-
-
Notifications
You must be signed in to change notification settings - Fork 14.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
hdf5: 1.10.6 -> 1.10.7 #111313
hdf5: 1.10.6 -> 1.10.7 #111313
Conversation
/rebase-staging |
Actually I am not sure if this should go through staging but over 500 rebuilds when hydra has issues seems a bit much. |
712540c
to
455ea0d
Compare
For security updates one could make an exception and bypass staging. However, nixpkgs-review shows ~900 rebuilds, probably making staging the right call. |
Does anyone know? |
Does not fix. https://repology.org/project/hdf5/cves?version=1.12.0 |
Maybe the maintainers can update to a version > 1.12.0 after this is merged. |
There is no version > 1.12.0. |
Yeah I think it's very unlikely it fixes CVE-2020-10809 - |
Looking more broadly, I don't think that CVE has been fixed anywhere, even in hdf |
Marking it as insecure will impact a very high number of packages. What should we do? |
I opened an upstream issue. I think we should merge this and discuss the remaining CVEs in the issue linked above. |
What needs to be done to get this merged? |
hdf5 builds locally fine. Note:
|
Motivation for this change
fix CVE-2018-13870, CVE-2018-13869, CVE-2018-17438, and CVE-2018-17435 (see https://github.com/HDFGroup/hdf5/blob/hdf5-1_10_7/release_docs/RELEASE.txt)
I'm not sure if this fixes the vulnerabilities mentioned in #88322.
Things done
sandbox
innix.conf
on non-NixOS linux)nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
./result/bin/
)nix path-info -S
before and after)cc @tviti @ttuegel @markuskowa