Upgrading libxul, dependency on Firefox 3

Beat Gätzi beat at FreeBSD.org
Sat Oct 22 19:49:47 UTC 2011


On Oct 22, 2011, at 2:54 AM, Joe Altman wrote:
> Greetings...
> 
> I was running portupgrade on libxul and noticed it depends on Firefox
> 3.x. I cancelled the upgrade, because I thought FF3.x was insecure and
> therefore deprecated while FF7 was recommended and secure.
> 
> My questions:
> 
> 1) is the dependency libxul has for FF3 a security problem?

libxul doesn't depend on FF3. We just use the FF3.6 source tarball
to build xulrunner (libxul) as upstream no longer provides tarballs
for the latest xulrunner 1.9.2.x releases. Nevertheless FF3.6 is still
supported upstream and security problems get fixed regularly during
the normal Mozilla release cycle.

> 2) is the dependency on FF3 a bug in libxul? If it is a bug, who
>   should receive a report: gecko@ or the Mozilla project?

There is no FF3 dependency in libxul.

HTH,
Beat

> FYI: I'm pretty sure it was portsclean -D (and not me) that deleted
> FF3...yet libxul tried to pull it in during the portupgrade.
> 
> Best regards,
> 
> Joe
> _______________________________________________
> freebsd-questions at freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "freebsd-questions-unsubscribe at freebsd.org"



More information about the freebsd-questions mailing list