-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add expat and libxml2 to list of allowed version ranges #23603
Add expat and libxml2 to list of allowed version ranges #23603
Conversation
🤖 Beep Boop! This pull request is making changes to 'docs//'. 👋 @prince-chrismc @MartinDelille @Croydon you might be interested. 😉 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
is libpng not allowed any more ?
Good catch @ericLemanissier, unintended, fixed now :) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nice!
* Add expat and libxml2 to list of allowed version ranges * Typo * Update docs/adding_packages/dependencies.md
* Zlib: `[>=1.2.11 <2]` | ||
* Libpng: `[>=1.6 <2]` | ||
* Expat: `[>=2.6.2 <3]` | ||
* Libxml2: `[>=2.12.5 <3]` |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It there a rational for such high lower bound? I know that some recipes are not compatible with libxml2 2.12.x due to removal of few functions.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hi, this is just the version that had no cve at the time of writing
Note that when necessary, we can nudge the verison ranges to fit when a library does not support newer versions, I'll add a note, thanks for the heads up :)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pinging @SpaceIm in case you don't get answer notifications! (Which is what happened to me, if you comment on old cclosed issues, feel free to ping so I dont lose the notification!)
Document bounds for libxml2 and expat
/cc @mayeut who's been pushing for this lately, thanks!