On Wednesday 22 of April 2009 13:49:10 Lars Vogdt wrote:
On Dienstag 21 April 2009 14:52:48 Petr Uzel wrote:
By de-digesting the FreshMeat [fm] digest, I have found the (apparently) new version 1.1 of your package nmzmail. (Old version last notified/in tree was 1.0).
Done ;)
Reading this, two things "pop up" in my mind: 1) Contrib != frozen? Have I missed any new guidelines about packages in contrib are frozen after a release?
Afaik Contrib was not released. But situation is little bit unclear, because updates in frozen Contrib should be allowed too (and some peoples want to have Contrib as rolling updates repository like Packman).
2) Security in mind...? Who controls changes in packages after the first review?
Maintainers of packages and Contrib.
As example (sorry Sascha - this is not against you - I took the first package I find):
https://build.opensuse.org/package/show?package=rkhunter&project=openSUSE:F actory:Contrib
Maintainer: saigkill
saigkill is maintainer of the openSUSE:Factory:Contrib project and respectively (as far as I know) all of his packages/submissions should be reviewed. But as long as saigkill is added as maintainer for his package, he can do everything with it directly in openSUSE:Factory:Contrib once it is accepted.
Is this really intended?
Yes, this is current approach - changes of packages in Contrib are done by maintainers of those packages without explicit review. It's the same behavior as everyone project in openSUSE BuildService has. This was discussed several times (for example I prefer reviews for Contrib), but this is a current consensus.
With kind regards, Lars
Regards Michal Vyskocil -- To unsubscribe, e-mail: opensuse-contrib+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-contrib+help@opensuse.org