xz: switch to a working src URL, add warning

This commit is contained in:
Vladimír Čunát 2024-03-30 06:39:25 +01:00
parent 04a895835e
commit 6aa50d0808
No known key found for this signature in database
GPG Key ID: E747DF1F9575A3AA
1 changed files with 5 additions and 2 deletions

View File

@ -11,10 +11,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "xz";
version = "5.4.6";
version = "5.4.6"; # Beware of CVE-2024-3094 and related risks!!!
src = fetchurl {
url = with finalAttrs; "https://github.com/tukaani-project/xz/releases/download/v${version}/xz-${version}.tar.bz2";
url = with finalAttrs;
# The original URL has been taken down.
# "https://github.com/tukaani-project/xz/releases/download/v${version}/xz-${version}.tar.bz2";
"mirror://sourceforge/lzmautils/xz-${version}.tar.bz2";
sha256 = "sha256-kThRsnTo4dMXgeyUnxwj6NvPDs9uc6JDbcIXad0+b0k=";
};