Maintainer lookup by email, not name
kaniini opened this issue · 3 comments
kaniini commented
It is possible that two maintainers might have the same name if it is a common one. So we should use email addresses instead.
clandmeter commented
I have been reluctant to add email address to pkgs.a.o because spam related risks. This is also the reason that package listing only shows the name and does not include the email address.
Is it worth taking the risk or do we have some way to work around it?
kaniini commented
I don't think it really matters. A spam bot can get the emails by crawling our git repositories since cgit is available.
kaniini commented
Not to mention just pulling them out of the APKINDEX. There is precedent for this; at least one spammer has pulled emails out of the Debian package indexes.