oss-fuzz icon indicating copy to clipboard operation
oss-fuzz copied to clipboard

python-multipart: initial integration

Open manunio opened this issue 3 years ago • 12 comments

Hi, python-multipart is a streaming multipart parser for Python. It has 2 million+ monthly downloads as per pypistats, and is being used by projects like fastapi, starlette.

manunio avatar Sep 02 '22 15:09 manunio

Hi @jonathanmetzman please review this pr.

manunio avatar Sep 08 '22 07:09 manunio

Hi @Navidem please review this pr :)

manunio avatar Sep 12 '22 18:09 manunio

Has upstream agreed to this?

jonathanmetzman avatar Sep 18 '22 00:09 jonathanmetzman

Has upstream agreed to this?

@jonathanmetzman There's no response yet.

manunio avatar Sep 18 '22 08:09 manunio

Has upstream agreed to this?

@jonathanmetzman There's no response yet.

We don't accept projects unless upstream agrees

jonathanmetzman avatar Sep 18 '22 10:09 jonathanmetzman

Has upstream agreed to this?

@jonathanmetzman There's no response yet.

We don't accept projects unless upstream agrees

@jonathanmetzman thanks for the review, can you please clear doubt of mine. I can see pr https://github.com/google/oss-fuzz/pull/8347 with no response being merged. Whats the difference here? Just curious thanks.

manunio avatar Sep 18 '22 11:09 manunio

cc @oliverchang

manunio avatar Sep 18 '22 14:09 manunio

Has upstream agreed to this?

@jonathanmetzman There's no response yet.

We don't accept projects unless upstream agrees

@jonathanmetzman thanks for the review, can you please clear doubt of mine. I can see pr #8347 with no response being merged. Whats the difference here? Just curious thanks.

These are our contractors and we treat these projects differently.

jonathanmetzman avatar Sep 18 '22 14:09 jonathanmetzman

These are our contractors and we treat these projects differently.

@jonathanmetzman a previous pr: https://github.com/google/oss-fuzz/pull/8279 of mine was merged same way, that's why it was creating confusion for me.

manunio avatar Sep 18 '22 14:09 manunio

I probably shouldn't have merged it because there's no one upstream to accept bug reports, but there's a linked issue where upstream agreed to the integration. Here there is nothing

jonathanmetzman avatar Sep 18 '22 14:09 jonathanmetzman

I probably shouldn't have merged it because there's no one upstream to accept bug reports, but there's a linked issue where upstream agreed to the integration. Here there is nothing

Yes, that was because maintainer agreed a day or two later. and thanks for clearing my doubts I'll keep this in mind for my contributions :)

manunio avatar Sep 18 '22 14:09 manunio

I probably shouldn't have merged it because there's no one upstream to accept bug reports, but there's a linked issue where upstream agreed to the integration. Here there is nothing

Yes, that was because maintainer agreed a day or two later. and thanks for clearing my doubts I'll keep this in mind for my contributions :)

Yeah youre right, their agreement was later. I shouldn't have merged it but it ended up being OK.

jonathanmetzman avatar Sep 18 '22 14:09 jonathanmetzman