Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Time for a new release? #264

Open
petterreinholdtsen opened this issue Oct 23, 2023 · 1 comment
Open

Time for a new release? #264

petterreinholdtsen opened this issue Oct 23, 2023 · 1 comment

Comments

@petterreinholdtsen
Copy link
Contributor

It hs a while since the last stamped release on sourceforge. Is it time to stamp a new one? It would make life easier for maintainers of the package in Linux distributions like Debian.

@skull-squadron
Copy link

skull-squadron commented Nov 21, 2024

A year+ later and Gentoo (and likely nonzero rolling distros) are shipping under-maintained, CVE-vulnerable .jar redistributable libraries like xalan.jar 2.7.2 HIGH CVE-2022-34169 in app-text/docbook-xsl-ns-stylesheets-1.79.1 (outdated sf copy from 2015) in the stage3 base system. It's not like it's an RCE web service attack surface, but it's a symptom of knock-on effects of insufficiently-rigorous and regular cadence release engineering combined with under-maintaining vendored dependencies, under-maintained downstream packaging, and the risks inherent to dependencies. Lots of swiss cheese slices need to line up for this to be bad, it just doesn't look good at first glance. Conventional semver releases would be awesome. I'll have to search the interwebs if there's a more current ebuild in another repo for this and docbook parent deps because it's currently in "needs a new maintainer" state in the official Gentoo portage repo. Thanks to all who attempt to fix legacy codebases without throwing away compatibility of important little pieces that hold up the entire internet.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants