You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Sugar CLI v2.8.0 release binary incorrectly reports itself as v2.7.2 when running sugar -V, despite being a different binary from the actual v2.7.2 release.
## Environment
- OS: Manjaro Linux (Rolling)
- Kernel: Linux 6.6.54-2-MANJARO x86_64
- Shell: zsh (/usr/bin/zsh)
- Architecture: x86_64 GNU/Linux
- Installation method: Both direct download and installer script
Investigation Steps Taken
Initial state check:
bash
$ sugar -V
sugar-cli 2.7.2
Checked all possible cargo/sugar config locations:
Rationale:
This affects Candy Machine, which is a Tier 2 program. It's a functional issue that could affect deployments and operations. Could cause confusion in production environments. Most importantly, it indicates a potential build/release process issue that could mask more serious problems.
The screenshots affect the security reporting process itself, which is critical for the bug bounty program.
Issue description
Description
The Sugar CLI v2.8.0 release binary incorrectly reports itself as v2.7.2 when running
sugar -V
, despite being a different binary from the actual v2.7.2 release.Investigation Steps Taken
Additional System Context
PS Bonus issue in screenshot when I tried to email [email protected]
PS BONUS BONUS ISSUE
Email html link does not go to the email users will see
Solana wallet if this is worth anything to the team:
W3kTfwdyGoT48Hy5iSNY9gRuYAsQ6SNrysso17e77ZF
Relevant log output
No response
Priority this issue should have
Low (slightly annoying)
The text was updated successfully, but these errors were encountered: