5 Commits

Author SHA1 Message Date
Natanael Copa
edfe8b82ee community/soundtouch: security upgrade to 2.1.2
CVE-2018-17096 soundtouch: Assertion failure in BPMDetect class in
BPMDetect.cpp
CVE-2018-17097 soundtouch: Double free in WavFileBase class in
WavFile.cpp
CVE-2018-17098 soundtouch: Heap corruption in WavFileBase class in
WavFile.cpp

fixes #9881
2019-01-23 19:12:36 +00:00
Jakub Jirutka
63f5e7d295 [various]: unify names of licenses according to SPDX
This commit updates $license variable in all APKBUILDs to comply with
short names specified by SPDX version 3.0 [1] where possible. It was
done using find-and-replace method on substrings inside $license
variables.

Only license names were updated, not "expressions" specifying relation
between the licenses (e.g. "X and Y", "X or Y", "X and (Y or Z)") or
exceptions (e.g. "X with exceptions").

Many licenses have a version or multiple variants, e.g. MPL-2.0,
BSD-2-Clause, BSD-3-Clause. However, $license in many aports do not
contain license version or variant. Since there's no way how to infer
this information just from abuild, it were left without the variant
suffix or version, i.e. non SPDX compliant.

GNU licenses (AGPL, GFDL, GPL, LGPL) are especially complicated. They
exist in two variants: -only (formerly e.g. GPL-2.0) and -or-later
(formerly e.g. GPL-2.0+). We did not systematically noted distinguish
between these variants, so GPL-2.0, GPL2, GPLv2 etc. may mean
GPL-2.0-only or GPL-2.0-or-later. Thus GNU licenses without "+" (e.g.
GPL2+) were left without the variant suffix, i.e. non SPDX compliant.

Note: This commit just fixes format of the license names, no
verification has been done if the specified license information is
actually correct!

[1]: https://spdx.org/licenses/
2017-12-30 21:05:50 +01:00
Natanael Copa
a1e7c4015e community/soundtouch: upgrade to 2.0.0 2017-10-31 10:42:42 +00:00
Sören Tempel
73233acb7a community/soundtouch: fix build, modernize APKBUILD 2017-05-02 23:31:35 +02:00
Natanael Copa
730eb4aa5d community/soundtouch: move from main
only needed by audacity
2015-11-25 13:51:31 +00:00