[gentoo-dev] Last rites: dev-java/jackson-mapper

2015-03-06 Thread James Le Cuirot
# James Le Cuirot ch...@gentoo.org (6 Mar 2015) # A Jackon library that was part of v1 but not v2. Nothing in the tree # has ever required v1. Removal in 30 days. dev-java/jackson-mapper -- James Le Cuirot (chewi) Gentoo Linux Developer pgpfkAnoiHJi9.pgp Description: OpenPGP digital signature

Re: [gentoo-portage-dev] Security and Comparison of Portage with other Package Managers

2015-03-06 Thread Rick Zero_Chaos Farina
On 03/06/15 08:53, Mark Kubacki wrote: 2015-03-06 1:56 GMT+01:00 Rick Zero_Chaos Farina zeroch...@gentoo.org: tl;dr webrsync-gpg is a built in feature of the package manager which OPTIONALLY adds a significant amount of security against the attacks described on your website. This is not

Re: [gentoo-dev] what's the correct format for bugs containing package name and version?

2015-03-06 Thread Ulrich Mueller
On Thu, 5 Mar 2015, Paweł Hajdan, Jr. wrote: I'm trying to find the best fix for https://bugs.gentoo.org/show_bug.cgi?id=535814 Currently file-stabilization-bugs.py uses the '%s: stabilization request' % cpv format. The Emacs team used to have a stabilisation template with summary Please

Re: [gentoo-dev] what's the correct format for bugs containing package name and version?

2015-03-06 Thread Rich Freeman
On Thu, Mar 5, 2015 at 2:01 PM, Paweł Hajdan, Jr. phajdan...@gentoo.org wrote: What is your preference? Let's agree on something and avoid unnecessary changes on bugzilla. Out of curiousity, what makes the changes necessary in the first place? It seems like an incredible amount of effort is

Re: [gentoo-portage-dev] Security and Comparison of Portage with other Package Managers

2015-03-06 Thread Patrick Schleizer
Hi, it was naive of me to attempt to create such a comparison table. Takes much more time than I have available for this. It was to be expected that there are disagreements and I cannot resolve them without checking the code myself and perhaps without coming up with proof of concept exploitation

Re: [gentoo-dev] what's the correct format for bugs containing package name and version?

2015-03-06 Thread Jeroen Roovers
On Thu, 05 Mar 2015 15:20:23 -0500 Michael Orlitzky m...@gentoo.org wrote: So jer format is something like %s - foo. Yes. I now have a format named after me. I guess I subconsciously reverted to using a colon because that's what makes the most sense to me. But there is a little ambiguity

Re: [gentoo-dev] what's the correct format for bugs containing package name and version?

2015-03-06 Thread Jeroen Roovers
On Thu, 05 Mar 2015 20:01:23 +0100 Paweł Hajdan, Jr. phajdan...@gentoo.org wrote: I'm trying to find the best fix for https://bugs.gentoo.org/show_bug.cgi?id=535814 Currently file-stabilization-bugs.py uses the '%s: stabilization request' % cpv format. Here are some options I see: a)

Re: [gentoo-dev] what's the correct format for bugs containing package name and version?

2015-03-06 Thread Sven Vermeulen
On Fri, Mar 06, 2015 at 06:55:13AM -0500, Rich Freeman wrote: Out of curiousity, what makes the changes necessary in the first place? It seems like an incredible amount of effort is going into standardizing the format of textual summary lines and perhaps the simplest solution is to just not

Re: [gentoo-portage-dev] Security and Comparison of Portage with other Package Managers

2015-03-06 Thread Mark Kubacki
2015-03-06 1:56 GMT+01:00 Rick Zero_Chaos Farina zeroch...@gentoo.org: tl;dr webrsync-gpg is a built in feature of the package manager which OPTIONALLY adds a significant amount of security against the attacks described on your website. This is not currently the default setting, however, it

Re: [gentoo-dev] what's the correct format for bugs containing package name and version?

2015-03-06 Thread Rich Freeman
On Fri, Mar 6, 2015 at 1:14 PM, Sven Vermeulen sw...@gentoo.org wrote: It doesn't hurt to have a recommendation, and personally I really appreciate when people (yes, that includes developers and wranglers ;-) update the line to be more informative. There already is a recommendation on the