Create and install dependency manifests #230
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
A common problem when embedding sources is that you can't tell for any given executable what libraries it has. It might have an insecure version of OpenSSL, for example. This MR adds a dependency manifest, which lists each internally used dependency and its version. With this information it is easy to find executables that have unsafe dependencies and prevent them from running.
The format of the file is not final, more of a suggestion to get the ball rolling.