Re: [ANNOUNCE] Apache SpamAssassin 4.0.1 available

2024-03-29 Thread Sidney Markowitz
CNAME record to make sa-update work with new version number 4.0.2 that 
is in svn trunk has been added.


sa-update for trunk should now work again.

I have updated the checklist for release managers to have the update of 
the CNAME record be requested at the start of the 72 hour vote period 
for a full release so that sa-update will continue to work when the 
version number gets bumped up after the vote passes.


Benny, re-reading your email, I see that is not the issue you are 
bringing up... The downloads directory includes the rules files snapshot 
as they were at the time of the release build, which can be used by 
people who don't want to or can't run sa-update after installation. Of 
course, people should be running sa-update or doing something equivalent 
to keep their rules up to date. The snapshot rules file is there for 
anyone who needs it at the time of installation if running sa-update 
then is not feasible.


 Sidney


Benny Pedersen wrote on 30/03/24 7:08 am:

Sidney Markowitz skrev den 2024-03-29 15:25:

  
7e6093c8514e1b18f3b47215dc97d51b7b70142ca2fe7242362c021bf770b2c1c1e99a8227d1c5b9b5d303e405ab9e6a7c67a60b5b03dcb6588bd68c733e2448

   Mail-SpamAssassin-rules-4.0.1.r1916528.tgz


replaced fine with sa-update no ?

is admins just using this one time and not ever croned update and after
upgrade major versions never issue a sa-update :(

now that gentoo have binhost, i see more problems to other distro that
release precompiled problems

anyway thanks for release finaly now





[Bug 8233] New: Add URIBL rules for Validity DNSBL lookups

2024-03-29 Thread bugzilla-daemon
https://bz.apache.org/SpamAssassin/show_bug.cgi?id=8233

Bug ID: 8233
   Summary: Add URIBL rules for Validity DNSBL lookups
   Product: Spamassassin
   Version: SVN Trunk (Latest Devel Version)
  Hardware: PC
OS: Windows 11
Status: NEW
  Severity: normal
  Priority: P2
 Component: spamassassin
  Assignee: dev@spamassassin.apache.org
  Reporter: eric.hokan...@validity.com
  Target Milestone: Undefined

Created attachment 5946
  --> https://bz.apache.org/SpamAssassin/attachment.cgi?id=5946=edit
patch file for validity uribl

Attached is a patch for your review to add URIBL rules recently implemented for
Validity (formerly Return Path) DNSBL lookups. This was tested locally against
IP 209.61.190.180 producing the following matches:

Content analysis details:   (18.8 points, 5.0 required) 

 pts rule name  description 
 -- --  
 0.0 VALIDITY_BLOCKED_SAFE  ADMINISTRATOR NOTICE: The query to Validity 
was blocked.  See   
   
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block   
 for more information.  
[URI: 209.61.190.180]   
 0.0 VALIDITY_BLOCKED_RPBL  ADMINISTRATOR NOTICE: The query to Validity 
was blocked.  See   
   
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block   
 for more information.  
[URI: 209.61.190.180]   
 0.0 VALIDITY_BLOCKED_CERTIFIED ADMINISTRATOR NOTICE: The query to  
Validity was blocked.  See  
   
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block   
 for more information.  
[URI: 209.61.190.180]

...


We would also kindly request an entry on the DNS blocklist wiki page pointing
to our knowledge base article:
https://knowledge.validity.com/hc/en-us/articles/20961730681243-Accessing-Validity-reputation-data-through-DNS

Thank you.

-- 
You are receiving this mail because:
You are the assignee for the bug.

