[pkg] wfuzz - review

Lukas Schwaighofer lukas at schwaighofer.name
Wed Jun 28 20:15:50 UTC 2017


Hi Robert,

your changes look good to me.  I made a few more changes and pushed them
to git.

Two things are bugging me:
* upstream changelog: unfortunately upstream only has a changelog on
  their release page [1]. Policy §12.7 [2] states:
  
    If an upstream changelog is available, it should be accessible
    as /usr/share/doc/package/changelog.gz in plain text. (…)

  Maybe someone here with more experience can tell us if in that case
  we should make the effort of getting this into the package.

* Wouldn't it be better to install wfuzz.py directly as /usr/bin/wfuzz?
  The problem now is that e.g. `wfuzz -h` prints the following:

      Usage: ./wfuzz.py [options] -z payload,params <url>

  I find the "./wfuzz.py" a little bit irritating.  Installing wfuzz.py
  directly as /usr/bin/wfuzz would fix that problem.


Regards
Lukas

[1] https://github.com/xmendez/wfuzz/releases
[2] https://www.debian.org/doc/debian-policy/ch-docs.html#s-changelogs
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-security-team/attachments/20170628/65e663a8/attachment.sig>


More information about the Pkg-security-team mailing list