Permanent Update Policy Exception for certbot #3124
Labels
No labels
document it
fast track
meeting
next release
nonresponsive maintainer
packager revocation
pending announcement
provenpackager
python 2 exception
self contained change
stalled
Status
Accepted
Status
Duplicate
Status
Insufficient data
Status
Invalid
Status
Rejected
system wide change
updates policy exception
vote-in-progress
No milestone
No project
No assignees
9 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
fesco/tickets#3124
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This ticket asks FESCo to consider whether the certbot package should be granted a permanent exception under the Updates Policy.
The certbot package is a Python package published by EFF to manage free SSL certs mostly from Let's Encrypt but others are supported as well. It has integrations for various DNS providers as well as Apache and Nginx web servers.
No package depends on the certbot package.
This request is mostly so EPEL can inherit the exception as the short lifecycle of Fedora makes it less relevant to Fedora specifically. Given EPEL's long life cycle, many things can change cert-wise over a 10-year period along with APIs of the DNS providers with which certbot integrates. This leads to folks being unable to get the most ideal (secure) certs and/or completely broken integrations which can break or otherwise leave websites vulnerable if server admins don't take action.
certbot does have breaking changes in the traditional sense of changed functionality, it generally does not require user intervention and the value of updating far outweighs the very minute chance of an obscure breakage from said update.
I think this is reasonable as a Fedora-wide exception.
+1
Metadata Update from @ngompa:
+1 from me
Keeping certbot up to date is "critical infrastructure" in 2024.
We've passed the seven day mark (adjusted for the end-of-year absences) but we don't yet have +3, so voting will extend for another week,
@jonathanspw Good idea. +1 👏
+1
+1
+1
+1
This is APPROVED (+7, 0, 0)
Metadata Update from @ngompa:
Metadata Update from @tstellar:
Announced: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/message/UBVG6IOTUHHY5SHXFHOISZNHK3QLXTMX/