So, a) there's a libexpat security release: github.com/libexpat/libexpat/r

and b) the writeup on the security issue and how the resources to fix it were gathered is *really* good!
blog.hartwork.org/posts/expat-

Follow

@Bubu A very nice write up, I like the approach. I think the key is that he simply asked them for support. Lots of FOSS devs don't want to ask, I know that from myself. Asking for donations, or even nagging, is well know to work. Like Wikipedia. I wonder if it would be possible to eliminate the friction to donating so much that FOSS devs could make a living without having to learn how to run fundraising campaigns? Maybe it just isn't possible.

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml