tomcat6 wheezy DSA (was/and Re: tomcat6_6.0.41-2+squeeze5_amd64.changes REJECTED

tony mancill tmancill at debian.org
Sun Nov 23 21:41:17 UTC 2014


On 11/23/2014 01:16 PM, Holger Levsen wrote:
> Hi Tony,
> 
> On Sonntag, 23. November 2014, tony mancill wrote:
>> The cruft report for unstable will look *very* different due to 6.0.41-3
>> being a *radically* different package.
> 
> no, the report exactly looks like this *because* of this:
>  
>>>   * Build only the libservlet2.5-java and libservlet2.5-java-doc
>>>   packages.
> [..]
> 
>> The decision/requirement to remove tomcat6 from jessie has been
>> requested by the Security team for quite a while, and the 6.0.41-3
>> source upload effectively does this by just building libservlet2.5-java
>> (without which we would have many packages with missing r-deps).
> 
> what's missing now is a bug against ftp.debian.org asking for the removal of 
> the binaries from sid, which are not build by the -3 anymore. 

RM/NBS bug filed, #770769.

> *then*, -3 can migrate to jessie and those binaries will vanish 
> "automagically".
> 
> and the stuff in the cruft report breaks because of this.
> 
>> I not sure I understand all of the ramifications of the statement I'm
>> about to make, but for the purposes of squeeze and wheezy, we need to
>> consider 6.0.41-2 as the last version of a "complete" tomcat6 source
>> package.
> 
> yup, I will base the wheezy upload on this.

Thank you!

tony

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-java-maintainers/attachments/20141123/ff436d5a/attachment.sig>


More information about the pkg-java-maintainers mailing list