package update politics

Other talk about Salix
User avatar
witek
Posts: 233
Joined: 16. Nov 2009, 13:41
Location: Poland.Łódź

package update politics

Post by witek »

I`m wondering why the Salix developers keep updating firefox in the repo with its every new release? It seems most often updated package in Salix. Why firefox is so important and others ie. openoffice or claws-mail not?
User avatar
gapan
Salix Wizard
Posts: 6354
Joined: 6. Jun 2009, 17:40

Re: package update politics

Post by gapan »

Maybe because it's a major security hole?
Image
Image
Shador
Posts: 1295
Joined: 11. Jun 2009, 14:04
Location: Bavaria

Re: package update politics

Post by Shador »

I'm not maintaining firefox or thunderbird, but it's the only way afaik to get a secure browser/mail client. Mozilla started to do much faster releases necessarily, but most of them are not maintained for a longer period of time. But I guess firefox 10 is going to be a keeper as this is an ESR release, which means it's supported longer.
https://wiki.mozilla.org/Enterprise/Fir ... t:Proposal

Gapan, was faster. As he's maintaining those packages, I was right with the assumption, that there are security holes.
Image
User avatar
ElderDryas
Posts: 144
Joined: 3. Nov 2011, 22:06
Location: Lincoln, Nebraska USA

Re: package update politics

Post by ElderDryas »

As long as the subject has been brought up....

Is the security problem/hole specific to FF or with web browsers in general? I ask this because I've noticed that FF and Opera are at current versions while Midori and Chromium are not.
User avatar
gapan
Salix Wizard
Posts: 6354
Joined: 6. Jun 2009, 17:40

Re: package update politics

Post by gapan »

ElderDryas wrote:Is the security problem/hole specific to FF or with web browsers in general? I ask this because I've noticed that FF and Opera are at current versions while Midori and Chromium are not.
It mostly has to do with browser engines, not exactly browsers. FF and opera include their own engines so they have to be updated anyway, but midori uses webkit. Security holes specifically in midori are extremely rare and AFAIK there is none since version 0.3.3 which we currently have. And I don't know where you got chromium from, but it wasn't from salix, because we don't have it, at all.
Image
Image
User avatar
witek
Posts: 233
Joined: 16. Nov 2009, 13:41
Location: Poland.Łódź

Re: package update politics

Post by witek »

gapan wrote:Maybe because it's a major security hole?
If so then maybe it would be simpler to replace firefox with something else?
User avatar
ElderDryas
Posts: 144
Joined: 3. Nov 2011, 22:06
Location: Lincoln, Nebraska USA

Re: package update politics

Post by ElderDryas »

Thanks for the explanation.

Chromium (15.XXXXX) appears in Sourcery (at least on my box :)
User avatar
gapan
Salix Wizard
Posts: 6354
Joined: 6. Jun 2009, 17:40

Re: package update politics

Post by gapan »

witek wrote:If so then maybe it would be simpler to replace firefox with something else?
What else? I'm hoping that one day we'll be able to replace it with midori, but most people still want/need the features that firefox has.
ElderDryas wrote:Chromium (15.XXXXX) appears in Sourcery (at least on my box :)
Just because it's in sourcery doesn't mean it has anything to do with salix specifically. Salix doesn't offer any prebuilt packages. This one is from slackbuilds.org (as most things that appear in sourcery).
Image
Image
User avatar
ElderDryas
Posts: 144
Joined: 3. Nov 2011, 22:06
Location: Lincoln, Nebraska USA

Re: package update politics

Post by ElderDryas »

gapan wrote:I'm hoping that one day we'll be able to replace it with midori, but most people still want/need the features that firefox has.
The most recent version of Midori has the only FF features that I really want...an ad blocker and the ability to override the site fonts.
gapan wrote:Just because it's in sourcery doesn't mean it has anything to do with salix specifically. Salix doesn't offer any prebuilt packages. This one is from slackbuilds.org (as most things that appear in sourcery).
Again, thanks for the explanation. Just so I'm sure I understand things: 1) If it's in gslapt, it's Salix's; 2) If it's in Sourcery, it's not (i.e., go yell at some else :)
User avatar
gapan
Salix Wizard
Posts: 6354
Joined: 6. Jun 2009, 17:40

Re: package update politics

Post by gapan »

ElderDryas wrote:1) If it's in gslapt, it's Salix's;
No. It could be slackware or salix. Almost half packages are by slackware, the other half by salix. If the full package name ends with a number (like util-linux-2.19-x86_64-1), it's slackware's, if it ends with a number+initials, it's salix's (like terminus-font-4.30-noarch-1tm).
ElderDryas wrote:2) If it's in Sourcery, it's not (i.e., go yell at some else :)
Not exactly. It could be slackbuilds.org and it could be salix. But the vast majority are from slackbuilds.org. Something like 3000:50. You can check the source by right clicking/Get info.
Image
Image
Post Reply