From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp2 ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms11 with LMTPS id 2hJlNtUeWmCiGQAA0tVLHw (envelope-from ) for ; Tue, 23 Mar 2021 17:01:09 +0000 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp2 with LMTPS id 0AK6MdUeWmCZWQAAB5/wlQ (envelope-from ) for ; Tue, 23 Mar 2021 17:01:09 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 63C9989BB for ; Tue, 23 Mar 2021 18:01:09 +0100 (CET) Received: from localhost ([::1]:44480 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lOkOw-0001Co-OP for larch@yhetil.org; Tue, 23 Mar 2021 13:01:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:47804) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lOjnq-0007aU-4R for guix-devel@gnu.org; Tue, 23 Mar 2021 12:22:46 -0400 Received: from mx1.dismail.de ([78.46.223.134]:24632) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lOjnn-0003M3-R4 for guix-devel@gnu.org; Tue, 23 Mar 2021 12:22:45 -0400 Received: from mx1.dismail.de (localhost [127.0.0.1]) by mx1.dismail.de (OpenSMTPD) with ESMTP id 0f24d50a; Tue, 23 Mar 2021 17:22:38 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=dismail.de; h=from:to:cc :subject:references:date:in-reply-to:message-id:mime-version :content-type; s=20190914; bh=9ne0J6oBHBrVR+G3TBwEdnJ8s8blFWa+MB IDek9JWmk=; b=VzCb6S2q7QVBjDzQElc2qfnqRxMc2WQ3pD25PYbD8Z3EwM8W4H j9SpHT2UJNpsUxys3VGdSS2Uh/Bny7gOX/rUsYWLf0pWYuNUjDv08vgqGLRg4flw v4l2h4gcJn6rU/Jp+9cbll0hylItrMbhhymUSR+sVLoSXHH6R7hNHvzYspnpXB5S SBuYjlPixJUOvcHQjOn6ndE3zKwbMhCaLaeNaF5nBqk6eNNJkjm+UlS6Jz1vx8AK ujkhWsQNiM+RUqHcH3FrLAWbMO/65RYCRLHjX0kGrNhCh6KSITOKBCWgnn4t9FHJ sP6DmY5hnq4DSuLw6r3bbsvEn29c4qfs8jUA== Received: from smtp1.dismail.de ( [10.240.26.11]) by mx1.dismail.de (OpenSMTPD) with ESMTP id 5e93bb81; Tue, 23 Mar 2021 17:22:37 +0100 (CET) Received: from smtp1.dismail.de (localhost [127.0.0.1]) by smtp1.dismail.de (OpenSMTPD) with ESMTP id df6dfdb6; Tue, 23 Mar 2021 17:22:37 +0100 (CET) Received: by dismail.de (OpenSMTPD) with ESMTPSA id 1ce0763f (TLSv1.3:AEAD-AES256-GCM-SHA384:256:NO); Tue, 23 Mar 2021 17:22:37 +0100 (CET) From: Joshua Branson To: raingloom Cc: guix-devel@gnu.org Subject: Re: [opinion] CVE-patching is not sufficient for package security patching References: <9b9a43a584e2dc70488482fce5931b46abd0e006.camel@zaclys.net> <87v99qit39.fsf@netris.org> <877dm29iog.fsf@gnu.org> <20210322144404.1636b9cf@riseup.net> Mail-Followup-To: raingloom , guix-devel@gnu.org Date: Tue, 23 Mar 2021 12:22:24 -0400 In-Reply-To: <20210322144404.1636b9cf@riseup.net> (raingloom@riseup.net's message of "Mon, 22 Mar 2021 14:44:04 +0100") Message-ID: <87tup1lu0v.fsf@dismail.de> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.1 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain Received-SPF: pass client-ip=78.46.223.134; envelope-from=jbranso@dismail.de; helo=mx1.dismail.de X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: guix-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+larch=yhetil.org@gnu.org Sender: "Guix-devel" X-Migadu-Flow: FLOW_IN ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1616518869; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:in-reply-to:in-reply-to: references:references:list-id:list-help:list-unsubscribe: list-subscribe:list-post:dkim-signature; bh=rdNgLNgmDJONU/qeyf80KWGLH1W1sta54t3/BuXjpuA=; b=YrhYXxaRWw/5y+9SMgGpv7q57vGZwsW1sk6fmPmlQEHdblMoh+o25MWwguXT0QVRNFtmSi 2SF095LmYTsRuzR6KYoyIA2ZEI3FKkCUEx4BOgA/mVfghHI7QjBLQEPLnb0sNh3iFf5R/C xOHDTvWtoGsvT9lMMjzh215aZBjusk9xoEV/E0Oom0EPvO/YNv+be74kZGj7kXE+3+zhrV YcyWA8OOcn5AgYXEeCmobnv+URY2Ru7HEI+2zUOtpB4/mUqj5WuNE1ELZ7UdzEPDxF6pDC IZLvu4nddgL/kjYpuE7oGT2cESblOljIVgJw0WJ5ZXzWSCLHvbl7nn4saLPtPQ== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1616518869; a=rsa-sha256; cv=none; b=Lsqr1EX1ajTQyRA2sOnitbPo49GYVheotIYOpap6FOC2W+PeE0+ldm/9ZY4YGAZbqSGCF7 esSOp/cLAWXPDnRk4aiW9y49y78jbGQedCjKYujE9AAKSDntDmtFwNItl5OAwbXQOEMd9J nYFfnSLm/S4Hha5RWA40Z/YmzpKEarn348YLG0NbHGDxyo+K5hxvBnX7BWhQKzwWOb1a6k Uen/5KYzGHD0ELfLiwY1RL4ZKOwJcRSh9L7/L1wC5u0UTeGhwK9rpSDuvVvXb2HzvGVLmK DbTmbRFMCIQhN5RaexUKrPrQw8+ZFjoqVcXYlXmFwin/catj2P/8stt2mQOCnA== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=pass header.d=dismail.de header.s=20190914 header.b=VzCb6S2q; dmarc=pass (policy=reject) header.from=dismail.de; spf=pass (aspmx1.migadu.com: domain of guix-devel-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-devel-bounces@gnu.org X-Migadu-Spam-Score: -3.68 Authentication-Results: aspmx1.migadu.com; dkim=pass header.d=dismail.de header.s=20190914 header.b=VzCb6S2q; dmarc=pass (policy=reject) header.from=dismail.de; spf=pass (aspmx1.migadu.com: domain of guix-devel-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-devel-bounces@gnu.org X-Migadu-Queue-Id: 63C9989BB X-Spam-Score: -3.68 X-Migadu-Scanner: scn0.migadu.com X-TUID: m/yUQXR+VFYr raingloom writes: > > What about a Liberapay for Guix? Could also be used to pay developers. > I'd be game for something like this. We could have a guix membership. Drew Devault has a "secret irc" channel for paying patreons. Perhaps we could advertise a guix membership on the guix site. When someone signs up, it actually makes them an FSF member. I believe membership with the FSF includes perks such as: 5 email aliases, a federated XMPP account, and some other things... -- Joshua Branson (joshuaBPMan in #guix) Sent from Emacs and Gnus https://gnucode.me https://video.hardlimit.com/accounts/joshua_branson/video-channels https://propernaming.org "You can have whatever you want, as long as you help enough other people get what they want." - Zig Ziglar