On 10/01/19 18:10, Santiago Vila wrote:
> Package: src:fasm
> Version: 1.73.06-1
> Tags: upstream
>
> Dear maintainer:
>
> The source for this package contains two ELF binaries that should
> probably not be there. It is usual and customary to repack the source
> and exclude them. (If you could convince upstream to do so, even better).
>
> Thanks.

Hey Santiago,
they are there, because upstream uses this to also release new versions.
An unfortunately, in the past my upstream wasn't very responsive.

I used the fasm binary in the first upload to bootstrap everything.  I
can repack the source, but since I never use these binaries, I don't
think it is such a big deal (and I dislike repackaging in general as
this replaces one problem (binary files) with with a different
security problem (original tarballs are tampered with)).

Let me know what you think.
Tomasz

Attachment: signature.asc
Description: PGP signature

Reply via email to