On Sat, 22 Mar 2014 20:38:49 -0700 Nicholas Breen <nbr...@debian.org> wrote:
> On Sat, Mar 22, 2014 at 04:10:39PM +0000, Neil Williams wrote: > > I'm seeking the removal of pygrace and expeyes so that grace can be > > removed. CC'ing the relevant maintainers (and filing important bugs > > for each package). I expect the removal to start in two weeks > > unless I hear back about a viable solution. > > If just getting standalone t1lib out of the archive is the goal, I > don't mind incorporating all of the existing t1lib patches into the > embedded copy. No. How does that solve the problem of t1lib being abandoned upstream and already superseded by freetype? > As grace is almost exclusively used to plot > locally-supplied numeric data, and is not in any way practical to use > in a network setting, it has minimal security risk vs. some other > former users of t1lib like php5. The security issues were only one part of this - t1lib has been abandoned and superseded. It is unsupportable, as are packages which rely on it. > If getting t1lib in all its forms out of the archive is the goal, > then yes, grace would have to be removed. Rewriting it is not > practical and there doesn't seem to be anyone with the time + desire > + skillset to adopt t1lib. However, there's also no real replacement > for grace itself available. OK, so that is confirmation that grace will have to be removed once t1lib itself is removed and that reverse dependencies of grace like expeyes need to migrate away from grace. -- Neil Williams ============= http://www.linux.codehelp.co.uk/
signature.asc
Description: PGP signature