Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New RPM packages are not available #42

Open
mssucksalot opened this issue Nov 20, 2024 · 2 comments
Open

New RPM packages are not available #42

mssucksalot opened this issue Nov 20, 2024 · 2 comments

Comments

@mssucksalot
Copy link

It is latest available package at https://repo.sonatype.com/service/rest/repository/browse/community-yum-hosted/

nexus-repository-manager-3.69.0_02-1.el7.noarch.rpm  Tue Jun 04 20:25:41 Z 2024 	226606804

No 72-74 builds are available even if such tag as build_new_version_3.74.0-05 is created.

@bhamail
Copy link
Contributor

bhamail commented Nov 20, 2024

Thanks for taking the time to create this issue. There are a "few" problems to work through, mostly related to database upgrades, some of which are covered here: Issue #40

@mssucksalot
Copy link
Author

I see... I experienced the issue on upgrade, so I did migration manually and then switched back to 3.71 rpm package from this repository. I think currently it is revoked, but it works on my server.

The reason why I want to get 3.72, 3.73 and 3.74 is the CVE fixed in 3.73: https://support.sonatype.com/hc/en-us/articles/34496708991507-CVE-2024-5764-Nexus-Repository-Manager-3-Static-hard-coded-encryption-passphrase-used-by-default-2024-10-17

For me it is not critical issue. But it's better to update in any case. And I expect further releases can fix something and that will not be available this repo.

I think 3.71 and further releases can have some confirmation or notice like for example MariaDB has when it upgrades to new major version. No reason to disallow updates for all users who already have 3.71 version or later.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants