From jmckenna at gatewaygeomatics.com Mon Jul 6 12:32:42 2026 From: jmckenna at gatewaygeomatics.com (Jeff McKenna) Date: Mon, 6 Jul 2026 16:32:42 -0300 Subject: [MapServer-dev] Plan for 8.6.5 release Message-ID: <470f4683-5d07-43c1-a671-639456895da5@gatewaygeomatics.com> Hi all, Hope everyone is having a good summer. As there are a few "important" fixes coming in branch-8-6 (see https://github.com/MapServer/MapServer/pulls ) I am thinking of doing an 8.6.5 release on this coming Friday. That will give everyone some more time to tackle some issues. If you think we should wait a bit longer before 8.6.5, please speak up here. (recently we/MapServer have had to do a monthly security release it seems) (related read: OpenSSL's "summer of bliss" https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/ ) thanks, -jeff From jmckenna at gatewaygeomatics.com Mon Jul 6 12:36:42 2026 From: jmckenna at gatewaygeomatics.com (Jeff McKenna) Date: Mon, 6 Jul 2026 16:36:42 -0300 Subject: [MapServer-dev] Plan for 8.6.5 release In-Reply-To: <470f4683-5d07-43c1-a671-639456895da5@gatewaygeomatics.com> References: <470f4683-5d07-43c1-a671-639456895da5@gatewaygeomatics.com> Message-ID: <7b9e1ac4-b402-48d7-9b19-8582f2407f69@gatewaygeomatics.com> Sorry I meant cURL, not OpenSSL ;) (it seems I work full-time battling these security releases ha, they all blur into one) thanks, -jeff On 2026-07-06 4:32 p.m., Jeff McKenna via MapServer-dev wrote: > Hi all, > > Hope everyone is having a good summer. > > As there are a few "important" fixes coming in branch-8-6 (see https:// > github.com/MapServer/MapServer/pulls ) I am thinking of doing an 8.6.5 > release on this coming Friday.? That will give everyone some more time > to tackle some issues. If you think we should wait a bit longer before > 8.6.5, please speak up here.? (recently we/MapServer have had to do a > monthly security release it seems) > > (related read: OpenSSL's "summer of bliss" https://daniel.haxx.se/ > blog/2026/06/15/curl-summer-of-bliss/ ) > > thanks, > > -jeff > > > > > > > > _______________________________________________ > MapServer-dev mailing list > MapServer-dev at lists.osgeo.org > https://lists.osgeo.org/mailman/listinfo/mapserver-dev > -- Jeff McKenna GatewayGeo: Developers of MS4W, & offering MapServer Consulting/Dev co-founder of FOSS4G http://gatewaygeo.com/ From even.rouault at spatialys.com Tue Jul 7 04:41:35 2026 From: even.rouault at spatialys.com (Even Rouault) Date: Tue, 7 Jul 2026 13:41:35 +0200 Subject: [MapServer-dev] service providers: empty list, to check who is still on board Message-ID: <5d974625-a87d-4735-beeb-bfcfd1767b95@spatialys.com> Hi, I think we discussed that the list should be rebooted every couple years or so to keep it updated, so https://github.com/MapServer/MapServer-documentation/pull/1097 Even -- http://www.spatialys.com My software is free, but my time generally not. LLMs contribute to global warming and brain rot From jmckenna at gatewaygeomatics.com Tue Jul 7 05:18:53 2026 From: jmckenna at gatewaygeomatics.com (Jeff McKenna) Date: Tue, 7 Jul 2026 09:18:53 -0300 Subject: [MapServer-dev] service providers: empty list, to check who is still on board In-Reply-To: <5d974625-a87d-4735-beeb-bfcfd1767b95@spatialys.com> References: <5d974625-a87d-4735-beeb-bfcfd1767b95@spatialys.com> Message-ID: <914d00cf-c09e-480f-8f54-d419cf30bf8c@gatewaygeomatics.com> I think it is a good time to renew the commitment of my company, GatewayGeo, to MapServer and its community. GatewayGeo has been consistently providing time and effort to the development of MapServer, including: - assist the triage of security reports, manual testing, and publishing of fixes through releases as needed - constant documentation improvements - development of MS4W releases, for the Windows community - on-demand updates & improvements to the heavily-used demo.mapserver.org services, providing near 100% up-time - help with MapServer releases (often includes manual testing, and CI management) GatewayGeo is proudly committed to continuing this constant support to the MapServer community, to help in every way possible. thanks, -jeff On 2026-07-07 8:41 a.m., Even Rouault via MapServer-dev wrote: > Hi, > > I think we discussed that the list should be rebooted every couple years > or so to keep it updated, so https://github.com/MapServer/MapServer- > documentation/pull/1097 > > Even > From even.rouault at spatialys.com Tue Jul 7 14:08:47 2026 From: even.rouault at spatialys.com (Even Rouault) Date: Tue, 7 Jul 2026 23:08:47 +0200 Subject: [MapServer-dev] Limit open pull requests from users without write access: 3 Message-ID: <261ba04b-7320-4030-91cb-b5558449d7a5@spatialys.com> As we're getting pull requests from agents (that I'm personally unwilling to review), I've changed https://github.com/MapServer/MapServer/settings/interaction_limits to Pull request limits Restrict how many pull requests users without write access can have open at one time and add specific users to a bypass list. These settings stay in effect until you change them. Currently, users without write access can have up to *3* open pull requests at a time. Limit open pull requests from users without write access Loading Maximum open pull requests per user Enter a number from 1 to 1000 -- http://www.spatialys.com My software is free, but my time generally not. LLMs contribute to global warming and brain rot -------------- next part -------------- An HTML attachment was scrubbed... URL: From steve.lime at state.mn.us Tue Jul 7 14:22:23 2026 From: steve.lime at state.mn.us (Lime, Steve D (MNIT)) Date: Tue, 7 Jul 2026 21:22:23 +0000 Subject: [MapServer-dev] Limit open pull requests from users without write access: 3 In-Reply-To: <261ba04b-7320-4030-91cb-b5558449d7a5@spatialys.com> References: <261ba04b-7320-4030-91cb-b5558449d7a5@spatialys.com> Message-ID: +1 on 3 - your guess is as good as mine. From: MapServer-dev On Behalf Of Even Rouault via MapServer-dev Sent: Tuesday, July 7, 2026 4:09 PM To: 'MapServer Dev Mailing List' Subject: [MapServer-dev] Limit open pull requests from users without write access: 3 This message may be from an external email source. Do not select links or open attachments unless verified. Report all suspicious emails to Minnesota IT Services Security Operations Center. ________________________________ As we're getting pull requests from agents (that I'm personally unwilling to review), I've changed https://github.com/MapServer/MapServer/settings/interaction_limits to Pull request limits Restrict how many pull requests users without write access can have open at one time and add specific users to a bypass list. These settings stay in effect until you change them. Currently, users without write access can have up to 3 open pull requests at a time. [X] Limit open pull requests from users without write access Loading Maximum open pull requests per user Enter a number from 1 to 1000 -- http://www.spatialys.com My software is free, but my time generally not. LLMs contribute to global warming and brain rot -------------- next part -------------- An HTML attachment was scrubbed... URL: From even.rouault at spatialys.com Tue Jul 7 18:18:49 2026 From: even.rouault at spatialys.com (Even Rouault) Date: Wed, 8 Jul 2026 03:18:49 +0200 Subject: [MapServer-dev] Limit open pull requests from users without write access: 3 In-Reply-To: References: <261ba04b-7320-4030-91cb-b5558449d7a5@spatialys.com> Message-ID: I believe all those 3 PRs should be closed. The profile of the account says "Hi, I'm ** Agent. Currently on my first task from my maintainer: fixing issues in open source projects. Feedback is always welcome ? it helps me get better." ?There's clearly no human. This is a straightforward violation of our AI tool policy. Le 07/07/2026 ? 23:22, Lime, Steve D (MNIT) via MapServer-dev a ?crit?: > > +1 on 3 - your guess is as good as mine. > > *From:*MapServer-dev *On > Behalf Of *Even Rouault via MapServer-dev > *Sent:* Tuesday, July 7, 2026 4:09 PM > *To:* 'MapServer Dev Mailing List' > *Subject:* [MapServer-dev] Limit open pull requests from users without > write access: 3 > > > > > *This message may be from an external email source.* > > Do not select links or open attachments unless verified. Report all > suspicious emails to Minnesota IT Services Security Operations Center. > > ------------------------------------------------------------------------ > > As we're getting pull requests from agents (that I'm personally > unwilling to review), I've changed > https://github.com/MapServer/MapServer/settings/interaction_limits to > > > Pull request limits > > Restrict how many pull requests users without write access can have > open at one time and add specific users to a bypass list. These > settings stay in effect until you change them. > > Currently, users without write access can have up to *3* open pull > requests at a time. > > [X] Limit open pull requests from users without write access Loading > > Maximum open pull requests per user > > Enter a number from 1 to 1000 > > -- > http://www.spatialys.com > My software is free, but my time generally not. > LLMs contribute to global warming and brain rot > > _______________________________________________ > MapServer-dev mailing list > MapServer-dev at lists.osgeo.org > https://lists.osgeo.org/mailman/listinfo/mapserver-dev -- http://www.spatialys.com My software is free, but my time generally not. LLMs contribute to global warming and brain rot -------------- next part -------------- An HTML attachment was scrubbed... URL: From sethg at geographika.co.uk Wed Jul 8 01:49:28 2026 From: sethg at geographika.co.uk (Seth G) Date: Wed, 08 Jul 2026 11:49:28 +0300 Subject: [MapServer-dev] Plan for 8.6.5 release In-Reply-To: <470f4683-5d07-43c1-a671-639456895da5@gatewaygeomatics.com> References: <470f4683-5d07-43c1-a671-639456895da5@gatewaygeomatics.com> Message-ID: Hi Jeff, Happy with a new security release if you have time to make one. I'm on holidays at the moment so no new PRs from me for the next week or so. I mentioned the problem of security related issues at FOSS4G Europe - https://geographika.github.io/mapserver-state-2026/#/2/1 - the slide is already out-of-date and the figures likely need to be doubled again. Seth -- web:https://geographika.net & https://mapserverstudio.net mastodon: @geographika at mastodon.social On Mon, Jul 6, 2026, at 10:32 PM, Jeff McKenna via MapServer-dev wrote: > Hi all, > > Hope everyone is having a good summer. > > As there are a few "important" fixes coming in branch-8-6 (see > https://github.com/MapServer/MapServer/pulls ) I am thinking of doing an > 8.6.5 release on this coming Friday. That will give everyone some more > time to tackle some issues. If you think we should wait a bit longer > before 8.6.5, please speak up here. (recently we/MapServer have had to > do a monthly security release it seems) > > (related read: OpenSSL's "summer of bliss" > https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/ ) > > thanks, > > -jeff > > > > > > > > _______________________________________________ > MapServer-dev mailing list > MapServer-dev at lists.osgeo.org > https://lists.osgeo.org/mailman/listinfo/mapserver-dev From sethg at geographika.co.uk Wed Jul 8 01:58:36 2026 From: sethg at geographika.co.uk (Seth G) Date: Wed, 08 Jul 2026 11:58:36 +0300 Subject: [MapServer-dev] Limit open pull requests from users without write access: 3 In-Reply-To: References: <261ba04b-7320-4030-91cb-b5558449d7a5@spatialys.com> Message-ID: <89feae63-b6a1-4ed6-96ac-440e60e4886a@app.fastmail.com> +1 to the limit. I would say we should link to the AI policy and give a warning to https://github.com/loom-agent but as the profile says it is an agent we can just close these. Tamas already tried the fix in https://github.com/MapServer/MapServer/pull/7565 without it resolving the issue (based on reading the comments). -- web:https://geographika.net & https://mapserverstudio.net mastodon: @geographika at mastodon.social On Wed, Jul 8, 2026, at 4:18 AM, Even Rouault via MapServer-dev wrote: > I believe all those 3 PRs should be closed. The profile of the account says "Hi, I'm ** Agent. Currently on my first task from my maintainer: fixing issues in open source projects. Feedback is always welcome ? it helps me get better." There's clearly no human. This is a straightforward violation of our AI tool policy. > > Le 07/07/2026 ? 23:22, Lime, Steve D (MNIT) via MapServer-dev a ?crit : >> +1 on 3 - your guess is as good as mine. >> >> *From:* MapServer-dev *On Behalf Of *Even Rouault via MapServer-dev >> *Sent:* Tuesday, July 7, 2026 4:09 PM >> *To:* 'MapServer Dev Mailing List' >> *Subject:* [MapServer-dev] Limit open pull requests from users without write access: 3 >> >> >> *This message may be from an external email source.* >> Do not select links or open attachments unless verified. Report all suspicious emails to Minnesota IT Services Security Operations Center. >> >> >> As we're getting pull requests from agents (that I'm personally unwilling to review), I've changed https://github.com/MapServer/MapServer/settings/interaction_limits to >> >> Pull request limits >> >> Restrict how many pull requests users without write access can have open at one time and add specific users to a bypass list. These settings stay in effect until you change them. >> >> Currently, users without write access can have up to *3* open pull requests at a time. >> >> [X] Limit open pull requests from users without write access Loading >> Maximum open pull requests per user >> Enter a number from 1 to 1000 >> >> >> >> -- http://www.spatialys.comMy software is free, but my time generally not.LLMs contribute to global warming and brain rot >> >> _______________________________________________ >> MapServer-dev mailing list >> MapServer-dev at lists.osgeo.org >> https://lists.osgeo.org/mailman/listinfo/mapserver-dev > -- > http://www.spatialys.com > My software is free, but my time generally not. > LLMs contribute to global warming and brain rot > _______________________________________________ > MapServer-dev mailing list > MapServer-dev at lists.osgeo.org > https://lists.osgeo.org/mailman/listinfo/mapserver-dev > -------------- next part -------------- An HTML attachment was scrubbed... URL: From jbo-ads at mailo.com Wed Jul 8 02:27:44 2026 From: jbo-ads at mailo.com (jbo-ads at mailo.com) Date: Wed, 8 Jul 2026 11:27:44 +0200 Subject: [MapServer-dev] Limit open pull requests from users without write access: 3 In-Reply-To: <89feae63-b6a1-4ed6-96ac-440e60e4886a@app.fastmail.com> References: <261ba04b-7320-4030-91cb-b5558449d7a5@spatialys.com> <89feae63-b6a1-4ed6-96ac-440e60e4886a@app.fastmail.com> Message-ID: <6802d73d-9822-45f3-ae94-ec2254c969f0@mailo.com> +1 on a limit of 3 On 7/8/26 10:58, Seth G via MapServer-dev wrote: > +1 to the limit. > > I would say we should link to the AI policy and give a warning to > https://github.com/loom-agent?but as the profile says it is an agent > we can just close these. Tamas already tried the fix in > https://github.com/MapServer/MapServer/pull/7565?without it resolving > the issue (based on reading the comments). > > -- > web:https://geographika.net & https://mapserverstudio.net > mastodon: @geographika at mastodon.social > > On Wed, Jul 8, 2026, at 4:18 AM, Even Rouault via MapServer-dev wrote: >> >> I believe all those 3 PRs should be closed. The profile of the >> account says "Hi, I'm ** Agent. Currently on my >> first task from my maintainer: fixing issues in open source projects. >> Feedback is always welcome ? it helps me get better."? ?There's >> clearly no human. This is a straightforward violation of our AI tool >> policy. >> >> Le 07/07/2026 ? 23:22, Lime, Steve D (MNIT) via MapServer-dev a ?crit?: >>> >>> +1 on 3 - your guess is as good as mine. >>> >>> *From:*MapServer-dev >>> *On Behalf Of *Even >>> Rouault via MapServer-dev >>> *Sent:* Tuesday, July 7, 2026 4:09 PM >>> *To:* 'MapServer Dev Mailing List' >>> >>> *Subject:* [MapServer-dev] Limit open pull requests from users >>> without write access: 3 >>> >>> >>> >>> >>> *This message may be from an external email source.* >>> >>> Do not select links or open attachments unless verified. Report all >>> suspicious emails to Minnesota IT Services Security Operations Center. >>> >>> ------------------------------------------------------------------------ >>> >>> As we're getting pull requests from agents (that I'm personally >>> unwilling to review), I've changed >>> https://github.com/MapServer/MapServer/settings/interaction_limits >>> to >>> >>> >>> Pull request limits >>> >>> Restrict how many pull requests users without write access can have >>> open at one time and add specific users to a bypass list. These >>> settings stay in effect until you change them. >>> >>> Currently, users without write access can have up to *3* open pull >>> requests at a time. >>> >>> [X] Limit open pull requests from users without write access Loading >>> >>> Maximum open pull requests per user >>> >>> Enter a number from 1 to 1000 >>> >>> -- >>> http://www.spatialys.com >>> My software is free, but my time generally not. >>> LLMs contribute to global warming and brain rot >>> >>> _______________________________________________ >>> MapServer-dev mailing list >>> MapServer-dev at lists.osgeo.org >>> https://lists.osgeo.org/mailman/listinfo/mapserver-dev >> -- >> http://www.spatialys.com >> My software is free, but my time generally not. >> LLMs contribute to global warming and brain rot >> _______________________________________________ >> MapServer-dev mailing list >> MapServer-dev at lists.osgeo.org >> https://lists.osgeo.org/mailman/listinfo/mapserver-dev >> > > > _______________________________________________ > MapServer-dev mailing list > MapServer-dev at lists.osgeo.org > https://lists.osgeo.org/mailman/listinfo/mapserver-dev -------------- next part -------------- An HTML attachment was scrubbed... URL: From tomkralidis at gmail.com Wed Jul 8 02:57:29 2026 From: tomkralidis at gmail.com (Tom Kralidis) Date: Wed, 8 Jul 2026 05:57:29 -0400 Subject: [MapServer-dev] Limit open pull requests from users without write access: 3 In-Reply-To: <89feae63-b6a1-4ed6-96ac-440e60e4886a@app.fastmail.com> References: <261ba04b-7320-4030-91cb-b5558449d7a5@spatialys.com> <89feae63-b6a1-4ed6-96ac-440e60e4886a@app.fastmail.com> Message-ID: +1 ..Tom On Wed, Jul 8, 2026 at 4:59?AM Seth G via MapServer-dev < mapserver-dev at lists.osgeo.org> wrote: > +1 to the limit. > > I would say we should link to the AI policy and give a warning to > https://github.com/loom-agent but as the profile says it is an agent we > can just close these. Tamas already tried the fix in > https://github.com/MapServer/MapServer/pull/7565 without it resolving the > issue (based on reading the comments). > > -- > web:https://geographika.net & https://mapserverstudio.net > mastodon: @geographika at mastodon.social > > On Wed, Jul 8, 2026, at 4:18 AM, Even Rouault via MapServer-dev wrote: > > I believe all those 3 PRs should be closed. The profile of the account > says "Hi, I'm ** Agent. Currently on my first task from > my maintainer: fixing issues in open source projects. Feedback is always > welcome ? it helps me get better." There's clearly no human. This is a > straightforward violation of our AI tool policy. > Le 07/07/2026 ? 23:22, Lime, Steve D (MNIT) via MapServer-dev a ?crit : > > +1 on 3 - your guess is as good as mine. > > > > *From:* MapServer-dev > *On Behalf Of *Even Rouault via > MapServer-dev > *Sent:* Tuesday, July 7, 2026 4:09 PM > *To:* 'MapServer Dev Mailing List' > > *Subject:* [MapServer-dev] Limit open pull requests from users without > write access: 3 > > > > *This message may be from an external email source.* > > Do not select links or open attachments unless verified. Report all > suspicious emails to Minnesota IT Services Security Operations Center. > > > ------------------------------ > > As we're getting pull requests from agents (that I'm personally unwilling > to review), I've changed > https://github.com/MapServer/MapServer/settings/interaction_limits to > Pull request limits > > Restrict how many pull requests users without write access can have open > at one time and add specific users to a bypass list. These settings stay in > effect until you change them. > > Currently, users without write access can have up to *3* open pull > requests at a time. > > [X] Limit open pull requests from users without write access Loading > > Maximum open pull requests per user > > Enter a number from 1 to 1000 > > > > -- > > http://www.spatialys.com > > My software is free, but my time generally not. > > LLMs contribute to global warming and brain rot > > > _______________________________________________ > MapServer-dev mailing listMapServer-dev at lists.osgeo.orghttps://lists.osgeo.org/mailman/listinfo/mapserver-dev > > -- http://www.spatialys.com > My