Skip to content

whisper: set knownVulnerabilities due to dated vendored libraries#457885

Merged
vcunat merged 1 commit intoNixOS:masterfrom
LunNova:push-lwxylrmnkozw
Nov 17, 2025
Merged

whisper: set knownVulnerabilities due to dated vendored libraries#457885
vcunat merged 1 commit intoNixOS:masterfrom
LunNova:push-lwxylrmnkozw

Conversation

@LunNova
Copy link
Member

@LunNova LunNova commented Nov 2, 2025

whisper vendors libraries that haven't been updated in 6 to 8 years.

Things done


Add a 👍 reaction to pull requests you find important.

whisper vendors libraries acof, aelf, deflate, bzip2, zlib 
that haven't been updated in 6-8 years
@LunNova LunNova added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Nov 2, 2025
@nix-owners nix-owners bot requested a review from jbedo November 2, 2025 19:19
@nixpkgs-ci nixpkgs-ci bot added 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. 10.rebuild-linux: 0 This PR does not cause any packages to rebuild on Linux. labels Nov 2, 2025
@LunNova
Copy link
Member Author

LunNova commented Nov 3, 2025

@trofi I noticed you've submitted fixes to upstream already, if you feel like making another PR to upstream to improve the situation we could go with that instead. If so I can close this.

@vcunat vcunat added this pull request to the merge queue Nov 17, 2025
@vcunat
Copy link
Member

vcunat commented Nov 17, 2025

When that happens, this commit is trivial to revert.

Merged via the queue into NixOS:master with commit 30d55d2 Nov 17, 2025
31 of 33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1.severity: security Issues which raise a security issue, or PRs that fix one 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. 10.rebuild-linux: 0 This PR does not cause any packages to rebuild on Linux.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants