On Thu, Feb 17, 2011 at 14:52:49 +0000, brian m. carlson wrote:

> On Thu, Feb 17, 2011 at 12:35:26AM -0800, Vincent Cheng wrote:
> > * Package name    : dropbox
> >   Version         : 1.0.20-1
> >   Upstream Author : Dropbox, Inc.
> > * URL             : http://www.dropbox.com
> > * License         : Proprietary
> >   Section         : non-free/net
> >   Description     : secure backup, sync and sharing util
> 
> It looks like you're still missing the source for librsync.so.1 in your
> packages.  Also, I *strongly* recommend that you not include binary-only
> shared libraries that are already available in Debian.  The security
> team will not be very happy with you.  As an example, your package
> ships libz.so.1, which has been the target of a DSA previously.
> 
The security team doesn't support the non-free section in any way, so
not really.  Still a bad idea though.

Cheers,
Julien



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to