mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-09-28 10:50:15 +00:00
ocamlPackages.mirage-crypto*: add knownVulnerabilities entries
This is a stop gap measure for now since we should be able to fix these issues (i.e. fixes are available and have been released). Unfortunately these fixes are spread across 2.2.0, 2.3.0, 2.4.0 which also contain breaking changes at time. See #562227. These breaking changes require (breaking) updates for at least httpcats and tls. Reference #561924.
This commit is contained in:
@@ -43,5 +43,8 @@ buildDunePackage (finalAttrs: {
|
||||
sternenseemann
|
||||
momeemt
|
||||
];
|
||||
knownVulnerabilities = [
|
||||
"CVE-2026-87732" # fixed in 2.2.0
|
||||
];
|
||||
};
|
||||
})
|
||||
|
||||
@@ -43,5 +43,10 @@ buildDunePackage {
|
||||
|
||||
meta = mirage-crypto.meta // {
|
||||
description = "Elliptic Curve Cryptography with primitives taken from Fiat";
|
||||
knownVulnerabilities = [
|
||||
"CVE-2026-87733" # fixed in 2.2.0
|
||||
"CVE-2026-87736" # fixed in 2.3.0
|
||||
"CVE-2026-87737" # fixed in 2.4.0
|
||||
];
|
||||
};
|
||||
}
|
||||
|
||||
@@ -30,5 +30,8 @@ buildDunePackage {
|
||||
|
||||
meta = mirage-crypto.meta // {
|
||||
description = "Simple public-key cryptography for the modern age";
|
||||
knownVulnerabilities = [
|
||||
"CVE-2026-87735" # fixed in 2.3.0
|
||||
];
|
||||
};
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user