-
-
Notifications
You must be signed in to change notification settings - Fork 616
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Important] Blocked, unable to make new releases. #531
Comments
Heads up: Still waiting for the roadies to investigate and/or address the security issue and reactivate the PyPi uploads. I try to monitor this daily, so you'll be notified as soon as I get the green light. Also, no promises, but I'll try to get some simple PRs merged and add them to the 1.10.0 release, as this release issue is taking longer than I expected. Thanks for your patience! |
@vphilippon any updates on this front? |
Strange as it sounds, is it possible to back this repo out of the jazzband organization, as it's been going on three months now where you've been unable to push code? |
Small update here: It seems the original security issue is still in cause (according to a recent reply from @jezdez to another similar issue). @dfee I feel like it's not a small decision to take (which I can't take either), and we might have other solutions to look at right now. @jezdez As a roadie, in the current situation, is it possible for you to manually perform an upload to PyPi for us? |
Hi all, the last PRs for 1.10.0 are merged, I've given the go for the release, so we'll freeze the code until the release. |
🎉 pip-tools 1.10.0 was officially released! 🎉 |
@jezdez We missed a pretty awful bug, essentially breaking |
@jezdez We got another important bugfix in that would require a 1.10.2 release, if you have the time. |
Great news: We should be able to get back on making So @davidovich and myself are currently assuming the new Lead role on I intend to release 1.10.2 soon. I'll report back to confirm that we're unblocked once I'll see the release on PyPi. |
1.10.2 is out, everything is rolling! |
Edit, see 2nd reply and onward
Hi all!
As you might have noticed, I've been preparing stuff for the 1.10.0 release.
But, as I tried to create 1.10.0rc1, I stumbled upon an error with the upload on PyPI. I've contacted the Jazzband roadies, and it seems they disabled PyPI releases while they are investigating a security related issue (jazzband/help#64).
So once this is fixed, I'll release 1.10.0rc1, give some time for the brave out there to test it, and then go for 1.10.0.
While I'm here: Thanks again to all for your time and for taking the time to make community-maintainable contributions. It's not as easy as when having one BDFL, but it's necessary and lets people like me sleep a little better at night.
Cheers!
The text was updated successfully, but these errors were encountered: