Re: [SECURITY] Which packages bundle sqlite?

2018-12-17 Thread Mark H Weaver
Hi Alex, This issue is being tracked at , so it would be best to send followups regarding this issue to <33...@debbugs.gnu.org>. Alex Vong writes: > I also want to know should we graft in this case since updating sqlite > would cause ~4000s rebuilts. Yes, it should

Re: [SECURITY] Which packages bundle sqlite?

2018-12-17 Thread Alex Vong
I also want to know should we graft in this case since updating sqlite would cause ~4000s rebuilts. Besides, how to deal with packages that inherit sqlite when grafting? (e.g. sqlite-with-fts5 and sqlite-with-column-metadata) Thanks, Alex Alex Vong writes: > Hello Guix, > > Recently, a remote

[SECURITY] Which packages bundle sqlite?

2018-12-17 Thread Alex Vong
Hello Guix, Recently, a remote execution vulnerability is discovered in sqlite[0][1]. Apart from updating the sqlite package, I think we need to update all packages bundling sqlite as well. What do you think? Cheers, Alex [0]: https://blade.tencent.com/magellan/index_en.html [1]: