Re: Proposal for removal of mICQ package
On Sat, 15 Feb 2003, Martin Godisch wrote:
> On Sat, Feb 15, 2003 at 12:33:47 +0700, Robert Lemmen wrote:
> > On Fri, Feb 14, 2003 at 10:35:05PM +0100, Martin Godisch wrote:
> Thank you! Together I think we should be able to do an audit in a
> reasonable timeframe.
>
> Whatever finds a consensus on this list. The package should be dropped
> now and let in again after an audit, or updated to a fixed but not yet
The package should be removed now. As it stands, we cannot trust upstream
and we cannot trust the maintainer when dealing with this particular
upstream.
There is no reason why it could not be repackaged, audited, and reinjected
into the distro, later. But it must be scrutinized for easter eggs from now
on. Given time, if the new maintainer manages to get a good relationship
with upstream going, less paranoia will be needed... or not ;-)
--
"One disk to rule them all, One disk to find them. One disk to bring
them all and in the darkness grind them. In the Land of Redmond
where the shadows lie." -- The Silicon Valley Tarot
Henrique Holschuh
Reply to: