guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Handling ‘file’ CVE


From: Ludovic Courtès
Subject: Re: Handling ‘file’ CVE
Date: Thu, 13 Nov 2014 17:54:52 +0100
User-agent: Gnus/5.13 (Gnus v5.13) Emacs/24.4 (gnu/linux)

address@hidden (Ludovic Courtès) skribis:

> What about this other option: make another public package, ‘file-5.20’,
> next to ‘file’, such that when a user explicitly installs ‘file’, they
> get the new one?

I ended up taking that route, in commit 310081e.

The replacement caused too much churn on Hydra.  Furthermore, it led to
a serious increase in the installation image size, because several
variants of a number of packages were present, and because
‘guix-register -p’ doesn’t deduplicate things.

Ludo’.



reply via email to

[Prev in Thread] Current Thread [Next in Thread]