Bug 2446966 - Retire python-PyPDF2 for Fedora 45+ [NEEDINFO]
Summary: Retire python-PyPDF2 for Fedora 45+
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: python-PyPDF2
Version: 45
Hardware: Unspecified
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Ranjan Maitra
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On: 2438989 2357714
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-12 15:34 UTC by Tadej Janež
Modified: 2026-08-17 14:18 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:
tadej.j: needinfo? (itsme_410)


Attachments (Terms of Use)

Description Tadej Janež 2026-03-12 15:34:52 UTC
The PyPDF2 project has been migrated/moved into the pypdf project.

We already have pypdf packaged separately:
https://src.fedoraproject.org/rpms/python-pypdf

Felix Schwarz talked about PyPDF2 retirement in the python-pypdf review request in May 2024:
https://bugzilla.redhat.com/show_bug.cgi?id=2279080#c7

As of today, only 2 packages in rawhide still depend on PyPDF2:
$ dnf4 repoquery --whatrequires python3-PyPDF2 --source --repo rawhide
Last metadata expiration check: 0:00:03 ago on Thu 12 Mar 2026 04:29:04 PM CET.
krop-0.5.1-29.fc44.src.rpm
pdf-stapler-1.0.0-0.27.20191215git8753251.fc44.src.rpm

Krop should be updated to version 0.7.0 which should:
- Support the new version of pypdf in addition to its predecessor PyPDF2 (thanks to Emmanuel Rosa for the idea and initial code)
(see: https://arminstraub.com/software/krop#changelog)
The bug to update Krop to version 0.7.0 is here: https://bugzilla.redhat.com/show_bug.cgi?id=2357714.

The PDF Stapler project upstream appears to be unmaintained for a long time (since Mar 2022):
https://github.com/hellerbarde/stapler/issues/99
And it currently FTBFS in Fedora:
https://bugzilla.redhat.com/show_bug.cgi?id=2438989


Reproducible: Always

Comment 1 Tadej Janež 2026-07-02 12:04:24 UTC
Krop has been updated to 0.7.0 in rawhide, so ti no longer blocks this.

PDF Stapler is the only package in rawhide that still depends on this as of today:
$ dnf4 repoquery --whatrequires python3-PyPDF2 --source --repo rawhide
Last metadata expiration check: 0:00:01 ago on Thu 02 Jul 2026 01:50:58 PM CEST.
pdf-stapler-1.0.0-0.28.20191215git8753251.fc45.src.rpm

Given the recent high number of CVEs reported against PyPDF2/pypdf, we should proceed with retiring both, PDF Stapler and then PyPDF2.

@itsme_410, agreed?

Comment 2 Ranjan Maitra 2026-07-03 06:18:44 UTC
Thank you. Yes, I agree. I will see if I can figure out how to package pdfly.

Comment 3 Tadej Janež 2026-07-03 09:20:25 UTC
(In reply to Ranjan Maitra from comment #2)
> Thank you. Yes, I agree.

Ok, great. Please, let me know if you need any assistance with retiring both.

I think you should retire PDF Stapler first then after it's been retired, proceed with PyPDF2.

> I will see if I can figure out how to package pdfly.

Great. I can help with that as well.

Comment 4 Tadej Janež 2026-08-01 09:32:44 UTC
@itsme_410, can you proceed with retiring PDF Stapler followed by PyPDF2?

Comment 5 Aoife Moloney 2026-08-17 14:18:11 UTC
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.


Note You need to log in before you can comment on or make changes to this bug.