On Sat, 2026-06-13 at 11:36 +0100, Andy Pieters wrote:
> I'm not sure if it's feasible to have a maintainer for each and every
> possible package not to mention keep them all to the latest version
> required by the software's own manifests....

Hi,

I don’t know enough about this topic to offer a well-informed
assessment, but this is something that really needs to be discussed.
Micro-packages that contain just a single line of code and perform
trivial tasks, that a programmer could easily write themselves, should
be phased out gradually, so that the number of packages requiring
maintenance is steadily reduced.
But if such discussions are deemed "inappropriate" everywhere, then
nothing will change over time. I don’t want to discuss this any further,
I just wanted to bring it to everyone's attention again. As AI
capabilities increase, a system that has ran out of control, one that
may have been well-intentioned at the time, creates unnecessary
vulnerabilities.

Regards,
Ralf


Reply via email to