From unknown Fri Aug 15 03:56:32 2025 X-Loop: help-debbugs@gnu.org Subject: [bug#73683] [PATCH] gnu: vips: Update to 8.15.3. [security fixes] Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Mon, 07 Oct 2024 22:07:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 73683 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 73683@debbugs.gnu.org Cc: Nicolas Graves X-Debbugs-Original-To: guix-patches@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.172833877230793 (code B ref -1); Mon, 07 Oct 2024 22:07:02 +0000 Received: (at submit) by debbugs.gnu.org; 7 Oct 2024 22:06:12 +0000 Received: from localhost ([127.0.0.1]:49183 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1sxvrn-00080b-Js for submit@debbugs.gnu.org; Mon, 07 Oct 2024 18:06:12 -0400 Received: from lists.gnu.org ([209.51.188.17]:58302) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1sxvrl-00080T-RU for submit@debbugs.gnu.org; Mon, 07 Oct 2024 18:06:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1sxvrc-0000uU-Cv for guix-patches@gnu.org; Mon, 07 Oct 2024 18:06:00 -0400 Received: from 2.mo581.mail-out.ovh.net ([87.98.143.68]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1sxvrZ-0007PH-L0 for guix-patches@gnu.org; Mon, 07 Oct 2024 18:06:00 -0400 Received: from director7.ghost.mail-out.ovh.net (unknown [10.108.9.148]) by mo581.mail-out.ovh.net (Postfix) with ESMTP id 4XMtWj6gQPz1KXT for ; Mon, 7 Oct 2024 22:05:53 +0000 (UTC) Received: from ghost-submission-55b549bf7b-947gt (unknown [10.111.182.119]) by director7.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 960DF1FE4D; Mon, 7 Oct 2024 22:05:53 +0000 (UTC) Received: from ngraves.fr ([37.59.142.99]) by ghost-submission-55b549bf7b-947gt with ESMTPSA id 1FgXOkBbBGekiBUAlyRhlg (envelope-from ); Mon, 07 Oct 2024 22:05:53 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-99G00366acfea8-0576-4cca-8423-62f0a9cb31df, 83E631236A2B63DF756DDFD3729F0B2EAC058DF1) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 From: Nicolas Graves Date: Tue, 8 Oct 2024 00:05:45 +0200 Message-ID: <20241007220550.6809-1-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 6575536933630042850 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdeftddgtdeiucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffogggtgfesthekredtredtjeenucfhrhhomheppfhitgholhgrshcuifhrrghvvghsuceonhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrqeenucggtffrrghtthgvrhhnpeelueehgfevfeevhffftdetgedugeevveehteeileeuueejhfegffetteffhffhvdenucffohhmrghinhepghhithhhuhgsrdgtohhmnecukfhppeduvdejrddtrddtrddupdekiedrvdegiedrudelrddvvddupdefjedrheelrddugedvrdelleenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepihhnvghtpeduvdejrddtrddtrddupdhmrghilhhfrhhomhepnhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrpdhnsggprhgtphhtthhopedupdhrtghpthhtohepghhuihigqdhprghttghhvghssehgnhhurdhorhhgpdfovfetjfhoshhtpehmohehkedupdhmohguvgepshhmthhpohhuth DKIM-Signature: a=rsa-sha256; bh=NWxBp89T29JaJ6COmjXvpAxTtZH+dvlsbYuqceNY52A=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1728338754; v=1; b=EFjQuqEU2cCoBPq6b8bPzAp/LZPbMfvAgs3F0X5wxUcTTtTyLMskpkqwLpcaSE6UJqfyBgKD zZkqpzDZQ19tl/Mc4gsRWRO8jSGR6b7mjaJ3HGelcD5Pc6cXbUJ+0KnmD9+VKe+4EfT7d3cSxMJ UZnFjK4O/xjXb8eAupqFBXxVZ8CAHZg1Ohw+AtrdWSYOHAbOmutcWv7NVxkr/rk5Wn8/B38Y5ya ng867vP9IS30yRkaiw+QOKk0eunPRjQlc1gT8r5n6MqoQAYfx0hvSgiCL6L+a1eZr0OIaoGA/az 9Tv3yVh9xtYXMlZX4G2hxqvaqoI67HGa4Ipw1MPsW4MmA== Received-SPF: pass client-ip=87.98.143.68; envelope-from=ngraves@ngraves.fr; helo=2.mo581.mail-out.ovh.net X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.3 (-) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.3 (--) This fixes CVE-2023-40032. * gnu/packages/image-processing.scm (vips): Update to 8.15.3. [build-system]: Switch to meson-build-system. [inputs]: Add glib:bin. --- gnu/packages/image-processing.scm | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/gnu/packages/image-processing.scm b/gnu/packages/image-processing.scm index 033e006d06..1a24837ac8 100644 --- a/gnu/packages/image-processing.scm +++ b/gnu/packages/image-processing.scm @@ -23,6 +23,7 @@ ;;; Copyright © 2022 Tomasz Jeneralczyk ;;; Copyright © 2022 Paul A. Patience ;;; Copyright © 2023 Cairn +;;; Copyright © 2024 Nicolas Graves ;;; ;;; This file is part of GNU Guix. ;;; @@ -49,6 +50,7 @@ (define-module (gnu packages image-processing) #:use-module (guix build-system qt) #:use-module (guix build-system cmake) #:use-module (guix build-system gnu) + #:use-module (guix build-system meson) #:use-module (guix build-system python) #:use-module (guix build-system pyproject) #:use-module (gnu packages) @@ -776,16 +778,16 @@ (define-public opencv (define-public vips (package (name "vips") - (version "8.13.1") + (version "8.15.3") (source (origin (method url-fetch) (uri (string-append "https://github.com/libvips/libvips/releases/download/v" - version "/vips-" version ".tar.gz")) + version "/vips-" version ".tar.xz")) (sha256 - (base32 "00kp3439jcqv9l2gcjg88xzvlq8clv54z1m3x66i3chvarz7ndxd")))) - (build-system gnu-build-system) + (base32 "182j20dw38f1nyfx8cf7cjsr0k4nl7lfk3wm2d0ddypa6vsxj9ry")))) + (build-system meson-build-system) (native-inputs (list gobject-introspection pkg-config)) (inputs @@ -793,6 +795,7 @@ (define-public vips fftw giflib glib + (list glib "bin") hdf5 imagemagick lcms -- 2.46.0 From unknown Fri Aug 15 03:56:32 2025 MIME-Version: 1.0 X-Mailer: MIME-tools 5.505 (Entity 5.505) X-Loop: help-debbugs@gnu.org From: help-debbugs@gnu.org (GNU bug Tracking System) To: Nicolas Graves Subject: bug#73683: closed (Re: [bug#73683] [PATCH] gnu: vips: Update to 8.15.3. [security fixes]) Message-ID: References: <87y12r5ssy.fsf@iscas.ac.cn> <20241007220550.6809-1-ngraves@ngraves.fr> X-Gnu-PR-Message: they-closed 73683 X-Gnu-PR-Package: guix-patches X-Gnu-PR-Keywords: patch Reply-To: 73683@debbugs.gnu.org Date: Mon, 14 Oct 2024 02:22:02 +0000 Content-Type: multipart/mixed; boundary="----------=_1728872522-31567-1" This is a multi-part message in MIME format... ------------=_1728872522-31567-1 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your bug report #73683: [PATCH] gnu: vips: Update to 8.15.3. [security fixes] which was filed against the guix-patches package, has been closed. The explanation is attached below, along with your original report. If you require more details, please reply to 73683@debbugs.gnu.org. --=20 73683: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=3D73683 GNU Bug Tracking System Contact help-debbugs@gnu.org with problems ------------=_1728872522-31567-1 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 73683-done) by debbugs.gnu.org; 14 Oct 2024 02:21:09 +0000 Received: from localhost ([127.0.0.1]:33732 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t0Aho-0008Ba-M5 for submit@debbugs.gnu.org; Sun, 13 Oct 2024 22:21:09 -0400 Received: from smtp84.cstnet.cn ([159.226.251.84]:42100 helo=cstnet.cn) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t0Ahl-0008AN-Ga for 73683-done@debbugs.gnu.org; Sun, 13 Oct 2024 22:21:07 -0400 Received: from m (unknown [107.174.64.25]) by APP-05 (Coremail) with SMTP id zQCowABHLWTvfwxnyAdBBw--.47938S2; Mon, 14 Oct 2024 10:20:38 +0800 (CST) From: Zheng Junjie To: Nicolas Graves via Guix-patches via Subject: Re: [bug#73683] [PATCH] gnu: vips: Update to 8.15.3. [security fixes] In-Reply-To: <20241007220550.6809-1-ngraves@ngraves.fr> (Nicolas Graves via Guix-patches via's message of "Tue, 8 Oct 2024 00:05:45 +0200") References: <20241007220550.6809-1-ngraves@ngraves.fr> Date: Mon, 14 Oct 2024 10:20:29 +0800 Message-ID: <87y12r5ssy.fsf@iscas.ac.cn> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-CM-TRANSID: zQCowABHLWTvfwxnyAdBBw--.47938S2 X-Coremail-Antispam: 1UD129KBjvJXoW7WFyUJr17Xw15CFy3KFyxuFg_yoW8urWfpa 4xAF1S9r18Gw4kXan2gFs2kr1ag39rtrW8u343Aw4xJw4avrZFkFW3tay3JF17A34fCw47 WryIq3WUWryUJrDanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUvGb7Iv0xC_Kw4lb4IE77IF4wAFF20E14v26r1j6r4UM7CY07I2 0VC2zVCF04k26cxKx2IYs7xG6rWj6s0DM7CIcVAFz4kK6r1j6r18M28lY4IEw2IIxxk0rw A2F7IY1VAKz4vEj48ve4kI8wA2z4x0Y4vE2Ix0cI8IcVAFwI0_Xr0_Ar1l84ACjcxK6xII jxv20xvEc7CjxVAFwI0_Gr0_Cr1l84ACjcxK6I8E87Iv67AKxVW8Jr0_Cr1UM28EF7xvwV C2z280aVCY1x0267AKxVWxJr0_GcWlnx0Ee4C267I2x7xF54xIwI0E7I0Y6sxI4wAS0I0E 0xvYzxvE52x082IY62kv0487M2AExVA0xI801c8C04v7Mc02F40EFcxC0VAKzVAqx4xG6I 80ewAv7VC0I7IYx2IY67AKxVWUGVWUXwAv7VC2z280aVAFwI0_Jr0_Gr1lOx8S6xCaFVCj c4AY6r1j6r4UM4x0Y48IcVAKI48JMxAIw28IcxkI7VAKI48JMxC20s026xCaFVCjc4AY6r 1j6r4UMI8I3I0E5I8CrVAFwI0_Jr0_Jr4lx2IqxVCjr7xvwVAFwI0_JrI_JrWlx4CE17CE b7AF67AKxVWUXVWUAwCIc40Y0x0EwIxGrwCI42IY6xIIjxv20xvE14v26r1j6r1xMIIF0x vE2Ix0cI8IcVCY1x0267AKxVWUJVW8JwCI42IY6xAIw20EY4v20xvaj40_Jr0_JF4lIxAI cVC2z280aVAFwI0_Jr0_Gr1lIxAIcVC2z280aVCY1x0267AKxVWUJVW8JbIYCTnIWIevJa 73UjIFyTuYvjxUh8u4DUUUU X-Originating-IP: [107.174.64.25] X-CM-SenderInfo: x2kh0wxmxqyx3h6l2u1dvotugofq/ X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 73683-done Cc: 73683-done@debbugs.gnu.org, Nicolas Graves X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Nicolas Graves via Guix-patches via writes: > This fixes CVE-2023-40032. > > * gnu/packages/image-processing.scm (vips): Update to 8.15.3. > [build-system]: Switch to meson-build-system. > [inputs]: Add glib:bin. > --- > gnu/packages/image-processing.scm | 11 +++++++---- > 1 file changed, 7 insertions(+), 4 deletions(-) > > diff --git a/gnu/packages/image-processing.scm b/gnu/packages/image-proce= ssing.scm > index 033e006d06..1a24837ac8 100644 > --- a/gnu/packages/image-processing.scm > +++ b/gnu/packages/image-processing.scm > @@ -23,6 +23,7 @@ > ;;; Copyright =C2=A9 2022 Tomasz Jeneralczyk > ;;; Copyright =C2=A9 2022 Paul A. Patience > ;;; Copyright =C2=A9 2023 Cairn > +;;; Copyright =C2=A9 2024 Nicolas Graves > ;;; > ;;; This file is part of GNU Guix. > ;;; > @@ -49,6 +50,7 @@ (define-module (gnu packages image-processing) > #:use-module (guix build-system qt) > #:use-module (guix build-system cmake) > #:use-module (guix build-system gnu) > + #:use-module (guix build-system meson) > #:use-module (guix build-system python) > #:use-module (guix build-system pyproject) > #:use-module (gnu packages) > @@ -776,16 +778,16 @@ (define-public opencv > (define-public vips > (package > (name "vips") > - (version "8.13.1") > + (version "8.15.3") > (source > (origin > (method url-fetch) > (uri (string-append > "https://github.com/libvips/libvips/releases/download/v" > - version "/vips-" version ".tar.gz")) > + version "/vips-" version ".tar.xz")) > (sha256 > - (base32 "00kp3439jcqv9l2gcjg88xzvlq8clv54z1m3x66i3chvarz7ndxd"))= )) > - (build-system gnu-build-system) > + (base32 "182j20dw38f1nyfx8cf7cjsr0k4nl7lfk3wm2d0ddypa6vsxj9ry"))= )) > + (build-system meson-build-system) > (native-inputs > (list gobject-introspection pkg-config)) > (inputs > @@ -793,6 +795,7 @@ (define-public vips > fftw > giflib > glib > + (list glib "bin") > hdf5 > imagemagick > lcms push, and add commit to fetch sources from git. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfr6klGDOXiwIdX/bO1qpk+Gi3/AFAmcMf+0ACgkQO1qpk+Gi 3/AeEA/9FVhJJhYScI6DG3M4yEICnwMfcu5bqhXoK067LxZBm/UXx68Gob9fpzJG aJvjrdjlAQ6NHrCG/bChac+sh9K1cDGLgu1luAPh4CslmWDf445BDIBeZmJEavL8 eUMEdZylCbAuBNyypRKUBjwgklLcuLoNghNRf83WiGcHAbzwYfPzcBYM6oCPLiZ0 TBQPAKGFhVJmtocsPh1TQEt1pYHZ9n7q6SCcBElUjpsxfwj4UasCnU+bLE5MzZC1 i9GfWrg03FgcjF+XDsrBiCx8sGy/LDB3ke9WS3S4/jt0Sd9K8b2GrvBSxcEZDWXj AA9m7wSilZcI/lbIZ871K6fD530/P4z7Wwp4IMpvsSLlmiGGUWdA0XKCmUcvwXrz xyPBJpsc9hGHF8lx/mnrsSyiwkMgG3zrTr8YajBZzX1Z/E1jThNqQ7hYEN4uPai2 +NYEACrI7x8hGzmA2sh1we4EGLZCZQoXzSQwj3HHp1RLlHqH4I8Hcz0wvmpmq64O 5ggsF64JMegqsjgRV+f+ADe0eQ0jvWwp25VMWz1s/13Uc7IFHhQdohVRjlHHN3Dk YIeWD/pBF01QxQFWEaL7XVexJVwlrQDGiCt8WwzUHwNu2zvepapUB/WBDxep4NN+ lqJVCUelScHDxfFqfZ+3AKsAE2qOTiB49kqyH9DK0dRq/y5v60Y= =SJMR -----END PGP SIGNATURE----- --=-=-=-- ------------=_1728872522-31567-1 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by debbugs.gnu.org; 7 Oct 2024 22:06:12 +0000 Received: from localhost ([127.0.0.1]:49183 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1sxvrn-00080b-Js for submit@debbugs.gnu.org; Mon, 07 Oct 2024 18:06:12 -0400 Received: from lists.gnu.org ([209.51.188.17]:58302) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1sxvrl-00080T-RU for submit@debbugs.gnu.org; Mon, 07 Oct 2024 18:06:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1sxvrc-0000uU-Cv for guix-patches@gnu.org; Mon, 07 Oct 2024 18:06:00 -0400 Received: from 2.mo581.mail-out.ovh.net ([87.98.143.68]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1sxvrZ-0007PH-L0 for guix-patches@gnu.org; Mon, 07 Oct 2024 18:06:00 -0400 Received: from director7.ghost.mail-out.ovh.net (unknown [10.108.9.148]) by mo581.mail-out.ovh.net (Postfix) with ESMTP id 4XMtWj6gQPz1KXT for ; Mon, 7 Oct 2024 22:05:53 +0000 (UTC) Received: from ghost-submission-55b549bf7b-947gt (unknown [10.111.182.119]) by director7.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 960DF1FE4D; Mon, 7 Oct 2024 22:05:53 +0000 (UTC) Received: from ngraves.fr ([37.59.142.99]) by ghost-submission-55b549bf7b-947gt with ESMTPSA id 1FgXOkBbBGekiBUAlyRhlg (envelope-from ); Mon, 07 Oct 2024 22:05:53 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-99G00366acfea8-0576-4cca-8423-62f0a9cb31df, 83E631236A2B63DF756DDFD3729F0B2EAC058DF1) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 From: Nicolas Graves To: guix-patches@gnu.org Subject: [PATCH] gnu: vips: Update to 8.15.3. [security fixes] Date: Tue, 8 Oct 2024 00:05:45 +0200 Message-ID: <20241007220550.6809-1-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 6575536933630042850 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdeftddgtdeiucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffogggtgfesthekredtredtjeenucfhrhhomheppfhitgholhgrshcuifhrrghvvghsuceonhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrqeenucggtffrrghtthgvrhhnpeelueehgfevfeevhffftdetgedugeevveehteeileeuueejhfegffetteffhffhvdenucffohhmrghinhepghhithhhuhgsrdgtohhmnecukfhppeduvdejrddtrddtrddupdekiedrvdegiedrudelrddvvddupdefjedrheelrddugedvrdelleenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepihhnvghtpeduvdejrddtrddtrddupdhmrghilhhfrhhomhepnhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrpdhnsggprhgtphhtthhopedupdhrtghpthhtohepghhuihigqdhprghttghhvghssehgnhhurdhorhhgpdfovfetjfhoshhtpehmohehkedupdhmohguvgepshhmthhpohhuth DKIM-Signature: a=rsa-sha256; bh=NWxBp89T29JaJ6COmjXvpAxTtZH+dvlsbYuqceNY52A=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1728338754; v=1; b=EFjQuqEU2cCoBPq6b8bPzAp/LZPbMfvAgs3F0X5wxUcTTtTyLMskpkqwLpcaSE6UJqfyBgKD zZkqpzDZQ19tl/Mc4gsRWRO8jSGR6b7mjaJ3HGelcD5Pc6cXbUJ+0KnmD9+VKe+4EfT7d3cSxMJ UZnFjK4O/xjXb8eAupqFBXxVZ8CAHZg1Ohw+AtrdWSYOHAbOmutcWv7NVxkr/rk5Wn8/B38Y5ya ng867vP9IS30yRkaiw+QOKk0eunPRjQlc1gT8r5n6MqoQAYfx0hvSgiCL6L+a1eZr0OIaoGA/az 9Tv3yVh9xtYXMlZX4G2hxqvaqoI67HGa4Ipw1MPsW4MmA== Received-SPF: pass client-ip=87.98.143.68; envelope-from=ngraves@ngraves.fr; helo=2.mo581.mail-out.ovh.net X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.3 (-) X-Debbugs-Envelope-To: submit Cc: Nicolas Graves X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.3 (--) This fixes CVE-2023-40032. * gnu/packages/image-processing.scm (vips): Update to 8.15.3. [build-system]: Switch to meson-build-system. [inputs]: Add glib:bin. --- gnu/packages/image-processing.scm | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/gnu/packages/image-processing.scm b/gnu/packages/image-processing.scm index 033e006d06..1a24837ac8 100644 --- a/gnu/packages/image-processing.scm +++ b/gnu/packages/image-processing.scm @@ -23,6 +23,7 @@ ;;; Copyright © 2022 Tomasz Jeneralczyk ;;; Copyright © 2022 Paul A. Patience ;;; Copyright © 2023 Cairn +;;; Copyright © 2024 Nicolas Graves ;;; ;;; This file is part of GNU Guix. ;;; @@ -49,6 +50,7 @@ (define-module (gnu packages image-processing) #:use-module (guix build-system qt) #:use-module (guix build-system cmake) #:use-module (guix build-system gnu) + #:use-module (guix build-system meson) #:use-module (guix build-system python) #:use-module (guix build-system pyproject) #:use-module (gnu packages) @@ -776,16 +778,16 @@ (define-public opencv (define-public vips (package (name "vips") - (version "8.13.1") + (version "8.15.3") (source (origin (method url-fetch) (uri (string-append "https://github.com/libvips/libvips/releases/download/v" - version "/vips-" version ".tar.gz")) + version "/vips-" version ".tar.xz")) (sha256 - (base32 "00kp3439jcqv9l2gcjg88xzvlq8clv54z1m3x66i3chvarz7ndxd")))) - (build-system gnu-build-system) + (base32 "182j20dw38f1nyfx8cf7cjsr0k4nl7lfk3wm2d0ddypa6vsxj9ry")))) + (build-system meson-build-system) (native-inputs (list gobject-introspection pkg-config)) (inputs @@ -793,6 +795,7 @@ (define-public vips fftw giflib glib + (list glib "bin") hdf5 imagemagick lcms -- 2.46.0 ------------=_1728872522-31567-1-- From unknown Fri Aug 15 03:56:32 2025 X-Loop: help-debbugs@gnu.org Subject: [bug#73683] [PATCH] gnu: vips: Update to 8.15.3. [security fixes] Resent-From: Zheng Junjie Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Mon, 14 Oct 2024 02:24:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 73683 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 73683@debbugs.gnu.org Cc: 73683-done@debbugs.gnu.org, Nicolas Graves X-Debbugs-Original-To: Nicolas Graves via Guix-patches via Received: via spool by submit@debbugs.gnu.org id=B.172887260631796 (code B ref -1); Mon, 14 Oct 2024 02:24:01 +0000 Received: (at submit) by debbugs.gnu.org; 14 Oct 2024 02:23:26 +0000 Received: from localhost ([127.0.0.1]:33742 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t0Ak1-0008Gm-Of for submit@debbugs.gnu.org; Sun, 13 Oct 2024 22:23:26 -0400 Received: from lists.gnu.org ([209.51.188.17]:36060) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t0Ajy-0008Gd-T3 for submit@debbugs.gnu.org; Sun, 13 Oct 2024 22:23:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t0Ahb-0001Og-6C for guix-patches@gnu.org; Sun, 13 Oct 2024 22:20:55 -0400 Received: from smtp84.cstnet.cn ([159.226.251.84] helo=cstnet.cn) by eggs.gnu.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1t0AhX-00075n-MB for guix-patches@gnu.org; Sun, 13 Oct 2024 22:20:54 -0400 Received: from m (unknown [107.174.64.25]) by APP-05 (Coremail) with SMTP id zQCowABHLWTvfwxnyAdBBw--.47938S2; Mon, 14 Oct 2024 10:20:38 +0800 (CST) From: Zheng Junjie In-Reply-To: <20241007220550.6809-1-ngraves@ngraves.fr> (Nicolas Graves via Guix-patches via's message of "Tue, 8 Oct 2024 00:05:45 +0200") References: <20241007220550.6809-1-ngraves@ngraves.fr> Date: Mon, 14 Oct 2024 10:20:29 +0800 Message-ID: <87y12r5ssy.fsf@iscas.ac.cn> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-CM-TRANSID: zQCowABHLWTvfwxnyAdBBw--.47938S2 X-Coremail-Antispam: 1UD129KBjvJXoW7WFyUJr17Xw15CFy3KFyxuFg_yoW8urWfpa 4xAF1S9r18Gw4kXan2gFs2kr1ag39rtrW8u343Aw4xJw4avrZFkFW3tay3JF17A34fCw47 WryIq3WUWryUJrDanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUvGb7Iv0xC_Kw4lb4IE77IF4wAFF20E14v26r1j6r4UM7CY07I2 0VC2zVCF04k26cxKx2IYs7xG6rWj6s0DM7CIcVAFz4kK6r1j6r18M28lY4IEw2IIxxk0rw A2F7IY1VAKz4vEj48ve4kI8wA2z4x0Y4vE2Ix0cI8IcVAFwI0_Xr0_Ar1l84ACjcxK6xII jxv20xvEc7CjxVAFwI0_Gr0_Cr1l84ACjcxK6I8E87Iv67AKxVW8Jr0_Cr1UM28EF7xvwV C2z280aVCY1x0267AKxVWxJr0_GcWlnx0Ee4C267I2x7xF54xIwI0E7I0Y6sxI4wAS0I0E 0xvYzxvE52x082IY62kv0487M2AExVA0xI801c8C04v7Mc02F40EFcxC0VAKzVAqx4xG6I 80ewAv7VC0I7IYx2IY67AKxVWUGVWUXwAv7VC2z280aVAFwI0_Jr0_Gr1lOx8S6xCaFVCj c4AY6r1j6r4UM4x0Y48IcVAKI48JMxAIw28IcxkI7VAKI48JMxC20s026xCaFVCjc4AY6r 1j6r4UMI8I3I0E5I8CrVAFwI0_Jr0_Jr4lx2IqxVCjr7xvwVAFwI0_JrI_JrWlx4CE17CE b7AF67AKxVWUXVWUAwCIc40Y0x0EwIxGrwCI42IY6xIIjxv20xvE14v26r1j6r1xMIIF0x vE2Ix0cI8IcVCY1x0267AKxVWUJVW8JwCI42IY6xAIw20EY4v20xvaj40_Jr0_JF4lIxAI cVC2z280aVAFwI0_Jr0_Gr1lIxAIcVC2z280aVCY1x0267AKxVWUJVW8JbIYCTnIWIevJa 73UjIFyTuYvjxUh8u4DUUUU X-Originating-IP: [107.174.64.25] X-CM-SenderInfo: x2kh0wxmxqyx3h6l2u1dvotugofq/ Received-SPF: pass client-ip=159.226.251.84; envelope-from=zhengjunjie@iscas.ac.cn; helo=cstnet.cn X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.4 (-) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.4 (--) --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Nicolas Graves via Guix-patches via writes: > This fixes CVE-2023-40032. > > * gnu/packages/image-processing.scm (vips): Update to 8.15.3. > [build-system]: Switch to meson-build-system. > [inputs]: Add glib:bin. > --- > gnu/packages/image-processing.scm | 11 +++++++---- > 1 file changed, 7 insertions(+), 4 deletions(-) > > diff --git a/gnu/packages/image-processing.scm b/gnu/packages/image-proce= ssing.scm > index 033e006d06..1a24837ac8 100644 > --- a/gnu/packages/image-processing.scm > +++ b/gnu/packages/image-processing.scm > @@ -23,6 +23,7 @@ > ;;; Copyright =C2=A9 2022 Tomasz Jeneralczyk > ;;; Copyright =C2=A9 2022 Paul A. Patience > ;;; Copyright =C2=A9 2023 Cairn > +;;; Copyright =C2=A9 2024 Nicolas Graves > ;;; > ;;; This file is part of GNU Guix. > ;;; > @@ -49,6 +50,7 @@ (define-module (gnu packages image-processing) > #:use-module (guix build-system qt) > #:use-module (guix build-system cmake) > #:use-module (guix build-system gnu) > + #:use-module (guix build-system meson) > #:use-module (guix build-system python) > #:use-module (guix build-system pyproject) > #:use-module (gnu packages) > @@ -776,16 +778,16 @@ (define-public opencv > (define-public vips > (package > (name "vips") > - (version "8.13.1") > + (version "8.15.3") > (source > (origin > (method url-fetch) > (uri (string-append > "https://github.com/libvips/libvips/releases/download/v" > - version "/vips-" version ".tar.gz")) > + version "/vips-" version ".tar.xz")) > (sha256 > - (base32 "00kp3439jcqv9l2gcjg88xzvlq8clv54z1m3x66i3chvarz7ndxd"))= )) > - (build-system gnu-build-system) > + (base32 "182j20dw38f1nyfx8cf7cjsr0k4nl7lfk3wm2d0ddypa6vsxj9ry"))= )) > + (build-system meson-build-system) > (native-inputs > (list gobject-introspection pkg-config)) > (inputs > @@ -793,6 +795,7 @@ (define-public vips > fftw > giflib > glib > + (list glib "bin") > hdf5 > imagemagick > lcms push, and add commit to fetch sources from git. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfr6klGDOXiwIdX/bO1qpk+Gi3/AFAmcMf+0ACgkQO1qpk+Gi 3/AeEA/9FVhJJhYScI6DG3M4yEICnwMfcu5bqhXoK067LxZBm/UXx68Gob9fpzJG aJvjrdjlAQ6NHrCG/bChac+sh9K1cDGLgu1luAPh4CslmWDf445BDIBeZmJEavL8 eUMEdZylCbAuBNyypRKUBjwgklLcuLoNghNRf83WiGcHAbzwYfPzcBYM6oCPLiZ0 TBQPAKGFhVJmtocsPh1TQEt1pYHZ9n7q6SCcBElUjpsxfwj4UasCnU+bLE5MzZC1 i9GfWrg03FgcjF+XDsrBiCx8sGy/LDB3ke9WS3S4/jt0Sd9K8b2GrvBSxcEZDWXj AA9m7wSilZcI/lbIZ871K6fD530/P4z7Wwp4IMpvsSLlmiGGUWdA0XKCmUcvwXrz xyPBJpsc9hGHF8lx/mnrsSyiwkMgG3zrTr8YajBZzX1Z/E1jThNqQ7hYEN4uPai2 +NYEACrI7x8hGzmA2sh1we4EGLZCZQoXzSQwj3HHp1RLlHqH4I8Hcz0wvmpmq64O 5ggsF64JMegqsjgRV+f+ADe0eQ0jvWwp25VMWz1s/13Uc7IFHhQdohVRjlHHN3Dk YIeWD/pBF01QxQFWEaL7XVexJVwlrQDGiCt8WwzUHwNu2zvepapUB/WBDxep4NN+ lqJVCUelScHDxfFqfZ+3AKsAE2qOTiB49kqyH9DK0dRq/y5v60Y= =SJMR -----END PGP SIGNATURE----- --=-=-=--