[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

please use release tarballs :-)



Hi,

FYI, while communicating with Matt Zimmerman a couple of weeks back on 
security issues for KDE (that the woody debs on kde.org have those fixed as 
well - Martin Schulze included that info while he was doing that) we were 
discussing things like that the KDE packages in sid are made from CVS 
checkouts rather than from the original release tarballs.  Matt would prefer 
to get them build from the release tarballs with patchsets against CVS if you 
need them - however, this is none of my business so you might want to check 
with Matt how to proceed with your next upload as that's probably the last 
chance to do it the way the security team would like to have things done for 
sarge.

I know making patchsets for every change requires a lot of time and effort but 
you should seriously think about doing it; it will ensure more quality 
control and give the security team a better base in case they will receive 
security patches from KDE - again this is my personal opinion, I'm not a 
debian developer yet that I could do this on my own but I would be willing to 
help there.

Ralf
-- 
We're not a company, we just produce better code at less costs.
--------------------------------------------------------------------
Ralf Nolden
nolden@kde.org

The K Desktop Environment       The KDevelop Project
http://www.kde.org              http://www.kdevelop.org

Attachment: pgpeXMHdQzFDA.pgp
Description: signature


Reply to: