[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Recommending get-orig-source for packages ?



* Andreas Tille <andreas@an3as.eu>, 2013-12-04, 10:41:
uscan to grow features for removing files from upstream tarballs, in a declarative way preferably.
That's in devscripts git and will be included in the next devscripts version. (see [1])

So now you'll have to audit both d/watch and d/copyright before you can run uscan. *sigh*

AFAICS they way get_main_source_dir() is currently implemented lets malicious upstream to plant files in their tarball that would cause arbitrary code execution...

Well, there was a lenthy discussion, uscan bug, Wiki page trying to summarise everything. The people who contributed did not brought up your (and Paul's concern) and I guess Charles Plessy would have been in favour of using d/upstream. I do not think it is my fault if you did not raised you voice when it was time ...

https://lists.debian.org/debian-policy/20130116133513.GA4160@jwilk.net

By the way: currently you also have to audit another file in addition to d/watch if you need to exclude some files.

Unless you knew in advance that there's nothing to exclude, which was most often the case, and you could guess it just by looking at version.

--
Jakub Wilk


Reply to: