Re: unmaintained packages hidden by team maintenance (was Re: Bits from the DPL)

Simon Josefsson <[email protected]> Thu, 05 Feb 2026 18:22:13 +0100
Newsgroups gmane.linux.debian.devel.project
Message-ID <[email protected]>
Colin Watson <[email protected]> writes:

> On Thu, Feb 05, 2026 at 04:14:15PM +0100, Simon Josefsson wrote:
>>But why would that matter?  Presumably if there are serious problems
>>with a team-maintained-but-really-one-person-doing-the-work-package,
>>when that person goes missing, anyone else from the team can step in and
>>fix it?  And if nobody else from the team takes responsibility, it is a
>>team-wide problem that MIA probably cannot resolve.
>>
>>Or are you thinking of finding out which maintainers just stopped
>>working and the packages doesn't have any serious problem, but several
>>versions behind?  In well-working teams, I would think that someone else
>>would just step in and feel at liberty of updating the package at some
>>point.  This approach works well in the Go team, in my perception.
>
> We have a lot of such cases in the Python team.  I think generally
> speaking we function reasonably well as a team, but there's a huge
> pile of stuff to do and only so many hours in the day.  I do quite
> often find that the alleged Uploader is somebody who last touched the
> package in 2016 or something like that.  Updating the package once we
> notice this isn't normally a huge problem, but it does mean that
> things will probably have been lagging behind for some time until
> somebody notices.

Do you (or anyone else) update the Uploaders field?  In what way?

For Go packages I don't bother to update Uploaders: even if I happen to
be the uploader of the last 5 uploads, and my perception is that nobody
else bothers either, so packages rarely change Uploaders:.  I'm not sure
if there is any policy or recommendation on this, and I hope nobody in
the Go team feels strongly that nobody should touch "their" Go team
package.

I don't find this problematic, since I mostly regard
Maintainer/Uploaders fields as a source of problems, but maybe someone
has suggestions what a good process for updating Uploaders: fields for
team packages.

>>Perhaps a tool that finds a top-list of the "worst" version laggers in
>>Debian would improve this?  That is, sort the set of packages which has
>>been behind upstream's latest release for the longest time.
>
> I wouldn't be 100% confident that something like this doesn't exist
> somewhere - sufficiently clever filters in UDD, say - but if it does
> then I've missed it and I would find it helpful.

I wonder if UDD stores upstream release events, which is necessary to
generate a "correct" list.  Maybe a list of the oldest packages in
Debian that has a new upstream release is a useful enough list to start
with.

/Simon
signature.asc (application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE-----

iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmmE0cUUHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA
/iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx
+3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6
qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF
PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh
is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFoiUGAQCpjjHGHHUB
Dx+D2rmPdJFWdnUqq98ArB/xdW4VCLr6zQEAs1OkHkRaDYZ5x48vUhO4yv8wUiDk
ltVX7EYXHks7tQ0=
=SXow
-----END PGP SIGNATURE-----