[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Security concerns with minified javascript code



Raphael Hertzog <hertzog@debian.org> writes:

> In both cases, I worked around the problem by shipping the upstream
> sources in debian/missing-sources/ but I did not support doing changes
> there and did not rebuild the embedded libraries.
>
> In some cases, I do replace the embedded library with a symlink to the
> packaged files and I even created dh_linktree to make this easier.

How would someone rebuild the minified javascript files from the
missing-sources files?  I'm looking for something that can become a
template for other packages.  A README-source snippet to document the
process could say something like:

  The included JavaScript file is minified and thus not readily
  modifiable, but source code exists in debian/missing-sources/
  directory and can be rebuilt into the minified version by doing X.

My understanding of the DFSG is still that the compiler must be in main
for the package itself to be in main.  But having a README.source
explaining how to rebuild file files may be a first step.

/Simon

Attachment: signature.asc
Description: PGP signature


Reply to: