EdenEast / nyx

⚙️Nix[OS] Configuration
The Unlicense
151 stars 10 forks source link

chore(flake): Automatic flake update #44

Closed EdenEast closed 2 years ago

EdenEast commented 2 years ago

Flake lock file changes:

github-actions[bot] commented 2 years ago

Report for theman

Version changes:

Version 1 -> 2:'
'  ICU: +1757.9 KiB'
'  aws-c-auth: 0.6.11 → 0.6.13, -22.8 KiB'
'  aws-c-cal: 0.5.14 → 0.5.17'
'  aws-c-common: 0.6.19 → 0.7.0, +41.7 KiB'
'  aws-c-http: 0.6.10 → 0.6.15, +31.6 KiB'
'  aws-c-io: 0.10.19 → 0.11.0'
'  aws-c-s3: 0.1.33 → 0.1.39, -25.3 KiB'
'  aws-crt-cpp: 0.17.16 → 0.17.28, +12.5 KiB'
'  bash-language-server: +166.7 KiB'
'  bat: 0.20.0 → 0.21.0, +228.5 KiB'
'  curl: 7.82.0 → 7.83.0'
'  darwin-system: 22.05.20220505.c777cdf+darwin4.2f2bdf6 → 22.05.20220513.fb222e0+darwin4.2f2bdf6'
'  expat: 2.4.7 → 2.4.8'
'  gh: 2.9.0 → 2.10.1, +40.7 KiB'
'  icu4c: 70.1 → 71.1, +967.2 KiB'
'  libgit2: 1.4.0 → 1.4.3'
'  libxml2: 2.9.13 → 2.9.14'
'  neovim-unwrapped: -70.7 KiB'
'  openssl: 1.1.1n → 1.1.1o'
'  pyright: 1.1.243 → 1.1.246, +81.6 KiB'
'  shfmt: 3.4.3 → 3.5.0'
'  source: -1066.5 KiB'
'  sqlite: 3.38.2 → 3.38.3'
'  tree-sitter-nix-grammar: +8.0 KiB'
'  tree-sitter-vim-grammar: +56.0 KiB'
'  tree-sitter-viml: 5268e0e → 4b9d2dd, +187.7 KiB'
'  typescript-language-server: 0.9.7 → 0.10.0, +917.4 KiB
Security vulnerability report
19 derivations with active advisories'
'20 derivations left out due to whitelisting'
''
'------------------------------------------------------------------------'
'async-2.2.4'
''
'/nix/store/ghjl2hifkkwrwrfq3zhd7aics64x2bl2-async-2.2.4.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2021-43138    7.8'
''
'------------------------------------------------------------------------'
'async-2.2.4-r1.cabal'
''
'/nix/store/k70wx8vnz42hxhzxg5pllaphxfr9fbv2-async-2.2.4-r1.cabal.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2021-43138    7.8'
''
'------------------------------------------------------------------------'
'cereal-0.5.8.2'
''
'/nix/store/syl9lyjqqqzhxqfbbzqj40j0qn00qyc5-cereal-0.5.8.2.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2020-11105    9.8'
'https://nvd.nist.gov/vuln/detail/CVE-2020-11104    5.3'
''
'------------------------------------------------------------------------'
'charset-0.3.9'
''
'/nix/store/h1dwq3847qnkksdlg5i86py3mpad58sc-charset-0.3.9.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2017-16098    7.5'
''
'------------------------------------------------------------------------'
'commonmark-0.2.2'
''
'/nix/store/szcvy3a07xw4nfx5jl20sh9lpji76q1b-commonmark-0.2.2.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2019-10010    6.1'
''
'------------------------------------------------------------------------'
'go-1.16-darwin-amd64-bootstrap'
''
'/nix/store/x0ynx51j1vzdi8qyryvgrln52mgh8ybj-go-1.16-darwin-amd64-bootstrap.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2021-38297    9.8'
'https://nvd.nist.gov/vuln/detail/CVE-2022-23806    9.1'
'https://nvd.nist.gov/vuln/detail/CVE-2021-39293    7.5'
'https://nvd.nist.gov/vuln/detail/CVE-2021-41771    7.5'
'https://nvd.nist.gov/vuln/detail/CVE-2021-41772    7.5'
'https://nvd.nist.gov/vuln/detail/CVE-2021-44716    7.5'
'https://nvd.nist.gov/vuln/detail/CVE-2022-23772    7.5'
'https://nvd.nist.gov/vuln/detail/CVE-2022-23773    7.5'
'https://nvd.nist.gov/vuln/detail/CVE-2022-24675    7.5'
'https://nvd.nist.gov/vuln/detail/CVE-2022-24921    7.5'
'https://nvd.nist.gov/vuln/detail/CVE-2022-28327    7.5'
'https://nvd.nist.gov/vuln/detail/CVE-2021-34558    6.5'
'https://nvd.nist.gov/vuln/detail/CVE-2021-44717    4.8'
''
'------------------------------------------------------------------------'
'http-client-0.7.11'
''
'/nix/store/mydrn8zjm171fm9si7z94alpmjfai3pk-http-client-0.7.11.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2020-11021    7.5'
''
'------------------------------------------------------------------------'
'http-client-0.7.11-r1.cabal'
''
'/nix/store/qpi0ir08vpxfz9i88cksqhi1mfww33lz-http-client-0.7.11-r1.cabal.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2020-11021    7.5'
''
'------------------------------------------------------------------------'
'lens-5.0.1'
''
'/nix/store/7lgnd9f07dhgcd8587b3f3w8s9wphygj-lens-5.0.1.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2021-44458    9.6'
'https://nvd.nist.gov/vuln/detail/CVE-2021-23154    7.8'
''
'------------------------------------------------------------------------'
'lens-5.0.1-r3.cabal'
''
'/nix/store/w0zx0zbdx3rnk10apc959jfypqiqjd89-lens-5.0.1-r3.cabal.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2021-44458    9.6'
'https://nvd.nist.gov/vuln/detail/CVE-2021-23154    7.8'
''
'------------------------------------------------------------------------'
'lua-2.1.0'
''
'/nix/store/jc3jx7qn10jcly501rfcx2qxc7ysvn9x-lua-2.1.0.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2022-28805    9.1'
'https://nvd.nist.gov/vuln/detail/CVE-2020-15888    8.8'
'https://nvd.nist.gov/vuln/detail/CVE-2020-15945    5.5'
''
'------------------------------------------------------------------------'
'network-3.1.2.7'
''
'/nix/store/2dn7abrca51q9f9sqdm0f3ji23yzrh45-network-3.1.2.7.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2021-35048    9.8'
'https://nvd.nist.gov/vuln/detail/CVE-2021-35047    8.8'
'https://nvd.nist.gov/vuln/detail/CVE-2021-35049    8.8'
'https://nvd.nist.gov/vuln/detail/CVE-2021-35050    7.5'
''
'------------------------------------------------------------------------'
'openldap-2.4.58'
''
'/nix/store/cyylpqilf64vbcbr284g1vixnw561123-openldap-2.4.58.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2022-29155    9.8'
''
'------------------------------------------------------------------------'
'openssl-0.10.30'
''
'/nix/store/sd0ay15fcz8arizwn57ka2pf66wfc725-openssl-0.10.30.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2018-16395    9.8'
'https://nvd.nist.gov/vuln/detail/CVE-2021-4044     7.5'
''
'------------------------------------------------------------------------'
'quote-1.0.7'
''
'/nix/store/amm6fjnmbf2lyd82w9skw2gagwvnai9p-quote-1.0.7.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2020-16194    5.3'
''
'------------------------------------------------------------------------'
'regex-1.4.5'
''
'/nix/store/klmk4arjvlc3hllc1kpl8m0a6ax5ab3d-regex-1.4.5.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2022-24713    7.5'
''
'------------------------------------------------------------------------'
'safe-0.3.19'
''
'/nix/store/dn01xgdkilzfsdn5f09vw2w32l2c7s4y-safe-0.3.19.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2019-11644    7.8'
'https://nvd.nist.gov/vuln/detail/CVE-2021-44751    5.3'
'https://nvd.nist.gov/vuln/detail/CVE-2021-40834    4.3'
'https://nvd.nist.gov/vuln/detail/CVE-2021-40835    4.3'
'https://nvd.nist.gov/vuln/detail/CVE-2022-28868    4.3'
'https://nvd.nist.gov/vuln/detail/CVE-2022-28869    4.3'
'https://nvd.nist.gov/vuln/detail/CVE-2022-28870    4.3'
'https://nvd.nist.gov/vuln/detail/CVE-2021-33596    4.1'
'https://nvd.nist.gov/vuln/detail/CVE-2021-33594    3.5'
'https://nvd.nist.gov/vuln/detail/CVE-2021-33595    3.5'
''
'------------------------------------------------------------------------'
'zlib-0.6.2.3'
''
'/nix/store/y5i90sa5shwdhc69ha0aq67dar99hgmz-zlib-0.6.2.3.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2018-25032    7.5'
''
'------------------------------------------------------------------------'
'zlib-0.6.2.3-r1.cabal'
''
'/nix/store/h9rwv6xj7p3f5r9zkivyrf2bkkh015mi-zlib-0.6.2.3-r1.cabal.drv'
'CVE                                                CVSSv3'
'https://nvd.nist.gov/vuln/detail/CVE-2018-25032    7.5'
''
'use --show-whitelisted to see derivations with only whitelisted CVEs
github-actions[bot] commented 2 years ago

