Dear Maintainer, The audit source package ships a (custom, patched) copy of libev. Moreover, it is not listed in the security team's list of code copies: https://anonscm.debian.org/viewvc/secure-testing/data/embedded-code-copies?view=markup I discovered the issue while preparing a DEP5 copyright file for the audit source package, and more generally fixing all Lintian warnings while preparing a patch for #759604. Best, nicoo
Control: severity -1 important Control: tags -1 patch I think this is an important issue and have included a patch. Would you please consider to apply this before the bookworm freeze?
Hello, Le 15/12/22 à 17:08, Bastian Germann a écrit : Do you think you could bring that upstream? Not sure we want to carry this patch forever
Am 16.12.22 um 12:20 schrieb Laurent Bigonville: Usually, projects have their reasons to vendor libraries (mostly, convenience or CI-related). The patch is not complete in the sense that it still reads the .m4 file from the vendored library. So I do not think this has a high chance to be considered for upstream inclusion. However, I can try to hand in one that gets rid of the vendoring completely (not happening in a timeframe before bookworm freeze). If you do not want to include the patch for now then please at least make sure the embedded libev is registered with the Security Team.