Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

openssl_1_1 is going to be marked as insecure/dropped #231

Open
jtojnar opened this issue May 12, 2023 · 9 comments
Open

openssl_1_1 is going to be marked as insecure/dropped #231

jtojnar opened this issue May 12, 2023 · 9 comments

Comments

@jtojnar
Copy link
Member

jtojnar commented May 12, 2023

Similar to #78, we might need to backport OpenSSL 3 compatibility patches (if possible).

Upstream issue: NixOS/nixpkgs#210452

@ajs124
Copy link
Contributor

ajs124 commented May 19, 2023

it's marked as insecure now. drop pending, but probably still a few months ahead.

@drupol
Copy link
Collaborator

drupol commented Jun 4, 2023

How are we going to tackle this thing in here?

@jtojnar
Copy link
Member Author

jtojnar commented Jun 4, 2023

In the short term, overriding the meta is probably the easiest.

@drupol
Copy link
Collaborator

drupol commented Jun 4, 2023

And marking the package as insecure adding meta.knownVulnerabilities ? If yes, which vulnerability ?

@aanderse
Copy link
Collaborator

aanderse commented Jun 4, 2023

I'm also interested in resolution to this.

@jtojnar
Copy link
Member Author

jtojnar commented Jun 4, 2023

And marking the package as insecure adding meta.knownVulnerabilities ? If yes, which vulnerability ?

Nixpkgs does that. So we would need to do the opposite – removing meta.knownVulnerabilities.

@drupol
Copy link
Collaborator

drupol commented Jun 4, 2023

Oooh. Ok.

@drupol
Copy link
Collaborator

drupol commented Jun 4, 2023

Your eyes here : #237

@jtojnar
Copy link
Member Author

jtojnar commented Jun 5, 2023

We still need to deal with this once the package is removed. Ideally, we would patch PHP to use OpenSSL 3.

@jtojnar jtojnar reopened this Jun 5, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants