[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: NEW queue processing causes relaxed treatment of security issues



Le Wed, Jan 14, 2026 at 12:25:04PM +0100, Julien Puydt a écrit :
> Software foo version 1.42 has a source package providing a certain set of
> binary packages. Software foo version 2.53 has a same source package now
> providing a different set of binary packages. It has to go through NEW even
> though there is no associated big report, so it shouldn't be rejected by
> default.

A bug report can then be opened by the uploader as a discussion space,
exactly like we open ITP reports before uploading a new source package.
If the FTP team has questions or remarks about this upload, they whould have
a dedicated place for that, instead of having to initiate a private discussion.

It would double down as some documentation for system administrators,
giving them advance notice about new binary packages being on their way.

This clearly deserves a discussion, but on principle I think I would support
a requirement for a bug report to close with any upload going through NEW.

Attachment: signature.asc
Description: PGP signature


Reply to: