From mboxrd@z Thu Jan 1 00:00:00 1970 From: Mark H Weaver Subject: IMPORTANT: expat security update Date: Fri, 25 Mar 2016 17:16:38 -0400 Message-ID: <87oaa2z2a1.fsf@netris.org> Mime-Version: 1.0 Content-Type: text/plain Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:47295) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ajZ6s-00009m-BC for guix-devel@gnu.org; Fri, 25 Mar 2016 17:17:35 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ajZ6p-0005Xw-4o for guix-devel@gnu.org; Fri, 25 Mar 2016 17:17:34 -0400 Received: from world.peace.net ([50.252.239.5]:41075) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ajZ6p-0005Xm-1F for guix-devel@gnu.org; Fri, 25 Mar 2016 17:17:31 -0400 List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org To: guix-devel@gnu.org I just pushed a security update for expat. See: https://lwn.net/Articles/681356/ I recommend that you update ASAP. Note that Icecat includes a bundled copy of expat, so I guess it is probably still vulnerable. I hope to update it some time in the next few hours. For now, you might want to use Epiphany. Also note that this introduces grafts back into master, unfortunately. It might be that releasing 0.9.1 without grafts is too much to hope for. Mark