severity -1 normal
thanks

Hi Matthias,

I have failed to reproduce this. I have built 0.19.6-2 in a clean
pbuilder chroot and got

        neurodebian@smaug ~/deb/builds/datalad/0.19.6-2-rebuild % grep -1 
'Searching for tqdm' *build
        datalad_0.19.6-2_amd64.build-Using /usr/lib/python3/dist-packages
        datalad_0.19.6-2_amd64.build:Searching for tqdm==4.66.4
        datalad_0.19.6-2_amd64.build-Best match: tqdm 4.66.4
        --
        datalad_0.19.6-2_amd64.build-Using /usr/lib/python3/dist-packages
        datalad_0.19.6-2_amd64.build:Searching for tqdm==4.66.4
        datalad_0.19.6-2_amd64.build-Best match: tqdm 4.66.4
        --
        datalad_0.19.6-2_amd64.build-Using /usr/lib/python3/dist-packages
        datalad_0.19.6-2_amd64.build:Searching for tqdm==4.66.4
        datalad_0.19.6-2_amd64.build-Best match: tqdm 4.66.4

then I updated and uploaded packaging for 1.1.0-1 and saw similar hits, no 
attempts to get to pypi:

        neurodebian@smaug ~/deb/builds/datalad/0.19.6-2-rebuild % grep 'Reading 
https://pypi.org/' *build
        neurodebian@smaug ~/deb/builds/datalad/1.1.0-1 % grep 'Reading 
https://pypi.org/' *build

NB Frankly, removing setting empty http_proxy resulted in tests to freeze but
that is orthogonal to this since tests are ran past installation of
depends.

So it would be interesting to know more details on the process to build the
package.  If could be reproduced from a blank debian system (may be a
dockerfile or alike to reproduce) -- would be great.

As can't reproduce, lowering severity

Cheers,

On Tue, 26 Mar 2024, Matthias Klose wrote:

> Package: src:datalad
> Version: 0.19.6-2
> Severity: serious
> Tags: sid trixie

> datalad downloads dependencies during the build:

> [...]
> running build_ext
> Creating /<<PKGBUILDDIR>>/bin/datalad.egg-link (link to .)
> Adding datalad 0.19.6 to easy-install.pth file
> Installing datalad script to bin
> Installing git-annex-remote-datalad script to bin
> Installing git-annex-remote-datalad-archives script to bin
> Installing git-annex-remote-ora script to bin
> Installing git-annex-remote-ria script to bin
> Installing git-credential-datalad script to bin

> Installed /<<PKGBUILDDIR>>
> Processing dependencies for datalad==0.19.6
> Searching for tqdm>=4.32.0
> Reading https://pypi.org/simple/tqdm/
> Downloading 
> https://files.pythonhosted.org/packages/2a/14/e75e52d521442e2fcc9f1df3c5e456aead034203d4797867980de558ab34/tqdm-4.66.2-py3-none-any.whl#sha256=1ee4f8a893eb9bef51c6e35730cebf234d5d0b6bd112b0271e10ed7c24a02bd9
> Best match: tqdm 4.66.2
> Processing tqdm-4.66.2-py3-none-any.whl
> Installing tqdm-4.66.2-py3-none-any.whl to /<<PKGBUILDDIR>>/bin
> Adding tqdm 4.66.2 to easy-install.pth file
> Installing tqdm script to bin



-- 
Yaroslav O. Halchenko
Center for Open Neuroscience     http://centerforopenneuroscience.org
Dartmouth College, 419 Moore Hall, Hinman Box 6207, Hanover, NH 03755
WWW:   http://www.linkedin.com/in/yarik        

Attachment: signature.asc
Description: PGP signature

Reply via email to