Re: Package takeover: bzlib
Andrew Lelechenko <[email protected]> Sat, 9 Mar 2024 19:36:54 +0000
| Newsgroups | gmane.comp.lang.haskell.libraries,gmane.comp.lang.haskell.cafe |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
------------=_65ECBA4C.0E4A8A00
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
Spam detection software, running on the system "mail.haskell.org", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Thanks a ton, Duncan! > On 9 Mar 2024, at 19:20, Duncan Coutts
wrote: > > Done! > > https://hackage.haskell.org/package/bzlib/maintainers/
> > On Sat, 2024-03-09 at 15:30 +0000, Andrew Lelechenko wrote: >> I’d
like to take over `bzlib` package (https://hackage.haskell.org/package/bzlib).
>> >> I’ve contacted the package maintainer (Duncan Coutts, CC'd) by email
twice in Aug 2023 and Oct 2023, but never heard back. Earlier Duncan granted
me rights for `tar` and `zlib` packages, so I imagine he is just exceedingly
busy. >> >> `bzlib` package has been on life support by Hackage Trustees
for many years with a fork maintained at https://github.com/hackage-trustees/bzlib.
While I can do another non-maintainer upload in my Trustee hat, I’d like
to seek a more permanent solution and maintain `bzlib` back to its canonical
home at https://github.com/haskell/bzlib (which I already have access to).
>> >> I do not plan any drastic changes. The immediate cause of this request
is HSEC-2024-0002 (https://github.com/haskell/security-advisories/pull/157,
https://github.com/hackage-trustees/bzlib/issues/4), which identifies a security
vulnerability in `bzlib`, thus raising a need for urgent update. >> >> Best
regards, >> Andrew > [...]
Content analysis details: (5.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(andrew.lelechenko[at]gmail.com)
-0.0 SPF_PASS SPF: sender matches SPF record
5.0 UNWANTED_LANGUAGE_BODY BODY: Message written in an undesired language
0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60%
[score: 0.4999]
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
------------=_65ECBA4C.0E4A8A00
Content-Type: message/rfc822; x-spam-type=original
Content-Description: original message before SpamAssassin
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
Return-Path: <[email protected]>
Received: from mail-wm1-x32e.google.com (mail-wm1-x32e.google.com [IPv6:2a00:1450:4864:20::32e])
by haskell.org (Postfix) with ESMTPS id C6BEBBC53D;
Sat, 9 Mar 2024 19:36:42 +0000 (UTC)
Received: by mail-wm1-x32e.google.com with SMTP id 5b1f17b1804b1-412e784060cso24481885e9.1;
Sat, 09 Mar 2024 11:37:12 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20230601; t=1710013025; x=1710617825; darn=haskell.org;
h=to:references:message-id:content-transfer-encoding:cc:date
:in-reply-to:from:subject:mime-version:from:to:cc:subject:date
:message-id:reply-to;
bh=AxzZ+QTNZumQgLJ3qNO6HS3ZCyk9gew4kSRBHg74Ka8=;
b=BZv37DpmszNWn0Vm+f+E4WshVkXZFTdYSdPAxuBI0nftPINwPTxAyfykAlEqrvJGdj
YfeMvMxe0ntO0KfWli0nCmaEMMZwVTMW6izhgmVhXOznEmvERWJPScOaLi+z5AR4XHpO
rhKwwynVfHU20ucRObhYPAo841pvElMXZixSbfmY0ul89W4LYkY9VvMYT2310cpIwGii
bodAKzmK4oiiBJFsweZRyz9gCiUYkbqHtHe8prIAWO5CWj1dfe78v75rEOftrmHk4CHw
VcCw+fFx4No19t/ixMRztye47Z85ZeNA5pG1lejcSj9HRe1b+7lEa0NBPFORxIcXzJEr
Bw0g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1710013025; x=1710617825;
h=to:references:message-id:content-transfer-encoding:cc:date
:in-reply-to:from:subject:mime-version:x-gm-message-state:from:to:cc
:subject:date:message-id:reply-to;
bh=AxzZ+QTNZumQgLJ3qNO6HS3ZCyk9gew4kSRBHg74Ka8=;
b=ize0Pu3iKervakvMlOWwN8ffeiO4RJvrzYWWbwRL3sF4V+v5wSUNl3aMlRbFtu/UK2
lA/qLopveT1/IrlpUCfGLUHBUxRiKJ2vy/E9W2dvDP4qEybN3nU0WWfZwJOMlgG2tOb0
/duwXpJn0F2hdrSCWpdYWkHdT+Du68z1irBMiRhzMwzj6wk8CsGEg8uqh/XpAuaN2ojA
OHCWsSlu4u0L7018Pnf3wZPX/zqUzdvvmOQW9+EFNvOBIf7q9xHdlsO+GfD2biAlJu4D
hvRyOtTeA12KSX+3CTRj2PHSGqpbDHOdpa7NEeDdBuciJ2ko+q2+tQkKm3SF6sBg2mWC
mJrQ==
X-Forwarded-Encrypted: i=1; AJvYcCW0wzO45Wdi7Fvivwgf1wBGyMfVOEIOYsuM8g2hvxlgwBpw/DFUJd4+3XVVX6akujoUB/c6IJSW+6Nf03HVQhDiV5A3mXR99oI=
X-Gm-Message-State: AOJu0YySLH/S18TGFPC2zRVS6xTfe3QowARUqlQOeAJ6SPEonpN6qp2D
2d/OAFrRDQw/s01nICKh5/HMKsJtfyZR0fQJlx3OJVGQtgnZfKIU
X-Google-Smtp-Source: AGHT+IFTuUnJsnK13VMQnUi4TAzPGr4yasyMwO8G+D0qm8eQnY9FOFxIMyZ2CSlZ7mo03ILyS9EbAA==
X-Received: by 2002:adf:8b5d:0:b0:33e:175b:4af8 with SMTP id v29-20020adf8b5d000000b0033e175b4af8mr3108859wra.28.1710013025339;
Sat, 09 Mar 2024 11:37:05 -0800 (PST)
Received: from smtpclient.apple (cpc114408-walt26-2-0-cust196.13-2.cable.virginm.net. [82.0.18.197])
by smtp.gmail.com with ESMTPSA id s13-20020a5d6a8d000000b0033d202abf01sm2462426wru.28.2024.03.09.11.37.04
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Sat, 09 Mar 2024 11:37:05 -0800 (PST)
Content-Type: text/plain;
charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.200.110.1.12\))
Subject: Re: Package takeover: bzlib
From: Andrew Lelechenko <[email protected]>
In-Reply-To: <[email protected]>
Date: Sat, 9 Mar 2024 19:36:54 +0000
Cc: Haskell Libraries <[email protected]>,
[email protected]
Content-Transfer-Encoding: quoted-printable
Message-Id: <[email protected]>
References: <[email protected]>
<[email protected]>
To: Duncan Coutts <[email protected]>
X-Mailer: Apple Mail (2.3731.200.110.1.12)
Thanks a ton, Duncan!
> On 9 Mar 2024, at 19:20, Duncan Coutts <[email protected]> wrote:
>=20
> Done!
>=20
> https://hackage.haskell.org/package/bzlib/maintainers/
>=20
> On Sat, 2024-03-09 at 15:30 +0000, Andrew Lelechenko wrote:
>> I=E2=80=99d like to take over `bzlib` package =
(https://hackage.haskell.org/package/bzlib).=20
>>=20
>> I=E2=80=99ve contacted the package maintainer (Duncan Coutts, CC'd) =
by email twice in Aug 2023 and Oct 2023, but never heard back. Earlier =
Duncan granted me rights for `tar` and `zlib` packages, so I imagine he =
is just exceedingly busy.=20
>>=20
>> `bzlib` package has been on life support by Hackage Trustees for many =
years with a fork maintained at =
https://github.com/hackage-trustees/bzlib. While I can do another =
non-maintainer upload in my Trustee hat, I=E2=80=99d like to seek a more =
permanent solution and maintain `bzlib` back to its canonical home at =
https://github.com/haskell/bzlib (which I already have access to).
>>=20
>> I do not plan any drastic changes. The immediate cause of this =
request is HSEC-2024-0002 =
(https://github.com/haskell/security-advisories/pull/157, =
https://github.com/hackage-trustees/bzlib/issues/4), which identifies a =
security vulnerability in `bzlib`, thus raising a need for urgent =
update.=20
>>=20
>> Best regards,
>> Andrew
>=20
------------=_65ECBA4C.0E4A8A00
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KTGlicmFyaWVz
IG1haWxpbmcgbGlzdApMaWJyYXJpZXNAaGFza2VsbC5vcmcKaHR0cDovL21haWwuaGFza2VsbC5v
cmcvY2dpLWJpbi9tYWlsbWFuL2xpc3RpbmZvL2xpYnJhcmllcwo=
------------=_65ECBA4C.0E4A8A00--