3 ms·
Sure they may have to fiddle with the dependency tree, but Node & Go both have well defined dependency formats (go.mod, package.json). It should be relatively e
by initplus 6y ago
Sure they may have to fiddle with the dependency tree, but Node & Go both have well defined dependency formats (go.mod, package.json). It should be relatively easy to record the go.mod/package.json when these applications are built, and issue mass dependency bump & rebuilds if some security issue comes up.
Really seems like the best of both worlds, and less work than trying to wrangle the entire set of node/go deps & a selection of versions into the Debian repos. I mean Debian apparently has ~160,000 packages, while npm alone has over 1,000,000!
- erik_seaberg 6y ago> mass dependency bump That’s not an option for Debian stable. They intentionally backport security and stability patches, and avoid other changes that might break prod without a really good reason. https://www.debian.org/doc/manuals/debian-faq/choosing.en.html#s3.1 https://www.debian.org/doc/manuals/debian-faq/choosing.en.ht...
- initplus 6y agoThe situation with backporting security fixes is still the same. Debian could backport the fix to any node/go lib the same way they backport security fixes to C libs. The only difference is that a backported fix in a language that uses vendored dependencies rather than .so's needs to have all depending packages rebuilt.
- debiandev 6y agoDebian Developer here. Backporting fixes to tenths of thousands of packages is already a huge amount of (thankless) work. But it's still done - as long as there's usually one version of a given library in the whole archive. Imagine doing that for e.g. 5 versions of a given library, embedded in the sources of 30 different packages.
- hackmiester 6y agoI'm sorry to hear that it's thankless. Thank you for doing it. It is one of the pillars of my sanity, and I am not exaggerating.