[Touch-packages] [Bug 1706471] Re: please demote exiv2 to universe
** Changed in: gexiv2 Status: Confirmed => Expired -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to exiv2 in Ubuntu. https://bugs.launchpad.net/bugs/1706471 Title: please demote exiv2 to universe Status in gexiv2: Expired Status in exiv2 package in Ubuntu: Triaged Bug description: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) Thanks To manage notifications about this bug go to: https://bugs.launchpad.net/gexiv2/+bug/1706471/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp
[Touch-packages] [Bug 1706471] Re: please demote exiv2 to universe
Unsubscribing ~ubuntu-archive, this is up to the desktop team to choose to remove from their seeds and, if they do, our magic reports will tell us to demote, we don't need a bug for that. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to exiv2 in Ubuntu. https://bugs.launchpad.net/bugs/1706471 Title: please demote exiv2 to universe Status in gexiv2: Confirmed Status in exiv2 package in Ubuntu: Triaged Bug description: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) Thanks To manage notifications about this bug go to: https://bugs.launchpad.net/gexiv2/+bug/1706471/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp
[Touch-packages] [Bug 1706471] Re: please demote exiv2 to universe
** Changed in: gexiv2 Status: Unknown => Confirmed ** Changed in: gexiv2 Importance: Unknown => Medium -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to exiv2 in Ubuntu. https://bugs.launchpad.net/bugs/1706471 Title: please demote exiv2 to universe Status in gexiv2: Confirmed Status in exiv2 package in Ubuntu: Triaged Bug description: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) Thanks To manage notifications about this bug go to: https://bugs.launchpad.net/gexiv2/+bug/1706471/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp
[Touch-packages] [Bug 1706471] Re: please demote exiv2 to universe
Thank you! ** Project changed: exiv2 => gexiv2 ** Changed in: exiv2 (Ubuntu) Status: Incomplete => Triaged -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to exiv2 in Ubuntu. https://bugs.launchpad.net/bugs/1706471 Title: please demote exiv2 to universe Status in gexiv2: Unknown Status in exiv2 package in Ubuntu: Triaged Bug description: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) Thanks To manage notifications about this bug go to: https://bugs.launchpad.net/gexiv2/+bug/1706471/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp
[Touch-packages] [Bug 1706471] Re: please demote exiv2 to universe
Good idea Jeremy; https://bugzilla.gnome.org/show_bug.cgi?id=785547 (heh, launchpad called it 'exiv2' when I linked them together. Oh well.) Thanks ** Bug watch added: GNOME Bug Tracker #785547 https://bugzilla.gnome.org/show_bug.cgi?id=785547 ** Also affects: exiv2 via https://bugzilla.gnome.org/show_bug.cgi?id=785547 Importance: Unknown Status: Unknown -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to exiv2 in Ubuntu. https://bugs.launchpad.net/bugs/1706471 Title: please demote exiv2 to universe Status in Exiv2: Unknown Status in exiv2 package in Ubuntu: Incomplete Bug description: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) Thanks To manage notifications about this bug go to: https://bugs.launchpad.net/exiv2/+bug/1706471/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp
[Touch-packages] [Bug 1706471] Re: please demote exiv2 to universe
Thank you for taking the time to report this bug and helping to make Ubuntu better. The issue you are reporting is an upstream one and it would be nice if somebody having it could send the bug to the developers of the software by following the instructions at https://wiki.ubuntu.com/Bugs/Upstream/GNOME. If you have done so, please tell us the number of the upstream bug (or the link), so we can add a bugwatch that will inform us about its status. Thanks in advance. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to exiv2 in Ubuntu. https://bugs.launchpad.net/bugs/1706471 Title: please demote exiv2 to universe Status in exiv2 package in Ubuntu: Incomplete Bug description: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) Thanks To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp
[Touch-packages] [Bug 1706471] Re: please demote exiv2 to universe
Yes, but could you file a bug or whatever upstream? Also, you should probably talk to the Desktop team about your concerns before asking the Archive Admins to demote a Desktop package. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to exiv2 in Ubuntu. https://bugs.launchpad.net/bugs/1706471 Title: please demote exiv2 to universe Status in exiv2 package in Ubuntu: Incomplete Bug description: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) Thanks To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp
[Touch-packages] [Bug 1706471] Re: please demote exiv2 to universe
I'm not saying it's not useful. The point is that the library that we're using for Exif metadata is unsuited for use on a modern desktop operating system or server connected to the Internet. The maintainer doesn't want to put in the work to take it from a fun hobby to a production-grade tool. I can understand that, and I'm even sympathetic that it was used more widely than it should have been. That's not his fault. But we have millions of users who expect us to protect them against drive-by downloads that own their desktops and server administrators who expect to use the tools we provide to build safe services for their users in turn. Ideally shotwell would be able to degrade service gracefully until someone cares enough to write a safe Exif library. Less ideal would be to demote shotwell until this is addressed. Thanks -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to exiv2 in Ubuntu. https://bugs.launchpad.net/bugs/1706471 Title: please demote exiv2 to universe Status in exiv2 package in Ubuntu: Incomplete Bug description: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) Thanks To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp
[Touch-packages] [Bug 1706471] Re: please demote exiv2 to universe
shotwell doesn't build without libgexiv2-dev. I assume you're aware that showing Exif information is very useful for a photo app. Are there any other libraries you suggest instead of exiv2? Please discuss your concerns with the shotwell and gexiv2 maintainer - I believe they are the same person. :) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to exiv2 in Ubuntu. https://bugs.launchpad.net/bugs/1706471 Title: please demote exiv2 to universe Status in exiv2 package in Ubuntu: Incomplete Bug description: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) Thanks To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp
[Touch-packages] [Bug 1706471] Re: please demote exiv2 to universe
I certainly hope that shotwell's dependency can be disabled at build time. Thanks -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to exiv2 in Ubuntu. https://bugs.launchpad.net/bugs/1706471 Title: please demote exiv2 to universe Status in exiv2 package in Ubuntu: Incomplete Bug description: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) Thanks To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp
[Touch-packages] [Bug 1706471] Re: please demote exiv2 to universe
shotwell depends on libgexiv2-2 which depends on libexiv2-14 So, um how would you fix that? ** Changed in: exiv2 (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to exiv2 in Ubuntu. https://bugs.launchpad.net/bugs/1706471 Title: please demote exiv2 to universe Status in exiv2 package in Ubuntu: Incomplete Bug description: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) Thanks To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp
[Touch-packages] [Bug 1706471] Re: please demote exiv2 to universe
** Description changed: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. - $ reverse-depends src:exiv2 - Reverse-Recommends - == - * geeqie(for exiv2) - + $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === - * cameraplugin-aal [amd64 arm64 armhf i386] (for libexiv2-14) - * darktable [amd64 arm64] (for libexiv2-14) - * decopy(for exiv2) - * digikam-private-libs (for libexiv2-14) - * ffdiaporama (for libexiv2-14) - * forensics-extra (for exiv2) - * gallery-app (for libexiv2-14) - * geeqie(for libexiv2-14) - * gimp-lensfun (for libexiv2-14) - * gimp-ufraw(for libexiv2-14) - * gnome-color-manager (for libexiv2-14) - * gnome-commander (for libexiv2-14) - * gpscorrelate (for libexiv2-14) - * gpscorrelate-gui (for libexiv2-14) - * gthumb(for libexiv2-14) - * gwenview (for libexiv2-14) - * hugin (for libexiv2-14) - * hugin-tools (for libexiv2-14) - * kde-runtime (for libexiv2-14) - * kio-extras(for libexiv2-14) - * kphotoalbum (for libexiv2-14) - * krename (for libexiv2-14) - * krita [amd64 i386 ppc64el s390x] (for libexiv2-14) - * libextractor3 (for libexiv2-14) * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) - * libkexiv2-11v5(for libexiv2-14) - * libkf5filemetadata-bin(for libexiv2-14) - * libkf5kexiv2-15.0.0 (for libexiv2-14) - * libkfilemetadata4 (for libexiv2-14) - * libmyth-0.28-0(for libexiv2-14) - * libnomacsloader3 (for libexiv2-14) - * libstreamanalyzer0v5 (for libexiv2-14) - * luminance-hdr (for libexiv2-14) - * merkaartor(for libexiv2-14) - * pdf2djvu (for libexiv2-14) - * phototonic(for libexiv2-14) - * pinot (for libexiv2-14) - * python-pyexiv2(for libexiv2-14) - * qtdeclarative5-ubuntu-ui-extras0.2 (for libexiv2-14) - * rapid-photo-downloader(for exiv2) - * ufraw (for libexiv2-14) - * ufraw-batch (for libexiv2-14) - * viewnior (for libexiv2-14) Thanks -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to exiv2 in Ubuntu. https://bugs.launchpad.net/bugs/1706471 Title: please demote exiv2 to universe Status in exiv2 package in Ubuntu: New Bug description: Hello, Please consider demoting exiv2 to universe. http://dev.exiv2.org/issues/1248 The upstream author appears overwhelmed with the task of hardening exiv2 for use against untrusted inputs and thus far (~nine months) no users have provided the project with patches against known issues. $ reverse-depends -c main -r artful src:exiv2 Reverse-Depends === * libgexiv2-2 (for libexiv2-14) * libgexiv2-dev (for libexiv2-dev) Thanks To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp