https://github.com/keepassxreboot/keepassxc/issues/10725#iss...
> This is now our fourth bug report because of the decision to neuter the base KeePassXC package in Debian
And I, as an end user, am absolutely fine with that, as a user of vim-nox package etc etc...
Do you have a non-trivial .vimrc/.vim directory?
Would you be accepting of the maintainer disabling a bunch of features and pushing those changes out under the main vim-nox package such that it breaks your existing install? Would it be reasonable to expect you as the end user to figure out what has happened and that you need to uninstall vim-nox and and install vim-nox-full?
That's how it used to be in the past (and still is for enterprise distros because you might as well use the support contract you paid for). But lately users have gotten more savvy about talking to upstream directly, especially since more and more upstreams are now on easy-to-use websites like GitHub instead of mailing lists. That's still fine if users do their own diligence to ensure the issue is with upstream and not with the distribution package, but alas they don't all do that, leading to these spurious reports.
I'm one of those users. If I'm loud, does that mean my opinion doesn't count anymore?
They were. apt shows the NEWS file during update when there's a change.
You definitely see it for several packages during dist-upgrades. Same in sid/testing except it can be any time though it's a rare event.
In case apt/dpkg is configured to ignore those, information still resides in /usr/share/doc/<pkg>
it'll also be put in the release notes when the next major Debian version is released.
I mean, distributions have already figured these things out 20 years ago, but I guess users nowadays expect these to be announced in Twitter or a pinned Github issue or something :-<
This really just breaks core functionality that exists and is expected by real users, under the guise of unnamed security risks...theres plenty of disabled options in Linux that are "potential" risks, so its a silly choice.
$ apt install keepassx
$ apt install keepassx-full
Choice made.
If it was so important they never should have packaged it in the first place. -Minimal option is the obvious reasonable choice, unless trying to be an arse to make a point, since you're changing a users choice after the fact.
Are we going to stop compiling sshd with plaintext pw options and root login, and suddenly?
If a user has an option enabled you don't like anymore, notify them, don't blindly remove functionality and say "your fault for not reading the changelogs".
Frankly the security claims ring more of hyperbole than anything
apt shows the NEWS file during update when there's a change. These users not only have chosen to actively ignore the warning that has been shown to them by default, they've also chosen to directly go to upstream to complain instead of first their distributions channels.