Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-12-18 Thread Sérgio Basto
On Tue, 2018-12-18 at 15:16 -0500, Neal Gompa wrote: > On Tue, Dec 18, 2018 at 3:10 PM Sérgio Basto > wrote: > > > > Hi, (sorry for duplicates I sent from wrong email before) > > > > Nothing happened last week . > > > > Can you add me to https://pagure.io/FedoraReview/ and to > > https://src.fe

Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-12-18 Thread Neal Gompa
On Tue, Dec 18, 2018 at 3:10 PM Sérgio Basto wrote: > > Hi, (sorry for duplicates I sent from wrong email before) > > Nothing happened last week . > > Can you add me to https://pagure.io/FedoraReview/ and to > https://src.fedoraproject.org/rpms/fedora-review please . > > My fas user is sergiomb ,

Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-12-18 Thread Sérgio Basto
Hi, (sorry for duplicates I sent from wrong email before) Nothing happened last week . Can you add me to https://pagure.io/FedoraReview/ and to https://src.fedoraproject.org/rpms/fedora-review please . My fas user is sergiomb , people want revert mock configurations of RPMFusion because is not

Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-12-11 Thread Sérgio Basto
On Tue, 2018-12-11 at 16:36 -0500, Neal Gompa wrote: > On Tue, Dec 11, 2018 at 10:30 AM Sérgio Basto > wrote: > > > > Hi, > > > > Any news ? > > > > "But I guess nothing's getting released, for some reason? fedora- > > review has been on version 0.6.1 since May 2016; all package > > activity si

Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-12-11 Thread Neal Gompa
On Tue, Dec 11, 2018 at 10:30 AM Sérgio Basto wrote: > > Hi, > > Any news ? > > "But I guess nothing's getting released, for some reason? fedora-review has > been on version 0.6.1 since May 2016; all package activity since then has > been housekeeping rebuilds. " > > may you add me as admin to F

Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-12-11 Thread Sérgio Basto
Hi, Any news ? "But I guess nothing's getting released, for some reason? fedora-review has been on version 0.6.1 since May 2016; all package activity since then has been housekeeping rebuilds. " may you add me as admin to Fedora-review package ? to release a new version . Thanks On Sat, 2018-08-

Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-08-18 Thread Jeff Johnson
To answer your question solely because I don't like FUD driven phears monger int discussions RPM based depsolvers select packages based on heuristics, including what is already installed. Any malicious package that had Provides: glibc would most likely be ignored because glibc is already insta

Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-08-18 Thread Stephen Gallagher
On Fri, Aug 17, 2018 at 2:08 PM Richard W.M. Jones wrote: > > While I agree that this is a good idea, I have one note of caution: > What's to stop someone adding a malicious package which did something > like ‘Provides: glibc’ and subsequently infects everyone's machine? > I think we'd want to co

Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-08-17 Thread Fabio Valentini
On Fri, Aug 17, 2018, 20:53 Richard W.M. Jones wrote: > > While I agree that this is a good idea, I have one note of caution: > What's to stop someone adding a malicious package which did something > like ‘Provides: glibc’ and subsequently infects everyone's machine? > I think we'd want to consid

Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-08-17 Thread Richard W.M. Jones
While I agree that this is a good idea, I have one note of caution: What's to stop someone adding a malicious package which did something like ‘Provides: glibc’ and subsequently infects everyone's machine? I think we'd want to consider the security implications of accepting packages after only aut

Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-08-16 Thread Ben Rosser
On Thu, Aug 16, 2018 at 4:09 PM, Stephen Gallagher wrote: > I'd *really* like to see us get to a point where package review is > fully-automated. Basically we could just have a web-service that you pass a > URL to an SRPM plus authenticate with your FAS account and it will perform > all of the val

Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-08-16 Thread Michal Novotny
On Thu, Aug 16, 2018 at 11:09 PM Neal Gompa wrote: > On Thu, Aug 16, 2018 at 5:04 PM Stephen Gallagher > wrote: > > > > > > > > On Thu, Aug 16, 2018 at 8:30 AM Michal Novotny wrote: > >> > >> On Thu, Aug 16, 2018 at 10:49 AM Zbigniew Jędrzejewski-Szmek < > zbys...@in.waw.pl> wrote: > >>> > >>>

Re: Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-08-16 Thread Neal Gompa
On Thu, Aug 16, 2018 at 5:04 PM Stephen Gallagher wrote: > > > > On Thu, Aug 16, 2018 at 8:30 AM Michal Novotny wrote: >> >> On Thu, Aug 16, 2018 at 10:49 AM Zbigniew Jędrzejewski-Szmek >> wrote: >>> >>> f-r currently fails to build (#1603956), it has a bunch of bugs open [1] >>> and many issue

Automating Package Review (Was: fedora-review -- do we have a maintainer?)

2018-08-16 Thread Stephen Gallagher
On Thu, Aug 16, 2018 at 8:30 AM Michal Novotny wrote: > On Thu, Aug 16, 2018 at 10:49 AM Zbigniew Jędrzejewski-Szmek < > zbys...@in.waw.pl> wrote: > >> f-r currently fails to build (#1603956), it has a bunch of bugs open [1] >> and many issues and unhandled pull requests in the upstream repo [2,