On 2013-09-11 17:09, Dicebot wrote:

Those should be provided as sources and built by dub too. Distributing
binary packages requires both package signing and reasonable web of
trust - something that is not easy to "just implement" from scratch.
Otherwise any single malicious package may ruin reputation of the whole
system.

I have no problems with the packages being distributed as source. That makes a lot of things easier. But it should compile and install it when it's downloaded. Currently it only clones the repository. Not giving much more than a plain "git clone".

--
/Jacob Carlborg

Reply via email to