[22.05] Revert "python3Packages.mistune_0_8: mark knownVulnerabilities CVE-2022-34749" #188031
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This reverts commit db8c230 (#184209/#186149).
Description of changes
Per lepture/mistune#314 (comment), Mistune 0.8.4 is not vulnerable to CVE-2022-34749, only 2.0.x versions of Mistune before 2.0.3 are. (release-22.05 now contains mistune 0.8.4 and 2.0.4, neither of which are vulnerable.)
Things done
nixpkgs-review is running, but will take a while.
sandbox = true
set innix.conf
? (See Nix manual)nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"
. Note: all changes have to be committed, also see nixpkgs-review usage./result/bin/
)nixos/doc/manual/md-to-db.sh
to update generated release notes