[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: python-django_1.8.18-1~bpo8+1_amd64.changes REJECTED



On Thu, 25 May 2017, Rhonda D'Vine wrote:
> * Brian May <bam@debian.org> [2017-05-25 12:39:41 CEST]:
> > I am going to switch sides here (am I allowed to do this?), and try to
> > guess:

Thanks Brian, it was helpful since you put into light one aspect that
Rhonda did not tell us explicitly yet.

>  For the record, we have that overview:
> https://backports.debian.org/jessie-backports/overview/
> https://backports.debian.org/jessie-backports/outdated/ (that's where
> the above 25% came from)

Maybe we could document in some way when the backport is not in
sync with testing and when it's a maintainer's choice ?

Or maybe it doesn't matter, and what we really care about is
https://security-tracker.debian.org/tracker/status/release/stable-backports
not having any CVE listed (I believe we are not currently properly
tracking CVE in backports).

>  If the packages are in sync, (LTS)maintaining oldstable-backports turns
> into a no-brainer, as the patches in stable shouldn't pose any
> additional incompatibilities that would affect the former backport.
> That is also another core reasons for the rule.  When the discussion
> came up for oldoldstable-backports and LTS, I said I would be willing to
> maintain it myself if people won't do it themself -- but I can only do
> that if the packages are in sync.  Everything else is not maintainable
> with minimum overhead.  I can't hold that offer for packages that are
> maintained in a way that makes them out of sync with the source from
> where they got backported.

As long as the backport has a proper maintainer, you have no reason to
worry. And in the specific case of python-django, upgrading the backports
so that it gets in sync with testing is easy. We are not doing it because
we don't want to do it, not because of any other problem. But if we
disappear and someone else believe that the best course of action is
to get back in sync with testing, then it will not require more than 10
minutes of work.

Cheers,
-- 
Raphaël Hertzog ◈ Debian Developer

Support Debian LTS: https://www.freexian.com/services/debian-lts.html
Learn to master Debian: https://debian-handbook.info/get/


Reply to: