[Haskell-cafe] Package takeover: bzlib
Duncan Coutts
duncan at well-typed.com
Sat Mar 9 19:20:09 UTC 2024
Spam detection software, running on the system "mail.haskell.org", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Done! https://hackage.haskell.org/package/bzlib/maintainers/
On Sat, 2024-03-09 at 15:30 +0000, Andrew Lelechenko wrote: > Iâd like
to take over `bzlib` package (https://hackage.haskell.org/package/bzlib).
> > Iâve contacted the package maintainer (Duncan Coutts, CC'd) by email
twice in Aug 2023 and Oct 2023, but never heard back. Earlier Duncan granted
me rights for `tar` and `zlib` packages, so I imagine he is just exceedingly
busy. > > `bzlib` package has been on life support by Hackage Trustees for
many years with a fork maintained at https://github.com/hackage-trustees/bzlib.
While I can do another non-maintainer upload in my Trustee hat, Iâd like
to seek a more permanent solution and maintain `bzlib` back to its canonical
home at https://github.com/haskell/bzlib (which I already have access to).
> > I do not plan any drastic changes. The immediate cause of this request
is HSEC-2024-0002 (https://github.com/haskell/security-advisories/pull/157,
https://github.com/hackage-trustees/bzlib/issues/4), which identifies a security
vulnerability in `bzlib`, thus raising a need for urgent update. > > Best
regards, > Andrew [...]
Content analysis details: (5.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
-0.0 SPF_PASS SPF: sender matches SPF record
5.0 UNWANTED_LANGUAGE_BODY BODY: Message written in an undesired language
0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60%
[score: 0.5000]
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
-------------- next part --------------
An embedded message was scrubbed...
From: Duncan Coutts <duncan at well-typed.com>
Subject: Re: Package takeover: bzlib
Date: Sat, 09 Mar 2024 19:20:09 +0000
Size: 2670
URL: <http://mail.haskell.org/pipermail/haskell-cafe/attachments/20240309/affcfe32/attachment.mht>
More information about the Haskell-Cafe
mailing list