community/flatpak: security upgrade to 1.10.5

updated the secfixes version due to follow-up fixes provided by
upstream, also added one that is expected to land on 1.10.6
This commit is contained in:
Leo 2021-10-14 14:11:28 -03:00
parent bf57debcde
commit 45e85477ea

View File

@ -3,7 +3,7 @@
# Maintainer: André Klitzing <aklitzing@gmail.com>
pkgname=flatpak
# Follows GNOME versioning, MAJOR must be even
pkgver=1.10.4
pkgver=1.10.5
pkgrel=0
pkgdesc="Application deployment framework for desktop apps"
url="https://flatpak.org"
@ -24,14 +24,15 @@ subpackages="
"
install="flatpak.pre-install flatpak.pre-upgrade flatpak.post-install"
source="https://github.com/flatpak/flatpak/releases/download/$pkgver/flatpak-$pkgver.tar.xz
musl-fixes.patch
modules-load.conf
"
followup-fix-CVE-2021-41133.patch::https://github.com/flatpak/flatpak/commit/3fc8c672676ae016f8e7cc90481b2feecbad9861.patch
musl-fixes.patch
modules-load.conf
"
options="suid !check" # Tests fail with no error message
# secfixes:
# 1.10.4-r0:
# - GHSA-67h7-w3jq-vh4q
# 1.10.5-r0:
# - CVE-2021-41133
# 1.10.1-r0:
# - CVE-2021-21261
# 1.2.4-r0:
@ -69,7 +70,8 @@ package() {
}
sha512sums="
ece3f945f23585ceee47cc21ffad6217dade138da85bdb673ff74e6c57afcfc01da642a743220e763e31a7819f8e2552d520c2c8ee82f18ac6094de5e3c9085d flatpak-1.10.4.tar.xz
8c2e365ce442a092c15178a8b39daecf21bfe162078c9a323e68d53194413f174e329812dd01d8da6bbfba3b0087aeb4d92a44067df3f6fa0253e33014d138ae flatpak-1.10.5.tar.xz
04b96fc6ffb6b65cdc3a75f92cebb6c40f5ce9b9c0359b1d4c8d4cd915618d6ee45b9e90601ac7f23d50bb92674c2491aa48f868b040c7db97c8523fea13e511 followup-fix-CVE-2021-41133.patch
9287ed146bf71665aa436a2c2110cc5edc829a7b4a3e3190947580850fe9ecfd2bb6adb015c692af022d425fb5259390fcdcbd402e8b0d12ee5d2c1a1071ed4f musl-fixes.patch
57d23d2778556eafc3035e6be575bf95b4032f123b35f2b1657eff5e7496de253173edc657f90531ee58e25673f4f27a5cd1cc76b14a038edb244f104a231771 modules-load.conf
"