-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Emmanuel Bourg wrote:
> I checked the packages, the upstream releases of the versions in the
> repository are all licensed under the Apache License 2.0.

Ouch.

> Is it necessary to file a bug of each package, or it is possible to file
> only one bug covering all the packages?

It needs separate bugs, of severity "serious". That way it will get the 
attention of maintainers, and each package will be kept 
out of releases until fixed. You can probably make a little script to file the 
bugs.

I don't think this qualifies as a "mass bug filing" [1] but you can check the 
recommendations for those anyway.

> Ok, I'll build a patch on this basis.

That's greatly appreciated.

Cheers,

Marcus

[1] 
http://www.debian.org/doc/developers-reference/beyond-pkging.html#submit-many-bugs
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkoyUjAACgkQXjXn6TzcAQleMACeMcSu1e3rF5bTMg/27qnomgWC
R1oAoPATM7jFibxs2KT6pbN2uMaRKMMN
=wmBO
-----END PGP SIGNATURE-----



_______________________________________________
pkg-java-maintainers mailing list
[email protected]
http://lists.alioth.debian.org/mailman/listinfo/pkg-java-maintainers

Reply via email to