Re: Re: Publicly listed channels

From: Date: Mon, 11 Apr 2005 22:48:01 +0000
Subject: Re: Re: Publicly listed channels
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-37176@lists.php.net to get a copy of this message
Hi all, Bertrand Mansion wrote:
Tomas V.V.Cox wrote:
Lukas Smith wrote:
Let me elaborate quickly. Anything we put into the installer is on some level endorsed by us. So we should take care about what channels we accept. At the same time we should base this decision not so much on the technical quality, but more on if we except this channel to stick around, if we trust the owners to not publish malicous code etc. We obviously cant gurantee that the owner will not publish malicous code.
I'd let that channels-listing site to a third party guys. We can't confuse people pointing them to channels out of PEAR/PECL where we have no control and no QA. Btw, it shouldn't be our task to review, calibrate or recommend code developed out of here and even worse to track it along the time.
I agree with this.
From the package browsing page: "Note: A number of other PHP projects do provide packages of their software, which are installable via the PEAR infrastructure, or they are planning to do so. Currently we know of Horde and Seagull, who have set up an overview about their PEAR-compatible packages at pear.horde.org resp. seagull.phpkitchen.com. Please inform the webmasters if your project is providing PEAR packages as well." What I am talking about is not much more than this. I want people to know about channels. They have to explicitly choose to install packages from that channel, and explicitly choose to list packages from another channel. This is not confusion. There will not be 1000s of channels the way there are 1000s of YUM repositories. YUM repositories are all distributing the same packages in slightly different configurations. PEAR does not do this at all, and because of the way mirrors are specified in channel.xml, it will never need to force the user to explicitly choose a mirror from some public list. Also, let's be realistic. Are Tomas's fears valid? Off the top of my head, I can only think of about 20 sites that would qualify as major PHP sites. We don't currently review Horde's packages, and they are installable via the pear command, nor do we review Seagull. There is no review, no calibration, and no recommendation in either case. Simply listing public channels that distribute packages that can be installed with the PEAR installer does not imply review or calibration. Also, a decent disclaimer is pretty easy to include. What will listing channels do? - great code that is not in PEAR will consider making that transition to using package.xml and distributing through a channel. - PEAR will be associated with great code. This is the main reason I suggested that channels should be at least 6 months old. I am happy to list every new channel that comes along through my own personal channel, for those who want bleeding edge, but the significant channels must be listed at pear.php.net. I understand that most people are thinking of channels as some kind of modified apt-get, up2date, yum, portage, etc. Stop thinking that way - PEAR's channels are a new thing, there is very little in common with any of these packages because PEAR is about PHP and not about maintaining an operating system. Greg P.S. I doubt PECL folks will care about any of this, to be blunt. They accept just about anything that isn't GPL into PECL, and don't have the problems that PEAR does with people releasing great extensions on their own sites. Also, the volume of new extensions is far lower than new PEAR packages.

« previous php.pear.dev (#37176) next »