bug#56895: rust-brotli-sys bundles (insecure!) brotli

2022-08-02 Thread Maxime Devos
Friendly reminder to the original patch author and committer (*) to check for bundling during review. (*) https://git.savannah.gnu.org/cgit/guix.git/commit/?id=52cc16b38b1b01b2bb354ed5510120856de15d39 Greetings, Maxime. OpenPGP_0x49E3EE22191725EE.asc Description: OpenPGP public key OpenPG

bug#56895: rust-brotli-sys bundles (insecure!) brotli

2022-08-02 Thread Maxime Devos
I noticed rust-brotli-sys bundles brotli: . The version it bundles is apparently insecure: As mentioned at , there