Re: [PATCHES] ImageMagick security updates without grafting

From: Mark H Weaver
Subject: Re: [PATCHES] ImageMagick security updates without grafting
Date: Sat, 27 Mar 2021 20:01:59 -0400

Hi Maxime,

Maxime Devos <> writes:
> This approach (& patches) look good to me.

Thanks for looking.

> What does ‘guix refresh --list-dependent imagemagick@6.9.11-48’
> output now?

When I last checked, it reported on the order of 2400 dependent package

> If it there are many dependent packages, could some
> of them use imagemagick/stable, dblatex/stable or gtk-doc/stable
> as well?

Yes, that's exactly the purpose of this patch set.  Although at present,
the only user of 'imagemagick/stable' is 'dblatex/stable', and the only
user of 'dblatex/stable' is 'gtk-doc/stable'.

> Maybe add a comment to imagemagick/stable on why there is a 
> /stable variant, for future reference.

Good idea.  I added comments similar to what you had suggested.

Thanks for the review!  I went ahead and pushed a revised version of
these commits to 'master', starting with commit
7c2b840d6c586f80fe22a862ce4e362c997559a5, but if anyone has further
input on this approach, it's still not too late to change things.


