On Mon 2017-08-14 21:02:38 +0200, Ansgar Burchardt wrote:
> The reason we currently require NEW uploads to include binary package is
> that they are easier to review than source-only uploads w.r.t. what will
> actually end up in a binary package.

So what if someoneā„¢ made a dedicated auto-builder that generated binary
packages from source-only uploads in NEW, and you could review those
binary packages?  would that resolve this part of the conern?

> Some bits of the tools also assume that binaries are included.

which bits are those?  are they documented somewhere so that people who
want to fix them can fix them?

> I'm not sure we should throw away included binaries either; that just
> means two packages with the same version, but different contents
> exist.

with reproducible builds, that shouldn't be an issue, right?

> Eventually moving to source-only uploads also for NEW seems to be the
> better solution to me.  That's why I set the bug to "wontfix" for now.

I agree that this is a better solution for the future.

Is there a bug report for moving to source-only uploads for NEW?  I'd
happily move this discussion over there.

        --dkg

Attachment: signature.asc
Description: PGP signature

Reply via email to