GNU bug report logs -
#17625
details of package signing mechanism
Previous Next
Reported by: Eric Abrahamsen <eric <at> ericabrahamsen.net>
Date: Thu, 29 May 2014 03:12:01 UTC
Severity: important
Tags: security
Found in version 24.4.50
Done: Stefan Monnier <monnier <at> iro.umontreal.ca>
Bug is archived. No further changes may be made.
Full log
View this message in rfc822 format
Stefan Monnier writes:
> I guess my APT blinders are getting in the way.
> But at least Debian seems to live rather well without caring where the
> packages come from.
I have not enough knowledge about APT to comment specifically on the
design goals it has implemented. Debian packaging however is quite
coordinated and disciplined in my experience. Come to think of it, that
might actually be neccessitated by the design of APT.
But stepping back from that discussion, the reality of Emacs' package
management is that it allows for an unlimited number of package
repositories to be configured and there are several different package
repositories that have different and sometimes uncoordinated ways of
doing their package versioning. That means for instance if I want to
try out a single package from melpa, package manager would try to update
all my other packages that are also available on melpa, whether I want
that or not. My current solution is to only temporarily enable melpa,
install that one package and disable the repository again. Now I have
the problem that I don't get the continuous updates that I'm supposed to
get when chosing from melpa. That makes package manager a lot less
useful than it could be in my book.
Regards,
Achim.
--
+<[Q+ Matrix-12 WAVE#46+305 Neuron microQkb Andromeda XTk Blofeld]>+
Factory and User Sound Singles for Waldorf Q+, Q and microQ:
http://Synth.Stromeko.net/Downloads.html#WaldorfSounds
This bug report was last modified 10 years and 236 days ago.
Previous Next
GNU bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson.