|
| 1 | +# conda-forge core meeting 2023-01-25 |
| 2 | + |
| 3 | +Add new agenda items under the `Your __new__() agenda items` heading |
| 4 | + |
| 5 | +[last weeks meeting](https://hackmd.io/CHleuNR-RsmpqnOa3IvF-A) |
| 6 | +[What time is the meeting in my time zone](https://arewemeetingyet.com/UTC/2020-08-26/17:00/w/Conda-forge%20dev%20meeting#eyJ1cmwiOiJodHRwczovL2hhY2ttZC5pby9wUk15dFVKV1FmU3NJM2xvMGlqQzJRP2VkaXQifQ==) |
| 7 | +Meeting info: |
| 8 | +* To join the video meeting, click this link: https://zoom.us/j/9138593505?pwd=SWh3dE1IK05LV01Qa0FJZ1ZpMzJLZz09 |
| 9 | +* Otherwise, to join by phone, dial +1 347-384-8597 and enter this PIN: 828 997 153# |
| 10 | +* To view more phone numbers, click this link: https://tel.meet/ijv-qsvm-tvn?hs=5 |
| 11 | + |
| 12 | +## Attendees |
| 13 | + |
| 14 | +| Name | Initials | GitHub ID | Affiliation | |
| 15 | +| ----------------------- | -------- | --------------- | --------------------------- | |
| 16 | +| Jaime Rodríguez-Guerra | JRG | jaimergp | Quansight / cf | |
| 17 | +| John Kirkham | JK | jakirkham | NVIDIA / cf | |
| 18 | +| Dave Clements | DPC | tnabtaf | Anaconda | |
| 19 | +| Cheng H. Lee | CHL | chenghlee | Anaconda / cf | |
| 20 | +| Jannis Leidel | JL | jezdez | Anaconda / cf | |
| 21 | +| | | | | |
| 22 | +| | | | | |
| 23 | +| | | | | |
| 24 | +| | | | | |
| 25 | +| | | | | |
| 26 | +| | | | | |
| 27 | +| | | | | |
| 28 | +| | | | | |
| 29 | +| | | | | |
| 30 | +| | | | | |
| 31 | +| | | | | |
| 32 | +| | | | | |
| 33 | + |
| 34 | +9 people total |
| 35 | + |
| 36 | + |
| 37 | +### Standing items |
| 38 | + |
| 39 | +* [ ] intros for new folks on the call |
| 40 | + |
| 41 | +* [ ] open votes |
| 42 | + |
| 43 | +### From previous meeting(s) |
| 44 | + |
| 45 | +* [ ] (MRB) updates on bots and secrets |
| 46 | + * we've centralized most of what we use in 1password |
| 47 | + * i've removed some of the keybase files that are old or misleading |
| 48 | + * we use github apps for everything where we can |
| 49 | + * will develop notes |
| 50 | +* [X] (HV) OpenSSL 3: https://github.com/conda-forge/conda-forge-pinning-feedstock/issues/3838 |
| 51 | + * JRG: Decision was made to close the migration. |
| 52 | + |
| 53 | +### Active votes |
| 54 | + |
| 55 | +### Your __new__() agenda items |
| 56 | + |
| 57 | +- [x] (JRG) GSoC applications: my ideas |
| 58 | + - Application time is open. |
| 59 | + - For CZI grant building infrastructure |
| 60 | + - Using Docusaurs web site |
| 61 | + - Use this momemtum to refactor conda-forge website? |
| 62 | + - Example: |
| 63 | + - https://czi-cf-docs.netlify.app |
| 64 | + - https://github.com/quansight-labs/czi-cf-docs |
| 65 | + - No pushback at all. |
| 66 | +- [x] (JRG) NumFOCUS SDG for opt-in CI |
| 67 | + - Small Development Grant |
| 68 | + - https://numfocus.org/programs/small-development-grants |
| 69 | + - Applications start ... soon (Feb 15?) |
| 70 | + - Build access control for CI. |
| 71 | + - They have cycles and out of cycle grant submission. |
| 72 | + - out of cycle are less likely to be approved. |
| 73 | + - This is not urgent. |
| 74 | + - Larger issue |
| 75 | + - **Do we need to vote on approving grant submissions?** |
| 76 | + - Feeling is no. We notify this group so we don't collide and to see if there are objections, but no formal vote. |
| 77 | + - Aligning on Travis? |
| 78 | + - Travis has been a little unstable lately. |
| 79 | + - https://github.com/conda-forge/conda-forge.github.io/issues/1875 |
| 80 | + - Could make travis opt in. |
| 81 | + - Requires access controls. |
| 82 | + - |
| 83 | +- [x] (JRG) Certificates for signed installers |
| 84 | + - Miniforge |
| 85 | + - Sign installers that miniforge produces. |
| 86 | + - Have a certificate from NumFOCUS for apple, but not windows |
| 87 | + - https://github.com/conda-forge/miniforge/issues/201 |
| 88 | + - Talking to Steve Dower @ Microsoft ( https://github.com/zooba ) for advice |
| 89 | + - Could do this for the whole community (?) (see point by Jannis below) |
| 90 | + - Need to look up if an EV cert is required and possibly other things (e.g., timestamping) |
| 91 | + - Concern about security/access to tokens/passwords on CI by non-core |
| 92 | + - Disolve miniforge team? |
| 93 | + - Promote them to core? |
| 94 | + - Some other way to do signing that avoids this issue? |
| 95 | + - ??? |
| 96 | + - JRG: Minimized in a way with [AzureSignTool](https://github.com/vcsjones/AzureSignTool), which relies on an Azure Vault instead of passing raw certificates. |
| 97 | + - CHL: Can get Anaconda supply chain security team to take a look, since that's work we are doing anyways. |
| 98 | +- [x] (JL) Conda Installer Team |
| 99 | + - [ ] future conda community governance team to handle underlying code/proceses to build conda installers |
| 100 | + - [ ] interest into joining miniforge and mambaforge into the team/repo? |
| 101 | + - [ ] still in the aligning/team charter writing phase |
| 102 | +- [x] (DPC) conda-forge tutorial proposal accepted at PyCon US 2023 |
| 103 | + - Schedule is not published yet. |
| 104 | + - One output is updated docs for conda-forge/staged-recipes |
| 105 | + - (JRG) Could create an element room for tutorial q&a |
| 106 | + - FF: Seek help from the community. Tweet about possible help room for participants |
| 107 | +- [x] (JK) OpenSSL |
| 108 | + - TensorFlow was a blocker. Has already been rebuilt. |
| 109 | + - Couple others with unknown status. |
| 110 | + - With Ruby you need a current version of Ruby |
| 111 | + - Same with NodeJS. |
| 112 | + - Is this done enough? |
| 113 | + - We talked about it in this call. There was no opposition. In fact there was outright support for closing it! |
| 114 | + - so: **Yes let's close.** |
| 115 | + - Who will do this? JRG will do this. |
| 116 | + |
| 117 | +### Pushed to next meeting |
| 118 | + |
| 119 | +### CFEPs |
| 120 | + |
| 121 | +* [cfep-12](https://github.com/conda-forge/cfep/pull/23) Removing packages that violate the terms of the source package |
| 122 | + * Stalled since May 26, 2020 |
| 123 | + * Active debate about moving to "broken" vs deleting from conda-forge channel |
| 124 | + * Active vote, ends on 2020-03-11 |
| 125 | + * What were the results of the vote? |
| 126 | + * Did we hear back from NumFOCUS? they did the legal seminar which is recorded |
| 127 | + * And, see above too. |
0 commit comments