GNU bug report logs - #29415
[PATCH] gnu: python-axolotl: Update to 0.1.39 and fix build.

Previous Next

Package: guix-patches;

Reported by: Adam Van Ymeren <adam <at> vany.ca>

Date: Thu, 23 Nov 2017 20:06:02 UTC

Severity: normal

Tags: patch

Done: ludo <at> gnu.org (Ludovic Courtès)

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: Leo Famulari <leo <at> famulari.name>
To: Adam Van Ymeren <adam <at> vany.ca>
Cc: 29415 <at> debbugs.gnu.org
Subject: [bug#29415] [PATCH] gnu: python-axolotl: Update to 0.1.39 and fix build.
Date: Mon, 27 Nov 2017 13:09:59 -0500
[Message part 1 (text/plain, inline)]
On Mon, Nov 27, 2017 at 10:00:01AM -0500, Adam Van Ymeren wrote:
> Leo Famulari <leo <at> famulari.name> writes:
> There is also a pull request pending from someone else that updates
> pyton-axolotl to use a newer python cryptography library rather than the
> deprecated python-pycrypto library.  That would also fix this issue and
> is a much better long term fix but also a more intrusive change.

I noticed that as well. Pycrypto is no longer maintained and has an
extremely serious bug that was never fixed in a released version:

https://github.com/dlitz/pycrypto/issues/176

And the author seems to implicitly agree that people should stop using
it:

https://github.com/dlitz/pycrypto/issues/173

So I added a TODO comment to the package, saying that we should remove
it:

https://git.savannah.gnu.org/cgit/guix.git/tree/gnu/packages/python-crypto.scm?id=12a130b0118c3f56e6337e011dc4a89f2671359a#n186

So, I recommend being careful how you use any package that depends on
pycrypto.
[signature.asc (application/pgp-signature, inline)]

This bug report was last modified 7 years and 110 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.