GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Tuesday, 02-Apr-2024 07:25:08 JSTHaelwenn /элвэн/ :triskell:Haelwenn /элвэн/ :triskell:
    in reply to
    • Jakub Jirutka 🇪🇺🇺🇦
    @jakub Rebuilding packages is easy, or at least is with sane package builders, you already need to do this on ABI bumps.
    Static linking also shouldn't be an issue, although you'd have to track which versions where used, you'd need an cleanly isolated environment, distros in the style of gentoo could fail there.

    The real issues are:
    - When language doesn't allows installation of libraries (be it `.so`, `.a` or source) or require strong version pinning: Having to patch a ton of package recipes (with the compatibility issues that can rise from doing so). And third-party packages would be left vulnerable.
    - When vendored: You'd have to somehow find and patch all packages shipping the payload. Basically impossible.

    See log4j where distros just fixed log4shell in a single day but others are likely still shipping vulnerable software.
    In conversationabout a year ago from queer.hacktivis.mepermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.