On 11/12/2016 21:02, Joerg Sonnenberger wrote:
On Sun, Nov 13, 2016 at 09:48:27AM +0700, Robert Elz wrote:Date: Sun, 13 Nov 2016 02:49:45 +0100 From: Joerg Sonnenberger <joerg%bec.de@localhost> Message-ID: <20161113014945.GA6523%britannica.bec.de@localhost> | On Sat, Nov 12, 2016 at 06:18:20PM -0600, John Marino wrote: | > The only thing I could ask the security team is to keep using ranges and not | > regex. | | We do not use regex. I suspect he means glob patterns.Yeah, except that is also wrong. I find it interesting to see a suggestion about replacing core infrastructure without even understanding something as fundamental as the dependency patterns.
Let me clear it for you then. I AM NOT SUGGESTING REPLACING CORE ANYTHING.All I did was continue Khorben's work which was to define a second PKG_FORMAT option. The first is called "pkg" and the new one is called "pkgng".
The vulnerability checks are hopelessly entangled with the first format. That infrastructure remains in place for the "pkg" format. The "pkgng" format has it's own formatting of the same data.
Is it clear now?I can be just as condescending as you can be. Well, if I try really hard, I can give you a run for your money anyway.
--- This email has been checked for viruses by Avast antivirus software. https://www.avast.com/antivirus