Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Last rites: dev-python/elasticsearch-curator
Date: Fri, 26 Mar 2021 17:05:55
Message-Id: d6812753fe927e6a75749cb9dc9a7546928eaa3f.camel@gentoo.org
In Reply to: Re: [gentoo-dev] Last rites: dev-python/elasticsearch-curator by "Robin H. Johnson"
1 On Fri, 2021-03-26 at 16:45 +0000, Robin H. Johnson wrote:
2 > On Fri, Mar 26, 2021 at 09:27:39AM +0100, Michał Górny wrote:
3 > > # Michał Górny <mgorny@g.o> (2021-03-26)
4 > > # Pins to a vulnerable version of dev-python/urllib3.  No maintainer
5 > > # in Gentoo.
6 > > # Removal on 2021-04-25.  Bug #714860.
7 > > dev-python/elasticsearch-curator
8 > Can you hold off a bit on this one?
9 >
10 > The latest version in the tree IS the latest version upstream, and they
11 > only made progress in the urllib3 issue in the past week:
12 > https://github.com/elastic/curator/pull/1595
13 > https://github.com/elastic/curator/issues/1589
14 >
15 > Hopefully they'll get a new version out within the next few weeks.
16
17 I don't see a problem delaying the removal. However, the previous
18 package maintainer resigned, so nothing's going to happen unless someone
19 decides to take it. Then, it really needs porting to non-vulnerable
20 urllib3 version.
21
22 --
23 Best regards,
24 Michał Górny