Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[20.09] home-assistant: mark as insecure #110848

Merged
merged 1 commit into from Jan 26, 2021

Conversation

dotlambda
Copy link
Member

Motivation for this change

The package from nixos-unstable should be used instead.

Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option sandbox in nix.conf on non-NixOS linux)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Determined the impact on package closure size (by running nix path-info -S before and after)
  • Ensured that relevant documentation is up to date
  • Fits CONTRIBUTING.md.

The package from nixos-unstable should be used instead.
@mweinelt
Copy link
Member

mweinelt commented Jan 26, 2021

The home-assistant package is not insecure by itself, it requires vulnerable third-party components, which are not even packaged in nixpkgs, to be installed, to be vulnerable. I guess it is fine to make endusers aware of that blog post and acknowledge it by permitting it explicitly.

The upstream added a few heuristics¹ in 2021.1.3 to prevent obvious abuse, but also most of the vulnerabilities found in those third-party components have been addressed. I wonder if we should just try and backport the patch instead? On second thought, this does not seem like a sensible idea. Nobody should really rely on the stable home-assistant package.

[1] https://patch-diff.githubusercontent.com/raw/home-assistant/core/pull/45179.patch

@mweinelt mweinelt merged commit 14e24e0 into NixOS:release-20.09 Jan 26, 2021
@dotlambda dotlambda deleted the home-assistant-insecure branch January 26, 2021 15:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants