On Wed, 2026-08-26 at 01:14 -0700, Jakub Szczudlo (Nokia) wrote: > Hi, > > I understand this CVE is bigger than I thought CVE patch can be. > Maybe we can think about updating expat beyond the fixed version? > I now it's not the best because it is stable branch but I can't think about > correct solution.
Hi, Upgrading expat on wrynose & scarthgap may be possible. We are carrying a *lot* of patches for expat, especially on scarthgap, so it's worth considering. It would need a few things: - Review of the delta between the current version on these branches, including the patches we're carrying, and the latest version. Check that there are no features removed or other backwards-incompatible changes. - Confirmation that the SONAME changes won't break anything. - Testing. - RFC patch on the mailing list with a clear subject so people can see it's an exception to the usual stable upgrade policy, explain the review and testing done. This gives chance for people to object if it will cause issues for them. - Agreement from the Yocto TSC, based on the above info. That all needs some time investment beyond what we currently have available, so if you have the bandwidth to look in to it then that would be welcome. Best regards, -- Paul Barker
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#244391): https://lists.openembedded.org/g/openembedded-core/message/244391 Mute This Topic: https://lists.openembedded.org/mt/120905189/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
