Changeset b0a6b0c


Ignore:
Timestamp:
02/25/2022 04:10:04 AM (7 months ago)
Author:
Xi Ruoyao <xry111@…>
Branches:
11.1, 11.2, 11.2-rc1, arm, multilib, s6-init, trunk, xry111/arm64, xry111/clfs-ng, xry111/lfs-next, xry111/queue-11.3
Children:
460f575, 9c12b93, cbd0a9a
Parents:
ba2dc1b
Message:

mention that expat may delete vulnerable releases

Location:
chapter03
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • chapter03/introduction.xml

    rba2dc1b rb0a6b0c  
    1515  versions of the software that are known to work, and this book is based on
    1616  their use. We highly recommend against using different versions because the build
    17   commands for one version may not work with a different version. The newest package
    18   versions may also have problems that require work-arounds. These work-arounds
    19   will be developed and stabilized in the development version of the
    20   book.</para>
     17  commands for one version may not work with a different version, unless the
     18  different version is specified by a LFS errata or security advisory.
     19  The newest package versions may also have problems that require
     20  work-arounds. These work-arounds will be developed and stabilized in the
     21  development version of the book.</para>
    2122
    2223  <para>For some packages, the release tarball and the (Git or SVN)
  • chapter03/packages.xml

    rba2dc1b rb0a6b0c  
    174174        <para>Download: <ulink url="&expat-url;"/></para>
    175175        <para>MD5 sum: <literal>&expat-md5;</literal></para>
     176        <note>
     177          <para>The upstream may remove tarballs of the specific releases of
     178          <application>Expat</application> when these releases contain a
     179          security vulnerability.  You should refer to
     180          <ulink url='&lfs-root;lfs/advisories/'>LFS security advisories</ulink>
     181          to figure out which version (with the vulnerability fixed) should
     182          be used.  You may download the vulnerable version from a mirror,
     183          but it's not recommended.</para>
     184        </note>
    176185      </listitem>
    177186    </varlistentry>
Note: See TracChangeset for help on using the changeset viewer.