[Python-Dev] Remove embedded expat library?
victor.stinner at gmail.com
Fri Jun 9 08:43:06 EDT 2017
Python embeds a copy of the expat library which already got two major
"CVE-2016-0718: expat bug #537"
"Issue #26556: Expat 2.1.1"
Would it be possible to maintain this dependency on an external
repository which would be easier to maintain? Like
http://svn.python.org/projects/external/ used to build Python on
I expect that all Linux distributions build Python using
--with-system-expat. It may become the default? What about macOS and
other operating systems?
By the way, Zachary Ware is working on converting this repository to
Git. I don't know his progress:
More information about the Python-Dev