** Description changed:

- [MIR] libmd (dependency of libbsd)
+ [Summary]
+ TODO: WRITE - The essence of the review result from the MIR POV
+ TODO: This does need a security review, so I'll assign ubuntu-security
+ TODO: List of specific binary packages to be promoted to main: <TODO>
+ 
+ Notes:
+ TODO: - add todos, issues or special cases to discuss
+ Required TODOs:
+ TODO - TBD
+ Recommended TODOs:
+ TODO - TBD
+ 
+ [Duplication]
+ TODO: There is no other package in main providing the same functionality.
+ 
+ [Dependencies]
+ OK:
+ TODO - no other Dependencies to MIR due to this
+ TODO   (use tools: check-mir, seeded-in-ubuntu, reverse-depends)
+ TODO - no -dev/-debug/-doc packages that need exclusion
+ 
+ TODO: Problems:
+ 
+ [Embedded sources and static linking]
+ OK:
+ TODO: - no embedded source present
+ TODO: - no static linking
+ 
+ TODO: Problems:
+ 
+ [Security]
+ OK:
+ TODO: - history of CVEs does not look concerning
+ TODO: - does not run a daemon as root
+ TODO: - does not use webkit1,2
+ TODO: - does not use lib*v8 directly
+ TODO: - does not parse data formats
+ TODO: - does not open a port
+ TODO: - does not process arbitrary web content
+ TODO: - does not use centralized online accounts
+ TODO: - does not integrate arbitrary javascript into the desktop
+ TODO: - does not deal with system authentication (eg, pam), etc)
+ 
+ TODO: Problems:
+ 
+ [Common blockers]
+ OK:
+ TODO: - does not FTBFS currently
+ TODO: - does have a test suite that runs at build time
+ TODO:   - test suite fails will fail the build upon error.
+ TODO: - does have a test suite that runs as autopkgtest
+ TODO: - The package has a team bug subscriber
+ TODO: - no translation present, but none needed for this case (user visible)?
+ TODO: - not a python/go package, no extra constraints to consider int hat 
regard
+ TODO: - no new python2 dependency
+ TODO: - Python package that is using dh_python
+ TODO: - Go package that uses dh-golang
+ 
+ TODO: Problems:
+ 
+ [Packaging red flags]
+ OK:
+ TODO: - Ubuntu does not carry a delta
+ TODO: - Ubuntu does carry a delta, but it is reasonable and maintenance under 
control
+ TODO: - symbols tracking is in place
+ TODO: - symbols tracking not applicable for this kind of code.
+ TODO: - d/watch is present and looks ok
+ TODO: - Upstream update history is (good/slow/sporadic)
+ TODO: - Debian/Ubuntu update history is (good/slow/sporadic)
+ TODO: - the current release is packaged
+ TODO: - promoting this does not seem to cause issues for MOTUs that so far
+ TODO:   maintained the package
+ TODO: - no massive Lintian warnings
+ TODO: - d/rules is rather clean
+ TODO: - Does not have Built-Using
+ TODO: - Go Package that follows the Debian Go packaging guidelines
+ TODO:   (see https://go-team.pages.debian.net/packaging.html)
+ 
+ TODO: Problems:
+ 
+ [Upstream red flags]
+ OK:
+ TODO: - no Errors/warnings during the build
+ TODO: - no incautious use of malloc/sprintf (as far as I can check it)
+ TODO: - no use of sudo, gksu, pkexec, or LD_LIBRARY_PATH
+ TODO: - no use of user nobody
+ TODO: - no use of setuid
+ TODO: - no important open bugs (crashers, etc) in Debian or Ubuntu
+ TODO: - no dependency on webkit, qtwebkit, seed or libgoa-*
+ TODO: - not part of the UI for extra checks
+ 
+ TODO: Problems:

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1915009

Title:
  [MIR] libmd (dependency of libbsd)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libmd/+bug/1915009/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to