From patchwork Tue Apr 19 09:19:35 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Zhu Zihao X-Patchwork-Id: 38669 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id BC25227BBEA; Tue, 19 Apr 2022 10:53:29 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-2.7 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,FREEMAIL_FROM,MAILING_LIST_MULTI,SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id 8472A27BBE9 for ; Tue, 19 Apr 2022 10:53:29 +0100 (BST) Received: from localhost ([::1]:35330 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1ngkY4-0001Zf-JN for patchwork@mira.cbaines.net; Tue, 19 Apr 2022 05:53:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:39292) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1ngk3f-000256-Hn for guix-patches@gnu.org; Tue, 19 Apr 2022 05:22:05 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:47762) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1ngk3f-0001rH-75 for guix-patches@gnu.org; Tue, 19 Apr 2022 05:22:03 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1ngk3f-0004c8-0t for guix-patches@gnu.org; Tue, 19 Apr 2022 05:22:03 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#55001] gnu: git: Update to 2.36.0 [fixes CVE-2022-24765] Was: Acknowledgement ([PATCH] gnu: git: Update to 2.35.2 [fixes CVE-2022-24765].) Resent-From: Zhu Zihao Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Tue, 19 Apr 2022 09:22:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 55001 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: Greg Hogan Cc: 55001@debbugs.gnu.org Received: via spool by 55001-submit@debbugs.gnu.org id=B55001.165036008017660 (code B ref 55001); Tue, 19 Apr 2022 09:22:02 +0000 Received: (at 55001) by debbugs.gnu.org; 19 Apr 2022 09:21:20 +0000 Received: from localhost ([127.0.0.1]:41653 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1ngk2x-0004al-M5 for submit@debbugs.gnu.org; Tue, 19 Apr 2022 05:21:19 -0400 Received: from mail-m971.mail.163.com ([123.126.97.1]:24835) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1ngk2u-0004aQ-MW for 55001@debbugs.gnu.org; Tue, 19 Apr 2022 05:21:18 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=163.com; s=s110527; h=From:Subject:Date:Message-ID:MIME-Version; bh=22Lky DkomUHbNSGxp9HuMIhEd5qFSN2iO+Gnp5GbC1U=; b=KY6Rz2IrvNmzUm6NLy2sn 5ZNmh3YqupOvFX/sd/24n+lpBfY948E9DzgiJ4EJOtMHQZTm6T9b+XisdHMMzL2H fqTPOOB5b7GOhurTAqeo4iFCZO8g+5uMjLgq9QfweJsO7OADmUhdRwKvOizpi1gX 4SYX0jmSzINbtDM8XlzyOs= Received: from asus-laptop (unknown [27.38.202.0]) by smtp1 (Coremail) with SMTP id GdxpCgCHJX7_fl5iaf28Bw--.14555S2; Tue, 19 Apr 2022 17:21:03 +0800 (CST) References: <8635iabj7y.fsf@163.com> <86y202a2rf.fsf@163.com> User-agent: mu4e 1.6.10; emacs 27.2 From: Zhu Zihao Date: Tue, 19 Apr 2022 17:19:35 +0800 In-reply-to: Message-ID: <86mtgh77k2.fsf@163.com> MIME-Version: 1.0 X-CM-TRANSID: GdxpCgCHJX7_fl5iaf28Bw--.14555S2 X-Coremail-Antispam: 1Uf129KBjDUn29KB7ZKAUJUUUUU529EdanIXcx71UUUUU7v73 VFW2AGmfu7bjvjm3AaLaJ3UbIYCTnIWIevJa73UjIFyTuYvjTE73sFUUUUU X-Originating-IP: [27.38.202.0] X-CM-SenderInfo: pdoosuxxwbztlvw6il2tof0z/xtbBawDnr1et4J5rxwAAsL X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: "Guix-patches" X-getmail-retrieved-from-mailbox: Patches Greg Hogan writes: > And now git 2.36 has been released. A new patch that updates to 2.36 is uploaded. Thanks for your mention :) From bad9eea70d56ec9ace36f7f62c5ea7c8f3e399a3 Mon Sep 17 00:00:00 2001 From: Zhu Zihao Date: Mon, 18 Apr 2022 21:40:19 +0800 Subject: [PATCH] gnu: git: Update to 2.36.0 [fixes CVE-2022-24765]. See https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24765 * gnu/packages/version-control.scm (git): Update to 2.36.0. --- gnu/packages/version-control.scm | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/gnu/packages/version-control.scm b/gnu/packages/version-control.scm index d77c2e51f6..ff9c6f7c14 100644 --- a/gnu/packages/version-control.scm +++ b/gnu/packages/version-control.scm @@ -221,14 +221,14 @@ (define git-cross-configure-flags (define-public git (package (name "git") - (version "2.35.1") + (version "2.36.0") (source (origin (method url-fetch) (uri (string-append "mirror://kernel.org/software/scm/git/git-" version ".tar.xz")) (sha256 (base32 - "100h37cpw49pmlpf6lcpm1xi578gllf6y9in60h5mxj3cj754s6p")))) + "1ly13j37h1y8bgcj3h0cl43vcpwk9j4gsasssk8gar44cp0vypmg")))) (build-system gnu-build-system) (native-inputs `(("native-perl" ,perl) @@ -248,7 +248,7 @@ (define-public git version ".tar.xz")) (sha256 (base32 - "00rqdj2bc3i7pfc16pciiz50ww41jkqg18iy5hi5jnf0y98sgqz4")))) + "0p6vc6nyaibx2lxirjj2nm5spk5q6svz8l3w0pqnaa3i7l7c6qy0")))) ;; For subtree documentation. ("asciidoc" ,asciidoc) ("docbook-xsl" ,docbook-xsl) -- 2.35.1