From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Lars Ingebrigtsen Newsgroups: gmane.emacs.devel Subject: Re: feature/package+vc 04c4c578c7 3/4: Allow for packages to be installed directly from VCS Date: Sun, 09 Oct 2022 16:21:12 +0200 Message-ID: <87edvhqdrb.fsf@gnus.org> References: <164484721900.31751.1453162457552427931@vcs2.savannah.gnu.org> <20220214140020.04438C00891@vcs2.savannah.gnu.org> <87bkqmqpvb.fsf@posteo.net> <871qris3xb.fsf@gnus.org> <877d1aqoc1.fsf@posteo.net> Mime-Version: 1.0 Content-Type: text/plain Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="19869"; mail-complaints-to="usenet@ciao.gmane.io" User-Agent: Gnus/5.13 (Gnus v5.13) Cc: Stefan Monnier , emacs-devel@gnu.org To: Philip Kaludercic Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane-mx.org@gnu.org Sun Oct 09 16:22:26 2022 Return-path: Envelope-to: ged-emacs-devel@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1ohXCD-0004x1-EF for ged-emacs-devel@m.gmane-mx.org; Sun, 09 Oct 2022 16:22:25 +0200 Original-Received: from localhost ([::1]:53738 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1ohXCC-0007ls-3Q for ged-emacs-devel@m.gmane-mx.org; Sun, 09 Oct 2022 10:22:24 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:36382) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1ohXBB-0006Ou-00 for emacs-devel@gnu.org; Sun, 09 Oct 2022 10:21:21 -0400 Original-Received: from quimby.gnus.org ([2a01:4f9:2b:f0f::2]:34648) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1ohXB8-0004jL-Ox for emacs-devel@gnu.org; Sun, 09 Oct 2022 10:21:20 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnus.org; s=20200322; h=Content-Type:MIME-Version:Message-ID:Date:References: In-Reply-To:Subject:Cc:To:From:Sender:Reply-To:Content-Transfer-Encoding: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=dSb644hQzuSOBPGh17a7ZRuBF0k0VF80gdwZ4PBeJIU=; b=RtMvnGJooexMGCK2dHg9PACSqz kBmHOXqvfLi7HZU2Q9DfB9pp473vhcqQMDSli6WO1aktkPAyS4LcNAp+o59hqairv3sFsMr0fuXdM 1D+aWdNVjWTTGSykjosB2CAqecD0Q9vvX8/6hHCngv6XgLSmoIJmAYqrsJhi606hCdw0=; Original-Received: from [84.212.220.105] (helo=downe) by quimby.gnus.org with esmtpsa (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1ohXB2-00031l-WE; Sun, 09 Oct 2022 16:21:15 +0200 In-Reply-To: <877d1aqoc1.fsf@posteo.net> (Philip Kaludercic's message of "Sat, 08 Oct 2022 16:20:30 +0000") Face: iVBORw0KGgoAAAANSUhEUgAAADAAAAAwAgMAAAAqbBEUAAAABGdBTUEAALGPC/xhBQAAACBj SFJNAAB6JgAAgIQAAPoAAACA6AAAdTAAAOpgAAA6mAAAF3CculE8AAAADFBMVEUqHCJVMjPAnmv/ ///dSr/NAAAAAWJLR0QDEQxM8gAAAAd0SU1FB+YKCQ4PBygToXIAAAFlSURBVCjPTZK/asMwEMbv StTZBivQzJ3yFArEu1x8gnrq0AzVU6RD9w7xksmBuOB7yt6dXKjAln989+fTyQC2XF922MjjFdDw /T88h1ogOIOq0jQogFcOsjUGD8xnuECAU+rokYfpUUXmH/7ky9uORwIaOzrwJWbmBbKm8v2FOd8N HN995usEzpSpYebvYo+nKBAK5BEFVuP76JjHVdmDKHMP0QDdwMsARAJPxzZZkicKriWBGeQoLSGR 2LkBxQDYkaw8axSgJynb7KRAgFbeVjVqNdGtX619cQVvsKUW5aM3SNQdJEv1iDT6HiuQYhiwH9WH ghe4USsNJacOrp/Vg9iRMEezp/Sq4KLrVPmwawt+KGGlc5rpdBXHNgYX/cCiVCWyTnJSu6TKh4oU NjKgxnce8gKoN++oayHJdAIEPOixIav/M/61aAC/ZDjdCoDaPeqfsKnAqZej+FDYLsVYMmcFXPoF Gpl5Wv37VTkAAAAldEVYdGRhdGU6Y3JlYXRlADIwMjItMTAtMDlUMTQ6MTU6MDcrMDA6MDAlZjsA AAAAJXRFWHRkYXRlOm1vZGlmeQAyMDIyLTEwLTA5VDE0OjE1OjA3KzAwOjAwVDuDvAAAAABJRU5E rkJggg== X-Now-Playing: Egg's _The Polite Force_: "Long Piece =?utf-8?Q?N=C2=BA?= 3 (Part 1)" Received-SPF: pass client-ip=2a01:4f9:2b:f0f::2; envelope-from=larsi@gnus.org; helo=quimby.gnus.org X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane-mx.org@gnu.org Original-Sender: "Emacs-devel" Xref: news.gmane.io gmane.emacs.devel:297271 Archived-At: Philip Kaludercic writes: > It seems to me that fetching a package from source is no more dangerous > than fetching a tarball, seeing as the tarball is automatically > generated from the repository. It doesn't matter much whether it's a tar ball or a git repo (although there is signing of the tar balls), but whether there's any oversight at all or not. All commits to Non/GNU ELPA end up on a mailing list, which provides a smidgen of transparency, which is better than none.