Hi Moritz,

> This package includes a whole copy of Gimp

You are right: the source package includes a copy of GIMP and the binary
packages include the GIMP binary (but not anything else).

> which regularly has vulnerabilities,

The idea is to make it depend on the latest version of the GIMP and update
it whenever a new version of GIMP comes out.  So it will be updated whenever
a new security fix for GIMP is released.  In fact, with the last release of
ingimp that I made yesterday, I set the dependency to be:

  gimp (>= 2.2.16), gimp (<< 2.2.17)

to force the versions to match exactly.

> it cannot be included in Lenny as is.

Could you explain a bit more why you think that way?  As long as ingimp
keeps up with GIMP releases, I fail to see how it should be treated any
differently.

Cheers,

Francois


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to