Bug#789256: cmus: Pulls in unwanted and potentially dangerous DECnet packages through libroar2

John Paul Adrian Glaubitz glaubitz at physik.fu-berlin.de
Sat Jun 20 18:50:28 UTC 2015


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On 06/20/2015 08:42 PM, Jonas Smedegaard wrote:
> Please file bugreports regarding security flaws of DECnet packages
>  against those DECnet packages, *not* their reverse dependencies!

Jonas, do you actually read what I wrote? This very bug report exists
because the maintainer of roaraudio refuses to handle any bug reports
regarding this issue - heck, he even claims that libroar2 does not
depend on libdnet which is, of course, incorrect - and the maintainer
for any of the DECnet stuff doesn't exist anymore, both in Debian and
upstream.

The sole reason for this bug report is to free cmus from broken
and unwanted dependencies. I am fully aware that the transitive
dependency on libdnet is to be blamed on roaraudio but as you have
seen, it's absolutely pointless to talk to its maintainer about
the subject. He ignores bug reports and refuses to accept the dependency
exists in the first place.

Adrian

- -- 
 .''`.  John Paul Adrian Glaubitz
: :' :  Debian Developer - glaubitz at debian.org
`. `'   Freie Universitaet Berlin - glaubitz at physik.fu-berlin.de
  `-    GPG: 62FF 8A75 84E0 2956 9546  0006 7426 3B37 F5B5 F913
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJVhbX0AAoJEHQmOzf1tfkTywYP/0YTJgOX3db6RjZ1SO8fHIfQ
6H3qEKjblWx7Ku1vO3TuwU/WEJYL8qlr4IBTamURvFV73Od3ByXGq5u184w5g0fC
qH+taEVOs6trUYLOstpaSJVxlL10mZPV0a/7x1tJt28Vplagftvkv3VMZQdSDgVh
LjLi8UpqUvQ4Gs0UjF1C829eBanq0NqidsSKX5nilp1F2wuyYXxaBhJNCUCxu+Yn
OkR7AFOg3RWrZNGznx5gHmZ3XSErjED3/G22txmIq4oU4FUFI7tvikeGpelSEfOp
dYZCaVJgLyYkKeCqbtrdVM6srDFf6MB6Y9DFEApGvSVMOq+uSaOLe28WTRCSyar9
QDCcF6s63gn+L+Wr/2yeLy23mqpCeT/A5NThAKfeCvBGeexa9tpuqcO20NeeYUgD
w7N02pNO9dXhB5v+1TRC76PtaumePa8aFfxPWHxvjHx7NynKvRW1KKftF91Njf2O
yNhajrRm0vLIfxPOXTHqGcRHPY/+xaDYswsrtLpV446GkoH9j8I5hsnQYWA9tVxG
H7PjWG4dxsCh1A3aAiXB9MYDcSo8DDj2PRx9eXhzVdNriAwJX7Ql2jqCH9or8BmL
UPBCtw6lDpErpdnl3CuKjEqMyV7TjxnI+JHnIj8/E2a6lDlUkHPaIyovCPXAH5UE
9xtsLlc3A7A5aszaYOwB
=Kpdg
-----END PGP SIGNATURE-----



More information about the pkg-multimedia-maintainers mailing list