nixpkgs/pkgs/applications
Maximilian Bosch e2a15cd395
rambox: unmaintain & mark as insecure
Rambox hasn't had a stable release in a while and an increasing number
of issues which is why I don't intend to use this anymore.

While taking a closer look at the source I also realized that it uses
Electron 7.2.4[1]. This is not only EOLed[2], it also contains a few
security vulnerabilities which is why I decided to mark it as insecure.

A few (most likely not all) vulnerabilities can be found by looking at
the Electron 7 changelog[3]: after 7.2.4 there were a few more releases
with security backports - mostly from Chromium. Security issues that
were found later on (and are probably exploitable on the dependency
chain of rambox) aren't listed here. I only added two issues that seemed
applicable to `rambox`, but I haven't researched enough to check the
other ones.

[1] https://github.com/ramboxapp/community-edition/blob/0.7.7/package.json#L70
[2] https://www.electronjs.org/docs/tutorial/support#currently-supported-versions
[3] https://www.electronjs.org/releases/stable?version=7
2021-06-05 13:13:42 +02:00
..
accessibility squeekboard: unstable-2021-03-09 -> 1.13.0 (#121614) 2021-05-18 11:00:08 +02:00
audio plexamp: 3.4.6 -> 3.4.7 2021-06-04 09:19:11 +00:00
backup pika-backup: 0.3.1 -> 0.3.2 2021-05-29 12:52:07 +02:00
blockchains treewide: setuptools_scm -> setuptools-scm 2021-06-03 12:44:33 +02:00
display-managers Merge #121780: treewide meta.maintainers tweaks 2021-05-08 10:47:08 +02:00
editors micro: 2.0.8 → 2.0.9 2021-06-04 02:22:53 +03:00
gis qmapshack: 1.15.2 -> 1.16.0 2021-05-27 09:35:57 +02:00
graphics nufraw: fix build 2021-06-04 08:26:06 +02:00
kde kio-gdrive: init 20.12.3 2021-05-31 12:19:41 +08:00
logging/humioctl
misc Merge pull request #125500 from etu/php-spring-release-cleaning 2021-06-04 17:48:47 +02:00
networking rambox: unmaintain & mark as insecure 2021-06-05 13:13:42 +02:00
office onlyoffice-bin: 6.1.0 -> 6.2.0 and fix runHook typo 2021-06-01 15:58:21 +08:00
printing/pappl
qubes/qubes-core-vchan-xen
radio Merge pull request #124893 from markuskowa/upd-welle-io 2021-05-30 03:49:04 +02:00
science geogebra6: 6-0-631-0 -> 6-0-644-0 2021-06-04 23:49:04 +10:00
search
system
terminal-emulators st: support cross-compilation (#123722) 2021-05-22 17:00:24 +02:00
version-management gh: 1.10.3 -> 1.11.0 2021-06-04 10:18:55 +10:00
video Merge pull request #121663 from vojta001/lwks 2021-06-04 17:19:48 +02:00
virtualization Merge pull request #125394 from fortuneteller2k/win-spice 2021-06-04 11:18:21 +02:00
window-managers Merge pull request #125417 from SebTM/update/i3lock-color_213c3 2021-06-03 17:38:52 +02:00