Re: [aur-general] Suggestion to add a pinned comment to PKGBUILDs of high risk vulnerable software

2017-07-04 Thread NicoHood
I want to point out another view from this situation: What if an outdated package is moved to AUR and does not have a new package with the replace=() variable? I personally had this several times and those packages are still kept on the system. This gave me some broken dependencies but also old s

Re: [aur-general] Suggestion to add a pinned comment to PKGBUILDs of high risk vulnerable software

2017-07-04 Thread Ralf Mardorf
On Tue, 4 Jul 2017 09:45:08 +0200, Ralf Mardorf wrote: >On Tue, 4 Jul 2017 14:00:50 +0800, Oon-Ee Ng via aur-general wrote: >>You could suggest it on the package's AUR page. > >Hi, > >yes, I could ask to do it for dependent packages such as >https://aur.archlinux.org/packages/xombrero/ even while

Re: [aur-general] Suggestion to add a pinned comment to PKGBUILDs of high risk vulnerable software

2017-07-04 Thread Ralf Mardorf
On Tue, 4 Jul 2017 14:00:50 +0800, Oon-Ee Ng via aur-general wrote: >You could suggest it on the package's AUR page. Hi, yes, I could ask to do it for dependent packages such as https://aur.archlinux.org/packages/xombrero/ even while I'm not using it. I could ask to do it for https://aur.archlin