Re: Publicly listed channels (was [PEAR-DEV] Considering package proposal:

From: Date: Mon, 11 Apr 2005 15:55:19 +0000
Subject: Re: Publicly listed channels (was [PEAR-DEV] Considering package proposal:
References: 1 2 3 4 5 6  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-37171@lists.php.net to get a copy of this message
Greg Beaver wrote:
Matthew Weier O'Phinney wrote:
It *would* be nice to see an area on PEAR for listing alternate channels and PEAR-based applications/frameworks/what-have-you, particularly if code linked there were reviewed (somewhat) by PEAR developers.
One of the political tasks that PEAR needs to work out as PEAR 1.4.0 reaches maturity is how channels will be added to the official channel
the above does not necessary imply he has a channel setup, nor should it require that someone has a channel setup.
list. I suspect that it would be best if there was a simple form at pear.php.net. Something along these lines:
I would say we should require a PEAR account for this and add pear.channel Karma or something like that. An actual channel could then be maintained in much the same way as a package. It needs a unique name, can have multiple people associated with it etc.
Then, a small panel of pear devs could evaluate initial submissions, weeding out the spam entries we are bound to receive. If a channel is a legitimate PEAR channel, it would simply be added to the list of channels users get when they run the "update-channels" command.
I would say have it run through pepr ... We just have to define what the criterias are for acceptance (+5 ..?)
Requirements for listing a channel at pear.php.net need to be worked out. I would recommend: - channel has a public browsable frontend like pear.php.net - channel has full support for the PEAR installer version 1.4.0 - channel has been around for at least 6 months and has at least 1 package with releases
I think the last one is a bit misleading. What does 6 months tell us? Not much imho. But sure a set of guidelines we can publish, but leave the actual decision to the pear community.
mature channels should be listed at pear.php.net. Obviously, some leeway needs to be there for sites that have established backgrounds like horde and php-tools.net. Clearly, these sites have got stuff worked out, and might not need the 6 month window to prove their maturity :).
Something like that makes sense.
The single most important thing we as PEAR folks can do is to be *non-restrictive* about channels. The only requirement for listing a channel must be that it works and is not distributing malicious code. Let the users decide whether a channel is worth investigating. Most will probably never change their default_channel to anything other pear.php.net/pecl.php.net, and that is just fine. The installer is designed so that you won't be distracted by other channels unless you want to be [1].
+1 Let me elaborate quickly. Anything we put into the installer is on some level endorsed by us. So we should take care about what channels we accept. At the same time we should base this decision not so much on the technical quality, but more on if we except this channel to stick around, if we trust the owners to not publish malicous code etc. We obviously cant gurantee that the owner will not publish malicous code. At the same time the scope of the installer is much broader for the php project at large. So I can see that pecl people might feel that they should have a say here too. We might want to bring this topic up on the pear-core list in a separate thread. regards, Lukas

« previous php.pear.dev (#37171) next »