[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Joblib 1.2.0 available on salsa



On Sun, Oct 09, 2022 at 12:47:14PM -0400, Aaron M. Ucko wrote:
> Nilesh Patra <nilesh@debian.org> writes:
> 
> > I could push the package to new again, with a new revision
> > but I fear another CVE being discovered meanwhile and we run into circles.
> 
> You can temporarily have a separate branch nominally targeting
> experimental, with docs included and version numbers along the lines of
> 1.2.0-1+doc or 1.2.0-1+exp1; subsequent uploads to unstable could either
> merge it or proceed with time-sensitive fixes, as appropriate.

Looks like I skipped reading the version numbers properly. Do you mean
"1.2.0+doc-2" instead?
I ask this because uploading a "1.2.0-2+doc" to experimtnal means
it'd be a problem if we meanwhile want to upload a new revision "1.2.0-3" to unstable, but
"1.2.0+doc-1" would be ok since we can keep uploading 1.2.0-$rev to unstable meanwhile.

Ofcourse, it could be worked around using numbers like "1.2.0-2.1" to unstable or
similar but then I am not sure how uploading 1.2.0-2+doc is better than uploading 1.2.0-3
to experimental, unless I misunderstand you.
Could you let me know?

-- 
Best,
Nilesh

Attachment: signature.asc
Description: PGP signature


Reply to: