Re: [Pkg-javascript-devel] components without major risks

2018-12-01 Thread Ross Gammon
On 11/27/18 1:47 PM, Xavier wrote: > Maybe a "debian/README.source" might be required for the DD to explain > his choices (lintian error if missing). +1 This is good practice anytime we add or subtract from the upstream tarball. Otherwise it is hard for other team members to help out later. --

Re: [Pkg-javascript-devel] components without major risks

2018-11-27 Thread Xavier
Le 27/11/2018 à 15:48, Bastien ROUCARIES a écrit : > On Tue, Nov 27, 2018 at 3:45 PM Xavier wrote: >> >> Le 27/11/2018 à 15:33, Jonas Smedegaard a écrit : >>> Quoting Xavier (2018-11-27 15:22:10) Le 27/11/2018 à 15:03, Jonas Smedegaard a écrit : > Quoting Xavier (2018-11-27 14:00:42)

Re: [Pkg-javascript-devel] components without major risks

2018-11-27 Thread Xavier
Le 27/11/2018 à 15:24, Jérémy Lal a écrit : > > > Le mar. 27 nov. 2018 à 15:22, Xavier > a écrit : > > Le 27/11/2018 à 15:03, Jonas Smedegaard a écrit : > > Quoting Xavier (2018-11-27 14:00:42) > >> Le 27/11/2018 à 11:55, Jonas Smedegaard a écrit : > >>>

Re: [Pkg-javascript-devel] components without major risks

2018-11-27 Thread Bastien ROUCARIES
On Tue, Nov 27, 2018 at 3:45 PM Xavier wrote: > > Le 27/11/2018 à 15:33, Jonas Smedegaard a écrit : > > Quoting Xavier (2018-11-27 15:22:10) > >> Le 27/11/2018 à 15:03, Jonas Smedegaard a écrit : > >>> Quoting Xavier (2018-11-27 14:00:42) > Le 27/11/2018 à 11:55, Jonas Smedegaard a écrit : >

Re: [Pkg-javascript-devel] components without major risks

2018-11-27 Thread Jérémy Lal
Le mar. 27 nov. 2018 à 15:22, Xavier a écrit : > Le 27/11/2018 à 15:03, Jonas Smedegaard a écrit : > > Quoting Xavier (2018-11-27 14:00:42) > >> Le 27/11/2018 à 11:55, Jonas Smedegaard a écrit : > >>> Hi Xavier and Paolo, > >>> > >>> Please allow me to highlight this security-related detail: >

Re: [Pkg-javascript-devel] components without major risks

2018-11-27 Thread Bastien ROUCARIES
On Tue, Nov 27, 2018 at 3:33 PM Jonas Smedegaard wrote: > > Quoting Xavier (2018-11-27 15:22:10) > > Le 27/11/2018 à 15:03, Jonas Smedegaard a écrit : > > > Quoting Xavier (2018-11-27 14:00:42) > > >> Le 27/11/2018 à 11:55, Jonas Smedegaard a écrit : > > >>> Hi Xavier and Paolo, > > >>> > > >>>

Re: [Pkg-javascript-devel] components without major risks

2018-11-27 Thread Jonas Smedegaard
Quoting Xavier (2018-11-27 15:22:10) > Le 27/11/2018 à 15:03, Jonas Smedegaard a écrit : > > Quoting Xavier (2018-11-27 14:00:42) > >> Le 27/11/2018 à 11:55, Jonas Smedegaard a écrit : > >>> Hi Xavier and Paolo, > >>> > >>> Please allow me to highlight this security-related detail: > >>> > >>>

Re: [Pkg-javascript-devel] components without major risks

2018-11-27 Thread Xavier
Le 27/11/2018 à 15:22, Xavier a écrit : > Le 27/11/2018 à 15:03, Jonas Smedegaard a écrit : >> Quoting Xavier (2018-11-27 14:00:42) >>> Le 27/11/2018 à 11:55, Jonas Smedegaard a écrit : Hi Xavier and Paolo, Please allow me to highlight this security-related detail: Quoting

Re: [Pkg-javascript-devel] components without major risks

2018-11-27 Thread Xavier
Le 27/11/2018 à 15:03, Jonas Smedegaard a écrit : > Quoting Xavier (2018-11-27 14:00:42) >> Le 27/11/2018 à 11:55, Jonas Smedegaard a écrit : >>> Hi Xavier and Paolo, >>> >>> Please allow me to highlight this security-related detail: >>> >>> Quoting Xavier (2018-11-26 16:29:32) Embedding

Re: [Pkg-javascript-devel] components without major risks

2018-11-27 Thread Jonas Smedegaard
Quoting Xavier (2018-11-27 14:00:42) > Le 27/11/2018 à 11:55, Jonas Smedegaard a écrit : > > Hi Xavier and Paolo, > > > > Please allow me to highlight this security-related detail: > > > > Quoting Xavier (2018-11-26 16:29:32) > >> Embedding components without following them may be a lack of

Re: [Pkg-javascript-devel] components without major risks

2018-11-27 Thread Xavier
Le 27/11/2018 à 11:55, Jonas Smedegaard a écrit : > Hi Xavier and Paolo, > > Please allow me to highlight this security-related detail: > > Quoting Xavier (2018-11-26 16:29:32) >> Embedding components without following them may be a lack of security. >> I think we should have a policy for

Re: [Pkg-javascript-devel] components without major risks

2018-11-27 Thread Xavier
Le 27/11/2018 à 13:47, Xavier a écrit : > Le 27/11/2018 à 11:55, Jonas Smedegaard a écrit : >> Hi Xavier and Paolo, >> >> Please allow me to highlight this security-related detail: >> >> Quoting Xavier (2018-11-26 16:29:32) >>> Embedding components without following them may be a lack of security.

Re: [Pkg-javascript-devel] components without major risks

2018-11-27 Thread Jonas Smedegaard
Hi Xaiver and Paolo, Please allow me to highlight this security-related detail: Quoting Xavier (2018-11-26 16:29:32) > Embedding components without following them may be a lack of security. > I think we should have a policy for embedding: > - components without major risks => not used in