!aRKdLCkUeIFjRPZuJT:nixos.org

NixOS JVM

122 Members
27 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
2 Nov 2024
@emilazy:matrix.orgemilyand if you could update the manual section to not reference it in that one too that'd be great02:07:16
@tomodachi94:matrix.orgTomodachi94 (they/them)
In reply to@emilazy:matrix.org
sure, maybe just roll it into the oraclejdk drop?
Maybe. I'm going to hunt for CVEs for it as well, so there's slightly stronger justification
02:07:43
@emilazy:matrix.orgemilyprobably not many people filing CVEs for a proprietary Java Card devkit I imagine02:08:04
@tomodachi94:matrix.orgTomodachi94 (they/them)* Maybe. I'm going to hunt for CVEs for javacard-devkit as well, so there's slightly stronger justification02:08:05
@emilazy:matrix.orgemilyIMO the justification is: it depends on a package being removed for being an unmaintained security disaster, is many years of out of date compared to what we could be packaging (there are modern Linux versions: https://www.oracle.com/java/technologies/javacard-downloads.html#sdk-sim), and it has been untouched since 2018 so there is no reason to expect that the former two will be resolved (and it's not your job to do so)02:09:54
@tomodachi94:matrix.orgTomodachi94 (they/them)Yeah fair. I'm finding 3 CVEs for the hardware itself, but nothing for the devkit02:09:55
@tomodachi94:matrix.orgTomodachi94 (they/them)(meant to be in reply to your message before justification)02:10:56
@tomodachi94:matrix.orgTomodachi94 (they/them) shakes fist at Atlassian Confluence & Crowd & Jira, and Docear packages for having an obscured dependency on oraclejre 02:19:21
@emilazy:matrix.orgemilyoh boy02:21:40
@emilazy:matrix.orgemily
        Atlassian only supports the Oracle JRE (JRASERVER-46152).
02:21:49
@emilazy:matrix.orgemily🤡02:21:51
@tomodachi94:matrix.orgTomodachi94 (they/them)So much for dropping OracleJDK/JRE 🤡02:22:20
@emilazy:matrix.orgemilyare you sure?02:22:27
@emilazy:matrix.orgemilyyou assume that these packages are, themselves, maintained02:22:40
@emilazy:matrix.orgemilydamn apparently at least one of them is02:22:59
@emilazy:matrix.orgemilyanyway, Atlassian definitely won't support running on an Oracle JDK from 202102:23:14
@tomodachi94:matrix.orgTomodachi94 (they/them)The Atlassian stuff is in the NixOS modules (I suspect it should actually be something configured in the package, but I digress)02:23:52
@emilazy:matrix.orgemilyhttps://jira.atlassian.com/browse/JRASERVER-4615202:24:01
@emilazy:matrix.orgemilythis doesn't actually back up the assertion02:24:04
@emilazy:matrix.orgemilyimo, set it to the corresponding OpenJDK packages in the PR, ping @techknowlogick since they seem to maintain them02:25:20
@emilazy:matrix.orgemilypeople deploying atlassian software on NixOS should certainly know that they're running an unsupported JDK, and AFAICT the issue linked is just about, like… a regex issue?02:26:02
@emilazy:matrix.orgemily
[emily@build01:~]$ nix run nixpkgs#jdk8 -- -version
openjdk version "1.8.0_422"
02:26:22
@emilazy:matrix.orgemilyand AFAICT our JDKs should pass the regex just fine02:26:28
@tomodachi94:matrix.orgTomodachi94 (they/them)
In reply to@emilazy:matrix.org
people deploying atlassian software on NixOS should certainly know that they're running an unsupported JDK, and AFAICT the issue linked is just about, like… a regex issue?
Well they'll know now that knownVulns is set /j
02:26:32

Show newer messages


Back to Room ListRoom Version: 6