pkgsrc-Users archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: cups builds



On Mon, 08 Oct 2012 08:30:44 +0900, Darrel <levitch%iglou.com@localhost> wrote:


It seems like we should have OpenSLP 2.0.0

Possibly. Do you have a patch for updating the package? :)


Perhaps a different year for me, and you aleady have lots on your list.

and D-Bus 1.7.0

No. From the homepage:
The current stable branch is D-Bus 1.6.x. This is the recommended version for 
most purposes.
The current development branch is D-Bus 1.7.x, which will lead to a 1.8.x 
stable branch in future.

We usually avoid development versions in pkgsrc.

Yes- the label is "stable" but every day I receive a message from package
vulnerabilities about dbus.  It would seem that if it was fixed then that
would also go back to dbus 1.6 but I am not sure.

For SA50544 (CVE-2012-3524), it may be fixed in dbus-1.7 (master branch),
but NEWS in dbus-1.6.6 and 1.6.8 also mentions about CVE-2012-3524.

One more question, though- if things like D-Bus 1.7 were included in
something like /usr/pkgsrc/devel, would it or would it not lead to more
secure versions of cups?

"pkgsrc/devel" is not for the place neither "development branch version 
packages"
nor "development library variant packages".

See comment in pkgsrc/devel/Makefile.


I am certainly willing to return to more primitive methods or printing -
but folks not on this or a similar list will not.

Darrel



--
OBATA Akio / obache%NetBSD.org@localhost


Home | Main Index | Thread Index | Old Index