Re: Workflow changes proposal for 2025

2025-01-14 Thread Thorsten Alteholz
Hi, so, here are my two cents: 1.1. I am fine with dh-make-golang introducing something new. I agree that it might be nice to change branch names when packages get an update. I wouldn't like this to become mandatory. I am afraid I have no time nor motivation to update old packages just due to

Re: RFS: Security patch for GitHub CLI client gh

2024-12-31 Thread Thorsten Alteholz
On 31.12.24 12:17, Loren M. Lang wrote: As I am relatively new to the Go Team, I chose to keep it to a smaller, easier to review, change which resolved the CVE with the highest score. That was the only CVE that lead to a Debian bug of severity grave and threatened to remove it from testing in

Re: RFS: Security patch for GitHub CLI client gh

2024-12-31 Thread Thorsten Alteholz
Hi Otto, On 31.12.24 10:59, Otto Kekäläinen wrote: Loren's message was posted at 2am my time zone, and Santiago had already done the upload by 5:30am my time zone. It is completely unreasonable to expect responses in a matter of hours regardless of the time zones. You agree this wasn't collabor

Re: RM'ing golang-github-grafana-grafana-plugin-model?

2024-07-28 Thread Thorsten Alteholz
Hi Mathias, On 28.07.24 08:18, Mathias Gibbens wrote: Rather than patching up this library, would it be OK with you if we filed a RM bug to remove it from the archive? yes, please do so.   Thorsten

Re: [WIP] golang-github-zmap-zcrypto

2024-06-19 Thread Thorsten Alteholz
On 19.06.24 13:59, Reinhard Tartler wrote: CC: ftp-master -- do you have records of a rejected package golang-github-zmap-zcrypto from Jun 2021? Where could I look up the rejection message, if there was any? No, I didn't find anything. At least the reject would be in the logfiles on coccia.

Re: RFC: Fixing golang-github-tidwall-gjson's RC bugginess for bookworm

2023-03-04 Thread Thorsten Alteholz
Hi Cyril, On Sun, 5 Mar 2023, Cyril Brulebois wrote: TL;DR, current plan: 1. upload 1.14.4-1 to experimental; 2. watch for fallouts; 3. decide what to consider for unstable and put the release team in the loop. Comments, yay, nay, alternative takes, etc. are welcome! as you seem to have do

Re: security updates of Golang packages

2022-04-25 Thread Thorsten Alteholz
On Mon, 25 Apr 2022, Shengjing Zhu wrote: If you look at package crowdsec, you find no dependency on golang-github-tidwall-gjson in its Built-Using:, but only an entry for golang-github-appleboy-gin-jwt. golang-github-appleboy-gin-jwt for its part depends on golang-github-tidwall-gjson-dev.

Re: security updates of Golang packages

2022-04-24 Thread Thorsten Alteholz
On Mon, 25 Apr 2022, Shengjing Zhu wrote: For binNMU, it's also possible to add Dep-Wait. Hmm, but that would be some manually work, wouldn't it? I don't have a preference for it. And I think binNMU is not friendly to Debian derivatives. Ok, that is a good point. For ratt and other pac

Re: security updates of Golang packages

2022-04-24 Thread Thorsten Alteholz
Hi, On 24.04.22 15:21, Shengjing Zhu wrote: Do you want to 1. Rebuild package to carry fixed CVE in dependencies 2. Fix CVE in library and then go through 1 I first fix the CVE in the affected package and than look at the list of packages that use it directly or via some kind of dependency c

security updates of Golang packages

2022-04-24 Thread Thorsten Alteholz
Hi everybody, some time ago, before the release of Buster, the Release Team and the Security Team critizied the missing tooling for security updates of Golang packages[1]. I would like to improve the situation here and try to develop some scripts to automatically rebuild/upload affected packag

Re: disruptive uploads

2021-08-28 Thread Thorsten Alteholz
On 28.08.21 18:03, Reinhard Tartler wrote: now that the freeze is over, and bookworm is open for development, any objections to uploading golang-github-vbauerster-mpb 6 to sid? -- I understand that it will require some dependent packages to get updated and might be a bit disruptive. Any tho

Re: expired certificate

2021-07-16 Thread Thorsten Alteholz
Hi Tianon, On Fri, 16 Jul 2021, Tianon Gravi wrote: I'm not sure who maintains it, but an issue on https://github.com/Debian/dh-make-golang is probably going to be more effective at reaching them. ok, it is issue #163 now. Thorsten

Re: expired certificate

2021-07-16 Thread Thorsten Alteholz
Hi Nilesh, thanks for checking. It is good to know that the problem is not sitting in front of my monitor. As far as I understood the docu, such redirections should automatically disappear when a real object with that name is created. Thorsten

expired certificate

2021-07-16 Thread Thorsten Alteholz
Hi everybody, does anybody know how to fix: $ dh-make-golang create-salsa-project golang-gonum-v1-gonum 2021/07/16 21:40:13 Post https://pgt-api-server.debian.net/v1/createrepo?repo=golang-gonum-v1-gonum: x509: certificate has expired or is not yet valid Or am I the only one having such prob

golang-raven-go

2020-12-17 Thread Thorsten Alteholz
Hi team, for a new package I need to update golang-raven-go to the newest version 0.2.0. Among others this version now depends on "github.com/certifi/gocertifi". Some time ago[1] Praveen suggested not to package this but use the system CA bundle instead. From my point of view this sounds reaso

Re: gopasspw packaging (#901133)

2020-01-19 Thread Thorsten Alteholz
Hi, On Fri, 17 Jan 2020, Balasankar "Balu" C wrote: 2. github.com/hashicorp/vault vault is a bit big[0] and a bit tricky. gopasspw does not require the entire vault codebase, but parts of it. Specifically things from api[1] and sdk[2] directories. isn't your vault related to [1]? Probably tha

Re: RFS: golang-gopkg-libgit2-git2go.v28/0.28+git20190813.37e5b53-1

2019-09-01 Thread Thorsten Alteholz
On Fri, 23 Aug 2019, Jongmin Kim wrote: libgit2-dev (0.28.1+dfsg.1-0.1) is available in experimental, right now. aah, ok, I didn't saw that. Could you please try again with it? and done Thorsten

Re: RFS: golang-github-rivo-tview/0.0~git20190829.f8bc69b-1 and its 1 dependency

2019-09-01 Thread Thorsten Alteholz
On Sat, 31 Aug 2019, Jongmin Kim wrote: The packages are on: https://salsa.debian.org/go-team/packages/golang-github-rivo-uniseg done Thorsten

Re: RFS: lazygit [ITP] and its 1 dependency

2019-08-26 Thread Thorsten Alteholz
Hi, lazygit: https://salsa.debian.org/go-team/packages/lazygit done But lintian says: I: lazygit: spelling-error-in-binary usr/bin/lazygit expresssion expression I: lazygit: spelling-error-in-binary usr/bin/lazygit erorr error which might be nice to fix ... Thorsten

Re: RFS: golang-gopkg-libgit2-git2go.v28/0.28+git20190813.37e5b53-1

2019-08-21 Thread Thorsten Alteholz
Hi, On Wed, 21 Aug 2019, Jongmin Kim wrote: The package is on: https://salsa.debian.org/go-team/packages/golang-gopkg-libgit2-git2go there seems to be something missing: The following packages have unmet dependencies: pbuilder-satisfydepends-dummy : Depends: libgit2-dev (> 0.28~) but it

Re: RFS: lazygit [ITP] and its 1 dependency

2019-08-21 Thread Thorsten Alteholz
Hi, On Wed, 21 Aug 2019, Jongmin Kim wrote: I'm looking for a sponsor for two packages: * golang-github-jesseduffield-gocui (update to 0.3.0+git20190622.e030e03-1) done golang-github-nicksnyder-go-i18n.v2 <-- NEW, pending upload (#931221) done, but please mention the unicode stuff i

Re: Revert some Go packages in unstable to align with testing/buster

2019-06-08 Thread Thorsten Alteholz
Hi everybody, On Wed, 5 Jun 2019, Paul Gevers wrote: One other problem is that tools are lacking to schedule binNMUs on the right packages in an efficient manner and in the right order. I just added [1]. It contains one simple shell script to calculate the build order of golang packages, for

Re: Revert some Go packages in unstable to align with testing/buster

2019-06-01 Thread Thorsten Alteholz
Hi everybody, On Sat, 1 Jun 2019, Paul Gevers wrote: On that topic, I'd like to take this opportunity to say that soon after the release of buster we will most likely remove Go and it's reverse dependencies from testing and prevent them from entering again until the infrastructure issues are sol

Re: ITP: golang-github-anacrolix-dms-dev -- a UPnP DLNA Digital Media Server that includes basic video transcoding

2019-05-03 Thread Thorsten Alteholz
On Fri, 3 May 2019, Drew Parsons wrote: How important do you consider dlna support in rclone? I don't use rclone yet, but when looking at the description "rsync for commercial cloud storage", I would be very surprised to get a DLNA server as well. Thorsten

Re: RFS: golang-github-mgutz-str

2019-04-29 Thread Thorsten Alteholz
On Sun, 21 Apr 2019, Jongmin Kim wrote: https://salsa.debian.org/go-team/packages/golang-github-mgutz-str The package was tested on both gbp and sbuild. It's also lintian-clean. Please consider to review and upload it. ... and uploaded. Thorsten

Re: RFS: golang-github-src-d-gcfg

2019-04-27 Thread Thorsten Alteholz
On Sun, 21 Apr 2019, Jongmin Kim wrote: https://salsa.debian.org/go-team/packages/golang-github-src-d-gcfg Please consider to review and upload it. ... and uploaded. Thorsten

Re: RFS: golang-github-muesli-crunchy

2019-04-27 Thread Thorsten Alteholz
On Fri, 19 Apr 2019, Balasankar C wrote: Thanks for taking a look. I got upstream to tag a new version and have updated the package to it. Can you try again, please? Now I could build the package and it looks good. Thorsten

Re: RFS: golang-github-mgutz-to/1.0.0-1

2019-04-27 Thread Thorsten Alteholz
On Fri, 19 Apr 2019, Dawid Dziurla wrote: I pushed to our team's Salsa: https://salsa.debian.org/go-team/packages/golang-github-mgutz-to Could you please reviewing/sponsoring this? ... and uploaded. Thorsten

Re: RFS: golang-github-cloudfoundry-jibber-jabber/0.0~git20151120.bcc4c83-1

2019-04-18 Thread Thorsten Alteholz
On Mon, 18 Mar 2019, Dawid Dziurla wrote: I pushed to our team's Salsa: https://salsa.debian.org/go-team/packages/golang-github-cloudfoundry-jibber-jabber Could you please reviewing/sponsoring this? you forgot a copyright holder in your debian/copyright Thorsten

Re: RFS: golang-github-nozzle-throttler/1.1-1

2019-04-18 Thread Thorsten Alteholz
On Mon, 18 Mar 2019, Dawid Dziurla wrote: I pushed to our team's Salsa: https://salsa.debian.org/go-team/packages/golang-github-nozzle-throttler Could you please reviewing/sponsoring this? ... and uploaded. Thorsten

Re: RFS: golang-gopkg-src-d-go-billy.v4/4.3.0-1

2019-04-18 Thread Thorsten Alteholz
On Mon, 18 Mar 2019, Dawid Dziurla wrote: I pushed to our team's Salsa: https://salsa.debian.org/go-team/packages/golang-gopkg-src-d-go-billy.v4 Could you please reviewing/sponsoring this? ... and uploaded. Thorsten

