https://www.puppet.com/community logo
Join Slack
Powered by
# voxpupuli
  • v

    VoxBot

    11/07/2024, 3:32 PM
    i'm not saying we actually have time to do that crap
  • v

    VoxBot

    11/07/2024, 3:32 PM
    ^this
  • v

    VoxBot

    11/07/2024, 3:32 PM
    but that's what perforce is leaving us with
  • v

    VoxBot

    11/07/2024, 3:32 PM
    anarcat: +1
  • v

    VoxBot

    11/07/2024, 3:32 PM
    @David - the question is how quickly/often the main branch of the Perforce internal repo is intended to get mirrored to the public repo?
  • v

    VoxBot

    11/07/2024, 3:32 PM
    unless i profoundly misunderstood the intentions of perforce and the effets of today's announcement
  • v

    VoxBot

    11/07/2024, 3:32 PM
    this is really concerning, and sad
  • v

    VoxBot

    11/07/2024, 3:33 PM
    ^ yup
  • v

    VoxBot

    11/07/2024, 3:33 PM
    if it is daily, then I think this will work out OK. if it is only when a new release is tagged, it will kill the eco-system.
  • v

    VoxBot

    11/07/2024, 3:33 PM
    i will also point out that there is a possibility of current world events are affecting our perception of the announcement, which might have been poorly timed
  • v

    VoxBot

    11/07/2024, 3:34 PM
    for reasons out of topic for this channel, i'm actually fucking scared right now, in general, because of the state of the world (trump, floodings in europe, fires in the americas, war in the middle east and ukraine, general apocalypse)
    🫂 1
  • v

    VoxBot

    11/07/2024, 3:34 PM
    so i'm scared, a priori, and i'm scared of this here as well
  • v

    VoxBot

    11/07/2024, 3:35 PM
    a proper approach would have been to try to be reassuring and say things like "puppet stays open source, and the canonical repo stays open source, and security and patches will land promptly in a public repo"
  • v

    VoxBot

    11/07/2024, 3:35 PM
    but right now, i just get FUD
  • d

    David Sandilands

    11/07/2024, 3:35 PM
    we aren't saying we don't want contributions or to work with open source users,
  • d

    David Sandilands

    11/07/2024, 3:36 PM
    "puppet stays open source, and the canonical repo stays open source, and security and patches will land promptly in a public repo" this is largely the truth although we are not committing to specific slas for security and patches
  • v

    VoxBot

    11/07/2024, 3:36 PM
    again a ten foot wide footnote there
  • v

    VoxBot

    11/07/2024, 3:36 PM
    "largely the truth" is not how open source works
  • v

    VoxBot

    11/07/2024, 3:37 PM
    you need trust from the community
  • v

    VoxBot

    11/07/2024, 3:37 PM
    if i feel that perforce is just going to take my contributions and shove them in a dark hole of closed software, i am not going to bother
  • v

    VoxBot

    11/07/2024, 3:38 PM
    what you seem to be saying is that there is a "canonical" repo, except for "security and patches", where there is a "private" repo that is governed by a different SLA, EULA, and therefore license than free software puppet
  • v

    VoxBot

    11/07/2024, 3:38 PM
    and that you are, effectively, forking puppet
  • v

    VoxBot

    11/07/2024, 3:38 PM
    i'd be really glad if i misunderstood
  • v

    VoxBot

    11/07/2024, 3:39 PM
    but every new comment i hear always has this escape hatch that allows perforce to have a private closed source repo of puppet
  • v

    VoxBot

    11/07/2024, 3:39 PM
    where development actually happens
  • v

    VoxBot

    11/07/2024, 3:39 PM
    but we'll see, i guess
  • v

    VoxBot

    11/07/2024, 3:39 PM
    a good mechanism that could allow you to have a "hardened" and "private" repo would be to have a closed coordination list with distros
  • v

    VoxBot

    11/07/2024, 3:39 PM
    where you could share security issues to ensure coordinated disclosures
  • v

    VoxBot

    11/07/2024, 3:40 PM
    i think "puppet stays open source" needs clarification because I think for puppet this means "licensed with an osi-approved license" but that the "source" will not actually be "open" (hence private repos)
  • v

    VoxBot

    11/07/2024, 3:40 PM
    there are actually mailing lists like this that already exists, for the record
1...620621622...648Latest