From patchwork Sat Oct 26 22:21:26 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Nicolas Graves X-Patchwork-Id: 2934 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id 61C4027BBEA; Sat, 26 Oct 2024 23:30:49 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-6.4 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_BLOCKED, RCVD_IN_VALIDITY_CERTIFIED,RCVD_IN_VALIDITY_RPBL,RCVD_IN_VALIDITY_SAFE, SPF_HELO_PASS,URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id 9A4BF27BBE2 for ; Sat, 26 Oct 2024 23:30:48 +0100 (BST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1t4pIn-0006QG-UU; Sat, 26 Oct 2024 18:30:34 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t4pIj-0006Pr-Up for guix-patches@gnu.org; Sat, 26 Oct 2024 18:30:30 -0400 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1t4pIj-00058u-9U for guix-patches@gnu.org; Sat, 26 Oct 2024 18:30:29 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debbugs.gnu.org; s=debbugs-gnu-org; h=MIME-Version:Date:From:To:Subject; bh=saa4kszOosd5q17mZlp9k9IHTrET1K1Ye5hUHuq70oc=; b=GWwxs6f+/UbID/9MAPoORK4cyh8wsLN9momWa/0vszpd1rnFfqME2Y/Yuv5bwswuFDc/gltlLzRLBGvzBAZPsE0m7aAtPczh7kdb+gi5IbZcsl2vBFEU3fD0IYCI2Oslhm6W6TJg3jsVLdYlD8dyYQQtJvDUhh4Gf18l46FRxc3r1m+EBR9rk5T3UjKnC9Q6NPD9oRdKMLOnQZkWIi3ZMP9PoDv0ypOErK2x/65nwecUy4Rmgr9ZrTl7LvGjbhrdZWjvSQ36oyROLlN7bkw9hxy2uROGZrgBfYKTt28cH3tBjNQ42ClNDol90wJW8E03Fipk6n0VbMmO12zNoHqUnA==; Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1t4pJG-00062d-QX for guix-patches@gnu.org; Sat, 26 Oct 2024 18:31:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#74034] [PATCH 00/21] Add lint-hidden-cve property for near-leaf packages. Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sat, 26 Oct 2024 22:31:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 74034 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 74034@debbugs.gnu.org Cc: Nicolas Graves X-Debbugs-Original-To: guix-patches@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.172998183722803 (code B ref -1); Sat, 26 Oct 2024 22:31:02 +0000 Received: (at submit) by debbugs.gnu.org; 26 Oct 2024 22:30:37 +0000 Received: from localhost ([127.0.0.1]:42837 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t4pIr-0005vi-7J for submit@debbugs.gnu.org; Sat, 26 Oct 2024 18:30:37 -0400 Received: from lists.gnu.org ([209.51.188.17]:46060) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t4pIn-0005vY-VU for submit@debbugs.gnu.org; Sat, 26 Oct 2024 18:30:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t4pID-0006Ir-40 for guix-patches@gnu.org; Sat, 26 Oct 2024 18:29:57 -0400 Received: from 9.mo583.mail-out.ovh.net ([178.32.96.204]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t4pIA-0004me-Mk for guix-patches@gnu.org; Sat, 26 Oct 2024 18:29:56 -0400 Received: from director10.ghost.mail-out.ovh.net (unknown [10.109.148.38]) by mo583.mail-out.ovh.net (Postfix) with ESMTP id 4XbZ8N2ZP7z1NRX for ; Sat, 26 Oct 2024 22:29:40 +0000 (UTC) Received: from ghost-submission-5b5ff79f4f-2tr4x (unknown [10.110.96.26]) by director10.ghost.mail-out.ovh.net (Postfix) with ESMTPS id DB02E1FDDC; Sat, 26 Oct 2024 22:29:39 +0000 (UTC) Received: from ngraves.fr ([37.59.142.95]) by ghost-submission-5b5ff79f4f-2tr4x with ESMTPSA id Q/FtGlNtHWfvBRMA8ngY+Q (envelope-from ); Sat, 26 Oct 2024 22:29:39 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-95G001ad0f7def-4b0e-468f-89a2-21d16ebfc1d9, E6BF9B87AE7FBE7894246B3B643E76DCC103CD4C) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 Date: Sun, 27 Oct 2024 00:21:26 +0200 Message-ID: <20241026222934.25890-1-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 MIME-Version: 1.0 X-Ovh-Tracer-Id: 7877921649261273826 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdejhedgudduucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffoggfgsedtkeertdertddtnecuhfhrohhmpefpihgtohhlrghsucfirhgrvhgvshcuoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqnecuggftrfgrthhtvghrnhepkeffgeetfffgffejgeejvdffgfdtvdeuueetgfefuedvjeegvdegjeejveeuueevnecukfhppeduvdejrddtrddtrddupdekiedrvdegiedrudelrddvvddupdefjedrheelrddugedvrdelheenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepihhnvghtpeduvdejrddtrddtrddupdhmrghilhhfrhhomhepnhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrpdhnsggprhgtphhtthhopedupdhrtghpthhtohepghhuihigqdhprghttghhvghssehgnhhurdhorhhgpdfovfetjfhoshhtpehmohehkeefpdhmohguvgepshhmthhpohhuth DKIM-Signature: a=rsa-sha256; bh=saa4kszOosd5q17mZlp9k9IHTrET1K1Ye5hUHuq70oc=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1729981780; v=1; b=0J3eZMzBGtpVDNVsK517cgizxfhsoyqUll+6gmn/sBw5HIr7mPWIGxsT96jqfvrJDEaT656t Sc6SKzQYfyMftUEKg+Qoa2o3+QkFyKulEC9gpTqsD91I3wkm2r7shwUAzvCA7/pMWZ9wkVV/KxL vWEyjBKMAfCGiwLMLWcOO0aZQOPMp9X+7bP/xo9Xf7fXilU8V2IJCrK0nM3TK9eaxlAnIkkHMf1 LC1rpyOlarrjIaCbzR/5PjcLJeeXXku7LwpgWKFtADMeqwQ9Rlj02eu2d0hIooo5lsPGOaLNbMF 31yBnqYdvmrLMbnrg+q6EVwjQWcKidQgQFQ2hKj9fj82A== Received-SPF: pass client-ip=178.32.96.204; envelope-from=ngraves@ngraves.fr; helo=9.mo583.mail-out.ovh.net X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-to: Nicolas Graves X-ACL-Warn: , Nicolas Graves via Guix-patches X-Patchwork-Original-From: Nicolas Graves via Guix-patches via From: Nicolas Graves Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org X-getmail-retrieved-from-mailbox: Patches This patch series is adding lint-hidden-cve properties for packages that have less than 10 dependents. Some packages of these packages have been updated, only when the update was trivial and harmless. This is not applying any security fix by itself, but will help security-related work. Nicolas Graves (21): gnu: libgda: Rename patch for guix lint. gnu: upx: Update to 4.2.4. gnu: halibut: Add lint-hidden-cve property. gnu: portfolio: Update to 1.0.1. gnu: folders: Add lint-hidden-cve property. gnu: spectra: Add lint-hidden-cve property. gnu: express: Add lint-hidden-cve property. gnu: cli: Add lint-hidden-cve property. gnu: h2c: Add lint-hidden-cve property. gnu: xenon: Update to 0.9.3. gnu: bolt: Update to 0.9.8. gnu: sylpheed: Add release-monitoring-url property. gnu: openvswitch: Update to 3.4.0. gnu: quagga: Fix build and hide CVE. gnu: bwm-ng: Add lint-hidden-cve property. gnu: onedrive: Update to 2.5.2. gnu: got: Update to 0.104. gnu: dex: Update to 0.10.1. gnu: immer: Add lint-hidden-cve property. gnu: cvs: Add lint-hidden-cve property. gnu: gerbv: Add lint-hidden-cve property. gnu/local.mk | 2 +- gnu/packages/algebra.scm | 2 ++ gnu/packages/bioinformatics.scm | 2 ++ gnu/packages/code.scm | 6 ++++-- gnu/packages/compression.scm | 7 ++++--- gnu/packages/cpp.scm | 4 ++++ gnu/packages/curl.scm | 2 ++ gnu/packages/documentation.scm | 16 ++++++++------ gnu/packages/engineering.scm | 2 ++ gnu/packages/esolangs.scm | 8 +++++++ gnu/packages/gnome-xyz.scm | 6 ++++-- gnu/packages/gnome.scm | 2 +- gnu/packages/linux.scm | 21 ++++++++++++------- gnu/packages/mail.scm | 2 ++ gnu/packages/networking.scm | 16 ++++++++++---- ...9359.patch => libgda-CVE-2021-39359.patch} | 0 gnu/packages/sync.scm | 8 +++++-- gnu/packages/version-control.scm | 13 +++++++++--- gnu/packages/xdisorg.scm | 19 ++++++++++------- 19 files changed, 99 insertions(+), 39 deletions(-) rename gnu/packages/patches/{libgda-cve-2021-39359.patch => libgda-CVE-2021-39359.patch} (100%)