!aRKdLCkUeIFjRPZuJT:nixos.org

NixOS JVM

130 Members
27 Servers

Load older messages


SenderMessageTime
2 Nov 2024
@tomasajt:matrix.orgToma joined the room.00:34:39
@tomodachi94:matrix.orgTomodachi94 (they/them)Hmm, does anyone have a good link for the oraclejdk knownVulns entry?00:41:02
@emilazy:matrix.orgemilyhttps://openjdk.org/groups/vulnerability/advisories/00:44:04
@emilazy:matrix.orgemilyI don't suggest trying to list every single applicable CVE, because there are so many00:44:22
@tomodachi94:matrix.orgTomodachi94 (they/them)Yes definitely, this should have been dropped a while ago afaict00:50:08
@tomodachi94:matrix.orgTomodachi94 (they/them) casually writes knownVulns entry with 50+ CVEs listed /joking 00:50:52
* @emilazy:matrix.orgemily requests changes – the convention is one CVE per entry00:51:08
@tomodachi94:matrix.orgTomodachi94 (they/them)Done at https://github.com/NixOS/nixpkgs/pull/35303400:58:45
@emilazy:matrix.orgemilyhm, I'm pretty sure 8 and 11 are supported: https://endoflife.date/oracle-jdk00:59:55
@emilazy:matrix.orgemilyit's just that nobody has been updating ours01:00:17
@emilazy:matrix.orgemily(and there is no reason to, because… it's just an OpenJDK build with a bad licence)01:00:36
@emilazy:matrix.orgemilyor maybe not for the free ones??01:01:57
@emilazy:matrix.orgemilyit's Oracle so it's of course incomprehensible01:02:07
@emilazy:matrix.orgemilyhttps://www.oracle.com/uk/java/technologies/javase/javase8u211-later-archive-downloads.html 8u421 is available at least.01:03:19
@emilazy:matrix.orgemily(just a message nit, not a proposal to handle the situation differently)01:03:42
@tomodachi94:matrix.orgTomodachi94 (they/them)Hmm maybe we just drop it right away and leave 24.05 alone?01:11:26
@tomodachi94:matrix.orgTomodachi94 (they/them)I'll see if anyone on the Fediverse knows what's up with Oracle JDK01:13:18
@emilazy:matrix.orgemilysorry, I'm a bit confused01:13:46
@emilazy:matrix.orgemilythere's nothing up with Oracle JDK except that it has a weird licence and is pointless to use since you can get OpenJDKs with normal licences01:13:59
@emilazy:matrix.orgemilythe problem with our package is that nobody has updated it with 2021, and clearly nobody will, and even if they would there's no reason for us to carry it since it's just a footgun to use it01:14:19
@emilazy:matrix.orgemily * the problem with our package is that nobody has updated it since 2021, and clearly nobody will, and even if they would there's no reason for us to carry it since it's just a footgun to use it01:14:24
@tomodachi94:matrix.orgTomodachi94 (they/them)Oh, so it's OpenJDK with the Oracle nametag01:14:32
@emilazy:matrix.orgemily it should definitely get knownVulnerabilities on 24.05, since it's unsafe to use 01:14:33
@emilazy:matrix.orgemilyyeah01:14:36
@emilazy:matrix.orgemilyand a really onerous licence01:14:40
@emilazy:matrix.orgemilythere's basically no reason for it to exist beyond Oracle's business model of entrapping people into having to pay them money01:15:07
@emilazy:matrix.orgemilyin the past, we carried it for AArch64, apparently01:15:44
@emilazy:matrix.orgemily per doc/languages-frameworks/java.section.md 01:15:54
@emilazy:matrix.orgemilywhich needs updating to reflect reality01:15:57
@tomodachi94:matrix.orgTomodachi94 (they/them)
In reply to@emilazy:matrix.org
it should definitely get knownVulnerabilities on 24.05, since it's unsafe to use
So a message like "Oracle JDKs are unsafe to use and are unmaintained in Nixpkgs. OpenJDK provides a comparable implementation." ?
01:18:19

Show newer messages


Back to Room ListRoom Version: 6