time is running: security issue BZ#2241470
by Marius Schwarz
Hi,
this is emerg ping for the security team, to take a look at this bz :
https://bugzilla.redhat.com/show_bug.cgi?id=2241470
excuse me, for bringing this to the list, as a security bz is the way to
go, but time is running fast and the patched release needs to be build
and shipped in 36h hours from now.
The deadline for having a fix shipped is the afternoon of SUN, 1. of Oct
2023 . On this date, the patches in upstream go public and exploits
will be developed for them. this impacts ALL of redhat based
installations which run as servers and are publically reachable. The
component in question is the default package for rh based installations.
best regards,
Marius Schwarz
7 months
Orphaned packages looking for new maintainers
by Miro Hrončok
The following packages are orphaned and will be retired when they
are orphaned for six weeks, unless someone adopts them. If you know for sure
that the package should be retired, please do so now with a proper reason:
https://fedoraproject.org/wiki/How_to_remove_a_package_at_end_of_life
Note: If you received this mail directly you (co)maintain one of the affected
packages or a package that depends on one. Please adopt the affected package or
retire your depending package to avoid broken dependencies, otherwise your
package will fail to install and/or build when the affected package gets retired.
Request package ownership via the *Take* button in he left column on
https://src.fedoraproject.org/rpms/<pkgname>
Full report available at:
https://churchyard.fedorapeople.org/orphans-2023-09-25.txt
grep it for your FAS username and follow the dependency chain.
For human readable dependency chains,
see https://packager-dashboard.fedoraproject.org/
For all orphaned packages,
see https://packager-dashboard.fedoraproject.org/orphan
Package (co)maintainers Status Change
================================================================================
RBTools orphan 2 weeks ago
aiodnsbrute orphan 2 weeks ago
andriller orphan 2 weeks ago
androwarn orphan 2 weeks ago
brd orphan 2 weeks ago
btest orphan 2 weeks ago
eric orphan 2 weeks ago
fedora-gather-easyfix orphan 2 weeks ago
golang-github-alicebob- go-sig, orphan 0 weeks ago
miniredis
libssh2-python orphan 2 weeks ago
perl-Plack-Middleware-Deflater orphan 1 weeks ago
php-ocramius-generated-hydrator orphan, remi 0 weeks ago
php-symfony4 orphan 0 weeks ago
pico-wizard orphan 2 weeks ago
pseudo ignatenkobrain, orphan 3 weeks ago
pyflowtools orphan 2 weeks ago
python-acora orphan, python-packagers-sig 2 weeks ago
python-adext orphan 2 weeks ago
python-aiozeroconf orphan, python-packagers-sig 2 weeks ago
python-airthings orphan 2 weeks ago
python-alarmdecoder orphan 2 weeks ago
python-ansible-pygments orphan 0 weeks ago
python-apply-defaults orphan 5 weeks ago
python-btlewrap orphan 2 weeks ago
python-cle epel-packagers-sig, fab, 5 weeks ago
orphan
python-convertdate orphan, python-packagers-sig 2 weeks ago
python-cypari2 orphan 2 weeks ago
python-dominate fab, orphan 2 weeks ago
python-elpy orphan 2 weeks ago
python-flask-bootstrap orphan 2 weeks ago
python-fpylll orphan 2 weeks ago
python-gccinvocation orphan 2 weeks ago
python-grako orphan 2 weeks ago
python-ipgetter orphan 2 weeks ago
python-jep orphan, python-packagers-sig 2 weeks ago
python-jsonrpc-server orphan 2 weeks ago
python-lacrosse orphan 2 weeks ago
python-lazr-smtptest orphan 2 weeks ago
python-leveldb orphan, python-packagers-sig 2 weeks ago
python-liblarch orphan 2 weeks ago
python-logging-tree orphan 2 weeks ago
python-metaextract orphan, python-packagers-sig 1 weeks ago
python-molecule gotmax23, orphan 0 weeks ago
python-molecule-docker orphan 0 weeks ago
python-molecule-podman orphan 0 weeks ago
python-nose_fixes orphan 2 weeks ago
python-notario orphan 2 weeks ago
python-py9p orphan 2 weeks ago
python-pyaes orphan 2 weeks ago
python-pybv orphan 2 weeks ago
python-pydiffx orphan 2 weeks ago
