Add indirect dependacies. Switch to lcms2 since that is actualy used. MFH: 2016Q3 Security: f5035ead-688b-11e6-8b1d-c86000169601, CVE-2016-6855