1 |
On 5/28/06, Bo Ørsted Andresen <bo.andresen@××××.dk> wrote: |
2 |
> this security measure. In this case the tar file changed without changing the |
3 |
> name after you originally installed the package (or after it was downloaded |
4 |
> to the mirror that you are using...). This change could be a bugfix. By |
5 |
> making your own digest you don't get this bugfix... |
6 |
|
7 |
I just have to say that if upstream authors include a bug-fix without |
8 |
releasing a new version (and a differently named tarball), they need a |
9 |
good clubbing. |
10 |
|
11 |
I can see a reason to release the same version of software with a |
12 |
documentation update (readme, authors, known issues, faq, etc), which |
13 |
would cause a different tarball with the same name. |
14 |
|
15 |
But if any of the sources change, I feel that should *always* be a new version. |
16 |
|
17 |
-Richard |
18 |
|
19 |
-- |
20 |
gentoo-user@g.o mailing list |