Please review the draft for week 154's blog post

2018-04-08 Thread Chris Lamb
gHi all,

Please review the draft for week 154's blog post:

  https://reproducible.alioth.debian.org/blog/drafts/154/

Feel free to commit any changes directly to drafts/154.mdwn in Git:

https://anonscm.debian.org/git/reproducible/blog.git/

I am very happy to reword and/or rework prior to publishing. I intend
to publish it no earlier than:

  https://time.is/compare/0900_10_Apr_2018_in_BST

or

  $ date -d 'Tue, 10 Apr 2018 09:00:00 +0100'


Regards,

-- 
  ,''`.
 : :'  : Chris Lamb
 `. `'`  la...@debian.org / chris-lamb.co.uk
   `-

___
Reproducible-builds mailing list
Reproducible-builds@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/reproducible-builds


Processed: Re: Bug#894832: CVE-2018-1002150

2018-04-08 Thread Debian Bug Tracking System
Processing control commands:

> forwarded -1 https://pagure.io/koji/issue/850
Bug #894832 [src:koji] CVE-2018-1002150
Set Bug forwarded-to-address to 'https://pagure.io/koji/issue/850'.

-- 
894832: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=894832
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems

___
Reproducible-builds mailing list
Reproducible-builds@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/reproducible-builds


Bug#894832: CVE-2018-1002150

2018-04-08 Thread Salvatore Bonaccorso
Control: forwarded -1 https://pagure.io/koji/issue/850

Hi

There is some further information on that issue in the upstrema bug at
https://pagure.io/koji/issue/850 and the
https://docs.pagure.org/koji/CVE-2018-1002150/ . Versions prior to
1.12.0 are not vulnerable because they do not have the dist-repo
feature.

Regards,
Salvatore

___
Reproducible-builds mailing list
Reproducible-builds@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/reproducible-builds