Activity log for bug #1568162

Date Who What changed Old value New value Message
2016-04-08 21:57:18 Nicholas Skaggs bug added bug
2016-04-08 22:03:20 Nicholas Skaggs bug added subscriber MIR approval team
2016-04-09 11:00:21 Martin Packman bug added subscriber Martin Packman
2016-04-11 20:25:40 Nicholas Skaggs bug added subscriber Ubuntu Server Team
2016-04-11 20:32:23 Nicholas Skaggs description [Availability] Source-only package currently available in universe. [Rationale] Build-dependency for juju. This is part of our on-going work for bug 1508120, to stop bundling our dependencies in our source package. [Security] This is a source package which will only be used by other Go projects that build-depend on it. Standard practices in the Go ecosystem unfortunately is not to do any release/tag, nor publish changelogs, bugfix announcements or other advisory information. Most of those projects will therefore have a 0.0+git-hash kind of version scheme for their packaged form. Update to those will typically be a completely new snapshot and refresh of their downstreams to match or be a one-off cherry-pick after a specific issue is reported. [Quality assurance] Source-only, arch:all package. There are currently no bug reports filed against this source package. The package is either maintained in Debian or maintained by its upstream directly in Ubuntu. Most of those packages do not have a debian/watch file due to their upstream never pushing out versioned releases. [Dependencies] We are only interested in the -dev source-only package. None of those have build-dependencies due to being source-only. [Maintenance] This package already has a maintainer, and exists in the archive already. The Juju QA team has been subscribed to all bug mails for this package, and all others which we are requesting promotion into main as part of of work on bug 1508120. [Background information] These MIRs are being filed in support of the ongoing work on bug 1508120, at the behest of the Security team, and the FFe for juju-core's inclusion in main for xenial, bug 1545913. Note, the juju package will continue to bundle this dependency for trusty and older release, due to lack of go support and resources to backport and maintain these dependencies in trusty. However, these dependencies are used for all new builds, and have priority whenever present. This is in-line with the security team's recommendations and agreement as part of bug 1508120. [Availability] Source-only package currently available in universe. [Rationale] Build-dependency for juju. This is part of our on-going work for bug 1508120, to stop bundling our dependencies in our source package. [Security] This is a source package which will only be used by other Go projects that build-depend on it. Standard practices in the Go ecosystem unfortunately is not to do any release/tag, nor publish changelogs, bugfix announcements or other advisory information. Most of those projects will therefore have a 0.0+git-hash kind of version scheme for their packaged form. Update to those will typically be a completely new snapshot and refresh of their downstreams to match or be a one-off cherry-pick after a specific issue is reported. [Quality assurance] Source-only, arch:all package. There are currently no bug reports filed against this source package. The package is either maintained in Debian or maintained by its upstream directly in Ubuntu. Most of those packages do not have a debian/watch file due to their upstream never pushing out versioned releases. [Dependencies] We are only interested in the -dev source-only package. None of those have build-dependencies due to being source-only. [Maintenance] This package already has a maintainer, and exists in the archive already. As with the other juju packages, the ubuntu-server team will provide ownership. However, the Juju QA team has also been subscribed to all bug mails for this package, and all others which we are requesting promotion into main as part of of work on bug 1508120 in order to ensure a smooth transition. [Background information] These MIRs are being filed in support of the ongoing work on bug 1508120, at the behest of the Security team, and the FFe for juju-core's inclusion in main for xenial, bug 1545913. Note, the juju package will continue to bundle this dependency for trusty and older release, due to lack of go support and resources to backport and maintain these dependencies in trusty. However, these dependencies are used for all new builds, and have priority whenever present. This is in-line with the security team's recommendations and agreement as part of bug 1508120.
2016-04-12 14:45:41 Michael Terry golang-gopkg-mgo.v2 (Ubuntu): status New Incomplete
2016-06-12 04:17:35 Launchpad Janitor golang-gopkg-mgo.v2 (Ubuntu): status Incomplete Expired
2016-06-13 12:39:54 Nicholas Skaggs golang-gopkg-mgo.v2 (Ubuntu): status Expired Incomplete
2016-08-13 04:17:27 Launchpad Janitor golang-gopkg-mgo.v2 (Ubuntu): status Incomplete Expired