> With the greatest embarrased... may I ask you to rebase your .debdiff?

Rebased everything and bumped up to 0.6.36, which also fixes the 3 CVE's
attached to this package. Will upload a new debdiff soon, need to build these
packages for sid and test them for a bit, including the updated dnf stuff.
Shouldn't take too long.


> Have your changes been upstream meanwhile?

I've reworked my own patchset, since the previous solution was weird. It should
be a lot cleaner now and not touching the whole pool content, but only RPM 
stuff.

I also decided not to even try to upstream it, because upstream would almost
certainly reject it anyway. It's a workaround for Debian breaking librpm/rpm, so
Debian is responsible for keeping the patch.

With a bit of luck, we will very soon be able to drop those patches completely
though, as I'm trying to get Debian to not apply the patch that breaks rpm in
the first place... see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=794495

(Un-?)fortunately the rpm package is up for grabs since the current maintainer
is not interested in maintaining/using it any longer.

I'm very much interesting in having a working and if possible up-to-date rpm
package within Debian as user, but I'm not a DD and I *know* that I won't have
the time for proper maintenance.



Mihai

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to