| 13 Nov 2025 |
Grimmauld (any/all) | I don't have the time to look into hdf5 for another ~6h, i am also not sure i really want to | 11:14:21 |
Grimmauld (any/all) | i am relying on hdf5 for my bachelors thesis (though not from nixpkgs), i have some idea about the pain with it | 11:15:02 |
Grimmauld (any/all) | (probably not helped by the fact i need to build hdf5 for msvc tooling, but oh well) | 11:15:16 |
Grimmauld (any/all) | the problem is: Not doing this upgrade means we'll have the CVEs on stable. Doing this upgrade is potentially breaking and will completely break the release schedule when we need to revert. | 11:17:03 |
Grimmauld (any/all) | Either way is not great | 11:17:11 |
leona | it's probably very awful to backport these patches? | 11:18:17 |
Grimmauld (any/all) | I didn't explicitly look, but its quite a few CVEs and over half a year of development in an active repo makes me dread the merge conflicts | 11:19:02 |
leona | fun | 11:19:26 |
Grimmauld (any/all) | but fair, we could try backporting CVE fixes, then do 2.0.0 on unstable after branch-off (and backport that later if it doesn't break too much stuff on the then-unstable) | 11:19:45 |
leona | that would be wonderful if that works IMO | 11:20:07 |
Grimmauld (any/all) | but that needs someone with spoons fixing merge conflicts | 11:20:20 |
Grimmauld (any/all) | ehmry is the listed maintainer, that won't fly | 11:20:34 |