Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.maint.java > #11976

Re: List of consultants focusing on Debian packaging for Java?

From Sam Kuper <sampablokuper@posteo.net>
Newsgroups linux.debian.maint.java
Subject Re: List of consultants focusing on Debian packaging for Java?
Date 2020-12-07 18:30 +0100
Message-ID <BjsuJ-2zD-1@gated-at.bofh.it> (permalink)
References (3 earlier) <BiNUD-1Pe-17@gated-at.bofh.it> <Bj9BL-7m1-5@gated-at.bofh.it> <Bj9BL-7m1-3@gated-at.bofh.it> <BjoKt-5C-5@gated-at.bofh.it> <BjoKt-5C-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Mon, Dec 07, 2020 at 02:26:01PM +0100, Hans-Christoph Steiner wrote:
> Third party package repositories are a thing, like Ubuntu PPAs, aptly,
> JFrog Debian Repositories, etc.  Unfortunately, due to Debian Apt's
> design, that means giving root access to each repository (package
> pre-install/remove/etc scripts are run as root).  So installing via
> external repositories means the user need to consider whether they
> trust those third party repositories with root access.

It isn't entirely unfortunate.

Users, and especially system administrators, ought to be minimally
trusting of external resources.  The TCB must be kept small, or security
is an illusion.

Apt's design, IMO, encourages people to think twice - and ideally to
stop themselves - before they install software.  Especially software
from outside Main, and *especially* software from outside Debian.

Put differently: yes, third party package repositories are a thing.  But
they are mostly not a good thing, and they should probably not be
encouraged.

Far, far better for the OP to keep the focus on getting OpenRefine into
Debian properly, rather than to consider expending time and resources on
less beneficial outcomes.

(BTW, Hans-Christoph, I think you were, above, trying to point out
pitfalls of third party repositories; not trying to encourage their use.
So, my email is not intended as a dig at you at all.  I just wanted to
point out that Apt's design is in many ways something to be glad about.
I am grateful to the Apt developers and to responsible Debian packagers
everywhere, and I would be happy for this gratitude to one day also
extend to whoever ends up packaging OpenRefine for Debian.)

-- 
A: When it messes up the order in which people normally read text.
Q: When is top-posting a bad thing?

()  ASCII ribbon campaign. Please avoid HTML emails & proprietary
/\  file formats. (Why? See e.g. https://v.gd/jrmGbS ). Thank you.

Back to linux.debian.maint.java | Previous | NextPrevious in thread | Next in thread | Find similar


Thread

List of consultants focusing on Debian packaging for Java? "Antonin Delpeuch (lists)" <lists@antonin.delpeuch.eu> - 2020-12-04 18:20 +0100
  Re: List of consultants focusing on Debian packaging for Java? Markus Koschany <apo@debian.org> - 2020-12-04 21:10 +0100
    Re: List of consultants focusing on Debian packaging for Java? Sam Kuper <sampablokuper@posteo.net> - 2020-12-05 03:30 +0100
      Re: List of consultants focusing on Debian packaging for Java? "Antonin Delpeuch (lists)" <lists@antonin.delpeuch.eu> - 2020-12-05 19:10 +0100
        Re: List of consultants focusing on Debian packaging for Java? Paul Wise <pabs@debian.org> - 2020-12-06 00:10 +0100
    Re: List of consultants focusing on Debian packaging for Java? Markus Koschany <apo@debian.org> - 2020-12-05 23:10 +0100
      Re: List of consultants focusing on Debian packaging for Java? Emmanuel Bourg <ebourg@apache.org> - 2020-12-06 22:20 +0100
        Re: List of consultants focusing on Debian packaging for Java? Hans-Christoph Steiner <hans@at.or.at> - 2020-12-07 14:30 +0100
          Re: List of consultants focusing on Debian packaging for Java? Sam Kuper <sampablokuper@posteo.net> - 2020-12-07 18:30 +0100
          Re: List of consultants focusing on Debian packaging for Java? Fabrice BAUZAC <noon@mykolab.com> - 2020-12-12 00:50 +0100
        Re: List of consultants focusing on Debian packaging for Java? Emmanuel Bourg <ebourg@apache.org> - 2020-12-07 22:00 +0100
          Re: List of consultants focusing on Debian packaging for Java? Pirate Praveen <praveen@onenetbeyond.org> - 2020-12-08 12:30 +0100
            Re: List of consultants focusing on Debian packaging for Java? Emmanuel Bourg <ebourg@apache.org> - 2020-12-10 23:10 +0100
          Re: List of consultants focusing on Debian packaging for Java? Hans-Christoph Steiner <hans@at.or.at> - 2020-12-08 21:00 +0100
      Re: List of consultants focusing on Debian packaging for Java? Markus Koschany <apo@debian.org> - 2020-12-07 12:50 +0100
        Re: List of consultants focusing on Debian packaging for Java? Thorsten Glaser <t.glaser@tarent.de> - 2020-12-07 15:40 +0100
          Re: List of consultants focusing on Debian packaging for Java? Markus Koschany <apo@debian.org> - 2020-12-07 21:20 +0100
            Re: List of consultants focusing on Debian packaging for Java? Sudip Mukherjee <sudipm.mukherjee@gmail.com> - 2020-12-07 22:00 +0100
          Re: List of consultants focusing on Debian packaging for Java? Emmanuel Bourg <ebourg@apache.org> - 2020-12-07 22:20 +0100
  Re: List of consultants focusing on Debian packaging for Java? Paul Wise <pabs@debian.org> - 2020-12-05 04:40 +0100
    Re: List of consultants focusing on Debian packaging for Java? "Antonin Delpeuch (lists)" <lists@antonin.delpeuch.eu> - 2020-12-05 19:00 +0100

csiph-web