Re: RFS: golang-github-jesseduffield-gocui

2019-04-18 Thread Thorsten Alteholz
On Thu, 18 Apr 2019, Jongmin Kim wrote: Fixed, thanks! ... and uploaded. Thorsten

Re: RFS: golang-github-jesseduffield-gocui

2019-04-17 Thread Thorsten Alteholz
On Sun, 14 Apr 2019, Jongmin Kim wrote: https://salsa.debian.org/go-team/packages/golang-github-jesseduffield-gocui this shows: gbp:info: Cloning from 'https://salsa.debian.org/go-team/packages/golang-github-jesseduffield-gocui' gbp:info: Running Postclone hook W: Paket golang-github-jesse

Re: RFS: golang-github-gliderlabs-ssh/0.1.3-1

2019-04-17 Thread Thorsten Alteholz
On Mon, 18 Mar 2019, Dawid Dziurla wrote: I pushed to our team's Salsa: https://salsa.debian.org/go-team/packages/golang-github-gliderlabs-ssh Could you please reviewing/sponsoring this? ... and uploaded. Thorsten

Re: Updating golang packages

2019-04-17 Thread Thorsten Alteholz
On Tue, 16 Apr 2019, Tong Sun wrote: Could you check it for me again please? ... and uploaded. Thorsten

Re: Updating golang packages

2019-04-16 Thread Thorsten Alteholz
On Tue, 16 Apr 2019, Tong Sun wrote: Yes, I've fixed everything upstream & locally, and it went through sbuild just fine, with manpage in the binary package. There is no man page in my version of the package: debian@devtime:~/golang/sponsor/p005$ dpkg -c easygen_3.0.0+git20180723.75369c3-1

Re: Bug#924783: RFS: golang-github-anmitsu-go-shlex/0.0~git20161002.648efa6-1

2019-04-14 Thread Thorsten Alteholz
On Sun, 14 Apr 2019, Dawid Dziurla wrote: Anyway. Done. ... and uploaded. Thorsten

Re: Bug#924893: RFS: golang-github-emirpasic-gods/1.12.0-1

2019-04-14 Thread Thorsten Alteholz
On Sun, 14 Apr 2019, Dawid Dziurla wrote: Changes pushed to salsa. Can you please also take care of: I: golang-github-emirpasic-gods-dev: description-synopsis-might-not-be-phrased-properly "Implementation of various data structures and algorithms in Go." Thorsten

Re: RFS: golang-github-muesli-crunchy

2019-04-14 Thread Thorsten Alteholz
Hi, this happens during gbp clone: gbp:info: Cloning from 'https://salsa.debian.org/go-team/packages/golang-github-muesli-crunchy' gbp:info: Running Postclone hook W: Unable to locate package golang-github-muesli-crunchy Trying uscan --download --download-current-version ... uscan warn: In de

Re: RFS: golang-github-jesseduffield-termbox-go

2019-04-14 Thread Thorsten Alteholz
On Sun, 14 Apr 2019, Jongmin Kim wrote: I noticed that the package was uploaded, however there is no "debian/0.0_git20180919.1e272ff-1" tag to commit 2bf90742 in Salsa yet. Could I tag this myself? Normally I set such tags only after the package has left NEW. As I am also lazy, yes, please d

Re: RFS: golang-github-michaeltjones-walk/0.0~git20161122.4748e29-1

2019-04-14 Thread Thorsten Alteholz
Hi Dawid On Sun, 14 Apr 2019, Dawid Dziurla wrote: It should be fixed now. yes, great, but please take care of: I: golang-github-michaeltjones-walk-dev: using-first-person-in-description line 2: my I: golang-github-michaeltjones-walk-dev: using-first-person-in-description line 4: we as wel

Re: Bug#924783: RFS: golang-github-anmitsu-go-shlex/0.0~git20161002.648efa6-1

2019-04-14 Thread Thorsten Alteholz
On Sun, 14 Apr 2019, Dawid Dziurla wrote: Fix pushed to salsa. ok, better, but now lintian complains about: I: golang-github-anmitsu-go-shlex-dev: description-synopsis-might-not-be-phrased-properly "Library to make a lexical analyzer like Unix shell for golang." I: golang-github-anmitsu-go

Re: Bug#924618: RFS: golang-github-kevinburke-ssh-config/0.5-1

2019-04-14 Thread Thorsten Alteholz
On Sun, 14 Apr 2019, Dawid Dziurla wrote: Done as requested. ... and uploaded Thorsten

Re: RFS: golang-github-michaeltjones-walk/0.0~git20161122.4748e29-1

2019-04-14 Thread Thorsten Alteholz
Hi Dawid, On Sun, 17 Mar 2019, Dawid Dziurla wrote: https://salsa.debian.org/go-team/packages/golang-github-michaeltjones-walk is it me or are your watch files broken: gbp:info: Running Postclone hook W: Paket golang-github-michaeltjones-walk kann nicht gefunden werden. Trying uscan --down

Re: RFS: golang-github-emirpasic-gods/1.12.0-1

2019-04-14 Thread Thorsten Alteholz
Hi dawid, On Mon, 18 Mar 2019, Dawid Dziurla wrote: https://salsa.debian.org/go-team/packages/golang-github-emirpasic-gods please also mention at least trees/avltree/avltree.go:// Copyright (c) 2017, Benjamin Scher Purcell. All rights reserved. trees/avltree/iterator.go:// Copyright (c) 20

Re: RFS: golang-github-kevinburke-ssh-config/0.5-1

2019-04-14 Thread Thorsten Alteholz
Hi Dawid, On Fri, 15 Mar 2019, Dawid Dziurla wrote: https://salsa.debian.org/go-team/packages/golang-github-kevinburke-ssh-config please also mention at least Copyright (c) 2013 - 2017 Thomas Pelletier, Eric Anderton in your debian/copyright. Thorsten

Re: RFS: golang-github-anmitsu-go-shlex/0.0~git20161002.648efa6-1

2019-04-14 Thread Thorsten Alteholz
Hi Dawid, On Sun, 17 Mar 2019, Dawid Dziurla wrote: https://salsa.debian.org/go-team/packages/golang-github-anmitsu-go-shlex gbp clone says: gbp:info: Running Postclone hook W: Unable to locate package golang-github-anmitsu-go-shlex Trying uscan --download --download-current-version ... u

Re: RFS: golang-github-hashicorp-go-safetemp, golang-github-fzambia-sentinel

2019-04-14 Thread Thorsten Alteholz
On Thu, 11 Apr 2019, Aman Verma wrote: https://salsa.debian.org/go-team/packages/golang-github-hashicorp-go-safetemp https://salsa.debian.org/go-team/packages/golang-github-fzambia-sentinel ok, uploaded both. Thorsten

Re: RFS: golang-github-jesseduffield-termbox-go

2019-04-13 Thread Thorsten Alteholz
On Sun, 14 Apr 2019, Jongmin Kim wrote: https://salsa.debian.org/go-team/packages/golang-github-jesseduffield-termbox-go This gives: I: golang-github-jesseduffield-termbox-go source: unused-file-paragraph-in-dep5-copyright paragraph at line 10 which is strange and probably just a matter

Re: RFS: golang-github-jesseduffield-pty

2019-04-13 Thread Thorsten Alteholz
On Sun, 14 Apr 2019, Jongmin Kim wrote: gbp clone uscan --force-download # for downloading the upstream tarball the new-workflow-document suggest to put "postclone=origtargz" into gbp.conf. Would the options used there (--download --download-current-version) produce the exact orig.

Re: RFS: golang-github-jesseduffield-pty

2019-04-13 Thread Thorsten Alteholz
Hi everybody, up to now, I never did anything with packages that are built according to the new workflow. So can you please confirm that: gbp clone gbp buildpackage --git-pbuilder is the way to go? Wouldn't it be good to have a "pristine-tar=false" in the debian/gbp.conf as well to overrid