On Fri, Sep 15, 2023 12:53:21 +0200, Laura Barcziova wrote:
> Yes, Fedora dist-git lookaside cache. The upstream archive is uploaded
> automatically, but only a pull request is created in the particular dist-git
> repo with the change of the sources reference. Once the PRs are created, it is
> up to the maintainer to review these changes and, just after that, merge the
> changes with the updated reference to the respective branches.

Packit is awesome, it really does help to automate lots of menial tasks,
but the risk really is that maintainers forget to do their due diligence
before merging the PRs and all that.

I guess it should be possible to make packit (or the-new-hotness?) run
licensecheck on the new sources and include that in the PR comment too,
perhaps also with a list of packages that depend on the one being
updated as an "impact check"?

Another issue relevant to us Fedora package maintainers is this one
(already being worked on from what I see):

Ankur Sinha "FranciscoD" (He / Him / His) |
Time zone: Europe/London

