Another benefit is we can only track security vulnerabilities in the bundled libraries if we know that they exist. In Fedora, we declare bundled libraries using RPM Provides, then Red Hat Product Security can consider those provides when searching for affected packages. A human (me) has to know and add the Provides. I didn't know about simde until the build started failing earlier this year.

I didn't know simdutf until: https://blogs.gnome.org/chergert/2024/10/01/utf-8-validation-performance/

Probably there are more bundled libraries that I don't know about!

Michael


_______________________________________________
webkit-dev mailing list
webkit-dev@lists.webkit.org
https://lists.webkit.org/mailman/listinfo/webkit-dev

Reply via email to