From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp12.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms9.migadu.com with LMTPS id iGIqHQ69HWSmRAAASxT56A (envelope-from ) for ; Fri, 24 Mar 2023 16:09:02 +0100 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp12.migadu.com with LMTPS id eK4CHQ69HWTLswAAauVa8A (envelope-from ) for ; Fri, 24 Mar 2023 16:09:02 +0100 Received: from lists.gnu.org (unknown [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 3B2AC5FD5 for ; Fri, 24 Mar 2023 16:09:02 +0100 (CET) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1pfb2F-0006Ae-HZ; Fri, 24 Mar 2023 02:36:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1pfb23-00065c-BV for guix-patches@gnu.org; Fri, 24 Mar 2023 02:36:12 -0400 Received: from debbugs.gnu.org ([209.51.188.43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1pfb22-00076m-3D for guix-patches@gnu.org; Fri, 24 Mar 2023 02:36:10 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1pfZ21-0008Jr-W8 for guix-patches@gnu.org; Fri, 24 Mar 2023 00:28:01 -0400 Subject: bug#62410: [staging PATCH] gnu: subversion: Update to 1.14.2 [security fixes]. Resent-From: Maxim Cournoyer Original-Sender: "Debbugs-submit" Resent-To: guix-patches@gnu.org Resent-Date: Fri, 24 Mar 2023 04:28:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: cc-closed 62410 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: Greg Hogan Cc: 62410-done@debbugs.gnu.org Mail-Followup-To: 62410@debbugs.gnu.org, maxim.cournoyer@gmail.com, code@greghogan.com Received: via spool by 62410-done@debbugs.gnu.org id=D62410.167963206831950 (code D ref 62410); Fri, 24 Mar 2023 04:28:01 +0000 Received: (at 62410-done) by debbugs.gnu.org; 24 Mar 2023 04:27:48 +0000 Received: from localhost ([127.0.0.1]:39623 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1pfZ1n-0008JF-Vt for submit@debbugs.gnu.org; Fri, 24 Mar 2023 00:27:48 -0400 Received: from mail-ua1-f41.google.com ([209.85.222.41]:36627) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1pfZ1i-0008Hu-5T for 62410-done@debbugs.gnu.org; Fri, 24 Mar 2023 00:27:46 -0400 Received: by mail-ua1-f41.google.com with SMTP id e12so622842uaa.3 for <62410-done@debbugs.gnu.org>; Thu, 23 Mar 2023 21:27:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; t=1679632052; h=mime-version:user-agent:message-id:in-reply-to:date:references :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to; bh=SoxNSVZ9F0/DNrnql2E6pZFcyyctIh42+HqhMAaIdbg=; b=ZV4WujOiCErui5MkqolBoiARs+Kr49+A7MdvvGGtIjtgsYIkSwNYrwte9IU/jXu2dx V7aele0zem1D180eqt/L6lvxTEBHrxqA35zz9/7bdGAdOBUHvsTCbUA53fOhC0hzA51x lTznV8sr8lxA+h7ymqSvTOIFBQW/sPtFd0z8g6NBQkPkg9hOOsAYJAiTmUa/iAbyITRy ssq/WR/zqR5d0IZAJ1h7fxnt+YROhM5raom1vQmb6dZ2S99GxXkqeZ3UogBfIUvd2GNt zWqck1Q2+p/sSBOfraiDiqTgDUUQ7FcJOm1tMhujLslcN7qW4h7aDD/K9uXCUM7KP1eM IGZw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; t=1679632052; h=mime-version:user-agent:message-id:in-reply-to:date:references :subject:cc:to:from:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=SoxNSVZ9F0/DNrnql2E6pZFcyyctIh42+HqhMAaIdbg=; b=CmPjAq3kF6ayxSPAwZpf/RN+SWO5DJ5s4SAt8J9WUQj5Ov6znyyMNuNy+p/FrKw0tD KtYThH3rfL11JezejD63FjKfF3jePbk43Cv6CUURZgwpZaFQR9QoYgNpXwpL/vHfx4po 96Wqm5c3agEZXv5AnGUScM/r5CRK5wcMtPD+MHaS1jRz0wYpcb7/pQipbIq2CtinUN9W EoY+1ecd82dCi5jyyqgoJAszJjtli3g+yQOC/N75nzbcqm5DUZbAKQ0j1P9rqBgFYp+h i1Ocym/97Vj8FehxPKlhGhZHUfP9e1vmtiTE8ezrpbHQcKZOvW3q3ReJS897yrvBSuNZ Qqmg== X-Gm-Message-State: AAQBX9f8//bswO8rXkKChJdHaMTzxGWIl7UrE90WjGywWWaVZTrVg+PZ qZ9uFLnodkDtsTale/n6xZsn9Gq4h7w= X-Google-Smtp-Source: AK7set/VkOr3oHn0ekTSLDHJ6s4DFJuxtP0H9NHeAuLNfN3Oz+8M8O9M4wbtj6yb1FBMcYQFNw9jvw== X-Received: by 2002:ad4:5d64:0:b0:5a3:9032:13ea with SMTP id fn4-20020ad45d64000000b005a3903213eamr15397902qvb.3.1679631625426; Thu, 23 Mar 2023 21:20:25 -0700 (PDT) Received: from hurd (dsl-155-54.b2b2c.ca. [66.158.155.54]) by smtp.gmail.com with ESMTPSA id o197-20020a3741ce000000b0073b575f3603sm13956485qka.101.2023.03.23.21.20.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 23 Mar 2023 21:20:25 -0700 (PDT) From: Maxim Cournoyer References: <20230323184631.1171191-1-code@greghogan.com> Date: Fri, 24 Mar 2023 00:20:23 -0400 In-Reply-To: <20230323184631.1171191-1-code@greghogan.com> (Greg Hogan's message of "Thu, 23 Mar 2023 18:46:31 +0000") Message-ID: <87v8iq2320.fsf@gmail.com> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/28.2 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: guix-patches-bounces+larch=yhetil.org@gnu.org X-Migadu-Country: US X-Migadu-Flow: FLOW_IN ARC-Seal: i=1; s=key1; d=yhetil.org; t=1679670542; a=rsa-sha256; cv=none; b=krE+mEp0izG2VLudvxyTWAoTwQIv2OPCCX7rxw94lx/ApJhj2rwKElXKpbdN5M1GOXUO6W ByRXk6LYJNf03SG3blElzTaB/PnwkR5Xs6NY1IsKw9/gkoGIipVioG622MswV1JL+jDvQM RxZ5QDE3eUSaZO5u5Vxc079KRu1RaXpqvAElEnS0QwPPAt2BYyPJ98ygYudDt+kLLqo8Qo pXbW1cSCurLJGKMdRAjGaeHN6GiwvhfkgNbCd+kNtQ1n/O73J/zcTAnsBGaso/6yzvhszy Rmrt8pdt1jMkSlBvF2U5v17v5SLzQ4LLIV92Nc2PLCZV97Z4z2N+YCdlQuz62w== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=gmail.com header.s=20210112 header.b=ZV4WujOi; dmarc=fail reason="SPF not aligned (relaxed)" header.from=gmail.com (policy=none); spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1679670542; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:resent-to:resent-from:resent-sender: resent-message-id:in-reply-to:in-reply-to:references:references: list-id:list-help:list-unsubscribe:list-subscribe:list-post: dkim-signature; bh=SoxNSVZ9F0/DNrnql2E6pZFcyyctIh42+HqhMAaIdbg=; b=nbTZRKJIG9SAGfCaiV4395TdSrHwwNoC2Ud4ZnS/dwqG/6vDUxSyiDSYGkg7veOTM52kh8 I+yChqpFB9JMBrRdUpxQDWWH3YddrwITbud8lpJjgNmbExf5HJnCbXfoX486TxwxVsJrf6 a+HvrewIW8ICFVULsn3Tj3/2RWLzkPmnhd+Bt79/raQ1XDTXvEJq3h79qY3qJvIKQVhaUX XM1es69q0rnz5w3JTWU0P3OLHzWKeozBzNf9ws5q8BqfRl79c+Wqfm+vEwT2I4T43tWVVN om8QnmRbhhiyFj/5hGQ8/Lq5uI9syVim2FKXykIOaoBZRCE40xaOPOJ60iqPhA== Authentication-Results: aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=gmail.com header.s=20210112 header.b=ZV4WujOi; dmarc=fail reason="SPF not aligned (relaxed)" header.from=gmail.com (policy=none); spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" X-Migadu-Scanner: scn1.migadu.com X-Migadu-Spam-Score: 0.36 X-Spam-Score: 0.36 X-Migadu-Queue-Id: 3B2AC5FD5 X-TUID: CfhGRDMCSSpm Hi Greg, Greg Hogan writes: > This release contains fixes for CVE-2021-28544 and CVE-2022-24070. > > * gnu/packages/version-control.scm (subversion): Update to 1.14.2. > --- > gnu/packages/version-control.scm | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/gnu/packages/version-control.scm b/gnu/packages/version-control.scm > index 12e21336ce..526b6bbb2b 100644 > --- a/gnu/packages/version-control.scm > +++ b/gnu/packages/version-control.scm > @@ -1995,14 +1995,14 @@ (define-public neon > (define-public subversion > (package > (name "subversion") > - (version "1.14.1") > + (version "1.14.2") > (source (origin > (method url-fetch) > (uri (string-append "mirror://apache/subversion/" > "subversion-" version ".tar.bz2")) > (sha256 > (base32 > - "1ag1hvcm9q92kgalzbbgcsq9clxnzmbj9nciz9lmabjx4lyajp9c")))) > + "0a6csc84hfymm8b5cnvq1n1p3rjjf33qy0z7y1k8lwkm1f6hw4y9")))) > (build-system gnu-build-system) > (arguments > '(#:parallel-tests? #f ; TODO Seems to cause test failures on I decided to push this to master, as the dependent packages count was rather low. I hope I wasn't misguided :-). -- Thanks, Maxim