From 642769707c05dc1dd5674d60cd3b55d77b35c9d9 Mon Sep 17 00:00:00 2001 From: Philip McGrath Date: Sat, 21 Oct 2023 00:20:30 -0400 Subject: gnu: nghttp2: Replace with 1.57.0. MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This release mitigates CVE-2023-44487. * gnu/packages/web.scm (nghttp2-1.57): New variable. (nghttp2)[replacement]: Use it. Signed-off-by: Ludovic Courtès --- gnu/packages/web.scm | 14 ++++++++++++++ 1 file changed, 14 insertions(+) (limited to 'gnu') diff --git a/gnu/packages/web.scm b/gnu/packages/web.scm index b1cdfda862..66d09700db 100644 --- a/gnu/packages/web.scm +++ b/gnu/packages/web.scm @@ -7959,6 +7959,7 @@ (define-public nghttp2 (package (name "nghttp2") (version "1.49.0") + (replacement nghttp2-1.57) (source (origin (method url-fetch) @@ -8069,6 +8070,19 @@ (define-public nghttp2-for-node (("print \\(ver >= '3\\.8'\\)") "print (tuple(map(int, ver.split('.'))) >= (3,8))"))))))))))) +(define-public nghttp2-1.57 + (package + (inherit nghttp2) + (version "1.57.0") + (source (origin + (method url-fetch) + (uri (string-append "https://github.com/nghttp2/nghttp2/" + "releases/download/v" version "/" + "nghttp2-" version ".tar.xz")) + (sha256 + (base32 + "0n598w7w8rqdqiay2fad3a11253hibakan5c4vjkpx09648v044j")))))) + (define-public hpcguix-web (package (name "hpcguix-web") -- cgit v1.2.3