Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 26 May 2014 21:54:59 +0200
From:      John Marino <freebsd.contact@marino.st>
To:        =?UTF-8?B?QmFydMWCb21pZWogUnV0a293c2tp?= <r@robakdesign.com>,  marino@FreeBSD.org
Cc:        ports@robakdesign.com, freebsd-python@FreeBSD.org
Subject:   Re: ports/189666: devel/py-demjson: unfetchable due to rerolled tarball
Message-ID:  <53839C13.4040405@marino.st>
In-Reply-To: <C6C210C7-53CE-4185-8624-CE3737598A4F@robakdesign.com>
References:  <201405260846.s4Q8kUdC079970@freefall.freebsd.org> <C6C210C7-53CE-4185-8624-CE3737598A4F@robakdesign.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On 5/26/2014 21:36, Bartłomiej Rutkowski wrote:
> I've just mailed the upstream, explaining the situation and
> suggesting releasing such changes as minor version numbers, like
> 2.0.1 or something similar. We'll see what, if any response will I
> receive, but for now, please, patch the port with new distinfo you've
> proposed. If this happens again and we wont get any answer by that
> time, we'll consider hosting the distfiles or removing the port.

Hi Bartek,
The issue is that I can't blindly update the distinfo.  Somebody (almost
always the maintainer) has to "diff" the original version and the new
version and evaluate exactly what changed and if it's malicious.

I already got chewed out last week for not verifying this personally,
but I generally trust the maintainer if he/she said he did this.  Have
you actually looked inside the new tarball?

Thanks,
John



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?53839C13.4040405>