Comment 0 for bug 1220427

Revision history for this message
Scott Moser (smoser) wrote :

This is a Main Inclusion Request for simplestreams source package.

 * I've gone through UbuntuMainInclusionRequirements
 * Rationale: simplestreams will be used by MAAS for synchronizing data from http://maas.ubuntu.com/images
 * Security: Source code review is requested of lp:simplestreams. This package is a client and library for reading data and synchronizing or mirroring it with another source. The areas relevant to security team are at least:
    * gpg usage and verification
    * bad 'path' elements in data escaping a target (ie, when mirroring source/ to 'target/' no writes should go outside of target/).

all dependencies of python-simplestreams, simplestreams, and python3-simplestreams are in main.