Comment by vlovich123
1 hour ago
The solution is to not do it because it’s identity laundering and that’s insecure inherently and not something any other sane package manager supports.
If you want to convince someone “my copy of foo is much better maintained than foo-legacy” you are free to go downstream dependency by downstream dependency and convincing a switch / convincing end users to install yours. You can even have hints to users “hey this package looks to be abandoned - did you mean X”
No comments yet
Contribute on Hacker News ↗