Hi, On Sun, Jan 17, 2021 at 10:44:09PM +0100, Chris Hofstaedtler wrote: > Source: tokyotyrant > > tokyotyrant is a network server. It's upstream has vanished, and > the last upstream release was in 2012 or earlier; that version is > not packaged in Debian. The package is currently orphaned in Debian. > > Should bullseye really ship with such a package? > > Also, it exposes tokyocabinet to the network, which itself is a > rather old codebase, last updated in 2013. A successor, Tkrzw is > actively maintained. > > Security team, maybe you also want to chime in here. > > I'll consider raising this bugs priority over time.
If unmaintained, I guess this can make sense. But one would need to solve the collectd build-dependency, as we probably woulld not want to loose collectd in bullseye. carnil@coccia:~$ dak rm --suite=sid -n -R tokyotyrant Will remove the following packages from sid: libtokyotyrant-dev | 1.1.40-4.3 | amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x libtokyotyrant3 | 1.1.40-4.3 | amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x tokyotyrant | 1.1.40-4.3 | source, amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x tokyotyrant-dbg | 1.1.40-4.3 | amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x tokyotyrant-doc | 1.1.40-4.3 | all tokyotyrant-utils | 1.1.40-4.3 | amd64, arm64, armel, armhf, i386, mips64el, mipsel, ppc64el, s390x Maintainer: Örjan Persson <ora...@fobie.net> ------------------- Reason ------------------- ---------------------------------------------- Checking reverse dependencies... # Broken Build-Depends: collectd: libtokyotyrant-dev Dependency problem found. carnil@coccia:~ Rgards, Salvatore