Skip to content

[liblzma] update to version 5.4.4#34306

Merged
BillyONeal merged 1 commit intomicrosoft:masterfrom
carsten-grimm:liblzma-5.4.4
Oct 9, 2023
Merged

[liblzma] update to version 5.4.4#34306
BillyONeal merged 1 commit intomicrosoft:masterfrom
carsten-grimm:liblzma-5.4.4

Conversation

@carsten-grimm
Copy link
Copy Markdown
Contributor

Fixes #34305.

  • Changes comply with the maintainer guide
  • SHA512s are updated for each updated download
  • The "supports" clause reflects platforms that may be fixed by this new version
  • Any fixed CI baseline entries are removed from that file.
  • Any patches that are no longer applied are deleted from the port's directory.
  • The version database is fixed by rerunning ./vcpkg x-add-version --all and committing the result.
  • Only one version is added to each modified port's versions file.

@carsten-grimm carsten-grimm marked this pull request as ready for review October 7, 2023 01:14
@FrankXie05 FrankXie05 added the category:port-update The issue is with a library, which is requesting update new revision label Oct 7, 2023
@FrankXie05 FrankXie05 added the info:needs-maintainer-attention Lets the current 'on rotation' vcpkg maintainer know they need to look at this. label Oct 7, 2023
@BillyONeal BillyONeal merged commit 8e8f057 into microsoft:master Oct 9, 2023
@BillyONeal
Copy link
Copy Markdown
Member

Thanks for the update!

clementperon pushed a commit to clementperon/vcpkg that referenced this pull request Oct 16, 2023
@Neustradamus
Copy link
Copy Markdown

@carsten-grimm: Can you update to 5.6.0?

I have done a ticket here:

Note: There was a 5.4.5 too.

Thanks in advance.

@Neustradamus
Copy link
Copy Markdown

Warning, some people attack me because I have requested the XZ update.
I am not linked to the XZ project.

@carsten-grimm
Copy link
Copy Markdown
Contributor Author

Warning, some people attack me because I have requested the XZ update. I am not linked to the XZ project.

@Neustradamus , I hope you did not mistake my post as an attack. It was never meant as such. I was/am worried that you might be affected by the backdoor and need to take measures on your end.

If you meant that somebody else was attacking you, then that is just silly. They might as well attack me for updating the version here without noticing a backdoor that was not even directly included in the source code from what I understand.

@Neustradamus
Copy link
Copy Markdown

@carsten-grimm: No problem with you!

I have received (and have seen several messages) against me because I have requested the liblzma/XZ update with the backdoor.

Some people are really not correct and mix all.

Since a very long time, I do announcements of new project releases and at the same time, I request updates...

I have done the CVE-2024-3094 announcement and specified to quickly revert.

I repeat to all, I am not linked with XZ project.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

category:port-update The issue is with a library, which is requesting update new revision info:needs-maintainer-attention Lets the current 'on rotation' vcpkg maintainer know they need to look at this.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[liblzma] update to 5.4.4

4 participants