15:00:54 #startmeeting Stewardship SIG Meeting (2019-05-28) 15:00:54 Meeting started Tue May 28 15:00:54 2019 UTC. 15:00:54 This meeting is logged and archived in a public location. 15:00:54 The chair is decathorpe. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:54 Useful Commands: #action #agreed #halp #info #idea #link #topic. 15:00:54 The meeting name has been set to 'stewardship_sig_meeting_(2019-05-28)' 15:01:05 #meetingname stewardship-sig 15:01:05 The meeting name has been set to 'stewardship-sig' 15:01:16 #topic Roll Call 15:03:10 decathorpe: hey 15:05:04 hi :) 15:05:10 #chair mhroncok 15:05:10 Current chairs: decathorpe mhroncok 15:06:09 alright, I don't think there's anything urgent to discuss 15:06:14 #topic Agenda 15:06:36 #link https://pagure.io/stewardship-sig/issue/28 15:08:08 * mhroncok looks at the bugz 15:08:14 jetty has CVEs 15:08:35 again? it's not our problem anymore 15:10:00 decathorpe: oh. the bugzillas are still assigned to stewardship sig 15:10:47 good, we can reassign them 15:11:35 decathorpe: to mbooth? 15:11:45 I think he took jetty? 15:11:48 so yes 15:12:41 done 15:13:50 thanks! 15:14:24 there's only two other things I wanted to talk about: my open PRs and the incomplete dep check 15:15:05 did you have a chance to look at the PRs? or should we assign them to somebody who isn't here? ;) 15:16:09 decathorpe: no, send links please (I was not doing any stewardship SIG work recently and neither I was following it much, sorry) 15:19:36 Sorry, I'm here now. 15:20:08 #chair cipherboy 15:20:08 Current chairs: cipherboy decathorpe mhroncok 15:20:16 no need to apologise :) 15:20:43 decathorpe: there is too many PRs, do you have some particular ones in mind? 15:20:57 yes. just a sec, I need to find the links 15:22:21 For third component bumps, do we just want to ACK/NACK them based on the COPR build script? 15:22:39 (x.y.z+1) 15:22:58 https://src.fedoraproject.org/rpms/maven-dependency-tree/pull-request/1 15:22:58 https://src.fedoraproject.org/rpms/maven-parent/pull-request/1 15:22:58 https://src.fedoraproject.org/rpms/maven-resolver/pull-request/2 15:22:58 https://src.fedoraproject.org/rpms/apache-parent/pull-request/1 15:22:58 https://src.fedoraproject.org/rpms/plexus-classworlds/pull-request/1 15:25:02 micro/latch-level updates should be fine if we do basic sanity checks with the script, I guess. but we can always check if the packages have already been updated for MBI 15:25:08 or the javapackages branch 15:26:13 maybe the links aren't all up to date, I resubmitted some PRs to resolve merge conflicts. 15:26:23 decathorpe: all but one are +1ed by me now 15:26:34 decathorpe: also, I would only do f30 updates when asked to 15:26:37 not by default 15:28:26 yes, I agree 15:28:29 only rawhide 15:28:55 except to fix f30 FTBFS issues 15:29:00 Sure, ACK from me. 15:30:16 perfect, thanks 15:31:53 decathorpe: as for our script, i porpose we stop dropping packages unless we fix it 15:31:59 yes 15:32:20 or double-check with dnf repoquery manually 15:32:27 Sure; do we have a description of the issue? 15:32:41 cipherboy: it reports false leaves 15:33:09 Which script? 15:34:32 generate_report.py 15:35:05 OK, I'll try to take a look later. Might not get to it to next week. 15:35:28 thanks! 15:35:28 somehow it missed the transitive dependency from gradle to apache-commons-discovery 15:37:03 I think I did sanity checks before I orphaned packages, but I seem to have missed this 15:37:42 Yeah, sounds like we're not building enough of a rpm graph, but I'll take a look. 15:38:18 the script checks (build) requires, recommends, and suggests. 15:38:29 the only thing missing might be some weird Boolean dependency stuff ... 15:38:48 Hmm ok. Not (yet) familiar with it, so we'll see. 15:39:43 decathorpe: anything else? 15:39:47 yeah. I have no idea why it doesn't work (and this is the only time this happened so far) 15:40:13 mhroncok: I don't think so 15:40:52 CVEs was my only issue, but glad they weren't for us. 15:42:02 and I pushed your fixes for c3p0 to stable yesterday 15:42:07 thanks again for the PRs 15:45:46 let's close this meeting then. if we forgot anything, feel free to open a ticket and assign it to me. 15:45:59 #endmeeting