Re: Fwd: can anyone review diaspora-installer?

On Thu, Apr 06, 2017 at 09:42:33AM +0000, Holger Levsen wrote:
> Finally, as Lars pointed out, running /usr/lib/diaspora-common/scripts/diaspora-download.sh
> in postinst is both horrible from a security point of view, plus it's a
> policy violation, so that's two more RC bugs.

diasporo-installer is in contrib, so running this script is not a policy

(the rest of my mail stil stands…)


