https://bugzilla.redhat.com/show_bug.cgi?id=2523675



--- Comment #9 from Petr Menšík <[email protected]> ---
I think upstream should be asked to clearly mention, which versions are
modified (and briefly why) and which are not. I completely understand why
people hate moving libraries with changing behaviour. But at the same time it
is then upstream's author duty to watch for possible CVE fixes, even if they do
not need later bug fixes or improvements. I doubt that is a common practice by
projects bundling external dependencies. It is much easier to work with, but
not without (hidden) additional costs.

If possible, helping upstream with using stock unmodified libraries plus maybe
some external addition would be better for the future. But not without extra
work now.


-- 
You are receiving this mail because:
You are always notified about changes to this product and component
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2523675

Report this comment as SPAM: 
https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-spam&short_desc=Report%20of%20Bug%202523675%23c9

-- 
_______________________________________________
package-review mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to