From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp2 ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms11 with LMTPS id cI1JNupuvl+sYAAA0tVLHw (envelope-from ) for ; Wed, 25 Nov 2020 14:49:14 +0000 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp2 with LMTPS id qPEzMupuvl/0FgAAB5/wlQ (envelope-from ) for ; Wed, 25 Nov 2020 14:49:14 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id E11979403E8 for ; Wed, 25 Nov 2020 14:49:13 +0000 (UTC) Received: from localhost ([::1]:44628 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1khw6a-0005zK-PK for larch@yhetil.org; Wed, 25 Nov 2020 09:49:12 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:39408) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1khrYo-0008OD-8d for bug-guix@gnu.org; Wed, 25 Nov 2020 04:58:02 -0500 Received: from debbugs.gnu.org ([209.51.188.43]:51131) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1khrYo-0007wS-0d for bug-guix@gnu.org; Wed, 25 Nov 2020 04:58:02 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1khrYo-0002zz-08 for bug-guix@gnu.org; Wed, 25 Nov 2020 04:58:02 -0500 X-Loop: help-debbugs@gnu.org Subject: bug#44863: Warning about importing a MELPA package Resent-From: Zhu Zihao Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Wed, 25 Nov 2020 09:58:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 44863 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: 44863@debbugs.gnu.org X-Debbugs-Original-To: bug-guix@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.160629825111487 (code B ref -1); Wed, 25 Nov 2020 09:58:01 +0000 Received: (at submit) by debbugs.gnu.org; 25 Nov 2020 09:57:31 +0000 Received: from localhost ([127.0.0.1]:34444 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1khrYJ-0002zC-1t for submit@debbugs.gnu.org; Wed, 25 Nov 2020 04:57:31 -0500 Received: from lists.gnu.org ([209.51.188.17]:57048) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1khrYH-0002z4-JG for submit@debbugs.gnu.org; Wed, 25 Nov 2020 04:57:29 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:39316) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1khrYH-0008M5-Av for bug-guix@gnu.org; Wed, 25 Nov 2020 04:57:29 -0500 Received: from mail-m974.mail.163.com ([123.126.97.4]:38040) by eggs.gnu.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.90_1) (envelope-from ) id 1khrY9-0007gp-AH for bug-guix@gnu.org; Wed, 25 Nov 2020 04:57:27 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=163.com; s=s110527; h=From:Subject:Date:Message-ID:MIME-Version; bh=Vno1Q ipESn9tnNr4TVSqK59Dg4ma9frek5DCRmnC6Jw=; b=G6XrtkT+TdNuYsB9367VG eOz+oi8TmHYtB88IadDDJIfDPSFOHk6TD1/21BRRXs/T2r3pQziRWF6KG0JKCnyU VGtU0Dm6SxwEgbNsZ8zztTANKg2iOpN6wP4bUM/hEDmwrZvy2vWGCz3rlGCRkb1R A/HNsYTHdTUtO44hY0miUU= Received: from asus-laptop (unknown [27.39.89.133]) by smtp4 (Coremail) with SMTP id HNxpCgD3s1Z6Kr5fA1JtaA--.15397S2; Wed, 25 Nov 2020 17:57:15 +0800 (CST) User-agent: mu4e 1.4.13; emacs 27.1 From: Zhu Zihao Date: Wed, 25 Nov 2020 17:57:08 +0800 Message-ID: <86mtz5zrm3.fsf@163.com> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" X-CM-TRANSID: HNxpCgD3s1Z6Kr5fA1JtaA--.15397S2 X-Coremail-Antispam: 1Uf129KBjvdXoWrtFy3GFykJF1kuF1fJr15twb_yoWxAwb_Zr WFqr9FgrZ5JrsrCr10qF4ftrZ8Wrn5ZryYv3W5CF1DGw1xA3ZrZFn8CFy8Aay2k3Wjqr90 9r4kKw129FWY9jkaLaAFLSUrUUUUUb8apTn2vfkv8UJUUUU8Yxn0WfASr-VFAUDa7-sFnT 9fnUUvcSsGvfC2KfnxnUUI43ZEXa7IU8OzVUUUUUU== X-Originating-IP: [27.39.89.133] X-CM-SenderInfo: pdoosuxxwbztlvw6il2tof0z/1tbiKRvnr1Xlyb9mDgAAsU Received-SPF: pass client-ip=123.126.97.4; envelope-from=all_but_last@163.com; helo=mail-m974.mail.163.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: 0.1 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-Spam-Score: -2.4 (--) X-Mailman-Approved-At: Wed, 25 Nov 2020 09:49:02 -0500 X-BeenThere: bug-guix@gnu.org List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+larch=yhetil.org@gnu.org Sender: "bug-Guix" X-Scanner: ns3122888.ip-94-23-21.eu Authentication-Results: aspmx1.migadu.com; dkim=fail (headers rsa verify failed) header.d=163.com header.s=s110527 header.b=G6XrtkT+; dmarc=fail reason="SPF not aligned (relaxed)" header.from=163.com (policy=none); spf=pass (aspmx1.migadu.com: domain of bug-guix-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=bug-guix-bounces@gnu.org X-Spam-Score: 0.49 X-TUID: jzaahTftaAYs --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable ELPA importer supports MELPA[1] currently. But MELPA is a rolling archive, which does not persist any old version tarball of package, and harmful for reproducible build. It's still useful for Guix packager to import package from MELPA to draft a sketch of Emacs package, but it's not a reliable download service. We may better warn user don't submit package which download url belongs to MELPA. Maybe emit warning while executing `guix import elpa -a melpa XXX`, or writing this rule to manual. [1]: the stable archive is "MELPA stable", I use term "MELPA" to refer to the unstable one. =2D-=20 Retrieve my PGP public key: https://meta.sr.ht/~citreu.pgp Zihao --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQFIBAEBCAAzFiEE7NCVzXX6efyusptG1SOVn+xGFqYFAl++KnQVHGFsbF9idXRf bGFzdEAxNjMuY29tAAoJENUjlZ/sRhamfasH9jxauMcL6gBh7pbAYzgvcY1JgkvT MRbg7LC8qo3swIxpTmcVQqy9GcBEmnzpf9vn63E4Qpz9MmLpt2s+4IHI5Cy2RkrW 01gvjw/j8UINfZrdZ3hhhOY9uOrJTYvbSmqbNRv0f7YCTx1oQ3Im0qnGdNTOQaZQ OYW7B4B43fHfuUGGZrJzUvQdPl4txycr6zfPBWzI6YaA2OVbmv7demptw7xTzcKv 61TUuenGens7Gw44PNLDL3Rxuxyz7NE+8C1t482INztLrqy0BmRblLtptHZyb5kC 3vt+GHDnzwom98sK1S8auj5yXLWT4yhjeaaVHLBxGNb0mNawfluDFPYRiQ== =QhaM -----END PGP SIGNATURE----- --=-=-=--