MainInclusionReportClamav
Main Inclusion Report for clamav
The purpose of promoting clamav is to get a more complete server solution.
Requirements
Availability: http://archive.ubuntu.com/ubuntu/pool/universe/c/clamav/; available for all supported architectures
Rationale:
Approved spec for Intrepid: https://wiki.ubuntu.com/ClamavSpamassassinInMain. Note: clamav-milter binary can stay in Universe.
Security:
CVE entries Clamav has a long history of large numbers of CVEs. It seems to be trending better.
- Any binaries running as root or suid/sgid ? NO Any daemons ? YES (clamav-freshclam, clamav-daemon, and clamav-milter)
- Network activity: does it open any port ? Yes Does it handle incoming network data ? YES
- Does it directly (not through a library) process binary (video, audio, etc) or structured (PDF, etc) data ? YES
- Any source code review performed ? (The approver will do a quick and shallow check.) NO
Quality assurance:
- In what situations does the package not work out of the box without configuration ? None
- Does the package ask any debconf questions higher than priority 'medium' ? No
Debian Bugs: None
Maintenance in Debian is vigorous. The current maintainer is a bit burned out on the package and has recently started pkg-clamav on alioth. He's agreed to host Ubuntu branches in the same Git repository and we can work on it together there.
Upstream is frenetic and does not have a good track record for interface stability.
- Hardware: Does this package deal with hardware and if so how exotic is it ? NO
- Is there a test suite in the upstream source or packaging ? YES Is it enabled to run in the build ?
Standards compliance:
FHS, Debian Policy compliance ? YES
Debian library packaging guide standards compliance ? YES
- Packaging system (debhelper/cdbs/dbs) ? Debhelper Patch system ? dpatch historically, maintained in Git now. Any packaging oddities ? Package is complex and somewhat painful due to it's long and complex history. Debian maintainer plans to simplify post-Lenny.
Dependencies:
Build-Depends: dpkg-dev (>= 1.13.19), debhelper (>=5.0), po-debconf, zlib1g-dev (>=1:1.1.4), libbz2-dev, libmilter-dev, libgmp3-dev, libwrap0-dev, perl, bc
Depends : adduser, ucf (>= 0.28), logrotate, sharutils, arj, and unzoo
- Are these all in main ? NO (MIR needed for arj and unzoo)
Background information:
- What do upstream call this software ? CLAMAV Has it had different names in the past ? NO
Reviewers
MIR bug: https://launchpad.net/ubuntu/+source/clamav/+bug/261249
Author: leonelnunez and ScottKitterman
MainInclusionReportClamav (last edited 2008-08-26 11:31:51 by static-72-81-252-22)