Leo Famulari writes: > * gnu/packages/patches/weex-CVE-2005-3150.patch: New file. > * gnu/local.mk (dist_patch_DATA): Add it. > * gnu/packages/ftp.scm (weex)[source]: Use it. Wow, an 11 year-old CVE. There is a 2.8.0 release of weex from last year on http://weex.sf.net, is that still affected? We have 2.6.15.