guix-commits
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

03/03: gnu: nghttp2: Replace with 1.57.0.


From: guix-commits
Subject: 03/03: gnu: nghttp2: Replace with 1.57.0.
Date: Sun, 29 Oct 2023 19:36:18 -0400 (EDT)

civodul pushed a commit to branch master
in repository guix.

commit 642769707c05dc1dd5674d60cd3b55d77b35c9d9
Author: Philip McGrath <philip@philipmcgrath.com>
AuthorDate: Sat Oct 21 00:20:30 2023 -0400

    gnu: nghttp2: Replace with 1.57.0.
    
    This release mitigates CVE-2023-44487.
    
    * gnu/packages/web.scm (nghttp2-1.57): New variable.
    (nghttp2)[replacement]: Use it.
    
    Signed-off-by: Ludovic Courtès <ludo@gnu.org>
---
 gnu/packages/web.scm | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/gnu/packages/web.scm b/gnu/packages/web.scm
index b1cdfda862..66d09700db 100644
--- a/gnu/packages/web.scm
+++ b/gnu/packages/web.scm
@@ -7959,6 +7959,7 @@ derivation by David Revoy from the original MonsterID by 
Andreas Gohr.")
   (package
     (name "nghttp2")
     (version "1.49.0")
+    (replacement nghttp2-1.57)
     (source
      (origin
        (method url-fetch)
@@ -8069,6 +8070,19 @@ compressed JSON header blocks.
                    (("print \\(ver >= '3\\.8'\\)")
                     "print (tuple(map(int, ver.split('.'))) >= 
(3,8))")))))))))))
 
+(define-public nghttp2-1.57
+  (package
+    (inherit nghttp2)
+    (version "1.57.0")
+    (source (origin
+              (method url-fetch)
+              (uri (string-append "https://github.com/nghttp2/nghttp2/";
+                                  "releases/download/v" version "/"
+                                  "nghttp2-" version ".tar.xz"))
+              (sha256
+               (base32
+                "0n598w7w8rqdqiay2fad3a11253hibakan5c4vjkpx09648v044j"))))))
+
 (define-public hpcguix-web
   (package
     (name "hpcguix-web")



reply via email to

[Prev in Thread] Current Thread [Next in Thread]