<hexa->
is there a consenus on what to do about old packages that patches fixing security vulns, that are not recognizable as such by tools like broken.sh?
<hexa->
e.g. pkgs/applications/office/antiword/10_fix_buffer_overflow_wordole_c.patch
<flokli>
I don't understand the question
<hexa->
should 10_fix_buffer_overflow_wordole_c.patch be renamed to CVE-2014-8123.patch so broken.sh can pick that up?
<hexa->
or what does broken.sh use to look up fixes?
<flokli>
it usually uses the patch name. if we fetch it via fetchurl, this works, if it's a nonrecognizable patch shipped in nixpkgs, renaming might help.
<hexa->
antiword is shown as being vulnerable although it was ptched
KeiraT has quit [Ping timeout: 240 seconds]
KeiraT has joined #nixos-security
justanotheruser has quit [Ping timeout: 264 seconds]