Source: gperf
Version: 3.0.4-1
Severity: serious
Justification: Policy 4.5
Usertags: timestamps


Your packages contains an embedded code copy of texi2html which is
copyright Lionel Cons and others and is licensed under the GPL and
Creative Commons Attribution-ShareAlike license. This information is
missing from debian/copyright of gperf and is thus a violation of policy

I found this bug while working on the reproducible builds project [1] to
make texi2html produce reproducible output.

>From that point of view there are two options:

 1. remove the embedded code copy [2] and build-depend on texi2html
    (this would also make policy §4.13 happy). I would prefer this
    solution and would supply you with a patch if you want. Your package
    would then automatically become reproducible.

 2. keep the embedded code copy and amend your debian/copyright. In this
    case I would open another bug so that your embedded copy of
    texi2html is patched to produce reproducible output.

Kind regards, 


Reproducible-builds mailing list

Reply via email to