Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 30 Mar 2024 17:00:08 +0100
From:      =?UTF-8?Q?Fernando_Apestegu=C3=ADa?= <fernando.apesteguia@gmail.com>
To:        Daniel Engberg <daniel.engberg.lists@pyret.net>
Cc:        Gleb Popov <arrowd@freebsd.org>, Alexey Dokuchaev <danfe@freebsd.org>,  "ports-committers@FreeBSD.org" <ports-committers@freebsd.org>, dev-commits-ports-all@freebsd.org,  dev-commits-ports-main@freebsd.org
Subject:   Re: git: 020281bef16d - main - archivers/fastjar: remove undue deprecation of maintained port
Message-ID:  <CAGwOe2azznY5jtMdL4uuupMi3SgCd5Pj7O7wWT7qtcV_zDNUNA@mail.gmail.com>
In-Reply-To: <03cc3443b1bbb8ec3ff881e73483b2cb@mail.infomaniak.com>
References:  <202403300538.42U5c9Fc039162@gitrepo.freebsd.org> <CALH631ns%2Bwp5gmR8c0mahc5JOVDJ2KRPgqmkbxbwhbjNKR5LYQ@mail.gmail.com> <03cc3443b1bbb8ec3ff881e73483b2cb@mail.infomaniak.com>

next in thread | previous in thread | raw e-mail | index | archive | help
--0000000000007596de0614e2daa9
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

El s=C3=A1b, 30 mar 2024, 14:21, Daniel Engberg <daniel.engberg.lists@pyret=
.net>
escribi=C3=B3:

> On 2024-03-30T09:06:51.000+01:00, Gleb Popov <arrowd@freebsd.org> wrote:
> >  On Sat, Mar 30, 2024 at 8:38=E2=80=AFAM Alexey Dokuchaev <danfe@freebs=
d.org>
> wrote:
> >
> > >
> > >  The branch main has been updated by danfe:
> > >
> > >  URL:
> https://cgit.FreeBSD.org/ports/commit/?id=3D020281bef16d866a64bac35850f21=
ae27f956b5c
> > >
> > >  commit 020281bef16d866a64bac35850f21ae27f956b5c
> > >  Author:     Alexey Dokuchaev <danfe@FreeBSD.org>
> > >  AuthorDate: 2024-03-30 05:36:18 +0000
> > >  Commit:     Alexey Dokuchaev <danfe@FreeBSD.org>
> > >  CommitDate: 2024-03-30 05:36:18 +0000
> > >
> > >      archivers/fastjar: remove undue deprecation of maintained port
> >
> > It is my personal opinion, but I think that one should assume
> > maintainership when undeprecating a port (especially maintained by a
> group)
>
> I also found an old CVE which I don't know if it's fixed or not.
> https://www.opencve.io/cve/CVE-2006-3619


If you don't know, then it is not an argument to keep the port deprecated.
If you are, then it might be. Even in that case, as per the handbook, ports
with security issues are marked as FORBIDDEN, not DEPRECATED:

https://docs.freebsd.org/en/books/porters-handbook/book/#security-fix



>
> There's also a fork here from what I can tell:
> http://download.savannah.nongnu.org/releases/fastjar/
>
> I don't know if it's worth keeping for less than a sec of processing and
> newer version of openjdk might have improved performance too (openjdk8 is
> pretty old).
>

*might*? I think arguments for or against deprecating should not be guesses=
.

Don't get me wrong, I'm all for keeping the ports tree clean, but these "a
posteriori" (non) arguments sound a bit weak :-)


> Best regards,
> Daniel
>

--0000000000007596de0614e2daa9
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto"><div><br><br><div class=3D"gmail_quote"><div dir=3D"ltr" =
class=3D"gmail_attr">El s=C3=A1b, 30 mar 2024, 14:21, Daniel Engberg &lt;<a=
 href=3D"mailto:daniel.engberg.lists@pyret.net" target=3D"_blank" rel=3D"no=
referrer">daniel.engberg.lists@pyret.net</a>&gt; escribi=C3=B3:<br></div><b=
lockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px =
#ccc solid;padding-left:1ex">On 2024-03-30T09:06:51.000+01:00, Gleb Popov &=
lt;<a href=3D"mailto:arrowd@freebsd.org" rel=3D"noreferrer noreferrer" targ=
et=3D"_blank">arrowd@freebsd.org</a>&gt; wrote:<br>
&gt;=C2=A0 On Sat, Mar 30, 2024 at 8:38=E2=80=AFAM Alexey Dokuchaev &lt;<a =
href=3D"mailto:danfe@freebsd.org" rel=3D"noreferrer noreferrer" target=3D"_=
blank">danfe@freebsd.org</a>&gt; wrote:<br>
&gt; <br>
&gt; &gt;=C2=A0 =C2=A0<br>
&gt; &gt;=C2=A0 The branch main has been updated by danfe:<br>
&gt; &gt; <br>
&gt; &gt;=C2=A0 URL: <a href=3D"https://cgit.FreeBSD.org/ports/commit/?id=
=3D020281bef16d866a64bac35850f21ae27f956b5c" rel=3D"noreferrer noreferrer n=
oreferrer" target=3D"_blank">https://cgit.FreeBSD.org/ports/commit/?id=3D02=
0281bef16d866a64bac35850f21ae27f956b5c</a><br>
&gt; &gt; <br>
&gt; &gt;=C2=A0 commit 020281bef16d866a64bac35850f21ae27f956b5c<br>
&gt; &gt;=C2=A0 Author:=C2=A0 =C2=A0 =C2=A0Alexey Dokuchaev &lt;danfe@FreeB=
SD.org&gt;<br>
&gt; &gt;=C2=A0 AuthorDate: 2024-03-30 05:36:18 +0000<br>
&gt; &gt;=C2=A0 Commit:=C2=A0 =C2=A0 =C2=A0Alexey Dokuchaev &lt;danfe@FreeB=
SD.org&gt;<br>
&gt; &gt;=C2=A0 CommitDate: 2024-03-30 05:36:18 +0000<br>
&gt; &gt; <br>
&gt; &gt;=C2=A0 =C2=A0 =C2=A0 archivers/fastjar: remove undue deprecation o=
f maintained port<br>
&gt;=C2=A0 <br>
&gt; It is my personal opinion, but I think that one should assume<br>
&gt; maintainership when undeprecating a port (especially maintained by a<b=
r>
group)<br>
<br>
I also found an old CVE which I don&#39;t know if it&#39;s fixed or not. <b=
r>
<a href=3D"https://www.opencve.io/cve/CVE-2006-3619" rel=3D"noreferrer nore=
ferrer noreferrer" target=3D"_blank">https://www.opencve.io/cve/CVE-2006-36=
19</a></blockquote></div></div><div dir=3D"auto"><br></div><div dir=3D"auto=
">If you don&#39;t know, then it is not an argument to keep the port deprec=
ated. If you are, then it might be. Even in that case, as per the handbook,=
 ports with security issues are marked as FORBIDDEN, not DEPRECATED:</div><=
div dir=3D"auto"><br></div><div dir=3D"auto"><a href=3D"https://docs.freebs=
d.org/en/books/porters-handbook/book/#security-fix">https://docs.freebsd.or=
g/en/books/porters-handbook/book/#security-fix</a></div><div dir=3D"auto"><=
br></div><div dir=3D"auto"><br></div><div dir=3D"auto"><div class=3D"gmail_=
quote"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-=
left:1px #ccc solid;padding-left:1ex"><br>
<br>
There&#39;s also a fork here from what I can tell: <a href=3D"http://downlo=
ad.savannah.nongnu.org/releases/fastjar/" rel=3D"noreferrer noreferrer nore=
ferrer" target=3D"_blank">http://download.savannah.nongnu.org/releases/fast=
jar/</a><br>
<br>
I don&#39;t know if it&#39;s worth keeping for less than a sec of processin=
g and newer version of openjdk might have improved performance too (openjdk=
8 is pretty old).<br></blockquote></div></div><div dir=3D"auto"><br></div><=
div dir=3D"auto">*might*? I think arguments for or against deprecating shou=
ld not be guesses.</div><div dir=3D"auto"><br></div><div dir=3D"auto">Don&#=
39;t get me wrong, I&#39;m all for keeping the ports tree clean, but these =
&quot;a posteriori&quot; (non) arguments sound a bit weak :-)</div><div dir=
=3D"auto"><br></div><div dir=3D"auto"><div class=3D"gmail_quote"><blockquot=
e class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc sol=
id;padding-left:1ex">
<br>
Best regards,<br>
Daniel<br>
</blockquote></div></div></div>

--0000000000007596de0614e2daa9--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAGwOe2azznY5jtMdL4uuupMi3SgCd5Pj7O7wWT7qtcV_zDNUNA>