Subject: uploads policy [Was: Re: pkg_add mozilla ...?]
To: Steven M. Bellovin <smb@research.att.com>
From: Xavier de Labouret <Xavier.de_Labouret@cvf.fr>
List: port-i386
Date: 08/30/2002 13:44:04
> > [openoffice] It's in pkgsrc. The binary may not be there for the same
> > reason as
> >mozilla.
> 
> And of course, right now the pkgsrc version of Mozilla has a security
> advisory on it...

Thank you for these precisions. I just have to add that i found how to
update a binary with pkg_add: pkg_add -u <package>. I sould just have
read the pkg_add man page more in depth. For my defense i should say that
this important option is not put in evidence as much as needed in the man
page :}

I suppose this may have been discussed elsewhere, but i do not really see
the point in removing the binaries from the FTP archive for security
reasons. Practically, the package remains installable, for you just have
to download the source and compile it. It just makes it less immediate
(particularly for openoffice) and practical.

But maybe the reason is different? Ideally, is there an official or
technical document on the policy of binaries uploads/removals on the
server? I am coming from the Debian world, where the process seems
slightly more clear to me for now.

Thanks,

Xavier de Labouret