Details
-
User Story
-
Resolution: Done
-
P1: Critical
-
None
-
None
Description
Following actions needs to be done for all Qt modules using 3rd party components
- Update all 3rd party components used (with security fixes if available)
- Add version information to 3rd party components
List of 3rd party components for each module are listed here: http://doc.qt.io/qt-5/licenses-used-in-qt.html
There was related discussion in Qt Contributors Summit. Memo: https://wiki.qt.io/QtCS2018_Third-Party_Sources_Policy_and_Security
If there are questions, please contact dedicated R&D owner mentioned in each sub-task.
Attachments
Gerrit Reviews
For Gerrit Dashboard: QTBUG-70007 | ||||||
---|---|---|---|---|---|---|
# | Subject | Branch | Project | Status | CR | V |
240463,4 | Upgrade double-conversion to v3.1.1 | 5.12 | qt/qtbase | Status: MERGED | +2 | 0 |
240701,1 | Upgrade double-conversion to v3.1.1 | dev | qt/qtbase | Status: ABANDONED | 0 | 0 |
242877,5 | 3rdparty/xkbcommon: update bundled version 0.4.1 -> 0.8.2 | 5.12 | qt/qtbase | Status: MERGED | +2 | 0 |
243112,3 | Update valgrind header | 5.12 | qt/qtbase | Status: ABANDONED | 0 | 0 |
243130,3 | Update dbus header and document its provenance | 5.12 | qt/qtbase | Status: MERGED | +2 | 0 |
243162,3 | angle: Add additional information to qt_attribution.json | 5.12 | qt/qtbase | Status: MERGED | +2 | 0 |
243425,3 | Update various qt_attribution.json files | 5.12 | qt/qtbase | Status: MERGED | -2 | 0 |
243451,3 | Update sha3's brg_endian.h, document provenance and version | 5.12.0 | qt/qtbase | Status: MERGED | +2 | 0 |
243460,2 | Update DejaVuSans.ttf from upstream | 5.12.0 | qt/qtbase | Status: MERGED | +2 | 0 |
244744,2 | Update documented chromium version | 5.12.0 | qt/qtwebengine | Status: MERGED | +2 | 0 |
248897,2 | configure: properly atomize render vs. renderutil | 5.12 | qt/qtbase | Status: MERGED | +2 | 0 |