Seems like my ideas weren’t far off…

I don’t like “I told you so” posts, but since this might actually help to spread the knowledge that I already have written about, I’ll do it.

Remember my post about bundling libraries ? As it turns out, one of the bugs I’ve reported in the past weeks turned into a security bug since osalp bundles a vulnerable libaudiofile .

As you can see from the bug numbers, the bundled library bug was open before the libaudiofile vulnerability was reported, which to me just shows how important it is not to bundle libraries.

