1 |
On Wednesday 12 July 2006 16:43, exg@g.o wrote: |
2 |
> Guys, |
3 |
> |
4 |
> The xpdf version we have currently in the tree is a modified one that |
5 |
> links to poppler, provided in IRC to genstef by an ubuntu developer (no, |
6 |
> ubuntu does not use it); now, I can understand that having a single |
7 |
> point of failure is desiderable, but I completely disagree when doing |
8 |
> this implies using a thirdy-party version not maintained/hosted anywhere |
9 |
> (the reasons being obvious, I hope). Besides, it's improbable that |
10 |
> upstream will add support for poppler in xpdf. |
11 |
> |
12 |
> I really would like to see back the upstream version, what do you think? |
13 |
The reason for this was security I believe. xpdf code is embedded in lots of |
14 |
other packages (see http://glsa.gentoo.org for some examples). By linking to |
15 |
poppler this is fixed in one place. |
16 |
|
17 |
Though if someone is willing to maintain a vanilla xpdf ebuild I'd have no |
18 |
complaints. Genstef? |
19 |
|
20 |
-- |
21 |
Sune Kloppenborg Jeppesen |
22 |
Gentoo Linux Security Team |