Dependencies Status Krita September 2019
Open, NormalPublic

Description

This task is to list all dependencies for Krita current versions used and dependencies versions as of September 2019. A quick review of changelog was made.

DependencyUsedAvailableUpgrade?Notes and Changes
Boost1.611.69,1.71-Too many changes and fixes.
DrMingw0.8.10.9.2Probably notcmake: Install, dbgcore.dll if it exists, Add option to debug heap
eigen33.3.43.3.7YesBug fixing releases
exiv20.260.27.2Yesbug fixes in general: https://github.com/Exiv2/exiv2/milestone/1?closed=1
expat2.1.02.1.1, 2.2.9YesFixes many Security risks
ffmpeg4.04.2.1only Win, maybeAs external tool, its ok to update (No terminal API changes it seems).
fftw33.3.83.3.8----
fontconfig2.12.02.12.93, 2.13.1Yes, Probably2.13.1 looks safe https://www.freedesktop.org/software/fontconfig/release/ChangeLog-2.13.1
KDE Frameworks5.605.62ProbablyFixes on KArchive (Android creation of files and crashes), KConfig: Security fix and memory leak. (but many other changes)
FreeType2.6.52.10.1AdvicedSo many changes: rendering behaviour change, CFF and OpenType full support
gettext0.18,0.19.80.19.8.1, 0.20.1Yes, Probably--
giflib5.1.45.2.1--
gmic-qt2.7.02.7.2--
gsl2.3.02.6.0Okhttp://git.savannah.gnu.org/cgit/gsl.git/tree/NEWS
heif:libde2651.0.31.0.3--
heif:yasm1.3.01.3.0-No new versions since Aug 10, 2014
heif:nasm2.14.03rc22.14.03rc2--
heif:libx2653.03.2Probably-
heif:libheif1.4.01.4.1YesBugfix release
iconv1.141.16OkNo Changelog for 1.16… strange
ilmbase2.2.12.3.0Ok-
jpeg-turbo2.0.22.0.3Okfixes: https://sourceforge.net/projects/libjpeg-turbo/files/2.0.3/
lcms22.92.9--
libraw0.18.60.19.5YesSmall ABI change! (https://www.libraw.org/news/libraw-0-19-5-release)
lzma5.2.45.2.4--
ocio1.1.01.1.1-https://github.com/AcademySoftwareFoundation/OpenColorIO/releases
openexr2.2.12.4.0Probably2.4.0 released sept 19, 2019.
openssl1.1.1b1.1.1dYesSecurity fixes: https://www.openssl.org/news/vulnerabilities-1.1.1.html
patch2.5.92.7-Using binary format, for windows.
pkgconfig0.29.10.29.2OkBut not necessary https://cgit.freedesktop.org/pkg-config/log/
png1.6.341.6.37YesVulnerabilty! http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7317
png2ico--??More info on this needed
poppler0.62.00.81.0-Latest 22 Sept, 2019 (https://poppler.freedesktop.org/releases.html)
poppler-data0.4.80.4.9ok-
pyqt5.12.15.13.1Only ifUpdate if moving to Qt 5.13
python3.5.23.5.7, 3.7.4Branch okhttps://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-7
qt5.12.55.13.1--
quazip0.7.60.8.1Probablysupport UTF-8, OS code setting...
sip4.19.154.19.19-Not substancial fixes: https://www.riverbankcomputing.com/static/Downloads/sip/4.19.19/ChangeLog
tiff4.0.94.0.9-is the source correct?
vc1.3.31.4.1-some API breaks: https://github.com/VcDevel/Vc/releases
zlib1.2.111.2.11--

Sources

LIBHEIF

vanyossi created this task.Oct 1 2019, 3:08 AM
vanyossi triaged this task as Normal priority.
rempt added a comment.Oct 20 2019, 9:13 AM

Note: OpenEXR 2.4.0 is out with some security updates, so I think we really want to update to that release. See https://github.com/openexr/openexr/releases

vanyossi updated the task description. (Show Details)Nov 12 2019, 12:39 AM