[bug#76819,v7,21/35] gnu: jq: Add lint-hidden-cve property.

Message ID 20250307183914.8825-21-ngraves@ngraves.fr
State New
Headers
Series Add lint-hidden-cpe-vendors property |

Commit Message

Nicolas Graves March 7, 2025, 6:38 p.m. UTC
  * gnu/packages/web.scm (jq)[properties]: Add lint-hidden-cve property.
---
 gnu/packages/web.scm | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)
  

Patch

diff --git a/gnu/packages/web.scm b/gnu/packages/web.scm
index 193241bcf3..25436c32ab 100644
--- a/gnu/packages/web.scm
+++ b/gnu/packages/web.scm
@@ -5608,7 +5608,10 @@  (define-public jq
 mangle the data format that you have into the one that you want with very
 little effort, and the program to do so is often shorter and simpler than
 you'd expect.")
-    (license (list license:expat license:cc-by3.0))))
+    (license (list license:expat license:cc-by3.0))
+    ;; Both those CVEs are actually fixed in version 1.7.1.
+    (properties `((lint-hidden-cve . ("CVE-2023-50246"
+                                      "CVE-2023-50268"))))))
 
 (define-public go-github-com-mikefarah-yq-v4
   (package