[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: package.el + DVCS for security and convenience
From: |
Stephen J. Turnbull |
Subject: |
Re: package.el + DVCS for security and convenience |
Date: |
Mon, 07 Jan 2013 11:03:07 +0900 |
Ted Zlatanov writes:
> I'm actually suggesting that the GNU ELPA maintainers (note the "GNU
> ELPA" part here, this is not any ELPA maintainer) should review and sign
> *every* commit to the GNU ELPA.
I have no idea what you think you're proposing. Security reviews are
expensive; I doubt you'll have anybody willing to maintain GNU ELPA
after a couple of months of that, unless you pay handsomely, or you
enlist a maintainer per package or so to reduce the burden on
individual maintainers to a manageable level. The obvious candidates
for the latter are the authors.
If they are not security reviews, what's the point of reviewing at
all? You just want signed commits, verifying that the commit was
actually received at the GNU ELPA. AFAICS this can be done by a bot,
which checks the authors' signatures on the commits.
- Re: package.el + DVCS for security and convenience, Stefan Monnier, 2013/01/03
- Re: package.el + DVCS for security and convenience, Ted Zlatanov, 2013/01/04
- Re: package.el + DVCS for security and convenience, Stefan Monnier, 2013/01/04
- Re: package.el + DVCS for security and convenience, Ted Zlatanov, 2013/01/04
- Re: package.el + DVCS for security and convenience, Stephen J. Turnbull, 2013/01/04
- Re: package.el + DVCS for security and convenience, Ted Zlatanov, 2013/01/06
- Re: package.el + DVCS for security and convenience,
Stephen J. Turnbull <=
- Re: package.el + DVCS for security and convenience, Ted Zlatanov, 2013/01/07
- Re: package.el + DVCS for security and convenience, Stephen J. Turnbull, 2013/01/07
- Re: package.el + DVCS for security and convenience, Ted Zlatanov, 2013/01/08
- Re: package.el + DVCS for security and convenience, Stephen J. Turnbull, 2013/01/08
- Re: package.el + DVCS for security and convenience, Ted Zlatanov, 2013/01/08
- Re: package.el + DVCS for security and convenience, Stefan Monnier, 2013/01/08
- Re: package.el + DVCS for security and convenience, Stephen J. Turnbull, 2013/01/08
- Re: package.el + DVCS for security and convenience, Stephen J. Turnbull, 2013/01/07
- Re: package.el + DVCS for security and convenience, Xue Fuqiao, 2013/01/08
Re: package.el + DVCS for security and convenience, Xue Fuqiao, 2013/01/04