treewide: add knownVulnerabilities to old libxml2

Users should be informed if they're using packages that are
deliberately opting in to using old versions of dependencies with
vulnerabilities that have otherwise been fixed in Nixpkgs.

Changed files
+21 -6
pkgs
applications
networking
remote
citrix-workspace
by-name
ci
ciscoPacketTracer7
ciscoPacketTracer8
+7 -2
pkgs/applications/networking/remote/citrix-workspace/generic.nix
···
'';
};
-
libxml2' = libxml2.overrideAttrs rec {
version = "2.13.8";
src = fetchurl {
url = "mirror://gnome/sources/libxml2/${lib.versions.majorMinor version}/libxml2-${version}.tar.xz";
hash = "sha256-J3KUyzMRmrcbK8gfL0Rem8lDW4k60VuyzSsOhZoO6Eo=";
};
-
};
in
···
'';
};
+
libxml2' = libxml2.overrideAttrs (oldAttrs: rec {
version = "2.13.8";
src = fetchurl {
url = "mirror://gnome/sources/libxml2/${lib.versions.majorMinor version}/libxml2-${version}.tar.xz";
hash = "sha256-J3KUyzMRmrcbK8gfL0Rem8lDW4k60VuyzSsOhZoO6Eo=";
};
+
meta = oldAttrs.meta // {
+
knownVulnerabilities = oldAttrs.meta.knownVulnerabilities or [ ] ++ [
+
"CVE-2025-6021"
+
];
+
};
+
});
in
+7 -2
pkgs/by-name/ci/ciscoPacketTracer7/package.nix
···
];
};
-
libxml2' = libxml2.overrideAttrs rec {
version = "2.13.8";
src = fetchurl {
url = "mirror://gnome/sources/libxml2/${lib.versions.majorMinor version}/libxml2-${version}.tar.xz";
hash = "sha256-J3KUyzMRmrcbK8gfL0Rem8lDW4k60VuyzSsOhZoO6Eo=";
};
-
};
fhs = buildFHSEnv {
pname = "packettracer7";
···
];
};
+
libxml2' = libxml2.overrideAttrs (oldAttrs: rec {
version = "2.13.8";
src = fetchurl {
url = "mirror://gnome/sources/libxml2/${lib.versions.majorMinor version}/libxml2-${version}.tar.xz";
hash = "sha256-J3KUyzMRmrcbK8gfL0Rem8lDW4k60VuyzSsOhZoO6Eo=";
};
+
meta = oldAttrs.meta // {
+
knownVulnerabilities = oldAttrs.meta.knownVulnerabilities or [ ] ++ [
+
"CVE-2025-6021"
+
];
+
};
+
});
fhs = buildFHSEnv {
pname = "packettracer7";
+7 -2
pkgs/by-name/ci/ciscoPacketTracer8/package.nix
···
"8.2.2" = "CiscoPacketTracer822_amd64_signed.deb";
};
-
libxml2' = libxml2.overrideAttrs rec {
version = "2.13.8";
src = fetchurl {
url = "mirror://gnome/sources/libxml2/${lib.versions.majorMinor version}/libxml2-${version}.tar.xz";
hash = "sha256-J3KUyzMRmrcbK8gfL0Rem8lDW4k60VuyzSsOhZoO6Eo=";
};
-
};
unwrapped = stdenvNoCC.mkDerivation {
name = "ciscoPacketTracer8-unwrapped";
···
"8.2.2" = "CiscoPacketTracer822_amd64_signed.deb";
};
+
libxml2' = libxml2.overrideAttrs (oldAttrs: rec {
version = "2.13.8";
src = fetchurl {
url = "mirror://gnome/sources/libxml2/${lib.versions.majorMinor version}/libxml2-${version}.tar.xz";
hash = "sha256-J3KUyzMRmrcbK8gfL0Rem8lDW4k60VuyzSsOhZoO6Eo=";
};
+
meta = oldAttrs.meta // {
+
knownVulnerabilities = oldAttrs.meta.knownVulnerabilities or [ ] ++ [
+
"CVE-2025-6021"
+
];
+
};
+
});
unwrapped = stdenvNoCC.mkDerivation {
name = "ciscoPacketTracer8-unwrapped";