Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Updated xz to 5.4.6 #7916

Draft
wants to merge 1 commit into
base: main
Choose a base branch
from
Draft

Updated xz to 5.4.6 #7916

wants to merge 1 commit into from

Conversation

radarhere
Copy link
Member

@nulano
Copy link
Contributor

nulano commented Mar 30, 2024

I'm assuming you are aware of CVE-2024-3094 and didn't upgrade to 5.6.1 for that reason. Perhaps it is an overreaction at this point, but I'm wondering if we should consider completely removing liblzma from the wheels for the upcoming release. liblzma is only an indirect optional dependency via libtiff and users could just install from source if they need it.

@wiredfool
Copy link
Member

Yes, we're aware. I'd like to hold off on merging this until more clarity comes out of this from the experts. Xz is deeply in use in debian (e.g. dpkg) so they're digging pretty heavily now (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024).

@hugovk hugovk marked this pull request as draft March 30, 2024 20:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants