MainInclusionReportLibvigraimpex

Main Inclusion Report for libvigraimpex

Requirements

  1. Availability: http://archive.ubuntu.com/ubuntu/pool/universe/libv/libvigraimpex; needs build on lpia

  2. Rationale:

    • Build dependency of openoffice.org, openoffice.org-l10n
  3. Security:

    • CVE entries: no entries

    • Secunia history: no entries

    • No suid binaries. No daemons.
    • No network access.
    • Any source code review performed ? No
  4. Quality assurance:

    • In what situations does the package not work out of the box without configuration ? None, its a library
    • Does the package ask any debconf questions higher than priority 'medium' ? No
    • Debian bugs: library name transition bug

    • Maintenance in Debian is frenetic/vigorous/calm/dead ? calm

    • Upstream is frenetic/vigorous/calm/dead ? calm

    • Upstream bug tracker: (mention any particularly relevant or critical) no bug tracker but has mailing list

    • Hardware: Does this package deal with hardware and if so how exotic is it ? no
  5. Standards compliance:

  6. Dependencies:

    • libc6, libgcc1, libjpeg62, libjpeg62-dev, libpng12-0, libpng12-dev, libstdc++6, libtiff4, libtiff4-dev, zlib1g, fftw3, fftw3-dev
    • Are these all in main ? yes
  7. Background information:

    • The general purpose and context of the package should be clear from the package's debian/control file. If it isn't then please explain. It is.
    • What do upstream call this software ? Has it had different names in the past ? vigra, not that i know of

Reviewers

ChrisCheney: author

Approved for Ubuntu main by Ian Jackson, despite reservations. I'm not wholly happy about this; it's not clear to me why OpenOffice.org upstream have chosen to use a 500kloc computer vision library for what looks like routine image conversion tasks. The lack of a vulnerability history for this code is likely to be more related to its obscurity than quality, even though I've had a quick look at the code and it doesn't look terrible. Realistically I don't think we have any choice but to include this.

MainInclusionReportLibvigraimpex (last edited 2008-08-06 16:15:56 by localhost)