Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

oraclejdk: 8u171, 8u172 -> 8u181, 10.0.1 -> 10.0.2 [Critical security fixes] #43811

Merged
merged 2 commits into from Jul 20, 2018

Conversation

taku0
Copy link
Contributor

@taku0 taku0 commented Jul 19, 2018

Motivation for this change
  • Critical security fixes
  • Other changes and fixes

https://www.oracle.com/technetwork/java/javase/8u181-relnotes-4479407.html
http://www.oracle.com/technetwork/java/javase/10-0-2-relnotes-4477557.html
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html#AppendixJAVA

Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option sandbox in nix.conf on non-NixOS)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nox --run "nox-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Determined the impact on package closure size (by running nix path-info -S before and after)
  • Fits CONTRIBUTING.md.

@srhb srhb merged commit defa760 into NixOS:master Jul 20, 2018
srhb added a commit to srhb/nixpkgs that referenced this pull request Jul 21, 2018
oraclejdk: 10.0.1 -> 10.0.2 [Critical security fixes]

(cherry picked from commit defa760)
andir added a commit that referenced this pull request Oct 6, 2018
Backport of #43811 jdk updates (help needed)
andir added a commit to andir/nixpkgs that referenced this pull request Oct 6, 2018
This is a sort port of 4d6f880 (NixOS#43811). The mentioned issues are not
being fixed in the release. The CPU release should be used instead.

Since someone might still need the PSU version it will just be marked as
insecure allowing the user to whitelist it, if required.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants