From mboxrd@z Thu Jan 1 00:00:00 1970 From: ng0 Subject: Re: Adding packages with vulnerabilities (was Re: [PATCH 1/2] gnu: Add perl-net-psyc. [pcre]) Date: Mon, 03 Oct 2016 21:06:12 +0000 Message-ID: <87a8elqh17.fsf@we.make.ritual.n0.is> References: <20160913113237.17434-1-ng0@we.make.ritual.n0.is> <20160913191644.GC5986@jasmine> <87twdjmw4y.fsf@we.make.ritual.n0.is> <87twdj8qqg.fsf@we.make.ritual.n0.is> <878tulr4qk.fsf@we.make.ritual.n0.is> <8737ktr17c.fsf@we.make.ritual.n0.is> <87shstccqg.fsf@we.make.ritual.n0.is> <20160927165640.GB2497@jasmine> <87twczrsju.fsf@we.make.ritual.n0.is> <20161002015022.GB26660@jasmine> <87twcta14r.fsf@gnu.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:39491) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1brART-0000zz-Df for guix-devel@gnu.org; Mon, 03 Oct 2016 17:06:32 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1brARR-0002Qx-4D for guix-devel@gnu.org; Mon, 03 Oct 2016 17:06:30 -0400 In-Reply-To: <87twcta14r.fsf@gnu.org> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Ludovic =?utf-8?Q?Court=C3=A8s?= , Leo Famulari Cc: guix-devel@gnu.org Ludovic Courtès writes: > Leo Famulari skribis: > >> On Thu, Sep 29, 2016 at 08:58:29AM +0000, ng0 wrote: >>> Leo Famulari writes: >>> > On Wed, Sep 21, 2016 at 06:46:31PM +0000, ng0 wrote: >>> >> Subject: [PATCH 1/2] gnu: Add psyclpc. >>> >> >>> >> * gnu/packages/psyc.scm (psyclpc): New variable. >> >>> >> + (inputs >>> >> + `(("zlib" ,zlib) >>> >> + ("openssl" ,openssl))) >>> >> + ;; pcre is bundled to ensure the version is compatible. XXX: look into >>> >> + ;; unbundling it. Upstream should update from pcre 4.5 to 8.38. For >>> >> + ;; functionality reasons we can not unbundle it now. >>> >> + ;; ("pcre" ,pcre))) >>> > >>> > That version of PCRE was released in 2003. We might want to add a >>> > warning to the package description... >>> > >>> > https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=pcre >>> >>> Update on this: the pcre bundling was inherited from ldmud, current >>> ldmud has unbundled pcre, so we will be able to unbundle pcre. >>> >>> I'd still like to have the patches in their current form and update >>> psyclpc when the next version without pcre is out. >> >> I'd like some more opinions on this. Should we add this package even >> though we know it contains some security bugs (linked above)? > > I don’t think so. > > From the comment above, it seems difficult to have this package use a > current version of PCRE, right? Then I would suggest discussing it with > upstream. After all, they’re developing network-facing software, so > they’re probably interested in avoiding security issues. > > ng0, could you take it with them? > > TIA, > Ludo’. > Leo, Ludovic: I really appreciate the review, but please use the more current thread. I commented that this is the wrong thread and that we already fixed the pcre, last week. No need to discuss about pcre anymore. Thanks --