Files
nixpkgs/pkgs/applications
Maximilian Bosch ef186b47af rambox: unmaintain & mark as insecure
Rambox hasn't had a stable release in a while and an increasing number
of issues which is why I don't intend to use this anymore.

While taking a closer look at the source I also realized that it uses
Electron 7.2.4[1]. This is not only EOLed[2], it also contains a few
security vulnerabilities which is why I decided to mark it as insecure.

A few (most likely not all) vulnerabilities can be found by looking at
the Electron 7 changelog[3]: after 7.2.4 there were a few more releases
with security backports - mostly from Chromium. Security issues that
were found later on (and are probably exploitable on the dependency
chain of rambox) aren't listed here. I only added two issues that seemed
applicable to `rambox`, but I haven't researched enough to check the
other ones.

[1] https://github.com/ramboxapp/community-edition/blob/0.7.7/package.json#L70
[2] https://www.electronjs.org/docs/tutorial/support#currently-supported-versions
[3] https://www.electronjs.org/releases/stable?version=7

(cherry picked from commit e2a15cd395f1e137c680d22f83cd195caf3d6c14)
2021-06-05 11:44:21 +00:00
..
2021-06-02 19:40:46 +02:00
2021-05-30 02:04:12 +00:00
2021-05-16 18:32:44 +00:00
2021-06-02 08:18:16 +00:00
2021-06-03 04:30:30 -04:00
2021-05-30 01:52:44 +00:00
2021-05-02 21:22:56 +02:00
2021-05-30 02:19:51 +00:00