15:00:54 <decathorpe> #startmeeting Stewardship SIG Meeting (2019-05-28) 15:00:54 <zodbot> Meeting started Tue May 28 15:00:54 2019 UTC. 15:00:54 <zodbot> This meeting is logged and archived in a public location. 15:00:54 <zodbot> The chair is decathorpe. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:54 <zodbot> Useful Commands: #action #agreed #halp #info #idea #link #topic. 15:00:54 <zodbot> The meeting name has been set to 'stewardship_sig_meeting_(2019-05-28)' 15:01:05 <decathorpe> #meetingname stewardship-sig 15:01:05 <zodbot> The meeting name has been set to 'stewardship-sig' 15:01:16 <decathorpe> #topic Roll Call 15:03:10 <mhroncok> decathorpe: hey 15:05:04 <decathorpe> hi :) 15:05:10 <decathorpe> #chair mhroncok 15:05:10 <zodbot> Current chairs: decathorpe mhroncok 15:06:09 <decathorpe> alright, I don't think there's anything urgent to discuss 15:06:14 <decathorpe> #topic Agenda 15:06:36 <decathorpe> #link https://pagure.io/stewardship-sig/issue/28 15:08:08 * mhroncok looks at the bugz 15:08:14 <mhroncok> jetty has CVEs 15:08:35 <decathorpe> again? it's not our problem anymore 15:10:00 <mhroncok> decathorpe: oh. the bugzillas are still assigned to stewardship sig 15:10:47 <decathorpe> good, we can reassign them 15:11:35 <mhroncok> decathorpe: to mbooth? 15:11:45 <decathorpe> I think he took jetty? 15:11:48 <decathorpe> so yes 15:12:41 <mhroncok> done 15:13:50 <decathorpe> thanks! 15:14:24 <decathorpe> there's only two other things I wanted to talk about: my open PRs and the incomplete dep check 15:15:05 <decathorpe> did you have a chance to look at the PRs? or should we assign them to somebody who isn't here? ;) 15:16:09 <mhroncok> decathorpe: no, send links please (I was not doing any stewardship SIG work recently and neither I was following it much, sorry) 15:19:36 <cipherboy> Sorry, I'm here now. 15:20:08 <decathorpe> #chair cipherboy 15:20:08 <zodbot> Current chairs: cipherboy decathorpe mhroncok 15:20:16 <decathorpe> no need to apologise :) 15:20:43 <mhroncok> decathorpe: there is too many PRs, do you have some particular ones in mind? 15:20:57 <decathorpe> yes. just a sec, I need to find the links 15:22:21 <cipherboy> For third component bumps, do we just want to ACK/NACK them based on the COPR build script? 15:22:39 <cipherboy> (x.y.z+1) 15:22:58 <decathorpe> https://src.fedoraproject.org/rpms/maven-dependency-tree/pull-request/1 15:22:58 <decathorpe> https://src.fedoraproject.org/rpms/maven-parent/pull-request/1 15:22:58 <decathorpe> https://src.fedoraproject.org/rpms/maven-resolver/pull-request/2 15:22:58 <decathorpe> https://src.fedoraproject.org/rpms/apache-parent/pull-request/1 15:22:58 <decathorpe> https://src.fedoraproject.org/rpms/plexus-classworlds/pull-request/1 15:25:02 <decathorpe> micro/latch-level updates should be fine if we do basic sanity checks with the script, I guess. but we can always check if the packages have already been updated for MBI 15:25:08 <decathorpe> or the javapackages branch 15:26:13 <decathorpe> maybe the links aren't all up to date, I resubmitted some PRs to resolve merge conflicts. 15:26:23 <mhroncok> decathorpe: all but one are +1ed by me now 15:26:34 <mhroncok> decathorpe: also, I would only do f30 updates when asked to 15:26:37 <mhroncok> not by default 15:28:26 <decathorpe> yes, I agree 15:28:29 <decathorpe> only rawhide 15:28:55 <decathorpe> except to fix f30 FTBFS issues 15:29:00 <cipherboy> Sure, ACK from me. 15:30:16 <decathorpe> perfect, thanks 15:31:53 <mhroncok> decathorpe: as for our script, i porpose we stop dropping packages unless we fix it 15:31:59 <decathorpe> yes 15:32:20 <decathorpe> or double-check with dnf repoquery manually 15:32:27 <cipherboy> Sure; do we have a description of the issue? 15:32:41 <mhroncok> cipherboy: it reports false leaves 15:33:09 <cipherboy> Which script? 15:34:32 <decathorpe> generate_report.py 15:35:05 <cipherboy> OK, I'll try to take a look later. Might not get to it to next week. 15:35:28 <decathorpe> thanks! 15:35:28 <decathorpe> somehow it missed the transitive dependency from gradle to apache-commons-discovery 15:37:03 <decathorpe> I think I did sanity checks before I orphaned packages, but I seem to have missed this 15:37:42 <cipherboy> Yeah, sounds like we're not building enough of a rpm graph, but I'll take a look. 15:38:18 <decathorpe> the script checks (build) requires, recommends, and suggests. 15:38:29 <decathorpe> the only thing missing might be some weird Boolean dependency stuff ... 15:38:48 <cipherboy> Hmm ok. Not (yet) familiar with it, so we'll see. 15:39:43 <mhroncok> decathorpe: anything else? 15:39:47 <decathorpe> yeah. I have no idea why it doesn't work (and this is the only time this happened so far) 15:40:13 <decathorpe> mhroncok: I don't think so 15:40:52 <cipherboy> CVEs was my only issue, but glad they weren't for us. 15:42:02 <decathorpe> and I pushed your fixes for c3p0 to stable yesterday 15:42:07 <decathorpe> thanks again for the PRs 15:45:46 <decathorpe> let's close this meeting then. if we forgot anything, feel free to open a ticket and assign it to me. 15:45:59 <decathorpe> #endmeeting