New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
nheko: mark as insecure #48281
nheko: mark as insecure #48281
Conversation
The package is no longer maintained and includes potential security vulnerabilities (a use-after-free and several crashes) that are known and not fixed in the version present in nixpkgs. They don't look too bad judging from the trigger vectors mentioned in the changelog, but with the project going unmaintained one of them becoming a security vulnerability would likely not be noticed.
No attempt on aarch64-linux (full log) The following builds were skipped because they don't evaluate on aarch64-linux: nheko Partial log (click to expand)
|
No attempt on x86_64-linux (full log) The following builds were skipped because they don't evaluate on x86_64-linux: nheko Partial log (click to expand)
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Makes sense, upstream github repo has archived. This can be reverted later if a maintained fork appears.
The package is no longer maintained and includes potential security vulnerabilities (a use-after-free and several crashes) that are known and not fixed in the version present in nixpkgs. They don't look too bad judging from the trigger vectors mentioned in the changelog, but with the project going unmaintained one of them becoming a security vulnerability would likely not be noticed. (cherry picked from commit ad992cb)
backported to 18.09 in 14bb2f4 |
Can you point to any further information about the security / crashes? I see it marked no longer maintained which is a bummer but curious about the rest so I can understand if I need to stop using it or what :). |
@dtzWill OK, so actually I need to withdraw my point about the use-after-free / crashes: I did not notice you took over maintaining it, and thought it was still at the pre-0.5 version I had left it at (never got to redoing the packaging work after the build system changed, and wasn't notified that someone else had done it :)), so I assumed all the things I was seeing in the changelog were still waiting in nixpkgs. As nothing looked too bad it didn't trigger me to spend an afternoon on re-doing the packaging to the new build system, though :'( Now, unmaintained packages mostly mean that if there's a security vulnerability found we likely won't know about it, so I'd personally stop using it, but… your pick :) |
FYI: There is https://github.com/Nheko-Reborn/nheko. |
@dotlambda did you or @fpletz already take a spin on updating the derivation to it? |
The package is no longer maintained and includes potential security
vulnerabilities (a use-after-free and several crashes) that are known
and not fixed in the version present in nixpkgs. They don't look too bad
judging from the trigger vectors mentioned in the changelog, but with
the project going unmaintained one of them becoming a security
vulnerability would likely not be noticed.
Backport is in #48280
Motivation for this change
Things done
sandbox
innix.conf
on non-NixOS)nix-shell -p nox --run "nox-review wip"
./result/bin/
)nix path-info -S
before and after)