summary refs log tree commit diff
diff options
context:
space:
mode:
authorLéo Le Bouter <lle-bout@zaclys.net>2021-03-23 15:38:40 +0100
committerJulien Lepiller <julien@lepiller.eu>2021-03-23 23:29:14 +0100
commit8b2b5463963d5d4dee480b0cf73fa4a9eca414ba (patch)
tree75fd983509163219f461e10e51b2e43c7227c9a9
parent08b9e0ca0be309a732f0784ceee7e436bfd70f15 (diff)
downloadguix-8b2b5463963d5d4dee480b0cf73fa4a9eca414ba.tar.gz
gnu: java-xstream: Update to 1.4.16 [security fixes].
Fixes CVE-2021-21341, CVE-2021-21342, CVE-2021-21343, CVE-2021-21344,
CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21348,
CVE-2021-21349, CVE-2021-21350 and CVE-2021-21351.

* gnu/packages/xml.scm (java-xstream): Update to 1.4.16.
[inputs]: Add java-mxparser, a fork of java-xpp3 made by upstream.
Java-xpp3 is still needed.

Signed-off-by: Julien Lepiller <julien@lepiller.eu>
-rw-r--r--gnu/packages/xml.scm5
1 files changed, 3 insertions, 2 deletions
diff --git a/gnu/packages/xml.scm b/gnu/packages/xml.scm
index 808a847eaf..d05d326f5b 100644
--- a/gnu/packages/xml.scm
+++ b/gnu/packages/xml.scm
@@ -2272,7 +2272,7 @@ outputting XML data from Java code.")
 (define-public java-xstream
   (package
     (name "java-xstream")
-    (version "1.4.15")
+    (version "1.4.16")
     (source
      (origin
        (method git-fetch)
@@ -2284,7 +2284,7 @@ outputting XML data from Java code.")
                                   version)))))
        (file-name (git-file-name name version))
        (sha256
-        (base32 "1178qryrjwjp44439pi5dxzd32896r5zs429z1qhlc09951r7mi9"))))
+        (base32 "16k2mc63h2fw7lxv74qmhg4p8q9hfrw114daa6nxwnpv08cnq755"))))
     (build-system ant-build-system)
     (arguments
      `(#:jar-name "xstream.jar"
@@ -2299,6 +2299,7 @@ outputting XML data from Java code.")
        ("java-joda-time" ,java-joda-time)
        ("java-jettison" ,java-jettison)
        ("java-xom" ,java-xom)
+       ("java-mxparser" ,java-mxparser)
        ("java-xpp3" ,java-xpp3)
        ("java-dom4j" ,java-dom4j)
        ("java-stax2-api" ,java-stax2-api)