[Secure-testing-team] #464770 Should probably build-depend on libpng-dev?
Axel Beckert
abe at debian.org
Sun Mar 7 16:32:56 UTC 2010
retitle 464770 wml: Should not use embedded libgd copy or build-depend on libpng-dev
kthxbye
Hi,
djpig wrote:
> If libpng-dev is present, the resulting binary package will depend
> on it. Which probably means that it should be build-depended upon
> (or the PNG support should be explicetly disabled).
This seems due to a embedded and modified copy of libgd 1.6.3 inside
WML.
That code has been embedded and modified because of GD's upstream
decided to remove GIF support because of potential patent issues.
Which is no more the case for a few years now anyway. So I would
expect current libgd versions can generate GIF as well as PNG again.
I'll check if I can easily replace the embedded code copy with any of
the libgd2* packages as dependency.
Cc to the security testing team, see
https://wiki.debian.org/EmbeddedCodeCopies
Regards, Axel
--
,''`. | Axel Beckert <abe at debian.org>, http://people.debian.org/~abe/
: :' : | Debian Developer, ftp.ch.debian.org Admin
`. `' | 1024D: F067 EA27 26B9 C3FC 1486 202E C09E 1D89 9593 0EDE
`- | 4096R: 2517 B724 C5F6 CA99 5329 6E61 2FF9 CD59 6126 16B5
More information about the Secure-testing-team
mailing list