[Buildroot] [PATCH 1/2] package/mcrypt: drop package

Yann E. MORIN yann.morin.1998 at free.fr
Thu Aug 19 21:58:14 UTC 2021


Fabrice, All,

On 2021-08-19 23:21 +0200, Fabrice Fontaine spake thusly:
> Le jeu. 19 août 2021 à 23:05, Thomas Petazzoni
> <thomas.petazzoni at bootlin.com> a écrit :
> >
> > Hello Fabrice,
> >
> > On Thu,  5 Aug 2021 19:42:51 +0200
> > Fabrice Fontaine <fontaine.fabrice at gmail.com> wrote:
> >
> > > Drop mcrypt which is not maintained anymore (no release since 2008).
[--SNIP--]
> > Do we have a good reason to drop these packages? We have lots of
> > packages with no upstream activity, and we drop them only when there is
> > some particular issue. What prompted you to propose these packages for
> > removal ?
> Because it is a cryptographic package, here is an extract of
> https://en.wikipedia.org/wiki/Mcrypt:
> "The last update to libmcrypt was in 2007, despite years of unmerged
> patches. These facts have led security experts to declare mcrypt
> abandonware and discourage its use in new development."

OK, with such explanations, that makes sense.

Can you please resubmit both patches with tese in the commit log?

Regards,
Yann E. MORIN.

-- 
.-----------------.--------------------.------------------.--------------------.
|  Yann E. MORIN  | Real-Time Embedded | /"\ ASCII RIBBON | Erics' conspiracy: |
| +33 662 376 056 | Software  Designer | \ / CAMPAIGN     |  ___               |
| +33 561 099 427 `------------.-------:  X  AGAINST      |  \e/  There is no  |
| http://ymorin.is-a-geek.org/ | _/*\_ | / \ HTML MAIL    |   v   conspiracy.  |
'------------------------------^-------^------------------^--------------------'


More information about the buildroot mailing list