Bug#907051: Say much more about vendoring of libraries

2018-08-23 Thread Jonathan Nieder
Hi, Arnaud Rebillout wrote: > During all this time when I was questioning myself on the reason to > un-bundle, the only official documentation I found was the short > paragraph in the Debian Policy [1], which is quite thin. Only now, > through the thread in debian-devel, I discover that there is

Bug#907051: Say much more about vendoring of libraries

2018-08-23 Thread Jonathan Nieder
Hi, Sean Whitton wrote: > On Thu 23 Aug 2018 at 12:27PM +0200, Alec Leamas wrote: >> https://fedoraproject.org/wiki/Packaging:Guidelines#Bundling_and_Duplication_of_system_libraries > > Thank you for sharing this link -- it seems like Fedora have thought > harder about this than we have, at

Bug#907051: Say much more about vendoring of libraries

2018-08-23 Thread Arnaud Rebillout
On 08/23/2018 08:13 PM, Sean Whitton wrote: > In particular, Policy should explain /why/ bundling is best avoided, and > the consensus that it sometimes has to happen should be noted, along > with mention of registering bundled copies with the security team where > appropriate. I can only agree

Bug#907051: Say much more about vendoring of libraries

2018-08-23 Thread Sean Whitton
Package: debian-policy Version: 4.2.0.1 Hello, On Thu 23 Aug 2018 at 12:27PM +0200, Alec Leamas wrote: > https://fedoraproject.org/wiki/Packaging:Guidelines#Bundling_and_Duplication_of_system_libraries Thank you for sharing this link -- it seems like Fedora have thought harder about this than