nixpkgs/pkgs
Maximilian Bosch e2a15cd395
rambox: unmaintain & mark as insecure
Rambox hasn't had a stable release in a while and an increasing number
of issues which is why I don't intend to use this anymore.

While taking a closer look at the source I also realized that it uses
Electron 7.2.4[1]. This is not only EOLed[2], it also contains a few
security vulnerabilities which is why I decided to mark it as insecure.

A few (most likely not all) vulnerabilities can be found by looking at
the Electron 7 changelog[3]: after 7.2.4 there were a few more releases
with security backports - mostly from Chromium. Security issues that
were found later on (and are probably exploitable on the dependency
chain of rambox) aren't listed here. I only added two issues that seemed
applicable to `rambox`, but I haven't researched enough to check the
other ones.

[1] https://github.com/ramboxapp/community-edition/blob/0.7.7/package.json#L70
[2] https://www.electronjs.org/docs/tutorial/support#currently-supported-versions
[3] https://www.electronjs.org/releases/stable?version=7
2021-06-05 13:13:42 +02:00
..
applications rambox: unmaintain & mark as insecure 2021-06-05 13:13:42 +02:00
build-support Merge pull request #125216 from hercules-ci/follow-up-115491 2021-06-02 16:58:49 +02:00
common-updater
data Merge pull request #124360 from frogamic/124352-quintom-cursor-theme 2021-06-04 11:15:23 +02:00
desktops gnome.gnome-initial-setup: 40.1 -> 40.2 2021-06-04 07:31:16 +00:00
development Merge pull request #125500 from etu/php-spring-release-cleaning 2021-06-04 17:48:47 +02:00
games osu-lazer: 2021.515.0 -> 2021.602.0 2021-06-04 20:01:22 +08:00
misc vimPlugins.vim-colorschemes: Fix source hash 2021-06-03 20:11:14 -07:00
os-specific nixos-rebuild --fast: Don't imply --show-trace 2021-06-03 19:01:09 +02:00
pkgs-lib
servers Merge pull request #125500 from etu/php-spring-release-cleaning 2021-06-04 17:48:47 +02:00
shells nushell: 0.31.0 -> 0.32.0 2021-06-03 16:46:11 +05:30
stdenv stdenv.darwin: nixpkgs-fmt 2021-06-02 19:03:48 +09:00
test
tools Merge pull request #125606 from Vonfry/update/opencc 2021-06-04 13:40:44 +02:00
top-level Merge pull request #125500 from etu/php-spring-release-cleaning 2021-06-04 17:48:47 +02:00