List Info

Thread: no more package.xml 1.0




no more package.xml 1.0
user name
2007-01-30 09:51:36
Hi,

This is the final notice: when I have the time to make the
change,
release-upload.php will no longer allow you to release a
package that
does not have package.xml version 2.0.

You will still be able to release a package that has both
package.xml
and package2.xml.

PEAR 1.3.x has security holes, and we are not going to
encourage people
to use it.

Please inform everyone you know who has not yet upgraded.

Greg

-- 
PEAR Development Mailing List (http://pear.php.net/)
To unsubscribe, visit: http://www.php.net/unsub
.php


Re: no more package.xml 1.0
user name
2007-01-30 10:28:39
Hi,

Before you do that, make sure all dependencies on PEAR exist
in version
available in 1.0 format, in order to avoid bugs like this
one:
  http://pear.
php.net/bugs/bug.php?id=9965

Ideally, PEAR upgrade should handle this case:
 - PEAR depends on Structure_Graph v1.0.3
 - The latest version of Structure_Graph is v1.0.5
 - Structure_Graph v1.0.5 has package.xml version 2.0 and
the currently
installed PEAR does not understand it.
 - Structure_Graph v1.0.3 has package.xml version 1.0 and
could be used to
upgrade PEAR.

However, this may not be possible, because the code that
should handle it is
already deployed.

Cheers,

On 1/30/07, Gregory Beaver <gregchiaraquartet.net>
wrote:
>
> Hi,
>
> This is the final notice: when I have the time to make
the change,
> release-upload.php will no longer allow you to release
a package that
> does not have package.xml version 2.0.
>
> You will still be able to release a package that has
both package.xml
> and package2.xml.
>
> PEAR 1.3.x has security holes, and we are not going to
encourage people
> to use it.
>
> Please inform everyone you know who has not yet
upgraded.
>
> Greg
>
> --
> PEAR Development Mailing List (http://pear.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub
.php
>
>


-- 
Sérgio Carvalho
Re: no more package.xml 1.0
user name
2007-01-30 12:21:32
Greg,


> This is the final notice: when I have the time to make
the change,
> release-upload.php will no longer allow you to release
a package that
> does not have package.xml version 2.0.

I think this is a good step, since there are still too many
packages on 1.0:
http
://pear.cweiske.de/packagestatus/simple.html

-- 
Regards/Mit freundlichen Grüßen
Christian Weiske

Re: no more package.xml 1.0
user name
2007-01-30 13:26:52
Sérgio Carvalho wrote:
> Hi,
> 
> Before you do that, make sure all dependencies on PEAR
exist in version
> available in 1.0 format, in order to avoid bugs like
this one:
>  http://pear.
php.net/bugs/bug.php?id=9965
> 
> Ideally, PEAR upgrade should handle this case:
> - PEAR depends on Structure_Graph v1.0.3
> - The latest version of Structure_Graph is v1.0.5
> - Structure_Graph v1.0.5 has package.xml version 2.0
and the currently
> installed PEAR does not understand it.
> - Structure_Graph v1.0.3 has package.xml version 1.0
and could be used to
> upgrade PEAR.
> 
> However, this may not be possible, because the code
that should handle
> it is
> already deployed.

Sergio,

As I said in my email, this is already (and easily) handled
by having
*both* package.xml 1.0 and 2.0 in the same release.

For PEAR dependencies, package.xml 2.0 is required because
PEAR has
strict dependency requirements, and the <compatible>
tag is only
available in package.xml 2.0.

Greg

-- 
PEAR Development Mailing List (http://pear.php.net/)
To unsubscribe, visit: http://www.php.net/unsub
.php


[1-4]

about | contact  Other archives ( Real Estate discussion Medical topics )