tomcat6 wheezy DSA (was/and Re: tomcat6_6.0.41-2+squeeze5_amd64.changes REJECTED
tony mancill
tmancill at debian.org
Sun Nov 23 21:41:17 UTC 2014
On 11/23/2014 01:16 PM, Holger Levsen wrote:
> Hi Tony,
>
> On Sonntag, 23. November 2014, tony mancill wrote:
>> The cruft report for unstable will look *very* different due to 6.0.41-3
>> being a *radically* different package.
>
> no, the report exactly looks like this *because* of this:
>
>>> * Build only the libservlet2.5-java and libservlet2.5-java-doc
>>> packages.
> [..]
>
>> The decision/requirement to remove tomcat6 from jessie has been
>> requested by the Security team for quite a while, and the 6.0.41-3
>> source upload effectively does this by just building libservlet2.5-java
>> (without which we would have many packages with missing r-deps).
>
> what's missing now is a bug against ftp.debian.org asking for the removal of
> the binaries from sid, which are not build by the -3 anymore.
RM/NBS bug filed, #770769.
> *then*, -3 can migrate to jessie and those binaries will vanish
> "automagically".
>
> and the stuff in the cruft report breaks because of this.
>
>> I not sure I understand all of the ramifications of the statement I'm
>> about to make, but for the purposes of squeeze and wheezy, we need to
>> consider 6.0.41-2 as the last version of a "complete" tomcat6 source
>> package.
>
> yup, I will base the wheezy upload on this.
Thank you!
tony
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-java-maintainers/attachments/20141123/ff436d5a/attachment.sig>
More information about the pkg-java-maintainers
mailing list