[Buildroot] package/expat: please backport to 2021.11.x

Thomas Petazzoni thomas.petazzoni at bootlin.com
Tue Feb 22 08:32:46 UTC 2022


On Mon, 21 Feb 2022 21:21:16 -0800
Christian Stewart <christian at paral.in> wrote:

> Expat v2.4.4 (vulnerable) download has been removed from sourceforge.
> 
> So 2021.11.x build is broken with the older expat.

This is strange: if the expat tarball is no longer available from
sourceforge, Buildroot should fallback to sources.buildroot.net, which
contains the expat-2.4.4.tar.xz tarball, at
http://sources.buildroot.net/expat/.

Of course, it is better to update since there is a security issue in
2.4.4, but I'm wondering why you're saying that the build is broken: it
should not.

Best regards,

Thomas
-- 
Thomas Petazzoni, co-owner and CEO, Bootlin
Embedded Linux and Kernel engineering and training
https://bootlin.com



More information about the buildroot mailing list