[24.05] vaultwarden: 1.30.5 -> 1.31.0 -> 1.32.0#334099
[24.05] vaultwarden: 1.30.5 -> 1.31.0 -> 1.32.0#334099dotlambda merged 5 commits intoNixOS:release-24.05from
Conversation
|
We don't want to backport the webvault bumps? |
|
yeah, we do. I am currently trying to get a newer rust |
6ee4b0f to
45a7ba4
Compare
|
I didn't realize we need a newer Rust. In that case we might just want to apply the security fixes as patches. Also, please use |
45a7ba4 to
8efa3fd
Compare
As already mentioned, I am not going to invest any time into such activities.
To late now. Also the information in there would be incorrect anyway, since I cherry-picked from my forked branches. @ofborg build vaultwarden |
|
This pull request has been mentioned on NixOS Discourse. There might be relevant details there: https://discourse.nixos.org/t/several-information-leaks-in-vaultwarden-1-32-0/50500/1 |
Just cherry-pick from master instead. If you want, I can open my own PR. |
8efa3fd to
8b3db81
Compare
yeah, whatever. Just did it. |
|
Thank you! |
|
@ofborg test vaultwarden |
|
Does it make sense to add release note entries at this point? |
I doubt it. |
|
I am going ahead and will be merging this because of the security situation. I personally don't have the time or knowledge to properly backport the patches and no one spoke up in the last day, so I don't see a quick alternative. |
|
The only reason I hadn't merged yet was to give people a chance to look at the Rust stuff. But they can complain later if they don't like it. |
|
Just for reference: I based it on #298206 so I hope it is fine 😅 |
Description of changes
https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0
1.31.0 contains breaking changes https://github.com/dani-garcia/vaultwarden/releases/tag/1.31.0 . I am not going to attempt to backport any changes because of the size of the patches.
Things done
nix.conf? (See Nix manual)sandbox = relaxedsandbox = truenix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD". Note: all changes have to be committed, also see nixpkgs-review usage./result/bin/)Add a 👍 reaction to pull requests you find important.