Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 704202 - dev-libs/libxml2-2.9.10 version bump
Summary: dev-libs/libxml2-2.9.10 version bump
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Linux Gnome Desktop Team
URL:
Whiteboard:
Keywords: PullRequest
Depends on:
Blocks: CVE-2019-20388, CVE-2020-7595
  Show dependency tree
 
Reported: 2019-12-29 19:01 UTC by Ulenrich
Modified: 2020-07-29 20:55 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ulenrich 2019-12-29 19:01:44 UTC
You can find a new version source at
ftp://xmlsoft.org/libxml2/libxml2-2.9.10.tar.gz

But this is not proper announced at 
http://www.xmlsoft.org/news.html
The last version proper announced there is 2.9.7

As one can read in the current: 
file:////usr/share/doc/libxml2-2.9.9-r2/NEWS.bz2 
---
The change log at
ChangeLog.html
 describes the recents commits
to the GIT at
https://gitlab.gnome.org/GNOME/libxml2
----

Seemingly home has gone to Gnomes gitlab. There you have 
the proper announcement in:
https://gitlab.gnome.org/GNOME/libxml2/-/tags

I don't know if Gentoo should change this mentioned
Homepage:    http://www.xmlsoft.org/
to the gitlab.gnome.org tree of libxml2
???

The same homepage issue is with dev-libs/libxslt:
https://gitlab.gnome.org/GNOME/libxslt/-/tags
Comment 1 Larry the Git Cow gentoo-dev 2020-07-29 20:55:30 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=53ccf8fa1b30f2a7baebd9617de599e3109963b4

commit 53ccf8fa1b30f2a7baebd9617de599e3109963b4
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2020-06-23 11:28:23 +0000
Commit:     Matt Turner <mattst88@gentoo.org>
CommitDate: 2020-07-29 20:55:19 +0000

    dev-libs/libxml2: security bump to 2.0.10, with patches
    
    We bump here to 2.0.10, but include patches up to the upstream commit
    c0440868.
    
    The only modifications made between the git repo from upstream and
    creation of the patchset tarball were removal of any patches which could
    not apply because e.g. they touch files not in the release tarball, or
    were applicable just to fuzzing so not useful here, and git could not
    apply them anyway.
    
    Let's bump to EAPI 7 too, while we're here, to help out the cross
    compilers.
    
    Bug: https://bugs.gentoo.org/710748
    Closes: https://bugs.gentoo.org/719088
    Closes: https://bugs.gentoo.org/704202
    Closes: https://github.com/gentoo/gentoo/pull/16405
    Signed-off-by: Sam James <sam@gentoo.org>
    Signed-off-by: Matt Turner <mattst88@gentoo.org>

 dev-libs/libxml2/Manifest              |   2 +
 dev-libs/libxml2/libxml2-2.9.10.ebuild | 224 +++++++++++++++++++++++++++++++++
 2 files changed, 226 insertions(+)