Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

spamassassin: 3.4.3 -> 3.4.4 #108559

Merged
merged 2 commits into from Jan 6, 2021
Merged

Conversation

alyssais
Copy link
Member

@alyssais alyssais commented Jan 6, 2021

Motivation for this change
Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option sandbox in nix.conf on non-NixOS linux)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Determined the impact on package closure size (by running nix path-info -S before and after)
  • Ensured that relevant documentation is up to date
  • Fits CONTRIBUTING.md.

Copy link
Member

@andir andir left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me. I couldn't test it as I've no setup using it and we are lacking a nixos test.

I'd appreciate if we could add references to the two CVEs fixed in the release:

2020-01-28: Apache SpamAssassin 3.4.4 has been released! Apache SpamAssassin 3.4.4 is primarily a security release. In this release, there are bug fixes for two CVEs:

CVE-2020-1931 for Nefarious rule configuration (.cf) files can be configured to run system commands with warnings.
CVE-2020-1930 for Nefarious rule configuration (.cf) files can be configured to run system commands with sa-compile.`

(might be worth backporting to 20.09 as well)

@SuperSandro2000
Copy link
Member

This is a semi-automatic executed nixpkgs-review which does not build all packages (e.g. lumo, tensorflow or pytorch)
If you find some bugs or got suggestions for further things to search or run please reach out to SuperSandro2000 on IRC.

Result of nixpkgs-review pr 108559 run on x86_64-linux 1

3 packages failed to build and are new build failures:
  • almanah: log was empty
  • evolution-ews: log was empty
  • gnome3.evolution: log was empty
1 package built:
  • spamassassin

My machine has no big-parallel to build evolution.

@SuperSandro2000
Copy link
Member

This is a semi-automatic executed nixpkgs-review which does not build all packages (e.g. lumo, tensorflow or pytorch)
If you find some bugs or got suggestions for further things to search or run please reach out to SuperSandro2000 on IRC.

Result of nixpkgs-review pr 108559 run on x86_64-darwin 1

1 package marked as broken and skipped:
  • almanah
1 package built:
  • spamassassin

@SuperSandro2000 SuperSandro2000 merged commit b3ebcdb into NixOS:master Jan 6, 2021
@lukegb lukegb added the 9.needs: port to stable A PR needs a backport to the stable release. label Jan 6, 2021
@erictapen
Copy link
Member

Backport in 4296e67.

@erictapen erictapen added 8.has: port to stable A PR already has a backport to the stable release. and removed 9.needs: port to stable A PR needs a backport to the stable release. labels Jan 12, 2021
@alyssais
Copy link
Member Author

alyssais commented Jan 14, 2021 via email

@alyssais alyssais deleted the spamassassin branch April 9, 2021 20:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants