Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 490192

Summary: Various dev-dotnet/*-sharp ebuilds require =sys-devel/automake-1.10* despite automake security vulnerability
Product: Gentoo Linux Reporter: Paul McDermott <pmcdermott98>
Component: Current packagesAssignee: dotnet project <dotnet>
Status: RESOLVED FIXED    
Severity: major    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---
Bug Depends on: 489450    
Bug Blocks:    

Description Paul McDermott 2013-11-02 20:41:48 UTC
The following ebuilds require =sys-devel/automake-1.10*

server paul # emerge --depclean -p -v =sys-devel/automake-1.10.3

Calculating dependencies... done!
  sys-devel/automake-1.10.3 pulled in by:
    dev-dotnet/atk-sharp-2.12.10 requires =sys-devel/automake-1.10*, sys-devel/automake
    dev-dotnet/gdk-sharp-2.12.10 requires =sys-devel/automake-1.10*, sys-devel/automake
    dev-dotnet/glade-sharp-2.12.10 requires =sys-devel/automake-1.10*, sys-devel/automake
    dev-dotnet/glib-sharp-2.12.10 requires =sys-devel/automake-1.10*, sys-devel/automake
    dev-dotnet/gtk-sharp-2.12.10 requires sys-devel/automake, =sys-devel/automake-1.10*
    dev-dotnet/gtk-sharp-gapi-2.12.10 requires =sys-devel/automake-1.10*, sys-devel/automake
    dev-dotnet/pango-sharp-2.12.10 requires sys-devel/automake, =sys-devel/automake-1.10*


<=sys-devel/automake-1.11.6 is subject to GLSA 201310-15.

Without this dependancy being resolved, I get a warning message from GLSA every time glsa-check is run (daily, automatically), which I can't do anything about


Reproducible: Always

Steps to Reproduce:
1.Install one or more of the above dev-dotnet/*-sharp ebuilds
2.Run glsa-check
3.
Actual Results:  
glsa-check reports GLSA 201310-15

Expected Results:  
No security vulnerabilities on my system
Comment 1 Pacho Ramos gentoo-dev 2013-11-06 20:00:55 UTC
No idea how base-system will handle this as there are more packages still depending on old slots
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2019-09-22 16:06:39 UTC
These ebuilds have since been fixed and/or are no longer present in the tree.