Hacker News new | ask | show | jobs
by eigenlicht 993 days ago
I've just had a look into my flatpak installation, where my default "Platform" (runtime) is still vulnerable. That didn't even seem too much of a worry though since as I found out all of the flatpak apps I use that have a dependency ship their own libwebp. And sure enough, except for Firefox which is patched, none of them is.

$ flatpak update --no-related --force remove

Checking for updates...

Nothing to do.

My base system (Debian) got the patch almost two weeks ago. Might as well trash flatpak for good.