From patchwork Sat Oct 26 22:29:48 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Nicolas Graves X-Patchwork-Id: 2935 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id 1EE2727BBEA; Sat, 26 Oct 2024 23:33:45 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-6.4 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_BLOCKED, RCVD_IN_VALIDITY_CERTIFIED,RCVD_IN_VALIDITY_RPBL,RCVD_IN_VALIDITY_SAFE, SPF_HELO_PASS,URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id 67DE127BBE2 for ; Sat, 26 Oct 2024 23:33:44 +0100 (BST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1t4pLe-0006cn-TA; Sat, 26 Oct 2024 18:33:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t4pLd-0006cd-8t for guix-patches@gnu.org; Sat, 26 Oct 2024 18:33:29 -0400 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1t4pLc-0005XX-UW for guix-patches@gnu.org; Sat, 26 Oct 2024 18:33:29 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debbugs.gnu.org; s=debbugs-gnu-org; h=MIME-Version:Date:From:To:Subject; bh=TR9DVQxpqO6JNm+Rxl4itS1RT8Pscd28W9kCvoLnsM0=; b=dJ3hXatsw2L87vrIFN1yWcYrarVn9PDJU/2hxaWmGM7FN2o1WOlLq2tKShlzQSr8KBiPTSUPW4ZbBxpPGhLE75hneM+LSDMwQmL3Ck54+EvHq94URN1/uK5XSzSlxYigNJrB3OVu7fVvXN/KA6xaeTpL5+mPkzOH3wTI44+bqftomWk2tneeA/qb3U+iP0zFuYNVVWnq1KlhD14gHaG1KS/P+TA+TsJTMJb6+644ZSvBDmaManaviSnqKV4wB0SeTfmBC5emVAtWKSXG4ilKhs5eF7KJG/G1TxXy/xvsikGV31nbSXP4OQ7bElNwfQ8mcL3R56RJYn9da7MzPbO6hA==; Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1t4pMA-00067h-Py for guix-patches@gnu.org; Sat, 26 Oct 2024 18:34:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#74035] [PATCH 00/24] [security fixes] for near-leaf packages Resent-From: Nicolas Graves Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sat, 26 Oct 2024 22:34:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 74035 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 74035@debbugs.gnu.org Cc: Nicolas Graves X-Debbugs-Original-To: guix-patches@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.172998200423482 (code B ref -1); Sat, 26 Oct 2024 22:34:02 +0000 Received: (at submit) by debbugs.gnu.org; 26 Oct 2024 22:33:24 +0000 Received: from localhost ([127.0.0.1]:42846 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t4pLX-00066g-VZ for submit@debbugs.gnu.org; Sat, 26 Oct 2024 18:33:24 -0400 Received: from lists.gnu.org ([209.51.188.17]:48912) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t4pLW-00066Z-IW for submit@debbugs.gnu.org; Sat, 26 Oct 2024 18:33:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t4pKy-0006af-2d for guix-patches@gnu.org; Sat, 26 Oct 2024 18:32:48 -0400 Received: from 11.mo584.mail-out.ovh.net ([46.105.34.195]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1t4pKw-0005Pp-A8 for guix-patches@gnu.org; Sat, 26 Oct 2024 18:32:47 -0400 Received: from director10.ghost.mail-out.ovh.net (unknown [10.108.2.179]) by mo584.mail-out.ovh.net (Postfix) with ESMTP id 4XbZCt4jXXz1Pl8 for ; Sat, 26 Oct 2024 22:32:42 +0000 (UTC) Received: from ghost-submission-5b5ff79f4f-7f7jj (unknown [10.110.113.115]) by director10.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 488761FDDC; Sat, 26 Oct 2024 22:32:42 +0000 (UTC) Received: from ngraves.fr ([37.59.142.98]) by ghost-submission-5b5ff79f4f-7f7jj with ESMTPSA id vDxXBwpuHWdU3QIALPKLSA (envelope-from ); Sat, 26 Oct 2024 22:32:42 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-98R0021f91fe0c-76e0-4846-8668-17f2e16d3842, E6BF9B87AE7FBE7894246B3B643E76DCC103CD4C) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 Date: Sun, 27 Oct 2024 00:29:48 +0200 Message-ID: <20241026223238.26667-1-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 MIME-Version: 1.0 X-Ovh-Tracer-Id: 7929150095631442658 