There was a talk about this.
I'll copy/paste:
By Allen Brooker:
---------
As far as I can tell, qmail is now unmaintained by djb and the website
doesn't appear to have been updated recently (at a guess, atleast in the
past couple of years). On top of this, qmail's license unfortunately
means that no one can take over qmail or fork it any way (would a "fully
featured" fork that some admins seem to want be such a bad thing?)
While there's nothing inherently wrong with applying patches to a base
code set, applying patches, especially patches on top of already patched
code, surely introduces an inherent risk of introducing bugs and other
flaws that might be avoided if the patches were being submitted to a
central code base which evaluated each patch before applying it to a
central code base?
While djb's security guarantee looks good, how can I know that if there
is a vulnerabiltiy found, that it will be patched in a timely manner and
in a way that won't compromise the security or stability of qmail
further? How can I know that vulnerabilities haven't already been found
and just been ignored / lost because djb has no time to maintain qmail?
----------
There's a lot of the same patches (not compatible), broken links.. etc.
Central qmail patch web site would be a good thing, imho, again.
If we do something like ./do --with-ldap --with-helochecks etc. which generates
(from patches suplied on repository) one big patch that will without errors
patch qmail source, that will be a pretty damn good thing. But as Jeremy
Kitchen said, we'll discuss that later.
Kind Regarrds,
Sasa
On Tue, 27 Feb 2007 19:30:44 -0500
Jeremy Kister <qmail-05@jeremykister.com> wrote:
> On 2/27/2007 6:45 PM, Amitai Schlair wrote:
> > Does anyone agree, disagree, want to pitch in?
>
> I don't see the benefit of taking people away from qmail.org and
> qmailwiki.org.
>
> Either site can and does list patches from a plethora of hosts,
> including freshmeat and sourceforge. What does
> "awebsitededicatedtojustqmailpatches.tld" buy a qmail user besides one
> more place to look ?
>
> --
>
> Jeremy Kister
> http://jeremy.kister.net./
>
>
|