emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: feature/package+vc 04c4c578c7 3/4: Allow for packages to be installe


From: Philip Kaludercic
Subject: Re: feature/package+vc 04c4c578c7 3/4: Allow for packages to be installed directly from VCS
Date: Sun, 09 Oct 2022 14:34:45 +0000

Lars Ingebrigtsen <larsi@gnus.org> writes:

> Philip Kaludercic <philipk@posteo.net> writes:
>
>> It seems to me that fetching a package from source is no more dangerous
>> than fetching a tarball, seeing as the tarball is automatically
>> generated from the repository.
>
> It doesn't matter much whether it's a tar ball or a git repo (although
> there is signing of the tar balls), but whether there's any oversight at
> all or not.  All commits to Non/GNU ELPA end up on a mailing list, which
> provides a smidgen of transparency, which is better than none.

OK, in that case my proposal shouldn't be any more dangerous than what
is already going on.



reply via email to

[Prev in Thread] Current Thread [Next in Thread]