Merge branch 'staging-next'
This round is without the systemd CVE, as we don't have binaries for that yet. BTW, I just ignore darwin binaries these days, as I'd have to wait for weeks for them.
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
{ config, stdenv, fetchurl, pkgconfig, libiconv
|
||||
{ config, stdenv, fetchurl, fetchpatch, pkgconfig, libiconv
|
||||
, libintl, expat, zlib, libpng, pixman, fontconfig, freetype, xorg
|
||||
, gobjectSupport ? true, glib
|
||||
, xcbSupport ? true # no longer experimental since 1.12
|
||||
@@ -22,6 +22,19 @@ in stdenv.mkDerivation rec {
|
||||
sha256 = "0c930mk5xr2bshbdljv005j3j8zr47gqmkry3q6qgvqky6rjjysy";
|
||||
};
|
||||
|
||||
patches = [
|
||||
# Fixes CVE-2018-19876; see Nixpkgs issue #55384
|
||||
# CVE information: https://nvd.nist.gov/vuln/detail/CVE-2018-19876
|
||||
# Upstream PR: https://gitlab.freedesktop.org/cairo/cairo/merge_requests/5
|
||||
#
|
||||
# This patch is the merged commit from the above PR.
|
||||
(fetchpatch {
|
||||
name = "CVE-2018-19876.patch";
|
||||
url = "https://gitlab.freedesktop.org/cairo/cairo/commit/6edf572ebb27b00d3c371ba5ae267e39d27d5b6d.patch";
|
||||
sha256 = "112hgrrsmcwxh1r52brhi5lksq4pvrz4xhkzcf2iqp55jl2pb7n1";
|
||||
})
|
||||
];
|
||||
|
||||
outputs = [ "out" "dev" "devdoc" ];
|
||||
outputBin = "dev"; # very small
|
||||
|
||||
|
||||
Reference in New Issue
Block a user