logo

overlay

My own overlay for experimentations, use with caution, no support is provided git clone https://anongit.hacktivis.me/git/overlay.git/

package.mask (5142B)


  1. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2025-11-20)
  2. # prebuilt
  3. www-plugins/pdfjs
  4. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2025-10-17)
  5. # Unmaintained, several known security issues (double-free, OOB read, …)
  6. # CVE-2017-16516 CVE-2022-24795 CVE-2023-33460
  7. # https://github.com/lloyd/yajl/issues/219
  8. dev-libs/yajl
  9. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2025-06-11)
  10. # Non-Free
  11. # https://bugzilla.redhat.com/show_bug.cgi?id=449037
  12. # https://spot.livejournal.com/303000.html?nojs=1
  13. # https://raw.githubusercontent.com/kholtman/afio/21f0408cb3df40e5de3d3fa2698eb6626c57df02/afio_license_issues_v5.txt
  14. app-arch/afio
  15. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2025-05-04)
  16. # Avoid forcing libxcrypt in
  17. >=virtual/libcrypt-2
  18. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2025-01-29)
  19. # Let's try to reduce the amount of machines contaminated by boost
  20. dev-libs/boost
  21. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2024-12-26)
  22. # Last release (14.4.2) in 2015, known CVEs since
  23. # Including 2 heap buffer overflows triggerable from a file:
  24. # CVE-2021-23159, CVE-2021-40426
  25. <media-sound/sox-14.3
  26. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2024-06-04)
  27. # Last release (0.8.0) in 2009 with several known bugs
  28. # leading Gentoo to maintain a patchset.
  29. #
  30. # Also no releases since CVE-2016-8859 <https://www.openwall.com/lists/oss-security/2016/10/19/1>
  31. # > Multiple integer overflows in the TRE library and musl libc allow attackers
  32. # > to cause memory corruption via a large number of (1) states or (2) tags,
  33. # > which triggers an out-of-bounds write.
  34. dev-libs/tre
  35. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2024-05-23)
  36. # Dropped by Debian maintainers who did the port from NetBSD to Linux
  37. # in favor of bmake
  38. # No gentoo maintainers either
  39. dev-build/pmake
  40. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2024-05-06)
  41. # No trust in an allocator with such a broken buildsystem configuration.
  42. # https://queer.hacktivis.me/notice/AhcQTrlYbAHhVftkKu
  43. sys-libs/talloc
  44. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2024-04-12)
  45. # No.
  46. app-admin/sudo
  47. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2024-02-29)
  48. # Screw language-specific package managers, none of them do proper reviews
  49. # Only exceptions so far are the ones where packaging in gentoo is
  50. # either insane or incomplete such as:
  51. # - npm and others using npmjs.org
  52. # - dev-elixir/hex
  53. dev-python/pip
  54. dev-lua/luarocks
  55. dev-ml/opam
  56. dev-scheme/akku
  57. dev-util/conan
  58. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2024-02-14)
  59. # Qt release pace for a chromium fork, effectively a forever:
  60. # Has security bugs don't use
  61. dev-qt/qtwebengine
  62. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2024-01-30)
  63. # Non-uniform small-keyspace crackable passwords by default
  64. # See https://www.openwall.com/lists/oss-security/2012/01/17/5
  65. app-admin/pwgen
  66. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2024-01-18)
  67. # Nobody should use imake anymore, X moved off from it in 2005.
  68. # https://lists.x.org/archives/xorg-announce/2024-January/003440.html
  69. x11-misc/imake
  70. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2023-08-08)
  71. # https://www.roguelazer.com/blog/surprising-behavior-in-gnu-tar/
  72. app-arch/tar
  73. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> (2023-07-25)
  74. # Dead upstream, known vulnerabilities (CVE-2021-42260)
  75. # Author switched to tinyxml2
  76. dev-libs/tinyxml
  77. # Haelwenn (lanodan) Monnier - 2023-07-09
  78. # Binaries
  79. dev-lang/go-bootstrap
  80. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> 2023-02-03
  81. # No bootstrapping, would need a way to bootstrap dev-lang/fpc
  82. dev-lang/nim
  83. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> 2023-01-30
  84. # No bootstrapping, you're supposed to download the blobs from npmjs.org
  85. # which isn't trustworthy
  86. # https://github.com/microsoft/TypeScript-go
  87. # which will eventually merge in typescript proper should be checked
  88. dev-lang/typescript
  89. # Haelwenn (lanodan) Monnier <contact@hacktivis.me> 2018-12-27
  90. # Bloated, quite insecure (too much trust in other apps, more than paging)
  91. # alternative can be sys-apps/most, see virtual/pager for others
  92. sys-apps/less
  93. # https://www.audacityteam.org/about/desktop-privacy-notice/
  94. # TL;DR: Audacity is now a Surveillance application
  95. media-sound/audacity
  96. # Haelwenn (lanodan) Monnier - 2022-02-05
  97. # Unmaintained, last update in 2016, 2021 is because Arthur Zamarin of gentoo
  98. # made a small fork with few patches on top.
  99. # Also: https://zaitcev.livejournal.com/263602.html - PyPI is not trustworthy
  100. dev-python/nose
  101. # Haelwenn (lanodan) Monnier - 2022-06-02
  102. # Unmaintained, last tarball in 2010, last git update in 2015
  103. # Contains data like IANA which should be kept up-to-date regularly
  104. sys-apps/miscfiles
  105. # Haelwenn (lanodan) Monnier - 2022-07-11
  106. # Dead upsteam, last updated in 2003
  107. # Known security bugs, effectively vague fork by distros
  108. media-libs/id3lib
  109. # Haelwenn (lanodan) Monnier - 2022-07-11
  110. # Dead upsteam, last release in 2016
  111. media-sound/easytag
  112. # Haelwenn (lanodan) Monnier - 2022-08-30
  113. # Open-Core
  114. # https://github.com/danmar/cppcheck/commit/8f386e15fdedff37486c683d933ccc9a1e307388
  115. dev-util/cppcheck