
Sign up to save your podcasts
Or


by Simon Josefsson
At: miniDebConf Berlin 2024
I will describe a new way to maintain Debian packages whose upstream use gnulib. This avoids vendoring gnulib files which allows several advantages, including being able to security patch gnulib code in one package (the Debian gnulib package) and have that code trickle down to all packages using gnulib. Another advantage is reducing the amount of duplicated code that people have to audit to find concerns like the xz utils incident.
Room: c-base
By by Simon Josefsson
At: miniDebConf Berlin 2024
I will describe a new way to maintain Debian packages whose upstream use gnulib. This avoids vendoring gnulib files which allows several advantages, including being able to security patch gnulib code in one package (the Debian gnulib package) and have that code trickle down to all packages using gnulib. Another advantage is reducing the amount of duplicated code that people have to audit to find concerns like the xz utils incident.
Room: c-base