https://bugzilla.redhat.com/show_bug.cgi?id=1440971



--- Comment #14 from Athos Ribeiro <[email protected]> ---
(In reply to Athos Ribeiro from comment #2)
> As I see it, the needed actions are
> 
> - update pyclipper to use the latest polyclipper version
This needs fixing
> - update pyclipper build to allow using the system SO
Solved downstream, it would be nice to implement it upstream
> - update polyclipper in Fedora to the latest version
Solved.

(In reply to Shawn Starr from comment #13)
> Can we not provide temporary patches locally to use the system libraries
> until upstream has their solution in place?

Yes, it is already done. The problem is the the latest polyclipping ABI is
different from the one used in this python package. We should also patch it to
use the latest ABI.

I have been quite busy to dive into upstream code and provide a patch. I will
assess the necessary work this weekend, if I cannot provide the patch by then,
I would not oppose into looking at embedding it for now. I wouldn't be
comfortable doing so without consulting the packaging committee first though.
FYI, after a quick search, I could not find any CVEs open for previous
polyclipper versions.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
You are always notified about changes to this product and component
_______________________________________________
package-review mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to