Re: [ANNOUNCE] Apache SpamAssassin 4.0.1 available

2024-03-29 Thread Benny Pedersen

Sidney Markowitz skrev den 2024-03-29 15:25:

 
7e6093c8514e1b18f3b47215dc97d51b7b70142ca2fe7242362c021bf770b2c1c1e99a8227d1c5b9b5d303e405ab9e6a7c67a60b5b03dcb6588bd68c733e2448 
  Mail-SpamAssassin-rules-4.0.1.r1916528.tgz


replaced fine with sa-update no ?

is admins just using this one time and not ever croned update and after 
upgrade major versions never issue a sa-update :(


now that gentoo have binhost, i see more problems to other distro that 
release precompiled problems


anyway thanks for release finaly now



[ANNOUNCE] Apache SpamAssassin 4.0.1 available

2024-03-29 Thread Sidney Markowitz

On behalf of the Apache SpamAssassin Project,
I am pleased to announce version 4.0.1 is available.

Release Notes -- Apache SpamAssassin -- Version 4.0.1


Introduction


Apache SpamAssassin 4.0.1 is a patch release that fixes issues that
have surfaced since the release of 4.0.0. It provides compatibility
with the latest version of Perl, 5.38, which was released in July,
2023, as well as with recent release versions of some required Perl
modules.

Many thanks to the committers (see CREDITS file), contributors, rule
testers, mass checkers, and code testers who have made this release
possible.

Notable features:
=

None noted.

Notable changes
---

This release addresses the following issues:

  - Incompatibilities with some versions of perl and some perl modules
that have been released since the release of SpamAssassin 4.0.0

  - Problems using cpan to install SpamAssassin when certain required
or optional modules are not already installed

  - Support for space characters in the path name of some executables
used by certain plugins

  - Improved handling of URL shortener link redirects

  - Improved TxRep locking management

  - Added Mail::SpamAssassin::Plugin::AuthRes plugin to use
Authentication-Results header fields in other plugins

  - Added a Pyzor Perl implementation

  - Perl crash when certain uri_detail rules processed some messages
with UTF-8 characters

  - Inconsistent handling of newlines in header rules

  - Text or HTML content placed in octet-stream attachments by
spammers to bypass SpamAssassin scanning

  - Implemented TCP fallback for truncated DNS UDP replies

* Spamc can now be built on a Windows platform as part of the gmake
  build procedure, using the compiler toolchain that is part of a
  standard Strawberry Perl installation, with no need to install a
  separate Visual Studio, msys, or mingw.

The detailed list of all commits can be found in the Changes file.
A detailed view of the issues as they were filed in the Bugzilla issue
tracker can be seen at https://s.apache.org/7apqr

New configuration options
-

None noted

Notable Internal changes


None noted

Other updates
-

None noted.


Optimizations
-

None noted

Downloading and availability


Downloads are available from:

https://spamassassin.apache.org/downloads.html

sha256sum of archive files:

 9775ed7559e83ec3e6c03edb2be8ffc7f15cc405fb13e85c148eb0bf191721a8 
Mail-SpamAssassin-4.0.1.tar.bz2
 5c6bb222e18405f1a276816d04e1ffc5cc90785e1265714b4506c2b541d6d5e5 
Mail-SpamAssassin-4.0.1.tar.gz
 728ffbc536fcb4f9bb07adfc72eeb706f8ff1257833bf0bf6c70ab2eea01de97 
Mail-SpamAssassin-4.0.1.zip
 381eadfc7e513e5f735389b78173de5af471f3d06fe6ab8f129634a6644b4bf4 
Mail-SpamAssassin-rules-4.0.1.r1916528.tgz

sha512sum of archive files:

 
66183e356b07d1049cf5598fc1e563e4aab580dfca04bf8ec37781dfb57ef568d33c6f6455076f54f940947f5a5dfefa7a08d233833deea5fe5ea18b669cd790
   Mail-SpamAssassin-4.0.1.tar.bz2
 
7ac2d789d8744dfe37f647013871e293de50cfcd792029956eb6cea8e51343aad135398bd91867c3c21a68e5fb6330bd6b38a04b794a24449a59287b46d4ac70
   Mail-SpamAssassin-4.0.1.tar.gz
 
efed5a7ae2fb4f200c9f248d61bdda44a6e4103b4245b086c3b94f1880e5cee1f19a7b4d810d4553cc566208970052d4f26cc5512fa4a0e1d0d09d4fa54bdd15
   Mail-SpamAssassin-4.0.1.zip
 
7e6093c8514e1b18f3b47215dc97d51b7b70142ca2fe7242362c021bf770b2c1c1e99a8227d1c5b9b5d303e405ab9e6a7c67a60b5b03dcb6588bd68c733e2448
   Mail-SpamAssassin-rules-4.0.1.r1916528.tgz

Note that the Rules files, aka *-rules-*.tgz, are only necessary if
you cannot, or do not wish to, run "sa-update" after
installation. Using sa-update will download the latest rules

See the INSTALL and UPGRADE files in the distribution for important
installation notes


GPG Verification Procedure
--
The release files also have a .asc accompanying them.  The file serves
as an external GPG signature for the given release file.  The signing
key is available via the keys.gnupg.net or keys.openpgp.org key
servers, as well as https://www.apache.org/dist/spamassassin/KEYS


The following key is used to sign SA releases 3.3.0 and later:

pub   4096R/F7D39814 2009-12-02
  Key fingerprint = D809 9BC7 9E17 D7E4 9BC2  1E31 FDE5 2F40 F7D3 9814
uid  SpamAssassin Project Management Committee 

uid  SpamAssassin Signing Key (Code Signing Key, replacement for 
1024D/265FA05B) 
sub   4096R/7B3265A5 2009-12-02

The following key is used to sign rule updates:

pub   4096R/5244EC45 2005-12-20
  Key fingerprint = 5E54 1DC9 59CB 8BAC 7C78  DFDC 4056 A61A 5244 EC45
uid  updates.spamassassin.org Signing Key 

sub   4096R/24F434CE 2005-12-20

To verify a release file, download the file with the accompanying .asc
file and run the following commands:

  gpg --verbose --keyserver keys.openpgp.org --recv-key FDE52F40F7D39814
  gpg 

[RESULT] [VOTE] Release of 4.0.1

2024-03-29 Thread Sidney Markowitz

With four +1, no 0, and no -1 binding votes, the vote to release Apache
SpamAssassin 4.0.1 has PASSED.

I will now commence the remainder of the release process.

Thank you everyone who has helped with coding, testing, and bug
reporting for the 4.0.1 release.

Sidney Markowitz
Chair, Apache SpamAssassin PMC
sid...@apache.org




Re: [VOTE] Release of 4.0.1 - vote will close on Friday, March 29, 2024 06:30am UTC

2024-03-29 Thread giovanni

On 3/26/24 07:26, Sidney Markowitz wrote:

[This email is bcc'd to the Apache PMC to ensure they notice it]

Hello everyone,

Calling for a vote on the release of Apache SpamAssassin 4.0.1

Only votes from members of the PMC will be binding, but everyone is
encouraged to thoroughly test that these files properly install and
pass the make test checks on your platform and any other tests that
you can perform.

Here are the files that will be released as Apache SpamAssassin 4.0.1
if there are at least three binding +1 votes and more +1 votes
than -1 binding votes at the end of the 72 hour voting period,
Friday, March 29, 2024 06:30am UTC.

Note that the policy on voting for releases is not the same as for
voting for code committing where a single binding -1 is a veto.

Files are inĀ  https://dist.apache.org/repos/dist/dev/spamassassin/

There have been a few minor commits since the release of 4.0.1-rc1.
We think those changes are safe, but definitely test these release
files to be sure.

As per https://www.apache.org/legal/release-policy.html#release-approval
please download and check the files on your platform(s) before voting
+1 if you approve the release, or -1 and state a technical reason why
these files are not ready for release.

The current draft of the release announcement can be seen at
https://svn.apache.org/repos/asf/spamassassin/trunk/build/announcements/4.0.1.txt

I vote +1 for release after checking on Ubuntu 22.04, macOS 13, and Windows 10.


+1 to make release.
Tested on CentOS8-Stream, Fedora39, OpenBSD-7.5

Thanks for rming.
 Giovanni



OpenPGP_signature.asc
Description: OpenPGP digital signature