Am Montag, den 22.10.2007, 11:24 +0200 schrieb Josef Spillner: > Hello, > > gnome-games has for some time offered online gaming capabilities on top of the > GGZ Gaming Zone platform. Three games are already working fine, a fourth one > is currently being ported. As an upstream author of GGZ I'm very pleased to > see this. > > However, gnome-games includes internal copies of all GGZ libraries in its SVN, > with the justification of wanting to have GGZ support even if the distro in > question doesn't have GGZ packages yet. Recently, a member of the Debian > security team got very upset about this as this requires patching more > packages. > I share these concerns, especially since there are no major distros left that > do not include recent GGZ packages. I'm all for this, even if you will continue to include an internal copy as long as you allow building/linking against an external version of it. This would of course require you to not patch the internal GGZ copy to much ;) Of course dropping the internal copy is even better :) Bundling bigger libraries is evil and especially for such network stuff a great security problem...
Attachment:
signature.asc
Description: Dies ist ein digital signierter Nachrichtenteil