Bug#837938: move the hardening-check script from hardening-includes to devscripts

Jakub Wilk jwilk at debian.org
Sat Oct 1 17:15:51 UTC 2016


* Paul Wise <pabs at debian.org>, 2016-09-30, 12:44:
>>check-all-the-things runs hardening-check and maintainers might want to run 
>>it manually, any thoughts about moving it to devscripts anyway?

hardening-check is also packaged for other distros:
https://admin.fedoraproject.org/pkgdb/package/rpms/hardening-check/
https://aur.archlinux.org/packages/hardening-check/
https://packages.gentoo.org/packages/app-admin/hardening-check

It would be a shame if it disappeared.

>Reading through #836162 it seems like lintian is a better place for 
>hardening-check than devscripts. I wonder if the lintian maintainers are open 
>to that,

IMO devscripts or a separate package would be a better place.

>which would allow keeping the stackprotector tag.

The stackprotector check in hardening-check is very simple. It would be easy to 
implement it directly in Lintian. But this check is so unreliable, it's not 
worth the trouble.

-- 
Jakub Wilk



More information about the devscripts-devel mailing list