all messages for Guix-related lists mirrored at yhetil.org
 help / color / mirror / code / Atom feed
* Re: 03/15: gnu: wxwidgets: Use webkitgtk-2.4.
       [not found] ` <20180122190058.656FA207C0@vcs0.savannah.gnu.org>
@ 2018-01-22 20:19   ` Leo Famulari
  2018-01-22 23:55     ` Danny Milosavljevic
  0 siblings, 1 reply; 3+ messages in thread
From: Leo Famulari @ 2018-01-22 20:19 UTC (permalink / raw)
  To: guix-devel

[-- Attachment #1: Type: text/plain, Size: 900 bytes --]

On Mon, Jan 22, 2018 at 02:00:57PM -0500, Danny Milosavljevic wrote:
> dannym pushed a commit to branch master
> in repository guix.
> 
> commit 8a58182c12193ae27359591c92febfdd602411f4
> Author: Danny Milosavljevic <dannym@scratchpost.org>
> Date:   Mon Jan 22 17:34:13 2018 +0100
> 
>     gnu: wxwidgets: Use webkitgtk-2.4.
>     
>     * gnu/packages/wxwidgets.scm (wxwidgets)[inputs]: Replace "webkitgtk" by
>     "webkitgtk-2.4".

Hi Danny,

What's the reason for this change?

Webkitgtk is actively examined and exploited by security researchers. I
think we should try not to build wxwidgets with this unmaintained
version of webkitgtk.

If some application needs wxwidgets with this older webkitgtk, we should
make a new package for it and maybe file a bug upstream pointing out the
risks of such a dependency. We already have a few such "special"
wxwidgets packages.

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: 03/15: gnu: wxwidgets: Use webkitgtk-2.4.
  2018-01-22 20:19   ` 03/15: gnu: wxwidgets: Use webkitgtk-2.4 Leo Famulari
@ 2018-01-22 23:55     ` Danny Milosavljevic
  2018-01-23  0:09       ` Danny Milosavljevic
  0 siblings, 1 reply; 3+ messages in thread
From: Danny Milosavljevic @ 2018-01-22 23:55 UTC (permalink / raw)
  To: Leo Famulari; +Cc: guix-devel

Hi Leo,

On Mon, 22 Jan 2018 15:19:04 -0500
Leo Famulari <leo@famulari.name> wrote:

> On Mon, Jan 22, 2018 at 02:00:57PM -0500, Danny Milosavljevic wrote:
> > dannym pushed a commit to branch master
> > in repository guix.
> > 
> > commit 8a58182c12193ae27359591c92febfdd602411f4
> > Author: Danny Milosavljevic <dannym@scratchpost.org>
> > Date:   Mon Jan 22 17:34:13 2018 +0100
> > 
> >     gnu: wxwidgets: Use webkitgtk-2.4.
> >     
> >     * gnu/packages/wxwidgets.scm (wxwidgets)[inputs]: Replace "webkitgtk" by
> >     "webkitgtk-2.4".  
> 
> What's the reason for this change?

wxwidgets didn't enable webview at all - which failed a few other
programs (I looked through the core-updates hydra failure list).

> Webkitgtk is actively examined and exploited by security researchers. I
> think we should try not to build wxwidgets with this unmaintained
> version of webkitgtk.
> 
> If some application needs wxwidgets with this older webkitgtk

Sorry, didn't know.  Should we revert this for the time being?

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: 03/15: gnu: wxwidgets: Use webkitgtk-2.4.
  2018-01-22 23:55     ` Danny Milosavljevic
@ 2018-01-23  0:09       ` Danny Milosavljevic
  0 siblings, 0 replies; 3+ messages in thread
From: Danny Milosavljevic @ 2018-01-23  0:09 UTC (permalink / raw)
  To: Leo Famulari; +Cc: guix-devel

I've reverted it.

Hmm, why is the newer version of webkitgtk an input of wxwidgets when it
can't be used by wxwidgets (and it can't be)?

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2018-01-23  0:09 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <20180122190055.4417.86639@vcs0.savannah.gnu.org>
     [not found] ` <20180122190058.656FA207C0@vcs0.savannah.gnu.org>
2018-01-22 20:19   ` 03/15: gnu: wxwidgets: Use webkitgtk-2.4 Leo Famulari
2018-01-22 23:55     ` Danny Milosavljevic
2018-01-23  0:09       ` Danny Milosavljevic

Code repositories for project(s) associated with this external index

	https://git.savannah.gnu.org/cgit/guix.git

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.