From mboxrd@z Thu Jan 1 00:00:00 1970 From: Danny Milosavljevic Subject: Re: Updating mono. Adding MSBuild. Date: Wed, 27 Mar 2019 12:23:10 +0100 Message-ID: <20190327122310.4c8155eb@scratchpost.org> References: <875zs5c72r.fsf@posteo.net> <874l7o4y1p.fsf@elephly.net> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; boundary="Sig_/gosXaIm2.lDApq6UT2z/aR6"; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([209.51.188.92]:56538) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1h96eR-0007iX-SQ for guix-devel@gnu.org; Wed, 27 Mar 2019 07:23:24 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1h96eP-00064I-WD for guix-devel@gnu.org; Wed, 27 Mar 2019 07:23:22 -0400 Received: from dd26836.kasserver.com ([85.13.145.193]:33060) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1h96eP-00060B-Mq for guix-devel@gnu.org; Wed, 27 Mar 2019 07:23:21 -0400 In-Reply-To: <874l7o4y1p.fsf@elephly.net> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Ricardo Wurmus Cc: Guix-devel --Sig_/gosXaIm2.lDApq6UT2z/aR6 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Hi, > > Mono, for most distributions, seems to be bootstrapped with a prebuilt > > binary mono-lite. Due to this, I am unsure of how to make the first step > > in correctly repackaging Mono. =20 >=20 > Instead of adding a new binary mono-lite, can we reuse the existing > =E2=80=9Cmono=E2=80=9D package to build the new Mono? +1 > (I don=E2=80=99t know what MSBuild is and how it would help here.) MSBuild is something like Ant for .NET. (or "make", but with more XML :) ) I think Brett means that MSBuild is bundled with mono. I failed to unbundle some things just to have a CVE in one of the bundled dependencies DAYS later. I think it's not a good idea in general to bundle things. (But if it's from the same vendor and team anyway they'll probably update their bundled copy after fixing CVEs, too) --Sig_/gosXaIm2.lDApq6UT2z/aR6 Content-Type: application/pgp-signature Content-Description: OpenPGP digital signature -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEds7GsXJ0tGXALbPZ5xo1VCwwuqUFAlybXR4ACgkQ5xo1VCww uqU0IggAkyKGD6tR+rzjacC1Uc8eNB9LM0PMB/byQNK9/auC5Sscq1FlAJzmRgpJ eohfykJrU91UYoJVYtUtpshZdHKKfZnK65lUG7WHt8pzTMCOtNGV4SeVgLpqWqiL TpALTnYVcB1TPbPE9FkafyIA6RqjWlPqsXQyhH6ZW4B9volFxnbBXQbuhf/B58y0 137nNDlWMohUJpF8czlsmQeo+4Lykdo4irvWSFJ60d6DLFzr1ACvhriKd56LeMlc 1/EsTmZysAWKVLr40kjPx+ueUNIrsHtVBkVUqAOIxf6HQmOJ0LTcW74d+oh+axZg yTjF/+Dxr2hHOa2WrcQnMbcu2LmP0w== =Ba8o -----END PGP SIGNATURE----- --Sig_/gosXaIm2.lDApq6UT2z/aR6--