[Secure-testing-team] Bug#724287: rt4-extension-jsgantt, trac-jsgantt: embeds jsgantt - should depend on libjs-jsgantt separately packaged
Jonas Smedegaard
dr at jones.dk
Mon Sep 23 11:56:01 UTC 2013
Package: rt4-extension-jsgantt,trac-jsgantt
Severity: normal
Tags: security
Packages rt4-extension-jsgantt and trac-jsgantt embed the Javascript
library jsgantt.
That Javascript library should instead be packaged separately and
depended upon. Package name should be libjs-jsgantt according to
<https://wiki.debian.org/Javascript/Policy>.
This issue potentially affects security: See Debian Policy 3.9.4 § 4.13.
- Jonas
More information about the Secure-testing-team
mailing list