On Sat, Oct 16, 2021 at 10:08 PM Kevin Kofler via devel < devel@lists.fedoraproject.org> wrote:
> Steve Grubb wrote: > > I'd like to suggest making libcurl-minimal very minimal for security > > reasons. The main curl package has many security issues (CVE's) > > constantly. But usually, the problem is in some obscure feature/protocol. > > Looking at the packages that depend on libcurl with rpmreaper, most would > > use http(s). There might be some that use another protocol. But clear > text > > protocols like telnet and ftp really don't have a use in today's > internet. > > Too many threats for clear text. > > I suspect that disabling FTP in libcurl is going to break a lot of stuff. > I'd be curious, what package uses curl for it's FTP support? -Steve
_______________________________________________ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure