From: | Bruce Momjian <bruce(at)momjian(dot)us> |
---|---|
To: | Joe Conway <mail(at)joeconway(dot)com> |
Cc: | Andres Freund <andres(at)anarazel(dot)de>, Robert Haas <robertmhaas(at)gmail(dot)com>, PostgreSQL-development <pgsql-hackers(at)postgresql(dot)org> |
Subject: | Re: Security lessons from liblzma |
Date: | 2024-03-31 01:52:47 |
Message-ID: | ZgjB7-Kvvj4xYluH@momjian.us |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-hackers |
On Sat, Mar 30, 2024 at 07:54:00PM -0400, Joe Conway wrote:
> Virtually every RPM source, including ours, contains out of tree patches
> that get applied on top of the release tarball. At least for the PGDG
> packages, it would be nice to integrate them into our git repo as build
> options or whatever so that the packages could be built without any patches
> applied to it. Add a tarball that is signed and traceable back to the git
> tag, and we would be in a much better place than we are now.
How would someone access the out-of-tree patches? I think Debian
includes the patches in its source tarball.
--
Bruce Momjian <bruce(at)momjian(dot)us> https://momjian.us
EDB https://enterprisedb.com
Only you can decide what is important to you.
From | Date | Subject | |
---|---|---|---|
Next Message | Thomas Munro | 2024-03-31 01:56:06 | Re: pg_combinebackup --copy-file-range |
Previous Message | Thomas Munro | 2024-03-31 01:03:25 | Re: pg_combinebackup --copy-file-range |