From ce27cfc49f61459abdb74536dc4f01c1abb7e17f Mon Sep 17 00:00:00 2001 From: Anastassios Nanos Date: Sat, 26 Sep 2026 12:37:08 +0300 Subject: [PATCH] fix(bundle): Carry brig v0.3.0 A direct install from this repository's install.sh gets the brig the bundle carries, and v0.1.0-rc10 carries brig v0.2.0. brig v0.3.0 is released, and 0.2.0 is in the affected range of GHSA-wp6x-29qx-fpr7. brig's own install.sh replaces the bundle's brig with the release it installs, so only the direct path is behind. Signed-off-by: Anastassios Nanos --- scripts/build-bundle.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/build-bundle.sh b/scripts/build-bundle.sh index 63e408a..09504e9 100755 --- a/scripts/build-bundle.sh +++ b/scripts/build-bundle.sh @@ -91,7 +91,7 @@ done # The brig release this bundle carries. On Linux it is the brig a user gets, # so it is pinned like every other component. Bump it with the brig release a # bundle is cut for. BRIG_VERSION=latest still works for a local build. -BRIG_VERSION="${BRIG_VERSION:-v0.2.0}" +BRIG_VERSION="${BRIG_VERSION:-v0.3.0}" BRIG_REPO="${BRIG_REPO:-brig-sh/brig}" # urunc and urunit have no release that carries what brig needs, so they are # built from source, and the source is pinned to one commit each. A branch tip