Bug 2415237 - Review Request: skipfish - Web application security scanner
Summary: Review Request: skipfish - Web application security scanner
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Nobody's working on this, feel free to take it
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-11-16 05:57 UTC by Michal Ambroz
Modified: 2025-11-19 11:15 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Michal Ambroz 2025-11-16 05:57:27 UTC
Spec URL: https://rebus.fedorapeople.org/skipfish.spec
SRPM URL: https://rebus.fedorapeople.org/skipfish-2.10-0.24.b.fc42.src.rpm

Description:
High-performance, easy, and sophisticated Web application security testing
tool. It features a single-threaded multiplexing HTTP stack, heuristic
detection of obscure Web frameworks, and advanced, differential security
checks capable of detecting blind injection vulnerabilities, stored XSS,
and so forth.

Fedora Account System Username: rebus

Comment 1 Michal Ambroz 2025-11-16 05:59:45 UTC
Hello,
using the patches from debian/kali I would like to revive in Fedora a skipfish package, which I was previously maintaining.

Scratchbuild is here https://koji.fedoraproject.org/koji/taskinfo?taskID=138955541

Michal Ambroz

Comment 2 Fedora Review Service 2025-11-16 06:02:20 UTC
Copr build:
https://copr.fedorainfracloud.org/coprs/build/9802157
(succeeded)

Review template:
https://download.copr.fedorainfracloud.org/results/@fedora-review/fedora-review-2415237-skipfish/fedora-rawhide-x86_64/09802157-skipfish/fedora-review/review.txt

Found issues:

- pcre-devel is deprecated, you must not depend on it.
  Read more: https://docs.fedoraproject.org/en-US/packaging-guidelines/deprecating-packages/
- License file COPYING is not marked as %license
  Read more: https://docs.fedoraproject.org/en-US/packaging-guidelines/LicensingGuidelines/#_license_text
- A package with this name already exists. Please check https://src.fedoraproject.org/rpms/skipfish
  Read more: https://docs.fedoraproject.org/en-US/packaging-guidelines/Naming/#_conflicting_package_names

Please know that there can be false-positives.

---
This comment was created by the fedora-review-service
https://github.com/FrostyX/fedora-review-service

If you want to trigger a new Copr build, add a comment containing new
Spec and SRPM URLs or [fedora-review-service-build] string.

Comment 3 Michal Ambroz 2025-11-17 00:13:44 UTC
Spec URL: https://rebus.fedorapeople.org/skipfish.spec
SRPM URL: https://rebus.fedorapeople.org/skipfish-2.10-0.25.b.fc42.src.rpm

> - License file COPYING is not marked as %license
truth - fixed

> - A package with this name already exists. Please check https://src.fedoraproject.org/rpms/skipfish
yes package exists and I am the package owner. It was FTPBFS for some time due to changes in gcc.
I managed to make it compile again with couple of patches from debian/kali.

> - pcre-devel is deprecated, you must not depend on it.
next thing I will be working on
For now - this is not a new dependency for this package, I hope it is not blocker for this package to be re-approved.


Note You need to log in before you can comment on or make changes to this bug.