python-pyls-spyder orphan 5 weeks ago
python-pytenable orphan 2 weeks ago
python-pytest-metadata orphan 2 weeks ago
python-pyvex epel-packagers-sig, fab, 5 weeks ago
orphan
python-qstylizer jonathanspw, orphan 5 weeks ago
python-restfly orphan 2 weeks ago
python-sklearn-genetic-opt orphan 2 weeks ago
python-smart-gardena orphan 2 weeks ago
python-snipeit orphan 2 weeks ago
python-sphinx_ansible_theme orphan 0 weeks ago
python-sphinxcontrib-actdiag epel-packagers-sig, openstack- 2 weeks ago
sig, orphan
python-stdio-mgr orphan 2 weeks ago
python-tambo orphan 2 weeks ago
python-test_server orphan, python-packagers-sig 2 weeks ago
python-textdistance orphan 5 weeks ago
python-upoints orphan 2 weeks ago
python-uri-templates orphan 2 weeks ago
python-whatthepatch jonathanspw, orphan 5 weeks ago
python-yamlordereddictloader orphan 2 weeks ago
python-yourls orphan 5 weeks ago
python3-script orphan 2 weeks ago
pyutil orphan 2 weeks ago
rubygem-pr_geohash orphan 3 weeks ago
rubygem-shoulda orphan, stahnma 1 weeks ago
sagemath orphan 2 weeks ago
sword cicku, jkastner, orphan 2 weeks ago
The following packages require above mentioned packages:
Depending on: golang-github-alicebob-miniredis (2), status change: 2023-09-25
(0 weeks ago)
golang-github-siddontang-goredis (maintained by: eclipseo, go-sig)
golang-github-siddontang-goredis-0-0.7.20210111git0b4019c.fc39.src requires
golang(github.com/alicebob/miniredis) = 2.14.5-7.fc39
golang-github-ledisdb (maintained by: eclipseo, go-sig)
golang-github-ledisdb-0.6-9.20210112gitd35789e.fc39.src requires
golang(github.com/siddontang/goredis) = 0-0.7.20210111git0b4019c.fc39
golang-github-ledisdb-devel-0.6-9.20210112gitd35789e.fc39.noarch requires
golang(github.com/siddontang/goredis) = 0-0.7.20210111git0b4019c.fc39
Depending on: perl-Plack-Middleware-Deflater (1), status change: 2023-09-16 (1
weeks ago)
perl-Twiggy (maintained by: cheeselee)
perl-Twiggy-0.1026-9.fc39.src requires perl(Plack::Middleware::Deflater) = 0.12
Depending on: php-symfony4 (21), status change: 2023-09-19 (0 weeks ago)
php-doctrine-cache (maintained by: remi, siwinski)
php-doctrine-cache-1.13.0-4.fc39.src requires
php-composer(symfony/var-exporter) = 4.4.47
php-doctrine-datafixtures (maintained by: remi, siwinski)
php-doctrine-datafixtures-1.6.5-2.fc39.src requires
php-composer(doctrine/orm) = 2.14.1, php-symfony4-cache = 4.4.47-1.fc38
php-doctrine-doctrine-bundle (maintained by: siwinski)
php-doctrine-doctrine-bundle-1.12.13-6.fc38.src requires
php-composer(doctrine/orm) = 2.14.1, php-symfony4-cache = 4.4.47-1.fc38,
php-symfony4-config = 4.4.47-1.fc38, php-symfony4-console = 4.4.47-1.fc38,
php-symfony4-dependency-injection = 4.4.47-1.fc38, php-symfony4-doctrine-bridge
= 4.4.47-1.fc38, php-symfony4-framework-bundle = 4.4.47-1.fc38,
php-symfony4-property-info = 4.4.47-1.fc38, php-symfony4-proxy-manager-bridge =
4.4.47-1.fc38, php-symfony4-twig-bridge = 4.4.47-1.fc38, php-symfony4-validator
= 4.4.47-1.fc38, php-symfony4-web-profiler-bundle = 4.4.47-1.fc38,
php-symfony4-yaml = 4.4.47-1.fc38
php-doctrine-orm (maintained by: remi, siwinski)
php-doctrine-orm-2.14.1-3.fc39.src requires php-composer(doctrine/cache) =
1.13.0, php-composer(symfony/var-exporter) = 4.4.47
php-doctrine-orm-2.14.1-3.fc39.noarch requires php-composer(doctrine/cache) =
1.13.0
php-nyholm-psr7 (maintained by: remi)
php-nyholm-psr7-1.8.0-2.fc39.src requires php-composer(symfony/error-handler)
= 4.4.47
php-phpspec (maintained by: remi)
php-phpspec-7.4.0-2.fc39.noarch requires php-symfony4-console =
4.4.47-1.fc38, php-symfony4-event-dispatcher = 4.4.47-1.fc38,
php-symfony4-finder = 4.4.47-1.fc38, php-symfony4-process = 4.4.47-1.fc38,
php-symfony4-yaml = 4.4.47-1.fc38
php-phpunit-DbUnit (maintained by: remi)
php-phpunit-DbUnit-2.0.3-16.fc39.noarch requires php-symfony4-yaml =
4.4.47-1.fc38
php-phpunit-PHPUnit (maintained by: remi)
php-phpunit-PHPUnit-5.7.27-20.fc39.noarch requires php-symfony4-yaml =
4.4.47-1.fc38
php-phpunit-PHPUnit-5.7.27-20.fc39.src requires php-symfony4-yaml = 4.4.47-1.fc38
php-symfony-polyfill (maintained by: siwinski)
php-symfony-polyfill-1.28.0-1.fc40.src requires php-symfony4-intl =
4.4.47-1.fc38, php-symfony4-var-dumper = 4.4.47-1.fc38
php-doctrine-annotations (maintained by: remi, siwinski)
php-doctrine-annotations-1.14.3-2.fc39.src requires
php-composer(doctrine/cache) = 1.13.0
php-doctrine-common (maintained by: remi, siwinski)
php-doctrine-common-1:2.13.3-10.fc39.noarch requires
php-composer(doctrine/cache) = 1.13.0
php-doctrine-dbal (maintained by: lcts, remi)
php-doctrine-dbal-2.13.9-4.fc39.noarch requires php-composer(doctrine/cache)
= 1.13.0
php-doctrine-dbal-2.13.9-4.fc39.src requires php-composer(doctrine/cache) =
1.13.0
php-doctrine-dbal3 (maintained by: remi)
php-doctrine-dbal3-3.6.2-2.fc39.noarch requires php-composer(doctrine/cache)
= 1.13.0
php-doctrine-dbal3-3.6.2-2.fc39.src requires php-composer(doctrine/cache) =
1.13.0
php-doctrine-doctrine-cache-bundle (maintained by: remi, siwinski)
php-doctrine-doctrine-cache-bundle-1.4.0-8.fc39.noarch requires
php-composer(doctrine/cache) = 1.13.0
php-doctrine-persistence (maintained by: remi)
php-doctrine-persistence-1.3.8-7.fc39.noarch requires
php-composer(doctrine/cache) = 1.13.0
php-doctrine-persistence-1.3.8-7.fc39.src requires
php-composer(doctrine/cache) = 1.13.0
php-doctrine-persistence2 (maintained by: remi)
php-doctrine-persistence2-2.5.7-2.fc39.noarch requires
php-composer(doctrine/cache) = 1.13.0
php-doctrine-persistence2-2.5.7-2.fc39.src requires
php-composer(doctrine/cache) = 1.13.0
php-symfony (maintained by: siwinski)
php-symfony-2.8.52-10.fc38.src requires php-composer(doctrine/cache) =
1.13.0, php-composer(doctrine/data-fixtures) = 1.6.5,
php-composer(doctrine/doctrine-bundle) = 1.12.13, php-composer(doctrine/orm) =
2.14.1
php-symfony-framework-bundle-2.8.52-10.fc38.noarch requires
php-composer(doctrine/cache) = 1.13.0
php-symfony-serializer-2.8.52-10.fc38.noarch requires
php-composer(doctrine/cache) = 1.13.0
php-symfony-validator-2.8.52-10.fc38.noarch requires
php-composer(doctrine/cache) = 1.13.0
php-symfony-doctrine-bridge-2.8.52-10.fc38.noarch requires
php-composer(doctrine/data-fixtures) = 1.6.5, php-composer(doctrine/orm) = 2.14.1
php-symfony3 (maintained by: remi, siwinski)
php-symfony3-3.4.49-5.fc38.src requires php-composer(doctrine/cache) =
1.13.0, php-composer(doctrine/data-fixtures) = 1.6.5,
php-composer(doctrine/doctrine-bundle) = 1.12.13, php-composer(doctrine/orm) =
2.14.1
php-symfony4 (maintained by: orphan)
php-symfony4-4.4.47-1.fc38.src requires php-composer(doctrine/cache) =
1.13.0, php-composer(doctrine/data-fixtures) = 1.6.5,
php-composer(doctrine/doctrine-bundle) = 1.12.13, php-composer(doctrine/orm) =
2.14.1, php-composer(nyholm/psr7) = 1.8.0
php-symfony4-framework-bundle-4.4.47-1.fc38.noarch requires
php-composer(doctrine/cache) = 1.13.0
php-symfony-psr-http-message-bridge (maintained by: siwinski)
php-symfony-psr-http-message-bridge-1.3.0-7.fc38.src requires
php-composer(nyholm/psr7) = 1.8.0
php-phpspec-prophecy (maintained by: remi)
php-phpspec-prophecy-1.17.0-3.fc39.src requires php-composer(phpspec/phpspec)
= 7.4.0
Too many dependencies for php-symfony4, not all listed here
Depending on: python-ansible-pygments (4), status change: 2023-09-22 (0 weeks ago)
python-sphinx_ansible_theme (maintained by: orphan)
python-sphinx_ansible_theme-0.10.1-1.fc39.src requires
python3dist(ansible-pygments) = 0.1.1
python3-sphinx_ansible_theme-0.10.1-1.fc39.noarch requires
python3.11dist(ansible-pygments) = 0.1.1
python-molecule (maintained by: gotmax23, orphan)
python-molecule-4.0.4-5.fc38.src requires python3dist(sphinx-ansible-theme) =
0.10.1
python-molecule-docker (maintained by: orphan)
python-molecule-docker-2.1.0-2.fc38.src requires python3dist(molecule) = 4.0.4
python3-molecule-docker-2.1.0-2.fc38.noarch requires python3.11dist(molecule)
= 4.0.4
python-molecule-podman (maintained by: orphan)
python-molecule-podman-2.0.3-2.fc38.src requires python3dist(molecule) = 4.0.4
python3-molecule-podman-2.0.3-2.fc38.noarch requires python3.11dist(molecule)
= 4.0.4
Depending on: python-cypari2 (1), status change: 2023-09-04 (2 weeks ago)
sagemath (maintained by: orphan)
sagemath-9.8-2.fc39.src requires python3-cypari2-devel = 2.1.3-1.fc39
sagemath-core-9.8-2.fc39.x86_64 requires python3dist(cypari2) = 2.1.3
Depending on: python-dominate (1), status change: 2023-09-04 (2 weeks ago)
python-flask-bootstrap (maintained by: orphan)
python3-flask-bootstrap-3.3.7.1-22.fc39.noarch requires python3-dominate =
2.7.0-2.fc38
Depending on: python-fpylll (1), status change: 2023-09-04 (2 weeks ago)
sagemath (maintained by: orphan)
sagemath-9.8-2.fc39.src requires python3dist(fpylll) = 0.5.9
sagemath-core-9.8-2.fc39.x86_64 requires python3dist(fpylll) = 0.5.9
Depending on: python-molecule (2), status change: 2023-09-22 (0 weeks ago)
python-molecule-docker (maintained by: orphan)
python-molecule-docker-2.1.0-2.fc38.src requires python3dist(molecule) = 4.0.4
python3-molecule-docker-2.1.0-2.fc38.noarch requires python3.11dist(molecule)
= 4.0.4
python-molecule-podman (maintained by: orphan)
python-molecule-podman-2.0.3-2.fc38.src requires python3dist(molecule) = 4.0.4
python3-molecule-podman-2.0.3-2.fc38.noarch requires python3.11dist(molecule)
= 4.0.4
Depending on: python-pydiffx (1), status change: 2023-09-04 (2 weeks ago)
RBTools (maintained by: orphan)
RBTools-4.0-4.fc39.noarch requires python3.11dist(pydiffx) = 1.1
RBTools-4.0-4.fc39.src requires python3dist(pydiffx) = 1.1
Depending on: python-pyls-spyder (1), status change: 2023-08-16 (5 weeks ago)
spyder (maintained by: jonathanspw, music, neuro-sig, thozza)
python3-spyder-5.3.1-8.fc40.noarch requires python3.12dist(pyls-spyder) = 0.4
Depending on: python-pyvex (1), status change: 2023-08-21 (5 weeks ago)
python-cle (maintained by: epel-packagers-sig, fab, orphan)
python-cle-9.2.39-3.fc39.src requires python3dist(pyvex) = 9.2.39
python3-cle-9.2.39-3.fc39.noarch requires python3.12dist(pyvex) = 9.2.39
Depending on: python-qstylizer (1), status change: 2023-08-16 (5 weeks ago)
spyder (maintained by: jonathanspw, music, neuro-sig, thozza)
python3-spyder-5.3.1-8.fc40.noarch requires python3.12dist(qstylizer) = 0.2.2
Depending on: python-restfly (1), status change: 2023-09-04 (2 weeks ago)
python-pytenable (maintained by: orphan)
python-pytenable-1.4.13-1.fc39.src requires python3dist(restfly) = 1.4.7
python3-pytenable-1.4.13-1.fc39.noarch requires python3.11dist(restfly) = 1.4.7
Depending on: python-sphinx_ansible_theme (3), status change: 2023-09-22 (0
weeks ago)
python-molecule (maintained by: gotmax23, orphan)
python-molecule-4.0.4-5.fc38.src requires python3dist(sphinx-ansible-theme) =
0.10.1
python-molecule-docker (maintained by: orphan)
python-molecule-docker-2.1.0-2.fc38.src requires python3dist(molecule) = 4.0.4
python3-molecule-docker-2.1.0-2.fc38.noarch requires python3.11dist(molecule)
= 4.0.4
python-molecule-podman (maintained by: orphan)
python-molecule-podman-2.0.3-2.fc38.src requires python3dist(molecule) = 4.0.4
python3-molecule-podman-2.0.3-2.fc38.noarch requires python3.11dist(molecule)
= 4.0.4
Depending on: python-textdistance (1), status change: 2023-08-16 (5 weeks ago)
spyder (maintained by: jonathanspw, music, neuro-sig, thozza)
python3-spyder-5.3.1-8.fc40.noarch requires python3.12dist(textdistance) = 4.2
Depending on: python-whatthepatch (4), status change: 2023-08-16 (5 weeks ago)
python-lsp-server (maintained by: gui1ty, jonathanspw, neuro-sig,
python-packagers-sig)
python-lsp-server-1.8.0-1.fc40.src requires python3dist(whatthepatch) = 1.0.2
python-lsp-black (maintained by: gui1ty, jonathanspw, neuro-sig)
python-lsp-black-1.3.0-1.fc40.src requires python3dist(python-lsp-server) =
0.1~~dev2
python3-lsp-black-1.3.0-1.fc40.noarch requires
python3.12dist(python-lsp-server) = 0.1~~dev2
python-pyls-spyder (maintained by: orphan)
python3-pyls-spyder-0.4.0-8.fc39.noarch requires
python3.12dist(python-lsp-server) = 0.1~~dev2
spyder (maintained by: jonathanspw, music, neuro-sig, thozza)
python3-spyder-5.3.1-8.fc40.noarch requires python3.12dist(pyls-spyder) =
0.4, python3.12dist(python-lsp-black) = 1.3, python3.12dist(python-lsp-server)
= 0.1~~dev2
Depending on: sword (2), status change: 2023-09-04 (2 weeks ago)
bibletime (maintained by: cicku, greghellings)
bibletime-3.0.3-2.fc39.src requires sword-devel = 1:1.9.0-16.fc38
bibletime-3.0.3-2.fc39.x86_64 requires libsword.so.1.9()(64bit)
xiphos (maintained by: cicku, greghellings)
xiphos-4.2.1-20.fc39.src requires sword-devel = 1:1.9.0-16.fc38
xiphos-4.2.1-20.fc39.x86_64 requires libsword.so.1.9()(64bit)
See dependency chains of your packages at
https://packager-dashboard.fedoraproject.org/
See all orphaned packages at https://packager-dashboard.fedoraproject.org/orphan
Affected (co)maintainers (either directly or via packages' dependencies):
cheeselee: perl-Plack-Middleware-Deflater
cicku: sword
eclipseo: golang-github-alicebob-miniredis
epel-packagers-sig: python-cle, python-pyvex, python-sphinxcontrib-actdiag
fab: python-cle, python-dominate, python-pyvex
go-sig: golang-github-alicebob-miniredis
gotmax23: python-ansible-pygments, python-sphinx_ansible_theme, python-molecule
greghellings: sword
gui1ty: python-whatthepatch
ignatenkobrain: pseudo
jkastner: sword
jonathanspw: python-textdistance, python-qstylizer, python-whatthepatch,
python-pyls-spyder
lcts: php-symfony4
music: python-textdistance, python-qstylizer, python-whatthepatch,
python-pyls-spyder
neuro-sig: python-textdistance, python-qstylizer, python-whatthepatch,
python-pyls-spyder
openstack-sig: python-sphinxcontrib-actdiag
python-packagers-sig: python-aiozeroconf, python-whatthepatch,
python-metaextract, python-acora, python-convertdate, python-test_server,
python-jep, python-leveldb
remi: php-symfony4, php-ocramius-generated-hydrator
siwinski: php-symfony4
stahnma: rubygem-shoulda
thozza: python-textdistance, python-qstylizer, python-whatthepatch,
python-pyls-spyder
--
The script creating this output is run and developed by Fedora
Release Engineering. Please report issues at its pagure instance:
https://pagure.io/releng/
The sources of this script can be found at:
https://pagure.io/releng/blob/main/f/scripts/find_unblocked_orphans.py
Report finished at 2023-09-25 11:51:42 UTC
7 months, 1 week
Contact attempt for the Inactive Packagers Policy for the F39 release cycle
by Mattia Verga
****
This email was sent both to the mailing list for raising awareness to
the community and BCC directly to the affected users from which we need
a reply. If you have received this email only from the mailing list, you
can ignore the next part.
****
Hello,
during our periodic check as per the "Inactive packagers policy" [1] we
detected no activity from you as a packager, nor in other Fedora
community places, like Bodhi or mailing lists.
In order to reduce security risks from possible accounts hijacking we
tried to contact you by tagging your username in the appropriate ticket
within pagure.io repository [2], but your username is not registered
there, so we cannot contact you in that way.
Please, let us know if you're still intersted in participating in Fedora
and if you still need your account to be listed in the packager group.
You can reply here in the mailing list, so that your activity can be
detected by the script, or just login in pagure.io with your Fedora
account and reply to the ticket which refers to your username.
Without any reply from you, one week after the release of F39 the
`packager` group membership will be removed from your account and any
package for which you are the main admin will be orphaned, so that
co-maintainers can pick them up.
[1]
https://docs.fedoraproject.org/en-US/fesco/Policy_for_inactive_packagers/
[2] https://pagure.io/find-inactive-packagers/issues
Thank you.
Mattia
---------
This is the full list of usernames which cannot be reached by tag in
pagure.io:
gsgatlin
dmarlin
andriy
buytenh
jbernard
shardy
bhills
lgao
lgoncalv
krionbsd
rkennke
angelonord
athomas
dmaley
eglynn
endur
florencia
mwringe
rosslagerwall
sgros
tlavocat
xinghong
pcullen
jshort
---------
_______________________________________________
devel-announce mailing list -- devel-announce(a)lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave(a)lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedora...
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
7 months, 1 week
SPDX Statistics - Munich Agreement edition
by Miroslav Suchý
Hot news: we are over 50 %!!! With almost 4k license tags converted in past 2 weeks. How it was possible?
First - it is because you rocks and really lots of work has been done. Both on our (Change owners) side and on you as
package maintainers.
But the biggest impact was migration of texlive package. Texlive is huge package and it has 6558 subpackages and 4010
License tags. Texlive package was converted to SPDX format long time ago. But it is not sufficient to use SPDX formula.
The license has to be approved for usage in Fedora too. I.e. SPDX IDs added to fedora-license-data collection. It took
some time and the licenses ware review few days ago. This resulted in 3700 license tags being suddenly marked as
migrated. That is good, because it was result of several months of work. There will be additional work because there is
still 339 tags that does not conform our guidelines and one license has been found as not-allowed. Richard and Than is
working on it and I applaud to them.
I must highlight that we added 25 license to fedora-license-data in past 2 weeks. That is almost 2 licenses per day
(including weekends). When you realize that it requires legal audit, comparing to existing licenses, diving into
history, sometimes communicating with stewards of the licenses. Submitting them to SPDX where we discuss it and add
markup that allow to have template for several similar licenses... This is simply amazing pace.
Can I ask for additional help? Robert-André packaged scancode-toolkit for Fedora. This is license-check on steroids.
Very useful and powerful tool. But it has lots of dependencies. Robert packaged them too. He "just" need reviewers to
get this in Fedora. If you can check "Depends on" of https://bugzilla.redhat.com/show_bug.cgi?id=2235055 and do review
of one of these dependecies that will be awesome.
Now lets dive into numbers:
Two weeks ago we had:
> * 23143 spec files in Fedora
>
> * 29600license tags in all spec files
>
> * 16169 tags have not been converted to SPDX yet
>
> * 5903tags can be trivially converted using `license-fedora2spdx`
>
> * Progress: 45.35% ░░░░██████ 100%
>
> ELN subset:
>
> 603 out of 2986 packages are not converted yet
>
Today we have:
* 23100 spec files in Fedora
* 29479license tags in all spec files
* 12870 tags have not been converted to SPDX yet
* 5817tags can be trivially converted using `license-fedora2spdx`
* Progress: 56.34% ░░░░░█████ 100%
ELN subset:
913 out of 3957 packages are not converted yet
Graph with the burndown chart:
https://docs.google.com/spreadsheets/d/1QVMEzXWML-6_Mrlln02axFAaRKCQ8zE80...
The list of packages needed to be converted is here:
https://pagure.io/copr/license-validate/blob/main/f/packages-without-spdx...
List by package maintainers is here
https://pagure.io/copr/license-validate/blob/main/f/packages-without-spdx...
List of packages from ELN subset that needs to be converted:
https://pagure.io/copr/license-validate/blob/main/f/eln-not-migrated.txt
New version of fedora-license-data has been released. With 25 new licenses (plus bunch of public domain declarations).
18 licenses are waiting to be review by SPDX.org (and then to be added to fedora-license-data).
Legal docs and especially
https://docs.fedoraproject.org/en-US/legal/allowed-licenses/
was updated too.
New projection when we will be finished is 2024-08-06. Pure linear approximation.
If your package does not have neither git-log entry nor spec-changelog entry mentioning SPDX and you know your license
tag matches SPDX formula, you can put your package on ignore list
https://pagure.io/copr/license-validate/blob/main/f/ignore-packages.txt
Either pull-request or direct email to me is fine.
Why Munich Agreement edition? On today's date [*] at 1938, four biggest European countries agreed that Germany can annex
border parts of Czechoslovakia where ethnics German lived. It was done in hope that it will stop the low-intensity war
and to keep the peace in Europe. But it was actually prelude to World War II.
https://en.wikipedia.org/wiki/Munich_Agreement
[*] the pact was signed shortly after midnight, so some resources use tomorrows date.
Do you hesitate how to proceed with the migration? Please follow
https://docs.fedoraproject.org/en-US/legal/update-existing-packages/
Miroslav
7 months, 1 week
16 packages still need a Python 3.12 rebuild, final freeze in 6 days
by Miro Hrončok
Hello packagers,
here is the list of packages that still need a Python 3.12 rebuild for Fedora 39+.
Packages on this list have broken dependencies and hence the users of Fedora
Linux 39+ cannot install them at all.
Moreover, users of Fedora Linux 37 or 38 with the listed packages installed are
unable to upgrade to Fedora Linux 39+.
We need to either rebuild those packages in Fedora Linux 39+ or retire+obsolete
them to clear the upgrade path. Package retirement is not a "punishment" for
not fixing the package, it is merely a way to allow our users to upgrade.
When a retired package is fixed after Fedora Linux 39 final release, it can be
added back to the distribution.
The Fedora 39 Final Freeze starts on 2023-10-03 14:00 UTC -- that leaves only 6
days to push updates via Bodhi, meaning they will not be autopushed in time.
Please, if you are planning to fix the packages, set low karma limits and ask
another packager to test it and add karma.
Request freeze exceptions when needed:
https://qa.fedoraproject.org/blockerbugs/propose_bug
I plan to propose "mass" retirement of the remaining packages without a
requested freeze exception and a clear path forward a couple days after the
freeze starts, so we have time to ship an updated fedora-obsolete-packages.
Packages broken in Rawhide by maintainer:
atkac fail2ban
cottsay python-bloom
dcavalca python-mathics3 python-mathicsscript
echevemaster python-protego
hobbes1069 fail2ban freecad python-pyside2
jcaratzas python-logutils
jkastner freecad
luya openshadinglanguage
matyas condor
music openshadinglanguage
orion fail2ban
qulogic python-geomet
rebus dionaea python-smbpasswd
rmattes python-bloom
salimma python-rust-update-set
sdyroff python-ansi
slaanesh openshadinglanguage
tmz fail2ban
ttheisen condor
valtri condor
zbyszek python-igor
Details:
condor
======
https://bugzilla.redhat.com/2172684
Bugzilla ASSIGNED half a year ago, no update since.
Maintainer NEEDINFOed today.
Seems to a problem with Boost since Fedora 38.
dionaea
=======
https://bugzilla.redhat.com/2219972
Bugzilla ASSIGNED 2 months ago, no update since.
Maintainer NEEDINFOed last week.
fail2ban
========
https://bugzilla.redhat.com/2219991
https://github.com/fail2ban/fail2ban/issues/3487
Bugzilla ASSIGNED 2 months ago, no update since.
Maintainers NEEDINFOed last week.
freecad
=======
Bugzilla ASSIGNED 2 months ago, no update since.
Maintainer NEEDINFOed last week.
Blocked on pyside2.
openshadinglanguage
===================
https://bugzilla.redhat.com/2220055
Seems to be actively progressing, blocked on this clang15 PR:
https://src.fedoraproject.org/rpms/clang15/pull-request/1
python-ansi
===========
https://bugzilla.redhat.com/2220110
Bugzilla ASSIGNED 2 months ago, no update since.
Maintainers NEEDINFOed last week.
The fix of FTBFS is trivial (BR python3-setuptools, as described in
https://bugzilla.redhat.com/2155030 in December 2022).
However, package has no %check, so I am reluctant to fix it myself, not knowing
if it even works.
python-bloom
============
https://bugzilla.redhat.com/2220133
Maintainer said to retire it last week.
python-geomet
=============
https://bugzilla.redhat.com/2220250
https://github.com/geomet/geomet/issues/92
Bugzilla ASSIGNED 2 months ago, no update since.
Maintainer NEEDINFOed last week.
python-igor
===========
https://bugzilla.redhat.com/2220275
Bugzilla ASSIGNED a month ago, no update since.
Maintainer NEEDINFOed last week.
python-logutils
===============
https://bugzilla.redhat.com/2220313
https://src.fedoraproject.org/rpms/python-logutils/pull-request/2
PR opened a month ago, no progress since.
New maintainer NEEDINFOed this week.
python-mathics3
===============
https://bugzilla.redhat.com/2220323
https://src.fedoraproject.org/rpms/python-mathics3/pull-request/2 (still fails)
Bugzilla ASSIGNED a month ago, no update since.
Maintainer NEEDINFOed last week.
python-mathicsscript
====================
https://bugzilla.redhat.com/2220324
Depends on mathics3
Bugzilla ASSIGNED a month ago, no update since.
Maintainer NEEDINFOed last week.
python-protego
==============
https://bugzilla.redhat.com/2240746
Built in Fedora 39 only (the f39 branch is ahead of rawhide).
I'd normally just go ahead and merge the branches myself,
but the "fix" was to remove all the tests and add redundant manual Requires,
so I am reluctant to do that.
python-pyside2
==============
https://bugzilla.redhat.com/2155447
https://bugzilla.redhat.com/2220452
https://bugreports.qt.io/browse/PYSIDE-2388 (WONTFIX)
Upstream no longer cares about this pyside2 version.
Bugzilla ASSIGNED 2 months ago, no update since.
Maintainer NEEDINFOed last week.
python-rust-update-set
======================
https://bugzilla.redhat.com/2220488
Bugzilla ASSIGNED 2 months ago, no update since.
Maintainer NEEDINFOed last week.
python-smbpasswd
================
https://bugzilla.redhat.com/2154979
Bugzilla ASSIGNED 8 months ago, no update since.
Maintainer NEEDINFOed last week.
---
Packages fixed in Rawhide with Fedora 39 updates in need of karma:
python-box https://bodhi.fedoraproject.org/updates/FEDORA-2023-595f85c4f3
python-click-spinner https://bodhi.fedoraproject.org/updates/FEDORA-2023-39dcc5afea
python-elpy https://bodhi.fedoraproject.org/updates/FEDORA-2023-a999e30051
python-nipy https://bodhi.fedoraproject.org/updates/FEDORA-2023-ed0adf8107
python-pvc https://bodhi.fedoraproject.org/updates/FEDORA-2023-05814fcc72
python-pydocstyle https://bodhi.fedoraproject.org/updates/FEDORA-2023-3703495e43
python-sklearn-genetic-opt
https://bodhi.fedoraproject.org/updates/FEDORA-2023-d8d9f6376a
python-streamlink https://bodhi.fedoraproject.org/updates/FEDORA-2023-0eeb1b6b0e
python-uinput https://bodhi.fedoraproject.org/updates/FEDORA-2023-9ba7c6ba53
python-uvicorn https://bodhi.fedoraproject.org/updates/FEDORA-2023-ae19f823c9
python-uvloop https://bodhi.fedoraproject.org/updates/FEDORA-2023-ae19f823c9
python-ZEO https://bodhi.fedoraproject.org/updates/FEDORA-2023-24d588cf46
python-ZODB3 https://bodhi.fedoraproject.org/updates/FEDORA-2023-24d588cf46
Thanks for your help.
--
Miro Hrončok
--
Phone: +420777974800
IRC: mhroncok
7 months, 1 week
[Test-Announce] 2023-10-02 @ 16:00 UTC - Fedora 39 Blocker Review Meeting
by Adam Williamson
# F39 Blocker Review meeting
# Date: 2023-10-02
# Time: 16:00 UTC
# Location: #fedora-blocker-review on irc.libera.chat (*NOT* Matrix)
Hi folks! We have 7 proposed Final blockers and 3 proposed Final freeze
exception issues to review, so let's have a meeting on Monday.
I will not be around to run the meeting, but I'm hoping somebody else
will volunteer. lruzicka has said he'll do it if nobody else is
available but he'd prefer somebody with native English to do it if
possible. Don't be shy :) The SOP to run the meeting is
https://fedoraproject.org/wiki/QA:SOP_Blocker_Bug_Meeting , it's not
too hard.
The meeting will on IRC only due to the ongoing lack of a Matrix <->
IRC bridge and a meeting bot on the Matrix side. If you no longer have
an IRC setup you can join via webIRC: https://web.libera.chat/ , enter
a nickname and put #fedora-blocker-review in the Channel box.
If you have time this weekend, you can take a look at the proposed or
accepted blockers before the meeting - the full lists can be found
here: https://qa.fedoraproject.org/blockerbugs/ .
Remember, you can also now vote on bugs outside of review meetings! If
you look at the bug list in the blockerbugs app, you'll see links
labeled "Vote!" next to all proposed blockers and freeze exceptions.
Those links take you to tickets where you can vote.
https://pagure.io/fedora-qa/blocker-review has instructions on how
exactly you do it. We usually go through the tickets shortly before the
meeting and apply any clear votes, so the meeting will just cover bugs
where there wasn't a clear outcome in the ticket voting yet. **THIS
MEANS IF YOU VOTE NOW, THE MEETING WILL BE SHORTER!**
We'll be evaluating these bugs to see if they violate any of the
Release Criteria and warrant the blocking of a release if they're not
fixed. Information on the release criteria for F39 can be found on the
wiki [0].
For more information about the Blocker and Freeze exception process,
check out these links:
- https://fedoraproject.org/wiki/QA:SOP_blocker_bug_process
- https://fedoraproject.org/wiki/QA:SOP_freeze_exception_bug_process
And for those of you who are curious how a Blocker Review Meeting
works - or how it's supposed to go and you want to run one - check out
the SOP on the wiki:
- https://fedoraproject.org/wiki/QA:SOP_Blocker_Bug_Meeting
Have a good weekend and someone will see you on Monday, I hope!
[0] https://fedoraproject.org/wiki/Fedora_Release_Criteria
--
Adam Williamson (he/him/his)
Fedora QA
Fedora Chat: @adamwill:fedora.im | Mastodon: @adamw(a)fosstodon.org
https://www.happyassassin.net
_______________________________________________
test-announce mailing list -- test-announce(a)lists.fedoraproject.org
To unsubscribe send an email to test-announce-leave(a)lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/test-announce@lists.fedorap...
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
7 months, 1 week