2021-06-16 conda-forge core meeting
Zoom link What time is the meeting in my time zone last weeks meeting
Attendees
- Jannis Leidel (Anaconda/Conda)
- Matt B
Agenda
Standing items
-
intros for new folks on the call
- MattiP from PyPy
-
(CJ) budget
- current approvals?
- Whenever updated numbers land, please screenshare and show the budget.
- Link is in Keybase (numfocus_spreadsheets.txt)
-
open votes
From previous meeting(s)
- (JK) OSU OpenPOWER Survey
- have until july 31
- should bump this item to next meeting as a reminder
Your new() agenda items
-
(MRB) legal meeting todos
- file-type scanning
- use the linux file command
- add an ok list?
- todos
- do this on quetz and discuss next time
- increased automation
- staged recipes prob not
- new maintainers maybe?
- add a new add maintainer command to make a PR with CI skip
- better python version testing
- file-type scanning
-
(CHL) response to CVE-2021-29921 (leading zeros being parsed as octal)
- Anaconda received request to patch Python 3.8 for this CVE: https://github.com/ContinuumIO/anaconda-issues/issues/12459
- Rated critical by NVD; CPython decided not to patch due to breaking documented API (leading zeros are expected)
- Ubuntu patched: https://changelogs.ubuntu.com/changelogs/pool/main/p/python3.8/python3.8_3.8.6-1ubuntu0.3/changelog
- open ticket about docs being wrong: https://bugs.launchpad.net/ubuntu/+source/python3.8/+bug/1931296
- RedHat noted issue, not taken action: https://bugzilla.redhat.com/show_bug.cgi?id=1957458
- Consensus is to respect upstream decision to not patch
- todos
- matt B to send python 3.9.5 PR and try and fix jinja2
- Anaconda to reach out to CPython devs to ask if they'll reconsider patching 3.8
-
(MattiP) PyPy now has a win64 3.7 version, can we roll out feedstocks?
- wait for https://github.com/regro/cf-scripts/pull/1405
- send a PR to https://github.com/conda-forge/pypy-meta-feedstock
- send a PR to conda-forge-pinning.
-
(jaimergp) Introduce new role at Quansight and community involvement
-
(MRB) gpu stuff w/ quantsight updates?
-
(MRB) any CDN outage todo items for conda-forge?
- TODO: Cheng to set up @anaconda-infrastructure handle (or similar) to bump the right people/teams in Anaconda