Re: Fwd: Ophaning lcms(1)

2014-06-04 Thread Sérgio Basto
On Ter, 2014-06-03 at 08:54 -0500, Jon Ciesla wrote: Ther inkscape (maintained by: limb, duffy, lkundrak) inkscape-0.48.4-16.fc21.src requires lcms-devel = 1.19-11.fc21 rawstudio (maintained by: giallu) Hi, rawstudio is a little unmaintained

Re: Fwd: Ophaning lcms(1)

2014-06-03 Thread Hans de Goede
Hi, On 06/02/2014 10:39 PM, Nicolas Chauvet wrote: Hello, I'm orphaning lcms, this package has seen few security issue and upstream claim it's deprecated over lcms2 rhel 7 doesn't depends on it for the few package, so it might be an option not to build lcms support for certain package

Re: Fwd: Ophaning lcms(1)

2014-06-03 Thread Daniel P. Berrange
On Mon, Jun 02, 2014 at 10:39:56PM +0200, Nicolas Chauvet wrote: Hello, I'm orphaning lcms, this package has seen few security issue and upstream claim it's deprecated over lcms2 # repoquery --whatrequires liblcms.so.1 --source entangle-0.5.3-2.fc20.src.rpm FYI the repo you're pointing

Re: Fwd: Ophaning lcms(1)

2014-06-03 Thread Sandro Mani
On 02.06.2014 23:07, Toshio Kuratomi wrote: On Mon, Jun 02, 2014 at 10:39:56PM +0200, Nicolas Chauvet wrote: python-pillow-2.2.1-4.fc20.src.rpm This one can be fixed by upgrading to 2.3.0 (or greater. 2.4.0 is current). 2.4.0 is what's in rawhide. Not sure if that's safe to push back to

Re: Fwd: Ophaning lcms(1)

2014-06-03 Thread Jon Ciesla
On Mon, Jun 2, 2014 at 5:23 PM, Till Maas opensou...@till.name wrote: On Mon, Jun 02, 2014 at 10:39:56PM +0200, Nicolas Chauvet wrote: # repoquery --whatrequires liblcms.so.1 --source cinepaint-1.4-5.fc20.src.rpm cmyktool-0.1.6-0.6.pre1.fc20.src.rpm DevIL-1.7.8-16.fc20.src.rpm

Re: Fwd: Ophaning lcms(1)

2014-06-03 Thread Toshio Kuratomi
https://apps.fedoraproject.org/packages/lcms/bugs/all lists a CVE. If lcms-11 is no longer going to be maintained in Fedora that (and any other) security flaws won't be addressed. It's therefore advisable for them to update to the new version of lcms if feasible. The affected packager would

Re: Fwd: Ophaning lcms(1)

2014-06-03 Thread Sandro Mani
On 03.06.2014 23:20, Toshio Kuratomi wrote: https://apps.fedoraproject.org/packages/lcms/bugs/all lists a CVE. If lcms-11 is no longer going to be maintained in Fedora that (and any other) security flaws won't be addressed. It's therefore advisable for them to update to the new version of

Fwd: Ophaning lcms(1)

2014-06-02 Thread Nicolas Chauvet
Hello, I'm orphaning lcms, this package has seen few security issue and upstream claim it's deprecated over lcms2 rhel 7 doesn't depends on it for the few package, so it might be an option not to build lcms support for certain package # repoquery --whatrequires liblcms.so.1 --source

Re: Fwd: Ophaning lcms(1)

2014-06-02 Thread Toshio Kuratomi
On Mon, Jun 02, 2014 at 10:39:56PM +0200, Nicolas Chauvet wrote: python-pillow-2.2.1-4.fc20.src.rpm This one can be fixed by upgrading to 2.3.0 (or greater. 2.4.0 is current). 2.4.0 is what's in rawhide. Not sure if that's safe to push back to f20 and earlier. (Although I see that there's an

Re: Fwd: Ophaning lcms(1)

2014-06-02 Thread Till Maas
On Mon, Jun 02, 2014 at 10:39:56PM +0200, Nicolas Chauvet wrote: # repoquery --whatrequires liblcms.so.1 --source cinepaint-1.4-5.fc20.src.rpm cmyktool-0.1.6-0.6.pre1.fc20.src.rpm DevIL-1.7.8-16.fc20.src.rpm entangle-0.5.3-2.fc20.src.rpm f-spot-0.8.2-11.fc20.src.rpm