Re: [security] only latest Qt 5.14.1 has all fixes

2020-01-31 Thread Rex Dieter
Rex Dieter wrote: > Damian Ivanov wrote: > >>>Bumping Qt versions is... a fairly difficult process in fedora, >>>unfortunately. >> >> Introducing a new Qt version could be very simple I think: >> 1) Branch all Qt related packages (it should be with a one line >> command or using a web

Re: [security] only latest Qt 5.14.1 has all fixes

2020-01-31 Thread Rex Dieter
Damian Ivanov wrote: >>Bumping Qt versions is... a fairly difficult process in fedora, >>unfortunately. > > Introducing a new Qt version could be very simple I think: > 1) Branch all Qt related packages (it should be with a one line > command or using a web interface) > 2) Edit package version

Re: [security] only latest Qt 5.14.1 has all fixes

2020-01-29 Thread Damian Ivanov
Hello Rex, >So, we (kde-sign, Qt maintainers) generally update strategically where it >makes sense to warrant the time investment in doing so. I understand. Also that some people contribute it in their free time/or paid time (but not mandatory to contribute), which of course means a lot. I

Re: [security] only latest Qt 5.14.1 has all fixes

2020-01-29 Thread Rex Dieter
Damian Ivanov wrote: > But it's not the only CVE fixed with Qt 5.14.1 > The point is that there is other software using Qt which doesn't start > with K even though K works just fine with 5.14 by the experience of other > distributions. Bumping Qt versions is... a fairly difficult process in

Re: [security] only latest Qt 5.14.1 has all fixes

2020-01-29 Thread Damian Ivanov
But it's not the only CVE fixed with Qt 5.14.1 The point is that there is other software using Qt which doesn't start with K even though K works just fine with 5.14 by the experience of other distributions. Though all software is affected by security issues by using unpatched Qt. Affected by

Re: [security] only latest Qt 5.14.1 has all fixes

2020-01-28 Thread Rex Dieter
Kevin Kofler wrote: > Rex Dieter wrote: >> Latest CVE there has a backported fix applied to fedora's packaging, and >> is currently in bodhi updates-testing, >> https://bodhi.fedoraproject.org/updates/FEDORA-2020-9139ba5469 >> https://bodhi.fedoraproject.org/updates/FEDORA-2020-e9b85978d4 > >

Re: [security] only latest Qt 5.14.1 has all fixes

2020-01-28 Thread Kevin Kofler
Rex Dieter wrote: > Latest CVE there has a backported fix applied to fedora's packaging, and > is currently in bodhi updates-testing, > https://bodhi.fedoraproject.org/updates/FEDORA-2020-9139ba5469 > https://bodhi.fedoraproject.org/updates/FEDORA-2020-e9b85978d4 But that's only QtBase.

Re: [security] only latest Qt 5.14.1 has all fixes

2020-01-28 Thread Rex Dieter
Latest CVE there has a backported fix applied to fedora's packaging, and is currently in bodhi updates-testing, https://bodhi.fedoraproject.org/updates/FEDORA-2020-9139ba5469 https://bodhi.fedoraproject.org/updates/FEDORA-2020-e9b85978d4 ___ devel

Re: [security] only latest Qt 5.14.1 has all fixes

2020-01-28 Thread Damian Ivanov
This is more a request to ship secure versions of software in fedora and rhel that don't have open CVE's when fixed versions are available On Tue, 28 Jan 2020, 19:21 Artem Tim, wrote: > Request 768036 (accepted) > Qt 5.14.1 - untested, as usual > https://build.opensuse.org/request/show/768036 >

Re: [security] only latest Qt 5.14.1 has all fixes

2020-01-28 Thread Artem Tim
Request 768036 (accepted) Qt 5.14.1 - untested, as usual https://build.opensuse.org/request/show/768036 That is all we need to know about how packages updating in openSUSE or something else? ___ devel mailing list -- devel@lists.fedoraproject.org To

[security] only latest Qt 5.14.1 has all fixes

2020-01-28 Thread Damian Ivanov
As mentioned in: https://www.qt.io/blog/qt-5.14.1-released https://www.qt.io/blog/qt-offering-changes-2020 Qt 5.14.1 seems to be the only available Qt version that contains various security fixes for CVE's, after Qt's recent switch of patch handling (for open source only the latest version