Hi

We have no control over github releases, they are made automatically
as you said. Can't modify any schema or anything.

But I can't be clear enough about this: distributions should use
sources on lxqt.org (as long as they rehost of course). Github sources
are the untrusted ones because they are handled by a third party.
lxqt.org sources are tagged, checksummed and pushed as is to the
lxqt.org repos which are fully under the control of the lxde team.
The issue regarding the layout inside those archives is known and
fixed for 0.8, which will be released imminently (for real guys, we're
talking within next couple of days).

J. Leclanche


2014-10-10 17:28 GMT+02:00 Eugene Pivnev <ti.eug...@gmail.com>:
> I'm starting pushing LXQT into official Fedore/CentOS repos (as maintainer).
> And ask you to make 0.7.0 (tarballs in github) with standart rules
> (<name>-<version>.tar.gz, that contains <name>-<version> folder).
>
> Standard source URL must be like:
> https://github.com/$OWNER/%{name}/archive/%{name}-%{version}.tar.gz
> E.g.: https://github.com/lxde/liblxqt/archive/liblxde-0.7.0.tar.gz
>
> Now _all_ of sources are:
> https://github.com/$OWNER/%{name}/archive/%{version}.tar.gz
>
> Please - tune release tarballs
>
> ====
> Q&A:
>
> Q: Each src are downloading as <name>-<version>.tar.gz with browser.
> A: Yes. But Fedora build system is not browser. Try wget.
>
> Q: this is not problem for liblxqt
> A: Yes. But this is problem for packageing from 1+ sources
> (http://download.opensuse.org/repositories/X11:/QtDesktop:/LXQT/Fedora_20/src/lxqt-0.7.0-19.1.src.rpm).
> Each from src tarball will be "0.7.0.tar.gz".
>
> Q: you can download from http://lxqt.org/downloads/lxqt/0.7.0/
> A: Yes. But:
> - these sources differe against github ones
> - and non-standard too (folder <name>-<version> inside)
> - and not trusted (github sources are made automatically)
>
>
> ------------------------------------------------------------------------------
> Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
> Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
> Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
> Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer
> http://pubads.g.doubleclick.net/gampad/clk?id=154622311&iu=/4140/ostg.clktrk
> _______________________________________________
> Lxde-list mailing list
> Lxde-list@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/lxde-list

------------------------------------------------------------------------------
Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer
http://p.sf.net/sfu/Zoho
_______________________________________________
Lxde-list mailing list
Lxde-list@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/lxde-list

Reply via email to