~alpine/devel

3 3

[alpine-devel] Packages to consider moving from main/ to community/

Details
Message ID
<18a9b3a4-c34b-4727-28c6-0fb416b354a4@adelielinux.org>
Sender timestamp
1518633734
DKIM signature
missing
Download raw message
Hi there Alpinists,

We've made a list of packages currently in main/ that may be better
suited to being in community/:

== Media software / stuff that uses Qt5 upstream ==

Rationale: Qt 5 is in community, doesn't really belong in main

* audacious
* v4l-utils


== HTTP servers ==

Rationale: HTTP servers are notoriously terrible at security and having
them in main means lots of maintenance work for Alpine to keep security
fixes for them for years.

* darkhttpd
* lighttpd (+ acf-lighttpd)
* mini_httpd
* nghttp2


Thanks for your consideration.


Best to you and yours,
--arw

-- 
A. Wilcox (awilfox)
Project Lead, Adélie Linux
http://adelielinux.org
William Pitcock <nenolod@dereferenced.org>
Details
Message ID
<CA+T2pCGKNEKQ3t2qGSy2ruNwuTK-811LzHf-RBfztq6=pHTjUQ@mail.gmail.com>
In-Reply-To
<20180214213643.5bplV%steffen@sdaoden.eu> (view parent)
Sender timestamp
1518655883
DKIM signature
missing
Download raw message
Hello,

On Wed, Feb 14, 2018 at 3:36 PM, Steffen Nurpmeso <steffen@sdaoden.eu> wrote:
> "A. Wilcox" <awilfox@adelielinux.org> wrote:
>  |We've made a list of packages currently in main/ that may be better
>  |suited to being in community/:
>  ...
>  |== HTTP servers ==
>  |
>  |Rationale: HTTP servers are notoriously terrible at security and having
>  |them in main means lots of maintenance work for Alpine to keep security
>  |fixes for them for years.
>  ...
>  |* lighttpd (+ acf-lighttpd)
>
> I understand only main/ is backward supported?
> But i really have to stand up for this one.
> Reported bugs end up in new releases occasionally, which then end
> in main by updating APKBUILD.  If i look at the commit log i see
> something back in July 2015, which surely was a pain.  Can a port
> be managed any cheaper than this one?

We suggested lighttpd for move to community because upstream is not
always fast on fixing security problems.

William


---
Unsubscribe:  alpine-devel+unsubscribe@lists.alpinelinux.org
Help:         alpine-devel+help@lists.alpinelinux.org
---
Francesco Colista <fcolista@alpinelinux.org>
Details
Message ID
<03401572b392aba00aa2831a9065679a@alpinelinux.org>
In-Reply-To
<18a9b3a4-c34b-4727-28c6-0fb416b354a4@adelielinux.org> (view parent)
Sender timestamp
1518634422
DKIM signature
missing
Download raw message
Il 2018-02-14 19:42 A. Wilcox ha scritto:
> Hi there Alpinists,
> 
> We've made a list of packages currently in main/ that may be better
> suited to being in community/:
> 
> == Media software / stuff that uses Qt5 upstream ==
> 
> Rationale: Qt 5 is in community, doesn't really belong in main
> 
> * audacious
> * v4l-utils

Hi!
You need to consider the dependencies.
So far, in main there are ffmpeg and gst-plugins-good who depends from 
v4l-utils-dev.
If you move it in community, dependency will break.
And move them also to community, will end up in moving:
- sox
- audacious-plugings
- gst-libav
- omxplayer
- pianobar

audacious is not a dependency of any pacakge besides audacious-plugins.

Move all of them, IMHO, is not a bad idea.

-- 
:: Francesco Colista
:: Alpine Linux Infrstraucture
:: http://www.alpinelinux.org
:: GnuPG ID: C4FB9584


---
Unsubscribe:  alpine-devel+unsubscribe@lists.alpinelinux.org
Help:         alpine-devel+help@lists.alpinelinux.org
---
Steffen Nurpmeso <steffen@sdaoden.eu>
Details
Message ID
<20180214213643.5bplV%steffen@sdaoden.eu>
In-Reply-To
<18a9b3a4-c34b-4727-28c6-0fb416b354a4@adelielinux.org> (view parent)
Sender timestamp
1518644203
DKIM signature
missing
Download raw message
"A. Wilcox" <awilfox@adelielinux.org> wrote:
 |We've made a list of packages currently in main/ that may be better
 |suited to being in community/:
 ...
 |== HTTP servers ==
 |
 |Rationale: HTTP servers are notoriously terrible at security and having
 |them in main means lots of maintenance work for Alpine to keep security
 |fixes for them for years.
 ...
 |* lighttpd (+ acf-lighttpd)

I understand only main/ is backward supported?
But i really have to stand up for this one. 
Reported bugs end up in new releases occasionally, which then end
in main by updating APKBUILD.  If i look at the commit log i see
something back in July 2015, which surely was a pain.  Can a port
be managed any cheaper than this one?

--steffen
|
|Der Kragenbaer,                The moon bear,
|der holt sich munter           he cheerfully and one by one
|einen nach dem anderen runter  wa.ks himself off
|(By Robert Gernhardt)


---
Unsubscribe:  alpine-devel+unsubscribe@lists.alpinelinux.org
Help:         alpine-devel+help@lists.alpinelinux.org
---
Reply to thread Export thread (mbox)