From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp12.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms0.migadu.com with LMTPS id OA44Ih0sMWIRUAAAgWs5BA (envelope-from ) for ; Wed, 16 Mar 2022 01:15:25 +0100 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp12.migadu.com with LMTPS id 0AbYHh0sMWKxVwEAauVa8A (envelope-from ) for ; Wed, 16 Mar 2022 01:15:25 +0100 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 19710E9C9 for ; Wed, 16 Mar 2022 01:15:25 +0100 (CET) Received: from localhost ([::1]:58622 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1nUHK0-0002IV-Bl for larch@yhetil.org; Tue, 15 Mar 2022 20:15:24 -0400 Received: from eggs.gnu.org ([209.51.188.92]:33268) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nUHJf-0002I8-4n for guix-patches@gnu.org; Tue, 15 Mar 2022 20:15:03 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:55990) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1nUHJe-00062I-Rt for guix-patches@gnu.org; Tue, 15 Mar 2022 20:15:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1nUHJe-0007vk-LP for guix-patches@gnu.org; Tue, 15 Mar 2022 20:15:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#54414] [SECURITY] gnu: expat: Update to 2.4.7. Resent-From: Leo Famulari Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Wed, 16 Mar 2022 00:15:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 54414 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: To: 54414@debbugs.gnu.org X-Debbugs-Original-To: guix-patches@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.164738968630438 (code B ref -1); Wed, 16 Mar 2022 00:15:02 +0000 Received: (at submit) by debbugs.gnu.org; 16 Mar 2022 00:14:46 +0000 Received: from localhost ([127.0.0.1]:49887 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nUHJO-0007ur-Et for submit@debbugs.gnu.org; Tue, 15 Mar 2022 20:14:46 -0400 Received: from lists.gnu.org ([209.51.188.17]:36074) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nUHJN-0007uj-3F for submit@debbugs.gnu.org; Tue, 15 Mar 2022 20:14:45 -0400 Received: from eggs.gnu.org ([209.51.188.92]:33254) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nUHJM-0002GD-VE for guix-patches@gnu.org; Tue, 15 Mar 2022 20:14:44 -0400 Received: from out2-smtp.messagingengine.com ([66.111.4.26]:43391) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nUHJL-0005y0-Cs for guix-patches@gnu.org; Tue, 15 Mar 2022 20:14:44 -0400 Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.nyi.internal (Postfix) with ESMTP id DB04A5C024B; Tue, 15 Mar 2022 20:14:42 -0400 (EDT) Received: from mailfrontend1 ([10.202.2.162]) by compute3.internal (MEProxy); Tue, 15 Mar 2022 20:14:42 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name; h=cc:content-transfer-encoding:date:date:from:from:in-reply-to :message-id:mime-version:reply-to:sender:subject:subject:to:to; s=mesmtp; bh=eAUIhxQgqkXpTBM4sNarraupqcu8uBIHjFBeZT+hhLo=; b=ec tb3mnRkW/bhFTpYbzaaVcHwz15BN+5hXb6qgZAkpPqV0AibcoLzTubQ7/XpHgeNi 1A9/ZQM50iInc2h2Pl2IL4OcWVG0bY5Oi+HtIbInuLTQqe56vgnFAWm5nyvmy/cB xqY/ngUeOwmymbOCQbGRlkge8QUgEPjKlLgcSyKPI= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:date:date :from:from:in-reply-to:message-id:mime-version:reply-to:sender :subject:subject:to:to:x-me-proxy:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm3; bh=eAUIhxQgqkXpTBM4sNarraupqcu8u BIHjFBeZT+hhLo=; b=CgEDwsCbVyTtCgq1PYtGGHLa0okXuF/pCMva2/9TwS8Nz bM4hKxI2G39iL3d22jbCYDcnKTG+kLuoHXo7nhLBMDjw3nXCHcsktQKmUTlyTvSL zw9FqIu7bDK4CG6M1H1sJlbmXer+3pOnh8LIZpC4W7EFjqlKb+2IhMl59F8cvcAn Q1MwV93TbQJ/QdIc6TXSJeP2YGolVcTJpA2TLIjQhy2kMf+H3S/e2kLw5mNo2R1w Plh0+/N/yDz9+FrL9NjzxQIJcXaoR3P0bViYqy6/cOGDVW37t+dKD/BmdE0gpyrg ecCMcUY+9h84poxbzdeoYM0XEodwVwWZNKgJv556g== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvvddrudefuddgvddtucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpefhvffufffkofgggfestdekredtre dttdenucfhrhhomhepnfgvohcuhfgrmhhulhgrrhhiuceolhgvohesfhgrmhhulhgrrhhi rdhnrghmvgeqnecuggftrfgrthhtvghrnheptdefhfehffekhfeghffhkeeiueehffekke etudffgeeileetheejgeevhfekhedtnecuffhomhgrihhnpeigmhhlrdgtohhmnecuvehl uhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomheplhgvohesfhgrmh hulhgrrhhirdhnrghmvg X-ME-Proxy: Received: by mail.messagingengine.com (Postfix) with ESMTPA for ; Tue, 15 Mar 2022 20:14:42 -0400 (EDT) From: Leo Famulari Date: Tue, 15 Mar 2022 20:14:39 -0400 Message-Id: X-Mailer: git-send-email 2.34.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Received-SPF: pass client-ip=66.111.4.26; envelope-from=leo@famulari.name; helo=out2-smtp.messagingengine.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: "Guix-patches" X-Migadu-Flow: FLOW_IN X-Migadu-To: larch@yhetil.org X-Migadu-Country: US ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1647389725; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding:resent-cc: resent-from:resent-sender:resent-message-id:list-id:list-help: list-unsubscribe:list-subscribe:list-post:dkim-signature; bh=eAUIhxQgqkXpTBM4sNarraupqcu8uBIHjFBeZT+hhLo=; b=l6ZUdp9hKHK4wQvgHApWLFEemHr7QFUOOh0WVeAkDwB/16kCjVtl9n27A9n2NjVxNMPebS IjvHBLWZp2WK3tri6v2UMckELxxLcp7ZEFGoDONcXXZiHdWvnr5hxvAKtKDRbhkIloJyiQ U3/RDyGn3IKTlwX2GI+oUPt/Pn9AbkFOv32NFE10l13ogj1rlZn6hH/vN24HEVKJfTpRrh uVWdWeJdD3vKMQdUMSA4LfBZJoha62PtQ7PPcLcEIYjCU3saISpAdxreKE7ZE8yBpKhqAq DR0XpDPR5xuidFsbcWSoI9O//BB/6I4oAmtFo92CY5jiAUQPMd1PVRi3UpuR+A== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1647389725; a=rsa-sha256; cv=none; b=bdlBzPX/dG3bDNLGPoS7wCY92oA8AbVoIsX4j0uCQ4zyClG5CPEBzg+vDR5/LS3NbbH6y5 /6RHI/yu6S5PAkd/lBO7p93m2ynXJPUjcC0/shFLigiv+2PtY/c1fENCFmGEnm4oYRd0x+ 4F4XzpgRPo+Bgr7MQC2ut114sO7ExkJDwqf3uFp21e3OUt2Gcy1aeHzkDSFvrlSZXz2/FX q548ILIcS5oMwYVjE69c0HHTMB93UqOXXnDEi8CDTmk9kcv4M5U7jgYKaYSX9oLi+Lzvrc l1VILUddIeJ2IU+47+/puBTuxm18yA+hwy7KZSVzbqNyCxeuo7X1NQsK4/ZoxA== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=famulari.name header.s=mesmtp header.b="ec tb3mn"; dkim=fail ("headers rsa verify failed") header.d=messagingengine.com header.s=fm3 header.b=CgEDwsCb; dmarc=none; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" X-Migadu-Spam-Score: 1.33 Authentication-Results: aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=famulari.name header.s=mesmtp header.b="ec tb3mn"; dkim=fail ("headers rsa verify failed") header.d=messagingengine.com header.s=fm3 header.b=CgEDwsCb; dmarc=none; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" X-Migadu-Queue-Id: 19710E9C9 X-Spam-Score: 1.33 X-Migadu-Scanner: scn0.migadu.com X-TUID: Ahw2yhx+Mo3g This fixes some regressions in 2.4.5 and 2.4.6: https://www.xml.com/news/2022-02-expat-246/ https://www.xml.com/news/2022-03-expat-247/ * gnu/packages/xml.scm (expat/fixed): Update to 2.4.7. --- gnu/packages/xml.scm | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/gnu/packages/xml.scm b/gnu/packages/xml.scm index 3ce5e771c7..49275c3e0c 100644 --- a/gnu/packages/xml.scm +++ b/gnu/packages/xml.scm @@ -158,7 +158,7 @@ (define-public expat (define expat/fixed (package (inherit expat) - (version "2.4.5") + (version "2.4.7") (source (let ((dot->underscore (lambda (c) (if (char=? #\. c) #\_ c)))) (origin (method url-fetch) @@ -170,7 +170,7 @@ (define expat/fixed "/expat-" version ".tar.xz"))) (sha256 (base32 - "0y95yg7y0hb53ddljdzllg1w64xi5k8xd3531n98ffn6rp3qzbzj"))))))) + "0zbss0dssn17mjmvk17qfi5cmvm0lcyzs62cwvqr219hhl864xcq"))))))) (define-public libebml (package -- 2.34.0