[release-25.11] nodePackages.prebuild-install: mark as potentially vulnerable#470915
Merged
tomodachi94 merged 1 commit intoNixOS:release-25.11from Dec 15, 2025
Merged
[release-25.11] nodePackages.prebuild-install: mark as potentially vulnerable#470915tomodachi94 merged 1 commit intoNixOS:release-25.11from
tomodachi94 merged 1 commit intoNixOS:release-25.11from
Conversation
Contributor
There was a problem hiding this comment.
This report is automatically generated by the PR / Check / cherry-pick CI workflow.
Some of the commits in this PR require the author's and reviewer's attention.
If you need to merge this PR despite the warnings, please dismiss this review shortly before merging.
Important
79933db is not a cherry-pick, because: Package was dropped on master (#470892). Please review this commit manually.
Hint: The full diffs are also available in the runner logs with slightly better highlighting.
This package might be vulnerable to CVE-2025-59343 due to its dependency on an old version of tar-fs. I don't know if this CVE can be exploited with prebuild-install, but better safe than sorry here. Not-cherry-picked-because: Package was dropped on master (NixOS#470892)
75afb60 to
79933db
Compare
unneeded, package is dropped on master but is kept for back-compat on 25.11
Merged
via the queue into
NixOS:release-25.11
with commit Dec 15, 2025
7be9787
33 of 36 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dropped in #470892. This package might be vulnerable to CVE-2025-59343 due to its dependency on an old version of tar-fs. I don't know if this CVE can be exploited with prebuild-install, but better safe than sorry here.
Things done
passthru.tests.nixpkgs-reviewon this PR. See nixpkgs-review usage../result/bin/.Add a 👍 reaction to pull requests you find important.