Bug#789256: cmus: Pulls in unwanted and potentially dangerous DECnet packages through libroar2
Jonas Smedegaard
dr at jones.dk
Fri Jun 19 18:25:20 UTC 2015
severity 789256 wishlist
retitle 789256 cmus: please drop support for ROAR
thanks
Quoting James Cowgill (2015-06-19 06:02:31)
> On Fri, 2015-06-19 at 10:52 +0200, John Paul Adrian Glaubitz wrote:
>> Severity: serious
>> Justification: potentially breaks other packages
>> As previously discussed, I am opening a bug report against cmus to
>> drop ROAR support from cmus. The reason is that ROAR still depends on
>> libdnet which is potentially dangerous as it may disrupt a user's
>> network configuration [1] for users who run apt-get with
>> --install-suggests and a consequently, the removal of ROAR audio
>> support was previously requested in Debian [2] as well as Ubuntu [3].
>
> Using apt-get with --install-suggests isn't that common so I don't
> think this warrants an RC severity (it doesn't break the package for
> everyone).
cmus does not pull in ptentially dangerous packages - the package
management system does, via the --install-suggests argument.
This issue is therefore not even important, but only a wishlist issue of
dropping a truly optional feature. Lowering accordingly.
- Jonas
--
* Jonas Smedegaard - idealist & Internet-arkitekt
* Tlf.: +45 40843136 Website: http://dr.jones.dk/
[x] quote me freely [ ] ask before reusing [ ] keep private
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-multimedia-maintainers/attachments/20150619/2cd8897e/attachment.sig>
More information about the pkg-multimedia-maintainers
mailing list