Report for eden

Version changes:

Version 1 -> 2:
  aws-c-auth: 0.6.11 → 0.6.13, -23.6 KiB
  aws-c-cal: 0.5.14 → 0.5.17
  aws-c-common: 0.6.19 → 0.7.0, +53.8 KiB
  aws-c-http: 0.6.10 → 0.6.15, +39.8 KiB
  aws-c-io: 0.10.19 → 0.11.0
  aws-c-s3: 0.1.33 → 0.1.39, -22.8 KiB
  aws-crt-cpp: 0.17.16 → 0.17.28, +14.2 KiB
  aws-sdk-cpp: +11.7 KiB
  bash-language-server: +166.7 KiB
  bat: 0.20.0 → 0.21.0, +233.0 KiB
  cachix: +8.6 KiB
  clang: -97.2 KiB
  cmake-cursesUI: +36.5 KiB
  curl: 7.82.0 → 7.83.0
  expat: 2.4.7 → 2.4.8
  gcc: 11.2.0 → 11.3.0, +112.8 KiB
  gcc-wrapper: 11.2.0 → 11.3.0
  gh: 2.9.0 → 2.10.1, +42.0 KiB
  git: +34.5 KiB
  icu4c: 70.1 → 71.1, +970.0 KiB
  libgit2: 1.4.0 → 1.4.3
  libxml2: 2.9.13 → 2.9.14
  lldb: -235.9 KiB
  llvm: -46.4 KiB
  neovim-unwrapped: -65.0 KiB
  nix: +26.5 KiB
  openssl: 1.1.1n → 1.1.1o
  pyright: 1.1.243 → 1.1.246, +81.6 KiB
  rust-analyzer-nightly: 81b3e6d → 06448c5, +211.1 KiB
  s2n-tls: 1.3.6 → 1.3.12, +10.1 KiB
  shfmt: 3.4.3 → 3.5.0
  source: -1066.5 KiB
  sqlite: 3.38.2 → 3.38.3
  tree-sitter-nix-grammar: +8.0 KiB
  tree-sitter-vim-grammar: +60.1 KiB
  tree-sitter-viml: 5268e0e → 4b9d2dd, +187.7 KiB
  typescript-language-server: 0.9.7 → 0.10.0, +917.4 KiB
  vim: 8.2.4609 → 8.2.4816, +69.8 KiB
Security vulnerability report
33 derivations with active advisories
24 derivations left out due to whitelisting

------------------------------------------------------------------------
ShellCheck-0.8.0

/nix/store/p7xd0lmy4ah3rrhczb04xr4qly80kn9g-ShellCheck-0.8.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-28794    9.8

------------------------------------------------------------------------
anymap-0.12.1

/nix/store/grm97rckj9572yvpanz72jmzn7b739xw-anymap-0.12.1.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-38187    9.8

------------------------------------------------------------------------
async-2.2.4

/nix/store/fyz9zf01m9vg66ha77j45d1zraa169qh-async-2.2.4.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-43138    7.8

------------------------------------------------------------------------
async-2.2.4-r1.cabal

/nix/store/fvj0jp3bqy83xlwpn3njp7ym5g39x4hc-async-2.2.4-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-43138    7.8

------------------------------------------------------------------------
cereal-0.5.8.2

/nix/store/9j58ijsr48q8wl4lk25w8yqhn3zxsxvy-cereal-0.5.8.2.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-11105    9.8
https://nvd.nist.gov/vuln/detail/CVE-2020-11104    5.3

------------------------------------------------------------------------
charset-0.3.9

/nix/store/mr8w7rvkjp954dijrssgn89299kj6vby-charset-0.3.9.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2017-16098    7.5

------------------------------------------------------------------------
commonmark-0.2.2

/nix/store/qpngiglpnzb1a8aicqmxabbrd1brfpl8-commonmark-0.2.2.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2019-10010    6.1

------------------------------------------------------------------------
dot-0.1.4

/nix/store/bz837f84kg1swniiikybbkgdqbjpwcd1-dot-0.1.4.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-7639     5.3

------------------------------------------------------------------------
fuse-2.9.9-closefrom-glibc-2-34.patch?id=8a970396fca7aca2d5a761b8e7a8242f1eef14c9

/nix/store/43fvswxdakdcjrknc9phd1yayb0c8bir-fuse-2.9.9-closefrom-glibc-2-34.patch?id=8a970396fca7aca2d5a761b8e7a8242f1eef14c9.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2019-14860    6.5
https://nvd.nist.gov/vuln/detail/CVE-2019-14900    6.5

------------------------------------------------------------------------
go-1.16-linux-amd64-bootstrap

/nix/store/s5wliwnshsc7c6akd0phx44p7fmlf001-go-1.16-linux-amd64-bootstrap.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-38297    9.8
https://nvd.nist.gov/vuln/detail/CVE-2022-23806    9.1
https://nvd.nist.gov/vuln/detail/CVE-2021-39293    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-41771    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-41772    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-44716    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-23772    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-23773    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-24675    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-24921    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-28327    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-34558    6.5
https://nvd.nist.gov/vuln/detail/CVE-2021-44717    4.8

------------------------------------------------------------------------
home-0.5.3

/nix/store/vy4amkb5jx2g3c7dpbfjrlfj5425ifw8-home-0.5.3.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-25264    6.7

------------------------------------------------------------------------
http-client-0.7.11

/nix/store/9iwcbmihrhqsdgqx450a54868vn7vp89-http-client-0.7.11.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-11021    7.5

------------------------------------------------------------------------
http-client-0.7.11-r1.cabal

/nix/store/bhy90gcvsaxkwr5yf5bkj33m09z21w3b-http-client-0.7.11-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-11021    7.5

------------------------------------------------------------------------
instant-0.1.12

/nix/store/nj6ksv74g52v3xwc8qlv3jsdmxf5m75i-instant-0.1.12.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2017-13099    5.9

------------------------------------------------------------------------
jose-0.9

/nix/store/j8dwnrn7rpqssi533ynhjli8zmc7in83-jose-0.9.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-29444    5.9
https://nvd.nist.gov/vuln/detail/CVE-2021-29445    5.9
https://nvd.nist.gov/vuln/detail/CVE-2021-29446    5.9

------------------------------------------------------------------------
lens-5.0.1

/nix/store/p85palv493r01sqdggljcc1aqq1n5c4w-lens-5.0.1.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-44458    9.6
https://nvd.nist.gov/vuln/detail/CVE-2021-23154    7.8

------------------------------------------------------------------------
lens-5.0.1-r3.cabal

/nix/store/yh2is7x1mfaaa69pra8x5k2pxa7i6wjh-lens-5.0.1-r3.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-44458    9.6
https://nvd.nist.gov/vuln/detail/CVE-2021-23154    7.8

------------------------------------------------------------------------
lua-2.1.0

/nix/store/z99dgpvnx257ihq351p0aib49nl32blq-lua-2.1.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-28805    9.1
https://nvd.nist.gov/vuln/detail/CVE-2020-15888    8.8
https://nvd.nist.gov/vuln/detail/CVE-2020-15945    5.5

------------------------------------------------------------------------
network-3.1.2.7

/nix/store/60ihlfc3hbvn1wgbrf40sfwfk69lggh3-network-3.1.2.7.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-35048    9.8
https://nvd.nist.gov/vuln/detail/CVE-2021-35047    8.8
https://nvd.nist.gov/vuln/detail/CVE-2021-35049    8.8
https://nvd.nist.gov/vuln/detail/CVE-2021-35050    7.5

------------------------------------------------------------------------
openldap-2.4.58

/nix/store/mah8m3zkb6i3hbqa0flg0arxccdi2ngm-openldap-2.4.58.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-29155    9.8

------------------------------------------------------------------------
openssl-0.10.30

/nix/store/pb1nx6amhqg9i5x3hvafgh5km51hrgsa-openssl-0.10.30.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-16395    9.8
https://nvd.nist.gov/vuln/detail/CVE-2021-4044     7.5

------------------------------------------------------------------------
quote-1.0.7

/nix/store/1v07kcr389v9dkp66m5w5z9vhswhl1c9-quote-1.0.7.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-16194    5.3

------------------------------------------------------------------------
quote-1.0.18

/nix/store/5vyv1pirqiv1x448h2c31s5fn7x8c57w-quote-1.0.18.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-16194    5.3

------------------------------------------------------------------------
regex-1.4.5

/nix/store/mbm7wl9bsfa05qd3q9xz7dja2h5i2fq1-regex-1.4.5.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-24713    7.5

------------------------------------------------------------------------
safe-0.3.19

/nix/store/0v8qfqfh3ksb4ihdpzw3rrrghrldrfsy-safe-0.3.19.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2019-11644    7.8
https://nvd.nist.gov/vuln/detail/CVE-2021-44751    5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-40834    4.3
https://nvd.nist.gov/vuln/detail/CVE-2021-40835    4.3
https://nvd.nist.gov/vuln/detail/CVE-2022-28868    4.3
https://nvd.nist.gov/vuln/detail/CVE-2022-28869    4.3
https://nvd.nist.gov/vuln/detail/CVE-2022-28870    4.3
https://nvd.nist.gov/vuln/detail/CVE-2021-33596    4.1
https://nvd.nist.gov/vuln/detail/CVE-2021-33594    3.5
https://nvd.nist.gov/vuln/detail/CVE-2021-33595    3.5

------------------------------------------------------------------------
systemd-2.3.0

/nix/store/1qhwqjbhnv5v9lp98nkvjbl9b6anh1wy-systemd-2.3.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2017-1000082  9.8
https://nvd.nist.gov/vuln/detail/CVE-2018-15688    8.8
https://nvd.nist.gov/vuln/detail/CVE-2017-18078    7.8
https://nvd.nist.gov/vuln/detail/CVE-2018-6954     7.8
https://nvd.nist.gov/vuln/detail/CVE-2018-15686    7.8
https://nvd.nist.gov/vuln/detail/CVE-2018-16864    7.8
https://nvd.nist.gov/vuln/detail/CVE-2018-16865    7.8
https://nvd.nist.gov/vuln/detail/CVE-2019-3843     7.8
https://nvd.nist.gov/vuln/detail/CVE-2019-3844     7.8
https://nvd.nist.gov/vuln/detail/CVE-2020-1712     7.8
https://nvd.nist.gov/vuln/detail/CVE-2017-9217     7.5
https://nvd.nist.gov/vuln/detail/CVE-2018-15687    7.0
https://nvd.nist.gov/vuln/detail/CVE-2019-3842     7.0
https://nvd.nist.gov/vuln/detail/CVE-2020-13776    6.7
https://nvd.nist.gov/vuln/detail/CVE-2018-1049     5.9
https://nvd.nist.gov/vuln/detail/CVE-2021-33910    5.5
https://nvd.nist.gov/vuln/detail/CVE-2018-16888    4.7
https://nvd.nist.gov/vuln/detail/CVE-2019-20386    2.4

------------------------------------------------------------------------
vault-0.3.1.5

/nix/store/v5nq5ip88p8a756p6aig7jxppr975x79-vault-0.3.1.5.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-19786    8.1
https://nvd.nist.gov/vuln/detail/CVE-2020-13223    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-27400    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-41802    5.4
https://nvd.nist.gov/vuln/detail/CVE-2020-25594    5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-3024     5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-38554    5.3

------------------------------------------------------------------------
vault-0.3.1.5-r1.cabal

/nix/store/9gszsfsb0hm1sz20gv16iv65kng0xrwh-vault-0.3.1.5-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-19786    8.1
https://nvd.nist.gov/vuln/detail/CVE-2020-13223    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-27400    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-41802    5.4
https://nvd.nist.gov/vuln/detail/CVE-2020-25594    5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-3024     5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-38554    5.3

------------------------------------------------------------------------
websockets-0.12.7.3

/nix/store/yl5jcrzymcws92k5dm4q70s5vmckijhd-websockets-0.12.7.3.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-33880    5.9

------------------------------------------------------------------------
websockets-0.12.7.3-r1.cabal

/nix/store/hmjdb5rympax1ryd8fyssamzfia1svf9-websockets-0.12.7.3-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-33880    5.9

------------------------------------------------------------------------
xshell-0.2.1

/nix/store/ms4ik6w7g7dncicha5ivsbq4xans34p8-xshell-0.2.1.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-42095    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-27966    6.5

------------------------------------------------------------------------
zlib-0.6.2.3

/nix/store/3fz3f1a8kv5jmj1awvmadrb4vn49wkpn-zlib-0.6.2.3.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-25032    7.5

------------------------------------------------------------------------
zlib-0.6.2.3-r1.cabal

/nix/store/wp6f9fldqwygrs0wc4ipd1ib1mvwwjwh-zlib-0.6.2.3-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-25032    7.5

use --show-whitelisted to see derivations with only whitelisted CVEs
github-actions[bot] commented 2 years ago

Report for sloth

Version changes:

Version 1 -> 2:
  NetworkManager-sstp-gnome: ∅ → 1.3.0, +1061.6 KiB
  NetworkManager-sstp-gnome-unstable: 2020-04-20 → ∅, -973.8 KiB
  alsa-firmware: -10388.3 KiB
  aws-c-auth: 0.6.11 → 0.6.13, -23.6 KiB
  aws-c-cal: 0.5.14 → 0.5.17
  aws-c-common: 0.6.19 → 0.7.0, +53.8 KiB
  aws-c-http: 0.6.10 → 0.6.15, +39.8 KiB
  aws-c-io: 0.10.19 → 0.11.0
  aws-c-s3: 0.1.33 → 0.1.39, -22.8 KiB
  aws-crt-cpp: 0.17.16 → 0.17.28, +14.2 KiB
  aws-sdk-cpp: +11.7 KiB
  bash-language-server: +166.7 KiB
  bat: 0.20.0 → 0.21.0, +233.0 KiB
  btrfs-progs: 5.16.2 → 5.17, +40.1 KiB
  cachix: +8.6 KiB
  clang: -97.2 KiB
  cmake: +27.4 KiB
  cmake-cursesUI: +36.5 KiB
  curl: 7.82.0 → 7.83.0, +10.9 KiB
  expat: 2.4.7 → 2.4.8
  extra: ∅ → ε, +21836.8 KiB
  ffmpeg: -16.0 KiB
  firefox: -16.1 KiB
  firefox-unwrapped: +5605.3 KiB
  gcc: 11.2.0 → 11.3.0, +112.8 KiB
  gcc-wrapper: 11.2.0 → 11.3.0
  gcr: +38.8 KiB
  gfortran: 11.2.0 → 11.3.0
  gh: 2.9.0 → 2.10.1, +42.0 KiB
  ghostscript-with-X: 9.55.0 → 9.56.1, +3009.9 KiB
  git: +34.5 KiB
  icu4c: 70.1 → 71.1, +970.0 KiB
  ijs: 9.55.0 → 9.56.1
  imlib2: 1.7.5 → 1.8.1, +41.0 KiB
  initrd: ∅ → ε
  initrd-linux: 5.15.36 → 5.15.39
  intel2200BGFirmware: -351.3 KiB
  keymap: ∅ → ε
  libgit2: 1.4.0 → 1.4.3
  libheif: ∅ → 1.12.0, +795.6 KiB
  libnotify: 0.7.9 → 0.7.11
  libopenmpt: 0.6.2 → 0.6.3
  libpulseaudio: +133.5 KiB
  libreelec-dvb-firmware: -2979.2 KiB
  librsvg: 2.54.0 → 2.54.1, +98.9 KiB
  libsndfile: 1.0.31 → 1.1.0
  libxml2: 2.9.13 → 2.9.14
  lightdm-gtk-greeter: +13.2 KiB
  linux: 5.15.36, 5.15.36-modules → 5.15.39, 5.15.39-modules, +21.4 KiB
  linux-firmware: 20220310 → 20220509, -499058.2 KiB
  lldb: -235.9 KiB
  llvm: -46.4 KiB
  mdadm.conf: ∅ → ε
  nano: 6.2 → 6.3, +100.6 KiB
  neovim-unwrapped: -65.0 KiB
  network-manager-applet: +18.4 KiB
  nix: +21.9 KiB
  nixos: +48.2 KiB
  nixos-manual: +136.7 KiB
  nixos-system-sloth: 22.05.20220505.c777cdf → 22.05.20220513.fb222e0
  openal-soft: -8.1 KiB
  opencv: +49.3 KiB
  openexr: -8.2 KiB
  openssl: 1.1.1n → 1.1.1o
  pipewire: 0.3.49 → 0.3.51, +17.4 KiB
  poppler-glib: 22.03.0 → 22.04.0, +28.7 KiB
  poppler-utils: 22.03.0 → 22.04.0, +29.4 KiB
  protobuf: 3.19.3 → 3.19.4, -50.9 KiB
  pulseaudio: +115.7 KiB
  pyright: 1.1.243 → 1.1.246, +81.6 KiB
  qpdf: +13.0 KiB
  qttools: +8.4 KiB
  rav1e: ∅ → 0.5.1, +98494.9 KiB
  rofi: +71.8 KiB
  rt5677: ε → ∅, -705.9 KiB
  rt5677-firmware: ∅ → ε, +169.9 KiB
  rtl8192su-unstable: -418.9 KiB
  rtl8723bs-firmware: 2017-04-06 → ∅, -58.1 KiB
  rtl8761b: ε → ∅, -26.3 KiB
  rtw88-firmware-unstable: -444.4 KiB
  rtw89-firmware-unstable: -1263.6 KiB
  rust-analyzer-nightly: 81b3e6d → 06448c5, +211.1 KiB
  s2n-tls: 1.3.6 → 1.3.12, +10.1 KiB
  shfmt: 3.4.3 → 3.5.0
  sndio: ∅ → 1.8.1, +328.5 KiB
  sof-firmware: -10808.3 KiB
  source: -1066.5 KiB
  sqlite: 3.38.2 → 3.38.3
  stage: ∅ → 1-init.sh, +19.5 KiB
  tracker: +24.5 KiB
  tree-sitter-nix-grammar: +8.0 KiB
  tree-sitter-vim-grammar: +60.1 KiB
  tree-sitter-viml: 5268e0e → 4b9d2dd, +187.7 KiB
  typescript-language-server: 0.9.7 → 0.10.0, +917.4 KiB
  udev: +35.4 KiB
  vim: 8.2.4609 → 8.2.4816, +69.8 KiB
  wireless-regdb: -11.2 KiB
  xfsprogs: 5.15.0 → 5.16.0, +41.1 KiB
  zd1211-firmware: -337.2 KiB
  zimg: 3.0.3 → 3.0.4
Security vulnerability report
34 derivations with active advisories
39 derivations left out due to whitelisting

------------------------------------------------------------------------
ShellCheck-0.8.0

/nix/store/p7xd0lmy4ah3rrhczb04xr4qly80kn9g-ShellCheck-0.8.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-28794    9.8

------------------------------------------------------------------------
anymap-0.12.1

/nix/store/grm97rckj9572yvpanz72jmzn7b739xw-anymap-0.12.1.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-38187    9.8

------------------------------------------------------------------------
async-2.2.4

/nix/store/fyz9zf01m9vg66ha77j45d1zraa169qh-async-2.2.4.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-43138    7.8

------------------------------------------------------------------------
async-2.2.4-r1.cabal

/nix/store/fvj0jp3bqy83xlwpn3njp7ym5g39x4hc-async-2.2.4-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-43138    7.8

------------------------------------------------------------------------
cereal-0.5.8.2

/nix/store/9j58ijsr48q8wl4lk25w8yqhn3zxsxvy-cereal-0.5.8.2.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-11105    9.8
https://nvd.nist.gov/vuln/detail/CVE-2020-11104    5.3

------------------------------------------------------------------------
charset-0.3.9

/nix/store/mr8w7rvkjp954dijrssgn89299kj6vby-charset-0.3.9.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2017-16098    7.5

------------------------------------------------------------------------
commonmark-0.2.2

/nix/store/qpngiglpnzb1a8aicqmxabbrd1brfpl8-commonmark-0.2.2.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2019-10010    6.1

------------------------------------------------------------------------
dot-0.1.4

/nix/store/bz837f84kg1swniiikybbkgdqbjpwcd1-dot-0.1.4.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-7639     5.3

------------------------------------------------------------------------
exfat-1.3.0

/nix/store/96cgdgd0j2gwpdz629z2mcdjz1aahmc7-exfat-1.3.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-29973    4.7

------------------------------------------------------------------------
fuse-2.9.9-closefrom-glibc-2-34.patch?id=8a970396fca7aca2d5a761b8e7a8242f1eef14c9

/nix/store/43fvswxdakdcjrknc9phd1yayb0c8bir-fuse-2.9.9-closefrom-glibc-2-34.patch?id=8a970396fca7aca2d5a761b8e7a8242f1eef14c9.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2019-14860    6.5
https://nvd.nist.gov/vuln/detail/CVE-2019-14900    6.5

------------------------------------------------------------------------
gcc-6.5.0

/nix/store/qwk3qfqccxvaxxidmrmmv1mrrhzcagpg-gcc-6.5.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-37322    7.8

------------------------------------------------------------------------
go-1.16-linux-amd64-bootstrap

/nix/store/s5wliwnshsc7c6akd0phx44p7fmlf001-go-1.16-linux-amd64-bootstrap.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-38297    9.8
https://nvd.nist.gov/vuln/detail/CVE-2022-23806    9.1
https://nvd.nist.gov/vuln/detail/CVE-2021-39293    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-41771    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-41772    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-44716    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-23772    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-23773    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-24675    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-24921    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-28327    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-34558    6.5
https://nvd.nist.gov/vuln/detail/CVE-2021-44717    4.8

------------------------------------------------------------------------
home-0.5.3

/nix/store/vy4amkb5jx2g3c7dpbfjrlfj5425ifw8-home-0.5.3.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-25264    6.7

------------------------------------------------------------------------
http-client-0.7.11

/nix/store/9iwcbmihrhqsdgqx450a54868vn7vp89-http-client-0.7.11.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-11021    7.5

------------------------------------------------------------------------
http-client-0.7.11-r1.cabal

/nix/store/bhy90gcvsaxkwr5yf5bkj33m09z21w3b-http-client-0.7.11-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-11021    7.5

------------------------------------------------------------------------
instant-0.1.12

/nix/store/nj6ksv74g52v3xwc8qlv3jsdmxf5m75i-instant-0.1.12.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2017-13099    5.9

------------------------------------------------------------------------
jose-0.9

/nix/store/j8dwnrn7rpqssi533ynhjli8zmc7in83-jose-0.9.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-29444    5.9
https://nvd.nist.gov/vuln/detail/CVE-2021-29445    5.9
https://nvd.nist.gov/vuln/detail/CVE-2021-29446    5.9

------------------------------------------------------------------------
lens-5.0.1

/nix/store/p85palv493r01sqdggljcc1aqq1n5c4w-lens-5.0.1.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-44458    9.6
https://nvd.nist.gov/vuln/detail/CVE-2021-23154    7.8

------------------------------------------------------------------------
lens-5.0.1-r3.cabal

/nix/store/yh2is7x1mfaaa69pra8x5k2pxa7i6wjh-lens-5.0.1-r3.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-44458    9.6
https://nvd.nist.gov/vuln/detail/CVE-2021-23154    7.8

------------------------------------------------------------------------
lua-2.1.0

/nix/store/z99dgpvnx257ihq351p0aib49nl32blq-lua-2.1.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-28805    9.1
https://nvd.nist.gov/vuln/detail/CVE-2020-15888    8.8
https://nvd.nist.gov/vuln/detail/CVE-2020-15945    5.5

------------------------------------------------------------------------
lua-5.2.4-env

/nix/store/2x7h2mc4nva89w002mk0lcg1rpy8ridz-lua-5.2.4-env.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-28805    9.1
https://nvd.nist.gov/vuln/detail/CVE-2020-15888    8.8
https://nvd.nist.gov/vuln/detail/CVE-2020-15945    5.5
https://nvd.nist.gov/vuln/detail/CVE-2021-43519    5.5

------------------------------------------------------------------------
markdown-0.33-1.rockspec

/nix/store/rzg1q9zdixvhqgv59p9mhsbf9wv63wmj-markdown-0.33-1.rockspec.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-1000874  6.1

------------------------------------------------------------------------
network-3.1.2.7

/nix/store/60ihlfc3hbvn1wgbrf40sfwfk69lggh3-network-3.1.2.7.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-35048    9.8
https://nvd.nist.gov/vuln/detail/CVE-2021-35047    8.8
https://nvd.nist.gov/vuln/detail/CVE-2021-35049    8.8
https://nvd.nist.gov/vuln/detail/CVE-2021-35050    7.5

------------------------------------------------------------------------
openldap-2.4.58

/nix/store/mah8m3zkb6i3hbqa0flg0arxccdi2ngm-openldap-2.4.58.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-29155    9.8

------------------------------------------------------------------------
quote-1.0.18

/nix/store/5vyv1pirqiv1x448h2c31s5fn7x8c57w-quote-1.0.18.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-16194    5.3

------------------------------------------------------------------------
safe-0.3.19

/nix/store/0v8qfqfh3ksb4ihdpzw3rrrghrldrfsy-safe-0.3.19.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2019-11644    7.8
https://nvd.nist.gov/vuln/detail/CVE-2021-44751    5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-40834    4.3
https://nvd.nist.gov/vuln/detail/CVE-2021-40835    4.3
https://nvd.nist.gov/vuln/detail/CVE-2022-28868    4.3
https://nvd.nist.gov/vuln/detail/CVE-2022-28869    4.3
https://nvd.nist.gov/vuln/detail/CVE-2022-28870    4.3
https://nvd.nist.gov/vuln/detail/CVE-2021-33596    4.1
https://nvd.nist.gov/vuln/detail/CVE-2021-33594    3.5
https://nvd.nist.gov/vuln/detail/CVE-2021-33595    3.5

------------------------------------------------------------------------
systemd-2.3.0

/nix/store/1qhwqjbhnv5v9lp98nkvjbl9b6anh1wy-systemd-2.3.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2017-1000082  9.8
https://nvd.nist.gov/vuln/detail/CVE-2018-15688    8.8
https://nvd.nist.gov/vuln/detail/CVE-2017-18078    7.8
https://nvd.nist.gov/vuln/detail/CVE-2018-6954     7.8
https://nvd.nist.gov/vuln/detail/CVE-2018-15686    7.8
https://nvd.nist.gov/vuln/detail/CVE-2018-16864    7.8
https://nvd.nist.gov/vuln/detail/CVE-2018-16865    7.8
https://nvd.nist.gov/vuln/detail/CVE-2019-3843     7.8
https://nvd.nist.gov/vuln/detail/CVE-2019-3844     7.8
https://nvd.nist.gov/vuln/detail/CVE-2020-1712     7.8
https://nvd.nist.gov/vuln/detail/CVE-2017-9217     7.5
https://nvd.nist.gov/vuln/detail/CVE-2018-15687    7.0
https://nvd.nist.gov/vuln/detail/CVE-2019-3842     7.0
https://nvd.nist.gov/vuln/detail/CVE-2020-13776    6.7
https://nvd.nist.gov/vuln/detail/CVE-2018-1049     5.9
https://nvd.nist.gov/vuln/detail/CVE-2021-33910    5.5
https://nvd.nist.gov/vuln/detail/CVE-2018-16888    4.7
https://nvd.nist.gov/vuln/detail/CVE-2019-20386    2.4

------------------------------------------------------------------------
vault-0.3.1.5

/nix/store/v5nq5ip88p8a756p6aig7jxppr975x79-vault-0.3.1.5.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-19786    8.1
https://nvd.nist.gov/vuln/detail/CVE-2020-13223    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-27400    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-41802    5.4
https://nvd.nist.gov/vuln/detail/CVE-2020-25594    5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-3024     5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-38554    5.3

------------------------------------------------------------------------
vault-0.3.1.5-r1.cabal

/nix/store/9gszsfsb0hm1sz20gv16iv65kng0xrwh-vault-0.3.1.5-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-19786    8.1
https://nvd.nist.gov/vuln/detail/CVE-2020-13223    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-27400    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-41802    5.4
https://nvd.nist.gov/vuln/detail/CVE-2020-25594    5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-3024     5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-38554    5.3

------------------------------------------------------------------------
websockets-0.12.7.3

/nix/store/yl5jcrzymcws92k5dm4q70s5vmckijhd-websockets-0.12.7.3.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-33880    5.9

------------------------------------------------------------------------
websockets-0.12.7.3-r1.cabal

/nix/store/hmjdb5rympax1ryd8fyssamzfia1svf9-websockets-0.12.7.3-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-33880    5.9

------------------------------------------------------------------------
xshell-0.2.1

/nix/store/ms4ik6w7g7dncicha5ivsbq4xans34p8-xshell-0.2.1.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-42095    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-27966    6.5

------------------------------------------------------------------------
zlib-0.6.2.3

/nix/store/3fz3f1a8kv5jmj1awvmadrb4vn49wkpn-zlib-0.6.2.3.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-25032    7.5

------------------------------------------------------------------------
zlib-0.6.2.3-r1.cabal

/nix/store/wp6f9fldqwygrs0wc4ipd1ib1mvwwjwh-zlib-0.6.2.3-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-25032    7.5

use --show-whitelisted to see derivations with only whitelisted CVEs
github-actions[bot] commented 2 years ago

Report for pride

Version changes:

Version 1 -> 2:
  NetworkManager-sstp-gnome: ∅ → 1.3.0, +1061.6 KiB
  NetworkManager-sstp-gnome-unstable: 2020-04-20 → ∅, -973.8 KiB
  alsa-firmware: -10388.3 KiB
  aws-c-auth: 0.6.11 → 0.6.13, -23.6 KiB
  aws-c-cal: 0.5.14 → 0.5.17
  aws-c-common: 0.6.19 → 0.7.0, +53.8 KiB
  aws-c-http: 0.6.10 → 0.6.15, +39.8 KiB
  aws-c-io: 0.10.19 → 0.11.0
  aws-c-s3: 0.1.33 → 0.1.39, -22.8 KiB
  aws-crt-cpp: 0.17.16 → 0.17.28, +14.2 KiB
  aws-sdk-cpp: +11.7 KiB
  bash-language-server: +166.7 KiB
  bat: 0.20.0 → 0.21.0, +233.0 KiB
  blueman: +384.4 KiB
  btrfs-progs: 5.16.2 → 5.17, +40.1 KiB
  bubblewrap: 0.6.1 → 0.6.2
  cachix: +8.6 KiB
  clang: -97.2 KiB
  cmake: +27.4 KiB
  cmake-cursesUI: +36.5 KiB
  cpupower: 5.17.5 → 5.17.7
  curl: 7.82.0 → 7.83.0, +10.4 KiB
  expat: 2.4.7 → 2.4.8
  extra: ∅ → ε, +21836.8 KiB
  ffmpeg: -16.0 KiB
  firefox: -16.1 KiB
  firefox-unwrapped: +5605.3 KiB
  game-music-emu: -10.6 KiB
  gcc: 11.2.0 → 11.3.0, +112.8 KiB
  gcc-wrapper: 11.2.0 → 11.3.0
  gcr: +38.8 KiB
  gfortran: 11.2.0 → 11.3.0
  gh: 2.9.0 → 2.10.1, +42.0 KiB
  ghostscript-with-X: 9.55.0 → 9.56.1, +3009.9 KiB
  git: +34.5 KiB
  icu4c: 70.1 → 71.1, +1940.4 KiB
  ijs: 9.55.0 → 9.56.1
  imlib2: 1.7.5 → 1.8.1, +82.5 KiB
  initrd: ∅ → ε
  initrd-linux: 5.17.5 → 5.17.7
  intel2200BGFirmware: -351.3 KiB
  keymap: ∅ → ε
  libgit2: 1.4.0 → 1.4.3
  libheif: ∅ → 1.12.0, +1602.2 KiB
  libnotify: 0.7.9 → 0.7.11
  libopenmpt: 0.6.2 → 0.6.3
  libpulseaudio: +133.5 KiB
  libreelec-dvb-firmware: -2979.2 KiB
  librsvg: 2.54.0 → 2.54.1, +196.7 KiB
  libsndfile: 1.0.31 → 1.1.0
  libvlc: +8.0 KiB
  libxml2: 2.9.13 → 2.9.14
  lightdm-gtk-greeter: +13.2 KiB
  linux: 5.17.5, 5.17.5-modules → 5.17.7, 5.17.7-modules, -63.5 KiB
  linux-firmware: 20220310 → 20220509, -499058.2 KiB
  lldb: -235.9 KiB
  llvm: -61.5 KiB
  mdadm.conf: ∅ → ε
  nano: 6.2 → 6.3, +100.6 KiB
  neovim-unwrapped: -65.0 KiB
  network-manager-applet: +18.4 KiB
  nix: +21.9 KiB
  nixos: +48.2 KiB
  nixos-manual: +136.7 KiB
  nixos-system-pride: 22.05.20220505.c777cdf → 22.05.20220513.fb222e0
  nvidia-settings: +35.3 KiB
  nvidia-x11: 510.68.02-5.17.5 → 510.68.02-5.17.7, +9.8 KiB
  obs-studio: -8.2 KiB
  openal-soft: -8.1 KiB
  opencv: +49.3 KiB
  openexr: -8.2 KiB
  openssl: 1.1.1n → 1.1.1o
  pipewire: 0.3.49 → 0.3.51, +34.0 KiB
  poppler-glib: 22.03.0 → 22.04.0, +28.7 KiB
  poppler-utils: 22.03.0 → 22.04.0, +29.4 KiB
  protobuf: 3.19.3 → 3.19.4, -50.9 KiB
  pulseaudio: +115.7 KiB
  pyright: 1.1.243 → 1.1.246, +81.6 KiB
  qpdf: +13.0 KiB
  qttools: +8.4 KiB
  rav1e: ∅ → 0.5.1, +189177.7 KiB
  rofi: +71.8 KiB
  rt5677: ε → ∅, -705.9 KiB
  rt5677-firmware: ∅ → ε, +169.9 KiB
  rtl8192su-unstable: -418.9 KiB
  rtl8723bs-firmware: 2017-04-06 → ∅, -58.1 KiB
  rtl8761b: ε → ∅, -26.3 KiB
  rtw88-firmware-unstable: -444.4 KiB
  rust-analyzer-nightly: 81b3e6d → 06448c5, +211.1 KiB
  s2n-tls: 1.3.6 → 1.3.12, +10.1 KiB
  shfmt: 3.4.3 → 3.5.0
  sndio: ∅ → 1.8.1, +328.5 KiB
  sof-firmware: -10808.3 KiB
  source: -1066.5 KiB
  sqlite: 3.38.2 → 3.38.3
  stage: ∅ → 1-init.sh, +19.5 KiB
  steam: +87.1 KiB
  steam-run: +87.1 KiB
  svt-av1: 0.9.1 → 1.0.0
  tracker: +47.2 KiB
  tree-sitter-nix-grammar: +8.0 KiB
  tree-sitter-vim-grammar: +60.1 KiB
  tree-sitter-viml: 5268e0e → 4b9d2dd, +187.7 KiB
  typescript-language-server: 0.9.7 → 0.10.0, +917.4 KiB
  udev: +35.4 KiB
  vim: 8.2.4609 → 8.2.4816, +69.8 KiB
  wireless-regdb: -11.2 KiB
  xfsprogs: 5.15.0 → 5.16.0, +41.1 KiB
  zd1211-firmware: -337.2 KiB
  zenity: +13.3 KiB
  zimg: 3.0.3 → 3.0.4
Security vulnerability report
39 derivations with active advisories
42 derivations left out due to whitelisting

