Commit Graph

179259 Commits

Author SHA1 Message Date
c0bw3b
9a48332935 dcraw: mark as vulnerable 2019-11-20 19:46:14 +01:00
c0bw3b
a13779a779 opencv: disable jasper by default
jasper has many unfixed CVEs, upstream disable its use by default
https://github.com/opencv/opencv/issues/14058
2019-11-20 19:46:14 +01:00
c0bw3b
d2a536ff9a openscenegraph: disable jasper by default 2019-11-20 19:46:14 +01:00
c0bw3b
9ee141e8c4 libraw: disable JPEG2000 support by default
jasper has many security issues and it's only used for some
old Redcine cameras. See:
https://github.com/LibRaw/LibRaw/issues/69
2019-11-20 19:46:14 +01:00
c0bw3b
329270e852 libicns: replace jasper with openjpeg 2019-11-20 19:46:13 +01:00
c0bw3b
652a178840 grib-api: replace jasper with openjpeg 2019-11-20 19:46:13 +01:00
c0bw3b
9aa62321ea gdk-pixbuf: disable JPEG2000 support
jasper has unfixed CVE
Upstream has no plan to switch to openjpeg AFAICT
2019-11-19 22:19:08 +01:00
c0bw3b
0a443f4c72 kodi: drop jasper dependency
Unused since:
424c5138b6
2019-11-17 19:36:29 +01:00
c0bw3b
ab8889d8b1 k2pdfopt: disable JPEG2000 support by default
jasper has unfixed CVE
2019-11-17 19:32:27 +01:00
c0bw3b
acd9058931 digikam: disable JPEG2000 support by default
jasper has several unfixed CVE and seems unmaintained
Upstream open bug to replace it with OpenJPEG is:
https://bugs.kde.org/show_bug.cgi?id=364231
2019-11-17 19:28:05 +01:00
c0bw3b
9315000432 saga: remove jasper from inputs
It is unused since v2.2.6 (2016)
https://sourceforge.net/p/saga-gis/bugs/224/
2019-11-17 19:17:12 +01:00
Florian Klink
9daa5b7a6d
Merge pull request #73516 from risicle/ris-fribidi-CVE-2019-18397
fribidi: add patch for CVE-2019-18397
2019-11-17 18:02:23 +01:00
Robert Scott
55b583d334 fribidi: add patch for CVE-2019-18397 2019-11-16 19:55:48 +00:00
Robert Scott
6217e94778 ghostscript: add patch for CVE-2019-14869 2019-11-16 13:36:25 +00:00
Aaron Andersen
f0e68d7977
Merge pull request #73244 from volth/cpan2nix-2019-11-11
perlPackages.LWPUserAgentDNSHosts: init at 0.13
2019-11-15 06:00:07 -05:00
Jan Tojnar
94d4fe8546
Merge branch 'staging-next' into staging 2019-11-14 23:25:55 +01:00
Jan Tojnar
da76deffd1
Merge branch 'master' into staging-next 2019-11-14 23:25:36 +01:00
Jan Tojnar
2024d55020
meson: fix unknown compiler error (#73423)
meson: fix unknown compiler error
2019-11-14 23:24:54 +01:00
Guanpeng Xu
66d5277375 mathematica: fix version issue with zlib (#73425) 2019-11-14 17:19:30 -05:00
Jan Tojnar
3108c4dd15
meson: fix unknown compiler error 2019-11-14 22:54:37 +01:00
Jan Tojnar
21f3586b03
meson: fix patch URL
Hopefully commits will be more stable.
2019-11-14 22:39:34 +01:00
Renaud
32b0cb0f46
Merge pull request #70604 from moaxcp/asciidoctorj
asciidoctorj init at 2.1.0
2019-11-14 22:30:45 +01:00
Renaud
df7cdb37ce
Merge pull request #71057 from jansol/renderdoc
renderdoc: 1.4 -> 1.5
2019-11-14 21:45:22 +01:00
Daniel Schaefer
a2aaa7cdf4 protocol: 20171226 -> 2019-03-28 2019-11-15 05:36:47 +09:00
Jan Tojnar
c846ede763
gstreamer 1.16.1 (#70690)
gstreamer 1.16.1
2019-11-14 21:33:25 +01:00
Doron Behar
c32ecb4b0e luaPackages.pulseaudio: 0.1 -> 0.2 2019-11-15 05:24:19 +09:00
Mario Rodas
669a6d0edb luaPackages.luasystem: fix build on darwin 2019-11-15 05:08:45 +09:00
Nathan van Doorn
00c866bf62 intecture-cli: use openssl 1.0.2
(#70614)
2019-11-14 20:19:14 +01:00
Pascal Bach
ec1a73201e plex: 1.18.0.1944 -> 1.18.1.1973
(#72196)
2019-11-14 19:49:47 +01:00
John Ericson
bca2e8255e treewide: CAML_LD_LIBRARY_PATH may be undefined 2019-11-14 13:44:07 -05:00
Aaron Andersen
2295a94fc1 mariadb: 10.3.18 -> 10.3.20 2019-11-14 10:13:27 -08:00
Renaud
e8de40db65
Merge pull request #72212 from lightbulbjim/openrct2-update
openrct2: 0.2.3 -> 0.2.4
2019-11-14 18:55:24 +01:00
Lily Ballard
66b094c780 jazzy: 0.11.2 -> 0.12.0 2019-11-14 09:48:18 -08:00
Kyle Sferrazza
5434a2b8a5 mattermost: fix path in desktop file 2019-11-14 09:42:29 -08:00
adisbladis
e578b8499f fetchgitPrivate: Remove fetcher
Since Nix 2.0 we have `builtins.fetchGit` which is a much better
option since it runs in the evaluator and has access to the regular
users ssh keys.
2019-11-14 09:34:12 -08:00
Sascha Grunert
65e7d9c8c9 kubernetes-helm: 2.15.1 -> 3.0.0
Signed-off-by: Sascha Grunert <sgrunert@suse.com>
2019-11-14 09:31:31 -08:00
Sebastian Graf
de121909d2 libinput-gestures: Add coreutils to $PATH
Otherwise it can't find `stdbuf` when run as a systemd service.
2019-11-14 09:30:59 -08:00
Tristan Helmich (omniIT)
83b221bc6c davmail: 5.2.0 -> 5.4.0 2019-11-14 09:24:50 -08:00
worldofpeace
682930b790 celluloid: add worldofpeace to maintainers 2019-11-14 09:18:35 -08:00
worldofpeace
911bc93fe1 celluloid: 0.17 -> 0.18
Also don't sed out gtk-update-icon-cache, we have
setup to remove these caches.
2019-11-14 09:18:35 -08:00
Christian Kauhaus
be83d68556 vulnix: 1.8.2 -> 1.9.1
New upstream release. The old version is broken because NIST has
discontinued NVD XML feeds. vulnix 1.9.x uses the JSON feeds.
2019-11-14 09:14:30 -08:00
Niklas Hambüchen
5245766158 consul-alerts: 0.5.0 -> 0.6.0
Changelog: https://github.com/AcalephStorage/consul-alerts/releases/tag/v0.6.0
2019-11-14 18:12:46 +01:00
rht
b754a308f7 brave: 0.69.135 -> 1.0.0 2019-11-14 09:09:43 -08:00
Mario Rodas
1ae55b884d python3Packages.black: fix build on darwin 2019-11-14 08:53:09 -08:00
Florian Klink
b64034e1d2 python3.pkgs.authlib: init at 0.13
Co-authored-by: Jonathan Ringer <jonringer117@gmail.com>
2019-11-14 08:50:37 -08:00
Renaud
ab397825bf
Merge pull request #70507 from sikmir/qtpbfimageplugin
qtpbfimageplugin: 1.4 -> 2.0
2019-11-14 16:55:59 +01:00
Renaud
5b57dd52a7
Merge pull request #73369 from JohnAZoidberg/argp-standalone-cross
argp-standalone: Find ar when cross compiling
2019-11-14 16:53:21 +01:00
Sascha Grunert
08fa83ce52 conmon: v2.0.2 -> v2.0.3
Signed-off-by: Sascha Grunert <sgrunert@suse.com>
2019-11-14 16:47:48 +01:00
Edmund Wu
a951f2a27f mesa: 19.2.3 -> 19.2.4 2019-11-14 16:42:45 +01:00
Bastien Rivière
136c6c1815 terraform: 0.12.13 -> 0.12.14 (#73393)
update terraform to it's latest version
2019-11-14 15:30:19 +00:00