|
From: | Jean Abou Samra |
Subject: | Re: 64-bit Guile on Windows |
Date: | Wed, 6 Jul 2022 18:33:36 +0200 |
User-agent: | Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.11.0 |
On 6/28/22 12:52, Maxime Devos wrote:
Jean Abou Samra schreef op di 28-06-2022 om 10:38 [+0200]:We had exactly the same problem at LilyPond, and this was the fix: https://gitlab.com/lilypond/lilypond/-/blob/master/release/binaries/lib/dependencies.py#L721For security, shouldn't this check the hash of the downloaded tarballls and patches?
Sorry, I forgot to reply to this. Yes, it likely should. On the otherhand, LilyPond has a lot of much more pressing security issues to care about…
Jean
[Prev in Thread] | Current Thread | [Next in Thread] |