Re: libappimage lts update

2023-01-21 Thread Utkarsh Gupta
Hi Scarlett,

On Sat, Jan 21, 2023 at 8:51 PM Scarlett Moore
 wrote:
> and the CVE is not listed. I need to know how I proceed as it stated Do not
> add it, frontdesk needs to. I am a maintainer of the package and I do have the
> upstream fix.

Thank you for reaching out. I am at the front desk this week. As Anton
mentioned, please let me know whatever suits you, I'll be happy to
assist.


- u



Re: libappimage lts update

2023-01-21 Thread Anton Gladky
Hello Scarlett,

thanks for your email!

Please prepare a fix for the package, upload it to your salsa repo, and let
us know.
We will take care of adding the package to the dla-needed list and
preparing all necessary
steps for that.

If you prefer to upload the package on your own, we can also support and
consult you.

Best regards.

Anton


Am Sa., 21. Jan. 2023 um 16:21 Uhr schrieb Scarlett Moore <
scarlett.gately.mo...@gmail.com>:

> Hello,
> The security team pointed me here as Buster is now LTS.
> I am reaching out to see if/how I should update libappimage in buster.
> The bug is https://security-tracker.debian.org/tracker/CVE-2020-25265
> The upstream fix is:
> https://github.com/AppImageCommunity/libappimage/pull/146
> I followed instructions here:
>
> https://lts-team.pages.debian.net/wiki/Development.html#claim-the-issue-in-the-security-tracker-in-dla-needed-txt
>
> and the CVE is not listed. I need to know how I proceed as it stated Do
> not
> add it, frontdesk needs to. I am a maintainer of the package and I do have
> the
> upstream fix.
>
> Thank you for any assistance in the matter.
> Scarlett Moore
> 


libappimage lts update

2023-01-21 Thread Scarlett Moore
Hello,
The security team pointed me here as Buster is now LTS.
I am reaching out to see if/how I should update libappimage in buster.
The bug is https://security-tracker.debian.org/tracker/CVE-2020-25265
The upstream fix is: https://github.com/AppImageCommunity/libappimage/pull/146
I followed instructions here: 
https://lts-team.pages.debian.net/wiki/Development.html#claim-the-issue-in-the-security-tracker-in-dla-needed-txt

and the CVE is not listed. I need to know how I proceed as it stated Do not 
add it, frontdesk needs to. I am a maintainer of the package and I do have the 
upstream fix.

Thank you for any assistance in the matter.
Scarlett Moore


signature.asc
Description: This is a digitally signed message part.