[Zope-dev] Re: What happened to the infrae.subversion and py eggs?

Tres Seaver tseaver at palladion.com
Tue Apr 8 21:39:14 EDT 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Daniel Nouri wrote:
> Maurits van Rees <m.van.rees at zestsoftware.nl> writes:
>> Luckily for demonstration purposes this at least fails in a
>> virtualenv:
>>
>> ===========================================================
>> $ bin/easy_install infrae.subversion==1.0dev_r27844
>> Searching for infrae.subversion==1.0dev-r27844
>> Reading http://pypi.python.org/simple/infrae.subversion/
>> Reading https://svn.infrae.com/buildout/infrae.buildout/trunk/
>> No local packages or download links found for infrae.subversion==1.0dev-r27844
>> error: Could not find suitable distribution for Requirement.parse('infrae.subversion==1.0dev-r27844')
>> ===========================================================
>>
>> So has that version of the egg been removed from the cheeseshop?  And
>> can it be brought back?  I have buildouts that are pinned to that
>> version for stability and I would like those to work half a year from
>> now (or in fact tomorrow) in case I have to rebuild those buildouts on
>> a new server.  You never know when that meteor will hit your data
>> center. ;-)
> 
> 1.0dev-r27844 seems to be gone from PyPI.

Such a version should *never* have been "released" to PyPI (any egg /
source dist with an SVN revision number in its filename is *not*
suitable for sharing with the wider world).  Pushing such distributions
out to PyPI, rather than sharing them in a more restricted / private
location, induces pain on the wrong parties (those who innocently rely
on PiPI, rather than those perpetrating the risky behavior).

> I'm CCing Sylvain who I
> believe made the last release.  Maybe we can even convince him to make a
> proper release, not an SVN snapshot. :-)
> 
> Of course, we should also make sure that the latest version works
> properly with its pinned py dependency.

Amen!


Tres.
- --
===================================================================
Tres Seaver          +1 540-429-0999          tseaver at palladion.com
Palladion Software   "Excellence by Design"    http://palladion.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFH/B5C+gerLs4ltQ4RAtgwAJ464BsvjmvRqFuMLiuHdtpGIbGlAgCfZ/Pq
j56rwm9hVGP3gqp9kdY0LPY=
=+90j
-----END PGP SIGNATURE-----



More information about the Zope-Dev mailing list