1 |
On Wed, Aug 31, 2016 at 1:03 PM, Alexis Ballier <aballier@g.o> wrote: |
2 |
> On Wed, 31 Aug 2016 08:28:14 -0400 |
3 |
> Rich Freeman <rich0@g.o> wrote: |
4 |
>> Sure, but we're talking about a major version here, and a web browser |
5 |
>> where future security updates need to be deployed quickly. You don't |
6 |
>> want to be stuck figuring out what other ffmpeg API calls were touched |
7 |
>> in the new version while there is some exploit floating around. |
8 |
>> |
9 |
>> It seems like bundling is the simpler solution here, unless the |
10 |
>> necessary patches are trivial. If they're in fact trivial somebody |
11 |
>> can probably just post one and save a lot of speculation. :) |
12 |
> |
13 |
> It depends on the complexity of the patch indeed. We're talking about 3 |
14 |
> enum values that were added in ffmpeg-3 here. |
15 |
> |
16 |
|
17 |
If that is indeed all this is, then it does seem like a no-brainer... |
18 |
|
19 |
-- |
20 |
Rich |