It looks like upstream is good about including patches, but they have not made a new, tagged release since 2013. Upstream already includes the ability to build a shared library as well as a bunch of useful bug fixes:
https://github.com/google/zopfli/commit/422e58690b4673c1b44d0a50ba287965006a5b7f So I can see two approaches for going forward with this: * wait for upstream to make a new release and package that * go ahead and make a 1.0.0+40-g89cf773-1 package based on git Also, it would be good to submit the hardening_fixes.patch upstream to get it included so this package can be built without patches.
signature.asc
Description: OpenPGP digital signature