Bug#717213: Module::Metadata and taint mode

Niko Tyni ntyni at debian.org
Wed Sep 11 19:48:14 UTC 2013


forwarded 717213 https://rt.cpan.org/Public/Bug/Display.html?id=88576
tag 717213 fixed-upstream 
forwarded 722210 https://rt.cpan.org/Public/Bug/Display.html?id=88576
tag 722210 fixed-upstream 
block 722210 by 717213 
thanks

#717213 and #722210 are the same issue. This was recently fixed upstream
in Module-Metadata 1.000018 or so. See [rt.cpan.org #88576].

It seems useful to track the issue in both perl-modules and
libmodule-metadata-perl, so I'm not merging the bugs.

Clearly libmodule-metadata-perl needs to be fixed first, otherwise
installing its broken version would override a fixed version in
perl-modules.

While perl and libmodule-metadata-perl in stable are affected [1],
the primary problem seems to be via use by Module-Load-Conditional,
which doesn't happen in stable. So I don't think we need a stable update
unless another vector shows up.

[1] as per the test by Chris Williams (BINGOS):
  perl -TMModule::Metadata -E 'say Module::Metadata->new_from_module( "Test" )->filename'

-- 
Niko Tyni   ntyni at debian.org



More information about the pkg-perl-maintainers mailing list