Gentoo Archives: gentoo-dev

From: Rich Freeman <rich0@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Lastrite: media-gfx/pngcrush
Date: Sun, 09 Oct 2011 01:58:28
Message-Id: CAGfcS_=drDiNHDfXmpc6r59gphLy4=yap5JSxK_KFhw6NE-nHw@mail.gmail.com
In Reply to: Re: [gentoo-dev] Lastrite: media-gfx/pngcrush by Markos Chandras
1 On Sat, Oct 8, 2011 at 9:41 PM, Markos Chandras <hwoarang@g.o> wrote:
2 > 1) use bundled zlib and libpng14. Doh this is not a fix. It is barely
3 > a workaround. What if a vulnerability is discovered in the bundled
4 > version of libpng in the next months? Will upstream fix it? Highly
5 > unlikely since they don't seem able to keep up with libpng releases.
6
7 I'm no sure why a bundled library needs to be cause for masking. If
8 there is a vulnerability, of course we should mask away if we can't
9 fix it within the GLSA guidelines.
10
11 I think that the general principle of not bundling libraries is a good
12 one. However, that shouldn't be the sole reason for excluding a
13 package from the tree, and right now I can't see any other reason to
14 exclude this package since bundling the library fixes the block. I
15 haven't seen any evidence presented that upstream is lax with security
16 - not using the latest version of a library simply is a case of "if it
17 ain't broke, don't fix it."
18
19 Rich