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdejhedgudduucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffoggfgsedtkeertdertddtnecuhfhrohhmpefpihgtohhlrghsucfirhgrvhgvshcuoehnghhrrghvvghssehnghhrrghvvghsrdhfrheqnecuggftrfgrthhtvghrnhepkeffgeetfffgffejgeejvdffgfdtvdeuueetgfefuedvjeegvdegjeejveeuueevnecukfhppeduvdejrddtrddtrddupdekiedrvdegiedrudelrddvvddupdefjedrheelrddugedvrdelkeenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepihhnvghtpeduvdejrddtrddtrddupdhmrghilhhfrhhomhepnhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrpdhnsggprhgtphhtthhopedupdhrtghpthhtohepghhuihigqdhprghttghhvghssehgnhhurdhorhhgpdfovfetjfhoshhtpehmohehkeegpdhmohguvgepshhmthhpohhuth DKIM-Signature: a=rsa-sha256; bh=TR9DVQxpqO6JNm+Rxl4itS1RT8Pscd28W9kCvoLnsM0=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1729981962; v=1; b=Ml22yt/NriKXGi/3AbiIxXMOF2lIMYZeLWyeiamdW7DV5dX+Su3DPzzsFSUGlcw+C2Gf5Tmm sRd1KVrwbpuLwb5DNMTxwqaP7Q5Qf2VoCdgEJ+oMvYWlxYFxilytg0XBFPLnugTn4SM0ruEu0Zd O5H1Ij2u7tpXQNddcrph3rTs4/65mWEtT8t3yMrvrBTJnDn/9UWPIF0U1gcz6hPwsrKiaoDm8PO yZUmIRhcg14TXQbrb9QVyKwJjbqZmoOO3JkjZw8CPiSUq7GdH7sMMtXB7Az+ZK6eYGKbWbMi4+d M1mvyMJoYN2GrgEiNvD9gYikwVe7omy09EfFfdtrWr64w== Received-SPF: pass client-ip=46.105.34.195; envelope-from=ngraves@ngraves.fr; helo=11.mo584.mail-out.ovh.net X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-to: Nicolas Graves X-ACL-Warn: , Nicolas Graves via Guix-patches X-Patchwork-Original-From: Nicolas Graves via Guix-patches via From: Nicolas Graves Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org X-getmail-retrieved-from-mailbox: Patches This patch series adds updates and security fixes for packages that have less than 10 dependent packages. Nicolas Graves (24): gnu: python-django-4.2: Update to 4.2.16. [security fixes] gnu: maradns: Update to 3.5.0036. [security fixes] gnu: maradns: Improve style. gnu: libmobi: Update to 0.12. [security fixes] gnu: bart: Update to 0.9.00. [security fixes] gnu: wireshark: Update to 4.4.1. [security fixes] gnu: pam-u2f: Update to 1.3.0. [security fixes] gnu: darkhttpd: Update to 1.16. [security fixes] gnu: xlsxio: Update to 0.2.35. [security fixes] gnu: pypy: Update to 7.3.17. [security fixes] gnu: indent: Remove uneeded arguments. gnu: indent: Add patch for CVE-2024-0911. [security fixes] gnu: squashfs-tools: Update to 4.6.1. [security fixes] gnu: shapelib: Update to 1.6.1. [security fixes] gnu: libzapojit: Update to 0.0.3-1.99d49ba. [security fixes] gnu: gifsicle: Update to 1.95. [security fixes] gnu: sendmail: Update to 8.18.1. [security fixes] gnu: openvpn: Update to 2.6.12. [security fixes] gnu: youtube-dl: Deprecate package. gnu: liblouis: Update to 3.31.0. [security fixes] gnu: unicorn: Update to 2.1.1. [security fixes] gnu: Add sexpp. gnu: rnp: Update to 0.17.1. [security fixes] gnu: cjson: Update to 1.7.18. [security fixes] gnu/local.mk | 1 + gnu/packages/code.scm | 31 +------- gnu/packages/compression.scm | 52 ++++++------- gnu/packages/django.scm | 8 +- gnu/packages/dns.scm | 64 ++++++++-------- gnu/packages/ebook.scm | 4 +- gnu/packages/emulators.scm | 9 ++- gnu/packages/geo.scm | 8 +- gnu/packages/gnome.scm | 45 ++++++----- gnu/packages/image-processing.scm | 8 +- gnu/packages/image.scm | 4 +- gnu/packages/javascript.scm | 4 +- gnu/packages/language.scm | 47 ++++++------ gnu/packages/mail.scm | 5 +- gnu/packages/networking.scm | 4 +- gnu/packages/openpgp.scm | 76 +++++++++++++------ .../patches/indent-CVE-2024-0911.patch | 61 +++++++++++++++ gnu/packages/pypy.scm | 4 +- gnu/packages/security-token.scm | 9 +-- gnu/packages/video.scm | 3 +- gnu/packages/vpn.scm | 4 +- gnu/packages/web.scm | 24 +++--- gnu/packages/xml.scm | 4 +- 23 files changed, 278 insertions(+), 201 deletions(-) create mode 100644 gnu/packages/patches/indent-CVE-2024-0911.patch