# Tukaaani xz\_util vulnerability

**URL:** <https://forum.graphviz.org/t/tukaaani-xz-util-vulnerability/3408>\
**Category:** Help\
**Created:** [September 14, 2026, 10:45pm UTC](https://forum.graphviz.org/t/tukaaani-xz-util-vulnerability/3408 "2026-09-14T22:45:22Z")\
**Posts on this page:** 1\
**Showing post:** 21

<div class="post-metadata">

**Author:** ![magjac](https://sea2.discourse-cdn.com/graphviz/user_avatar/forum.graphviz.org/magjac/32/16_2.png) [@magjac](https://forum.graphviz.org/u/magjac)\
**Post date:** [September 21, 2026, 10:47am UTC](https://forum.graphviz.org/t/tukaaani-xz-util-vulnerability/3408/21 "2026-09-21T10:47:23Z")

</div>

We have three flavors of Windows: native, MinGW and Cygwin. The two last have established package managers. Native does not. I think. Or have many partial. IDK. Matt can probably elaborate. Native Windows is a mess.

Although I set up most of the Windows build jobs originally because I was the only maintainer with a Windows machine, I know almost nothing about Windows and extremely little about package managers in general. The separate Windows dependencies repo was inherited from an earlier maintainer, but I introduced vcpkg to update it because it seemed like a good idea at the time. 😬. Maybe it was. Maybe it wasn’t. It’s used by native Windows only and unrelated to MinGW/MSYS2/pacman.

Ideally (maybe?) we should use Docker also for Windows. I tried that [six years ago](https://forum.graphviz.org/t/docker-containers-for-windows-builds/267) to no avail.

---

_[View the full topic](https://forum.graphviz.org/t/tukaaani-xz-util-vulnerability/3408)._
