Re: GRAB Version 2.4 Released!

Jef Spaleta <[email protected]> 13 Mar 2003 09:22:23 -0500
Newsgroups gmane.linux.redhat.rpm.grab
Message-ID <[email protected]>
--=-+VLKc0Ji04mEnlmgZPJ/
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

On Thu, 2003-03-13 at 04:28, Greg Kurtzer wrote:
> There is really not too much going on in the world of GRAB. Things are lo=
oking
> very stable, almost boringly stable...
>=20
> Maybe it is time for a rewrite, or some new major something or other?! :)=
 Any
> ideas?

Work on a gui interface...though i think that would involve a
significant rewrite.

The ability to interface with apt and/or yum repositories.

The ability to distiguish updates by "vendor" or "packager" so that you
can have multiple mirrors in grab with versions of the same package from
multiple packagers listed...and grab will prefer to pickup updates and
dependancies from that same vendor(via a gpg signature check maybe) that
you currently have the orignal package installed. I like keeping chains
of dependancies from the same vendor.

Along the same lines...tiered server locations..so you can specific the
order in which updates and dependances are looked for.

> Does anyone here care about RedHat's new distribution "End Of Life" polic=
y?
> This means that they may stop releasing updates after 1 year of a distro
> being released. http://www.redhat.com/apps/support/errata/

may? more like will. There is a very interesting post to the beta-list
from a redhat employee...I'd repost it here but I don't think I have
permission. Check out the phoebe-list achive for the thread "Latest UTB
Newsletter". The post of interest is by Brent Fox.=20

And this is just going to mean more users for grab as the community
develops its own ecosystem for provide the support for releases past
EOL.  If you don't know about it already...check out the fedora project,
which seems to be the community answer to what to do in response to
Redhat EOL policy (and to provided addon packages).  The Fedora project
seems to be focused on the issue of how to securely offer community
based packages, and plans to make GPG signing mandatory. Maybe grab
could make itself compatible with what fedora is doing. I for one am
very interested in making GPG signing of 3rd party packages out there
for consumption a mandatory requirement. One signature from the packager
so you can verify the person claiming to have built it...built it. And a
second layer of signatures, from other people certifying they trust the
original author's package.

-jef"trust...but verify"spaleta

--=-+VLKc0Ji04mEnlmgZPJ/
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQA+cJQerWLDmRitRZURAqTIAKCHDaQGzsU+BnNBijL+fBUNlpto0wCfXFxA
ofMKZbNjWogTOiPClFe0XHQ=
=6643
-----END PGP SIGNATURE-----

--=-+VLKc0Ji04mEnlmgZPJ/--