* Should our openssl/fixed not have more fixin's by now? [not found] ` <20190911164845.C8B65207F5@vcs0.savannah.gnu.org> @ 2019-09-11 17:05 ` Tobias Geerinckx-Rice 0 siblings, 0 replies; only message in thread From: Tobias Geerinckx-Rice @ 2019-09-11 17:05 UTC (permalink / raw) To: guix-devel [-- Attachment #1: Type: text/plain, Size: 628 bytes --] Guix, 1 CVE patch since 1.0.2p seems suspiciously low to me. I hope I'm wrong. In any case, there are new ones[0]. Me on IRC: “I'd like to fix some CVEs in openssl, but it's not clear to me whether ‘letter releases’ are supposed to be ABI-compatible or not. It would be a big jump (1.0.2p → 1.0.2t), and our current openssl/fixed is just 1.0.2p + 1 patch, so I doubt it. But cherry-picking patches is proving too painful [for me].” …mainly because I'm not that familiar with OpenSSLs release/git habits. Kind regards, T G-R [0]: https://www.openssl.org/news/cl102.txt [-- Attachment #2: signature.asc --] [-- Type: application/pgp-signature, Size: 227 bytes --] ^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2019-09-11 17:05 UTC | newest] Thread overview: (only message) (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- [not found] <20190911164844.9037.97931@vcs0.savannah.gnu.org> [not found] ` <20190911164845.C8B65207F5@vcs0.savannah.gnu.org> 2019-09-11 17:05 ` Should our openssl/fixed not have more fixin's by now? Tobias Geerinckx-Rice
Code repositories for project(s) associated with this external index https://git.savannah.gnu.org/cgit/guix.git This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.