switch to system-wide libtomcrypt library #711
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hello,
please would you consider switching to the system installed share library of libtomcrypt instead of embedding its code in this project?
There is libtom system package in major distributions:
Fedora/EPEL - https://src.fedoraproject.org/rpms/libtomcrypt
Ubuntu - https://packages.ubuntu.com/bionic/libtomcrypt-dev
Debian - https://packages.debian.org/search?keywords=libtomcrypt
Embedding the code makes it difficult to identify and update some vulnerable code in case it is found (from recent history for example log4shell / text4shell vulnerabilities). All major distributions have a rule that the usage of embedded code should be avoided when possible. Inclusion of this patch would make it easier for the distribution package maintainers to deal with the updates of your package.
Thank you
Michal Ambroz