Override component to main
libwoff1 1.0.2-1 in cosmic amd64: universe/libs/optional/100% -> main
libwoff1 1.0.2-1 in cosmic arm64: universe/libs/optional/100% -> main
libwoff1 1.0.2-1 in cosmic armhf: universe/libs/optional/100% -> main
libwoff1 1.0.2-1 in cosmic i386: universe/libs/optional/100% -> main
libwoff1 1.0.2-1 in cosmic ppc64el: universe/libs/optional/100% -> main
libwoff1 1.0.2-1 in cosmic s390x: universe/libs/optional/100% -> main
Override [y|N]? y
** Changed in: woff2 (Ubuntu)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to webkit2gtk in Ubuntu.
https://bugs.launchpad.net/bugs/1742743
Title:
[MIR] woff2
Status in webkit2gtk package in Ubuntu:
Fix Committed
Status in woff2 package in Ubuntu:
Fix Released
Bug description:
Availability
============
Built for all supported architectures. In sync with Debian.
Rationale
=========
woff2 is a library maintained by Google to convert fonts from TTF to the
woff2 format and decompress from woff2 to TTF. The WOFF 2.0 format uses the
Brotli compression algorithm to compress fonts suitable for use in CSS
@font-face rules. WOFF 2.0 is a W3C Candidate Recommendation. See the brotli
MIR at LP: #1737053.
brotli and woff2 are libraries that are technically already in main
because they are bundled in Firefox and webkit2gtk.
The next major stable release of webkit2gtk, 2.20, will be released in March.
It drops those 2 bundled libraries. I think our options are basically
1) Bundle those libraries anyway, or
2) Approve this MIR, or
3) Drop support for the WOFF2 format in webkit2gtk
Security
========
I assume we want a security review here.
https://security-tracker.debian.org/tracker/source-package/woff2
https://launchpad.net/ubuntu/+source/woff2/+cve
Quality assurance
=================
- Ubuntu Desktop Bugs is subscribed.
- No test suite
- No autopkgtests
https://bugs.launchpad.net/ubuntu/+source/woff2
https://bugs.debian.org/cgi-bin/pkgreport.cgi?src=woff2
https://github.com/google/woff2/issues
Dependencies
============
Only universe binary dependency is brotli (LP: #1737053)
Standards compliance
====================
4.1.2, debhelper compat 10, dh7 simple rules
Maintenance
===========
Actively maintained:
https://github.com/google/woff2
Maintained by the Debian Fonts Team in Debian. It's a small team so it
may need co-maintenance help from the Ubuntu Desktop team.
Other Info
==========
woff2 was only packaged in Debian and Ubuntu very recently.
webkit2gtk is managed similar to Firefox and Chromium. So far, new
releases are pushed to Ubuntu 16.04 LTS and newer as security updates,
but the Ubuntu Security Team does not guarantee security support for
webkit2gtk.
We are going to need to backport brotli and woff2 into main as
security updates for 16.04 LTS and 17.10.
Packaging is at
https://salsa.debian.org/fonts-team/woff2/tree/debian/unstable/debian
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/webkit2gtk/+bug/1742743/+subscriptions
--
Mailing list: https://launchpad.net/~desktop-packages
Post to : [email protected]
Unsubscribe : https://launchpad.net/~desktop-packages
More help : https://help.launchpad.net/ListHelp