conda-forge / libarchive-feedstock

A conda-smithy repository for libarchive.
BSD 3-Clause "New" or "Revised" License
2 stars 26 forks source link

Backport libarchive#2101 #85

Closed jjerphan closed 2 months ago

jjerphan commented 3 months ago

Checklist

Preventively backport https://github.com/libarchive/libarchive/pull/2101 to revert changes of https://github.com/libarchive/libarchive/pull/1609 which might be related to the xz Backdoor (i.e. CVE-2024-3094).

Fix https://github.com/conda-forge/libarchive-feedstock/issues/84.

conda-forge-webservices[bot] commented 3 months ago

Hi! This is the friendly automated conda-forge-linting service.

I just wanted to let you know that I linted all conda-recipes in your PR (recipe) and found it was in an excellent condition.

jjerphan commented 3 months ago

@conda-forge-admin, please rerender

jjerphan commented 3 months ago

FYI, several distributions have back ported this change or revert the original PR, including:

beckermr commented 3 months ago

It appears all commits were re-reviewed and only the patch above has been applied?

https://github.com/libarchive/libarchive/issues/2103

beckermr commented 3 months ago

There was an associated bugfix in the same code areas but not specifically touched: https://github.com/libarchive/libarchive/pull/2104/files

beckermr commented 3 months ago

What do you think @conda-forge/core? Should we wait for the next release or go ahead with this patch and the one from https://github.com/libarchive/libarchive/pull/2104?

Maybe if the libarchive maintainers thought there was something to patch, they would have pushed a bugfix release?

isuruf commented 3 months ago

Please keep the discussion in #84.