freenode
Distributions & Plumbing

WebKitGTK orphaned in Fedora as maintainer leaves Red Hat

Fabio Valentini has taken the package; EPEL 10 remains badly outdated with hundreds of open CVE trackers, and GTK 3 support faces an uncertain upstream future.

Michael Catanzaro is orphaning WebKitGTK in Fedora as he leaves Red Hat at the end of the month, saying the company no longer intends to maintain the package. Fabio Valentini has since taken ownership of the Fedora package.

WebKitGTK is the browser engine behind a long list of desktop applications, not only GNOME software. Reverse dependency checks turn up many consumers, including KiCad via wxGTK and even components pulled in by rpm. Maintaining it means tracking frequent upstream releases: the CVE volume is high, and the main downstream hazard is s390x build failures on an architecture upstream does not test.

Catanzaro also flagged EPEL 10, where a different maintainer had left the package extremely outdated with roughly 400 unresolved CVE tracker bugs. He first proposed retiring it from EPEL 10, then orphaned it instead so a successor can decide whether to retire or keep the branches current. Stephen Smoogen backed retirement if no one is paid to carry the load; Valentini noted EPEL retirement is allowed when the documented process is followed.

A longer-term worry is GTK 3. GNOME has stopped building WebKitGTK's GTK 3 support to cut build times, which Catanzaro called hard on remaining GTK 3 apps and a weak case for WebKitGTK to keep that path forever. Milan Crha and others pushed back that GTK is not GNOME and that many non-GNOME packages still need the GTK 3 API. Neal Gompa added that porting to GTK 4 is non-trivial after large API removals. Catanzaro said nothing is decided upstream yet: GTK 3 support will go eventually, possibly via a new API version if maintainers want it, but the orphaned Fedora package was the immediate problem. He urged whoever owns it to keep every branch updated.