Heads up: planned Harfbuzz update in jdk11u-dev

Mario Torre neugens at redhat.com
Fri Feb 4 15:09:25 UTC 2022


On Fri, Feb 4, 2022 at 3:55 PM Severin Gehwolf <sgehwolf at redhat.com> wrote:
>
> On Tue, 2022-01-25 at 14:02 +0000, Lindenmaier, Goetz wrote:
> > Hi Andrew Haley, Andrew Hughes, Matthias, Christoph, others...
> >
> > > While I take your point, I'll note that a Harfbuzz update doesn't seem
> > > to meet any of the criteria required for backports
> >
> > I think updates to libraries that are not developed in OpenJDK are
> > special.  We are OpenJDK experts, not harfbuzz / siphash / jline etc

I can relate a bit, but I don't fully agree with this. The in tree
libraries are still an essential component of OpenJDK, it bothers me
to not be sure of what's in there.

That of course goes both ways, to be able to update when we know
there's a security issue or an important fix, and to be able to say
that we don't want to update when we need to be more conservative.

Cheers,
Mario


-- 
Mario Torre
Manager, Software Engineering, core OpenJDK
Red Hat GmbH <https://www.redhat.com>
9704 A60C B4BE A8B8 0F30  9205 5D7E 4952 3F65 7898



More information about the jdk-updates-dev mailing list