Please update libcurl

You currently ship libcurl 8.2.1 with your seadrive and seafile clients.

There are 29 security vulnerabilities in that version.

Would you please update libcurl to the latest version? Thank you!

Thanks for reporting the issue.

The fix is included in seafile client 9.0.19.

Thank you for updating it.

Sadly, there are already new critical vulnerabilities found in version 8.20 of libcurl :sweat_smile: . I don’t know your ci/cd pipeline, your build process and how you have to test newer versions of the dependencies, but maybe you could implement it that way, so you always ship the latest minor version in your seadrive / seafile clients? There normally shouldn’t be any breaking changes.

That would help a lot especially for users who have to act on found vulnerabilites in their environment. In my case I simply build a job in our automation tool and replace the older dll with the latest one. Works fine for the file and drive clients but is much more work than simply deploying the latest msi file.

Would be great if you could find a solution for this. If not, no worries. Thank you!

We’ll update libcurl again in the next version. In general we think it’s better to keep third-party libraries stable. In the future we’ll check third-party library versions about twice per year, to keep a good balance between security and stability.