Skip to content

Update webkit to 2.34.1#46

Closed
jhaygood86 wants to merge 5 commits intoelementary:mainfrom
jhaygood86:update-webkit-to-2.34
Closed

Update webkit to 2.34.1#46
jhaygood86 wants to merge 5 commits intoelementary:mainfrom
jhaygood86:update-webkit-to-2.34

Conversation

@jhaygood86
Copy link

@jhaygood86 jhaygood86 commented Oct 1, 2021

This updates to the latest webkit release (2.34). We might want to do this in the flatpak platform eventually as well (or instead of here) since the upstream GNOME platform we use (3.38) is no longer maintained now that GNOME 41 is out.

This fixes two security advisories:
https://webkitgtk.org/security/WSA-2021-0005.html
https://webkitgtk.org/security/WSA-2021-0006.html

It also includes a lot of web platform updates and bugfixes:
https://webkitgtk.org/2021/09/22/webkitgtk2.34.0-released.html
https://webkitgtk.org/2021/10/21/webkitgtk2.34.1-released.html

It also fixes #39.

@jhaygood86 jhaygood86 changed the title Update webkit to 2.34 Update webkit to 2.34.1 Oct 21, 2021
@alatiera
Copy link

No application should really bundle a web engine, apart from being a huge paint to build, its also a serious security concern.

@jhaygood86
Copy link
Author

jhaygood86 commented Oct 22, 2021

Well, we can move the update to the elementary platform.

As it stands, there are unfixed security issues and crashing bugs since WebKit is not maintained in the elementary Platform, and the upstream GNOME platform is EOL so isn't receiving feature or security updates.

Either way, we should update it somewhere

@jhaygood86 jhaygood86 requested a review from a team October 26, 2021 20:42
@danirabbit
Copy link
Member

Yeah I agree with @alatiera here that it doesn't make sense to bundle this here. It would be better to update in the plaform.

Something to look at is elementary/flatpak-platform#52 and if we can safely rev the 6 runtime to be based on the GNOME 40 runtime without API breaks or if we should create a 6.1 runtime built on GNOME 40 and migrate things to that

@danirabbit danirabbit closed this Oct 26, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Attempting to use the system emoji picker in websites causes the browser to crash

3 participants