unofficial mirror of guix-devel@gnu.org 
 help / color / mirror / code / Atom feed
* Warning on using 'guix pull'
@ 2017-02-09 13:32 Pjotr Prins
  2017-02-09 16:00 ` Leo Famulari
  0 siblings, 1 reply; 2+ messages in thread
From: Pjotr Prins @ 2017-02-09 13:32 UTC (permalink / raw)
  To: Pjotr Prins; +Cc: guix-devel

@FOSDEM we concluded that 'guix pull' does not necessarily work
that wel. I added to my guix-notes the following:

+Health warning: at this point 'guix pull' is considered a liability for two reasons
+
+1. You don't know what you get even if it is considered 'latest'
+2. Guix pull runs over http and is not considered safe
+


-- 

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: Warning on using 'guix pull'
  2017-02-09 13:32 Warning on using 'guix pull' Pjotr Prins
@ 2017-02-09 16:00 ` Leo Famulari
  0 siblings, 0 replies; 2+ messages in thread
From: Leo Famulari @ 2017-02-09 16:00 UTC (permalink / raw)
  To: Pjotr Prins; +Cc: guix-devel

[-- Attachment #1: Type: text/plain, Size: 843 bytes --]

On Thu, Feb 09, 2017 at 01:32:53PM +0000, Pjotr Prins wrote:
> +Health warning: at this point 'guix pull' is considered a liability for two reasons

For those who haven't read it before, see the bug report 'Trustable guix
pull':

http://bugs.gnu.org/22883

> +1. You don't know what you get even if it is considered 'latest'

Recently, I added some instructions to the manual to explain how to
deploy a specific version of Guix with `guix pull`:

https://git.savannah.gnu.org/cgit/guix.git/commit/?id=8a9cffb202414b20081910115ba76402924bdcdd

It depends on cgit, but it's better than nothing for now.

> +2. Guix pull runs over http and is not considered safe

Savannah will soon announce general availability of Git over HTTPS. It's
usable now. I sent an RFC patch that is not yet in the guix-devel
archive (so I don't have a link to share).

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2017-02-09 16:00 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-02-09 13:32 Warning on using 'guix pull' Pjotr Prins
2017-02-09 16:00 ` Leo Famulari

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/guix.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).