[pkg-go] Security support for packages written in Go

Dmitry Smirnov onlyjob at debian.org
Wed Apr 6 03:21:23 UTC 2016


On Tuesday, 5 April 2016 10:41:04 PM AEST Paul Tagliamonte wrote:
> | Backports are packages taken from the next Debian release (called
> | "testing"), adjusted and recompiled for usage on Debian stable.
> 
> So my confusion here is that you don't want to see them in Stable, but
> you do want to see them in testing (and backports). This isn't what
> testing is for, of course :)

I'm not comfortable with this idea. It requires a lot more work as well.
I just entertain possibility if we have to drop golang apps from next stable. 
After all even if not in next stable we might have some good ideas for next 
stable+1...


> I don't see anything inherent about Go that makes it unsupportable.

You are certainly more optimistic than I am. :)


> I *do* see more software being developed in a way that makes it nearly
> impossible for Debian to distribute.

But I'm not talking about distribution. We can distribute but security 
support is very difficult. Maybe we should just give up on it...


> This, however, is a much bigger conversation.

True...

-- 
Regards,
 Dmitry Smirnov.

---

Lies are the social equivalent of toxic waste: Everyone is potentially
harmed by their spread.
        -- Sam Harris
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: This is a digitally signed message part.
URL: <http://lists.alioth.debian.org/pipermail/pkg-go-maintainers/attachments/20160406/21440903/attachment.sig>


More information about the Pkg-go-maintainers mailing list