[Pkg-owncloud-maintainers] Bug#722213: owncloud: contains unregistered embedded copy of php-patchwork-utf8
Helmut Grohne
helmut at subdivi.de
Mon Sep 9 06:17:53 UTC 2013
Package: owncloud
Version: 5.0.10+dfsg-1
Severity: important
Dear Maintainer,
It has come to my attention that owncloud fully embeds[1] the
php-patchwork-utf8 package. This practise is discouraged by the Debian
policy, but not prohibited. Please investigate whether you can use the
php-patchwork-utf8 package instead of embedding it. In case there is a
strong version binding, this may be infeasible.
If this is not possible, at a bare minimum you need to register[2] your
embedded copy with the security tracker. This is especially true,
because both packages are network facing components and therefore are
likely candidates for security updates.
In case you conclude that removing the embedding is not feasible, I can
do the registration for you.
Helmut
[1] http://dedup.debian.net/compare/owncloud/php-patchwork-utf8
[2] https://wiki.debian.org/EmbeddedCodeCopies
More information about the Pkg-owncloud-maintainers
mailing list