Re: Following up on: Three steps we could take to make supply chain attacks a bit harder

2024-07-31 Thread Gordon Messmer
On 2024-07-31 9:40 AM, Michael Catanzaro wrote: On Wed, Jul 31 2024 at 09:23:12 AM -07:00:00, Kevin Fenzi wrote: Some possible ones I'll toss out there: avahi-daemon cups rsyslog dovecot cockpit Maybe gnome-remote-desktop? Those all sound good to me.  I'll work on opening some more PRs t

Review swap / python

2024-07-31 Thread Michal Ambroz
Hello,  please would be somebody having some spare time to review some of 3 new package requests needed for the upgrade of the python-oletools package to current version 0.60.2 ? For some time I am trying to get to fedora update to current version of oletools, but it requires some new python dep

Fedora rawhide compose report: 20240731.n.1 changes

2024-07-31 Thread Fedora Rawhide Report
OLD: Fedora-Rawhide-20240730.n.0 NEW: Fedora-Rawhide-20240731.n.1 = SUMMARY = Added images:4 Dropped images: 4 Added packages: 7 Dropped packages:1 Upgraded packages: 192 Downgraded packages: 0 Size of added packages: 2.27 MiB Size of dropped packages

Re: [SPDX] Mass license change - variety of licenses and compound formulas

2024-07-31 Thread Miroslav Suchý
Dne 31. 07. 24 v 6:57 odp. Richard Fontana napsal(a): Oh never mind, that is not what you're doing. Still, I am concerned about any mass replacement of Callaway "with exceptions", since that could refer to anything, or did you handle this on a package-by-package basis? Good point. I will remove

please help review some Haskell packages needed for F41

2024-07-31 Thread Jens-Ulrik Petersen
Hi, I am working on wrapping up my Haskell Change for F41 and it would really help me if there following packages could be reviewed quickly so that I can use them to complete the work: NEW ghc-crypton: https://bugzilla.redhat.com/show_bug.cgi?id=2266044 NEW ghc-crypton-x509: https://bugzilla.redha

Re: intermittent RPM metadata regression

2024-07-31 Thread Sandro via devel
On 31-07-2024 18:50, Sandro via devel wrote: On 31-07-2024 17:34, Sandro Mani wrote: See https://bugzilla.redhat.com/show_bug.cgi?id=2302033. The source of the issue is that the Requires: environment(modules) in rpm-mpi-hooks (which is a BuildRequirement of openmpi/mpich) did not result in env

Re: [SPDX] Mass license change - variety of licenses and compound formulas

2024-07-31 Thread Richard Fontana
On Wed, Jul 31, 2024 at 12:52 PM Richard Fontana wrote: > > On Wed, Jul 31, 2024 at 5:13 AM Miroslav Suchý wrote: > > > > Hi. > > > > This is a batch of remaining licenses that allows 1:1 conversion [*]. It > > includes leftovers from previous migrations, > > compound formulas and rarely used li

Re: [SPDX] Mass license change - variety of licenses and compound formulas

2024-07-31 Thread Richard Fontana
On Wed, Jul 31, 2024 at 5:13 AM Miroslav Suchý wrote: > > Hi. > > This is a batch of remaining licenses that allows 1:1 conversion [*]. It > includes leftovers from previous migrations, > compound formulas and rarely used licenses. > > The proposed diff is here https://k00.fr/5i348p12 > Unless s

Re: intermittent RPM metadata regression

2024-07-31 Thread Sandro via devel
On 31-07-2024 17:34, Sandro Mani wrote: See https://bugzilla.redhat.com/show_bug.cgi?id=2302033. The source of the issue is that the Requires: environment(modules) in rpm-mpi-hooks (which is a BuildRequirement of openmpi/mpich) did not result in environment-modules getting installed, which brok

Re: Following up on: Three steps we could take to make supply chain attacks a bit harder

2024-07-31 Thread Michael Catanzaro
On Wed, Jul 31 2024 at 09:23:12 AM -07:00:00, Kevin Fenzi wrote: Some possible ones I'll toss out there: avahi-daemon cups rsyslog dovecot cockpit Maybe gnome-remote-desktop? -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscrib

Re: package maintainers should be using fedpkg-1.45

2024-07-31 Thread Kevin Fenzi
On Tue, Jul 30, 2024 at 01:03:14PM GMT, Jens-Ulrik Petersen wrote: > It seems PDC was turned off about 12 hours ago. yeah, we have actually been disabling it and thinking we were done, but then something still has it's tendrils into it and we re-enable it to fix that, etc. It's now been down for

Re: Following up on: Three steps we could take to make supply chain attacks a bit harder

2024-07-31 Thread Kevin Fenzi
On Mon, Jul 29, 2024 at 03:33:21PM GMT, Gordon Messmer wrote: > tl;dr: Quick update, and one question: Are there other packages that should > be monitored? > > > > On 2024-06-24 9:03 PM, Gordon Messmer wrote: > > (As a topic for later: the tirpc library exports functions with the same > > name a

Re: Schedule for Tuesday's FESCo Meeting (2024-07-23)

2024-07-31 Thread Daniel P . Berrangé
On Wed, Jul 31, 2024 at 05:21:29PM +0200, Vít Ondruch wrote: > > Dne 31. 07. 24 v 15:12 Stephen Gallagher napsal(a): > > On Wed, Jul 31, 2024 at 5:54 AM Vít Ondruch wrote: > > > > > > Dne 24. 07. 24 v 20:17 Stephen Gallagher napsal(a): > > > > On Wed, Jul 24, 2024 at 1:46 PM Miroslav Suchý > >

Re: intermittent RPM metadata regression

2024-07-31 Thread Sandro Mani
Hi See https://bugzilla.redhat.com/show_bug.cgi?id=2302033. The source of the issue is that the Requires: environment(modules) in rpm-mpi-hooks (which is a BuildRequirement of openmpi/mpich) did not result in environment-modules getting installed, which broke the dependency generation by rpm-

Final few hours to complete the Fedora AI/ML Survye

2024-07-31 Thread Aoife Moloney
Hi folks, There are a few hours left today to fill out our short AI/ML survey[1] for Fedora. The Fedora council created this survey to try to understand the sentiment of our community when it comes to using AI/ML for or in the Fedora Projects ecosystem as we intend to create some guidelines for th

Re: Schedule for Tuesday's FESCo Meeting (2024-07-23)

2024-07-31 Thread Vít Ondruch
Dne 31. 07. 24 v 15:12 Stephen Gallagher napsal(a): On Wed, Jul 31, 2024 at 5:54 AM Vít Ondruch wrote: Dne 24. 07. 24 v 20:17 Stephen Gallagher napsal(a): On Wed, Jul 24, 2024 at 1:46 PM Miroslav Suchý wrote: Dne 24. 07. 24 v 12:30 odp. Joe Orton napsal(a): Having a "majority rule" vote o

Re: Schedule for Tuesday's FESCo Meeting (2024-07-23)

2024-07-31 Thread Simon Farnsworth via devel
On Wednesday 31 July 2024 10:53:37 BST Vít Ondruch wrote: > Dne 24. 07. 24 v 20:17 Stephen Gallagher napsal(a): > > > On Wed, Jul 24, 2024 at 1:46 PM Miroslav Suchý wrote: > > > >> Dne 24. 07. 24 v 12:30 odp. Joe Orton napsal(a): > >> > >> > >> > >> Having a "majority rule" vote of e.g. packager

intermittent RPM metadata regression

2024-07-31 Thread Sandro via devel
Hi, It seems something is going on with RPM metadata generation. With the latest update of openmpi the generated metadata has changed: $ rpm -q --provides -p openmpi-5.0.5-1.fc41.x86_64.rpm config(openmpi) = 5.0.5-1.fc41 libmpi.so.40()(64bit) libmpi_java.so.40()(64bit) libmpi_mpifh.so.40()(64bi

Re: Schedule for Tuesday's FESCo Meeting (2024-07-23)

2024-07-31 Thread Stephen Gallagher
On Wed, Jul 31, 2024 at 5:54 AM Vít Ondruch wrote: > > > Dne 24. 07. 24 v 20:17 Stephen Gallagher napsal(a): > > On Wed, Jul 24, 2024 at 1:46 PM Miroslav Suchý wrote: > >> Dne 24. 07. 24 v 12:30 odp. Joe Orton napsal(a): > >> > >> Having a "majority rule" vote of e.g. packagers or provenpackagers

Re: Packages with problematic license tag (for SPDX conversion)

2024-07-31 Thread Miroslav Suchý
Dne 31. 07. 24 v 11:14 dop. Vít Ondruch napsal(a): warning: not valid neither as Callaway nor as SPDX, please check How to reproduce this warning? These lines https://pagure.io/copr/license-validate/blob/main/f/packages-without-spdx-final.txt#_16 My script put it there whenever both:   $

Re: [SPDX] Mass license change - variety of licenses and compound formulas

2024-07-31 Thread Vít Ondruch
Dne 31. 07. 24 v 11:58 Miroslav Suchý napsal(a): Dne 31. 07. 24 v 11:16 dop. Vít Ondruch napsal(a): I probably don't understand right the first one: ~~~ diff -Naur rpm-specs.orig/aces_container.spec rpm-specs/aces_container.spec --- rpm-specs.orig/aces_container.spec    2024-07-18 04:00:12.

Re: [SPDX] Mass license change - variety of licenses and compound formulas

2024-07-31 Thread Miroslav Suchý
Dne 31. 07. 24 v 11:16 dop. Vít Ondruch napsal(a): I probably don't understand right the first one: ~~~ diff -Naur rpm-specs.orig/aces_container.spec rpm-specs/aces_container.spec --- rpm-specs.orig/aces_container.spec    2024-07-18 04:00:12.0 +0200 +++ rpm-specs/aces_container.spec   

Re: Schedule for Tuesday's FESCo Meeting (2024-07-23)

2024-07-31 Thread Vít Ondruch
Dne 24. 07. 24 v 20:17 Stephen Gallagher napsal(a): On Wed, Jul 24, 2024 at 1:46 PM Miroslav Suchý wrote: Dne 24. 07. 24 v 12:30 odp. Joe Orton napsal(a): Having a "majority rule" vote of e.g. packagers or provenpackagers on major technical decisions would be far superior, in my view. Apache

Re: [SPDX] Mass license change - variety of licenses and compound formulas

2024-07-31 Thread Vít Ondruch
I probably don't understand right the first one: ~~~ diff -Naur rpm-specs.orig/aces_container.spec rpm-specs/aces_container.spec --- rpm-specs.orig/aces_container.spec    2024-07-18 04:00:12.0 +0200 +++ rpm-specs/aces_container.spec    2024-07-31 10:52:00.694637327 +0200 @@ -3,10 +3,11

Re: Packages with problematic license tag (for SPDX conversion)

2024-07-31 Thread Vít Ondruch
Dne 30. 07. 24 v 16:07 Miroslav Suchý napsal(a): As the SPDX Change slowly finishes I focused on the license that I regularly report as:   warning: not valid neither as Callaway nor as SPDX, please check How to reproduce this warning? Vít OpenPGP_signature.asc Description: OpenPGP di

[SPDX] Mass license change - variety of licenses and compound formulas

2024-07-31 Thread Miroslav Suchý
Hi. This is a batch of remaining licenses that allows 1:1 conversion [*]. It includes leftovers from previous migrations, compound formulas and rarely used licenses. The proposed diff is here https://k00.fr/5i348p12 Affected packages: https://k00.fr/zszrcmgr Unless somebody stop me, I will

Re: Packages with problematic license tag (for SPDX conversion)

2024-07-31 Thread Petr Pisar
V Tue, Jul 30, 2024 at 05:46:56PM -0400, Richard Fontana napsal(a): > On Tue, Jul 30, 2024 at 1:24 PM Richard Shaw wrote: > > > >> perl-RPC-XML hobbes1069 jplesnik ppisar > > > > This one I have no idea what to do with: > > License:(Artistic 2.0 or Artistic or LGPLv2) and (Artistic 2.0