Update: thanks to an older backup from Ivan Kozik, we've been able to verify the
integrity of all but 45 jars. It's likely these were legitimate redeployments by
the maintainers, but I'm going to be reviewing the diffs by hand.

I've attached a list of jars which haven't been verified. If your dependency
tree (visible with `lein deps :tree` under Leiningen 2) does not include any of
these then you should be completely clear. If it does you're probably still
safe; I hope to have these cleared by the end of the day.

From what we know from Linode, the exposed data could not have resulted in a
compromise of the box without a reboot in order to reset passwords or use the
rescue image, and we've confirmed that a reboot did not occur. So checking the
jar diffs is probably not necessary, but we'd rather be extra-careful.

thanks,
Phil

Attachment: pgp2VesHkL5mX.pgp
Description: PGP signature

amazonica/amazonica/0.1.3/amazonica-0.1.3.jar
amazonica/amazonica/0.1.4/amazonica-0.1.4.jar
amazonica/amazonica/0.1.5/amazonica-0.1.5.jar
antler/caribou-admin/0.10.0/caribou-admin-0.10.0.jar
bwo/monads/0.1.0/monads-0.1.0.jar
cc/qbits/alia/1.0.0-beta7/alia-1.0.0-beta7.jar
chlorine/chlorine/1.5.2.1/chlorine-1.5.2.1.jar
chlorine/chlorine/1.5.2.2/chlorine-1.5.2.2.jar
chlorine/chlorine/1.5.3/chlorine-1.5.3.jar
clj-diffmatchpatch/clj-diffmatchpatch/0.0.9.1/clj-diffmatchpatch-0.0.9.1.jar
clj-diffmatchpatch/clj-diffmatchpatch/0.0.9.3/clj-diffmatchpatch-0.0.9.3.jar
clj-diffmatchpatch/clj-diffmatchpatch/0.0.9/clj-diffmatchpatch-0.0.9.jar
clojurewerkz/archimedes/1.0.0-alpha3/archimedes-1.0.0-alpha3.jar
com/akolov/xelery/0.3.0/xelery-0.3.0.jar
com/narkisr/carmine/1.6.0/carmine-1.6.0.jar
com/narkisr/gelfino-client/0.4.0/gelfino-client-0.4.0.jar
conveyor-coffeescript/conveyor-coffeescript/0.1.4/conveyor-coffeescript-0.1.4.jar
core-cl2/core-cl2/0.7.0/core-cl2-0.7.0.jar
core-cl2/core-cl2/0.7.1/core-cl2-0.7.1.jar
docopt/docopt/0.6.1/docopt-0.6.1.jar
factual/c4/0.0.11/c4-0.0.11.jar
homestake-server/homestake-server/0.1/homestake-server-0.1.jar
info/yasuhisay/clj-utils/0.1.1/clj-utils-0.1.1.jar
info/yasuhisay/liblinear/0.0.1/liblinear-0.0.1.jar
lamina/lamina/0.5.0-beta15/lamina-0.5.0-beta15.jar
lein-haml-sass/lein-haml-sass/0.2.5/lein-haml-sass-0.2.5.jar
lein-package/lein-package/0.1.2/lein-package-0.1.2.jar
lib-noir/lib-noir/0.5.0/lib-noir-0.5.0.jar
luminus/lein-template/0.5.3/lein-template-0.5.3.jar
luminus/lein-template/0.5.5/lein-template-0.5.5.jar
me/arrdem/imprecise/me.arrdem.imprecise/0.1.0/me.arrdem.imprecise-0.1.0.jar
net/clojure/monads/1.0.1/monads-1.0.1.jar
nsfw/lein-template/0.5.2/lein-template-0.5.2.jar
org/flatland/phonograph/0.1.4/phonograph-0.1.4.jar
org/trpr/integration-rabbitmq/1.2.2/integration-rabbitmq-1.2.2.jar
org/trpr/platform-core/1.2.2/platform-core-1.2.2.jar
org/trpr/platform-integration/1.2.2/platform-integration-1.2.2.jar
rojat/rojat-arrows/0.0.6/rojat-arrows-0.0.6.jar
rojat/rojat-math/0.0.2/rojat-math-0.0.2.jar
rojat/rojat-math/0.0.3/rojat-math-0.0.3.jar
rst-format-parser/rst-format-parser/0.0.1/rst-format-parser-0.0.1.jar
service-hub/service-hub/1.0.3/service-hub-1.0.3.jar
stereotype/stereotype/0.2.1/stereotype-0.2.1.jar
stereotype/stereotype/0.2.2/stereotype-0.2.2.jar
thebusby/clj-aws-ec2/0.2.2/clj-aws-ec2-0.2.2.jar

Reply via email to