Re: Pear webby
| From: | Stig S. Bakken | Date: | Wed, 20 Feb 2002 14:44:31 +0000 |
| Subject: | Re: Pear webby | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4828@lists.php.net to get a copy of this message | ||
On Wed, 2002-02-20 at 14:48, Tomas V.V.Cox wrote:
> "Stig S. Bakken" wrote:
> >
> > On Tue, 2002-02-19 at 18:58, Martin Jansen wrote:
> > > On Mon, 18 Feb 2002 23:36:27 +0100, Tomas V.V.Cox wrote:
> > >
> > > >Task what I see there are still in the TODO list:
> > > >
> > > >- Delete releases
> > >
> > > The PEAR administrators and the maintainer of the package can now
> > > delete releases via package-edit.php.
> >
> > Let's put up a big huge warning about how bad it would be to remove
> > releases that other packages depend on. Are we using the dependencies
> > table yet? If not we probably should start importing data there on
> > release uploads, to notify people when they are about to delete a
> > release that other releases depend on.
>
> My concerns here are that developers could upload a broken package (or a
> package with a big security flawn) that they will want to inmediatly
> correct before any user download it. Dependencies has to be taken in
> mind yes and AFAIK we haven't yet a release::update_deps().
>
> > In a perfect world, no releases should ever be deleted, just hidden from
> > view.
>
> You know that the world is far from being perfect and IMHO to hide or to
> delete has no practical differences (a broken package should not be
> avaible any where from my point of view). Confirm and huge warning are a
> real need thought.
Of course. But if we list the dependencies that would be broken, at
least the maintainer knows the consequence of removing the release.
- Stig