Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Package request: Re-add linux-wallpaperengine #348135

Closed
Pandapip1 opened this issue Oct 12, 2024 · 6 comments · Fixed by #348336
Closed

Package request: Re-add linux-wallpaperengine #348135

Pandapip1 opened this issue Oct 12, 2024 · 6 comments · Fixed by #348336
Labels
0.kind: packaging request Request for a new package to be added

Comments

@Pandapip1
Copy link
Contributor

Pandapip1 commented Oct 12, 2024

linux-wallpaperengine was removed due to depending on an unmaintained library with lots of critical CVEs (#323821; Almamu/linux-wallpaperengine#204). Now that dependency has been replaced with one that's actually secure, it should be re-added.

@Pandapip1 Pandapip1 added the 0.kind: packaging request Request for a new package to be added label Oct 12, 2024
@LovingMelody
Copy link
Contributor

cc @eclairevoyant you were previously the maintainer for this package, do you wish to re-add / be re-added to the maintainers for this?

@Pandapip1
Copy link
Contributor Author

I'm pretty sure they quit nixpkgs

@Frontear
Copy link
Member

Pretty surprising the entire derivation was removed rather than marked insecure..

@LovingMelody
Copy link
Contributor

It looked like they were struggling to get the package to even build based on its original commit history after the CEF dependency was added. Likely what lead to it being removed.

@Pandapip1
Copy link
Contributor Author

Pretty surprising the entire derivation was removed rather than marked insecure..

The rationale was that the vulnerabilities were pretty bad, and that the entire point of the program was to run user-generated content; and that said content had plenty of surface area to try to exploit those vulnerabilities. It was a "you really shouldn't use this under any circumstances"-type deal. Hence why it was removed.

@g-libardi
Copy link

Hello, I apologize if this isn’t the appropriate place, but I couldn’t find a discussion regarding Wallpaper Engine. If anyone is interested in using the version from the pull request before it's approved, you can do so with the following command:

nix profile install github:NixOS/nixpkgs/563f07d52d6ec4a48f1e0fa008194d00d99ea2cf#linux-wallpaperengine

This works with the experimental Nix CLI, and the link should also function within Nix files when used with the appropriate function.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
0.kind: packaging request Request for a new package to be added
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants