1 |
On Sat, Oct 8, 2011 at 9:41 PM, Markos Chandras <hwoarang@g.o> wrote: |
2 |
> 1) use bundled zlib and libpng14. Doh this is not a fix. It is barely |
3 |
> a workaround. What if a vulnerability is discovered in the bundled |
4 |
> version of libpng in the next months? Will upstream fix it? Highly |
5 |
> unlikely since they don't seem able to keep up with libpng releases. |
6 |
|
7 |
I'm no sure why a bundled library needs to be cause for masking. If |
8 |
there is a vulnerability, of course we should mask away if we can't |
9 |
fix it within the GLSA guidelines. |
10 |
|
11 |
I think that the general principle of not bundling libraries is a good |
12 |
one. However, that shouldn't be the sole reason for excluding a |
13 |
package from the tree, and right now I can't see any other reason to |
14 |
exclude this package since bundling the library fixes the block. I |
15 |
haven't seen any evidence presented that upstream is lax with security |
16 |
- not using the latest version of a library simply is a case of "if it |
17 |
ain't broke, don't fix it." |
18 |
|
19 |
Rich |