← Back to team overview

linux-traipu team mailing list archive

Re: [Bug 1188926] [NEW] please do not ship an embedded copy of jsoncpp

 

coldtobi <1188926@xxxxxxxxxxxxxxxxxx> writes:
> As embedded code copies of libraries makes the live for distributions
> harder. The Debian Policy Manual for examples states:
>
> "Having multiple copies of the same code in Debian is inefficient, often
> creates either static linking or shared library conflicts, and, most
> importantly, increases the difficulty of handling security
> vulnerabilities in the duplicated code. " [1]
>
> This problem causes an lintian-error [2] and therefore -- as severity is
> serious -- it is a possible show-stopper to package drizzle for Debian
> -- unless there are some good reasons why this  copy is needed. (If,
> please state them here ...) In this case it might be justified to
> override this linitian error.
>
> [1] http://www.debian.org/doc/debian-policy/footnotes.html#f30
>
> [2] http://lintian.debian.org/tags/embedded-library.html
>
> Many thanks for your help from the drizzle's package maintainer @ Debian
> :-)

I'll look into it, it probably isn't hard to link against the debian one
instead.

-- 
Stewart Smith

-- 
You received this bug notification because you are a member of UBUNTU -
AL - BR, which is subscribed to Drizzle.
https://bugs.launchpad.net/bugs/1188926

Title:
  please do not ship an embedded copy of jsoncpp

Status in A Lightweight SQL Database for Cloud Infrastructure and Web Applications:
  New
Status in Debian GNU/Linux:
  New

Bug description:
  Hallo,

  As embedded code copies of libraries makes the live for distributions
  harder. The Debian Policy Manual for examples states:

  "Having multiple copies of the same code in Debian is inefficient,
  often creates either static linking or shared library conflicts, and,
  most importantly, increases the difficulty of handling security
  vulnerabilities in the duplicated code. " [1]

  This problem causes an lintian-error [2] and therefore -- as severity
  is serious -- it is a possible show-stopper to package drizzle for
  Debian -- unless there are some good reasons why this  copy is needed.
  (If, please state them here ...) In this case it might be justified to
  override this linitian error.

  [1] http://www.debian.org/doc/debian-policy/footnotes.html#f30

  [2] http://lintian.debian.org/tags/embedded-library.html

  Many thanks for your help from the drizzle's package maintainer @
  Debian :-)

  coldtobi

To manage notifications about this bug go to:
https://bugs.launchpad.net/drizzle/+bug/1188926/+subscriptions


References