software is free, but my time generally not. > LLMs contribute to global warming and brain rot > > _______________________________________________ > MapServer-dev mailing list > MapServer-dev at lists.osgeo.org > https://lists.osgeo.org/mailman/listinfo/mapserver-dev > > > _______________________________________________ > MapServer-dev mailing list > MapServer-dev at lists.osgeo.org > https://lists.osgeo.org/mailman/listinfo/mapserver-dev > -------------- next part -------------- An HTML attachment was scrubbed... URL: From michael.smith.erdc at gmail.com Wed Jul 8 03:08:10 2026 From: michael.smith.erdc at gmail.com (Michael Smith) Date: Wed, 08 Jul 2026 06:08:10 -0400 Subject: [MapServer-dev] Limit open pull requests from users without write access: 3 In-Reply-To: References: <261ba04b-7320-4030-91cb-b5558449d7a5@spatialys.com> <89feae63-b6a1-4ed6-96ac-440e60e4886a@app.fastmail.com> Message-ID: <862132C1-3DDA-4FAA-8B43-694076A78C4A@gmail.com> +1 Mike From: MapServer-dev on behalf of Tom Kralidis via MapServer-dev Reply-To: Tom Kralidis Date: Wednesday, July 8, 2026 at 5:57?AM To: Seth G Cc: MapServer Devs Subject: Re: [MapServer-dev] Limit open pull requests from users without write access: 3 +1 ..Tom On Wed, Jul 8, 2026 at 4:59?AM Seth G via MapServer-dev wrote: +1 to the limit. I would say we should link to the AI policy and give a warning to https://github.com/loom-agent but as the profile says it is an agent we can just close these. Tamas already tried the fix in https://github.com/MapServer/MapServer/pull/7565 without it resolving the issue (based on reading the comments). -- web:https://geographika.net & https://mapserverstudio.net mastodon: @geographika at mastodon.social On Wed, Jul 8, 2026, at 4:18 AM, Even Rouault via MapServer-dev wrote: I believe all those 3 PRs should be closed. The profile of the account says "Hi, I'm ** Agent. Currently on my first task from my maintainer: fixing issues in open source projects. Feedback is always welcome ? it helps me get better." There's clearly no human. This is a straightforward violation of our AI tool policy. Le 07/07/2026 ? 23:22, Lime, Steve D (MNIT) via MapServer-dev a ?crit : +1 on 3 - your guess is as good as mine. From: MapServer-dev On Behalf Of Even Rouault via MapServer-dev Sent: Tuesday, July 7, 2026 4:09 PM To: 'MapServer Dev Mailing List' Subject: [MapServer-dev] Limit open pull requests from users without write access: 3 This message may be from an external email source. Do not select links or open attachments unless verified. Report all suspicious emails to Minnesota IT Services Security Operations Center. As we're getting pull requests from agents (that I'm personally unwilling to review), I've changed https://github.com/MapServer/MapServer/settings/interaction_limits to Pull request limits Restrict how many pull requests users without write access can have open at one time and add specific users to a bypass list. These settings stay in effect until you change them. Currently, users without write access can have up to 3 open pull requests at a time. [X] Limit open pull requests from users without write access Loading Maximum open pull requests per user Enter a number from 1 to 1000 -- http://www.spatialys.com My software is free, but my time generally not. LLMs contribute to global warming and brain rot _______________________________________________ MapServer-dev mailing list MapServer-dev at lists.osgeo.org https://lists.osgeo.org/mailman/listinfo/mapserver-dev -- http://www.spatialys.com My software is free, but my time generally not. LLMs contribute to global warming and brain rot _______________________________________________ MapServer-dev mailing list MapServer-dev at lists.osgeo.org https://lists.osgeo.org/mailman/listinfo/mapserver-dev _______________________________________________ MapServer-dev mailing list MapServer-dev at lists.osgeo.org https://lists.osgeo.org/mailman/listinfo/mapserver-dev _______________________________________________ MapServer-dev mailing list MapServer-dev at lists.osgeo.org https://lists.osgeo.org/mailman/listinfo/mapserver-dev -------------- next part -------------- An HTML attachment was scrubbed... URL: