Re: the status of gstreamer1.0-plugins-bad

2015-09-03 Thread Fabian Greffrath
Hi Vincent, > which is unacceptable from a security and stability point of view. do you conclude this from the package description? > One problem is that if this package is installed, then Iceweasel > automatically uses these plugins (even when not needed, currently > making it crash[*]), with a

Re: Security concerns with minified javascript code

2015-09-03 Thread Paul Wise
On Wed, Sep 2, 2015 at 11:47 PM, Russ Allbery wrote: > I think reading "preferred form of modification" from the perspective of > upstream is a useful standard because it handles some edge cases like > that, and because it feels ethically consistent with free software > principles. The goal is th

Bug#797875: ITP: libjs-bootswatch -- themes for Twitter Bootstrap

2015-09-03 Thread Thomas Goirand
Package: wnpp Severity: wishlist Owner: Thomas Goirand * Package name: libjs-bootswatch Version : 3.3.5+2+dfsg1 Upstream Author : Thomas Park * URL : https://github.com/thomaspark/bootswatch * License : Expat Programming Lang: Javascript, CSS, LessCSS, etc.

Re: Bug#797875: ITP: libjs-bootswatch -- themes for Twitter Bootstrap

2015-09-03 Thread Dmitry Smirnov
On Thursday 03 September 2015 10:55:22 Thomas Goirand wrote: > * Package name: libjs-bootswatch Apparently a duplicate of #771384... -- Best wishes, Dmitry Smirnov. --- The Santa myth is one of the most effective means ever devised for intimidating children, eroding their self-esteem, twi

Re: Security concerns with minified javascript code

2015-09-03 Thread Dmitry Smirnov
On Thursday 03 September 2015 08:47:11 Vincent Bernat wrote: > Please, publish your own study. I do not need to publish any studies to be sceptical. > This number is well known and supported > by an entity which is likely to have a population large enough to be > significant. You've mentioned n

Improving your archive and package system for small package

2015-09-03 Thread Bastien ROUCARIES
Hi, In order to improve node situation we need to improve the small packages problems. What are the main bottlenet ? What could be done to improve the situation ? The node small package does not change often so it could be a win to your archive size. Moreover if we could solve this problem we co

Re: Security concerns with minified javascript code

2015-09-03 Thread Vincent Bernat
❦ 3 septembre 2015 21:03 +1000, Dmitry Smirnov  : >> Without minification, we'll just ship packages that people won't >> use. Why would I run a crippled installation of Wordpress that will >> drive of part of my users to another competitor? > > Sorry but that feels like exaggeration. Maybe it is

Bug#797893: ITP: kvmtool -- Native Linux KVM Tool

2015-09-03 Thread Riku Voipio
Package: wnpp Severity: wishlist Owner: Riku Voipio * Package name: kvmtool Version : 20150903 Upstream Author : Pekka Enberg, Sasha Levin and others * URL : https://git.kernel.org/cgit/linux/kernel/git/will/kvmtool.git/ * License : GPL-2 Programming Lang

Re: Improving your archive and package system for small package

2015-09-03 Thread Jérémy Lal
2015-09-03 13:36 GMT+02:00 Bastien ROUCARIES : > Hi, > > In order to improve node situation we need to improve the small > packages problems. > > What are the main bottlenet ? What could be done to improve the situation ? > > The node small package does not change often so it could be a win to > y

Bug#797898: RFS: caffe/0.9999~rc2+git20150902+e8e660d3-1 [ITP]

2015-09-03 Thread lumin
Package: sponsorship-requests Severity: wishlist X-Debbugs-CC: debian-devel@lists.debian.org, debian-ment...@lists.debian.org, 788...@bugs.debian.org Dear mentors, I am looking for a sponsor for my package "caffe" * Package name: caffe Version : 0.~rc2+git20150902+e8e660d3

Re: Improving your archive and package system for small package

2015-09-03 Thread Bastien ROUCARIES
On Thu, Sep 3, 2015 at 2:26 PM, Jérémy Lal wrote: > > > 2015-09-03 13:36 GMT+02:00 Bastien ROUCARIES : >> >> Hi, >> >> In order to improve node situation we need to improve the small >> packages problems. >> >> What are the main bottlenet ? What could be done to improve the situation >> ? >> >> Th

Bug#797908: ITP: drf-fsm-transitions -- Django-FSM transitions for Django REST Framework

2015-09-03 Thread Michael Fladischer
Package: wnpp Severity: wishlist Owner: Michael Fladischer -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: drf-fsm-transitions Version : 0.2.0 Upstream Author : Jacob Haslehurst * URL : https://github.com/hzy/drf-fsm-transitions * License : Ex

Bug#797909: ITP: django-downloadview -- efficient static file serving with Django

2015-09-03 Thread Michael Fladischer
Package: wnpp Severity: wishlist Owner: Michael Fladischer -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: django-downloadview Version : 1.8 Upstream Author : Benoît Bryon * URL : https://github.com/fladi/django-downloadview * License : BSD-3-

Re: Improving your archive and package system for small package

2015-09-03 Thread Jose-Luis Rivas
On 03/09/15, 03:13pm, Bastien ROUCARIES wrote: > I was thinking generally, perl latex python have a lot of small > package. Each language could not come with its own solution. Maybe > creating a tool agregating small debian package in a big one. But > doing something only for javascript is not a

Re: Improving your archive and package system for small package

2015-09-03 Thread Adrien CLERC
Le 03/09/2015 13:36, Bastien ROUCARIES a écrit : > Hi, > > In order to improve node situation we need to improve the small > packages problems. > > What are the main bottlenet ? What could be done to improve the situation ? > > The node small package does not change often so it could be a win to >

Re: Improving your archive and package system for small package

2015-09-03 Thread Jonas Smedegaard
Quoting Bastien ROUCARIES (2015-09-03 13:36:15) > In order to improve node situation we need to improve the small > packages problems. > > What are the main bottlenet ? What could be done to improve the > situation ? > > The node small package does not change often so it could be a win to > yo

Bug#797914: ITP: jasp -- graphical statistical package designed to familiar to users of SPSS

2015-09-03 Thread Jonathon
Package: wnpp Severity: wishlist Owner: Jonathon * Package name: jasp Version : 0.7.1.12 Upstream Author : Jonathon Love * URL : https://jasp-stats.org * License : AGPL Programming Lang: C++, JavaScript, R Description : graphical statistical package de

Re: Security concerns with minified javascript code

2015-09-03 Thread Gunnar Wolf
Lars Wirzenius dijo [Wed, Sep 02, 2015 at 09:32:12AM +0300]: > However, I want to raise the point that upstreams do not always make > sensible decisions, and if they don't, it's good to raise that with > them. For example, there was recently an ITP bug for > node-number-is-nan. Upstream source code

Re: Security concerns with minified javascript code

2015-09-03 Thread Gunnar Wolf
Vincent Bernat dijo [Wed, Sep 02, 2015 at 09:47:23AM +0200]: > If you talk about uglifyjs or the like, it is already packaged and > doesn't solve all the problems we have (see my message to Odyx, > ). > > If you talk about Grunt, Grunt comes with a lot of plugins (and does > almost nothing without

Re: Security concerns with minified javascript code

2015-09-03 Thread Bas Wijnen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Thu, Sep 03, 2015 at 08:47:11AM +0200, Vincent Bernat wrote: > Without minification, we'll just ship packages that people won't > use. Why would I run a crippled installation of Wordpress that will > drive of part of my users to another competitor?

Re: Security concerns with minified javascript code

2015-09-03 Thread Russ Allbery
Paul Wise writes: > On Wed, Sep 2, 2015 at 11:47 PM, Russ Allbery wrote: >> If *no one* has access to anything better than a binary file, then >> possession of that binary file puts you on an equal footing with >> everyone else in the world, which I think is all that we can reasonably >> ask. >

Re: Security concerns with minified javascript code

2015-09-03 Thread Marvin Renich
* Neil Williams [150902 14:33]: > Minified isn't source for modification... [large snip] I don't believe I have disagreed with anything you said in the snipped text. I certainly did not mean to. I said that minified JS can only go in main if both the source and the tools to build it are also in

Re: Security concerns with minified javascript code

2015-09-03 Thread Marvin Renich
* Bas Wijnen [150902 17:36]: > > On Wed, 2 Sep 2015 13:33:57 -0400 Marvin Renich wrote: > > > No, "A preferred form" is what upstream uses. The DFSG does not use > > > the term "THE preferred form", and I believe that was wise. > > The DFSG doesn't define source at all. There seems to be conse

Re: Security concerns with minified javascript code

2015-09-03 Thread Marvin Renich
* Neil Williams [150902 14:15]: > On Wed, 2 Sep 2015 13:14:31 -0400 Marvin Renich wrote: > > It is presumed that upstream already has what it considers "source"; > > in the case of this thread, that is minified JS. > > Actually, not. Source, for upstream of JQuery at least, is a set of > directi

Bug#797928: ITP: python-cbor -- Python Implementation of RFC 7049. Concise Binary Object Representation (CBOR)

2015-09-03 Thread Agustin Henze
Package: wnpp Severity: wishlist X-Debbugs-CC: debian-devel@lists.debian.org Package name: python-cbor Version: 0.1.21 Upstream Author: 2014-2015 Brian Olson URL: https://bitbucket.org/bodhisnarkva/cbor License: Apache-2.0 Description: Python Implementation of R

Re: Security concerns with minified javascript code

2015-09-03 Thread Vincent Bernat
❦ 3 septembre 2015 17:22 GMT, Bas Wijnen  : > Because you know you have the right and the ability to be a part of the free > software community that created the software. That is why you are running > Debian and don't have contrib or non-free in your sources.list. > > From your mails it is clea

Bug#797935: ITP: golang-gopkg-gcfg.v1 -- read INI-style configuration files into Go structs

2015-09-03 Thread Dmitry Smirnov
Package: wnpp Severity: wishlist X-Debbugs-CC: debian-devel@lists.debian.org pkg-go-maintain...@lists.alioth.debian.org Owner: Dmitry Smirnov Control: block 795652 by -1 * Package name: golang-gopkg-gcfg.v1 AKA golang-googlecode-p-gcfg Version : 0.0~git20150817.0.5866678-1 Upstre

Re: Security concerns with minified javascript code

2015-09-03 Thread Nikolaus Rath
On Sep 03 2015, Vincent Bernat wrote: > ❦ 3 septembre 2015 17:22 GMT, Bas Wijnen  : > >> Because you know you have the right and the ability to be a part of the free >> software community that created the software. That is why you are running >> Debian and don't have contrib or non-free in your

Re: Improving your archive and package system for small package

2015-09-03 Thread Josh Triplett
Jonas Smedegaard wrote: > Seems Osamu Aoki is working on at least part of the puzzle: > https://bugs.debian.org/797045 Merging multiple sources *really* shouldn't be necessary. And the metadata for those sources will vary, so that likely won't save that much space. Perhaps we should add a few mo

Re: Security concerns with minified javascript code

2015-09-03 Thread Vincent Bernat
❦ 3 septembre 2015 13:19 -0700, Nikolaus Rath  : >>> Because you know you have the right and the ability to be a part of the free >>> software community that created the software. That is why you are running >>> Debian and don't have contrib or non-free in your sources.list. >>> >>> From your m

Re: Improving your archive and package system for small package

2015-09-03 Thread Jonas Smedegaard
Quoting Josh Triplett (2015-09-03 22:26:12) > Jonas Smedegaard wrote: >> Seems Osamu Aoki is working on at least part of the puzzle: >> https://bugs.debian.org/797045 > > Merging multiple sources *really* shouldn't be necessary. And the > metadata for those sources will vary, so that likely won't

Work-needing packages report for Sep 4, 2015

2015-09-03 Thread wnpp
The following is a listing of packages for which help has been requested through the WNPP (Work-Needing and Prospective Packages) system in the last week. Total number of orphaned packages: 669 (new: 3) Total number of packages offered up for adoption: 181 (new: 2) Total number of packages request

Bug#797970: ITP: bangsh -- framework for easy shell scripting

2015-09-03 Thread Paulo Kretcheu
Package: wnpp Severity: wishlist Owner: Paulo Kretcheu * Package name: bangsh Version : 0.1.1 Upstream Author : Gustavo.Dutra * URL : https://github.com/bangsh/bangsh * License : MIT/X Programming Lang: Shell Script Description : framework for easy she