Package: grml-keyring
Version: 2025.02.24
Severity: serious
Justification: violates Debian Policy

Hi,

I debootstraped sid and noticed that the resulting system contains an
APT sources file /etc/apt/sources.list.d/grml.sources pointing to a
3rd-party repository deb.grml.org. That file is part of grml-keyring
package which has Priority: important and is therefor installed by
default.

Debian Policy states¹ the following:

   Most Debian packages will have a priority of optional. Priority levels
   other than optional are only used for packages that should be included
   by default in a standard installation of Debian.
   …
   Unless a package should be installed by default on standard Debian
   systems, it should have a priority of optional.
   
Priority 'important' is described as:

   Important programs, including those which one would expect to find on
   any Unix-like system. … The important packages are just a bare minimum
   of commonly-expected and necessary tools.
   
I suppose that grml-keyring package is not meant to be part of default
Debian installation and therefor it should have Priority: optional.
   
 ¹ https://www.debian.org/doc/debian-policy/ch-archive.html#priorities

Reply via email to