Re: Evolving away from source package realms

2022-10-19 Thread Bastian Blank
On Tue, Oct 18, 2022 at 07:25:39AM -0700, Russ Allbery wrote: > This is probably my security brain from my day job, but I would prefer to > be able to drop permissions that I'm not currently using, as long as I can > get them back easily. It reduces the blast radius of mistakes and > compromises.

Re: Evolving away from source package realms

2022-10-19 Thread Timo Röhling
Hi, * Johannes Schauer Marin Rodrigues [2022-10-12 10:49]: If I understand what you write correctly, then you propose to put into place a technical barrier for uploading other people's packages. But that will not reduce the ownership (or hegemony) of developers over their packages and thus not

Re: Evolving away from source package realms

2022-10-19 Thread Thomas Goirand
On 10/18/22 16:25, Russ Allbery wrote: I think there's some merit for being able to restrict and expand your own permissions As much as I understand, *self-controlling* your own rights is not the original proposal. Cheers, Thomas Goirand (zigo)