20bf02ce18
Drop patch because the linker error no longer appears on br-x86-64-musl. v0.13.0 fixes the following CVEs: CVE-2019-0205: In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings. CVE-2019-0210: In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data. Also update the hash file to the new two-spaces convention Signed-off-by: Titouan Christophe <titouan.christophe@railnova.eu> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 lines
290 B
Plaintext
5 lines
290 B
Plaintext
# From https://www.apache.org/dist/thrift/0.13.0/thrift-0.13.0.tar.gz.sha256
|
|
sha256 7ad348b88033af46ce49148097afe354d513c1fca7c607b59c33ebb6064b5179 thrift-0.13.0.tar.gz
|
|
# License files, locally calculated
|
|
sha256 23df881cec3192d1f4474633c14eb2ec30a45b84f8daeb82b9de5d2bd3ac8218 LICENSE
|