www-legal-discuss mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Marvin Humphrey <mar...@rectangular.com>
Subject Re: PyPI MXNet
Date Mon, 11 Feb 2019 12:59:16 GMT
On Sun, Feb 10, 2019 at 5:27 PM Hen <bayard@apache.org> wrote:

> I think it's a jump to say it's not feasible. We reviewed GitHub, DockerHub
> and Maven Central.

The Board does not consistently review project-specific content on DockerHub
or Maven Central to enforce our policies, including Release Policy, because
those are *downstream* channels.

In contrast, the board does proactively review project download pages and
actively enforces our policies with regards to the canonical distribution
channel (www.apache.org/dev).

It's reasonable for us to review and enforce policies on channels where we
have complete control.  It is not reasonable to add an unbounded number of
downstream channels to review, in all their glorious, ever-expanding
diversity.

> Yet the public are (generally) getting our software from downstream
> channels, not from us.

That has been the case for a long, long time.  The current policy language --
including the sections dealing with downstream channels -- was drafted
under that assumption 5 years ago, and it was true long before that.

Marvin Humphrey

---------------------------------------------------------------------
To unsubscribe, e-mail: legal-discuss-unsubscribe@apache.org
For additional commands, e-mail: legal-discuss-help@apache.org


Mime
View raw message