On 18/03/2016 20:26, Richard Gaskin wrote:
> Separate from the question of security is a larger one:
> Is a stack repository even something we need/want the core dev team to
> be tasked with maintaining?
> R's CRAN, Python's PyPI, Perls CPAN, and others are all maintained by
> the communities of those languages, leaving the core dev teams to keep
> their focus on the scripting engines they produce.

As far as I know, we plan to introduce a package management system (with 
all of the capabilities that one might expect, such as version 
management, dependency management, checksums, cryptographic signatures, 
etc. etc.) as part of the delayed Extension Store feature.

It won't be a small or easy job but it's very important that we get it 
right when we do it.  Don't expect anything that you can try out for a 
few months yet.

Of course, if someone else comes up with something first then there's a 
good chance we might adopt and contribute to that, so don't let our 
ideas (there's no code yet!) put you off starting something.

If you do, you will find this to be relevant and useful reading material:


