Fedora eln compose report: 20250402.n.0 changes

2025-04-01 Thread Fedora ELN Report
OLD: Fedora-eln-20250401.n.0 NEW: Fedora-eln-20250402.n.0 = SUMMARY = Added images:0 Dropped images: 0 Added packages: 2 Dropped packages:2 Upgraded packages: 25 Downgraded packages: 0 Size of added packages: 6.02 MiB Size of dropped packages:4.26 MiB

Log your reports for F42 Upgrade Test Days

2025-04-01 Thread Sumantro Mukherjee
Hey All, This is a gentle reminder that we are hosting Upgrade Test Week[0] starting today and going through the whole week. Please record your upgrade experiences in [1] This will help us not only know the problems you faced (if at all any) and then resolve them (if they end up blocking). [0] ht

Re: Summary/Minutes from today's FESCo Meeting (2025-04-01)

2025-04-01 Thread Fabio Valentini
On Tue, Apr 1, 2025 at 9:31 PM Fabio Valentini wrote: > > = > # #meeting:fedoraproject.org: fesco > = > > Meeting started by @decathorpe:fedora.im at 2025-04-01 17:01:10 Forgot to include links to the minutes and full logs:

Summary/Minutes from today's FESCo Meeting (2025-04-01)

2025-04-01 Thread Fabio Valentini
= # #meeting:fedoraproject.org: fesco = Meeting started by @decathorpe:fedora.im at 2025-04-01 17:01:10 Summaries for individual topics provided by decathorpeLLM. 😉 Meeting summary --- * TOPIC: Roll Call (@decath

Re: packaging: prefer git archives to upstream archives for Source

2025-04-01 Thread Ben Beasley
I am very much in favor of continuing to improve reproducibility and auditability in general. However, as a general response to this discussion, I’d like to caution against writing new policies that implicitly rely on any of the following falsehoods: - All upstreams use some kind of forge, with

Re: packaging: prefer git archives to upstream archives for Source

2025-04-01 Thread Alexander Sosedkin
On Mon, Mar 31, 2025 at 9:31 PM Zbigniew Jędrzejewski-Szmek wrote: > > On Mon, Mar 31, 2025 at 01:24:06PM +0200, Alexander Sosedkin wrote: > > On Mon, Mar 31, 2025 at 12:56 PM Zbigniew Jędrzejewski-Szmek > > Just one question: how would you make those git forges output stable > > archives? > > Gi

Fedora 42 is in final freeze

2025-04-01 Thread Samyak Jain
Hi all, Today, 2025-04-01, is an important day on the Fedora Linux 42 schedule [1], with significant cut-offs. Today we have the Final Freeze [2] which starts at 14:00 UTC. This means that only packages which fix accepted blocker or freeze exception bugs [3][4][5] will be marked as 'stable' and in

Re: packaging: prefer git archives to upstream archives for Source

2025-04-01 Thread Carlos Rodriguez-Fernandez
Some static security tooling that restricts the use of binary files during the build, check, and install can help here as an alternative to git archive to mitigate xz kind of attacks (e.g., no binary files use during the build allowed, and can only be copied during the install as long as they a

Schedule for Tuesday's FESCo Meeting (2025-04-01)

2025-04-01 Thread Fabio Valentini
Following is the list of topics that will be discussed in the FESCo meeting Tuesday at 17:00 UTC in #meeting:fedoraproject.org on Matrix. To convert UTC to your local time, take a look at http://fedoraproject.org/wiki/UTCHowto or run: date -d '2025-04-01 17:00 UTC' Links to all issues to be

Re: Automatic detection of unused BuildRequires

2025-04-01 Thread Marián Konček
Reviving this thread. I have had success with this project implemented as a mock plugin [1] (available in copr: [2]). I intend to communicate with mock developers to see if it can be integrated into mock [3]. Implementation notes aside, this may be a good place to discuss the algorithm: On in

Fedora rawhide compose report: 20250401.n.0 changes

2025-04-01 Thread Fedora Rawhide Report
OLD: Fedora-Rawhide-20250331.n.0 NEW: Fedora-Rawhide-20250401.n.0 = SUMMARY = Added images:0 Dropped images: 0 Added packages: 5 Dropped packages:5 Upgraded packages: 105 Downgraded packages: 0 Size of added packages: 3.72 MiB Size of dropped packages

Re: packaging: prefer git archives to upstream archives for Source

2025-04-01 Thread Alexander Sosedkin
On Tue, Apr 1, 2025 at 12:23 PM Daniel P. Berrangé wrote: > > On Tue, Apr 01, 2025 at 10:49:59AM +0200, Alexander Sosedkin wrote: > > On Mon, Mar 31, 2025 at 9:31 PM Zbigniew Jędrzejewski-Szmek > > wrote: > > > > > > On Mon, Mar 31, 2025 at 01:24:06PM +0200, Alexander Sosedkin wrote: > > > > On M

Re: packaging: prefer git archives to upstream archives for Source

2025-04-01 Thread Daniel P . Berrangé
On Tue, Apr 01, 2025 at 10:49:59AM +0200, Alexander Sosedkin wrote: > On Mon, Mar 31, 2025 at 9:31 PM Zbigniew Jędrzejewski-Szmek > wrote: > > > > On Mon, Mar 31, 2025 at 01:24:06PM +0200, Alexander Sosedkin wrote: > > > On Mon, Mar 31, 2025 at 12:56 PM Zbigniew Jędrzejewski-Szmek > > > Just one q

Re: packaging: prefer git archives to upstream archives for Source

2025-04-01 Thread Daniel P . Berrangé
On Mon, Mar 31, 2025 at 07:59:50PM +, Zbigniew Jędrzejewski-Szmek wrote: > To expand on this one: it is true that the untrustworthy maintainer > would have been able to add files to git too. But it is also true that > people may much closer attention to the git commits than to the tarball. In

Re: packaging: prefer git archives to upstream archives for Source

2025-04-01 Thread Michael J Gruber
Michael Catanzaro venit, vidit, dixit 2025-03-31 23:37:42: > On Mon, Mar 31 2025 at 08:09:49 PM +00:00:00, Zbigniew > Jędrzejewski-Szmek wrote: > > OK, I guess I need to work on my English. You're the second person who > > read the abovequoted part in the exact opposite way to what I > > intende