https://bugzilla.redhat.com/show_bug.cgi?id=1680145 --- Comment #3 from Robert-André Mauchin <zebob.m@xxxxxxxxx> --- - Nitpick: Please have your script remove the temporary archive and directory it creates. - License: MPLv2.0 and BSD and MIT Please add a comment explaining the licenses breakdown. - Remove all these useless hidden files in %prep mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/.yarn-integrity mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/ajv/.tonic_example.js mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/ajv/lib/.DS_Store mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/ajv/scripts/.eslintrc.yml mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/fast-json-stable-stringify/.eslintrc.yml mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/fast-json-stable-stringify/.npmignore mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/fast-json-stable-stringify/.travis.yml mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/json-schema-traverse/.eslintrc.yml mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/json-schema-traverse/.travis.yml mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/json-schema-traverse/spec/.eslintrc.yml - You should work to unbundle all these node modules. Bundling is usually a last resort option. Package Review ============== Legend: [x] = Pass, [!] = Fail, [-] = Not applicable, [?] = Not evaluated [ ] = Manual review needed ===== MUST items ===== Generic: [x]: Package is licensed with an open-source compatible license and meets other legal requirements as defined in the legal section of Packaging Guidelines. [x]: License field in the package spec file matches the actual license. [!]: If the package is under multiple licenses, the licensing breakdown must be documented in the spec. [x]: Package contains no bundled libraries without FPC exception. [x]: Changelog in prescribed format. [x]: Sources contain only permissible code or content. [-]: Package contains desktop file if it is a GUI application. [-]: Development files must be in a -devel package [x]: Package uses nothing in %doc for runtime. [x]: Package consistently uses macros (instead of hard-coded directory names). [x]: Package is named according to the Package Naming Guidelines. [x]: Package does not generate any conflict. [x]: Package obeys FHS, except libexecdir and /usr/target. [-]: If the package is a rename of another package, proper Obsoletes and Provides are present. [x]: Requires correct, justified where necessary. [x]: Spec file is legible and written in American English. [-]: Package contains systemd file(s) if in need. [x]: Package is not known to require an ExcludeArch tag. [-]: Large documentation must go in a -doc subpackage. Large could be size (~1MB) or number of files. Note: Documentation size is 10240 bytes in 1 files. [x]: Package complies to the Packaging Guidelines [x]: Package successfully compiles and builds into binary rpms on at least one supported primary architecture. [x]: Package installs properly. [x]: Rpmlint is run on all rpms the build produces. Note: There are rpmlint messages (see attachment). [x]: Package requires other packages for directories it uses. [x]: Package does not own files or directories owned by other packages. [x]: Package uses either %{buildroot} or $RPM_BUILD_ROOT [x]: Package does not run rm -rf %{buildroot} (or $RPM_BUILD_ROOT) at the beginning of %install. [x]: Macros in Summary, %description expandable at SRPM build time. [x]: Dist tag is present. [x]: Package does not contain duplicates in %files. [x]: Permissions on files are set properly. [x]: Package use %makeinstall only when make install DESTDIR=... doesn't work. [x]: Package is named using only allowed ASCII characters. [x]: Package does not use a name that already exists. [x]: Package is not relocatable. [x]: Sources used to build the package match the upstream source, as provided in the spec URL. [x]: Spec file name must match the spec package %{name}, in the format %{name}.spec. [x]: File names are valid UTF-8. [x]: Packages must not store files under /srv, /opt or /usr/local ===== SHOULD items ===== Generic: [-]: If the source package does not include license text(s) as a separate file from upstream, the packager SHOULD query upstream to include it. [x]: Final provides and requires are sane (see attachments). [?]: Package functions as described. [x]: Latest version is packaged. [x]: Package does not include license text files separate from upstream. [-]: Description and summary sections in the package spec file contains translations for supported Non-English languages, if available. [-]: %check is present and all tests pass. [x]: Packages should try to preserve timestamps of original installed files. [x]: Reviewer should test that the package builds in mock. [x]: Buildroot is not present [x]: Package has no %clean section with rm -rf %{buildroot} (or $RPM_BUILD_ROOT) [x]: No file requires outside of /etc, /bin, /sbin, /usr/bin, /usr/sbin. [x]: Packager, Vendor, PreReq, Copyright tags should not be in spec file [x]: SourceX is a working URL. [x]: Package should compile and build into binary rpms on all supported architectures. [x]: Spec use %global instead of %define unless justified. ===== EXTRA items ===== Generic: [x]: Rpmlint is run on all installed packages. Note: There are rpmlint messages (see attachment). [x]: Spec file according to URL is the same as in SRPM. Rpmlint ------- Checking: mozilla-iot-gateway-addon-node-0.4.0-1.fc31.noarch.rpm mozilla-iot-gateway-addon-node-0.4.0-1.fc31.src.rpm mozilla-iot-gateway-addon-node.noarch: W: spelling-error %description -l en_US ons -> nos, ins, obs mozilla-iot-gateway-addon-node.noarch: W: only-non-binary-in-usr-lib mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/.yarn-integrity mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/ajv/.tonic_example.js mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/ajv/lib/.DS_Store mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/ajv/scripts/.eslintrc.yml mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/fast-json-stable-stringify/.eslintrc.yml mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/fast-json-stable-stringify/.npmignore mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/fast-json-stable-stringify/.travis.yml mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/json-schema-traverse/.eslintrc.yml mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/json-schema-traverse/.travis.yml mozilla-iot-gateway-addon-node.noarch: W: hidden-file-or-dir /usr/lib/node_modules/gateway-addon-node/node_modules/json-schema-traverse/spec/.eslintrc.yml mozilla-iot-gateway-addon-node.src: W: spelling-error %description -l en_US ons -> nos, ins, obs mozilla-iot-gateway-addon-node.src:6: E: hardcoded-library-path in %{_prefix}/lib/node_modules/gateway-addon-node/.*$ mozilla-iot-gateway-addon-node.src: W: invalid-url Source0: gateway-addon-node-v0.4.0.tar.gz 2 packages and 0 specfiles checked; 1 errors, 14 warnings. -- You are receiving this mail because: You are on the CC list for the bug. You are always notified about changes to this product and component _______________________________________________ package-review mailing list -- package-review@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to package-review-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-review@xxxxxxxxxxxxxxxxxxxxxxx