Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

gogs: 0.11.66 -> 0.11.86 #56819

Merged
merged 1 commit into from Mar 4, 2019
Merged

gogs: 0.11.66 -> 0.11.86 #56819

merged 1 commit into from Mar 4, 2019

Conversation

herrwiese
Copy link
Contributor

This release especially addresses CVE-2018-20303.

Motivation for this change

Versions prior this one are vulnerable to a RCE attack.

Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option sandbox in nix.conf on non-NixOS)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nox --run "nox-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Determined the impact on package closure size (by running nix path-info -S before and after)
  • Assured whether relevant documentation is up to date
  • Fits CONTRIBUTING.md.

This release especially addresses CVE-2018-20303.
@xeji
Copy link
Contributor

xeji commented Mar 4, 2019

@GrahamcOfBorg build gogs

@xeji
Copy link
Contributor

xeji commented Mar 4, 2019

https://gogs.io/docs/intro/change_log
Needs backport to 18.09 (security).

@xeji xeji added 9.needs: port to stable A PR needs a backport to the stable release. 1.severity: security labels Mar 4, 2019
@xeji xeji merged commit 1673a3c into NixOS:master Mar 4, 2019
xeji pushed a commit that referenced this pull request Mar 4, 2019
This release especially addresses CVE-2018-20303.

(cherry picked from commit 1673a3c)
@xeji
Copy link
Contributor

xeji commented Mar 4, 2019

picked to 18.09 19.03: c738ebc

@herrwiese
Copy link
Contributor Author

@xeji c738ebc is actually on 19.03, not 18.09, where it should be fixed, too, I think. Shall I create another PR against 18.09?

@herrwiese herrwiese deleted the gogs-0.11.86 branch March 4, 2019 19:16
@herrwiese herrwiese mentioned this pull request Mar 4, 2019
10 tasks
@xeji
Copy link
Contributor

xeji commented Mar 5, 2019

Sorry, my mistake. Thank you for the separate PR.

@vcunat vcunat removed the 9.needs: port to stable A PR needs a backport to the stable release. label Mar 10, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants