Navigation Menu

Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vorbis-tools: 1.4.0 -> 1.4.2 #109242

Merged
merged 1 commit into from Feb 6, 2021
Merged

Conversation

ajs124
Copy link
Member

@ajs124 ajs124 commented Jan 13, 2021

Motivation for this change

Closes #56371

The upstream issue @vcunat created, calling for a new release after a literal decade, was closed and this commit says 1.4.1 is now released.

Some of the debian patches stopped applying, but I'm not sure if all of them can be dropped. Debian hasn't updated (and accroding to repology nobody else either), so we can't just follow what they're doing, right now.

Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option sandbox in nix.conf on non-NixOS linux)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Determined the impact on package closure size (by running nix path-info -S before and after)
  • Ensured that relevant documentation is up to date
  • Fits CONTRIBUTING.md.

@vcunat
Copy link
Member

vcunat commented Jan 13, 2021

The point of taking all debian patches was the simplicity of addressing all the vulnerabilities. I haven't checked that all have been fixed upstream (so far), but I'd hope so.

@LeSuisse
Copy link
Contributor

It looks like vorbis-tools 1.4.2 has been properly released: https://ftp.osuosl.org/pub/xiph/releases/vorbis/vorbis-tools-1.4.2.tar.gz

@ajs124 ajs124 changed the title vorbis-tools: 1.4.0 -> 1.4.1 vorbis-tools: 1.4.0 -> 1.4.2 Jan 27, 2021
@ajs124 ajs124 marked this pull request as ready for review January 27, 2021 17:05
Copy link
Member

@vcunat vcunat left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes seem quite "safe". Overall we seem to have few reverse dependencies, and I don't expect more reviews will come here...

@vcunat vcunat merged commit cf8ad5e into NixOS:master Feb 6, 2021
@ajs124 ajs124 deleted the upd/vorbis-tools branch February 6, 2021 16:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Vulnerability roundup 62: vorbis-tools-1.4.0: 5 advisories
3 participants