Nice. I too wish I had infinite money to throw at otherwise creaky solutions for texlive installations. ;) I found out that one of gentoo's docbook packages in base (stage3) currently contains a high-rated CVE from an old bundled .jar file. It's not the end of the world™ because it's not a RCE, but it's kind of bad™ having old, vulnerable stuff included.