https://bugzilla.redhat.com/show_bug.cgi?id=2523675
--- Comment #9 from Petr Menšík <[email protected]> --- I think upstream should be asked to clearly mention, which versions are modified (and briefly why) and which are not. I completely understand why people hate moving libraries with changing behaviour. But at the same time it is then upstream's author duty to watch for possible CVE fixes, even if they do not need later bug fixes or improvements. I doubt that is a common practice by projects bundling external dependencies. It is much easier to work with, but not without (hidden) additional costs. If possible, helping upstream with using stock unmodified libraries plus maybe some external addition would be better for the future. But not without extra work now. -- You are receiving this mail because: You are always notified about changes to this product and component You are on the CC list for the bug. https://bugzilla.redhat.com/show_bug.cgi?id=2523675 Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-spam&short_desc=Report%20of%20Bug%202523675%23c9 -- _______________________________________________ package-review mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
