[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [SECURITY] [DSA 1156-1] New kdebase packages fix information disclosure



Florian Weimer wrote:
* Nick Boyce:

For interest, can anyone explain why a problem with kdm leads to the
need to reissue so many KDE packages ?

Security updates a performed on per source package (after all, we need
to ship an updated source package to comply with the DFSG and various
licenses).  The source package building KDE also builds tons of other
packages.

Um .. okay, thanks for explaining that. I should have thought of that ... except that seems a pretty weird idea - to bundle so much source code into one monster "kde-guts" source package.

It makes sense (to me) to bundle closely related source together - but isn't it a bit self-defeating to bundle so many disparate program sources (kate, konsole, konqueror ...) into the same source package as such a small thing as kdm ?

I don't mean to complain - not being a developer I may well not be aware of some very good reason for it - but the pain that ensues for people like me, on dial-up links (don't ask ...), when we must download so many binaries just because something small like kdm has changed, is non-trivial.

If there's a stock explanation you can point me to I'd be grateful for the education.

Cheers
Nick Boyce
Bristol, UK



Reply to: