Re: [DRAFT] Policy: allow packages with bundled dependencies subject to mandatory labelling
"Dmitry E. Oboukhov" <[email protected]>
| Newsgroups | gmane.linux.debian.devel.policy,gmane.linux.debian.devel.general |
|---|---|
| Message-ID | <aY3ILtA6r1XFlkmn@nb> |
> Great. Can you share more details on the tooling you use? > > I also think that the file format likely needs an extension for this use > case. At present it basically maps a source package to other source > packages that include a copy of the former. It also includes an optional > version of when the copy ceases to exist. In particular, there is no way > to record when a copy was introduced. With more vendoring going on, that > aspect is becoming more important to keep the workload manageable. Currently I've made a prototype utility dh_embedding, which as soon as I polish it, I plan to upload to salsa and make a post here. With this utility, Debian package developers will be able to easily (much like installing files with dh_install) specify a list of embedded files. The utility will add headers like: Embedded-Python: foo (1.0.1), bar (2.0.1). This way, answering the question "does any Debian package contain a vulnerable python package foo will be simple: just run grep ^Embedded-Python: Packages. Once I finish this and upload it, I plan to return to the mailing list and continue the discussion of this problem. -- . ''`. Dmitry E. Oboukhov <[email protected]> : :’ : <[email protected]> `. `~’ work: <[email protected]> `- 71ED ACFC 6801 0DD9 1AD1 9B86 8D1F 969A 08EE A756
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEce2s/GgBDdka0ZuGjR+Wmgjup1YFAmmNyCsACgkQjR+Wmgju p1akZhAAkTJ6+aOO/QrmdZHkcTP9a08y1PVcF8sJZ8RQj/i90p5lr/5paCFj2UmY GU21trj5qEr7xXQpxSxYi3CaBivpNWx7sOIAuHYqcrt2T8Ww7thx2V20Md/Y0Idl hWdDuXOnZPva1cbIXrkssQX7dX5Y9KfNwL37EXrcwmMjy08+2myj3tFWP/gMYn25 RYYX7fr8WBpJPf5pBIRdtv6F+LWBVQsy0QrcvtILzNxhhgRUnYa0X+wIPA61v0Ug egcVPCwF9l/PWeWaNOouAtFbpoI5NIJZoxHZR2TfOCs8JGF89gjN93/wm49J6eM+ n/Psm9wDZmeRhErqfVm8bFgP0VhlCn0Izng56/EWUDEN0kb/+LskOj+Ob+SAY5XV K0seS+rhElLlsnyRREPd1pOBflyofNEsVGmBLJPW038RKneq6/gyEYHDG3+OtBFC TNNXGtULMffOg0cuP7gp71tnNpokBdJJD2h47hh4AlKaXpkXUOD7/auqOCRCexYF xSQgKQQk44R0KKMp4hoci2iaY/LziM4BbNHEKDV2VM8Y3oWb4w2JrOk94FVPWjnc 3L4aQr124P/jtE8AdZX0Eh4bg1INMOTS78+Rog86HGE5AoiWr0h3FJT4q06+RvUy O9NJURhZ5AC9mFqDrffbW3TLwyBAlo5QYafh3n1kzrLAgdtwTUk= =CIfj -----END PGP SIGNATURE-----