~ruther/guix-local

b1b11ad30090bab4f622abe9eac0c022fef51103 — Nicolas Graves 8 months ago f1e9e05
gnu: libreoffice: Avoid libxml2@2.9 propagation.

libxml2@2.9 has CVEs, we don't want it in user profiles.  If the
following libraries end up in a user profile, then this vulnerable
libxml2 is propagated.

* gnu/packages/libreoffice.scm (libe-book, libcmis, libabw, libetonyek)
[propagated-inputs]: Replace libxml2 by libxml2-next.

Signed-off-by: Liliana Marie Prikler <liliana.prikler@gmail.com>
1 files changed, 4 insertions(+), 4 deletions(-)

M gnu/packages/libreoffice.scm
M gnu/packages/libreoffice.scm => gnu/packages/libreoffice.scm +4 -4
@@ 286,7 286,7 @@ into other word processors.")
    (native-inputs
     (list cppunit gperf pkg-config))
    (propagated-inputs ; in Requires or Requires.private field of .pkg
     (list icu4c liblangtag librevenge libxml2))
     (list icu4c liblangtag librevenge libxml2-next))
    (inputs
      (list boost))
    (arguments


@@ 372,7 372,7 @@ working with graphics in the WPG (WordPerfect Graphics) format.")
    (native-inputs
     (list autoconf automake libtool cppunit pkg-config))
    (propagated-inputs                  ;in Requires field of .pkg
     (list curl libxml2))
     (list curl libxml2-next))
    (inputs
     (list boost cyrus-sasl openssl))
    (arguments


@@ 413,7 413,7 @@ as Alfresco or Nuxeo.")
    (native-inputs
     (list doxygen gperf perl pkg-config))
    (propagated-inputs ; in Requires or Requires.private field of .pkg
     (list librevenge libxml2))
     (list librevenge libxml2-next))
    (inputs
     (list boost))
    (home-page "https://wiki.documentfoundation.org/DLP/Libraries/libabw")


@@ 467,7 467,7 @@ CorelDRAW documents of all versions.")
    (native-inputs
     (list cppunit doxygen gperf pkg-config))
    (propagated-inputs ; in Requires or Requires.private field of .pkg
     (list liblangtag librevenge libxml2 zlib))
     (list liblangtag librevenge libxml2-next zlib))
    (inputs
     (list boost glm mdds))
    (home-page "https://wiki.documentfoundation.org/DLP/Libraries/libetonyek")