[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: security-patches package
From: |
Ted Zlatanov |
Subject: |
Re: security-patches package |
Date: |
Fri, 22 Sep 2017 08:59:06 -0400 |
User-agent: |
Gnus/5.13 (Gnus v5.13) Emacs/26.0.50 (gnu/linux) |
On Thu, 21 Sep 2017 21:01:56 +0100 address@hidden (Phillip Lord) wrote:
PL> Ted Zlatanov <address@hidden> writes:
>> * how do we prevent accidental or malicious commits to this package?
>> Could it maybe live in a special "GNU ELPA security updates" archive
>> separate from elpa.git?
PL> I think this is not important. It wouldn't have any special privilege;
PL> i.e. the malicious user could do the same nasty things in any package.
PL> Accidental commits could just be controlled by constraining the
PL> *release* -- that is commits would be normal, but they wouldn't go live.
The proposition is to check these packages more frequently and for the
user to trust them more than any other packages, so I think there is
some value to that. But I'm OK with just using the GNU ELPA as long as
the packages are tagged in a special way.
>> * Can we do push notifications somehow or are we limited to polling?
PL> Polling. Worse polling at the users request, because ELPA doesn't also
PL> update.
PL> Changing ELPA to auto-update the archive would be a good thing to do, I
PL> think.
On Thu, 21 Sep 2017 23:12:47 -0400 Stefan Monnier <address@hidden> wrote:
SM> I'm firmly opposed to making any program initiate network connections
SM> without explicit user request.
I understand the concern.
Let's say the user can turn auto checking on, but normally it will just
be a prominent menu item or button they can click to check for an update?
Ted
- Re: [ANNOUNCE] Emacs 25.3 released, (continued)
- Re: [ANNOUNCE] Emacs 25.3 released, Eli Zaretskii, 2017/09/12
- Re: [ANNOUNCE] Emacs 25.3 released, Phillip Lord, 2017/09/12
- Re: [ANNOUNCE] Emacs 25.3 released, Stefan Monnier, 2017/09/12
- security-patches package (was: [ANNOUNCE] Emacs 25.3 released), Ted Zlatanov, 2017/09/14
- Re: security-patches package, Stefan Monnier, 2017/09/15
- Re: security-patches package, Ted Zlatanov, 2017/09/16
- Re: security-patches package, Phillip Lord, 2017/09/21
- Re: security-patches package, Stefan Monnier, 2017/09/21
- Message not available
- Re: security-patches package, Phillip Lord, 2017/09/25
- Re: security-patches package,
Ted Zlatanov <=
- Re: security-patches package, Stephen Leake, 2017/09/23
Hotfixing older Emacsen? Was: [ANNOUNCE] Emacs 25.3 released, Clément Pit-Claudel, 2017/09/12
Re: [ANNOUNCE] Emacs 25.3 released, Charles A. Roelli, 2017/09/13