Debian discusses vendoring—again
Debian discusses vendoring—again
Posted Jan 18, 2021 13:10 UTC (Mon) by amck (subscriber, #7270)In reply to: Debian discusses vendoring—again by LtWorf
Parent article: Debian discusses vendoring—again
De-vendoring is a pain, but possible.
Updates to stable for security fixes need to be done on a stable branch, porting just the security fix to the update - not including any other changes relative to existing stable. This is painful but possible.
The versioning naming done makes this possible. e.g. apache2-bin on my stable machine has version "2.4.38-3+deb10u4", the +version part showing the change which falls between stable and testing as required.
The real challenge is (a) bundling (b) overwhelming human resources and the resolution manager in apt.