Package: python-wxgtk-webview3.0 Version: 3.0.2.0+dfsg-4 Severity: serious Tags: sid buster User: [email protected] Usertags: oldlibs libwebkitgtk-1.0-0 webkit1
python-wxgtk-webview3.0 depends on libwxgtk-webview3.0-0v5 which depends on libwxgtk-webview3.0-0v5 which depends on libwebkitgtk-1.0-0. libwebkitgtk-1.0-0 is the old webkitgtk library that suffers from many reported CVEs that have been fixed in libwebkit2gtk-4.0-37 (src: webkit2gtk ). We do not intend to release Debian 10 "Buster" with libwebkitgtk-1.0-0. python-wxgtk-webview3.0 has no reverse dependencies in Debian or Ubuntu so it seems easy to just stop building this package for now. See also https://bugs.debian.org/790222 for the RC bug for wxwidgets3.0. On behalf of the Debian WebKit maintainers, Jeremy Bicha

