#5963: Orphaned vulnerable packages in EPEL

Fedora Release Engineering rel-eng at fedoraproject.org
Fri Jan 23 17:19:27 UTC 2015


#5963: Orphaned vulnerable packages in EPEL
------------------------------+-----------------------
  Reporter:  sparks           |      Owner:  rel-eng@…
      Type:  task             |     Status:  reopened
 Milestone:  Fedora 20 Final  |  Component:  epel
Resolution:                   |   Keywords:  meeting
Blocked By:                   |   Blocking:
------------------------------+-----------------------

Comment (by till):

 Here is a status update. I will update the comment after I checked other
 branches. Here is an update for EPEL5:

 Replying to [comment:8 sparks]:
 > Actually I see the following packages still in EPEL:
 >
 > mantis - epel-5[[BR]]

 not orphaned since 2014-11-09

 PoC: giallu (giallu, group::provenpackager, llaumgui, slankes)


 > mod_wsgi - epel-5 [[BR]]

 not orphaned since 2014-11-06

 PoC: orion (group::provenpackager, jkaluza, jokajak, jorton, joshkayse,
 lmacken, orion)

 > php-magpierss - epel-all [[BR]]
 > php-suhosin - epel-all[[BR]]
 > polipo - epel-6[[BR]]
 > python26-mod_wsgi - epel-5 [[BR]]

 Not orphaned since 2014-05-30

  PoC: lmacken (group::provenpackager, lmacken)

 > python26-simplejson - epel-5 [[BR]]

 will be retired soon

 > qemu - epel-5 [[BR]]

 This is not orphaned since 2014-05-14
 > revelation - epel-5 [[BR]]

 This should not be there since 2014-12-17
 > tigase-server - epel-all [[BR]]
 > torque - epel-all [[BR]]
 > xinha - epel-5 [[BR]]

 will be retired today

 > zope - epel-5

 Cannot be retired currently because it is a dependency for fedpkg (via
 several other pkgs)

-- 
Ticket URL: <https://fedorahosted.org/rel-eng/ticket/5963#comment:9>
Fedora Release Engineering <http://fedorahosted.org/rel-eng>
Release Engineering for the Fedora Project


More information about the rel-eng mailing list