Closed, ResolvedPublic



smplayer recommends nonfree smtube optional installation

Parabola patch

mladen created this task.May 16 2017, 6:20 PM
mladen edited the task description. (Show Details)

this is not part of any dependency chain, so before I drop into source code of it, can you provide me some screenshots about that issue @mladen.pejakovic

mladen added a comment.EditedMay 20 2017, 12:47 PM

Patch is already suggested:

Notes: Patch:

we just need to apply it.

ah that is easy one, just commenting lines (actually most of those gui suggestion will be solved by commenting lines). I'll see to patch this out today as well.

This comment was removed by mladen.

seems smplayer (authored by same upstream as smtube) is sloppy about executing external code: As an example, if youtube parsing fails then it offers to download updated javascript code for parsing - from insecure URL!

For security reasons I recommend to avoid smplayer (and smtube).

A less featureful alternative is gnome-mpv.

so, do you suggest to drop them both from archive (its not like we don't have plenty of other apps for such use case) and improvement in security and freedom of archive might be enough big to simply remove them from pureos archive (we can always change that in future if it changes)

Yes, I recommend to drop smplayer and smtube from PureOS.

If the mechanism to drop has the ability to include comments for those wondering why the Debian package is missing from PureOS, then I suggest mentioning gnome-mpv and minitube.

mak lowered the priority of this task from "95" to "Freedom Issue".Aug 19 2017, 5:09 AM
jonas.smedegaard closed this task as "Resolved".Sep 18 2017, 10:58 AM

Fixed in Debian.

jonas.smedegaard changed the title from "[FREEDOM ISSUE] smplayer" to "smplayer".Oct 24 2017, 12:40 PM
jonas.smedegaard claimed this task.
jonas.smedegaard edited the task description. (Show Details)
jonas.smedegaard added a subscriber: hema.prathaban.

Add Comment