On Tue, Mar 29, 2022 at 6:23 PM Sérgio Basto <ser...@serjux.com> wrote:
>
> Hi,
>
> ImageMagick 6.9.12.x have a bunch security fixes since 6.9.10.x .
> I'd like update ImageMagick (IM) on epel8 with soname bump .
> ImageMagick-6.9.10 last version, have almost 2 years and keep it and
> just pull security patches, it would have a lot more work in my
> opinion.
>
> so in  epel8-build-side-52356 repo (sidetag) we got now
> ImageMagick-6.9.12.44-1.el8
>
> I will rebuild these 24 packages [1] calculated
> with find_unblocked_orphans.py from
> https://pagure.io/releng/blob/main/f/scripts [2]
>
>
> Best regards,
>
>
> [1]
> Depending packages (epel8) (24): conky-manager converseen darktable
> digikam dvdauthor ettercap gnokii keepass latex2rtf lyx mediainfo
> openbabel perl-GD-SecurityImage perl-PAR-Packer playonlinux
> purple-discord putty stb stellarium tango-icon-theme w3m
> xemacs-packages-extra xfig xforms
>
> [2]
> ./find_unblocked_orphans.py --release epel8 --skip-orphans --max_deps 0
> ImageMagick
>
> conky-manager (maintained by: orphan)
> conky-manager-2.3.4-11.el8.x86_64 requires ImageMagick = 6.9.10.86-
> 1.el8
>
> converseen (maintained by: marionline)
> converseen-0.9.8.1-1.el8.src requires ImageMagick-c++-devel =
> 6.9.10.86-1.el8, ImageMagick-devel = 6.9.10.86-1.el8
> converseen-0.9.8.1-1.el8.x86_64 requires libMagick++-
> 6.Q16.so.8()(64bit), libMagickCore-6.Q16.so.6()(64bit)
>
> darktable (maintained by: asn, germano, kalev, madko)
> darktable-tools-noise-3.8.0-5.el8.x86_64 requires ImageMagick =
> 6.9.10.86-1.el8
>
> digikam (maintained by: dvratil, kde-sig, kwizart, nucleo, rdieter,
> than, tuxbrewr, vjancik)
> digikam-6.4.0-4.el8.src requires ImageMagick-c++-devel = 6.9.10.86-
> 1.el8, ImageMagick-devel = 6.9.10.86-1.el8
> digikam-6.4.0-4.el8.x86_64 requires libMagick++-6.Q16.so.8()(64bit),
> libMagickCore-6.Q16.so.6()(64bit)
> digikam-libs-6.4.0-4.el8.x86_64 requires libMagick++-
> 6.Q16.so.8()(64bit), libMagickCore-6.Q16.so.6()(64bit)
>
> dvdauthor (maintained by: hobbes1069, sergiomb)
> dvdauthor-0.7.2-14.el8.src requires ImageMagick-devel = 6.9.10.86-1.el8
> dvdauthor-0.7.2-14.el8.x86_64 requires libMagickCore-
> 6.Q16.so.6()(64bit)
>
> ettercap (maintained by: limb)
> ettercap-0.8.3.1-4.el8.src requires ImageMagick = 6.9.10.86-1.el8
>
> gnokii (maintained by: limb, robert, snirkel)
> gnokii-0.6.31-29.el8.src requires ImageMagick = 6.9.10.86-1.el8
>
> keepass (maintained by: mavit, tpokorra)
> keepass-2.45-1.el8.src requires ImageMagick = 6.9.10.86-1.el8
>
> latex2rtf (maintained by: cicku, yselkowitz)
> latex2rtf-2.3.18-4.el8.src requires ImageMagick = 6.9.10.86-1.el8
> latex2rtf-2.3.18-4.el8.x86_64 requires ImageMagick = 6.9.10.86-1.el8
>
> lyx (maintained by: jamatos, rdieter)
> lyx-2.3.6-2.el8.x86_64 requires ImageMagick = 6.9.10.86-1.el8
>
> mediainfo (maintained by: ivanromanov, vascom)
> mediainfo-21.09-1.el8.src requires ImageMagick = 6.9.10.86-1.el8
>
> openbabel (maintained by: alexpl, jussilehtola, rathann, sagitter,
> scitech_sig)
> openbabel-3.1.1-4.el8.src requires ImageMagick = 6.9.10.86-1.el8
>
> perl-GD-SecurityImage (maintained by: eseyman)
> perl-GD-SecurityImage-1.75-4.el8.noarch requires perl(Image::Magick)
> perl-GD-SecurityImage-1.75-4.el8.src requires perl(Image::Magick)
>
> perl-PAR-Packer (maintained by: jplesnik, ppisar)
> perl-PAR-Packer-1.052-2.el8.src requires ImageMagick = 6.9.10.86-1.el8
>
> playonlinux (maintained by: robert)
> playonlinux-4.4-2.el8.x86_64 requires ImageMagick = 6.9.10.86-1.el8
>
> purple-discord (maintained by: xvitaly)
> purple-discord-0-33.20210928gitb7ac723.el8.src requires ImageMagick =
> 6.9.10.86-1.el8
>
> putty (maintained by: jskarvad, olysonek, zaniyah)
> putty-0.76-1.el8.src requires ImageMagick = 6.9.10.86-1.el8
>
> stb (maintained by: churchyard, music)
> stb-0-0.7.20211022gitaf1a5bc.el8.src requires /usr/bin/convert
>
> stellarium (maintained by: limb, s4504kr)
> stellarium-0.20.1-1.el8.src requires ImageMagick = 6.9.10.86-1.el8
>
> tango-icon-theme (maintained by: cottsay, mavit)
> tango-icon-theme-0.8.90-24.el8.src requires ImageMagick-devel =
> 6.9.10.86-1.el8
>
> w3m (maintained by: pnemade, robert)
> w3m-img-0.5.3-50.git20210102.el8.x86_64 requires ImageMagick =
> 6.9.10.86-1.el8
>
> xemacs-packages-extra (maintained by: jjames, stevetraylen)
> xemacs-packages-extra-20191207-1.el8.src requires ImageMagick =
> 6.9.10.86-1.el8
>
> xfig (maintained by: jwrdegoede, stevetraylen)
> xfig-3.2.7b-3.el8.src requires ImageMagick = 6.9.10.86-1.el8
>
> xforms (maintained by: rdieter, robert)
> xforms-1.2.4-14.el8.src requires ImageMagick = 6.9.10.86-1.el8
>
> --
> Sérgio M. B.
> _______________________________________________
> devel mailing list -- de...@lists.fedoraproject.org
> To unsubscribe send an email to devel-le...@lists.fedoraproject.org
> Fedora Code of Conduct: 
> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives: 
> https://lists.fedoraproject.org/archives/list/de...@lists.fedoraproject.org
> Do not reply to spam on the list, report it: 
> https://pagure.io/fedora-infrastructure

This update changes a library soname, which makes it an incompatible
upgrade.  It must follow the EPEL incompatible upgrades policy [0].
This email can count as step 1 once you reply with the specific CVEs
this will address.  Then it must be open for discussion on list for
one week (step 2) before being added as an agenda item at next week's
EPEL Steering Committee meeting [1] (step 3).

[0] https://docs.fedoraproject.org/en-US/epel/epel-policy-incompatible-upgrades/
[1] https://calendar.fedoraproject.org/epel/#m9854

-- 
Carl George
_______________________________________________
epel-devel mailing list -- epel-devel@lists.fedoraproject.org
To unsubscribe send an email to epel-devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/epel-devel@lists.fedoraproject.org
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to