Hi, I've just commited an initial version of a text file that we should use to track information about packages that embed local copies of other sources packages and therefore need further fixing if a security problem arises in one of the packages. Cheers, Moritz