On Wed, Nov 27, 2024, 02:32 Kamil Dudka <kdudka@xxxxxxxxxx> wrote:
On Wednesday, November 27, 2024 12:07:29 AM GMT+1 Michel Lind wrote:
> On Tue, Nov 26, 2024 at 12:11:27PM -0300, Marco Benatto wrote:
> > Hello all,
> >
> > We recently noticed there's a couple of PRs opened to fix
> > vulnerabilities in EPEL8 python-django3 with no response from the
> > maintainer (CC'ed). This is an important update as it fixes 4
> > different CVEs.
> >
> > https://src.fedoraproject.org/rpms/python-django3/pull-request/2
> >
> > I have raised a bugzilla bug asking for contact according
> > https://docs.fedoraproject.org/en-US/fesco/Policy_for_nonresponsive_package_maintainers/
> >
> > https://bugzilla.redhat.com/show_bug.cgi?id=2328973
> >
> > may i please have your help in contacting the maintainer?
> >
> That PR was never in a state where it's merge-able, FYI
Michel, I know you are busy but let's avoid using nonsense excuses like this.
What an intriguing way to treat packagers this is. I'll make sure to note this behavior for the future.
-- _______________________________________________ devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue