Skip to content

dep: update libxml2 to v2.13.6 (v1.17.x branch) #3448

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Mar 2, 2025

Conversation

flavorjones
Copy link
Member

@flavorjones flavorjones commented Feb 24, 2025

https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.13.6

See related #3437 and #3438

I'm not making any kind of statement or promises about whether I'll cut security releases for v1.17.x in the future. I'm doing this because Mastodon 4.2 still supports Ruby 3.0 and its dependency on ruby-saml makes it potentially impacted by the underlying libxml2 fixes.

I know somebody out there, somewhere, is going to say "I'll stay on Ruby 3.0 if Mike is going to keep cutting security updates", and hoo boy that is NOT a bet you should be making. I am the most enthusiastic supporter of "dropping support for EOL versions of Ruby" that you will ever meet, and this is NOT going to continue.

I know somebody out there, somewhere, is going to try to convince me that because I made this one security update, I'm somehow obligated to continue supporting the v1.17.x branch. If you feel the urge to send me a message like that, please restrain yourself and do not make me regret doing this thing.

@flavorjones flavorjones merged commit ee5e835 into v1.17.x Mar 2, 2025
130 of 132 checks passed
@flavorjones flavorjones deleted the flavorjones-dep-libxml-2.13.6_v1.17.x branch March 2, 2025 20:06
@flavorjones
Copy link
Member Author

After chatting with one of the Mastodon maintainers, I'm not going to cut a release on this branch. They've shipped https://github.com/mastodon/mastodon/releases/tag/v4.2.17 which drops support for Ruby 3.0 and are encouraging users to upgrade Ruby. 👏👏

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant