Unverified Commit 731cc710 authored by Robert Schütz's avatar Robert Schütz Committed by GitHub
Browse files

Merge pull request #203477 from dotlambda/CVE-2022-42966

[22.11] python310Packages.cleo: fix CVE-2022-42966
parents f4660951 19bc1f31
Loading
Loading
Loading
Loading
+10 −0
Original line number Diff line number Diff line
{ lib
, buildPythonPackage
, fetchFromGitHub
, fetchpatch
, crashtest
, poetry-core
, pylev
@@ -20,6 +21,15 @@ buildPythonPackage rec {
    hash = "sha256-FtGGIRF/tA2OWEjkCFwa1HHg6VY+5E5mAiJC/zjUC1g=";
  };

  patches = [
    (fetchpatch {
      name = "CVE-2022-42966.patch";
      url = "https://github.com/python-poetry/cleo/commit/b5b9a04d2caf58bf7cf94eb7ae4a1ebbe60ea455.patch";
      relative = "src";
      hash = "sha256-nMmRipgQC/w4GIV+VHgKx1xmPm4j+4tR980sROmbfnM=";
    })
  ];

  postPatch = ''
    substituteInPlace pyproject.toml \
      --replace 'crashtest = "^0.3.1"' 'crashtest = "*"'