guix-patches
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[bug#31487] [PATCH] gnu: Add upx.


From: Pierre Neidhardt
Subject: [bug#31487] [PATCH] gnu: Add upx.
Date: Sun, 27 May 2018 15:46:48 +0200
User-agent: mu4e 1.0; emacs 26.1

Ludovic Courtès <address@hidden> writes:

> There’s one issue left though:
>
>   $ ./pre-inst-env guix lint upx
>   gnu/packages/compression.scm:2179:2: address@hidden: probably vulnerable to 
> CVE-2017-15056, CVE-2017-16869
>
> Could you check whether patches are available for these?  Better be safe
> than sorry!

Indeed they are.
They are not on the master branch though, only devel I think.
So what's the protocol here?  Shall we cherry-pick the fixing commits or
get latest devel?

-- 
Pierre Neidhardt

The day advanced as if to light some work of mine; it was morning,
and lo! now it is evening, and nothing memorable is accomplished.
                -- H.D. Thoreau

Attachment: signature.asc
Description: PGP signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]