-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 11/08/2013 04:18 PM, Diego Elio Pettenò wrote: > > On Fri, Nov 8, 2013 at 5:22 AM, "Paweł Hajdan, Jr." > <phajdan...@gentoo.org <mailto:phajdan...@gentoo.org>> wrote: > > Problem #1 is that sci-geosciences/osgearth-2.4 depends on > =dev-lang/v8-3.18.5.14 (see > <https://bugs.gentoo.org/show_bug.cgi?id=484786> for context). It > doesn't work with more recent v8, but it can be made to not depend > on v8. > > > If "made not to depend" means "bundle", is the bundled version any > safer than the ebuild there? If the answer is no, you're now > increasing the security issue. > > Diego Elio Pettenò — Flameeyes flamee...@flameeyes.eu > <mailto:flamee...@flameeyes.eu> — http://blog.flameeyes.eu/
https://github.com/gwaldron/osgearth/issues/333 in short: they kind of forked (I am not sure if there are any major modifications yet) it and do not plan to bundle it there is no release more current than osgearth-2.4, so I am fine with hardmasking/treecleaning osgearth I will not maintain a fork of v8. -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.22 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iQEcBAEBAgAGBQJSfVxtAAoJEFpvPKfnPDWzZ7EH/ib4oZPMLUTYDU0gvkC2NL9o XVvaSdD2lWbAi6ZTwS7RCqygGWoUu5duM4qAOpb/i+KcBgvmXiyDuoOarVFea0PW Si1StRzYf2aVitbdjTqUYlmynX5yiNFvnx5J3knZegzVpm1A9n2Dq2dnIeG7C7zO waWurRsOAdL+XAU3tNot1TepyZwojB3xz3w9k0YtuTTwHRX2vGQ7XM1MOnr9jrOy Is4x5naeau7P4t7Doi5+y9zj5ydshmEHeRm5Upt3DB6JO1WmPdA+8Z4ZmcOLiWUu tBLSqpxSf6TGaUbOop7hNWDWl8ptfrzoSyQjTu6fLHLSo+SMH4qToSEdOlpkqyc= =0K7T -----END PGP SIGNATURE-----