Bug#971515: kubernetes: excessive vendoring (private libraries)

2020-10-22 Thread Dmitry Smirnov
On Friday, 23 October 2020 4:20:37 AM AEDT Shengjing Zhu wrote: > However kubernetes is also a library, and the maintainer doesn't provide > it. It becomes headache for other maintainers. Yes we have to vendor "k8s.io/" all the time in multiple packages but I doubt it would be of help if

Bug#971515: Request for security team input on kubernetes TC bug

2020-10-22 Thread Dmitry Smirnov
On Thursday, 22 October 2020 2:22:11 AM AEDT Sean Whitton wrote: > The TC are being asked about src:kubernetes, and it would be good to > hear from you about whether and how security support is a relevant > consideration in determining whether the level of vendoring in that > package is

Bug#971515: kubernetes: excessive vendoring (private libraries)

2020-10-22 Thread Shengjing Zhu
On Tue, Oct 20, 2020 at 12:16:03PM -0700, Sean Whitton wrote: > > - are people trying to do cross-archive work going to find the packaging > of kubernetes getting in their way? (e.g. other Go team members > trying to update things, improve our binNMU techniques and machinery, > etc.) >