On Mon, 11 Mar 2019 22:14:13 +0100, Ivo De Decker wrote:

> Control: tags -1 buster-ignore

Thanks.
 
> > So I guess we have to consider if we're happy with the ability to
> > turn off loading objects and recommend it to consumers and close the
> > bugs; or if we want to change the defaults, which means setting
> > $YAML::LoadBlessed to 0 in all three packages.
> I guess it might be best to change the default, but that's obviously too late
> for buster. If this options is chosen, it should probably be done soon after
> the buster release, to allow for plenty of time for issues to be discovered
> (and fixed) for bullseye.

Ack; we discussed this on IRC some time ago, and I also had a talk
with one of the upstream developers in August (about an upstream
change of the default), but apparently this slipped off of
everybody's radar afterwards; and we should indeed fix this quickly
in the bullseye cycle.

Cheers,
gregor

-- 
 .''`.  https://info.comodo.priv.at -- Debian Developer https://www.debian.org
 : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D  85FA BB3A 6801 8649 AA06
 `. `'  Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe
   `-   NP: Chavela Vargas: Toda Una Vida

Attachment: signature.asc
Description: Digital Signature

Reply via email to