On Thu, Aug 29, 2013 at 11:08:31AM +0200, Raphael Geissert wrote: > Hi Zed, > > Looking at the big picture here it seems like the best way to go with > libmodplug is to remove it from old/stable and then re-consider its > inclusion in jessie and future releases. > MOD and other formats are rarely used yet they are readily available > in mainstream audio/video players through gstreamer, vlc, and xine. > These players/frameworks expose a lot of code that was most likely not > written with security in mind, putting users at risk. > > What I propose then is to: > * modify rdepends so that they no longer use libmodplug > * drop the modplug package entirely if no longer used > > Let me know what you think.
I think we should rather update to the current libmodplug in stable/oldstable. Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org