[Pkg-cacti-maint] About RFH Cacti and Cacti-spine

Sean Finney seanius at debian.org
Mon Apr 25 17:51:40 UTC 2011


hiya,

On Mon, Apr 25, 2011 at 08:21:01PM +0700, Mahyuddin Susanto wrote:
> First i doing packaging stuff with updating debconf translations,
> rewriting d/copyright as dep5 format. My works can be found at here
> http://people.ubuntu.com/~udienz/pkg/cacti.debdiff

One quick comment: I see you mention adding nginx/lighthttpd to Depends but
don't see the actual change adding them in the control file :)

> 
> but i'm not confident to push-ing to git because my changes is trivial, and:

It's fine to push even trivial stuff to git right away, I'd say.
if you have any doubts feel free to ask, or mail the patch to the list
with git format-patch + send-email, whatever you're comfortable with.

I would request though that the commits be isolated/broken into
individual changes and not "lumped together", and that they not include
debian/changelog (git-dch can generate a nice changelog later and
this allows lower chances of conflicts during cherry-pick/merge/revert).

>  - Bug 604395: I've forwarding to upstream for feedback

cool, thanks.  definitely something that should be addressed upstream.

>  - From security-tracker i see that some CVE still exits in lenny, can i
> fix it?

If you'd like to spend some time on it, by all means feel free to do so, but
they're pretty old issues and most/all[1] of them are low prio XSS
related ones that would involve a lot of work to dig out the right fixes.
So it could be a good exercise, and I certainly wouldn't refuse the help,
but if you have better things to do I would suggest you do those instead :)


	sean

[1] minus the "admin can run arbitrary commands instead of ping" one, which
    should be ignord imho.



More information about the Pkg-cacti-maint mailing list