Ok, I reviewed gupnp-igd and it's build-dependencies and think they are not fit fur a hush-hush main inclusion:
gupnp-igd depends on gupnp, which had at least one serious security issue in the past 3 months.
I think we should not hurry up to get those in main as they need to be thoroughly reviewed by a member of the security team and with feature freeze 14 days away, time is short.
But I'd like to have farsight2 0.0.14 in karmic nonetheless, so I disabled gupnp-igd again (debdiff attached).
farsight2 (0.0.14-2ubuntu1) karmic; urgency=low
* Merge from debian/unstable, remaining ubuntu changes: (LP: #410900)
- debian/control:
- don't depend on gstreamer0.10-plugins-bad, codecs moved to -good
- bump dependendency on -good to 0.10.15-2ubuntu1 to have necessary
codecs supported
- debian/rules, debian/control:
- disable gupnp-igd support, the necessary libraries are in universe
-- Andreas Moog <email address hidden> Wed, 12 Aug 2009 00:49:41 +0200
Ok, I reviewed gupnp-igd and it's build-dependencies and think they are not fit fur a hush-hush main inclusion:
gupnp-igd depends on gupnp, which had at least one serious security issue in the past 3 months.
I think we should not hurry up to get those in main as they need to be thoroughly reviewed by a member of the security team and with feature freeze 14 days away, time is short.
But I'd like to have farsight2 0.0.14 in karmic nonetheless, so I disabled gupnp-igd again (debdiff attached).
farsight2 (0.0.14-2ubuntu1) karmic; urgency=low
* Merge from debian/unstable, remaining ubuntu changes: (LP: #410900) 10-plugins- bad, codecs moved to -good
- debian/control:
- don't depend on gstreamer0.
- bump dependendency on -good to 0.10.15-2ubuntu1 to have necessary
codecs supported
- debian/rules, debian/control:
- disable gupnp-igd support, the necessary libraries are in universe
-- Andreas Moog <email address hidden> Wed, 12 Aug 2009 00:49:41 +0200