Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

kodiPackages.sendtokodi: remove dependency on youtube_dl #327480

Merged

Conversation

pks-t
Copy link
Contributor

@pks-t pks-t commented Jul 15, 2024

Description of changes

The sendtokodi plugin for Kodi can use both yt-dlp and youtube_dl to play back various URLs. Both of these packages have been susceptible to CVE-2024-38519. But while yt-dlp is still maintained and was patched, youtube_dl is unmaintained and thus known-vulnerable.

Patch out the dependency on youtube_dl so that sendtokodi will only ever use yt-dlp to resolve URLs.

Closes #326548.

Things done

  • Built on platform(s)
    • x86_64-linux
    • aarch64-linux
    • x86_64-darwin
    • aarch64-darwin
  • For non-Linux: Is sandboxing enabled in nix.conf? (See Nix manual)
    • sandbox = relaxed
    • sandbox = true
  • Tested, as applicable:
  • Tested compilation of all packages that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD". Note: all changes have to be committed, also see nixpkgs-review usage
  • Tested basic functionality of all binary files (usually in ./result/bin/)
  • 24.11 Release Notes (or backporting 23.11 and 24.05 Release notes)
    • (Package updates) Added a release notes entry if the change is major or breaking
    • (Module updates) Added a release notes entry if the change is significant
    • (Module addition) Added a release notes entry if adding a new NixOS module
  • Fits CONTRIBUTING.md.

Note that this only fixes one recent issue with the sendtokodi plugin. To make it fully working, #327479 needs to be merged as well since it transitively depends on inputstreamhelper.


Add a 👍 reaction to pull requests you find important.

The sendtokodi plugin for Kodi can use both yt-dlp and youtube_dl to
play back various URLs. Both of these packages have been susceptible to
CVE-2024-38519. But while yt-dlp is still maintained and was patched,
youtube_dl is unmaintained and thus known-vulnerable.

Patch out the dependency on youtube_dl so that sendtokodi will only ever
use yt-dlp to resolve URLs.
Copy link
Member

@aanderse aanderse left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you!

@aanderse aanderse merged commit 9731228 into NixOS:master Jul 16, 2024
28 of 30 checks passed
@pks-t pks-t deleted the pks-kodi-sendtokodi-remove-youtube_dl-dependency branch July 17, 2024 07:21
@aanderse aanderse added the backport release-24.05 Backport PR automatically label Jul 23, 2024
Copy link
Contributor

Successfully created backport PR for release-24.05:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

kodiPackages.sendtokodi: requires insecure youtube-dl, breaks stable
2 participants