MarsSeed [1] filed a deletion request for openssl-static [2]:

Unneeded, not very actively maintained duplicate of core/openssl.
Currently outdated since September 2023.
With this, it makes the Arch Linux installation that has this
vulnerable to discovered and published attack vectors.

Only AUR/x-minecraft-launcher depends on it. That package should
either use core/openssl, or if really necessary, bundle in openssl in
a static build, instead of forcing to have a duplicate of the repo
package on AUR.

Also, if a feature that is essential is missing from core/openssl,
please file an Arch bug ticket. That's what AUR submission guidelines
call for instead of modding and uploading repo PKGBUILDs to AUR.

[1] https://aur.archlinux.org/account/MarsSeed/
[2] https://aur.archlinux.org/pkgbase/openssl-static/

Reply via email to