guix-commits
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

02/02: gnu: python-pycrypto: Add TODO "removal" comment.


From: Leo Famulari
Subject: 02/02: gnu: python-pycrypto: Add TODO "removal" comment.
Date: Tue, 27 Dec 2016 00:52:23 +0000 (UTC)

lfam pushed a commit to branch master
in repository guix.

commit 1194575b3c44969e4f68cd10a62e6ed8603e39b4
Author: Leo Famulari <address@hidden>
Date:   Mon Dec 26 19:49:27 2016 -0500

    gnu: python-pycrypto: Add TODO "removal" comment.
    
    * gnu/packages/python.scm (python-pycrypto, python2-pycrypto): Add
    comment.
---
 gnu/packages/python.scm |    8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/gnu/packages/python.scm b/gnu/packages/python.scm
index 2ddd119..dd3ef8f 100644
--- a/gnu/packages/python.scm
+++ b/gnu/packages/python.scm
@@ -907,7 +907,13 @@ Python 3 support.")
 (define-public python2-setuptools
   (package-with-python2 python-setuptools))
 
-
+;;; Pycrypto is abandoned upstream [0] and contains at least one bug that can 
be
+;;; exploited to achieve arbitrary code execution [1].
+;;;
+;;; TODO Remove this package from GNU Guix.
+;;;
+;;; [0] https://github.com/dlitz/pycrypto/issues/173
+;;; [1] https://github.com/dlitz/pycrypto/issues/176
 (define-public python-pycrypto
   (package
     (name "python-pycrypto")



reply via email to

[Prev in Thread] Current Thread [Next in Thread]