Hi

I intend to orphan freeimage. Probably, the package should rather just be retired. Upstream is effectively dead, and there is a constant stream of CVEs getting filed against the package which are not addressed upstream. Over the past two years I've fixed many of those CVEs downstream, but the most recent batch of 15 CVEs is leading me to capitulate. Currently, the following packages require freeimage:

PerceptualDiff
allegro5
cegui06
deepin-image-viewer
gazebo
imv
ogre
photoqt

A minimal impact check:

PerceptualDiff: freeimage is a hard dependency. PerceptualDiff itself has seen its last commit 4 years ago, last release 8 years ago
allegro5: freeimage is an optional dependency
cegui06: freeimage is an optional dependency
deepin-image-viewer: freeimage is a hard dependency
gazebo: freeimage is a hard dependency. (The fedora package is for "gazebo-classic" https://github.com/gazebosim/gazebo-classic, which points to https://github.com/gazebosim/gz-sim as the "latest version", which does not appear to require freeimage)
imv: freeimage is an optional dependency
ogre: freeimage is an optional dependency
photoqt: freeimage is an optional dependency

Thanks

Sandro



--
_______________________________________________
devel mailing list -- devel@lists.fedoraproject.org
To unsubscribe send an email to devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to