[Pkg-security-team] Co-maintenance of pixiewps and/or wafw00f

Raphael Hertzog hertzog at debian.org
Wed Nov 16 10:42:03 UTC 2016


Hi,

On Wed, 16 Nov 2016, Samuel Henrique wrote:
> Raphael, could this have happened because i did not reuse the kali git
> repo, then by having pristine-tar recreating the tarball, thus changing the
> files's creation date? It looks like the debian tarball's files creation
> date coincide to when i imported them to our git repo.

No, I checked the git repo and the tarball in pristine-tar is correct:

$ pristine-tar checkout ./pixiewps_1.2.2.orig.tar.gz
$ md5sum pixiewps_1.2.2.orig.tar.gz 
52c0cd20eff10c5c422980a13fc86730  pixiewps_1.2.2.orig.tar.gz

I guess it's again Gianfranco who recreated the tarball instead
of using the one which is in the pristine-tar branch.

Gianfranco, can you make sure to add this to your ~/.gbp.conf ?

[DEFAULT]
pristine-tar = True

And double check before you sponsor any new package from Kali. :)

Thanks!
-- 
Raphaël Hertzog ◈ Debian Developer

Support Debian LTS: http://www.freexian.com/services/debian-lts.html
Learn to master Debian: http://debian-handbook.info/get/



More information about the Pkg-security-team mailing list