This repository was archived by the owner on Apr 12, 2021. It is now read-only.
-
-
Notifications
You must be signed in to change notification settings - Fork 104
Permalink
Choose a base ref
{{ refName }}
default
Choose a head ref
{{ refName }}
default
Comparing changes
Choose two branches to see what’s changed or to start a new pull request.
If you need to, you can also or
learn more about diff comparisons.
Open a pull request
Create a new pull request by comparing changes across two branches. If you need to, you can also .
Learn more about diff comparisons here.
base repository: NixOS/nixpkgs-channels
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 526b34a18e0b
Could not load branches
Nothing to show
Loading
Could not load tags
Nothing to show
{{ refName }}
default
Loading
...
head repository: NixOS/nixpkgs-channels
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: ea0820818a7b
Could not load branches
Nothing to show
Loading
Could not load tags
Nothing to show
{{ refName }}
default
Loading
- 20 commits
- 25 files changed
- 9 contributors
Commits on Jan 30, 2019
-
(cherry picked from commit 776c962)
Configuration menu - View commit details
-
Copy full SHA for fc0c9a2 - Browse repository at this point
Copy the full SHA fc0c9a2View commit details -
qt59.qtvirtualkeyboard: fix CVE-2018-19865
CVE-2018-19865 tracks the issue of qtvirtualkeyboard where it logs all user input. With this commit we are applying the recommended patches form the upstream project. More details can be obtained from the Qt annoucement [1]. [1] https://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ (cherry picked from commit 6660128)
Configuration menu - View commit details
-
Copy full SHA for 0d6c4a8 - Browse repository at this point
Copy the full SHA 0d6c4a8View commit details
Commits on Feb 2, 2019
-
qt56.qtvirtualkeyboard: init at 5.6.3
This adds the "missing" qtvirtualkeyboard module of qt56. I just add this so I can apply (& test) the patches for a CVE in the next commit. This might seem strange but in case anyone decided to add / use this in the future we are on the safe(r) side. (cherry picked from commit 295a210)
Configuration menu - View commit details
-
Copy full SHA for a3c82b9 - Browse repository at this point
Copy the full SHA a3c82b9View commit details -
qt56: fix CVE-2018-{15518,19873,19870,19871,19865,19869}
* CVE-2018-15518, Qt Base: “double free or corruption” in QXmlStreamReader * CVE-2018-19873, Qt Base: QBmpHandler segfault on malformed BMP file * CVE-2018-19870, Qt Base: Check for QImage allocation failure in qgifhandler * CVE-2018-19871, Qt Imageformats: QImage: QTgaFile CPU exhaustion * CVE-2018-19865, Qt Virtual Keyboard: Qt Virtual Keyboard logs all key presses * CVE-2018-19869, Qt Svg: Fix crash when parsing malformed url reference More details can be obtained from the Qt annoucement [1]. [1] https://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ (cherry picked from commit 066be85)
Configuration menu - View commit details
-
Copy full SHA for 0948f87 - Browse repository at this point
Copy the full SHA 0948f87View commit details -
This fixes * CVE-2018-15518, Qt Base: “double free or corruption” in QXmlStreamReader * CVE-2018-19873, Qt Base: QBmpHandler segfault on malformed BMP file * CVE-2018-19870, Qt Base: Check for QImage allocation failure in qgifhandler * CVE-2018-19871, Qt Imageformats: QImage: QTgaFile CPU exhaustion * CVE-2018-19865, Qt Virtual Keyboard: Qt Virtual Keyboard logs all key presses * CVE-2018-19869, Qt Svg: Fix crash when parsing malformed url reference More details can be obtained from the Qt annoucement [1]. [1] https://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ (cherry picked from commit 2f5d37b)
Configuration menu - View commit details
-
Copy full SHA for 89049f3 - Browse repository at this point
Copy the full SHA 89049f3View commit details -
Configuration menu - View commit details
-
Copy full SHA for 1e2c3be - Browse repository at this point
Copy the full SHA 1e2c3beView commit details
Commits on Feb 15, 2019
-
Configuration menu - View commit details
-
Copy full SHA for 657d92e - Browse repository at this point
Copy the full SHA 657d92eView commit details -
Configuration menu - View commit details
-
Copy full SHA for cd88dcb - Browse repository at this point
Copy the full SHA cd88dcbView commit details
Commits on Feb 16, 2019
-
qt511: add patch for macOS sdk
Unfortunately we don’t have access to NSWindowStyleMask. These patches should go away once we switch to a newer SDK. (cherry picked from commit 8153104)
Configuration menu - View commit details
-
Copy full SHA for 82434e7 - Browse repository at this point
Copy the full SHA 82434e7View commit details -
CVE-2018-0734: https://www.openssl.org/news/vulnerabilities.html#2018-0734 CVE-2018-5407: https://www.openssl.org/news/vulnerabilities.html#2018-5407 No patches can any longer be shared between 1.0.2 and 1.1, so reorganize patches into subdirectories (and remove an unused one). (cherry picked from commit ae29a9e)
Configuration menu - View commit details
-
Copy full SHA for 9c75f20 - Browse repository at this point
Copy the full SHA 9c75f20View commit details -
Configuration menu - View commit details
-
Copy full SHA for d7225e0 - Browse repository at this point
Copy the full SHA d7225e0View commit details -
Configuration menu - View commit details
-
Copy full SHA for fe00e77 - Browse repository at this point
Copy the full SHA fe00e77View commit details -
Configuration menu - View commit details
-
Copy full SHA for 7892372 - Browse repository at this point
Copy the full SHA 7892372View commit details -
Configuration menu - View commit details
-
Copy full SHA for af6b20c - Browse repository at this point
Copy the full SHA af6b20cView commit details -
(cherry picked from commit 04a1f84)
Configuration menu - View commit details
-
Copy full SHA for 19a0543 - Browse repository at this point
Copy the full SHA 19a0543View commit details
Commits on Feb 17, 2019
-
Merge branch 'staging-18.09' into release-18.09
Security updates for qt5* and openssl. We can't afford to wait for darwin rebuild - it would take far too long.
Configuration menu - View commit details
-
Copy full SHA for f4ddc31 - Browse repository at this point
Copy the full SHA f4ddc31View commit details -
adoptopenjdk: pick expression structure from master
They seem to be uninteresting changes just hindering backports of version bumps.
Configuration menu - View commit details
-
Copy full SHA for a332973 - Browse repository at this point
Copy the full SHA a332973View commit details -
Merge #54576: adoptopenjdk-bin: 11.0.1 -> 11.0.2
Includes security fixes. (cherry picked from commit 94b518f)
Configuration menu - View commit details
-
Copy full SHA for ef02c63 - Browse repository at this point
Copy the full SHA ef02c63View commit details -
Configuration menu - View commit details
-
Copy full SHA for 347bccc - Browse repository at this point
Copy the full SHA 347bcccView commit details -
Merge pull request #55949 from eadwu/backports/20190217
[18.09] vscode backports - 2019-02-17
Configuration menu - View commit details
-
Copy full SHA for ea08208 - Browse repository at this point
Copy the full SHA ea08208View commit details
There are no files selected for viewing