Re: [RFC][VOTE][RESULT] Removal of dead or not yet PHP7 ported SAPIs and extensions
| From: | Leigh | Date: | Tue, 10 Feb 2015 21:58:42 +0000 |
| Subject: | Re: [RFC][VOTE][RESULT] Removal of dead or not yet PHP7 ported SAPIs and extensions | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-82395@lists.php.net to get a copy of this message | ||
On 10 February 2015 at 21:38, David Muir <davidkmuir@gmail.com> wrote:
> Does this mean PHP will be taking on the role of maintaining libmcrypt as well?
That's not what it means, no.
> If a security issue is found, what is the course of action?
Well, what happened when there was vulnerabilities in OpenSSL?
I've been thinking quite hard about what we should do with regard to
mcrypt. We definitely need a plan to sunset it, but we can't really do
that without a readily available replacement. It's understandable if
people do not want to use OpenSSL as an alternative.