[Debian-pan-maintainers] Comments regarding pyxrd_0.8.4-1_amd64.changes
Scott Kitterman
ftpmaster at ftp-master.debian.org
Thu Jan 27 21:04:54 GMT 2022
I am going to accept this, but I am concerned about the presence of pip in
build-depends. Looking throught the upstream source, I don't see where it is
used/needed. If it is used, pip is very happy to download and excute code
from the internet, which is prohibited by Debian policy. Please double check
that this is acutally required and if it is, ensure it's not downloading
anything.
Scott K
More information about the Debian-pan-maintainers
mailing list