Re: ask github to encourage signed git tags

2016-04-13 Thread Paul Wise
On Thu, Apr 14, 2016 at 8:23 AM, Tiago Ilieve wrote: > Actually the possibility of attaching a tarball signature exists for a > while[1]. Found it less than five minutes after sending this message. > :-) > > [1]: https://wiki.debian.org/Creating%20signed%20GitHub%20releases This relies on github

Re: ask github to encourage signed git tags

2016-04-13 Thread Tiago Ilieve
On 13 April 2016 at 21:17, Tiago Ilieve wrote: > This feature went missing. The help section regarding GPG[2] doesn't > say anything about uploading tarball signatures. Unfortunately, this > is the part that would interest Debian most. Actually the possibility of attaching a tarball signature exi

Re: ask github to encourage signed git tags

2016-04-13 Thread Tiago Ilieve
Hi Thomas, On 21 August 2015 at 04:51, Thomas Koch wrote: > Hi, > > we want upstream to sign releases. Nowadays a lot of software is on github and > a release is just a git tag. - An unsigned git tag ... :-( > > Github has a site that shows tags[1] but it does not give any indication > whether th

Re: Packaging of static libraries

2016-04-13 Thread Bas Wijnen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wed, Apr 13, 2016 at 05:17:54PM +0200, Marco d'Itri wrote: > On Apr 13, Ian Jackson wrote: > > We in Debian are in a good position to defend our users from the > > fallout from this problem. We could change our default compiler > > options to favo

Re: Packaging of static libraries

2016-04-13 Thread Marco d'Itri
On Apr 13, Ian Jackson wrote: > We in Debian are in a good position to defend our users from the > fallout from this problem. We could change our default compiler > options to favour safety, and provide more traditional semantics. Which would not solve any problem in this case, because then the

Re: Packaging of static libraries

2016-04-13 Thread Vincent Lefevre
On 2016-04-13 12:40:39 +0100, Ian Jackson wrote: > Vincent Lefevre writes ("Re: Packaging of static libraries"): > > Note that by default, shared libraries would still be used, so that > > this would affect only users with specific applications, who would > > want to optimize as much as possible. >

Bug#820898: ITP: pyramid-multiauth -- An authentication policy for Pyramid that proxies to other authentication policies

2016-04-13 Thread David Douard
Package: wnpp Severity: wishlist Owner: David Douard * Package name: pyramid-multiauth Version : 0.8.0 Upstream Author : Mozilla * URL : https://github.com/mozilla-services/pyramid_multiauth * License : MPL 2 Programming Lang: Python Description : An au

Bug#820896: ITP: python-hashids -- Python implementation of hashids

2016-04-13 Thread Edward Betts
Package: wnpp Severity: wishlist Owner: Edward Betts * Package name: python-hashids Version : 1.1.0 Upstream Author : David Aurelio * URL : https://github.com/davidaurelio/hashids-python * License : MIT Programming Lang: Python Description : Python imp

Re: Packaging of static libraries

2016-04-13 Thread Ian Jackson
Adam Borowski writes ("Re: Packaging of static libraries"): > On Tue, Apr 12, 2016 at 02:52:33PM +0100, Ian Jackson wrote: > > I'm afraid that LTO is probably too dangerous to be used as a > > substitute for static linking. See my comments in the recent LTO > > thread here, where I referred to the

Re: Packaging of static libraries

2016-04-13 Thread Ian Jackson
Vincent Lefevre writes ("Re: Packaging of static libraries"): > On 2016-04-12 14:52:33 +0100, Ian Jackson wrote: > > I'm afraid that LTO is probably too dangerous to be used as a > > substitute for static linking. See my comments in the recent LTO > > thread here, where I referred to the problem o

Bug #820811: ITP: python-fitsio -- Python wrapper on the CFITSIO library

2016-04-13 Thread Ole Streicher
Package: wnpp Owner: Ole Streicher Severity: wishlist X-Debbugs-Cc: debian-devel@lists.debian.org,debian-as...@lists.debian.org,debian-pyt...@lists.debian.org * Package name: python-fitsio Version : 0.9.8 Upstream Author : Eric Sheldon * URL : https://github.com/eshel

Bug#820854: ITP: fsm-lite -- frequency-based string mining (lite)

2016-04-13 Thread Andreas Tille
Package: wnpp Severity: wishlist Owner: Andreas Tille * Package name: fsm-lite Version : 1.0 Upstream Author : Niko Välimäki * URL : https://github.com/nvalimak/fsm-lite * License : GPL Programming Lang: C Description : frequency-based string mining (li