Summary: | databases/postgresql13-server: request to enable XML option by default or define a flavor | ||
---|---|---|---|
Product: | Ports & Packages | Reporter: | topical <topical> |
Component: | Individual Port(s) | Assignee: | Palle Girgensohn <girgen> |
Status: | New --- | ||
Severity: | Affects Some People | CC: | dereckson, girgen, lwhsu, pat |
Priority: | --- | ||
Version: | Latest | ||
Hardware: | Any | ||
OS: | Any |
Description
topical
2023-01-23 12:41:06 UTC
Orbeon Forms requires this too. So, best way would be to add XML ON as default, and possibly add flavour for noxml? The original rationale around removing XML from the default build was that the xml packages had bad reputation for security flaws. This is always the case with XML, I guess, but I don't think it actually motivates not linking the library. You most oftenly actually need to USE the xml features to expose yourself to any security problems. I'd also like to add LLVM is moving to include libxml support. On a machine, I had already libxml installed, through a llvm package (not the base system). So that could become standard. And yes, there are still XML security issues, including for libxml: https://www.cvedetails.com/vulnerability-list/vendor_id-1962/product_id-3311/Xmlsoft-Libxml2.html |