Comment 9 for bug 413657

Revision history for this message
Martin Pitt (pitti) wrote : Re: [Bug 413657] Re: [needs-packaging] Please sync tor 0.2.1.19-1 (universe) from Debian unstable (main)

Aron Xu [2009-08-24 13:28 -0000]:
> I can maintain it for current stable release

That's the problem -- we need to maintain it in *all* stable
releases. E. g. right now we'd need to keep it up to date in dapper,
hardy, intrepid, and jaunty. Otherwise the users of those releases
would again use the old insecure versions, and we're back to square
one.

> I am using tor and many people around me need it more or less, many
> of them just wish it apt-getable directly rather than installing
> another third-party source by hand.

While that's true, and the point of a distribution, it becomes a weak
point if those old releases stay around forever. If upstream does a
much better job of providing packages for stable releases, it might be
better to refer people there.

I'd like to get the opinion of other MOTUs, too.