From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp12.migadu.com ([2001:41d0:8:6d80::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms5.migadu.com with LMTPS id aBuAC9/BA2MylAAAbAwnHQ (envelope-from ) for ; Mon, 22 Aug 2022 19:50:23 +0200 Received: from aspmx1.migadu.com ([2001:41d0:8:6d80::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp12.migadu.com with LMTPS id 6FOBC9/BA2MuOwAAauVa8A (envelope-from ) for ; Mon, 22 Aug 2022 19:50:23 +0200 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id DE50920F7A for ; Mon, 22 Aug 2022 19:50:22 +0200 (CEST) Received: from localhost ([::1]:46774 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1oQBZ7-0004WH-Nq for larch@yhetil.org; Mon, 22 Aug 2022 13:50:21 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:60082) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1oQ9gd-0004iL-VK for guix-devel@gnu.org; Mon, 22 Aug 2022 11:50:00 -0400 Received: from mail-wm1-x32a.google.com ([2a00:1450:4864:20::32a]:47026) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1oQ9gb-0004ia-S8; Mon, 22 Aug 2022 11:49:59 -0400 Received: by mail-wm1-x32a.google.com with SMTP id k6-20020a05600c1c8600b003a54ecc62f6so6245410wms.5; Mon, 22 Aug 2022 08:49:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=content-transfer-encoding:mime-version:message-id:date:references :in-reply-to:subject:cc:to:from:from:to:cc; bh=UnIRWhbjboMg0+VcmxdoMdWjUrrCaE8oQcNLmYK02os=; b=eHKP31ZaZsGnodp7n2WP7DxLvaOfY+mVlkQ1dVLHKC/ZjfCSNzPeTX0WoIQnwh0rR1 t9RUyP79hIDwd+xme70ZM+UDJwef+UG8QJ7On2772K8zNjAfq32CVCDIaXjynLKNVeZ1 iRo5jlKdX992ozHETc9yHPkI079Az8Vo0W9PjxQvosiTM3qo63q0SVkCghA+pQbDI4ut Pt7pnD8NG4FIQQnZZUHcLQy5L2otSL33mIwfYg6BsWb51XhWZlkTN1EDUI0oPfTsJOqW OggGAPeIReEPnvbuFLP3W0QZtFS7ahblzmPL8ETdWj//2HHk7vqbEvOF0O3wf8E2lwI1 6nCQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-transfer-encoding:mime-version:message-id:date:references :in-reply-to:subject:cc:to:from:x-gm-message-state:from:to:cc; bh=UnIRWhbjboMg0+VcmxdoMdWjUrrCaE8oQcNLmYK02os=; b=Li0wEvSV4IICl5/P6lWJU9T8VIujMW1eJn935ra8h9AhSd2URGTkCngbTO72OsEUl7 RoeG65vWqtDHLOe+agRxCpGIVT1qWHfh96S1fjPejfLRWwZQU+Aa50xDDJvBTCCcIcZM OavOMzwYNcpmiVVyOwDjdW4S1oxEAMh2jY+9zw+XBCBvSdO+NVX2BrGUt/2x3/HbQVIE qllggfadun0cJqMKIg5QVN+mgQo/H3OSdCij+g+VUVG+FLt7Why99dZb31pGjnq2W2ED Zxdujh06SWQaqcsAnSMR3xeAOb6+8MdDDIsjAhPpiYDSyknepTtjjkeQxkSz7+gInSHH LBrA== X-Gm-Message-State: ACgBeo0DyosqmrHFU55W6rhGMjia2OGoXW56UDiHFRJ4QuJ6QvLHBi/p UhaZ8a2BKoQrJXU2N0Zb2LsseOj+huM= X-Google-Smtp-Source: AA6agR5qaDldy3IlD0wzLrDuXmL3hLZ9nQHRPm2liCZfY+8efYMANbnNU1j4xHkhEYwCOtDpiOF9WA== X-Received: by 2002:a05:600c:1e8b:b0:3a6:1a09:2a89 with SMTP id be11-20020a05600c1e8b00b003a61a092a89mr14232685wmb.108.1661183391574; Mon, 22 Aug 2022 08:49:51 -0700 (PDT) Received: from pfiuh07 ([193.48.40.241]) by smtp.gmail.com with ESMTPSA id y15-20020a5d614f000000b0021f0ff1bc6csm12012349wrt.41.2022.08.22.08.49.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 22 Aug 2022 08:49:51 -0700 (PDT) From: zimoun To: Marius Bakke , Danny Milosavljevic , Mathieu Othacehe Cc: guix-devel@gnu.org Subject: Re: branch master updated: gnu: python-lxml: Update to 4.6.5. In-Reply-To: <87ilmshbhn.fsf@gnu.org> References: <166056773034.6462.13614226574276489780@vcs2.savannah.gnu.org> <878rnpd1q4.fsf@gnu.org> <20220816013639.37e0a562@scratchpost.org> <87ilmshbhn.fsf@gnu.org> Date: Mon, 22 Aug 2022 17:18:59 +0200 Message-ID: <878rng5msc.fsf@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Received-SPF: pass client-ip=2a00:1450:4864:20::32a; envelope-from=zimon.toutoune@gmail.com; helo=mail-wm1-x32a.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: guix-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+larch=yhetil.org@gnu.org Sender: "Guix-devel" X-Migadu-Flow: FLOW_IN X-Migadu-To: larch@yhetil.org X-Migadu-Country: US ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1661190622; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post:dkim-signature; bh=UnIRWhbjboMg0+VcmxdoMdWjUrrCaE8oQcNLmYK02os=; b=mkNHuOdrLSXrxkpOXBDpV8JnPH6h2uFhDPsL60VVASqFcPnTyIhIitqlvRjO59Eh4kgr8F shG/l/KNC1UhcrpiXGpQhmbCom3WB604sDUw39glAgdv0v1GFnAPYdMxIWXIdudgznDu12 lIqtRFSJpz4efHIm0G8iyYUGWf7WROtUSxtQCOOdrhM39ZGU4D4Q9t3o6OalnU6lv1SsgD py97JQEWLL0HBJsLCa0CgZNpV5W2sj5WHxzXeDlydAP7nTByCXJpJa+qITRuaHP2wmWvCV lg9RCSzfurSdhwKwrZYRmqNCmXDybUrTF8WzJEO4vix92WvoNYqkomzbSfUnsw== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1661190622; a=rsa-sha256; cv=none; b=U2Pk4j3FpKfWucT1p2OOxmwUdudAmTzSFW3D1V2rUbUOBSfzvmuEzTS4S8RJNApO3yaPeG oFR50hqXOuSbss6W/rQPhe/7LaxVunKln6xNjZvo0d9mv8iDZtsTSh8S05zrBvY0n9Mcjw asLBtaRNt84OTeFc9Ejza4lMZThpF07jjoGFy4ZiRneu9bsSx9FsvFrNtigGeedA3I30rV WsSu/xbdjJfWTR69IyHLveL3IN62hsZzdGMYtN2Mb7XA59HKnixYNej7Un7n2eVFTtCa8I rxlTfHq/oTZXrWpjlCWKi3RBLUe/W9qSsIz2Hh9MA/jhTMlttEE8/t/DQ7wEkg== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=pass header.d=gmail.com header.s=20210112 header.b=eHKP31Za; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (aspmx1.migadu.com: domain of "guix-devel-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-devel-bounces+larch=yhetil.org@gnu.org" X-Migadu-Spam-Score: -8.11 Authentication-Results: aspmx1.migadu.com; dkim=pass header.d=gmail.com header.s=20210112 header.b=eHKP31Za; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (aspmx1.migadu.com: domain of "guix-devel-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-devel-bounces+larch=yhetil.org@gnu.org" X-Migadu-Queue-Id: DE50920F7A X-Spam-Score: -8.11 X-Migadu-Scanner: scn0.migadu.com X-TUID: 2sPT30plAGif Hi, On mar., 16 ao=C3=BBt 2022 at 09:51, Marius Bakke wrote: >>> > * gnu/packages/xml.scm (python-lxml): Update to 4.6.5.=20=20 >> Now I see that python-lxml-4.7 shadows it. >> >> Note: This would have fixed two CVEs, CVE-2021-43818 and CVE-2021-43818. > > Can you add a "graft" for this version instead of updating in-place? Graft 4.6.3 by the already packaged 4.7? Or graft 4.6.3 by 4.6.5 because one of the 5208 dependant packages is incompatible with 4.7? Cheers, simon