From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on dcvr.yhbt.net X-Spam-Level: X-Spam-ASN: AS6130 216.105.38.0/24 X-Spam-Status: No, score=-3.8 required=3.0 tests=AWL,BAYES_00,DKIM_INVALID, DKIM_SIGNED,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI, RCVD_IN_DNSWL_MED,SPF_HELO_PASS,SPF_PASS shortcircuit=no autolearn=ham autolearn_force=no version=3.4.2 Received: from lists.sourceforge.net (lists.sourceforge.net [216.105.38.7]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by dcvr.yhbt.net (Postfix) with ESMTPS id 8BC101F462 for ; Thu, 23 May 2019 16:24:13 +0000 (UTC) Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.90_1) (envelope-from ) id 1hTqVj-0001JM-BL; Thu, 23 May 2019 16:24:07 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.90_1) (envelope-from ) id 1hTqVh-0001J6-MX for sox-devel@lists.sourceforge.net; Thu, 23 May 2019 16:24:05 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=In-Reply-To:Content-Type:Mime-Version:References: Message-ID:Subject:To:From:Date:Sender:Reply-To:Cc:Content-Transfer-Encoding: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=bDLbc+7+feAMwVumxGVGoSecX9ETa7g0uL6zm/ZxNeM=; b=hlH0tru5dH1xA6FBwOP4At2V+q kxuSgr+IhKjL9VWYF2Jb80YY0A+TFfFbeQdIKjdZtPCkl886FP/uE+rKnnS1OIKg3OEwd3E/Ds1fv 1evpLfntc6QeyJr7klv/ioPzndQ6iMVq+XY6scAKZPIMV54fy9FSSVQf7KknqRtTsbjw=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=In-Reply-To:Content-Type:Mime-Version:References:Message-ID:Subject:To: From:Date:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=bDLbc+7+feAMwVumxGVGoSecX9ETa7g0uL6zm/ZxNeM=; b=a4Y2WVbEKhKmA9PWV1xyBguDnj lSeJxOePC+5ToK45Df+IaYFEPeobdbYHBrPVvwPW75EU7K+0y+4DsiXC3ny7iaUA1Cg1TeLJ2GjQH YOhUZMHSMUg8TjxIxFRekpjWSn6rAJCZlwTcob+f1N0b9xvOdHH8r6W2nh4roM8icbkw=; Received: from sleepmap.de ([85.10.206.218] helo=mail.sleepmap.de) by sfi-mx-4.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.90_1) id 1hTqVf-002j5c-Ub for sox-devel@lists.sourceforge.net; Thu, 23 May 2019 16:24:05 +0000 Date: Thu, 23 May 2019 18:04:18 +0200 From: David Runge To: sox-devel@lists.sourceforge.net Message-ID: <20190523160418.GH31716@dvzrv.localdomain> References: <20181004173911.GC17559@dvzrv.localdomain> Mime-Version: 1.0 In-Reply-To: <20181004173911.GC17559@dvzrv.localdomain> X-Headers-End: 1hTqVf-002j5c-Ub Subject: Re: Next release X-BeenThere: sox-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: sox-devel@lists.sourceforge.net Content-Type: multipart/mixed; boundary="===============3710194072996039258==" Errors-To: sox-devel-bounces@lists.sourceforge.net --===============3710194072996039258== Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="GBDnBH7+ZvLx8QD4" Content-Disposition: inline --GBDnBH7+ZvLx8QD4 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Hi again, On 2018-10-04 19:39:11 (+0200), David Runge wrote: > I'm happy to see, that there has been some activity for sox this year. > I'm even more happy to see, that a lot of CVEs got fixed by patching it! >=20 > Currently, I'm maintaining sox for Arch Linux. I'd love to see a new > release, so I can drop all the extra patches soon. > It would of course generally be awesome to have more frequent releases > again! Is this a possibility for the current developers/maintainers? I > know, that this is not really an easy task... >=20 > Is there any ticket preventing a new release? If so, how can the process > be helped? as sox has now accumulated a total of twelve (!) CVEs for version 14.4.2 [1], I'd like to once more urge the current maintainers to tag a new release. Given the maintenance burden of applying all of these patches (and the numerous other bugfixes that have been added [2]) on top of the last stable release in a packaging context, I would very much like to see a new release. Is there anything preventing it? Is there something that can be helped with? Best, David [1] https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=3Dsox [2] https://sourceforge.net/p/sox/code/commit_browser --=20 https://sleepmap.de --GBDnBH7+ZvLx8QD4 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEkb2IFf4AQPp/9daHVMKPT/WhqUkFAlzmxH8ACgkQVMKPT/Wh qUkM3RAAnzz2FSaeWthagxpeZ2Xco36f6KcYTa5uQGQAzUk51GSzu5T9av8RS6kO /9DFgfge8kk0qB91kW+drhqs4drqNN7ABQXcSbeIjnhXhne4pyiMYITh/5XEU6L+ eA5mZA3T6jPkqP7fIsZSHD1cc3CLFupAA+xHqDgWP2pQyGL+UTzdYB3HmbK99aV8 MXFWyt11Jl40FLIpwGitTMibSe/UNv+qoKg92vcYxMyoQs8knDCVaGt80bcTO0Eg xQuOffolVbUgSy9/B420tfl+4DhCKMwWv3sb2sDMb2rakyS6/IlQCl1pZXLvg7Sq f5C9fOAEvlasMmR2S4o8ZNq/FRjVdnfl9KZGPeC9U4sa+uQUES05eS19NWLHhKgh ujXP0VmSe16Zoh5lGb87wQHsEIwL4PYZIya5pa3OdQztlG8p8S/ubip8VOP+YvOH rU7QM83u6diqPuUndzCYvlIRpZoolnsQ5Z4GgbLL6c95EbOr67rjawWOWeRTQ1Cs ybv0q9CxxtIKysKZvE+Cocb/2x4wRXgtb/W5u6AuVkQs/kXYoH3Q6rzJ1GbvbRx7 HzMZo5RjiYloyPnKVfwHk6GvoKF/PZeVZVKKUJBcV/Ovr07ZMDdEElnyZZFxnOG1 xP9PJDrkyfBnIM+XpGKAMD4sq8EuLxpGVXBkdGLFHaOSYZZH+m0= =VidY -----END PGP SIGNATURE----- --GBDnBH7+ZvLx8QD4-- --===============3710194072996039258== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============3710194072996039258== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ SoX-devel mailing list SoX-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/sox-devel --===============3710194072996039258==--