From 759b55712e62e913f5ab650651108649775cead2 Mon Sep 17 00:00:00 2001 From: Liliana Marie Prikler Date: Thu, 5 Oct 2023 08:11:34 +0200 Subject: [PATCH] gnu: curl: Update to 8.3.0. According to upstream, the current version has 19 security issues. See also . * gnu/packages/curl.scm (curl/fixed): New variable. (curl): Use it as replacement. --- gnu/packages/curl.scm | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/gnu/packages/curl.scm b/gnu/packages/curl.scm index 4e3c563570..cadf1ca361 100644 --- a/gnu/packages/curl.scm +++ b/gnu/packages/curl.scm @@ -65,6 +65,7 @@ (define-public curl (package (name "curl") (version "7.85.0") + (replacement curl/fixed) (source (origin (method url-fetch) (uri (string-append "https://curl.se/download/curl-" @@ -154,6 +155,20 @@ (define-public curl "See COPYING in the distribution.")) (home-page "https://curl.haxx.se/"))) +(define curl/fixed + (let ((%version "8.3.0")) + (package + (inherit curl) + (version "8.3.0a") ; add lowercase 'a' for grafting + (source (origin + (method url-fetch) + (uri (string-append "https://curl.se/download/curl-" + %version ".tar.xz")) + (sha256 + (base32 + "0qza6yf20y2l4aaxkn8dfw8p3fls1mxljvdb0m8z1i6ncxvn4v9p")) + (patches (search-patches "curl-use-ssl-cert-env.patch"))))))) + (define-public curl-ssh (package/inherit curl (arguments