• Question about contributing to debian financially.

    From Zeke Williams@21:1/5 to All on Tue Nov 15 16:20:01 2022
    Greetings.

    I'm considering in the future, funding the debian project financially.
    More specifically, helping fund hiring package maintainers for
    orphaned packages as well as individuals who can maintain the security
    patches. How can I help? Or rather, how would I be able to help if I
    wanted to help in the future?

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Gunnar Wolf@21:1/5 to All on Tue Nov 15 19:30:01 2022
    Hello Zeke,

    Zeke Williams dijo [Tue, Nov 15, 2022 at 08:36:15AM -0500]:
    I'm considering in the future, funding the debian project financially.
    More specifically, helping fund hiring package maintainers for
    orphaned packages as well as individuals who can maintain the security patches. How can I help? Or rather, how would I be able to help if I
    wanted to help in the future?

    First and foremost, thanks for your interest in helping Debian!

    Debian is defined –and proud– to be a volunteer-based project, that
    is, we don't hire and have never hired people to do our work,
    technical or otherwise. If you donate funds to Debian, we will most
    likely use them in hardware for the different project activities,
    hosting and connectivity, or travels for Debian conferences /
    miniconferences.

    If what you want to do is to ensure a given area of the project is
    well maintained, you can hire Debian Developers or Maintainers, and
    pay them to improve the areas you feel to be more important.

    There are many cases of individuals and compaines donating to Debian
    in both ways; perhaps the most visible is the Freexian's "Long Term
    Support" for Debian releases.

    -----BEGIN PGP SIGNATURE-----

    iHUEABYIAB0WIQRNFAUGU6QC1zaHBJ0kBMlUbhRTYAUCY3PY8QAKCRAkBMlUbhRT YDVqAQDqqwgaluNATjWpUUU+oQC0F8BmkebzGMa8rWshXgJYyQD8DXvAJ4GyZPMS VBOESlqKsMUeSji4uC6DwltbxxddCgM=
    =lreV
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Paul Wise@21:1/5 to Gunnar Wolf on Wed Nov 16 00:50:01 2022
    On Tue, 2022-11-15 at 12:22 -0600, Gunnar Wolf wrote:

    Debian is defined –and proud– to be a volunteer-based project,
    that is, we don't hire and have never hired people to do our work,
    technical or otherwise.

    The only exception thus far has been Outreachy internships.

    If you donate funds to Debian, we will most likely use them in
    hardware for the different project activities, hosting and
    connectivity, or travels for Debian conferences / miniconferences.

    https://www.debian.org/donations

    If what you want to do is to ensure a given area of the project is
    well maintained, you can hire Debian Developers or Maintainers, and
    pay them to improve the areas you feel to be more important.

    https://lists.debian.org/debian-jobs/ https://lists.debian.org/debian-consultants/ https://www.debian.org/consultants/
    https://www.fossjobs.net/
    https://github.com/fossjobs/fossjobs/wiki/resources

    There are many cases of individuals and compaines donating to Debian
    in both ways; perhaps the most visible is the Freexian's "Long Term
    Support" for Debian releases.

    https://wiki.debian.org/LTS
    https://wiki.debian.org/LTS/Funding
    https://wiki.debian.org/LTS/Team

    Freexian is also funding general Debian development:

    https://salsa.debian.org/debian/grow-your-ideas https://freexian-team.pages.debian.net/project-funding/ https://salsa.debian.org/freexian-team/project-funding

    --
    bye,
    pabs

    https://wiki.debian.org/PaulWise

    -----BEGIN PGP SIGNATURE-----

    iQIzBAABCgAdFiEEYQsotVz8/kXqG1Y7MRa6Xp/6aaMFAmN0I2AACgkQMRa6Xp/6 aaMtjA/+MtDXOIKfyV/RKS4VptH8uVkDlkrWc2heAgi1v1Y4x3fNq0YE/y85qwP4 qstXMPMqcOcUpi3gb5UbYq3FcnsnONJsmUqGe2BxmLeDshtqKmKoOBInY8A35ySR Vttx7uP7Xmw/itjNdB6qsiaiS4qEHWMdB0LsuMFTQvW6oG4O7v4ycI7N3y0JuPyy nzKGjYV9lyuX5kjqYHjBzT89R5iUv1CzTNuYVLbM9japnNrkGKHjqVYS/gyQ/RKA b5pCxSFygtjDoiF32JZHv773/Avriip1Jzjsa3e8HGdV8bhgevqll0pDNDnsqSLz 4D5HIgr9paEAOWS6eWmluz0wGHzqGxayEP5MuEu8hVoNateyZTPBAcuz9cnPXPtY 7oddlvEpO31vzU/CWqqyUMSIquUbatHvEybr6w7oNhDmc1fDpmy2MA5vqJ9rWAfV Gv8grjjO2y71ociu4B4jkJCrjoBO8gAk1s5L+pQwVzLsjlshRZUBG800USyblEXX pKoKGZMRn+C6eE1K6xK83EHNDxbSxVkclSqqJtPKqJ+8LISvvcNHLCUReo6/c6ZJ i7AC6ZxRfuc8pYj1j/RBIeePu7uMWvfqa5oaHcwlb6x0X3B466d+DF/bVi83aJla d1pEn+8pjmz5bB3TRVxffRkGLpo5K8y+zKopw/DmbafvLsrCbRA=
    =nTQU
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Zeke Williams@21:1/5 to pabs@debian.org on Wed Nov 16 14:50:01 2022
    I have an additional question for if I were to hire someone personally
    to maintain certain debian packages. What happens with the security
    team if a package has no maintainer and a security vulnerability is
    found? Does the security team recompile the package with the patch
    even if there is no maintainer? Is it more difficult to get involved
    with the security team or maintainers team?

    On Tue, Nov 15, 2022 at 6:40 PM Paul Wise <pabs@debian.org> wrote:

    On Tue, 2022-11-15 at 12:22 -0600, Gunnar Wolf wrote:

    Debian is defined –and proud– to be a volunteer-based project,
    that is, we don't hire and have never hired people to do our work, technical or otherwise.

    The only exception thus far has been Outreachy internships.

    If you donate funds to Debian, we will most likely use them in
    hardware for the different project activities, hosting and
    connectivity, or travels for Debian conferences / miniconferences.

    https://www.debian.org/donations

    If what you want to do is to ensure a given area of the project is
    well maintained, you can hire Debian Developers or Maintainers, and
    pay them to improve the areas you feel to be more important.

    https://lists.debian.org/debian-jobs/ https://lists.debian.org/debian-consultants/ https://www.debian.org/consultants/
    https://www.fossjobs.net/
    https://github.com/fossjobs/fossjobs/wiki/resources

    There are many cases of individuals and compaines donating to Debian
    in both ways; perhaps the most visible is the Freexian's "Long Term Support" for Debian releases.

    https://wiki.debian.org/LTS
    https://wiki.debian.org/LTS/Funding
    https://wiki.debian.org/LTS/Team

    Freexian is also funding general Debian development:

    https://salsa.debian.org/debian/grow-your-ideas https://freexian-team.pages.debian.net/project-funding/ https://salsa.debian.org/freexian-team/project-funding

    --
    bye,
    pabs

    https://wiki.debian.org/PaulWise

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Jonathan Dowland@21:1/5 to Zeke Williams on Wed Nov 16 16:30:01 2022
    On Wed, Nov 16, 2022 at 08:35:01AM -0500, Zeke Williams wrote:
    I have an additional question for if I were to hire someone personally
    to maintain certain debian packages. What happens with the security
    team if a package has no maintainer and a security vulnerability is
    found? Does the security team recompile the package with the patch
    even if there is no maintainer?

    Yes.

    Is it more difficult to get involved with the security team or maintainers team?

    If by "getting involved" you mean joining, as oppose to interacting
    with, the security team is much more difficult than "maintainers team"
    which I take to mean any package maintainer.

    --
    Please do not CC me for listmail.

    👱🏻 Jonathan Dowland
    jmtd@debian.org
    🔗 https://jmtd.net

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Paul Wise@21:1/5 to Zeke Williams on Thu Nov 17 03:10:01 2022
    On Wed, 2022-11-16 at 08:35 -0500, Zeke Williams wrote:

    I have an additional question for if I were to hire someone personally
    to maintain certain debian packages. What happens with the security
    team if a package has no maintainer and a security vulnerability is
    found? Does the security team recompile the package with the patch
    even if there is no maintainer? Is it more difficult to get involved
    with the security team or maintainers team?

    Anyone can contribute security updates to Debian.

    The security team do a lot of the work on that and they work on any
    package in Debian. They do not fix every security issue, some minor
    issues are left either without fixes or for someone else, usually the
    package maintainer.

    Joining the security team can only happen after one is already a Debian
    member and presumably after the person has been contributing security
    fixes for some time without being part of the team yet.

    If someone wants to get involved in improving Debian security, please
    have them take a look at our pages about Debian and security support:

    https://www.debian.org/security/
    https://www.debian.org/security/faq
    https://wiki.debian.org/Teams/Security
    https://security-team.debian.org/
    https://security-tracker.debian.org/tracker/ https://security-tracker.debian.org/tracker/data/report https://www.debian.org/doc/manuals/developers-reference/pkgs.en.html#bug-security

    --
    bye,
    pabs

    https://wiki.debian.org/PaulWise

    -----BEGIN PGP SIGNATURE-----

    iQIzBAABCgAdFiEEYQsotVz8/kXqG1Y7MRa6Xp/6aaMFAmN1lLAACgkQMRa6Xp/6 aaMJrw/7Bgxi5hKo+aiAD6JqNeQfI0AgMQqsuh1DatWWwW0823CDl2/fiOKtgrHl R8Or6E1lmxkxAZ9UScdrvbDYwJj/chU/MiogHqdwMhfd486FMZ4DACHjF6yI+Gr3 7k6Gn5iWJC16PlAR9HhQpvckNC6Trw9ZNPn5Y97jl/h/5LGDuFJhXwXMzgJf4qX7 bLvNmDF3LlzDeSqPx6HsF1onoQoHCws7l8Cul+xxQukZEF6Eik0f9BGnlP8mYSQB FNtiHbxviYt3uTWBv5BJr33yAwZPmZpVn620sc+aEbBtCSc+Hxer3Ar6nAg+ne/D s6VRB6uGbKNAVlEPuGs/3JLjnn8nBW2DK3iLTnj2XyBOSUhnmI5d1pLhXtFP0ZZ1 NOVToq5+qIXiRLPcSywduuN9MwXPn59qOkR64tRBnfigX4r0n2aQWUCxnMXYLndv ++Vb0zRQP78lt+ndt8TEXe71R+6HJChMPew4dBumwCiwE99w8q0C+3osk583u+5O PbKLlYChavqsoayAnuQaDDmtn5eerMBpAi1MJn7wR2NmGyzr4ICFfRG0Fi3G3gyw bAIl27JzAFnbSZpKlLuE2q9jEIuihlXou+XA4b3Y01+m6t+fQyoh1qR8DWo6RyRS JugfF1mjuqGJhgebo4AEcK81lZ4sPiX/2UfHQVDi3RbXVUTaN4U=
    =YNo8
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)