[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: madison



On Mon, Jul 16, 2001 at 11:02:26AM -0400, Jimmy Kaplowitz wrote:
> On Mon, Jul 16, 2001 at 04:17:07PM +1000, Anthony Towns wrote:
> > People in the n-m queue are not maintainers. Sponsored people can ask their
> > sponsors.
> Then why are they listed in the Maintainer: field for their packages?  Put
> another way, who is the maintainer of a sponsored package?

The sponsor is, as far as Debian is concerned. S/He's the one we trust to
ensure that upload doesn't contain trojans, and the one we can actually
identify if we have any need to.

Sponsorship is a gaping hole in our trust model.

Cheers,
aj

-- 
Anthony Towns <aj@humbug.org.au> <http://azure.humbug.org.au/~aj/>
I don't speak for anyone save myself. GPG signed mail preferred.

``_Any_ increase in interface difficulty, in exchange for a benefit you
  do not understand, cannot perceive, or don't care about, is too much.''
                      -- John S. Novak, III (The Humblest Man on the Net)

Attachment: pgpGR39ogTBfd.pgp
Description: PGP signature


Reply to: