Closed Bug 1211587 Opened 5 years ago Closed 5 years ago

upgrade mozilla 43 aurora to nspr 4.10.10 and nss 3.20.1 on october 16 (release candidate first, final on october 19)

Categories

(Core :: Security: PSM, defect)

43 Branch
defect
Not set
critical

Tracking

()

RESOLVED FIXED
Tracking Status
firefox43 + fixed

People

(Reporter: KaiE, Unassigned)

References

Details

(Keywords: meta, sec-other, Whiteboard: [post-critsmash-triage][adv-main43-])

Attachments

(1 file)

These NSPR and NSS upgrades are driven by the bugs listed in the dependency list, which are under embargo.

We intend to land these patches into public NSS repository on October 15, and immediately afterwards into mozilla-inbound/central, for initial testing using the Firefox test automation.

We should be ready to land release candidates of NSPR/NSS into the Firefox branch on October 16, and if it works fine, declare the final NSPR/NSS releases and land them into the Firefox branch by October 19.


We're trying to land these patches as late as possible, but because you'll need time for Firefox release preparation, and testing of final Firefox builds, we're planning to do so two weeks prior to the scheduled November 3rd release date.


Please let me know if this plan doesn't work for you.
Attached file placeholder-1211587
[Approval Request Comment]
fix critical security issues in NSPR and NSS

Could you please approve by to October 15? Thank you.
Attachment #8669837 - Flags: approval-mozilla-aurora?
Group: crypto-core-security → core-security-release
Keywords: meta, sec-other
Attachment #8669837 - Flags: approval-mozilla-aurora? → approval-mozilla-aurora+
https://hg.mozilla.org/releases/mozilla-aurora/rev/c02736eb4d23

Note these are release candidates.
The final tags (plus the change to bump configure.in) are expected to land on Monday,
hopefully without any code changes.
https://hg.mozilla.org/releases/mozilla-aurora/rev/542dfaef09d0
Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED
Whiteboard: [post-critsmash-triage]
Whiteboard: [post-critsmash-triage] → [post-critsmash-triage][adv-main43-]
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.