[oe-commits] [meta-openembedded] 18/19: mercurial-native: upgrade to 3.8.4

git at git.openembedded.org git at git.openembedded.org
Fri Jul 29 09:18:49 UTC 2016


martin_jansa pushed a commit to branch master-next
in repository meta-openembedded.

commit ea84b1b108c3cca971477eb40e0a23a92727c27c
Author: Jackie Huang <jackie.huang at windriver.com>
AuthorDate: Thu Jul 28 01:24:47 2016 -0400

    mercurial-native: upgrade to 3.8.4
    
    * Upgrade to the latest release to fix some CVEs:
      - CVE-2016-3068: arbitrary code execution with Git subrepos
      - CVE-2016-3069: arbitrary code execution when converting Git repos
      - CVE-2016-3630: remote code execution in binary delta decoding
      - CVE-2016-3105: arbitrary code execution when converting Git repos
    
    * For other changes please see:
      https://www.mercurial-scm.org/wiki/WhatsNew
    
    * Update SRC_URI with the new download link
    
    Signed-off-by: Jackie Huang <jackie.huang at windriver.com>
    Signed-off-by: Martin Jansa <Martin.Jansa at gmail.com>
---
 .../{mercurial-native_3.4.1.bb => mercurial-native_3.8.4.bb}        | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/meta-oe/recipes-devtools/mercurial/mercurial-native_3.4.1.bb b/meta-oe/recipes-devtools/mercurial/mercurial-native_3.8.4.bb
similarity index 73%
rename from meta-oe/recipes-devtools/mercurial/mercurial-native_3.4.1.bb
rename to meta-oe/recipes-devtools/mercurial/mercurial-native_3.8.4.bb
index aeec195..0526fc2 100644
--- a/meta-oe/recipes-devtools/mercurial/mercurial-native_3.4.1.bb
+++ b/meta-oe/recipes-devtools/mercurial/mercurial-native_3.8.4.bb
@@ -5,9 +5,9 @@ LICENSE = "GPLv2"
 LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
 DEPENDS = "python-native"
 
-SRC_URI = "http://mercurial.selenic.com/release/mercurial-${PV}.tar.gz"
-SRC_URI[md5sum] = "65783a60aefb46a11296b587e9403537"
-SRC_URI[sha256sum] = "7a8acf7329beda38ceea29c689212574d9a6bfffe24cf565015ea0066f7cee3f"
+SRC_URI = "https://www.mercurial-scm.org/release/${BP}.tar.gz"
+SRC_URI[md5sum] = "cec2c3db688cb87142809089c6ae13e9"
+SRC_URI[sha256sum] = "4b2e3ef19d34fa1d781cb7425506a05d4b6b1172bab69d6ea78874175fdf3da6"
 
 S = "${WORKDIR}/mercurial-${PV}"
 

-- 
To stop receiving notification emails like this one, please contact
the administrator of this repository.


More information about the Openembedded-commits mailing list