[MIR] epiphany-browser-runtime
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
epiphany-browser (Ubuntu) |
Expired
|
Undecided
|
Unassigned |
Bug Description
Availability
============
Co-maintained with Debian GNOME. Built for all supported architectures.
Changes from Debian:
- Update to 3.24
- 07_bookmarks.patch: Add Ubuntu default bookmarks (as seen in Firefox)
- add_new_
- ubuntu_
Rationale
=========
Needed for Ubuntu to have a proper webapp feature, particularly for Amazon in the default install (LP: #1688627)
The alternatives are to either
1) ship Chromium, or
2) water down the webapp feature to just be basically a bookmark which would have poor desktop integration and wouldn't really be a webapp at all,
3) or drop the webapp feature from the default install
Security
========
The most recent fixed security bug is LP: #1661805 (fixed in 16.04 LTS and up)
https:/
https:/
epiphany-browser is far smaller than either Firefox or Chromium since most of its browser functionality (and security vulnerability) is provided by webkit2gtk.
epiphany does not support HSTS https:/
New in epiphany 3.24 is off-by-default support for integrated HTTPS Everywhere using libhttpseverywhere (not yet packaged in Debian/Ubuntu) https:/
Epiphany currently has no support for webextensions. NPAPI plugins are still supported.
Quality assurance
=================
The Desktop Bugs and Desktop Packages teams are already subscribed.
https:/
https:/
https:/
No autopkgtest.
Tests aren't being run because of https:/
Dependencies
============
There are 2 binary universe dependencies, browser-
Standards compliance
=======
3.9.8
Maintenance
===========
- Actively developed upstream (the primary developer is paid to work on webkitgtk)
https:/
dh7-style short rules, compat level 10
3.25.1 uses meson for building instead of autotools.
Debian packaging uses svn, but we're hoping to convert to git this year (which will allow for Ubuntu branches):
https:/
Background information
=======
The intent here is to split epiphany-browser into 2 packages. The existing package would only contain the .desktop and appstream metadata and depend on the other package (provisionally named epiphany-
Therefore, only epiphany-
I intend to upload this split version to Ubuntu but I want to see if I can get feedback from Debian about the proposed package name and split first.
epiphany was in main until Ubuntu 9.10 "Karmic" (no MIR).
description: | updated |
Changed in epiphany-browser (Ubuntu): | |
assignee: | Ubuntu Security Team (ubuntu-security) → Mathieu Trudel-Lapierre (cyphermox) |
We should probably try to avoid shipping more than one browser by default. Currently we ship Firefox (and shipping a browser on live images is up to the Desktop team, AFAIK). The package split appears to make sense to provide just the webapp integration feature (but it's not done yet).
I have not made a full review of epiphany yet; I think given it's a browser and has has security history (despite most issues would be caused by webkit2gtk if anything), it would benefit a proper Security team review.