Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 684064 - Obsolete ::gentoo mirror on GitHub: https://github.com/portage/portage
Summary: Obsolete ::gentoo mirror on GitHub: https://github.com/portage/portage
Status: CONFIRMED
Alias: None
Product: Gentoo Foundation
Classification: Unclassified
Component: Proposals (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Board of Trustees
URL: https://github.com/portage/portage
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-04-21 21:13 UTC by Michał Górny
Modified: 2023-10-02 11:46 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2019-04-21 21:13:48 UTC
Someone apparently registered a 'portage' account on GitHub, and used it to publish some kind of ::gentoo repository mirror:

https://github.com/portage/portage

However, the whole thing doesn't seem to be maintained, data is severely outdated and the owner doesn't reply to bugs.  If someone accidentally clones this instead of our official repo, that someone is going to hit a lot of outdated and vulnerable software.

Could you try arranging for GitHub to remove this repository or at least add some clear indication this is not the official Gentoo 'product'?
Comment 1 Enne Eziarc 2019-04-22 04:27:26 UTC
(In reply to Michał Górny from comment #0)
> Someone apparently registered a 'portage' account on GitHub, and used it to
> publish some kind of ::gentoo repository mirror:

The owner's identity is in cleartext in the git commit metadata:
https://github.com/portage/portage/commit/9c80b9fe716cbdaae28eea7792fcb7b88bdb8a0e.patch
Comment 2 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2019-04-22 05:43:08 UTC
Good catch.  I'll try mailing him.
Comment 3 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2019-04-23 10:30:20 UTC
I have successfully contacted the owner. He asked me whether we want to take the 'portage' GitHub user over. Do we have any use for it?
Comment 4 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2019-04-23 18:02:04 UTC
I think we should take it over and have GitHub add a redirect to the correct repo. That will ensure anybody that does have it cloned will get a redirect and/or useful error message.
Comment 5 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2019-06-03 02:56:58 UTC
mgorny: do you have an update on the redirect?
Comment 6 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2019-06-05 18:26:49 UTC
(In reply to Robin Johnson from comment #5)
> mgorny: do you have an update on the redirect?

The owner said GitHub didn't let him create the redirect.  The repo was removed.  I think the request to pass it over to us was forgotten somewhere.  I'll re-ping.
Comment 7 Ulrich Müller gentoo-dev 2023-10-02 11:04:49 UTC
@mgorny: ping
Comment 8 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-10-02 11:06:37 UTC
At this point, do we really care about the redirect?
Comment 9 Ulrich Müller gentoo-dev 2023-10-02 11:46:52 UTC
I don't think that we have much of a handle there. Github policy is to assign account names on a first-come, first-serve basis:
https://docs.github.com/en/site-policy/other-site-policies/github-username-policy

AFAIK "portage" isn't a registered trade name, so we don't have any claims there. We could try to ask Github for removal of the account because of inactivity. Then again, does the Portage project need that Github account?