Overview

Request 1101188 revoked

follow-up based on comment in SR#1101063


Christophe Marin's avatar

I'm not interested in this change.


Christophe Marin's avatar

This bundle information is useless for packagers and wrong for every imaginary cases. This is not re2 = 2020-10-01


Marcus Rueckert's avatar

JFYI the policy is created to ensure that e.g. the security team can find all the copies of a library to check if we also need to fix said copies.


Christophe Marin's avatar

and it's utterly stupid in this case: https://github.com/google/re2/security


Marcus Rueckert's avatar

just because google doesnt use the GH included security handling does not mean that there is not a proper security handling for the re2 library.


Request History
Andreas Stieger's avatar

AndreasStieger created request

follow-up based on comment in SR#1101063


Christophe Marin's avatar

krop declined request

This information is not useful for anything


Andreas Stieger's avatar

AndreasStieger reopened request

Security team wants this


Christophe Marin's avatar

krop declined request

Stop that


Marcus Rueckert's avatar

darix reopened request

the policy is very clear about what is expected here. yes we know that chromium includes a lot of intree libraries, but that doesnt mean it is excempted from the policy


Andreas Stieger's avatar

AndreasStieger revoked request

Declined twice by maintainer. Security team and review team should talk to maintainer if they wish, or accept without this. This will block Chromium 116 around 2023-08-22.

openSUSE Build Service is sponsored by