Hi Paul, >> as the maintainer, I’d like to let you know the package ‘icdiff’ >> (new in unstable) contains a modified fork of Python’s difflib code. >> According to upstream, it’s "based on Python's difflib.HtmlDiff, with >> changes to provide console output instead of HTML output". > > Thanks, committed. Thanks! >> icdiff >> - libpython-stdlib <unfixable> (modified-embed) >> NOTE: core functionality based on Python difflib code with changed output format > > FYI, the format is the other way around and deals with source > packages. Ah, I see. This also makes more sense from a security point of view -- it maps included packages to including packages so fixes can be propagated downstream. Thanks for making this more clear. > Also, I think icdiff is more of a fork than modified-embed? I was reluctant to use 'fork' because its definition as 'a full-blown fork of another source package' suggested a complete copy of python. But you have seen many more of these cases and hence I trust you have made the right call. Thanks for the hints and best regards Sascha
Attachment:
signature.asc
Description: OpenPGP digital signature