Re: [MacPorts] #51516: MacPorts should use a bundled copy of a newer libcurl rather than the OS X version
#51516: MacPorts should use a bundled copy of a newer libcurl rather than the OS X version --------------------------+-------------------------------- Reporter: ryandesign | Owner: macports-tickets@… Type: enhancement | Status: new Priority: Normal | Milestone: MacPorts Future Component: base | Version: Resolution: | Keywords: Port: | --------------------------+-------------------------------- Comment (by ryandesign): The current discussion is centered around being able to reach servers running newer ssl. But the idea to use a bundled curl is much older, and is based on the idea that we should use the latest software, because it has more features and fixes bugs. That's the reason why we bundle tcl 8.5 now; we were able to remove workarounds for tcl 8.4 and start using features introduced in tcl 8.5. In the same way, the latest curl might offer some useful features not present in Tiger's curl, and there are workarounds in base for bugs in the version of curl included with Snow Leopard that we could remove if we bundled a newer version. The problem of needing to also bundle a newer ssl library to support newer ssl sites, and to quickly release new MacPorts base versions to update the ssl library should any vulnerabilities be found, makes this idea less wonderful. On the one hand, having a recent but not completely up to date ssl library would be better for users of old OS versions that don't get security updates anymore; but on the other hand, it would be worse for users of new OS versions that do. Maybe once we are on GitHub we will improve our testing and release process to the point where releasing a new version of MacPorts can be done very easily. If so, maybe then we can revisit this issue. -- Ticket URL: <https://trac.macports.org/ticket/51516#comment:23> MacPorts <https://www.macports.org/> Ports system for OS X
participants (1)
-
MacPorts