Bug#873016: [Pkg-javascript-devel] Bug#873016: node-lodash-packages: not preferred form for source: Should be built from node-lodash

2019-01-12 Thread Jonas Smedegaard
Quoting Ivo De Decker (2019-01-12 17:18:02)
> On Wed, Aug 23, 2017 at 11:41:28PM +0530, Pirate Praveen wrote:
> > On ബുധന്‍ 23 ആഗസ്റ്റ് 2017 11:33 വൈകു, Jonas Smedegaard wrote:
> > > Package: node-lodash-packages
> > > Severity: serious
> > > Justification: Policy 2.1
> > 
> > I do not think the root issue is serious, but only important.
> > 
> > > The source package node-lodash-packages does not contain the 
> > > source form preferred for editing by upstream.  Instead, upstream 
> > > documents how the contents of that code is generated from the 
> > > sources included in Debian in the source package node-lodash.
> > 
> > Adding a build dependency on node-lodash would be enough for the 
> > policy requirement.
> 
> No it wouldn't. You need to actually generate the code instead of 
> shipping the pregenerated code from upstream. Not doing that is a 
> serious bug. If you think this is easy to fix, please do so. If not, 
> this package should be removed from testing.

Relevant part of Debian Policy §2.1:

  The program must include source code

Build-depending on another package while using prebuilt code is 
argually permitted (but then discourage in other sections, with less 
strong words than "must"), but only if ensuring that in fact the 
distributed code was once built from this exact version of code in the 
build-depended on package.

I find it disgusting that you try find loopholes in policy, Praveen, 
instead of following the spirit of Debian Policy which is to distribute 
source, and build only from that distributed source (avoid distributing 
pre-built/pre-miified/pre-whatever code).

Please fix this properly!


 - Jonas

-- 
 * Jonas Smedegaard - idealist & Internet-arkitekt
 * Tlf.: +45 40843136  Website: http://dr.jones.dk/

 [x] quote me freely  [ ] ask before reusing  [ ] keep private


signature.asc
Description: signature


Bug#873016: [Pkg-javascript-devel] Bug#873016: node-lodash-packages: not preferred form for source: Should be built from node-lodash

2019-01-12 Thread Ivo De Decker
Hi,

On Wed, Aug 23, 2017 at 11:41:28PM +0530, Pirate Praveen wrote:
> On ബുധന്‍ 23 ആഗസ്റ്റ് 2017 11:33 വൈകു, Jonas Smedegaard wrote:
> > Package: node-lodash-packages
> > Severity: serious
> > Justification: Policy 2.1
> 
> I do not think the root issue is serious, but only important.
> 
> > The source package node-lodash-packages does not contain the source form
> > preferred for editing by upstream.  Instead, upstream documents how the
> > contents of that code is generated from the sources included in Debian
> > in the source package node-lodash.
> 
> Adding a build dependency on node-lodash would be enough for the policy
> requirement.

No it wouldn't. You need to actually generate the code instead of shipping the
pregenerated code from upstream. Not doing that is a serious bug. If you think
this is easy to fix, please do so. If not, this package should be removed
from testing.

Thanks,

Ivo



Bug#873016: [Pkg-javascript-devel] Bug#873016: node-lodash-packages: not preferred form for source: Should be built from node-lodash

2017-08-23 Thread Jonas Smedegaard
Quoting Pirate Praveen (2017-08-23 20:11:28)
> On ബുധന്‍ 23 ആഗസ്റ്റ് 2017 11:33 വൈകു, Jonas Smedegaard wrote:
> > Package: node-lodash-packages
> > Severity: serious
> > Justification: Policy 2.1
> 
> I do not think the root issue is serious, but only important.

Lack of source is serious.

Please elaborate why you think differently.


> > The source package node-lodash-packages does not contain the source 
> > form preferred for editing by upstream.  Instead, upstream documents 
> > how the contents of that code is generated from the sources included 
> > in Debian in the source package node-lodash.
> 
> Adding a build dependency on node-lodash would be enough for the 
> policy requirement.

If your reasoning is that the bug is easy to fix, then that does not 
change the severity (only - hopefully - the longevity of the bug staying 
open).


 - Jonas

-- 
 * Jonas Smedegaard - idealist & Internet-arkitekt
 * Tlf.: +45 40843136  Website: http://dr.jones.dk/

 [x] quote me freely  [ ] ask before reusing  [ ] keep private


signature.asc
Description: signature


Bug#873016: [Pkg-javascript-devel] Bug#873016: node-lodash-packages: not preferred form for source: Should be built from node-lodash

2017-08-23 Thread Pirate Praveen
On ബുധന്‍ 23 ആഗസ്റ്റ് 2017 11:33 വൈകു, Jonas Smedegaard wrote:
> Package: node-lodash-packages
> Severity: serious
> Justification: Policy 2.1

I do not think the root issue is serious, but only important.

> The source package node-lodash-packages does not contain the source form
> preferred for editing by upstream.  Instead, upstream documents how the
> contents of that code is generated from the sources included in Debian
> in the source package node-lodash.

Adding a build dependency on node-lodash would be enough for the policy
requirement.



signature.asc
Description: OpenPGP digital signature