backhand icon indicating copy to clipboard operation
backhand copied to clipboard

Investigate replacement of xz2 with liblzma-rs

Open wcampbell0x2a opened this issue 2 years ago • 2 comments
trafficstars

I'm not sure about the long term solution, but https://github.com/Portable-Network-Archive/liblzma-rs had been updated and actively maintained vs xz2.

wcampbell0x2a avatar Nov 07 '23 01:11 wcampbell0x2a

See https://github.com/Portable-Network-Archive/liblzma-rs/issues/95. I'm still using xz2, which uses an older version of xz that isn't vulnerable (not that the that version is vulnerable, but given the broad changes that maintainer created in the recent releases...)

wcampbell0x2a avatar Mar 30 '24 04:03 wcampbell0x2a

I think doing this with a xz-new and NOT on by default would be fine.

wcampbell0x2a avatar Aug 06 '24 02:08 wcampbell0x2a