-
-
Notifications
You must be signed in to change notification settings - Fork 104
Comparing changes
Open a pull request
base repository: NixOS/nixpkgs-channels
base: 520c39049f58
head repository: NixOS/nixpkgs-channels
compare: 776d66ec1156
- 7 commits
- 4 files changed
- 5 contributors
Commits on Aug 15, 2019
-
qt4: Vendor bitrotted Arch Linux patch
It is no longer found at this URL. Vendoring until a better solution comes along. Fixes #63084
Configuration menu - View commit details
-
Copy full SHA for 280795c - Browse repository at this point
Copy the full SHA 280795cView commit details -
Merge pull request #66685 from obsidiansystems/missing-qt-patch
qt4: Vendor bitrotted Arch Linux patch -- for 19.03
Configuration menu - View commit details
-
Copy full SHA for 6f7aca8 - Browse repository at this point
Copy the full SHA 6f7aca8View commit details -
icedtea_web: 1.7.1 -> 1.7.2 (plus CVE patches)
On Wed, 31 Jul 2019 it was announced that IcedTea-Web was affected by the below security vulnerabilities: - CVE-2019-10185: zip-slip attack during auto-extraction of a JAR file. - CVE-2019-10181: executable code could be injected in a JAR file without compromising the signature verification. - CVE-2019-10182: improper path sanitization from elements in JNLP files. Version 1.7 was patched, but no release was made. Moreover, the patches apply cleanly only to 1.7.2, not the current 1.7.1. Rather than marking 1.7.1 as insecure, update to 1.7.2 and apply the official patches. References: https://www.openwall.com/lists/oss-security/2019/07/31/2 AdoptOpenJDK/IcedTea-Web#327 AdoptOpenJDK/IcedTea-Web#346
Configuration menu - View commit details
-
Copy full SHA for f864ddf - Browse repository at this point
Copy the full SHA f864ddfView commit details -
icedtea-web: use glib build input instead of gtk2
gtk2 is not needed any more
Configuration menu - View commit details
-
Copy full SHA for eb01d7a - Browse repository at this point
Copy the full SHA eb01d7aView commit details -
icedtea-web: remove sh extension from launchers for back compat
icedtea-web 1.7.2 builds its launchers shell scripts with the "sh" extension, while version 1.7.1 did not. For backwards-compatibility, remove the extension from the executable in postInstall. Note that version 1.7.2 also creates a file called itw-modularjdk.args in the bin directory. This file is referenced by the shell launchers, so we leave it there (it's not executable anyway).
Configuration menu - View commit details
-
Copy full SHA for fc78b41 - Browse repository at this point
Copy the full SHA fc78b41View commit details -
Merge pull request #66444 from stefano-m/icedtea-web-1.7.2-cvefixes
icedtea_web: 1.7.1 -> 1.7.2 (plus CVE patches)
Configuration menu - View commit details
-
Copy full SHA for e36f91f - Browse repository at this point
Copy the full SHA e36f91fView commit details
Commits on Aug 16, 2019
-
systemd-networkd: link: Name -> OriginalName
(cherry picked from commit aa251bb)
Configuration menu - View commit details
-
Copy full SHA for 776d66e - Browse repository at this point
Copy the full SHA 776d66eView commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff 520c39049f58...776d66ec1156