1 |
On 01/21/2016 06:15 PM, Alexis Ballier wrote: |
2 |
> On Thu, 21 Jan 2016 10:53:58 -0600 |
3 |
> William Hubbs <williamh@g.o> wrote: |
4 |
> |
5 |
>> I would like to see a possible timelimit set on how long packages can |
6 |
>> stay in maintainer-needed; once a package goes there, if we can't find |
7 |
>> someone to maintain it, we should consider booting it after that time |
8 |
>> limit passes. |
9 |
> |
10 |
> Note that maintainer-needed doesn't necessarily mean package is crap. |
11 |
> Some simply don't really need a maintainer because they just work. |
12 |
> |
13 |
> |
14 |
|
15 |
However it can cause complications when issues are detected, in |
16 |
particular security relevant ones. Attaching a CSV of bugs assigned to |
17 |
security with maintainer-needed CCed. |
18 |
|
19 |
e.g app-text/htmltidy has multiple reverse dependecies but is itself |
20 |
maintainer needed with at least two vulnerabilities (bug 561452) |
21 |
|
22 |
-- |
23 |
Kristian Fiskerstrand |
24 |
Public PGP key 0xE3EDFAE3 at hkp://pool.sks-keyservers.net |
25 |
fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3 |