Re: Mono Package audit

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thursday 10 April 2008, Colin Walters wrote:
> On Thu, Apr 10, 2008 at 3:06 PM, Ville Skyttä <ville.skytta@xxxxxx> wrote:
>
> >  Hm, how do you mean rpmlint could check these?  Run "rpmbuild -bp" on
> >  src.rpm's it's given and check the extracted files from there?
>
> Yeah...it doesn't extract the tree already for other checks?

It extracts rpm contents only with "rpm2cpio | cpio", not tarballs etc within.

Not sure if running "rpmbuild -bp" would be considered a potential security 
issue, and I'd rather not even try re-implementing what %setup does to get 
around that (at least in upstream rpmlint; in Fedora it could use 
rpmdev-extract for that).

-- 
fedora-devel-list mailing list
fedora-devel-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-devel-list

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux