[pkg-php-pear] php-dompdf_0.6.0~beta3+dfsg-1_amd64.changes REJECTED

David Prévot taffit at debian.org
Sat Nov 23 14:42:18 UTC 2013


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hi Paul, thanks for the review.

Le 23/11/2013 00:01, Paul Richards Tagliamonte a écrit :

> lib\fonts\ contains lots of stuff we really really shouldn't distribute. This
> would get us a lawsuit. Please do go through the source and make sure you're
> stripping out all the non-free things. I stoped there.

[From IRC]
09:40 < taffit> paultag: about php-dompdf’s REJECT, did you notice “the
14 PostScript(R) AFM files it accompanies may be used, copied, and
distributed for any purpose and without charge, with or without
modification” in lib/fonts/mustRead.html and d/copyright?
09:40 < taffit> Anyway, they’re not shipped in the binary package (since
already packaged somewhere else), so I can provide a revised version shortly
[…]
10:23 < paultag> taffit: I didn't, but the filenames of the fonts were
enough to make me very concerned - the linotype licensing is not floss
friendly
10:23 < paultag> taffit: if I'm wrong, re-upload without changes, but I
really think that's trouble
[…]
10:24 < taffit> paultag: changes are ready, I’m about to re-upload a
font-free version, just checking some more stuff

0.6.0~beta3+dfsg0-1 uploaded

> Relatedly, please also properly depend on JavaScript libraries (or package them
> on their own), so that the source contains no code copies.

AFAICT, only EventHelpers.js is shipped in
/usr/share/doc/php-dompdf/examples/, and is not already packaged in
Debian. Even if I usually follow that trend (packaging extra JS in the
accurate team, and çake the binary package depends on it), I don’t
believe it’s worth the trouble here, just for an example. On the other
hand, if shipping it is not desirable, I’m totally fine to strip it away
from the examples dir.

Regards

David


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEcBAEBCAAGBQJSkL7JAAoJEAWMHPlE9r08tc4H+wSY7zSBFpGiLqcYvalgZY8o
l49Oy8ounjZOWEnEyaulbJGZ2dx70IuvMQz0z8SWrf+fTSyfehHfknDFhKlB+QwW
8bOvxHl4YaYfzUWOUEuVEDPr7A9ylmDIQXvNp2R+Woce85CsCXqJA+3qkKjHLCJa
o+UAxKlKQYTipQ3ELaomIzz0drMpUtj+JNJDQCo3IYfoRCSUdWoao92+S4kU3eLY
MNTphxLdm8YmESZamO937Ju963zePaMr3KZz4/J6YFZKPwsr7a0OZegGw8vSrtv9
CLMvwZWRUEhPz7s03vG2MouIco0brF/HEOYZ0mIq8aHnCnmapz0eraxiG31Qomg=
=Nc7z
-----END PGP SIGNATURE-----



More information about the pkg-php-pear mailing list