-
Type: Task
-
Resolution: Fixed
-
Priority: Major - P3
-
Affects Version/s: None
-
Component/s: kerberos
BinSkim (a Microsoft binary analyzer) has identified that kerberos.js is missing Spectre mitigation and control flow guard flags.
Spectre mitigation docs: https://learn.microsoft.com/en-us/cpp/build/reference/qspectre?view=msvc-170
Control flow guard docs: https://learn.microsoft.com/en-us/cpp/build/reference/guard-enable-guard-checks?view=msvc-170
This issue affects the compliance of Visual Studio Code downstream and the general security of the binary, and is a continuation of https://github.com/mongodb-js/kerberos/pull/158.
- causes
-
MONGOSH-1881 Bump kerberos to latest
- Waiting (Blocked)