Skip to content
This repository has been archived by the owner on Apr 12, 2021. It is now read-only.
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: NixOS/nixpkgs-channels
base: ffe35783f524
Choose a base ref
...
head repository: NixOS/nixpkgs-channels
compare: 063546478304
Choose a head ref
  • 2 commits
  • 2 files changed
  • 2 contributors

Commits on Dec 11, 2019

  1. gitlab: 12.5.3 -> 12.5.4

    https://about.gitlab.com/blog/2019/12/10/critical-security-release-gitlab-12-5-4-released/
    
    Insufficient parameter sanitization for Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions. The issue is now mitigated in the latest release and is assigned CVE-2019-19628.
    
    When transferring a public project to a private group, private code would be disclosed via the Group Search API provided by Elasticsearch integration. The issue is now mitigated in the latest release and is assigned CVE-2019-19629.
    
    The Git dependency has been upgraded to 2.22.2 in order to apply security fixes detailed here.
    
    CVE-2019-19604 was identified by the GitLab Security Research team. For more information on that issue, please visit the GitLab Security Research Advisory
    
    closes #75506.
    
    (cherry picked from commit 5bf07d6)
    flokli committed Dec 11, 2019
    Copy the full SHA
    4651952 View commit details
    Browse the repository at this point in the history
  2. matomo: 3.11 -> 3.13

    backport of #74319 without the file consistency checks.
    3.12 was rated a major security update but was broken for NixOS, therefore jump to 3.13 which incorporates the necessary fix.
    florianjacob authored and FRidh committed Dec 11, 2019
    Copy the full SHA
    0635464 View commit details
    Browse the repository at this point in the history