Miroslav Lichvar wrote:

> FWIW, considering how much code has changed since 1.3.0,

I don't think very much has changed. The biggest changes are Martin's
new apodization window changes.

> I'd rather
> see the security bug fixed in a new 1.3.0 release,

Err, no, rolling a new release with the same number as the old
release is a bad idea.

> maybe with some
> other serious bugs like the metaflac memory corruction, and have a
> prerelease for 1.3.1 to test it thoroughly.

So, you want the two CVEs fixed, plus the metaflac memory corruption
fix, but want to leave behind the numerous build system improvements?

> I know the new release is almost ready, but if some serious bug is
> found in 1.3.1, a new release will have to be made anyway to not force
> the users to the vulnerable version.

The new release has been ready for some time. ALl that was missing was
me to have some spare time to start the process. As lvqcl noted back
in October, Foobar2000 shipped with a git version of FLAC.

Erik
-- 
----------------------------------------------------------------------
Erik de Castro Lopo
http://www.mega-nerd.com/
_______________________________________________
flac-dev mailing list
flac-dev@xiph.org
http://lists.xiph.org/mailman/listinfo/flac-dev

Reply via email to