From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: Re: 03/15: gnu: wxwidgets: Use webkitgtk-2.4. Date: Mon, 22 Jan 2018 15:19:04 -0500 Message-ID: <20180122201904.GA20036@jasmine.lan> References: <20180122190055.4417.86639@vcs0.savannah.gnu.org> <20180122190058.656FA207C0@vcs0.savannah.gnu.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="C7zPtVaVf+AK4Oqc" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:58812) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1edihV-0003jM-R3 for guix-devel@gnu.org; Mon, 22 Jan 2018 15:28:18 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1edihQ-0002Jd-TO for guix-devel@gnu.org; Mon, 22 Jan 2018 15:28:17 -0500 Received: from out3-smtp.messagingengine.com ([66.111.4.27]:42769) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1edihQ-0002JR-Ne for guix-devel@gnu.org; Mon, 22 Jan 2018 15:28:12 -0500 Content-Disposition: inline In-Reply-To: <20180122190058.656FA207C0@vcs0.savannah.gnu.org> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org --C7zPtVaVf+AK4Oqc Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, Jan 22, 2018 at 02:00:57PM -0500, Danny Milosavljevic wrote: > dannym pushed a commit to branch master > in repository guix. >=20 > commit 8a58182c12193ae27359591c92febfdd602411f4 > Author: Danny Milosavljevic > Date: Mon Jan 22 17:34:13 2018 +0100 >=20 > gnu: wxwidgets: Use webkitgtk-2.4. > =20 > * gnu/packages/wxwidgets.scm (wxwidgets)[inputs]: Replace "webkitgtk"= by > "webkitgtk-2.4". Hi Danny, What's the reason for this change? Webkitgtk is actively examined and exploited by security researchers. I think we should try not to build wxwidgets with this unmaintained version of webkitgtk. If some application needs wxwidgets with this older webkitgtk, we should make a new package for it and maybe file a bug upstream pointing out the risks of such a dependency. We already have a few such "special" wxwidgets packages. --C7zPtVaVf+AK4Oqc Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlpmRzUACgkQJkb6MLrK fwgIoBAAu+sZc6dDtBr8K3IvtAA2ddTIQwY21FSR69iQI7fBYK1AWVdd+moecIRN OQXAI/5yE8xg3lzr38m75RS9Uj6g7+uGe6GcCMYicB+YbLQ3tV2jXKSL8fd9dyXs M2X1HrIGgAz4v+2EMpqxOBXFNfDTdN8av35Qr/QPQSP1yI/YwBX4cSANwu2t2Hjh 98aDnLjdWF87bnPGGGVAHTrTBD+hDBvP27461dWlc8nsLFFFzxiHuMZWTF5ceoWI rum9KBP5Wkw+fDf9nIe4kbvbISx/WP3+PMlYNSdYmgDcwmoyG99WC+7h7hCZ3OZ0 bXPBgTR8zJZ3v7fUNmOVc36ptqGdjESsNSSKZ78EBL2yY11V0T5R2MPVLHS4Lc17 xUJqGIutbfL0oKuyFZjcL/Vq3zvC6ib/8ng4bMv2lmkgjq6Uri0xQMDQi2wHPvJA hMwOX5JvL5FW9wfQDYJnpuGB+QUCmCTlbnduqK7rx3RNMpNcKYyf+Z8Phldu11eU Us1F5jGcCXdUafKvZo2i0LHvAi9dE07miCTkrNUu4bde/WXryCuNhxt9OPntJwUu er34jZpYi9v3uTnFInzPrG1eH2JqhPFt53XM9pQDIsRgNQC02csgLbwnDRlD3TLl 3ilgV7230B5hjmJqG07YkUmUZdek3A96Np44Sfx5Q9kwlF7BWN4= =0SJQ -----END PGP SIGNATURE----- --C7zPtVaVf+AK4Oqc--