Commit Graph

2360 Commits

Author SHA1 Message Date
Alyssa Ross
ba23c14b84
gnupg: apply default server CA verification patch
See discussion at
https://github.com/NixOS/nixpkgs/pull/63952#issuecomment-507048690.

Upstream commit:

commit 1c9cc97e9d47d73763810dcb4a36b6cdf31a2254
Author: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
Date:   Sun Jun 30 11:54:35 2019 -0400

    dirmngr: Only use SKS pool CA for SKS pool

    * dirmngr/http.c (http_session_new): when checking whether the
    keyserver is the HKPS pool, check specifically against the pool name,
    as ./configure might have been used to select a different default
    keyserver.  It makes no sense to apply Kristian's certificate
    authority to anything other than the literal host
    hkps.pool.sks-keyservers.net.

    Signed-off-by: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
    GnuPG-Bug-Id: 4593
2019-06-30 19:06:17 +00:00
Alyssa Ross
c727083e65
gnupg: change default keyserver to non-SKS
See https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f.

The SKS network is vulnerable to certificate poisoning, which can
destroy GnuPG installations. keys.openpgp.org is a new non-SKS keyserver
that is resistant to this type of attack.

With such an attack being possible, it is unsafe to use SKS keyservers
for almost anything, and so we should protect our users from a now
unsafe default. keys.openpgp.org offers some (but not all) functionality
of SKS, and is better than nothing.

This default is only present in gnupg22. gnupg20 and gnupg1orig are not
affected.
2019-06-30 14:09:02 +00:00
Frederik Rietdijk
d843e16cb8 Merge master into staging-next 2019-06-26 13:22:30 +02:00
Sarah Brofeldt
8f56d3eb04
Merge pull request #63310 from ckauhaus/vulnix-1.8.2
vulnix: 1.8.1 -> 1.8.2
2019-06-25 17:08:43 +02:00
Frederik Rietdijk
dafee3d91a Merge master into staging-next 2019-06-23 15:38:41 +02:00
R. RyanTM
b51c87b9df duo-unix: 1.11.1 -> 1.11.2
Semi-automatic update generated by
https://github.com/ryantm/nixpkgs-update tools. This update was made
based on information from
https://repology.org/metapackage/duo-unix/versions
2019-06-23 14:58:06 +02:00
Frederik Rietdijk
72d647f3d8 Merge master into staging-next 2019-06-21 08:20:26 +02:00
Mario Rodas
fe0d86317c
Merge pull request #63453 from r-ryantm/auto-update/vault
vault: 1.1.2 -> 1.1.3
2019-06-19 19:28:17 -05:00
R. RyanTM
f7908ef57e vault: 1.1.2 -> 1.1.3
Semi-automatic update generated by
https://github.com/ryantm/nixpkgs-update tools. This update was made
based on information from
https://repology.org/metapackage/vault/versions
2019-06-18 09:24:55 -07:00
Vladyslav M
abf2c876d6
hcxtools: 5.1.4 -> 5.1.6 (#63264)
hcxtools: 5.1.4 -> 5.1.6
2019-06-18 12:46:57 +03:00
Frederik Rietdijk
f120248daf Merge staging-next into staging 2019-06-18 11:07:56 +02:00
Matthew Bauer
4d6f65b81f
Merge pull request #62167 from matthewbauer/alias-libgl
Add libGL* aliases
2019-06-17 15:18:29 -04:00
Matthew Bauer
263f5891b6 treewide: mesa_noglu, mesa_drivers, libGL_driver -> mesa
Just use mesa for these to be more clear. Move these to aliases.nix
2019-06-17 14:43:18 -04:00
R. RyanTM
7b2b0187cc bitwarden_rs-vault: 2.10.0 -> 2.10.1
Semi-automatic update generated by
https://github.com/ryantm/nixpkgs-update tools. This update was made
based on information from
https://repology.org/metapackage/bitwarden_rs-vault/versions
2019-06-17 15:29:56 +02:00
Christian Kauhaus
99bade5fdb vulnix: 1.8.1 -> 1.8.2 2019-06-17 10:57:35 +02:00
R. RyanTM
7295e0122a hcxtools: 5.1.4 -> 5.1.6
Semi-automatic update generated by
https://github.com/ryantm/nixpkgs-update tools. This update was made
based on information from
https://repology.org/metapackage/hcxtools/versions
2019-06-16 18:52:59 -07:00
volth
f3282c8d1e treewide: remove unused variables (#63177)
* treewide: remove unused variables

* making ofborg happy
2019-06-16 19:59:05 +00:00
Frederik Rietdijk
7184efb40a Merge master into staging-next 2019-06-12 09:22:07 +02:00
Mario Rodas
9edf8f73f7 sops: 3.3.0 -> 3.3.1 2019-06-12 09:17:45 +02:00
Frederik Rietdijk
e58f0f6c99 Merge master into staging-next 2019-06-10 10:35:50 +02:00
Ryan Mulligan
621c8f6b9b
Merge pull request #62568 from r-ryantm/auto-update/shc
shc: 4.0.1 -> 4.0.2
2019-06-09 13:29:05 -07:00
Frederik Rietdijk
d3afcac771 Merge master into staging-next 2019-06-09 12:28:52 +02:00
Pascal Wittmann
b48110889e
Merge pull request #62696 from dtzWill/update/radamsa-0.6
radamsa: 0.5 -> 0.6
2019-06-07 12:12:42 +02:00
Vladimír Čunát
c0ccf42c69
Merge branch 'staging-next' into staging 2019-06-05 11:12:34 +02:00
Will Dietz
e3b8fcc310
radamsa: 0.5 -> 0.6
* new home (github -> gitlab)
* "modernize" a bit
* run tests!
2019-06-04 15:28:15 -05:00
Will Dietz
0e3a443f58
john: 1.8.0-jumbo-1 -> 1.9.0-jumbo-1
https://www.openwall.com/lists/announce/2019/05/14/1
2019-06-04 15:02:28 -05:00
Georges Dubus
537d213df5
Merge pull request #62220 from madjar/keybase-4.0.0
keybase,keybase-gui: 3.2.2 -> 4.0.0
2019-06-04 17:01:11 +02:00
Vladyslav M
b36bf7e2e2
hashcat: 5.0.0 -> 5.1.0 (#62142)
hashcat: 5.0.0 -> 5.1.0
2019-06-04 01:46:26 +03:00
Vladimír Čunát
ee86a325dd
Merge branch 'staging-next' into staging
Conflicts (simple):
	nixos/doc/manual/release-notes/rl-1909.xml
2019-06-03 22:34:49 +02:00
Lorenzo Manacorda
43a65d7b7a paperkey: use HTTPS 2019-06-03 13:51:02 +02:00
R. RyanTM
03be5e7ac3 shc: 4.0.1 -> 4.0.2
Semi-automatic update generated by
https://github.com/ryantm/nixpkgs-update tools. This update was made
based on information from
https://repology.org/metapackage/shc/versions
2019-06-02 20:37:13 -07:00
markuskowa
633d181f04
Merge pull request #62364 from r-ryantm/auto-update/bruteforce-luks
bruteforce-luks: 1.3.1 -> 1.3.2
2019-06-01 13:22:43 +02:00
markuskowa
ab421c0dc7
Merge pull request #62343 from r-ryantm/auto-update/aide
aide: 0.16.1 -> 0.16.2
2019-06-01 11:35:42 +02:00
R. RyanTM
6bb054cd62 bruteforce-luks: 1.3.1 -> 1.3.2
Semi-automatic update generated by
https://github.com/ryantm/nixpkgs-update tools. This update was made
based on information from
https://repology.org/metapackage/bruteforce-luks/versions
2019-06-01 00:56:49 -07:00
R. RyanTM
b6dd281f54 aide: 0.16.1 -> 0.16.2
Semi-automatic update generated by
https://github.com/ryantm/nixpkgs-update tools. This update was made
based on information from
https://repology.org/metapackage/aide/versions
2019-05-31 20:29:11 -07:00
Maximilian Bosch
479d161f00
Merge pull request #62218 from costrouc/rofi-pass-new-dependency
rofi-pass: refactor add new optional dependency pass-otp
2019-05-30 10:57:12 +02:00
Vladyslav M
f71eeb3735
Merge pull request #62149 from dywedir/hcxtools
hcxtools: init at 5.1.4
2019-05-30 10:13:50 +03:00
Georges Dubus
67406e2869 keybase,keybase-gui: 3.2.2 -> 4.0.0 2019-05-29 17:24:27 +02:00
Chris Ostrouchov
2623df3b09
rofi-pass: refactor add new optional dependency pass-otp
Rofi-pass as of a year ago added support for OTP passwords. This
dependency is "optional" but extremely nice to have as a default.

https://github.com/carnager/rofi-pass#requirements
2019-05-29 10:06:37 -04:00
Will Dietz
3f7657d7fb
gnupg: 2.2.15 -> 2.2.16
https://dev.gnupg.org/T4509
2019-05-28 21:06:20 -05:00
Vladyslav M
8c3dfab331
hcxtools: init at 5.1.4 2019-05-28 14:29:51 +03:00
Vladyslav M
b39e516708
hashcat: 5.0.0 -> 5.1.0 2019-05-28 11:51:43 +03:00
Frederik Rietdijk
36a6746f21 Merge master into staging-next 2019-05-28 08:32:03 +02:00
Silvan Mosberger
254cccd22d
Merge pull request #62085 from michaelpj/fix/fprintd-sysconfdir
fprintd: set sysconfdir
2019-05-27 18:05:35 +02:00
Robert Schütz
6bed56dafc spectre-meltdown-checker: 0.41 -> 0.42 2019-05-27 15:46:23 +02:00
Tristan Helmich (omniIT)
c5be0e5f05 hashcat-utils: init at 1.9 2019-05-27 11:02:56 +00:00
Michael Peyton Jones
1bb51a3a86
fprintd: set sysconfdir 2019-05-26 14:05:11 +01:00
Frederik Rietdijk
b2ab860db3 Merge master into staging-next 2019-05-25 12:38:00 +02:00
Justin Humm
ad6a5824ee opensc: add patch for CVE-2019-6502
Closes #61957
2019-05-25 08:29:04 +02:00
Frederik Rietdijk
6e4e7c5dc6 Merge master into staging-next 2019-05-24 12:39:37 +02:00