Bug#777608: zenity: depends on libwebkitgtk which doesn't have security support

Török Edwin edwin at etorok.net
Tue Feb 10 16:22:52 UTC 2015


Package: zenity
Version: 3.14.0-1
Severity: normal

Dear Maintainer,

   * What led up to the situation?

     Install debian-security-support package and try to remove the packages
     that don't have security support.

   * What exactly did you do (or not do) that was effective (or
     ineffective)?

    $ check-support-status
    * Source:webkitgtk
      Details: No security support upstream and backports not feasible, only for
      use on trusted content
      Affected binary packages:
        - libjavascriptcoregtk-3.0-0:amd64 (installed version: 2.4.8-1)
        - libwebkitgtk-3.0-0:amd64 (installed version: 2.4.8-1)
        - libwebkitgtk-3.0-common (installed version: 2.4.8-1)
    # apt-get purge libwebkitgtk-3.0-0

   * What was the outcome of this action?

   The following packages will be REMOVED:
     libwebkitgtk-3.0-0* marco* mate-desktop-environment*
     mate-desktop-environment-core* mate-media* mate-media-pulse*
     task-mate-desktop* zenity*
     The following NEW packages will be installed:
       mate-media-gstreamer

   * What outcome did you expect instead?

   The desktop environment to stay installed.
   MATE, Cinnamon (and Gnome too) depend on zenity, which depends on libwebkitgtk-3.0-0.

   FWIW KDE depends on kdelibs4, where check-security-support complains about
   khtml. I haven't checked XFCE and LXDE.

   I see that zenity has a configure flag to enable/disable webkit support,
   would it be possible to provide a zenity-nohtml package that would
   "Provides: zenity" so I can keep my *DE installed without depending on a package that has
   no security support?
   (Or have a zenity-html and zenity-nohtml package both providing the virtual
   zenity package, and using recommends somehow to choose the html version by
   default?)


-- System Information:
Debian Release: 8.0
  APT prefers testing-updates
  APT policy: (500, 'testing-updates'), (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.16.0-4-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)

Versions of packages zenity depends on:
ii  libc6               2.19-13
ii  libgdk-pixbuf2.0-0  2.31.1-2+b1
ii  libglib2.0-0        2.42.1-1
ii  libgtk-3-0          3.14.5-1
ii  libnotify4          0.7.6-2
ii  libpango-1.0-0      1.36.8-3
ii  libwebkitgtk-3.0-0  2.4.8-1
ii  libx11-6            2:1.6.2-3
ii  zenity-common       3.14.0-1

zenity recommends no packages.

zenity suggests no packages.

-- no debconf information




More information about the pkg-gnome-maintainers mailing list