16:00:18 <decathorpe> #startmeeting Stewardship SIG Meeting (2020-01-21)
16:00:18 <zodbot> Meeting started Tue Jan 21 16:00:18 2020 UTC.
16:00:18 <zodbot> This meeting is logged and archived in a public location.
16:00:18 <zodbot> The chair is decathorpe. Information about MeetBot at http://wiki.debian.org/MeetBot.
16:00:18 <zodbot> Useful Commands: #action #agreed #halp #info #idea #link #topic.
16:00:18 <zodbot> The meeting name has been set to 'stewardship_sig_meeting_(2020-01-21)'
16:00:22 <decathorpe> #meetingname stewardship-sig
16:00:22 <zodbot> The meeting name has been set to 'stewardship-sig'
16:00:26 <decathorpe> #topic Roll Call
16:01:12 <decathorpe> cipherboy, sillebille: Meeting Time
16:01:20 <sillebille> \o hello
16:01:27 <decathorpe> hello! o/
16:01:31 <decathorpe> #chair sillebille
16:01:31 <zodbot> Current chairs: decathorpe sillebille
16:02:08 <sillebille> i've been sloppy for the past few weeks due to deadlines and other things in the plate. I hope I'll get more time in the coming weeks :)
16:02:25 <decathorpe> no worries, we're all busy with $LIFE and $DAYJOB
16:02:44 <sillebille> decathorpe++ Thanks
16:04:02 <decathorpe> I'll wait until :05 to start the meeting
16:05:44 <decathorpe> #topic Review Open BugZilla tickets
16:05:49 <decathorpe> #link https://bugzilla.redhat.com/buglist.cgi?bug_status=__open__&email1=stewardship-sig%40lists.fedoraproject.org&emailassigned_to1=1&emailcc1=1&emailtype1=substring&list_id=10281127&product=Fedora&query_format=advanced
16:06:04 <decathorpe> we're down to less than 2 pages of bugs, which is good
16:06:17 <decathorpe> there's also only one open CVE, which is probably WONTFIX
16:06:40 <sillebille> cipherboy and me are part of another meeting. He should show up soon
16:06:51 <decathorpe> oh, ok. I can wait :)
16:06:59 <decathorpe> .nextmeetings
16:06:59 <zodbot> decathorpe: One moment, please...  Looking up the channel list.
16:07:02 <zodbot> decathorpe: In #fedora-admin is Fedora Infra Ops Daily Standup (starting in 2 hours)
16:07:04 <zodbot> decathorpe: In #fedora-meeting-1 is Server SIG (starting in 4 hours)
16:07:07 <zodbot> decathorpe: In #fedora-meeting is G11N  (starting in 12 hours)
16:07:10 <zodbot> decathorpe: In #fedora-meeting is Magazine editorial board (starting in 20 hours)
16:07:14 <zodbot> decathorpe: In #fedora-meeting-1 is FPgM office hours (starting in 21 hours)
16:07:22 <sillebille> yeah, that's some good  news
16:07:31 <decathorpe> looks like we can the channel for 4 hours yet ;)
16:07:36 <sillebille> also, i see few PRs already addressing few of those BZs
16:07:47 <decathorpe> true
16:07:49 <sillebille> LOL. You sure? We are in Eastern time zone ;)
16:08:15 <decathorpe> no, not sure at all
16:08:26 <sillebille> haha
16:09:03 <sillebille> ok. So, once the PRs get reviewed and merged, we should get the BZ # to a page. :)
16:09:33 <decathorpe> yeah, that could be our next goal
16:09:47 <sillebille> almost every bug is a rebase. I was thinkign whether we should start experimenting with packit.dev?
16:10:01 <decathorpe> that won't help us :(
16:10:21 <decathorpe> it's supposed to be integrated into upstream projects
16:10:46 <sillebille> well, we could try submitting a PR to the project. Would they be against it?
16:11:04 <decathorpe> you can try submitting things into Apache JIRA so they push things into SVN
16:11:05 <decathorpe> :D
16:11:20 <sillebille> lol
16:11:39 <decathorpe> so .. probably not
16:11:59 <sillebille> ok :(
16:13:11 <decathorpe> I'll try to work on a few version updates starting next week.
16:14:08 <sillebille> aye.
16:14:42 <sillebille> I will start by reviewing the open PRs this week ..
16:15:12 <decathorpe> I'll also make a list of packages where we need help from some real Java person :)
16:15:37 <sillebille> ok
16:16:07 <decathorpe> any other comments about open bugs?
16:16:48 <sillebille> (silly) question: are we going to rebase all the components listed in the BZ?
16:17:06 <sillebille> *are we planning to?
16:17:29 <decathorpe> if it is possible, yes
16:17:38 <sillebille> roger that.
16:17:45 <decathorpe> some things contain breaking changes, which I won't push into fedora
16:18:04 <sillebille> ok
16:18:18 <sillebille> i have nothing else on the BZ topic. cipherboy?
16:18:18 <decathorpe> #topic Open Pull Requests
16:18:24 <decathorpe> #link https://decathorpe.fedorapeople.org/stewardship-sig-prs.html
16:18:39 <decathorpe> I don't think there's anything interesting in BZ
16:19:06 <decathorpe> regarding PRs: jackson 2.10.2 updates are good to go
16:19:12 <decathorpe> junit 4.13.0 is good to go
16:19:18 <decathorpe> log4j 2.13.0 was merged and built
16:19:33 <decathorpe> sisu 0.3.4 is good to go
16:19:42 <decathorpe> apache-parent 22 is good to go
16:20:06 <decathorpe> everything else either causes issues with other packages, or has merge conflicts.
16:21:12 <sillebille> i had a quick dry run on few of the PRs but did not post any comments. Everything were all straight-forward rebases...
16:21:31 <sillebille> If you want to wait, I'll post the comments today or tomorrow. Or feel free to merge :)
16:21:49 <sillebille> slf4j hasn't been rebased. Should we poke at it again? :)
16:22:00 <decathorpe> sillebille: thanks, I'd like to have some form of documented "ACK" for the PRs
16:22:08 <decathorpe> yeah poke slf4j ...
16:23:33 <sillebille> done
16:23:56 <sillebille> and for the "ACK", i'll do it soon... :)
16:24:32 <decathorpe> thanks!
16:25:11 <cipherboy> decathorpe: Sorry, I'm here.
16:25:12 <decathorpe> #topic Review SIG Leaf Packages
16:25:18 <decathorpe> #chair cipherboy
16:25:18 <zodbot> Current chairs: cipherboy decathorpe sillebille
16:25:19 <decathorpe> o/
16:25:23 <cipherboy> \o
16:25:27 <cipherboy> Was busy in other meeting.
16:25:33 <decathorpe> no problem
16:25:33 <cipherboy> Glad sillebille  remembered :-)
16:25:42 <decathorpe> #link https://decathorpe.fedorapeople.org/stewardship-sig.html#sig-leaves
16:25:47 <decathorpe> #link https://pagure.io/stewardship-sig/issue/68
16:26:06 <cipherboy> Leaves I think look fine as-is, I wouldn't drop anything right now.
16:26:19 <decathorpe> proposal: we close issue 68, and wait until the next round of orphans is retired
16:26:27 <cipherboy> +1
16:27:56 <decathorpe> cipherboy: thanks for the log4j and junit PRs
16:28:15 <decathorpe> #topic Open Floor
16:29:10 <cipherboy> decathorpe: np. Is there something else you want me to look at next?
16:29:34 <sillebille> I am planning to start experimenting packit.dev on PKI next month
16:29:39 <sillebille> i have nothing else to discuss :)
16:30:36 <decathorpe> there are some patch-level version rebases pending, which I didn't yet have the time to get to. they should be easy
16:31:53 <decathorpe> e.g. velocity-parsers 2.8.3 → 2.8.4, woodstox-core 6.0.2 → 6.0.3, qdox 2.0~M9 → 2.0.0
16:32:29 <decathorpe> maven-enforcer 3.0.0~M2 → 3.0.0~M3
16:32:58 <cipherboy> ACK, I can take a look at those.
