Once upon a time, Michael Catanzaro <[email protected]> said:
> On Tue, Apr 29 2025 at 11:00:18 AM -05:00:00, Chris Adams
> <[email protected]> wrote:
> >I'm asking because there's a high-priority CVE on openh264 for months
> >that doesn't seem like it's progressing towards getting resolved in
> >Fedora.
> 
> For context on this, see: https://pagure.io/releng/issue/12617

So it's been another month and this still isn't resolved.  I know people
on the Fedora side have been trying (don't want to complain about
effort).  But if Fedora can't reliably get timely updates to a package
that has high security implications, it should NOT be enabled by
default, or even shipped by Fedora at all.

-- 
Chris Adams <[email protected]>
-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to