You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi, I am currently porting freej2me to nixpkgs (a linux package repository). Unfortunately, the package is stuck in draft due to the Freeimage dependency, which is littered with CVEs:
Due to the insecure nature of the dependency, it cannot be merged at the current state. I know that freej2me may not have high security concerns as it isn't a critical application, but I think using a freeimage should be avoided in it's current state.
I hope this can mark the start to migrating towards a vulnerability-free graphics library.
The text was updated successfully, but these errors were encountered:
Sigmanificient
changed the title
Freeimage is insecure, consider changing graphics library?
insecure dependency: Freeimage is littered with CVEs
Jul 20, 2024
Hi, I am currently porting
freej2me
to nixpkgs (a linux package repository). Unfortunately, the package is stuck in draft due to theFreeimage
dependency, which is littered with CVEs:Due to the insecure nature of the dependency, it cannot be merged at the current state. I know that freej2me may not have high security concerns as it isn't a critical application, but I think using a freeimage should be avoided in it's current state.
I hope this can mark the start to migrating towards a vulnerability-free graphics library.
The text was updated successfully, but these errors were encountered: