Re: [DRAFT] Policy: allow packages with bundled dependencies subject to mandatory labelling

"Dmitry E. Oboukhov" <[email protected]>
Newsgroups gmane.linux.debian.devel.policy,gmane.linux.debian.devel.general
Message-ID <aY3ILtA6r1XFlkmn@nb>
> Great. Can you share more details on the tooling you use?
> 
> I also think that the file format likely needs an extension for this use
> case. At present it basically maps a source package to other source
> packages that include a copy of the former. It also includes an optional
> version of when the copy ceases to exist. In particular, there is no way
> to record when a copy was introduced. With more vendoring going on, that
> aspect is becoming more important to keep the workload manageable.

Currently I've made a prototype utility dh_embedding, which as soon as
I polish it, I plan to upload to salsa and make a post here. With this
utility, Debian package developers will be able to easily (much like
installing files with dh_install) specify a list of embedded files. The
utility will add headers like: Embedded-Python: foo (1.0.1), bar
(2.0.1). This way, answering the question "does any Debian package
contain a vulnerable python package foo will be simple: just run
grep ^Embedded-Python: Packages. Once I finish this and upload it,
I plan to return to the mailing list and continue the discussion of
this problem.

-- 

. ''`.            Dmitry E. Oboukhov <[email protected]>
: :’  :                           <[email protected]>
`. `~’                  work: <[email protected]>
  `- 71ED ACFC 6801 0DD9 1AD1  9B86 8D1F 969A 08EE A756
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEce2s/GgBDdka0ZuGjR+Wmgjup1YFAmmNyCsACgkQjR+Wmgju
p1akZhAAkTJ6+aOO/QrmdZHkcTP9a08y1PVcF8sJZ8RQj/i90p5lr/5paCFj2UmY
GU21trj5qEr7xXQpxSxYi3CaBivpNWx7sOIAuHYqcrt2T8Ww7thx2V20Md/Y0Idl
hWdDuXOnZPva1cbIXrkssQX7dX5Y9KfNwL37EXrcwmMjy08+2myj3tFWP/gMYn25
RYYX7fr8WBpJPf5pBIRdtv6F+LWBVQsy0QrcvtILzNxhhgRUnYa0X+wIPA61v0Ug
egcVPCwF9l/PWeWaNOouAtFbpoI5NIJZoxHZR2TfOCs8JGF89gjN93/wm49J6eM+
n/Psm9wDZmeRhErqfVm8bFgP0VhlCn0Izng56/EWUDEN0kb/+LskOj+Ob+SAY5XV
K0seS+rhElLlsnyRREPd1pOBflyofNEsVGmBLJPW038RKneq6/gyEYHDG3+OtBFC
TNNXGtULMffOg0cuP7gp71tnNpokBdJJD2h47hh4AlKaXpkXUOD7/auqOCRCexYF
xSQgKQQk44R0KKMp4hoci2iaY/LziM4BbNHEKDV2VM8Y3oWb4w2JrOk94FVPWjnc
3L4aQr124P/jtE8AdZX0Eh4bg1INMOTS78+Rog86HGE5AoiWr0h3FJT4q06+RvUy
O9NJURhZ5AC9mFqDrffbW3TLwyBAlo5QYafh3n1kzrLAgdtwTUk=
=CIfj
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.