Bug#964496: libjson-validator-perl: URL is gone, this is now RC

Wouter Verhelst w at uter.be
Thu Dec 3 09:43:39 GMT 2020


Hi Andrius,

On Mon, Nov 30, 2020 at 01:00:46PM +0200, Andrius Merkys wrote:
> Hello,
> 
> On 2020-11-29 18:59, Wouter Verhelst wrote:
> > This bug is still present. Additionally, the URL for the OpenAPI JSON
> > scheme now returns a 404 error, which means that any software using
> > OpenAPI on Debian with this bug present will fail to function correctly.>
> > Please fix this bug before the release of bullseye.
> 
> While I agree that this is an important issue, I do not think severity
> "serious" is appropriate here. It is true that the upstream provides
> caching mechanism, but any URL may become offline, and a general
> approach to prevent failures in such cases is to use Debian-packaged
> files.

... which is exactly what this bug report is talking about, so I don't
understand?

> With OpenAPI schemas provided in openapi-specification binary
> package, this is as simple as replacing OpenAPI URLs with
> /usr/share/openapi-specification/schemas/$VERSION/schema.json in the
> using code.

Unfortunately, that doesn't work very if the code in question is also
packaged (because upgrades would blow those changes away, yada yada).

> The upstream caching mechanism could indeed be employed, but as said
> before [1], preferable way to use it needs transparency of cache hashes.
> 
> By the way, could you please provide OpenAPI URL that returns 404 now?

That would be https://spec.openapis.org/oas/3.0/schema/2019-04-02

-- 
To the thief who stole my anti-depressants: I hope you're happy

  -- seen somewhere on the Internet on a photo of a billboard



More information about the pkg-perl-maintainers mailing list