@jimp:
@robi:
I know that, but how will this affect security-wise? A lot of packages will be present there, while in the past they were not… and not even needed for operation.
We have found in some cases that build dependencies were not listed as such, so they were taken as run dependencies as well, so things get added to the pile that aren't really necessary.
Thanks for the detailed answer.
The qoute above is the reason why I was asking. I see this all the time in Linux too, seems that package devs usually mark as dependencies stuff "just to make sure" without properly checking if it's really needed or not.