------------------------------------------------------------------------
SDL_ttf-2.0.11

/nix/store/x9z3xqr8rry59c0sg2xpxprdmd0rgawz-SDL_ttf-2.0.11.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-27470    7.8

------------------------------------------------------------------------
ShellCheck-0.8.0

/nix/store/p7xd0lmy4ah3rrhczb04xr4qly80kn9g-ShellCheck-0.8.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-28794    9.8

------------------------------------------------------------------------
anymap-0.12.1

/nix/store/grm97rckj9572yvpanz72jmzn7b739xw-anymap-0.12.1.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-38187    9.8

------------------------------------------------------------------------
async-2.2.4

/nix/store/fyz9zf01m9vg66ha77j45d1zraa169qh-async-2.2.4.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-43138    7.8

------------------------------------------------------------------------
async-2.2.4-r1.cabal

/nix/store/fvj0jp3bqy83xlwpn3njp7ym5g39x4hc-async-2.2.4-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-43138    7.8

------------------------------------------------------------------------
cereal-0.5.8.2

/nix/store/9j58ijsr48q8wl4lk25w8yqhn3zxsxvy-cereal-0.5.8.2.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-11105    9.8
https://nvd.nist.gov/vuln/detail/CVE-2020-11104    5.3

------------------------------------------------------------------------
charset-0.3.9

/nix/store/mr8w7rvkjp954dijrssgn89299kj6vby-charset-0.3.9.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2017-16098    7.5

------------------------------------------------------------------------
commonmark-0.2.2

/nix/store/qpngiglpnzb1a8aicqmxabbrd1brfpl8-commonmark-0.2.2.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2019-10010    6.1

------------------------------------------------------------------------
dot-0.1.4

/nix/store/bz837f84kg1swniiikybbkgdqbjpwcd1-dot-0.1.4.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-7639     5.3

------------------------------------------------------------------------
exfat-1.3.0

/nix/store/96cgdgd0j2gwpdz629z2mcdjz1aahmc7-exfat-1.3.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-29973    4.7

------------------------------------------------------------------------
fuse-2.9.9-closefrom-glibc-2-34.patch?id=8a970396fca7aca2d5a761b8e7a8242f1eef14c9

/nix/store/43fvswxdakdcjrknc9phd1yayb0c8bir-fuse-2.9.9-closefrom-glibc-2-34.patch?id=8a970396fca7aca2d5a761b8e7a8242f1eef14c9.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2019-14860    6.5
https://nvd.nist.gov/vuln/detail/CVE-2019-14900    6.5

------------------------------------------------------------------------
gcc-6.5.0

/nix/store/qwk3qfqccxvaxxidmrmmv1mrrhzcagpg-gcc-6.5.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-37322    7.8

------------------------------------------------------------------------
gcc-7.5.0

/nix/store/lnhgdng0prcagj4hyzyq9vfp964rmzbi-gcc-7.5.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-12886    8.1
https://nvd.nist.gov/vuln/detail/CVE-2021-37322    7.8

------------------------------------------------------------------------
go-1.16-linux-amd64-bootstrap

/nix/store/s5wliwnshsc7c6akd0phx44p7fmlf001-go-1.16-linux-amd64-bootstrap.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-38297    9.8
https://nvd.nist.gov/vuln/detail/CVE-2022-23806    9.1
https://nvd.nist.gov/vuln/detail/CVE-2021-39293    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-41771    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-41772    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-44716    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-23772    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-23773    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-24675    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-24921    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-28327    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-34558    6.5
https://nvd.nist.gov/vuln/detail/CVE-2021-44717    4.8

------------------------------------------------------------------------
home-0.5.3

/nix/store/vy4amkb5jx2g3c7dpbfjrlfj5425ifw8-home-0.5.3.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-25264    6.7

------------------------------------------------------------------------
http-client-0.7.11

/nix/store/9iwcbmihrhqsdgqx450a54868vn7vp89-http-client-0.7.11.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-11021    7.5

------------------------------------------------------------------------
http-client-0.7.11-r1.cabal

/nix/store/bhy90gcvsaxkwr5yf5bkj33m09z21w3b-http-client-0.7.11-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-11021    7.5

------------------------------------------------------------------------
instant-0.1.12

/nix/store/nj6ksv74g52v3xwc8qlv3jsdmxf5m75i-instant-0.1.12.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2017-13099    5.9

------------------------------------------------------------------------
jose-0.9

/nix/store/j8dwnrn7rpqssi533ynhjli8zmc7in83-jose-0.9.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-29444    5.9
https://nvd.nist.gov/vuln/detail/CVE-2021-29445    5.9
https://nvd.nist.gov/vuln/detail/CVE-2021-29446    5.9

------------------------------------------------------------------------
lens-5.0.1

/nix/store/p85palv493r01sqdggljcc1aqq1n5c4w-lens-5.0.1.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-44458    9.6
https://nvd.nist.gov/vuln/detail/CVE-2021-23154    7.8

------------------------------------------------------------------------
lens-5.0.1-r3.cabal

/nix/store/yh2is7x1mfaaa69pra8x5k2pxa7i6wjh-lens-5.0.1-r3.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-44458    9.6
https://nvd.nist.gov/vuln/detail/CVE-2021-23154    7.8

------------------------------------------------------------------------
lua-2.1.0

/nix/store/z99dgpvnx257ihq351p0aib49nl32blq-lua-2.1.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-28805    9.1
https://nvd.nist.gov/vuln/detail/CVE-2020-15888    8.8
https://nvd.nist.gov/vuln/detail/CVE-2020-15945    5.5

------------------------------------------------------------------------
lua-5.2.4-env

/nix/store/2x7h2mc4nva89w002mk0lcg1rpy8ridz-lua-5.2.4-env.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-28805    9.1
https://nvd.nist.gov/vuln/detail/CVE-2020-15888    8.8
https://nvd.nist.gov/vuln/detail/CVE-2020-15945    5.5
https://nvd.nist.gov/vuln/detail/CVE-2021-43519    5.5

------------------------------------------------------------------------
markdown-0.33-1.rockspec

/nix/store/rzg1q9zdixvhqgv59p9mhsbf9wv63wmj-markdown-0.33-1.rockspec.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-1000874  6.1

------------------------------------------------------------------------
network-3.1.2.7

/nix/store/60ihlfc3hbvn1wgbrf40sfwfk69lggh3-network-3.1.2.7.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-35048    9.8
https://nvd.nist.gov/vuln/detail/CVE-2021-35047    8.8
https://nvd.nist.gov/vuln/detail/CVE-2021-35049    8.8
https://nvd.nist.gov/vuln/detail/CVE-2021-35050    7.5

------------------------------------------------------------------------
openldap-2.4.58

/nix/store/pxmniwzb69m1689mfil2457yj8s6wy6g-openldap-2.4.58.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-29155    9.8

------------------------------------------------------------------------
openssl-0.10.30

/nix/store/pb1nx6amhqg9i5x3hvafgh5km51hrgsa-openssl-0.10.30.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-16395    9.8
https://nvd.nist.gov/vuln/detail/CVE-2021-4044     7.5

------------------------------------------------------------------------
quote-1.0.7

/nix/store/1v07kcr389v9dkp66m5w5z9vhswhl1c9-quote-1.0.7.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-16194    5.3

------------------------------------------------------------------------
quote-1.0.18

/nix/store/5vyv1pirqiv1x448h2c31s5fn7x8c57w-quote-1.0.18.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2020-16194    5.3

------------------------------------------------------------------------
regex-1.4.5

/nix/store/mbm7wl9bsfa05qd3q9xz7dja2h5i2fq1-regex-1.4.5.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2022-24713    7.5

------------------------------------------------------------------------
safe-0.3.19

/nix/store/0v8qfqfh3ksb4ihdpzw3rrrghrldrfsy-safe-0.3.19.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2019-11644    7.8
https://nvd.nist.gov/vuln/detail/CVE-2021-44751    5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-40834    4.3
https://nvd.nist.gov/vuln/detail/CVE-2021-40835    4.3
https://nvd.nist.gov/vuln/detail/CVE-2022-28868    4.3
https://nvd.nist.gov/vuln/detail/CVE-2022-28869    4.3
https://nvd.nist.gov/vuln/detail/CVE-2022-28870    4.3
https://nvd.nist.gov/vuln/detail/CVE-2021-33596    4.1
https://nvd.nist.gov/vuln/detail/CVE-2021-33594    3.5
https://nvd.nist.gov/vuln/detail/CVE-2021-33595    3.5

------------------------------------------------------------------------
systemd-2.3.0

/nix/store/1qhwqjbhnv5v9lp98nkvjbl9b6anh1wy-systemd-2.3.0.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2017-1000082  9.8
https://nvd.nist.gov/vuln/detail/CVE-2018-15688    8.8
https://nvd.nist.gov/vuln/detail/CVE-2017-18078    7.8
https://nvd.nist.gov/vuln/detail/CVE-2018-6954     7.8
https://nvd.nist.gov/vuln/detail/CVE-2018-15686    7.8
https://nvd.nist.gov/vuln/detail/CVE-2018-16864    7.8
https://nvd.nist.gov/vuln/detail/CVE-2018-16865    7.8
https://nvd.nist.gov/vuln/detail/CVE-2019-3843     7.8
https://nvd.nist.gov/vuln/detail/CVE-2019-3844     7.8
https://nvd.nist.gov/vuln/detail/CVE-2020-1712     7.8
https://nvd.nist.gov/vuln/detail/CVE-2017-9217     7.5
https://nvd.nist.gov/vuln/detail/CVE-2018-15687    7.0
https://nvd.nist.gov/vuln/detail/CVE-2019-3842     7.0
https://nvd.nist.gov/vuln/detail/CVE-2020-13776    6.7
https://nvd.nist.gov/vuln/detail/CVE-2018-1049     5.9
https://nvd.nist.gov/vuln/detail/CVE-2021-33910    5.5
https://nvd.nist.gov/vuln/detail/CVE-2018-16888    4.7
https://nvd.nist.gov/vuln/detail/CVE-2019-20386    2.4

------------------------------------------------------------------------
vault-0.3.1.5

/nix/store/v5nq5ip88p8a756p6aig7jxppr975x79-vault-0.3.1.5.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-19786    8.1
https://nvd.nist.gov/vuln/detail/CVE-2020-13223    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-27400    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-41802    5.4
https://nvd.nist.gov/vuln/detail/CVE-2020-25594    5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-3024     5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-38554    5.3

------------------------------------------------------------------------
vault-0.3.1.5-r1.cabal

/nix/store/9gszsfsb0hm1sz20gv16iv65kng0xrwh-vault-0.3.1.5-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-19786    8.1
https://nvd.nist.gov/vuln/detail/CVE-2020-13223    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-27400    7.5
https://nvd.nist.gov/vuln/detail/CVE-2021-41802    5.4
https://nvd.nist.gov/vuln/detail/CVE-2020-25594    5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-3024     5.3
https://nvd.nist.gov/vuln/detail/CVE-2021-38554    5.3

------------------------------------------------------------------------
websockets-0.12.7.3

/nix/store/yl5jcrzymcws92k5dm4q70s5vmckijhd-websockets-0.12.7.3.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-33880    5.9

------------------------------------------------------------------------
websockets-0.12.7.3-r1.cabal

/nix/store/hmjdb5rympax1ryd8fyssamzfia1svf9-websockets-0.12.7.3-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-33880    5.9

------------------------------------------------------------------------
xshell-0.2.1

/nix/store/ms4ik6w7g7dncicha5ivsbq4xans34p8-xshell-0.2.1.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2021-42095    7.5
https://nvd.nist.gov/vuln/detail/CVE-2022-27966    6.5

------------------------------------------------------------------------
zlib-0.6.2.3

/nix/store/3fz3f1a8kv5jmj1awvmadrb4vn49wkpn-zlib-0.6.2.3.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-25032    7.5

------------------------------------------------------------------------
zlib-0.6.2.3-r1.cabal

/nix/store/wp6f9fldqwygrs0wc4ipd1ib1mvwwjwh-zlib-0.6.2.3-r1.cabal.drv
CVE                                                CVSSv3
https://nvd.nist.gov/vuln/detail/CVE-2018-25032    7.5

use --show-whitelisted to see derivations with only whitelisted CVEs