Package: gitaly
Version: 16.11.3+ds15-1
Severity: important

As discussed already in #debian-diaspora irc a few weeks back, posting here as well for reference.

1. gitaly has a lots of build dependencies
2. most dependency updates need to be handled like a transition including complicated ones like grpc and protobuf. This is not possible to complete in a short 3 months window of time when upstream provides security updates. 3. Even with vendoring it is really too much work to maintain (it used to be funded earlier, but not any more) and there is not many volunteers. 4. so we should download the prebuilt binaries from upstream ci in postinst (like we already do for node modules and some ruby gems). 5. This means moving the package to contrib. Once gitaly-installer is ready, we can drop gitaly.
6. Move gitlab-common binary also to gitaly-installer

Attachment: OpenPGP_0x8F53E0193B294B75.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

_______________________________________________
Pkg-go-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-go-maintainers

Reply via email to