Use a more recent version of hacking

Bug #1741100 reported by Matthew Thode
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Bandit
Fix Committed
High
Tin Lam
bandit (Gentoo Linux)
Fix Released
Medium

Bug Description

Using such an ancient version of hacking can cause downstream packaging issues.

https://bugs.gentoo.org/643294

Revision history for this message
In , mgorny (mgorny-gentoo-bugs) wrote :

This is the only package requiring old version of dev-python/hacking. Please look into the possibility of making it work with newer versions.

Revision history for this message
In , mgorny (mgorny-gentoo-bugs) wrote :

...which in turn requires ancient dev-python/flake8.

Changed in bandit (Gentoo Linux):
importance: Unknown → Medium
Revision history for this message
Gage Hugo (gagehugo) wrote :

I'm a bit confused here, bandit doesn't require hacking to run, it should only be used for testing via testenv. Also Bandit follows other OpenStack projects in terms of setting limits for the requirements, and hacking seems to be in line with both keystone[0] and nova[1]. I'm not sure what the reasoning is for the current cap at below 0.14.0 but I can look into it.

[0] https://github.com/openstack/keystone/blob/master/test-requirements.txt#L5
[1] https://github.com/openstack/nova/blob/master/test-requirements.txt#L5

Revision history for this message
Eric Brown (ericwb) wrote :

Fixed with https://review.openstack.org/#/c/533071/

Review accidentally referenced wrong bug number.

Changed in bandit:
assignee: nobody → Tin Lam (lamt)
importance: Undecided → High
status: New → Fix Committed
Revision history for this message
In , vdupras (vdupras-gentoo-bugs) wrote :

Update: upstream issue is fixed, bandit on pypi is at 1.5.1. Could we bump and clean?

Revision history for this message
In , prometheanfire (prometheanfire-gentoo-bugs) wrote :

should be good now, had to update 90 or so packages though.

Changed in bandit (Gentoo Linux):
status: Unknown → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.