From unknown Tue Sep 09 18:21:51 2025 X-Loop: help-debbugs@gnu.org Subject: [bug#74050] [PATCH 0/6] Add lint-hidden-cve property for near-leaf packages. Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sun, 27 Oct 2024 18:26:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 74050 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 74050@debbugs.gnu.org Cc: Nicolas Graves X-Debbugs-Original-To: guix-patches@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.173005350913815 (code B ref -1); Sun, 27 Oct 2024 18:26:02 +0000 Received: (at submit) by debbugs.gnu.org; 27 Oct 2024 18:25:09 +0000 Received: from localhost ([127.0.0.1]:46275 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t57wr-0003al-Bb for submit@debbugs.gnu.org; Sun, 27 Oct 2024 14:25:09 -0400 Received: from lists.gnu.org ([209.51.188.17]:48882) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t57wp-0003ad-D2 for submit@debbugs.gnu.org; Sun, 27 Oct 2024 14:25:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t57wF-0004zv-OJ for guix-patches@gnu.org; Sun, 27 Oct 2024 14:24:31 -0400 Received: from 6.mo576.mail-out.ovh.net ([46.105.50.107]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t57wD-000861-UC for guix-patches@gnu.org; Sun, 27 Oct 2024 14:24:31 -0400 Received: from director6.ghost.mail-out.ovh.net (unknown [10.109.139.54]) by mo576.mail-out.ovh.net (Postfix) with ESMTP id 4Xc4fy4gN0z1m1P for ; Sun, 27 Oct 2024 18:24:26 +0000 (UTC) Received: from ghost-submission-5b5ff79f4f-6ghlz (unknown [10.111.182.47]) by director6.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 593921FDDC; Sun, 27 Oct 2024 18:24:26 +0000 (UTC) Received: from ngraves.fr ([37.59.142.105]) by ghost-submission-5b5ff79f4f-6ghlz with ESMTPSA id CvlIA1qFHmeJJgAApxVJLg (envelope-from ); Sun, 27 Oct 2024 18:24:26 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-105G00611d15503-81d2-4d16-99c1-3054e6e5c763, E6BF9B87AE7FBE7894246B3B643E76DCC103CD4C) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 From: Nicolas Graves Date: Sun, 27 Oct 2024 19:22:11 +0100 Message-ID: <20241027182422.27007-1-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 9608992758372885218 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdejiedgheekucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffoggfgsedtkeertdertddtnecuhfhrohhmpefpihgtohhlrghsucfirhgrvhgvshcuoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqnecuggftrfgrthhtvghrnhepkeffgeetfffgffejgeejvdffgfdtvdeuueetgfefuedvjeegvdegjeejveeuueevnecukfhppeduvdejrddtrddtrddupdekiedrvdegiedrudelrddvvddupdefjedrheelrddugedvrddutdehnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepuddvjedrtddrtddruddpmhgrihhlfhhrohhmpehnghhrrghvvghssehnghhrrghvvghsrdhfrhdpnhgspghrtghpthhtohepuddprhgtphhtthhopehguhhigidqphgrthgthhgvshesghhnuhdrohhrghdpoffvtefjohhsthepmhhoheejiedpmhhouggvpehsmhhtphhouhht DKIM-Signature: a=rsa-sha256; bh=RoDSJ2L8AcYGTJ73eAMqECerfnVqarCXyePcq8iX5W4=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1730053466; v=1; b=e13tMZqOV6U5NsifwIYm6/mSqp9AZFcGccnAHRR5vEK9W8qoKwKHJHWi8KRQl0tIJrd9Fk8Q ryZ4vmDI6OHgffZeW+ybl4TaqgqauXPMxmgEqSUsdpPrxZ8beGKVKtTEtD6xUAkuIa/u6xhz4d1 OQes97L5VcGIg1i44/SogBGx9yMhTkarMLkzaxkfz+b2TcZFIaGP2kCOLvJyNxZz/l1/5PNzPSE VxjhnA/IVPGyAsTZehXaso02mESEgJDcr/jXgovD9cV34r1gghcIRIjTUjIvJw6Q9K1RFcKoK5I JuHYcqkoMVwgap3nBbvBOcJmRLWVlXFIH3WUk7RSrKYIg== Received-SPF: pass client-ip=46.105.50.107; envelope-from=ngraves@ngraves.fr; helo=6.mo576.mail-out.ovh.net X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.3 (-) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.3 (--) This patch series is what's left of 74034 after I've split it in two. It introduces some useful lint-hidden-cve properties were that's useful, fixing build or updating packages along the way. Nicolas Graves (6): gnu: gerbv: Add lint-hidden-cve property. gnu: libgda: Rename patch for guix lint. gnu: upx: Update to 4.2.4. gnu: sylpheed: Add release-monitoring-url property. gnu: openvswitch: Update to 3.4.0. gnu: quagga: Fix build and hide CVE. gnu/local.mk | 2 +- gnu/packages/compression.scm | 7 ++++--- gnu/packages/engineering.scm | 2 ++ gnu/packages/gnome.scm | 2 +- gnu/packages/mail.scm | 2 ++ gnu/packages/networking.scm | 14 ++++++++++---- ...021-39359.patch => libgda-CVE-2021-39359.patch} | 0 7 files changed, 20 insertions(+), 9 deletions(-) rename gnu/packages/patches/{libgda-cve-2021-39359.patch => libgda-CVE-2021-39359.patch} (100%) -- 2.46.0 From unknown Tue Sep 09 18:21:51 2025 X-Loop: help-debbugs@gnu.org Subject: [bug#74050] [PATCH 2/6] gnu: libgda: Rename patch for guix lint. Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sun, 27 Oct 2024 18:33:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 74050 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 74050@debbugs.gnu.org Cc: Nicolas Graves Received: via spool by 74050-submit@debbugs.gnu.org id=B74050.173005394715371 (code B ref 74050); Sun, 27 Oct 2024 18:33:02 +0000 Received: (at 74050) by debbugs.gnu.org; 27 Oct 2024 18:32:27 +0000 Received: from localhost ([127.0.0.1]:46291 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t583v-0003zm-8x for submit@debbugs.gnu.org; Sun, 27 Oct 2024 14:32:27 -0400 Received: from 9.mo584.mail-out.ovh.net ([46.105.40.176]:56459) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t583t-0003zX-B0 for 74050@debbugs.gnu.org; Sun, 27 Oct 2024 14:32:26 -0400 Received: from director7.ghost.mail-out.ovh.net (unknown [10.109.140.5]) by mo584.mail-out.ovh.net (Postfix) with ESMTP id 4Xc4qT2nL7z1NdK for <74050@debbugs.gnu.org>; Sun, 27 Oct 2024 18:31:49 +0000 (UTC) Received: from ghost-submission-5b5ff79f4f-75tfv (unknown [10.110.188.144]) by director7.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 28EA51FD6F; Sun, 27 Oct 2024 18:31:49 +0000 (UTC) Received: from ngraves.fr ([37.59.142.105]) by ghost-submission-5b5ff79f4f-75tfv with ESMTPSA id 1eFhAxWHHmeoLx0AHczbNw (envelope-from ); Sun, 27 Oct 2024 18:31:49 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-105G0069571bb35-d766-4b61-9e0a-563a9243eded, E6BF9B87AE7FBE7894246B3B643E76DCC103CD4C) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 From: Nicolas Graves Date: Sun, 27 Oct 2024 19:31:31 +0100 Message-ID: <20241027183141.28120-2-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 In-Reply-To: <20241027183141.28120-1-ngraves@ngraves.fr> References: <20241027183141.28120-1-ngraves@ngraves.fr> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 9733686169788736226 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdejiedghedtucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffojghfggfgsedtkeertdertddtnecuhfhrohhmpefpihgtohhlrghsucfirhgrvhgvshcuoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqnecuggftrfgrthhtvghrnhepleffjeetueethfefkeffffefvddukeejkefgleduiedthfekvefhiedvhfffgeegnecukfhppeduvdejrddtrddtrddupdekiedrvdegiedrudelrddvvddupdefjedrheelrddugedvrddutdehnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepuddvjedrtddrtddruddpmhgrihhlfhhrohhmpehnghhrrghvvghssehnghhrrghvvghsrdhfrhdpnhgspghrtghpthhtohepuddprhgtphhtthhopeejgedthedtseguvggssghughhsrdhgnhhurdhorhhgpdfovfetjfhoshhtpehmohehkeegpdhmohguvgepshhmthhpohhuth DKIM-Signature: a=rsa-sha256; bh=tzxiP39YU3VDBWTdvgjMX2pybX7l/XsR45MTvzMVRkA=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1730053909; v=1; b=zteSDBsk7mfEe+T55iPGQEI4J33edcmg/ZBjjVCnV5SVxEwwADBJ8JKhyDlW491ySkciUw6E 9TAFOlupW/u6OpRqcptmC39uQiR0qo9oYokBId0pZwFyWFPXzqdhyvxfW/OmSeWxplS5obQ2kp/ G2esfecVpRwXtWJaWm3M1nNMgvriLOipkMNj7lKfqonmKfGmxCCoicOLwewSDONtl3wzcV/6PIE 5ohyYt2l7cEG4fcsdP8++Y1v0kW85K+yF6SApOD/3zYFAZxTSOIIgNcqaqiuLSuaLrYiHswNJjC lQpq3bXvgH5p4JcRx0NmHdlD2UA3xr6TeGG71nZ6eK64g== X-Spam-Score: 1.7 (+) X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: * gnu/packages/gnome.scm (libgda)[source]: Rename patch for CVE to be ignored by guix lint. --- gnu/local.mk | 2 +- gnu/packages/gnome.scm | 2 +- ...{libgda-cve-2021-39359.patch => libgda-CVE- [...] Content analysis details: (1.7 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [46.105.40.176 listed in sa-accredit.habeas.com] -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [46.105.40.176 listed in list.dnswl.org] 1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist [URIs: ngraves.fr] 0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [46.105.40.176 listed in bl.score.senderscore.com] 0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [46.105.40.176 listed in wl.mailspike.net] 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record -0.0 SPF_PASS SPF: sender matches SPF record 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: 0.7 (/) * gnu/packages/gnome.scm (libgda)[source]: Rename patch for CVE to be ignored by guix lint. --- gnu/local.mk | 2 +- gnu/packages/gnome.scm | 2 +- ...{libgda-cve-2021-39359.patch => libgda-CVE-2021-39359.patch} | 0 3 files changed, 2 insertions(+), 2 deletions(-) rename gnu/packages/patches/{libgda-cve-2021-39359.patch => libgda-CVE-2021-39359.patch} (100%) diff --git a/gnu/local.mk b/gnu/local.mk index c432685775..d253b424bb 100644 --- a/gnu/local.mk +++ b/gnu/local.mk @@ -1666,7 +1666,7 @@ dist_patch_DATA = \ %D%/packages/patches/libcroco-CVE-2020-12825.patch \ %D%/packages/patches/libcyaml-libyaml-compat.patch \ %D%/packages/patches/libexpected-use-provided-catch2.patch \ - %D%/packages/patches/libgda-cve-2021-39359.patch \ + %D%/packages/patches/libgda-CVE-2021-39359.patch \ %D%/packages/patches/libgda-disable-data-proxy-test.patch \ %D%/packages/patches/libgda-fix-build.patch \ %D%/packages/patches/libgda-fix-missing-initialization.patch \ diff --git a/gnu/packages/gnome.scm b/gnu/packages/gnome.scm index 77a0633b50..9b26819261 100644 --- a/gnu/packages/gnome.scm +++ b/gnu/packages/gnome.scm @@ -13653,7 +13653,7 @@ (define-public libgda name "-" version ".tar.xz")) (sha256 (base32 "0w564z7krgjk19r39mi5qn4kggpdg9ggbyn9pb4aavb61r14npwr")) - (patches (search-patches "libgda-cve-2021-39359.patch" + (patches (search-patches "libgda-CVE-2021-39359.patch" "libgda-disable-data-proxy-test.patch" "libgda-fix-build.patch" "libgda-fix-missing-initialization.patch" diff --git a/gnu/packages/patches/libgda-cve-2021-39359.patch b/gnu/packages/patches/libgda-CVE-2021-39359.patch similarity index 100% rename from gnu/packages/patches/libgda-cve-2021-39359.patch rename to gnu/packages/patches/libgda-CVE-2021-39359.patch -- 2.46.0 From unknown Tue Sep 09 18:21:51 2025 X-Loop: help-debbugs@gnu.org Subject: [bug#74050] [PATCH 1/6] gnu: gerbv: Add lint-hidden-cve property. References: <20241027182422.27007-1-ngraves@ngraves.fr> In-Reply-To: <20241027182422.27007-1-ngraves@ngraves.fr> Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sun, 27 Oct 2024 18:33:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 74050 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 74050@debbugs.gnu.org Cc: Nicolas Graves Received: via spool by 74050-submit@debbugs.gnu.org id=B74050.173005394915381 (code B ref 74050); Sun, 27 Oct 2024 18:33:02 +0000 Received: (at 74050) by debbugs.gnu.org; 27 Oct 2024 18:32:29 +0000 Received: from localhost ([127.0.0.1]:46293 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t583w-000400-NH for submit@debbugs.gnu.org; Sun, 27 Oct 2024 14:32:28 -0400 Received: from 5.mo561.mail-out.ovh.net ([87.98.178.36]:47797) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t583t-0003zV-3i for 74050@debbugs.gnu.org; Sun, 27 Oct 2024 14:32:26 -0400 Received: from director8.ghost.mail-out.ovh.net (unknown [10.109.176.180]) by mo561.mail-out.ovh.net (Postfix) with ESMTP id 4Xc4qS5XGRz1P4x for <74050@debbugs.gnu.org>; Sun, 27 Oct 2024 18:31:48 +0000 (UTC) Received: from ghost-submission-5b5ff79f4f-v27qh (unknown [10.110.113.175]) by director8.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 8D09B1FDF1; Sun, 27 Oct 2024 18:31:48 +0000 (UTC) Received: from ngraves.fr ([37.59.142.100]) by ghost-submission-5b5ff79f4f-v27qh with ESMTPSA id qFxaHBSHHmeMxAYAGi/6QQ (envelope-from ); Sun, 27 Oct 2024 18:31:48 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-100R003d31ad02f-fba6-48a4-8c0a-b2034d7b6d12, E6BF9B87AE7FBE7894246B3B643E76DCC103CD4C) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 From: Nicolas Graves Date: Sun, 27 Oct 2024 19:31:30 +0100 Message-ID: <20241027183141.28120-1-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 9733404696022082274 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdejiedguddufecutefuodetggdotefrodftvfcurfhrohhfihhlvgemucfqggfjpdevjffgvefmvefgnecuuegrihhlohhuthemucehtddtnecunecujfgurhephffvvefufffkofgggfestdekredtredttdenucfhrhhomheppfhitgholhgrshcuifhrrghvvghsuceonhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrqeenucggtffrrghtthgvrhhnpeekffegteffgfffjeegjedvfffgtddvueeutefgfeeuvdejgedvgeejjeevueeuveenucfkphepuddvjedrtddrtddruddpkeeirddvgeeirdduledrvddvuddpfeejrdehledrudegvddruddttdenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepihhnvghtpeduvdejrddtrddtrddupdhmrghilhhfrhhomhepnhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrpdhnsggprhgtphhtthhopedupdhrtghpthhtohepjeegtdehtdesuggvsggsuhhgshdrghhnuhdrohhrghdpoffvtefjohhsthepmhhoheeiuddpmhhouggvpehsmhhtphhouhht DKIM-Signature: a=rsa-sha256; bh=UFpallWz0g6Do1CneIKpYpdPW9vmzAE5XwHjZ3OVhCw=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1730053908; v=1; b=KHjn2CAM71/QBTx7MQi//11gMyG5VZvkmQeHgloO2zcufJR08Ik9ENGJW8IBYAWTl31N0QhB Nz8KD+oN4ZvqDnUKEzbnX0+LU/S4/HIIRQ0kINaUfHTTDf/Roqyjgi7pDtnfEEkxv81GOiB5oED zA20RKQCbfOjT53CrPXrFiyTr0nhlWNJJGLIszdvtqEHhTeBUd7efHmTguIrJl7s1vb2NjIboKL /JQGXkuerzP2DP6wTCGL8Of0Rsk7zG4ExcQMb4o2lSylebN6JfqzAnkLDzY2HP6ZYPG3pq31RPI mOZgHj8jEBlShcNy7tFB2QcFn3FdZ1marx7O9+4BBWN6Q== X-Spam-Score: 1.7 (+) X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: * gnu/packages/engineering.scm (gerbv)[properties]: Add lint-hidden-cve property. --- gnu/packages/engineering.scm | 2 ++ 1 file changed, 2 insertions(+) diff --git a/gnu/packages/engineering.scm b/gnu/packages/engineering.scm index 6f449f0c39..89e60a7218 100644 --- a/gnu/packages/engineering.scm +++ b/gnu/packages/engineering.scm @@ -868,6 +868,8 @@ ( [...] Content analysis details: (1.7 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [87.98.178.36 listed in sa-accredit.habeas.com] 0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [87.98.178.36 listed in bl.score.senderscore.com] -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [87.98.178.36 listed in list.dnswl.org] 0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [87.98.178.36 listed in wl.mailspike.net] 1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist [URIs: ngraves.fr] 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record -0.0 SPF_PASS SPF: sender matches SPF record 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: 0.7 (/) * gnu/packages/engineering.scm (gerbv)[properties]: Add lint-hidden-cve property. --- gnu/packages/engineering.scm | 2 ++ 1 file changed, 2 insertions(+) diff --git a/gnu/packages/engineering.scm b/gnu/packages/engineering.scm index 6f449f0c39..89e60a7218 100644 --- a/gnu/packages/engineering.scm +++ b/gnu/packages/engineering.scm @@ -868,6 +868,8 @@ (define-public gerbv you load several files on top of each other, do measurements on the displayed image, etc. Besides viewing Gerbers, you may also view Excellon drill files as well as pick-place files.") + ;; This CVE has been fixed in version 2.10.0. + (properties '((lint-hidden-cve . ("CVE-2023-4508")))) (license license:gpl2+))) (define-public translate2geda -- 2.46.0 From unknown Tue Sep 09 18:21:51 2025 X-Loop: help-debbugs@gnu.org Subject: [bug#74050] [PATCH 3/6] gnu: upx: Update to 4.2.4. Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sun, 27 Oct 2024 18:33:03 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 74050 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 74050@debbugs.gnu.org Cc: Nicolas Graves Received: via spool by 74050-submit@debbugs.gnu.org id=B74050.173005394915390 (code B ref 74050); Sun, 27 Oct 2024 18:33:03 +0000 Received: (at 74050) by debbugs.gnu.org; 27 Oct 2024 18:32:29 +0000 Received: from localhost ([127.0.0.1]:46297 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t583x-000403-0n for submit@debbugs.gnu.org; Sun, 27 Oct 2024 14:32:29 -0400 Received: from 8.mo561.mail-out.ovh.net ([87.98.172.249]:58585) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t583u-0003zZ-Dl for 74050@debbugs.gnu.org; Sun, 27 Oct 2024 14:32:27 -0400 Received: from director3.ghost.mail-out.ovh.net (unknown [10.109.139.93]) by mo561.mail-out.ovh.net (Postfix) with ESMTP id 4Xc4qV1l50z1PCv for <74050@debbugs.gnu.org>; Sun, 27 Oct 2024 18:31:50 +0000 (UTC) Received: from ghost-submission-5b5ff79f4f-fx75z (unknown [10.110.113.51]) by director3.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 0EB4C1FD55; Sun, 27 Oct 2024 18:31:50 +0000 (UTC) Received: from ngraves.fr ([37.59.142.105]) by ghost-submission-5b5ff79f4f-fx75z with ESMTPSA id MkJBNxWHHmeTEgAA0a65xQ (envelope-from ); Sun, 27 Oct 2024 18:31:50 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-105G006ccddea51-1f2a-48bb-89c4-67276b154b23, E6BF9B87AE7FBE7894246B3B643E76DCC103CD4C) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 From: Nicolas Graves Date: Sun, 27 Oct 2024 19:31:32 +0100 Message-ID: <20241027183141.28120-3-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 In-Reply-To: <20241027183141.28120-1-ngraves@ngraves.fr> References: <20241027183141.28120-1-ngraves@ngraves.fr> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 9733967645143065314 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 49 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdejiedguddufecutefuodetggdotefrodftvfcurfhrohhfihhlvgemucfqggfjpdevjffgvefmvefgnecuuegrihhlohhuthemucehtddtnecuogfuuhhsphgvtghtffhomhgrihhnucdlgeelmdenucfjughrpefhvfevufffkffojghfggfgsedtkeertdertddtnecuhfhrohhmpefpihgtohhlrghsucfirhgrvhgvshcuoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqnecuggftrfgrthhtvghrnhepudetheeutdejjeetleefudfhfedvheeltdejfeegfeejieeludffgfevvedvgfdunecuffhomhgrihhnpehgihhthhhusgdrtghomhdpghhithhhuhgsrdhiohenucfkphepuddvjedrtddrtddruddpkeeirddvgeeirdduledrvddvuddpfeejrdehledrudegvddruddtheenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepihhnvghtpeduvdejrddtrddtrddupdhmrghilhhfrhhomhepnhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrpdhnsggprhgtphhtthhopedupdhrtghpthhtohepjeegtdehtdesuggvsggsuhhgshdrghhnuhdrohhrghdpoffvtefjohhsthepmhhoheeiuddpmhhouggvpehsmhhtphhouhht DKIM-Signature: a=rsa-sha256; bh=SdSOrovg3XzSwWEhw5EJDTg6zZq4G/rkwuvV71g5eb4=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1730053910; v=1; b=Ny+04OAzpsLdfA04rIb5ZbvxTcrI1ptCLIsqfMqYPgk3aVq93oBw2BR+EsW60O31m7hmMEG0 +thsT5/KlPgFLhtQxWPORFQPWAT4T/sR+Cg/ArWxeGHbvVQQox5SmNXExidS3CrvqNNkUPJjJFc 0N1uBwmeJwEYHa7Cnvd4qn1hBmu36guP1ndYeISDEAWd2xyKVU+mtte4EYEIvflgIZuC8AdIJsI heA5OD63cNMPou0mzzxfjmMt6PBv6QVifT+fNikCLknMw9H/bqKk5pw4Si/QSoHHCpy0NDrjt8Q VrFuswm++/j1vKl+/QPbyBzfi6MmchxEIGxMj/uBwFtuQ== X-Spam-Score: 2.4 (++) X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: * gnu/packages/compression.scm (upx): Update to 4.2.4. [properties]: Add lint-hidden-cve property. --- gnu/packages/compression.scm | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/gnu/packages/compression.scm b/gnu/packages/compression.scm index 97696ff0ef..a32b15a64a 100644 --- a/gnu/packages/compression.scm +++ b/gnu/packages/compression.scm @@ -2438,15 +2438,14 [...] Content analysis details: (2.4 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist [URIs: ngraves.fr] 0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [87.98.172.249 listed in sa-accredit.habeas.com] -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [87.98.172.249 listed in list.dnswl.org] 0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [87.98.172.249 listed in bl.score.senderscore.com] 0.1 URIBL_SBL_A Contains URL's A record listed in the Spamhaus SBL blocklist [URIs: upx.github.io] 0.6 URIBL_SBL Contains an URL's NS IP listed in the Spamhaus SBL blocklist [URIs: upx.github.io] 0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [87.98.172.249 listed in wl.mailspike.net] 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record -0.0 SPF_PASS SPF: sender matches SPF record 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: 1.4 (+) X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: * gnu/packages/compression.scm (upx): Update to 4.2.4. [properties]: Add lint-hidden-cve property. --- gnu/packages/compression.scm | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/gnu/packages/compression.scm b/gnu/packages/compression.scm index 97696ff0ef..a32b15a64a 100644 --- a/gnu/packages/compression.scm +++ b/gnu/packages/compression.scm @@ -2438,15 +2438,14 [...] Content analysis details: (1.4 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist [URIs: ngraves.fr] 0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [87.98.172.249 listed in sa-accredit.habeas.com] -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [87.98.172.249 listed in list.dnswl.org] 0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [87.98.172.249 listed in wl.mailspike.net] 0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [87.98.172.249 listed in bl.score.senderscore.com] 0.1 URIBL_SBL_A Contains URL's A record listed in the Spamhaus SBL blocklist [URIs: upx.github.io] 0.6 URIBL_SBL Contains an URL's NS IP listed in the Spamhaus SBL blocklist [URIs: upx.github.io] 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record -0.0 SPF_PASS SPF: sender matches SPF record 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders -1.0 MAILING_LIST_MULTI Multiple indicators imply a widely-seen list manager * gnu/packages/compression.scm (upx): Update to 4.2.4. [properties]: Add lint-hidden-cve property. --- gnu/packages/compression.scm | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/gnu/packages/compression.scm b/gnu/packages/compression.scm index 97696ff0ef..a32b15a64a 100644 --- a/gnu/packages/compression.scm +++ b/gnu/packages/compression.scm @@ -2438,15 +2438,14 @@ (define-public ucl (define-public upx (package (name "upx") - (version "4.1.0") + (version "4.2.4") (source (origin (method url-fetch) (uri (string-append "https://github.com/upx/upx/releases/download/v" version "/upx-" version "-src.tar.xz")) (sha256 - (base32 - "1l273pwa573x9l3izw75cz8ysn2g8w8w3s56rahppa3ya65zg0h5")))) + (base32 "1i71p03861hlf5x1w217l67zm5inm449zhbg6kpv8zyj0wb5dmjy")))) (build-system cmake-build-system) (home-page "https://upx.github.io/") (synopsis "Compression tool for executables") @@ -2455,6 +2454,8 @@ (define-public upx compressor. UPX typically reduces the file size of programs and shared libraries by around 50%--70%, thus reducing disk space, network load times, download times, and other distribution and storage costs.") + ;; These CVEs have been fixed since 4.0.2 but are still linted. + (properties `((lint-hidden-cve . ("CVE-2023-23456" "CVE-2023-23457")))) (license license:gpl2+))) (define-public quazip-0 -- 2.46.0 From unknown Tue Sep 09 18:21:51 2025 X-Loop: help-debbugs@gnu.org Subject: [bug#74050] [PATCH 4/6] gnu: sylpheed: Add release-monitoring-url property. Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sun, 27 Oct 2024 18:33:03 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 74050 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 74050@debbugs.gnu.org Cc: Nicolas Graves Received: via spool by 74050-submit@debbugs.gnu.org id=B74050.173005395815429 (code B ref 74050); Sun, 27 Oct 2024 18:33:03 +0000 Received: (at 74050) by debbugs.gnu.org; 27 Oct 2024 18:32:38 +0000 Received: from localhost ([127.0.0.1]:46303 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t5846-00040m-FV for submit@debbugs.gnu.org; Sun, 27 Oct 2024 14:32:38 -0400 Received: from 3.mo575.mail-out.ovh.net ([46.105.58.60]:54183) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t583w-0003zz-Pm for 74050@debbugs.gnu.org; Sun, 27 Oct 2024 14:32:29 -0400 Received: from director3.ghost.mail-out.ovh.net (unknown [10.109.139.93]) by mo575.mail-out.ovh.net (Postfix) with ESMTP id 4Xc4qX6WdYz1j0n for <74050@debbugs.gnu.org>; Sun, 27 Oct 2024 18:31:52 +0000 (UTC) Received: from ghost-submission-5b5ff79f4f-grrv4 (unknown [10.110.168.164]) by director3.ghost.mail-out.ovh.net (Postfix) with ESMTPS id B8CD21FDFB; Sun, 27 Oct 2024 18:31:52 +0000 (UTC) Received: from ngraves.fr ([37.59.142.99]) by ghost-submission-5b5ff79f4f-grrv4 with ESMTPSA id uvllIRiHHmdi1AEAdct96w (envelope-from ); Sun, 27 Oct 2024 18:31:52 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-99G003f8ec7a83-a909-4fde-8fd9-bf6c908495bd, E6BF9B87AE7FBE7894246B3B643E76DCC103CD4C) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 From: Nicolas Graves Date: Sun, 27 Oct 2024 19:31:33 +0100 Message-ID: <20241027183141.28120-4-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 In-Reply-To: <20241027183141.28120-1-ngraves@ngraves.fr> References: <20241027183141.28120-1-ngraves@ngraves.fr> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 9734530597106737890 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdejiedgieejucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffojghfggfgsedtkeertdertddtnecuhfhrohhmpefpihgtohhlrghsucfirhgrvhgvshcuoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqnecuggftrfgrthhtvghrnhephfetieegffdtvdekueffgefgudeuudeghfevvefhfeeljedtgfelvdfgvddvhfeknecuffhomhgrihhnpehsrhgrohhsshdrjhhpnecukfhppeduvdejrddtrddtrddupdekiedrvdegiedrudelrddvvddupdefjedrheelrddugedvrdelleenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepihhnvghtpeduvdejrddtrddtrddupdhmrghilhhfrhhomhepnhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrpdhnsggprhgtphhtthhopedupdhrtghpthhtohepjeegtdehtdesuggvsggsuhhgshdrghhnuhdrohhrghdpoffvtefjohhsthepmhhoheejhedpmhhouggvpehsmhhtphhouhht DKIM-Signature: a=rsa-sha256; bh=rctlaM9g8p9JdUyaMWubQs6dbqjhRRamb7StKiDd9Xk=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1730053913; v=1; b=OsphbZ0d1pKBUqGk3JH03SLJ6QubD/TENqN0VpAzaUzKCajWb+AF0xn6WMR7DKtUXFP1LP12 xhG+eiZGolnKXM2ksEa7dh49AMW4k0TQ+kdxrJeXDorBqpQ06aMA5bMCfQeiYyqJpv9agOm96k6 BIt3UlYlc2SGJtmczeOwbyLH84y77d77TLEY/GGLF3I44wXs/Sh82CqT52pZBQ3RvNhlv/KyAIJ 8+5z4qbDOtEScYVR2anlzWD8o+tY4XPMXn+dfdrKgWJXxM46kyWTAC+8iIhWMfE1vCPXDJn3cOv LSFQscnvPh6OX3aQw67y0aNS9SmSp2bRecKWubGvqzCCg== X-Spam-Score: 1.7 (+) X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: * gnu/packages/mail.scm (sylpheed)[properties]: Add release-monitoring-url. --- gnu/packages/mail.scm | 2 ++ 1 file changed, 2 insertions(+) diff --git a/gnu/packages/mail.scm b/gnu/packages/mail.scm index 2c69a7b818..77be7626a9 100644 --- a/gnu/packages/mail.scm +++ b/gnu/packages/mail.scm @@ -4561,6 +4561,8 @@ (define-public sylpheed "Sy [...] Content analysis details: (1.7 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist [URIs: ngraves.fr] 0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [46.105.58.60 listed in sa-accredit.habeas.com] 0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [46.105.58.60 listed in bl.score.senderscore.com] -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [46.105.58.60 listed in list.dnswl.org] -0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [46.105.58.60 listed in wl.mailspike.net] 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record -0.0 SPF_PASS SPF: sender matches SPF record X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: 0.7 (/) * gnu/packages/mail.scm (sylpheed)[properties]: Add release-monitoring-url. --- gnu/packages/mail.scm | 2 ++ 1 file changed, 2 insertions(+) diff --git a/gnu/packages/mail.scm b/gnu/packages/mail.scm index 2c69a7b818..77be7626a9 100644 --- a/gnu/packages/mail.scm +++ b/gnu/packages/mail.scm @@ -4561,6 +4561,8 @@ (define-public sylpheed "Sylpheed is a simple, lightweight but featureful, and easy-to-use e-mail client. Sylpheed provides intuitive user-interface. Sylpheed is also designed for keyboard-oriented operation.") + (properties '((release-monitoring-url + . "https://sylpheed.sraoss.jp/en/download.html"))) (license license:gpl2+))) (define-public python-authres -- 2.46.0 From unknown Tue Sep 09 18:21:51 2025 X-Loop: help-debbugs@gnu.org Subject: [bug#74050] [PATCH 5/6] gnu: openvswitch: Update to 3.4.0. Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sun, 27 Oct 2024 18:33:04 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 74050 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 74050@debbugs.gnu.org Cc: Nicolas Graves Received: via spool by 74050-submit@debbugs.gnu.org id=B74050.173005395915438 (code B ref 74050); Sun, 27 Oct 2024 18:33:04 +0000 Received: (at 74050) by debbugs.gnu.org; 27 Oct 2024 18:32:39 +0000 Received: from localhost ([127.0.0.1]:46305 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t5846-00040o-SE for submit@debbugs.gnu.org; Sun, 27 Oct 2024 14:32:39 -0400 Received: from 2.mo575.mail-out.ovh.net ([46.105.52.162]:59047) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t583y-00040A-4L for 74050@debbugs.gnu.org; Sun, 27 Oct 2024 14:32:31 -0400 Received: from director3.ghost.mail-out.ovh.net (unknown [10.109.139.93]) by mo575.mail-out.ovh.net (Postfix) with ESMTP id 4Xc4qY6vWyz1hCZ for <74050@debbugs.gnu.org>; Sun, 27 Oct 2024 18:31:53 +0000 (UTC) Received: from ghost-submission-5b5ff79f4f-dn5kt (unknown [10.110.101.145]) by director3.ghost.mail-out.ovh.net (Postfix) with ESMTPS id ACD111FDFB; Sun, 27 Oct 2024 18:31:53 +0000 (UTC) Received: from ngraves.fr ([37.59.142.107]) by ghost-submission-5b5ff79f4f-dn5kt with ESMTPSA id EnRAIBmHHmdr8SAAFL8Frw (envelope-from ); Sun, 27 Oct 2024 18:31:53 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-107S0011a2bc9d9-3dca-4b14-8a7e-43cab797aa48, E6BF9B87AE7FBE7894246B3B643E76DCC103CD4C) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 From: Nicolas Graves Date: Sun, 27 Oct 2024 19:31:34 +0100 Message-ID: <20241027183141.28120-5-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 In-Reply-To: <20241027183141.28120-1-ngraves@ngraves.fr> References: <20241027183141.28120-1-ngraves@ngraves.fr> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 9734812072647516898 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdejiedgieejucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffojghfggfgsedtkeertdertddtnecuhfhrohhmpefpihgtohhlrghsucfirhgrvhgvshcuoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqnecuggftrfgrthhtvghrnhepleffjefhtddttdelffevkeejteettdeltddufedthffgudejhfeutddvleehvddvnecuffhomhgrihhnpehophgvnhhvshifihhttghhrdhorhhgnecukfhppeduvdejrddtrddtrddupdekiedrvdegiedrudelrddvvddupdefjedrheelrddugedvrddutdejnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepuddvjedrtddrtddruddpmhgrihhlfhhrohhmpehnghhrrghvvghssehnghhrrghvvghsrdhfrhdpnhgspghrtghpthhtohepuddprhgtphhtthhopeejgedthedtseguvggssghughhsrdhgnhhurdhorhhgpdfovfetjfhoshhtpehmohehjeehpdhmohguvgepshhmthhpohhuth DKIM-Signature: a=rsa-sha256; bh=tvWCtVM8JaCmGzsCMHfZE57gi2yHnNeEOKRZN4HMlOI=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1730053914; v=1; b=CE7sahZYyfz/sVxSgf4798Kk8WC05kAkYigDyTeV/g9EfgJ71iIIJnmAxReSdNOUpFGeIVzG VSl+8l5bH3g+VSHTpeBrFJlRSEijAbP/uGOQYDy14rinwbIA+/IX4q4p6FOKDYgejgM9KAtnJoz oYzIsOAvRfpSXYQ49ofvzlnJ8QWrDyFhhoFHUPRVnCHGjO61xaB3fIAsK4cuTbbP8eE+cKlueh0 sn9PVNh01TfVYzSFZytsM3UEbsfegU6hL2QAw1JnxHmpoXHhOEUAl04VZb/0m8kp7rqESnBSSRC yhwt4e+uoGQzunIyLvuzJ02LHK9mXh2Dvbj4vOaomqUWA== X-Spam-Score: 2.4 (++) X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: * gnu/packages/networking.scm (openvswitch): Update to 3.4.0. [properties]: Add lint-hidden-cve property. --- gnu/packages/networking.scm | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/gnu/packages/networking.scm b/gnu/packages/networking.scm index 8c5548323f..67584be64b 100644 --- a/gnu/packages/networking.scm +++ b/gnu/packages/networking.scm @@ -2878,7 +2878,7 @@ (de [...] Content analysis details: (2.4 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist [URIs: ngraves.fr] 0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [46.105.52.162 listed in sa-accredit.habeas.com] 0.1 URIBL_SBL_A Contains URL's A record listed in the Spamhaus SBL blocklist [URIs: www.openvswitch.org] 0.6 URIBL_SBL Contains an URL's NS IP listed in the Spamhaus SBL blocklist [URIs: www.openvswitch.org] 0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [46.105.52.162 listed in bl.score.senderscore.com] 0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [46.105.52.162 listed in wl.mailspike.net] 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record -0.0 SPF_PASS SPF: sender matches SPF record -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [46.105.52.162 listed in list.dnswl.org] 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: 1.4 (+) X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: * gnu/packages/networking.scm (openvswitch): Update to 3.4.0. [properties]: Add lint-hidden-cve property. --- gnu/packages/networking.scm | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/gnu/packages/networking.scm b/gnu/packages/networking.scm index 8c5548323f..67584be64b 100644 --- a/gnu/packages/networking.scm +++ b/gnu/packages/networking.scm @@ -2878,7 +2878,7 @@ (de [...] Content analysis details: (1.4 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist [URIs: ngraves.fr] 0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [46.105.52.162 listed in sa-accredit.habeas.com] -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [46.105.52.162 listed in list.dnswl.org] 0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [46.105.52.162 listed in wl.mailspike.net] 0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [46.105.52.162 listed in bl.score.senderscore.com] 0.1 URIBL_SBL_A Contains URL's A record listed in the Spamhaus SBL blocklist [URIs: www.openvswitch.org] 0.6 URIBL_SBL Contains an URL's NS IP listed in the Spamhaus SBL blocklist [URIs: www.openvswitch.org] 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record -0.0 SPF_PASS SPF: sender matches SPF record 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders -1.0 MAILING_LIST_MULTI Multiple indicators imply a widely-seen list manager * gnu/packages/networking.scm (openvswitch): Update to 3.4.0. [properties]: Add lint-hidden-cve property. --- gnu/packages/networking.scm | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/gnu/packages/networking.scm b/gnu/packages/networking.scm index 8c5548323f..67584be64b 100644 --- a/gnu/packages/networking.scm +++ b/gnu/packages/networking.scm @@ -2878,7 +2878,7 @@ (define-public nzbget (define-public openvswitch (package (name "openvswitch") - (version "3.2.0") + (version "3.4.0") (source (origin (method url-fetch) (uri (string-append @@ -2886,7 +2886,7 @@ (define-public openvswitch version ".tar.gz")) (sha256 (base32 - "1i0lb40lwbakmmqklmfcgr01l1ymsawgdi7k9a1zzp8ariw7x4ff")))) + "10g84h6lis6fafyjhvmdrs8r539xcar04cc3rsk448gs6848hsqr")))) (build-system gnu-build-system) (arguments '(#:configure-flags @@ -2962,7 +2962,9 @@ (define-public openvswitch supporting standard management interfaces and protocols (e.g. NetFlow, sFlow, IPFIX, RSPAN, CLI, LACP, 802.1ag).") (properties - '((release-monitoring-url . "https://www.openvswitch.org/download/"))) + '((release-monitoring-url . "https://www.openvswitch.org/download/") + ;; This CVE is fixed since 3.2.0. + (lint-hidden-cve . ("CVE-2023-5366")))) (license ; see debian/copyright for detail (list license:lgpl2.1 ; xenserver and utilities/bugtool license:gpl2 ; datapath -- 2.46.0 From unknown Tue Sep 09 18:21:51 2025 X-Loop: help-debbugs@gnu.org Subject: [bug#74050] [PATCH 6/6] gnu: quagga: Fix build and hide CVE. Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sun, 27 Oct 2024 18:33:04 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 74050 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 74050@debbugs.gnu.org Cc: Nicolas Graves Received: via spool by 74050-submit@debbugs.gnu.org id=B74050.173005395915444 (code B ref 74050); Sun, 27 Oct 2024 18:33:04 +0000 Received: (at 74050) by debbugs.gnu.org; 27 Oct 2024 18:32:39 +0000 Received: from localhost ([127.0.0.1]:46307 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t5847-00040x-89 for submit@debbugs.gnu.org; Sun, 27 Oct 2024 14:32:39 -0400 Received: from 12.mo550.mail-out.ovh.net ([87.98.162.229]:48149) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t583z-00040N-Lw for 74050@debbugs.gnu.org; Sun, 27 Oct 2024 14:32:33 -0400 Received: from director4.ghost.mail-out.ovh.net (unknown [10.109.140.5]) by mo550.mail-out.ovh.net (Postfix) with ESMTP id 4Xc4qb2LVWz1RQG for <74050@debbugs.gnu.org>; Sun, 27 Oct 2024 18:31:55 +0000 (UTC) Received: from ghost-submission-5b5ff79f4f-852sz (unknown [10.111.174.111]) by director4.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 1A0021FE6E; Sun, 27 Oct 2024 18:31:55 +0000 (UTC) Received: from ngraves.fr ([37.59.142.98]) by ghost-submission-5b5ff79f4f-852sz with ESMTPSA id Fp9SMhqHHmf3UggAEPcHVg (envelope-from ); Sun, 27 Oct 2024 18:31:55 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-98R00298ae745f-126a-4475-a8d6-9f5ad9e09f48, E6BF9B87AE7FBE7894246B3B643E76DCC103CD4C) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 From: Nicolas Graves Date: Sun, 27 Oct 2024 19:31:35 +0100 Message-ID: <20241027183141.28120-6-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 In-Reply-To: <20241027183141.28120-1-ngraves@ngraves.fr> References: <20241027183141.28120-1-ngraves@ngraves.fr> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 9735375019970257634 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdejiedguddtjecutefuodetggdotefrodftvfcurfhrohhfihhlvgemucfqggfjpdevjffgvefmvefgnecuuegrihhlohhuthemucehtddtnecunecujfgurhephffvvefufffkofgjfhgggfestdekredtredttdenucfhrhhomheppfhitgholhgrshcuifhrrghvvghsuceonhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrqeenucggtffrrghtthgvrhhnpeejgfehffetleetueehiedtudefvdelgfeffeefjeevveelgfduhefhffehvdfgieenucffohhmrghinhepnhhonhhgnhhurdhorhhgpdhophgvnhhsuhhsvgdrohhrghenucfkphepuddvjedrtddrtddruddpkeeirddvgeeirdduledrvddvuddpfeejrdehledrudegvddrleeknecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepuddvjedrtddrtddruddpmhgrihhlfhhrohhmpehnghhrrghvvghssehnghhrrghvvghsrdhfrhdpnhgspghrtghpthhtohepuddprhgtphhtthhopeejgedthedtseguvggssghughhsrdhgnhhurdhorhhgpdfovfetjfhoshhtpehmohehhedtpdhmohguvgepshhmthhpohhuth DKIM-Signature: a=rsa-sha256; bh=85rLbCrTsBnElizszbP0sJ9gEdDwee/GT/HTWoj30kY=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1730053915; v=1; b=WYDpIPBmPO9tM8UL4b6fqTHodZnAvcDBUFmuuWyj3POtCoDmtBHMmdJWaX07IYp6D9v4r4W0 LasTXPy+TMCxZ70rENi79uOfB69DQ4xSn1FFsBzWimmKgzk2oEk5RB9OwWFxUJib3uK2mzpoCGb I25QXfzoEPGI5coD608BlLm3T+FjCelPxM/3bn0yB0Z6lJo0n++eszBaTwzJUChZ6FDN6OG0+y4 YmFD3I1hq7oGrAIwfAFjkSyHysg1IrR90m4yQzAERcZL0Z4/L607M+Etw4ZQYhAgs22+KzvLZR1 yfWjmWsNYaNoR7hL0f2FVxEKC5ixLanwymgloR+/jLufg== X-Spam-Score: 1.7 (+) X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: * gnu/packages/networking.scm (quagga) [inputs]: Add libxcrypt. [properties]: Add lint-hidden-cve property. --- gnu/packages/networking.scm | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/gnu/packages/networking.scm b/gnu/packages/networking.scm index 67584be64b..910299a0a6 100644 --- a/gnu/packages/networking.scm +++ b/gnu/packages/networking.scm @@ -3139,7 +3139,7 @@ (de [...] Content analysis details: (1.7 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist [URIs: ngraves.fr] 0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [87.98.162.229 listed in bl.score.senderscore.com] 0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [87.98.162.229 listed in sa-accredit.habeas.com] 0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [87.98.162.229 listed in wl.mailspike.net] 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record -0.0 SPF_PASS SPF: sender matches SPF record -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [87.98.162.229 listed in list.dnswl.org] 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: 0.7 (/) * gnu/packages/networking.scm (quagga) [inputs]: Add libxcrypt. [properties]: Add lint-hidden-cve property. --- gnu/packages/networking.scm | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/gnu/packages/networking.scm b/gnu/packages/networking.scm index 67584be64b..910299a0a6 100644 --- a/gnu/packages/networking.scm +++ b/gnu/packages/networking.scm @@ -3139,7 +3139,7 @@ (define-public quagga (delete-file "vtysh/extract.pl"))))) (build-system gnu-build-system) (native-inputs (list gawk gcc-9 pkg-config perl dejagnu)) - (inputs (list readline c-ares)) + (inputs (list c-ares libxcrypt readline)) (synopsis "Routing Software Suite") (description "Quagga is a routing software suite, providing implementations of OSPFv2, OSPFv3, RIP v1 and v2, RIPng and BGP-4 for Unix platforms. @@ -3150,6 +3150,10 @@ (define-public quagga clients which typically implement a routing protocol and communicate routing updates to the zebra daemon.") (home-page "https://www.nongnu.org/quagga/") + ;; This CVE concerns systemd services files that we currently don't use. + ;; If we were to use them, a fixing patch can be found here: + ;; https://build.opensuse.org/request/show/1035188 + (properties '((lint-hidden-cve . ("CVE-2021-44038")))) (license license:gpl2+))) (define-public bgpq3 -- 2.46.0 From unknown Tue Sep 09 18:21:51 2025 MIME-Version: 1.0 X-Mailer: MIME-tools 5.505 (Entity 5.505) X-Loop: help-debbugs@gnu.org From: help-debbugs@gnu.org (GNU bug Tracking System) To: Nicolas Graves Subject: bug#74050: closed (Re: [bug#74050] [PATCH 0/6] Add lint-hidden-cve property for near-leaf packages.) Message-ID: References: <87msicukd2.fsf@gnu.org> <20241027182422.27007-1-ngraves@ngraves.fr> X-Gnu-PR-Message: they-closed 74050 X-Gnu-PR-Package: guix-patches X-Gnu-PR-Keywords: patch Reply-To: 74050@debbugs.gnu.org Date: Wed, 06 Nov 2024 21:27:02 +0000 Content-Type: multipart/mixed; boundary="----------=_1730928422-22310-1" This is a multi-part message in MIME format... ------------=_1730928422-22310-1 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your bug report #74050: [PATCH 0/6] Add lint-hidden-cve property for near-leaf packages. which was filed against the guix-patches package, has been closed. The explanation is attached below, along with your original report. If you require more details, please reply to 74050@debbugs.gnu.org. --=20 74050: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=3D74050 GNU Bug Tracking System Contact help-debbugs@gnu.org with problems ------------=_1730928422-22310-1 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 74050-done) by debbugs.gnu.org; 6 Nov 2024 21:26:18 +0000 Received: from localhost ([127.0.0.1]:46258 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t8nXe-0005ml-5A for submit@debbugs.gnu.org; Wed, 06 Nov 2024 16:26:18 -0500 Received: from eggs.gnu.org ([209.51.188.92]:36226) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t8nXb-0005mW-Fp for 74050-done@debbugs.gnu.org; Wed, 06 Nov 2024 16:26:16 -0500 Received: from fencepost.gnu.org ([2001:470:142:3::e]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t8nVO-0002A4-4q; Wed, 06 Nov 2024 16:23:58 -0500 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org; s=fencepost-gnu-org; h=MIME-Version:Date:References:In-Reply-To:Subject:To: From; bh=ANQ5NH+czFxA774DOA4pA1pf7a2XWXyfx9EdORAvdLE=; b=Sr8uNu9d2AHOAr6KvJzv 4vqfeSay4/fw+aZdxWot/zQmpMzMaGYebLcffAZja/SHsXtNkjOK9/cYxTyQ3KakZNNF7VmYlSZPe iducAkHDpZVTLcOgnsn7OX5mmjPuitFb9gSSxZRg17YFK6qudU7igPtv5SllTpG3t6eBeVvq9UZGh TonSj0BeiLwDr8mYeOyj6qfss1zkPlHH+trf/JoL9YpQX5J+fYajfevAsr1UuqSgz5QkWcxH9L0dV qgjEww+xOcG6maRC5cfFc+9XygaN3OOCSZ2T7WdtmzFAYOsDoxtjBFJO2wdDUms2s+V9hZdgL5FNz BSwZovcJmHhOIw==; From: =?utf-8?Q?Ludovic_Court=C3=A8s?= To: Nicolas Graves Subject: Re: [bug#74050] [PATCH 0/6] Add lint-hidden-cve property for near-leaf packages. In-Reply-To: <20241027182422.27007-1-ngraves@ngraves.fr> (Nicolas Graves's message of "Sun, 27 Oct 2024 19:22:11 +0100") References: <20241027182422.27007-1-ngraves@ngraves.fr> Date: Wed, 06 Nov 2024 22:23:53 +0100 Message-ID: <87msicukd2.fsf@gnu.org> User-Agent: Gnus/5.13 (Gnus v5.13) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Spam-Score: -2.3 (--) X-Debbugs-Envelope-To: 74050-done Cc: 74050-done@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -3.3 (---) Hi, Nicolas Graves skribis: > gnu: gerbv: Add lint-hidden-cve property. > gnu: libgda: Rename patch for guix lint. > gnu: upx: Update to 4.2.4. > gnu: sylpheed: Add release-monitoring-url property. > gnu: openvswitch: Update to 3.4.0. > gnu: quagga: Fix build and hide CVE. Applied, thanks! Ludo=E2=80=99. ------------=_1730928422-22310-1 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by debbugs.gnu.org; 27 Oct 2024 18:25:09 +0000 Received: from localhost ([127.0.0.1]:46275 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t57wr-0003al-Bb for submit@debbugs.gnu.org; Sun, 27 Oct 2024 14:25:09 -0400 Received: from lists.gnu.org ([209.51.188.17]:48882) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t57wp-0003ad-D2 for submit@debbugs.gnu.org; Sun, 27 Oct 2024 14:25:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t57wF-0004zv-OJ for guix-patches@gnu.org; Sun, 27 Oct 2024 14:24:31 -0400 Received: from 6.mo576.mail-out.ovh.net ([46.105.50.107]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t57wD-000861-UC for guix-patches@gnu.org; Sun, 27 Oct 2024 14:24:31 -0400 Received: from director6.ghost.mail-out.ovh.net (unknown [10.109.139.54]) by mo576.mail-out.ovh.net (Postfix) with ESMTP id 4Xc4fy4gN0z1m1P for ; Sun, 27 Oct 2024 18:24:26 +0000 (UTC) Received: from ghost-submission-5b5ff79f4f-6ghlz (unknown [10.111.182.47]) by director6.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 593921FDDC; Sun, 27 Oct 2024 18:24:26 +0000 (UTC) Received: from ngraves.fr ([37.59.142.105]) by ghost-submission-5b5ff79f4f-6ghlz with ESMTPSA id CvlIA1qFHmeJJgAApxVJLg (envelope-from ); Sun, 27 Oct 2024 18:24:26 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-105G00611d15503-81d2-4d16-99c1-3054e6e5c763, E6BF9B87AE7FBE7894246B3B643E76DCC103CD4C) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 From: Nicolas Graves To: guix-patches@gnu.org Subject: [PATCH 0/6] Add lint-hidden-cve property for near-leaf packages. Date: Sun, 27 Oct 2024 19:22:11 +0100 Message-ID: <20241027182422.27007-1-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 9608992758372885218 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdejiedgheekucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffoggfgsedtkeertdertddtnecuhfhrohhmpefpihgtohhlrghsucfirhgrvhgvshcuoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqnecuggftrfgrthhtvghrnhepkeffgeetfffgffejgeejvdffgfdtvdeuueetgfefuedvjeegvdegjeejveeuueevnecukfhppeduvdejrddtrddtrddupdekiedrvdegiedrudelrddvvddupdefjedrheelrddugedvrddutdehnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepuddvjedrtddrtddruddpmhgrihhlfhhrohhmpehnghhrrghvvghssehnghhrrghvvghsrdhfrhdpnhgspghrtghpthhtohepuddprhgtphhtthhopehguhhigidqphgrthgthhgvshesghhnuhdrohhrghdpoffvtefjohhsthepmhhoheejiedpmhhouggvpehsmhhtphhouhht DKIM-Signature: a=rsa-sha256; bh=RoDSJ2L8AcYGTJ73eAMqECerfnVqarCXyePcq8iX5W4=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1730053466; v=1; b=e13tMZqOV6U5NsifwIYm6/mSqp9AZFcGccnAHRR5vEK9W8qoKwKHJHWi8KRQl0tIJrd9Fk8Q ryZ4vmDI6OHgffZeW+ybl4TaqgqauXPMxmgEqSUsdpPrxZ8beGKVKtTEtD6xUAkuIa/u6xhz4d1 OQes97L5VcGIg1i44/SogBGx9yMhTkarMLkzaxkfz+b2TcZFIaGP2kCOLvJyNxZz/l1/5PNzPSE VxjhnA/IVPGyAsTZehXaso02mESEgJDcr/jXgovD9cV34r1gghcIRIjTUjIvJw6Q9K1RFcKoK5I JuHYcqkoMVwgap3nBbvBOcJmRLWVlXFIH3WUk7RSrKYIg== Received-SPF: pass client-ip=46.105.50.107; envelope-from=ngraves@ngraves.fr; helo=6.mo576.mail-out.ovh.net X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.3 (-) X-Debbugs-Envelope-To: submit Cc: Nicolas Graves X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.3 (--) This patch series is what's left of 74034 after I've split it in two. It introduces some useful lint-hidden-cve properties were that's useful, fixing build or updating packages along the way. Nicolas Graves (6): gnu: gerbv: Add lint-hidden-cve property. gnu: libgda: Rename patch for guix lint. gnu: upx: Update to 4.2.4. gnu: sylpheed: Add release-monitoring-url property. gnu: openvswitch: Update to 3.4.0. gnu: quagga: Fix build and hide CVE. gnu/local.mk | 2 +- gnu/packages/compression.scm | 7 ++++--- gnu/packages/engineering.scm | 2 ++ gnu/packages/gnome.scm | 2 +- gnu/packages/mail.scm | 2 ++ gnu/packages/networking.scm | 14 ++++++++++---- ...021-39359.patch => libgda-CVE-2021-39359.patch} | 0 7 files changed, 20 insertions(+), 9 deletions(-) rename gnu/packages/patches/{libgda-cve-2021-39359.patch => libgda-CVE-2021-39359.patch} (100%) -- 2.46.0 ------------=_1730928422-22310-1--