Le 2014-03-17 07:36:35, GARU a écrit :
Show quoted text> 1) When installing previously downloaded dists locally, there's no way
> to know where it came from. Should we simply skip those?
Yes, skip if we can't map this dist strictly to a CPAN release.
Show quoted text> 2) cpanm allows you to fetch/install dists not just from CPAN, but
> also from (local|remote) personal mirrors, BackPAN and even Github.
> Should we query all of those? What guarantee do we have that the
> remote dist actually comes from CPAN with this approach?
I like the checksum idea of ETHER. CPAN already has CHECKSUM files in author dirs.
This could only apply if we are installing from an archive file, not from a local dir or Github.
Until we can compare the the local distribution with some official release on CPAN, it would be safer to avoid sending the report somewhere.
--
Olivier Mengué -
http://perlresume.org/DOLMEN