Re: ipp-usb 0.9.27 announce
Johannes Meixner <[email protected]> Wed, 24 Jul 2024 16:14:35 +0200
| Newsgroups | dev.linux.lists.printing-architecture |
|---|---|
| Message-ID | <[email protected]> |
Hello Zdenek On 2024-07-24 15:37, Zdenek Dohnal wrote: > can I somehow ignore vendor dir of goipp at the moment? I don't know how ipp-usb is made on Fedora / Red Hat so I may misunderstand things here. I guess you talk about some additional vendor.tar.zst source file? At openSUSE we have ipp-usb and goipp as separated source packages in the openSUSE Build Service (OBS) see https://build.opensuse.org/package/show/Printing/ipp-usb and https://build.opensuse.org/package/show/Printing/goipp Why separated source packages? See my https://build.opensuse.org/request/show/1157901#comment-1919874 where I wrote (excerpt): ----------------------------------------------------------- please describe via an explanatory comment in the spec file what the additional vendor.tar.zst source is, what its purpose is, and wherefrom it can be downloaded (exact upstream download URL) so that others at openSUSE can understand what that additional source is, why it is needed for the openSUSE package, and that we can verify that vendor.tar.zst in the openSUSE package is the unmodified source from its upstream URL. ----------------------------------------------------------- and my subsequent https://build.opensuse.org/request/show/1157901#comment-1919883 where I wrote (excerpt): ----------------------------------------------------------- In this particular case (additional vendor.tar.zst source) the files in vendor/github.com/OpenPrinting/goipp neither match GitHub master code in https://github.com/OpenPrinting/goipp nor what on https://github.com/OpenPrinting/goipp/tags the tar.gz for v1.0.0 nor v1.1.0 result (in contrast to what vendor/modules.txt seems to tell) so currently the additional vendor.tar.zst source looks rather "suspicious" - at least to me. ----------------------------------------------------------- I wrote that in Aplil 2024 with the XZ attack in my mind so additional sources that do not match what one gets from its "well known" upstream URLs are rather scary. I would recommend to Keep Separated Sources Strictly Separated ( KSSSS ;-) so that others can understand what "the sources" are and can retrace where "the sources" come from and can validate that "the sources" are unmodified upstream sources. Kind Regards Johannes Meixner -- SUSE Software Solutions Germany GmbH Frankenstr. 146 - 90461 Nuernberg - Germany (HRB 36809, AG Nuernberg) GF: Ivo Totev