-
-
Notifications
You must be signed in to change notification settings - Fork 14.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[24.05] vaultwarden: 1.30.5 -> 1.31.0 -> 1.32.0 #334099
[24.05] vaultwarden: 1.30.5 -> 1.31.0 -> 1.32.0 #334099
Conversation
We don't want to backport the webvault bumps? |
yeah, we do. I am currently trying to get a newer rust |
6ee4b0f
to
45a7ba4
Compare
I didn't realize we need a newer Rust. In that case we might just want to apply the security fixes as patches. Also, please use |
45a7ba4
to
8efa3fd
Compare
As already mentioned, I am not going to invest any time into such activities.
To late now. Also the information in there would be incorrect anyway, since I cherry-picked from my forked branches. @ofborg build vaultwarden |
This pull request has been mentioned on NixOS Discourse. There might be relevant details there: https://discourse.nixos.org/t/several-information-leaks-in-vaultwarden-1-32-0/50500/1 |
Just cherry-pick from master instead. If you want, I can open my own PR. |
8efa3fd
to
8b3db81
Compare
yeah, whatever. Just did it. |
Thank you! |
@ofborg test vaultwarden |
Does it make sense to add release note entries at this point? |
I doubt it. |
I am going ahead and will be merging this because of the security situation. I personally don't have the time or knowledge to properly backport the patches and no one spoke up in the last day, so I don't see a quick alternative. |
The only reason I hadn't merged yet was to give people a chance to look at the Rust stuff. But they can complain later if they don't like it. |
Just for reference: I based it on #298206 so I hope it is fine 😅 |
Description of changes
https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0
1.31.0 contains breaking changes https://github.com/dani-garcia/vaultwarden/releases/tag/1.31.0 . I am not going to attempt to backport any changes because of the size of the patches.
Things done
nix.conf
? (See Nix manual)sandbox = relaxed
sandbox = true
nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"
. Note: all changes have to be committed, also see nixpkgs-review usage./result/bin/
)Add a 👍 reaction to pull requests you find important.