package/prosody: security bump to 0.11.8
authorFrancois Perrad <fperrad@gmail.com>
Mon, 1 Mar 2021 12:24:35 +0000 (13:24 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Mon, 1 Mar 2021 22:21:54 +0000 (23:21 +0100)
commit9aba85e3f509498426bd37df8a043fdaa8220953
tree8a29b947337ade0034fb6002545915661d99173d
parent3673b0c7e2b80e5ad53715c19ff9389c19a05d74
package/prosody: security bump to 0.11.8

From the release notes:
https://blog.prosody.im/prosody-0.11.8-released/

This release also fixes a security issue, where channel binding, which
connects the authentication layer (i.e.  SASL) with the security layer (i.e.
TLS) to detect man-in-the-middle attacks, could be used on connections
encrypted with TLS 1.3, despite the holy texts declaring this undefined.

https://issues.prosody.im/1542

Signed-off-by: Francois Perrad <francois.perrad@gadz.org>
[Peter: mark as security bump, expand commit text]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/prosody/prosody.hash
package/prosody/prosody.mk