[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1112402: RFS: python-cvss/3.6-1 -- CVSS2/3/4 library with interactive calculator for Python



Control: tags -1 moreinfo

On Fri, 29 Aug 2025 17:22:01 +0530
Nishit Majithia <nishit.nm@gmail.com> wrote:

> I am looking for a sponsor for my package python-cvss:

hi Nishit,

took a look at the package, and found a couple things that need
attention:

* copyright: missing info for a bunch of files that appear to be 
  licensed under 3-clause bsd or similar:
  tests/schemas/cvss-v2.0.json:3:        "Copyright (c) 2017, FIRST.ORG, INC.",
  tests/schemas/cvss-v3.1.json:3:        "Copyright (c) 2021, FIRST.ORG, INC.",
  tests/schemas/cvss-v4.0.json:3:        "Copyright (c) 2023, FIRST.ORG, INC.",
  tests/schemas/cvss-v3.0.json:3:        "Copyright (c) 2017, FIRST.ORG, INC.",

* control: the long description would benefit from spelling out the
  meaning of the "CVSS" abbreviation, along the lines of the upstream
  README file.

* the manpage is auto-generated with help2man and gets overwritten on
  every build. Updating the version in the static copy that sits in
  the debian directory is therefore pointless, as is keeping that
  file around in the first place.

* tests: d/control sets 'Testsuite: autopkgtest-pkg-pybuild', but
  there's also a "manual" definition in d/tests that appears to run
  the identical set of tests again. If so, the latter is redundant;
  if not, it should be fixed to not run tests inside the extracted
  source package (use the $AUTOPKGTEST_TMP directory instead).


Let me know when you have an updated package ready.

Attachment: pgpC_CveqdQuj.pgp
Description: OpenPGP digital signature


Reply to: