On 2024-08-08 22:04, Marc Chamberlin via openSUSE Users wrote:

Hmm Why couldn't the hardware project just leave the hardware repository "as is" at EOL so that us slow to upgrade folks could continue to use and retrieve software from it? According to github hw-probe was in the OpenSuSE 15.4 hardware repository - 

https://github.com/linuxhw/hw-probe/blob/master/INSTALL.md#install-on-opensuse

It seems harsh to actually dump the ability to use a repository just because the associated version of OpenSuSE went to EOL. In this day and age, I can't believe disk storage space is a problem! So what gives? Why break something that was working? Seems like this is a poor policy decision. The repository should just be frozen, no further updates or fixes added, but let it continue to work and be available.


Ah actually found it: https://build.opensuse.org/request/show/1176822 So looks like I pushed for it to be deleted, as it should be. 

Obviously not speaking for the hardware project but: Using EOL software is irresponsible and a general security concern: CWE-1104, CWE-1395, OWASP A06:2012. A lack of forwarded-looking upgrade planning for long predictable dates does not mean that it will be there forever. Nothing broke because it never worked: The risk was taken when a dependency outside of the user's control was taken.

Additionally maintaining old things would cause significant load on the finite OBS resource. Your idea of archiving is acknowledged, if it is needed it may exist. It does not right now, indicating that this is a fringe request for which there is a better option: Plan to upgrade in time and execute. For myself I am happy with the archived distro itself, which is why I put things I need into the distro.

From https://en.opensuse.org/Lifetime, which I believe I wrote when I was involved in the openSUSE Maintenance team:

Discontinued distributions

Users running a (soon-to-be) discontinued version of openSUSE should upgrade their systems to a supported release to receive security updates and community support. Since eventually package repositories for discontinued releases are removed from download servers as well as the build target list of the Build Service, it will be increasingly difficult to install new software on such distributions.

cya,

Andreas