On Tue, Feb 05, 2019 at 09:18:23AM +0000, Zbigniew Jędrzejewski-Szmek wrote:
>
> == Scope ==
> * Proposal owners:
> ** Add python SWID tools (swidq, rpm2swidtag)
Does "add" mean "package" here? Or are they to be added to some
other
package? Are the review requests / pull requests to be reviewed
somewhere?
New package is what we are thinking about. I don't have review
request yet, the upstream development currently happens at
https://github.com/swidtags/rpm2swidtag
and I have a couple more things to flesh out before being ready for review.
> ** add SWID metadata awareness to createrepo (but this will not
be
Do you mean createrepo_c? createrepo is going away.
Yes. Is it OK to update the change page to fix that?
> used in Fedora, only enabled for user use), agreeing metadata
format
> with dnf team
F30 beta is in exactly 2 weeks. I doubt "agreeing" and implementation
can happen in this timeframe. It should be OK to put in parts of the
implementation, even if things are not complete for this release.
But for "advertising purposes", maybe it's better to bump it to F31,
so that we don't advertise something that is not fully implemented?
> ** add dnf and libdnf plugins (no core dnf/libdnf changes expected)
A bit more detail here would be useful.
The latest improvements to dnf and libdnf plugin API seems to cover
everything that we need to be able to generate SWID tags locally
after every transaction, as well as pull in SWID tags from repository
metadata, if present.
--
Jan Pazdziora
Senior Principal Software Engineer, Security Engineering, Red Hat