Re: unmaintained packages hidden by team maintenance

Simon Josefsson <[email protected]> Sat, 21 Feb 2026 15:45:18 +0100
Newsgroups gmane.linux.debian.devel.project
Message-ID <[email protected]>
Tobias Frost <[email protected]> writes:

> As this thread shows, there are differing interpretations of what "team
> responsibility" entails in practice. This suggests the change is not
> merely a metadata adjustment, but a shift in expectations about
> accountability and recovery.

I think you are right.

> In practice, many packages - even within established teams - are
> effectively driven by one or a few individuals. When responsibility is
> purely collective, inactivity can become less visible, particularly in
> smaller or less structured teams where attempts to contact the team may
> not result in any response.

And even further, I think the shift of expectations is already deployed
for many years:

At least for the Go team, but apparently in some other teams too, the
bulk of work on many packages is driven by the needs of the other
packages, rather then the individual packages.

You only ever package golang-github-foo-bar-dev library because you need
it for some other (usually binary) package.

You only ever upgrade golang-github-foo-bar-dev because a new (or newer
version) of some package needs it.

It seems unlikely that a single person will ever care strongly about
golang-github-foo-bar-dev at all.  Nor is that necessarily desirable.
The golang-* packages are just a vehicle to get something else packaged.

It could be that for some libraries, someone will care deeply about it
(which is great!), but at least for golang-*-dev packages, I think that
is a really small minority.

This reflects in the Uploaders field being pointless for Go team
packages: it is normally merely set to whomever originally uploaded the
package into Debian, and usually not touched again.  I sometimes add
myself to avoid the lintian warnings about missing 'Team upload'
changelog entries, but usually not.

I now realize that the MIA workflow is not particulary aligned with how
the Go team operates, but I don't see any problem here: the go team
tries to take care of all golang-* packages, so there is no problem with
someone just disappearing from the go team.  Which seems to have
happened a couple of times in the past.  I don't think the MIA team need
to worry a lot about golang-* packages for a MIA person.  There is just
nothing to do in that case, except possibly remove someone from
Uploaders (which argues for making it optional).  Golang-* packages will
be updated when there is a need for it, which is how the team pretty
much have appears to have operated for several years, long before I
joined it.

/Simon
signature.asc (application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE-----

iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmmZxP4UHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA
/iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx
+3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6
qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF
PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh
is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFotyHAQCQZ89Igr0X
wRy0mh/tokq44ghnec+zqjcmHjwIo73b5wEAj9gF8QS6C/lAgenFIKj3i0q8Ady4
nCTLCME9/iQQyAI=
=33wH
-----END PGP SIGNATURE-----