Control: tag -1 - moreinfo On June 25, 2019 4:16:17 PM EDT, Salvatore Bonaccorso <car...@debian.org> wrote: >Hi Paul, hi Afif, > [...] >> >> Your proposed changes very much do not align with the freeze policy, >so >> you're asking for an exception for a new upstream release. This >package >> is currently listed to be auto-removed due to docker.io, so I am not >> going to review it now. docker.io is a major concern for the >> security-team so that needs to be resolved first. If that gets >resolved >> in a timely manner, i.e. before it is auto-removed, please ping this >bug >> (e.g. by removing the moreinfo bug). > >I do agree that the changes are not really reviewable given the size >of the diff. But with Afifs argument and now the package not beeing >marked as autoremoved: if we want to support singularity-container >security wise in buster we would need to bite into the apple and >accept this late new version bump for buster as the 3.1 version. > >So I think the two options we have is (in order of preference): 1. >unblock singularity-container and let the 3.1 based version in to >buster, or 2. remove singularity-container from buster. > >Cc'in team@s.d.o for further comments. >
Thanks, Salvatore. I'm removing the moreinfo tag as Paul said to do since the autoremoval warning has been lifted. regards Afif