25 ms·
> Pinning every Python dependency instead of fetching HEAD is how you get local control and security! yes it is? they make sure the user get a specific version
by lesto 5y ago
> Pinning every Python dependency instead of fetching HEAD is how you get local control and security!
yes it is? they make sure the user get a specific version that is (hopefully) vetted and know as working properly; this is much safer than pulling HEAD for a 3th party repo. As long as the libs are updated regularly and when security issue are found, I see no problem with this approach
> he has the right to transitively make Home Assistant un-packagable on NixOS?
Pretty sure a custom license is not compatible with the Apache 2 license of "Home Assistant"; also as the code is in use by a third party, the author should not be able to retroactively change license, only next releases.
Probably will be forked or removed depending on the specific of the case and of the code.
- ris 5y ago> they make sure the user get a specific version that is (hopefully) vetted and know as working properly This is exactly what nixpkgs maintainers do, using more reliable and explicit tools than the likes of pip. A significant effort is made to enable tests on as many packages as possible, meaning that when you get a package from nixpkgs, it has been tested against the exact dependency chain (down to the libc) it is being shipped to you with. If tests fail, issues are investigated and solved. This is a far stronger guarantee than you get from almost any other installation method.