Re: [ITA] nginx 1.28.2
Brian Inglis via Cygwin-apps <[email protected]> Wed, 25 Feb 2026 22:23:18 -0700
| Newsgroups | gmane.os.cygwin.applications |
|---|---|
| Organization | Systematic Software |
| Message-ID | <[email protected]> |
I think we all knew that: please post only in plain UTF-8 text not HTML!
Non-maintainers should be able to force push to playground branch; maybe you
need site creds: it's been a long while for me.
Otherwise you will have to publish your source and binary package builds on some
file sharing public web site like Apple iCloud Drive, BitBucket, Box, DropBox,
GitHub, GitLab, Google Drive, iDrive, MS OneDrive, Proton Drive or similar,
depending on what you can access and afford; you should attach the cygport as
plain text to the email.
.
On 2026-02-25 18:09, xumouren225588 via Cygwin-apps wrote:
> And my real name is Chaoyang Xu, I comes from China
> 发自我的网易邮箱手机智能版
> On Thu, 26 Feb 2026 09:03:15 +0800, Chaoyang Xu wrote:
> But how to push change, I'am not a package maintainer
> 在 2026-02-25 22:53:40,"Brian Inglis via Cygwin-apps" 写道:
> On 2026-02-25 02:45, xumouren225588 via Cygwin-apps wrote:
>> Changes with nginx 1.28.2 04 Feb 2026
>> *) Security: an attacker might inject plain text data in the response from an SSL backend (CVE-2026-1642).
>> *) Bugfix: use-after-free might occur after switching to the next gRPC or HTTP/2 backend.
>> *) Bugfix: fixed warning when compiling with MSVC 2022 x86.
>
> Please follow the processes linked below, using info elsewhere on that page:
>
> https://cygwin.com/packaging-contributors-guide.html#adopt
>
> https://cygwin.com/packaging-contributors-guide.html#submitting
>
> You may simplify things if you check out repo:
>
> https://cygwin.com/git/cygwin-packages/nginx
>
> branch playground and make your cygport updates, then push to playground branch,
> which will submit and run a job on GitHub Scallywag CI, which you can use to
> reference your work.
>
> From the source package summary page, the current release is 1.29.5, which may
> be your ultimate target for stable release on branch main:
>
> https://cygwin.com/packages/summary/nginx-src.html
>
> Packaging policy follows Fedora guidelines, so reviewing nginx.spec and
> accompanying patches under:
>
> https://src.fedoraproject.org/rpms/nginx/blob/main/f/nginx.spec
>
> https://src.fedoraproject.org/rpms/nginx/blob/rawhide/f/nginx.spec
>
> https://src.fedoraproject.org/rpms/nginx/blob/stream-mainline/f/nginx.spec
>
> and perhaps applying some of those patches may improve the result.
>
> For use in organizations mandating security such as government, federal agencies
> and contractors, and regulated industries including education, finance, health,
> energy, and others, FIPS compliance is important and often supported in Fedora
> packages or stream versions; see also:
>
> https://docs.nginx.com/nginx/fips-compliance-nginx-plus/#ciphers-disabled-in-fips-mode
>
>
--
Take care. Thanks, Brian Inglis Calgary, Alberta, Canada
La perfection est atteinte Perfection is achieved
non pas lorsqu'il n'y a plus rien à ajouter not when there is no more to add
mais lorsqu'il n'y a plus rien à retrancher but when there is no more to cut
-- Antoine de Saint-Exupéry