16:33:43 <decathorpe> great, thanks
16:33:52 <decathorpe> those 4 should be pretty straightforward.
16:34:41 <decathorpe> we can also steal some work from the modular branches :)
16:36:13 <decathorpe> one more thing: mbooth asked whether we can unretire xmlrpc on rawhide and f31, it's the last package that's blocking eclipse
16:42:03 <sillebille> hmmm. Upstream xmlrpc project has been discontinued ?
16:42:56 <cipherboy> I'd be fine taking xmlrpc in support of non-modular eclipse.
16:43:21 <cipherboy> But I worry that there might not be a good migration plan to/from modular/non-modular, especially considering gimp having issues.
16:43:36 <cipherboy> decathorpe: Do you want me to update the spec and you do the review?
16:43:56 <decathorpe> cipherboy: yeah, sure
16:44:14 <decathorpe> Note that there are two open CVEs against xmlrpc
16:44:27 <cipherboy> decathorpe: Yuck. And upstream is dead? sillebille -- do you know if they fixed it?
16:44:33 <decathorpe> but I think we can ignore those for local use ...
16:45:06 <sillebille> cipherboy, I can't seem to downlaod tar nor access svn: http://ws.apache.org/xmlrpc/download.html
16:45:29 <sillebille> there is an archive available here: http://archive.apache.org/dist/ws/xmlrpc/
16:46:29 <cipherboy> [   ] apache-xmlrpc-current-src.zip              2013-01-31 16:06  361K
16:46:35 <cipherboy> That's a little old.
16:47:04 <sillebille> yeah. May be the project died. :
16:47:06 <sillebille> :\
16:47:18 <decathorpe> uhm. yeah.
16:47:44 <decathorpe> the /sources/ directory has correctly named tarballs, btw.
16:47:56 <decathorpe> (3.1.3, not "current")
16:48:29 <sillebille> last module build includes 3.1.3
16:48:52 <mbooth> Wah, I was in another meeting and could not appear from out of the ether at the mention of Eclipse
16:49:40 <mbooth> I'm actually thinking of dropping eclipse-mylyn because of it;s use of this comedy old and insecurity library
16:49:41 <cipherboy> Hmmm -- https://bugzilla.redhat.com/show_bug.cgi?id=1775193 -- lots of internal comments there, but there is a public proposed patch we could review and use.
16:50:14 <cipherboy> mbooth: Yeah, I think that'd be best. I don't particularly like maintaining unmaintained code bases... :-)
16:51:03 <mbooth> Mylyn has nothing that particularly benefits from being packaged (non native bits, no requirement for deep integration with the host system)
16:51:51 <cipherboy> mbooth: Yeah, can you pull it in as a plugin?
16:52:15 <mbooth> And users can still install it via p2 or the Eclipse Market Place client from the upstream plug-in repositories
16:52:23 <mbooth> If they really want it
16:52:32 * mbooth doesn't use it, TBH
16:52:36 <cipherboy> Yeah, +1 to that.
16:52:43 <sillebille> +1
16:53:04 <decathorpe> great
16:53:06 <decathorpe> :)
16:53:11 <cipherboy> Thanks mbooth!
16:53:54 <mbooth> Well, fewer RPMs is better.
16:53:59 <decathorpe> mbooth++
16:54:05 * mbooth tries to get his package load below 100
16:54:52 <decathorpe> I'm trying to keep mine below 400 ...
16:55:19 <mbooth> Eclipse platform itself counts for like 300, I'm sure :-p
16:55:38 <decathorpe> I'm taking your word for it :-)
16:57:50 <decathorpe> alright, is there anything else? otherwise I'd close the meeting on time
16:59:09 <sillebille> i don't have any :)
17:00:25 <decathorpe> #endmeeting