Hi, thanks for taking the time to contribute to Debian.

On Fri, 2026-01-09 at 23:53 +0100, Juan Mendez wrote:
> Package: sponsorship-requests
> Severity: normal

RFS bugs should be Severity: wishlist. The template that
mentors.debian.net provides should have this set correctly.

[...]
>    Changes since upstream:
>     - Vendored dependencies (+ds tarball) for offline Debian builds

Dependencies should not be vendored. They need to be packaged separately
in Debian and added to your package's Build-Depends (e.g. golang-github-
burntsushi-toml-dev(. It appears some dependencies aren't in Debian yet,
so they will need to be packaged first.


Since syft is primarily written in Go, consider maintaining it under the
Debian Go Packaging Team umbrella.

--
Maytham

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to