Re: [OE-core] [kirkstone][PATCH 0/1] Update webkitgtk to 2.38.4 for CVEs

2023-02-22 Thread Alexander Kanavin
The other option is to make a mixin layer, they're meant exactly for backporting version updates that aren't eligible for direct availability. We've done this for pieces like go, docker and the kernel. https://git.yoctoproject.org/meta-lts-mixins/ Alex On Wed, 22 Feb 2023 at 01:59, Kai Kang wrot

Re: [OE-core] [kirkstone][PATCH 0/1] Update webkitgtk to 2.38.4 for CVEs

2023-02-14 Thread Kai Kang
On 2/15/23 00:22, Steve Sakoman wrote: Stable branch policy doesn't allow this type of version upgrade. I can only take upgrades that are strict bug/security fix only releases. The reason that why upgrade webkitgtk directly is that there is no obvious single patch to fix CVEs. It just declares

Re: [OE-core] [kirkstone][PATCH 0/1] Update webkitgtk to 2.38.4 for CVEs

2023-02-14 Thread Steve Sakoman
Stable branch policy doesn't allow this type of version upgrade. I can only take upgrades that are strict bug/security fix only releases. Exceptions to the policy would require TSC approval. Best regards, Steve On Sun, Feb 12, 2023 at 7:50 PM Kai Kang wrote: > > From: Kai Kang > > Update web

[OE-core] [kirkstone][PATCH 0/1] Update webkitgtk to 2.38.4 for CVEs

2023-02-12 Thread Kai Kang
From: Kai Kang Update webkitgtk 2.36.8 to latest version 2.38.4 which solves a lot of CVEs. The diff output of header files is attached at the end of this file. Kai Kang (1): webkitgtk: 2.36.8 -> 2.38.4 ...spection.cmake-prefix-variables-obta.patch | 39 +-- .../0001-Fix-build-without-open