start_character":0,"end_line":31,"end_character":102},"in_reply_to":"7d896ffa_c0fc096b","updated":"2026-08-18 14:31:34.000000000","message":"Yes, please revert to the original version.\n\nLogic behind the decision is simple: \n- This is a list of versions that are vulnerable to this bug\n- Even though the intiial patch was broken, it still closed the vulnerability -- so no further releases of Ironic were impacted by the security issue\n- Therefore, the affected products doesn\u0027t need to change","commit_id":"577fbde1082880d7dfe68dc8be6541486e667c61"},{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"19f22c5b00167a65f768e5a80f4638000c28685d","unresolved":true,"context_lines":[{"line_number":28,"context_line":""},{"line_number":29,"context_line":"affected-products:"},{"line_number":30,"context_line":"  - product: ironic"},{"line_number":31,"context_line":"    version: \u0027\u003e\u003d4.3.0 \u003c26.1.6, \u003e\u003d27.0.0 \u003c29.0.7, \u003e\u003d30.0.0 \u003c32.0.2, \u003e\u003d33.0.0 \u003c35.0.2, \u003e\u003d36.0.0 \u003c39.0.0\u0027"},{"line_number":32,"context_line":""},{"line_number":33,"context_line":"vulnerabilities:"},{"line_number":34,"context_line":"  - cve-id: \u0027CVE-2026-42510\u0027"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"7d896ffa_c0fc096b","line":31,"range":{"start_line":31,"start_character":0,"end_line":31,"end_character":102},"in_reply_to":"86de4895_07ec384c","updated":"2026-08-18 10:13:31.000000000","message":"So, should I revert to the originally published string?","commit_id":"577fbde1082880d7dfe68dc8be6541486e667c61"},{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"e349abbc546c6433e26595e843101396c99d4433","unresolved":false,"context_lines":[{"line_number":28,"context_line":""},{"line_number":29,"context_line":"affected-products:"},{"line_number":30,"context_line":"  - product: ironic"},{"line_number":31,"context_line":"    version: \u0027\u003e\u003d4.3.0 \u003c26.1.6, \u003e\u003d27.0.0 \u003c29.0.7, \u003e\u003d30.0.0 \u003c32.0.2, \u003e\u003d33.0.0 \u003c35.0.2, \u003e\u003d36.0.0 \u003c39.0.0\u0027"},{"line_number":32,"context_line":""},{"line_number":33,"context_line":"vulnerabilities:"},{"line_number":34,"context_line":"  - cve-id: \u0027CVE-2026-42510\u0027"}],"source_content_type":"text/x-yaml","patch_set":3,"id":"5a45830b_8dfb5c1e","line":31,"range":{"start_line":31,"start_character":0,"end_line":31,"end_character":102},"in_reply_to":"9927af11_9e4a91b6","updated":"2026-08-18 15:37:10.000000000","message":"Acknowledged","commit_id":"577fbde1082880d7dfe68dc8be6541486e667c61"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"c2a06cd0055bb0e435c4d1ebc305dd39f55b7095","unresolved":false,"context_lines":[{"line_number":84,"context_line":"    console interface immediately."},{"line_number":85,"context_line":""},{"line_number":86,"context_line":"errata_history:"},{"line_number":87,"context_line":"  - 2026-08-12 - Errata 2"},{"line_number":88,"context_line":"  - 2026-04-29 - Errata 1"},{"line_number":89,"context_line":"  - 2026-04-27 - Original Version"},{"line_number":90,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"a4e465bd_f7a1ddf7","line":87,"updated":"2026-08-19 19:16:17.000000000","message":"This was a week ago, is that intentional?","commit_id":"80dae90437ac479e684d39aca1f09534529f3bed"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"cd6ecc69d46b4c262197db5c1a9432e0bdcd6920","unresolved":true,"context_lines":[{"line_number":84,"context_line":"    console interface immediately."},{"line_number":85,"context_line":""},{"line_number":86,"context_line":"errata_history:"},{"line_number":87,"context_line":"  - 2026-08-12 - Errata 2"},{"line_number":88,"context_line":"  - 2026-04-29 - Errata 1"},{"line_number":89,"context_line":"  - 2026-04-27 - Original Version"},{"line_number":90,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":4,"id":"3cc72315_ba630474","line":87,"in_reply_to":"a4e465bd_f7a1ddf7","updated":"2026-08-19 19:16:48.000000000","message":"Not really imo, let\u0027s update it","commit_id":"80dae90437ac479e684d39aca1f09534529f3bed"},{"author":{"_account_id":16643,"name":"Goutham Pacha Ravi","email":"gouthampravi@gmail.com","username":"gouthamr"},"change_message_id":"b1bfce803b2dbecf8cb42dd505023ee476b72d42","unresolved":true,"context_lines":[{"line_number":82,"context_line":"    35.0.1, 36.0.0, 37.0.0 and 38.0.0 releases; stable/2024.2 has since"},{"line_number":83,"context_line":"    been retired, so 26.1.6 can only be corrected by applying the"},{"line_number":84,"context_line":"    additional fix locally.\u0027"},{"line_number":85,"context_line":" "},{"line_number":86,"context_line":"errata_history:"},{"line_number":87,"context_line":"  - 2026-08-19 - Errata 2"},{"line_number":88,"context_line":"  - 2026-04-29 - Errata 1"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"e577645a_a7ffb7db","line":85,"updated":"2026-08-19 19:32:37.000000000","message":"stray whitespace; get it if you\u0027ve to do errata 3 :( :)","commit_id":"06a2f380c1bb0731a9709c0925af3167832a0401"}]}
