Hello Simon,

On 2026-10-08 16:50, Simon Tournier wrote:

Hi release team,

Roaming on the old bug tracker (bug#35301), it reminds me:

27e6ec957a2371be8743fed51fc503ba0c6eba6c
CommitDate: Sat Feb 25 18:00:39 2023 +0100

gnu: Remove eolie.

The package has not seen a new release in more than two years.
It depends on the cryptography library python-pycrypto, which has had
its last release in 2013 and "is unmaintained, obsolete, and contains
security vulnerabilities" according to its homepage.

* gnu/packages/gnome.scm (eolie): Delete variable.

and the current manual reads:

--8<---------------cut here---------------start------------->8---
@cindex certificates
Another typical use case for containers is to run security-sensitive
applications such as a web browser.  To run Eolie, we must expose and
share some files and directories; we include @code{nss-certs} and expose @file{/etc/ssl/certs/} for HTTPS authentication; finally we preserve the
@env{DISPLAY} environment variable since containerized graphical
applications won't display without it.

@example
guix environment --preserve='^DISPLAY$' --container --network \
--expose=/etc/machine-id \
--expose=/etc/ssl/certs/ \
--share=$HOME/.local/share/eolie/=$HOME/.local/share/eolie/ \
--ad-hoc eolie nss-certs dbus --  eolie
@end example
--8<---------------cut here---------------end--------------->8---

Therefore, it could be nice to fix the manual before the next
release. :-)

Cheers,
simon

It would be interesting to purge all no longer secure packages (Im sure there would be more).

It would be interesting to form an overview over this, just so were a major insecurity discovered that it would be possible to immediately know what should be removed or (re)edited.

Incase I have the time to look around are there any non obvious areas to look?

Kind regards,


Jonathan

Reply via email to