Change History (7)
comment:1 by , 13 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 13 months ago
comment:5 by , 12 months ago
Changes
Version 1.1.1
Features:
- Add option to disable man page creation
Bugfixes:
- Add explicit UTF-8 tests to check for libfyaml's unicode handling
- yaml: Drop implicit string quoting, make it explicit
Miscellaneous:
- qt: Drop support for Qt5
Version 1.1.0
Notes:
- This release switches to libfyaml for YAML parsing. This allows us to support YAML 1.2 and limit parsing to it, enables better JSON parsing, and lower peak memory use when processing YAML. It also allows for future memory optimizations. Parsing a more restricted set of YAML may also help security.
- This release also seals some internal libappstream-compose API that was public for a while for use by appstream-generator. It has no users anymore and should not have been public. This is one step closer to declaring the compose C API stable as well.
Features:
- Port YAML parsing to libfyaml
- Port YAML emission to libfyaml
- compose: Port to libfyaml
- yaml: Reduce string copies when comparing main keys, compare lengths first
- yaml: Reduce copies when filling locale tables and string list
- compose: Add support for JPEG-XL
- compose: Make the AscImage API more generic
- compose: Seal away all GdkPixbuf and AscCanvas references from public API
Bugfixes:
- validator: Fix possible double dereference of the same issue instance
- tests: Pass tests with older versions of libfyaml
- Fix a few double-free issues in error conditions
- compose: Fix possible race condition when fetching pangrams
- compose: Draw better background shapes and center text properly for font icons
- parser: Guard against "tag" elements with NULL values
- yaml: Allow duplicate keys when parsing data (speeds up parsing dramatically)
- cache: Fix potential use-after-free issue when counting components
Miscellaneous:
- Update
COPYINGwith latest from FSF - Update
GPL-2.0.txtwith latest from FSF - compose: Prefer
intoveruinteverywhere in AscImage API
comment:6 by , 12 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 066bce9e88142b522849a411f4d26502f7576148.
Note:
See TracTickets
for help on using tickets.

This release will require the addition of libfyaml (not to be confused with libyaml). This is done for added security and to utilize the YAML 1.2 specification. Specifically, it limits parsing to just 1.2. Using libyaml is no longer an option.
libfyaml seems to be a pretty simple package addition.