Hi Mark,

> rek...@elephly.net (Ricardo Wurmus) writes:
>
>> rekado pushed a commit to branch core-updates
>> in repository guix.
>>
>> commit 53e66fbceb275262184ad44f60a5a8d4e7061fcb
>> Author: Ricardo Wurmus <rek...@elephly.net>
>> Date:   Thu Apr 12 20:37:54 2018 +0200
>>
>>     gnu: gnucash: Update to 3.0.
>
> This commit removes the last reference to 'webkitgtk/gtk+-2', which in
> turn contains the only reference to 'webkitgtk-2.4'.  So, we could now
> delete both of those packages from the 'core-updates' branch.
>
> I would advocate removing them, since these old versions of webkitgtk
> are no longer maintained and contain a large number of known remote code
> execution vulnerabilities.
>
> Are there any objections to removing them?

No objections from me; please go ahead and remove them.  Thanks!

--
Ricardo


Reply via email to