Re: Package takeover: bzlib

Duncan Coutts <[email protected]> Sat, 09 Mar 2024 19:20:09 +0000
Newsgroups gmane.comp.lang.haskell.cafe,gmane.comp.lang.haskell.libraries
Message-ID <[email protected]>
This is a multi-part message in MIME format.

------------=_65ECB65A.4F1B3279
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

Spam detection software, running on the system "mail.haskell.org", has
identified this incoming email as possible spam.  The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email.  If you have any questions, see
@@CONTACT_ADDRESS@@ for details.

Content preview:  Done! https://hackage.haskell.org/package/bzlib/maintainers/
   On Sat, 2024-03-09 at 15:30 +0000, Andrew Lelechenko wrote: > I’d like
  to take over `bzlib` package (https://hackage.haskell.org/package/bzlib).
  > > I’ve contacted the package maintainer (Duncan Coutts, CC'd) by email
   twice in Aug 2023 and Oct 2023, but never heard back. Earlier Duncan granted
   me rights for `tar` and `zlib` packages, so I imagine he is just exceedingly
   busy. > > `bzlib` package has been on life support by Hackage Trustees for
   many years with a fork maintained at https://github.com/hackage-trustees/bzlib.
   While I can do another non-maintainer upload in my Trustee hat, I’d like
   to seek a more permanent solution and maintain `bzlib` back to its canonical
   home at https://github.com/haskell/bzlib (which I already have access to).
   > > I do not plan any drastic changes. The immediate cause of this request
   is HSEC-2024-0002 (https://github.com/haskell/security-advisories/pull/157,
   https://github.com/hackage-trustees/bzlib/issues/4), which identifies a security
   vulnerability in `bzlib`, thus raising a need for urgent update. > > Best
   regards, > Andrew [...] 

Content analysis details:   (5.8 points, 5.0 required)

 pts rule name              description
---- ---------------------- --------------------------------------------------
-0.0 SPF_HELO_PASS          SPF: HELO matches SPF record
-0.0 T_RP_MATCHES_RCVD      Envelope sender domain matches handover relay
                            domain
-0.0 SPF_PASS               SPF: sender matches SPF record
 5.0 UNWANTED_LANGUAGE_BODY BODY: Message written in an undesired language
 0.8 BAYES_50               BODY: Bayes spam probability is 40 to 60%
                            [score: 0.5000]
 0.0 T_DKIM_INVALID         DKIM-Signature header exists but is not valid



------------=_65ECB65A.4F1B3279
Content-Type: message/rfc822; x-spam-type=original
Content-Description: original message before SpamAssassin
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

Return-Path: <[email protected]>
Received: from mail.well-typed.com (white.well-typed.com [IPv6:2a01:4f8:1c1c:cdb1::1])
	by haskell.org (Postfix) with ESMTPS id 56477BC491;
	Sat,  9 Mar 2024 19:19:49 +0000 (UTC)
Message-ID: <[email protected]>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=well-typed.com;
	s=mail; t=1710011915;
	h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
	 to:to:cc:mime-version:mime-version:content-type:content-type:
	 content-transfer-encoding:content-transfer-encoding:
	 in-reply-to:in-reply-to:references:references;
	bh=Upq65QYHpAY1tECWXK2YNivavQdROgLoiL8cNHH9RzQ=;
	b=pqwr+oekMUVAKmTY7OnbHeP+OQCiGEaVGnTlwFMR0YkvwlnteqMz/GptDuOLeBL4xilF7b
	tLTmsl/HDmsaOvi16P+uB8bofy7WxIWEjLHDpBAyZcsjCHU4UNg73z3K8M83r0LfRGfJhD
	5m/Bq94H54w8+6qnUsh193YTtiuY+2E=
Authentication-Results: ORIGINATING;
	auth=pass smtp.auth=duncan [email protected]
Subject: Re: Package takeover: bzlib
From: Duncan Coutts <[email protected]>
To: Andrew Lelechenko <[email protected]>, Haskell Libraries
	 <[email protected]>, [email protected]
Date: Sat, 09 Mar 2024 19:20:09 +0000
In-Reply-To: <[email protected]>
References: <[email protected]>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0

Done!

https://hackage.haskell.org/package/bzlib/maintainers/

On Sat, 2024-03-09 at 15:30 +0000, Andrew Lelechenko wrote:
> I=E2=80=99d like to take over `bzlib` package (https://hackage.haskell.or=
g/package/bzlib).=20
>=20
> I=E2=80=99ve contacted the package maintainer (Duncan Coutts, CC'd) by em=
ail twice in Aug 2023 and Oct 2023, but never heard back. Earlier Duncan gr=
anted me rights for `tar` and `zlib` packages, so I imagine he is just exce=
edingly busy.=20
>=20
> `bzlib` package has been on life support by Hackage Trustees for many yea=
rs with a fork maintained at https://github.com/hackage-trustees/bzlib. Whi=
le I can do another non-maintainer upload in my Trustee hat, I=E2=80=99d li=
ke to seek a more permanent solution and maintain `bzlib` back to its canon=
ical home at https://github.com/haskell/bzlib (which I already have access =
to).
>=20
> I do not plan any drastic changes. The immediate cause of this request is=
 HSEC-2024-0002 (https://github.com/haskell/security-advisories/pull/157, h=
ttps://github.com/hackage-trustees/bzlib/issues/4), which identifies a secu=
rity vulnerability in `bzlib`, thus raising a need for urgent update.=20
>=20
> Best regards,
> Andrew


------------=_65ECB65A.4F1B3279
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KSGFza2VsbC1D
YWZlIG1haWxpbmcgbGlzdApUbyAodW4pc3Vic2NyaWJlLCBtb2RpZnkgb3B0aW9ucyBvciB2aWV3
IGFyY2hpdmVzIGdvIHRvOgpodHRwOi8vbWFpbC5oYXNrZWxsLm9yZy9jZ2ktYmluL21haWxtYW4v
bGlzdGluZm8vaGFza2VsbC1jYWZlCk9ubHkgbWVtYmVycyBzdWJzY3JpYmVkIHZpYSB0aGUgbWFp
bG1hbiBsaXN0IGFyZSBhbGxvd2VkIHRvIHBvc3Qu

------------=_65ECB65A.4F1B3279--