[Debian-astro-maintainers] Bug#949188: starjava-topcat: Please remove unneeded build-dependency on libxmlrpc3-client-java

Markus Koschany apo at debian.org
Fri Jan 17 22:42:54 GMT 2020


Source: starjava-topcat
Version: 4.7-1
Severity: important

Hi,

please remove the build-dependency on libxmlrpc3-client-java because
libxmlrpc3-java is EOL, no longer supported by upstream, affected by
CVE-2019-17570 and should be removed from Debian. starjava-topcat is
the only reverse-dependency. It appears you can safely remove the
build-dependency because it is not needed to build your package.

Regards,

Markus



More information about the Debian-astro-maintainers mailing list