FS#52750 - [gnucash] depends on outdated webkitgtk2

Attached to Project: Arch Linux
Opened by Stefan Haller (fgrsnau) - Saturday, 28 January 2017, 14:25 GMT
Last edited by Jan de Groot (JGC) - Saturday, 28 January 2017, 14:31 GMT
Task Type Bug Report
Category Packages: Extra
Status Closed
Assigned To No-one
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No


The current version of gnucash (gnucash-2.6.15-1) depends on webkitgtk2. This results in the following information printed during installation of the package:

(1/2) installing webkitgtk2

> WARNING: WebKitGTK+ 2.4 is known to have many security vulnerabilities that
will NOT be fixed. Avoid browsing with it.

As far as I understand, it should be possible to let gnucash depend on the webkit2gtk package instead. Even though this might not necessarily be critical for gnucash, users don’t want to install libraries with well-known vulnerabilities on their system.
This task depends upon

Closed by  Jan de Groot (JGC)
Saturday, 28 January 2017, 14:31 GMT
Reason for closing:  Upstream
Comment by Jan de Groot (JGC) - Saturday, 28 January 2017, 14:31 GMT
Upstream doesn't care about this, they don't support webkit2. There's nothing we can fix here.