!aRKdLCkUeIFjRPZuJT:nixos.org

NixOS JVM

121 Members
27 Servers

Load older messages


SenderMessageTime
30 Oct 2024
@tomodachi94:matrix.orgTomodachi94 (they/them)Additionally, it is very insecure, with four CVEs that are only patched in v7 or higher: https://github.com/NixOS/nixpkgs/pull/35223604:38:02
@tomodachi94:matrix.orgTomodachi94 (they/them)Only three packages are using it04:38:44
@tomodachi94:matrix.orgTomodachi94 (they/them)* Only three packages are using it afaict04:40:18
@emilazy:matrix.orgemilyusually we just list CVE identifiers with no explanation I think04:41:58
@emilazy:matrix.orgemilyI think we can drop now, before release.04:43:13
@emilazy:matrix.orgemily dropping packages came up in #nixos-release-management:nixos.org recently, it's fine until the release, and security trumps freeze anyway 04:43:32
@emilazy:matrix.orgemilydo any of the three users work with a newer gradle?04:44:21
@tomodachi94:matrix.orgTomodachi94 (they/them)Yes, one does. Upstream fixed it but hasn't released yet; I PRed a patch at https://github.com/NixOS/nixpkgs/pull/35227504:45:12
@tomodachi94:matrix.orgTomodachi94 (they/them)armitage looks like upstream might have been abandoned; no commits in two years04:46:34
@tomodachi94:matrix.orgTomodachi94 (they/them)jd-gui also looks abandoned upstream, no commits since 201904:47:19
@emilazy:matrix.orgemilyok, let's merge the vulns PR to get it backported, and that fix04:47:20
@emilazy:matrix.orgemilythen let's work on removal04:47:25
@emilazy:matrix.orgemilyhow complicated do the other two failures look?04:50:30
@emilazy:matrix.orgemilyjd-gui AUR package uses 7: https://aur.archlinux.org/packages/jd-gui04:50:53
@tomodachi94:matrix.orgTomodachi94 (they/them)
In reply to@emilazy:matrix.org
how complicated do the other two failures look?
Unsure, I'll start the builds and have them use latest gradle
04:51:00
@emilazy:matrix.orgemilyjackpot: https://aur.archlinux.org/cgit/aur.git/plain/gradle-7-build.patch?h=jd-gui&id=7748f3a58e1e1d85d1558fae35d79350ed0a93bb04:51:31
@emilazy:matrix.orgemilyhope we weren't using that macOS .app code 😅04:52:15
@tomodachi94:matrix.orgTomodachi94 (they/them)Started the build for armitage04:53:32
@tomodachi94:matrix.orgTomodachi94 (they/them)"Could not find method archiveName() for arguments [armitage.jar]" at line 2204:58:00
@tomodachi94:matrix.orgTomodachi94 (they/them)Let's try gradle_704:58:09
@tomodachi94:matrix.orgTomodachi94 (they/them)Friendlier error! This one is about a duplicate handling strategy04:59:42
@tomodachi94:matrix.orgTomodachi94 (they/them)* Friendlier error! This one is about a "duplicate handling strategy"04:59:47
@emilazy:matrix.orgemilyit's probably only worth putting a bounded amount of effort into this if it proves complicated05:06:05
@emilazy:matrix.orgemilymaybe we could juts restore the old Ant build 😂05:07:38
@emilazy:matrix.orgemilyOTOH, their build really does not look complex05:07:56
@tomodachi94:matrix.orgTomodachi94 (they/them)

True. Can't find any patches for this on Kali nor AUR

05:15:14
@tomodachi94:matrix.orgTomodachi94 (they/them)

Would you believe me if I said this software was forked twice because it was abandoned? :)

05:15:46
@emilazy:matrix.orgemilyeasily :P05:15:54
@emilazy:matrix.orgemilyhttps://docs.gradle.org/current/userguide/upgrading_version_6.html05:16:07
@emilazy:matrix.orgemilyhttps://docs.gradle.org/current/userguide/upgrading_version_7.html05:16:13

Show newer messages


Back to Room ListRoom Version: 6