Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-12-27 Thread Moritz Mühlenhoff
Am Wed, Dec 27, 2023 at 05:18:52PM +0100 schrieb Jérémy Lal: > Le mer. 27 déc. 2023 à 17:16, Moritz Mühlenhoff a écrit : > > > [ Also adding Paul Gevers for awareness, for context we're bumping nodejs > > in Bookworm to the latest 18.x security/LTS release ] > > > > On Wed, Dec 27, 2023 at

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-12-27 Thread Jérémy Lal
Le mer. 27 déc. 2023 à 17:16, Moritz Mühlenhoff a écrit : > [ Also adding Paul Gevers for awareness, for context we're bumping nodejs > in Bookworm to the latest 18.x security/LTS release ] > > On Wed, Dec 27, 2023 at 03:03:20PM +0100 Jérémy Lal wrote: > > > I don't think so, there are all

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-12-27 Thread Moritz Mühlenhoff
[ Also adding Paul Gevers for awareness, for context we're bumping nodejs in Bookworm to the latest 18.x security/LTS release ] On Wed, Dec 27, 2023 at 03:03:20PM +0100 Jérémy Lal wrote: > I don't think so, there are all either node-undici-related, or just test > suites regressions. > Here are

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-12-27 Thread Jérémy Lal
Le mer. 27 déc. 2023 à 14:43, Moritz Mühlenhoff a écrit : > Am Thu, Dec 21, 2023 at 11:26:27PM +0100 schrieb Jérémy Lal: > > Le jeu. 21 déc. 2023 à 20:34, Moritz Mühlenhoff a > écrit : > > > > > Am Thu, Dec 21, 2023 at 11:29:12AM +0100 schrieb Jérémy Lal: > > > > Le jeu. 21 déc. 2023 à 10:54,

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-12-21 Thread Jérémy Lal
Le jeu. 21 déc. 2023 à 20:34, Moritz Mühlenhoff a écrit : > Am Thu, Dec 21, 2023 at 11:29:12AM +0100 schrieb Jérémy Lal: > > Le jeu. 21 déc. 2023 à 10:54, Moritz Muehlenhoff a > écrit : > > > > > On Thu, Dec 21, 2023 at 06:43:35AM +0100, Salvatore Bonaccorso wrote: > > > > Hi, > > > > > > > >

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-12-21 Thread Moritz Mühlenhoff
Am Thu, Dec 21, 2023 at 11:29:12AM +0100 schrieb Jérémy Lal: > Le jeu. 21 déc. 2023 à 10:54, Moritz Muehlenhoff a écrit : > > > On Thu, Dec 21, 2023 at 06:43:35AM +0100, Salvatore Bonaccorso wrote: > > > Hi, > > > > > > [CC'ing node-undici uploader] > > > > [CC-ing the good email address for

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-12-21 Thread Jérémy Lal
Le jeu. 21 déc. 2023 à 10:54, Moritz Muehlenhoff a écrit : > On Thu, Dec 21, 2023 at 06:43:35AM +0100, Salvatore Bonaccorso wrote: > > Hi, > > > > [CC'ing node-undici uploader] > [CC-ing the good email address for node-undici uploader] > > > >> Ack, let's do that. Could you prepare

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-12-21 Thread Moritz Muehlenhoff
On Thu, Dec 21, 2023 at 06:43:35AM +0100, Salvatore Bonaccorso wrote: > Hi, > > [CC'ing node-undici uploader] > > >> Ack, let's do that. Could you prepare bookworm-security updates > > >> based on 18.17.0 (after it has landed in unstable)? > > > > > nodejs 18.19.0 has landed in testing. > > It

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-12-20 Thread Salvatore Bonaccorso
Hi, [CC'ing node-undici uploader] On Wed, Dec 20, 2023 at 09:12:36PM +0100, J??r??my Lal wrote: > Le mer. 19 juil. 2023 ?? 21:51, J??r??my Lal a ??crit : > > > > > > > Le mer. 19 juil. 2023 ?? 14:18, Moritz M??hlenhoff a > > ??crit : > > > >> Am Fri, Jun 30, 2023 at 08:12:37PM +0200 schrieb

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-12-20 Thread Jérémy Lal
Le mer. 19 juil. 2023 à 21:51, Jérémy Lal a écrit : > > > Le mer. 19 juil. 2023 à 14:18, Moritz Mühlenhoff a > écrit : > >> Am Fri, Jun 30, 2023 at 08:12:37PM +0200 schrieb Jérémy Lal: >> > Hi, >> > >> > Le ven. 30 juin 2023 à 19:21, Salvatore Bonaccorso >> a >> > écrit : >> > >> > > Source:

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-07-19 Thread Jérémy Lal
Le mer. 19 juil. 2023 à 14:18, Moritz Mühlenhoff a écrit : > Am Fri, Jun 30, 2023 at 08:12:37PM +0200 schrieb Jérémy Lal: > > Hi, > > > > Le ven. 30 juin 2023 à 19:21, Salvatore Bonaccorso a > > écrit : > > > > > Source: nodejs > > > Version: 18.13.0+dfsg1-1 > > > Severity: important > > >

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-07-19 Thread Moritz Mühlenhoff
Am Fri, Jun 30, 2023 at 08:12:37PM +0200 schrieb Jérémy Lal: > Hi, > > Le ven. 30 juin 2023 à 19:21, Salvatore Bonaccorso a > écrit : > > > Source: nodejs > > Version: 18.13.0+dfsg1-1 > > Severity: important > > Tags: security upstream > > X-Debbugs-Cc: car...@debian.org, Debian Security Team <

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-06-30 Thread Salvatore Bonaccorso
Hi [CC'ing the security team alias] On Fri, Jun 30, 2023 at 08:12:37PM +0200, Jérémy Lal wrote: > Hi, > > Le ven. 30 juin 2023 à 19:21, Salvatore Bonaccorso a > écrit : > > > Source: nodejs > > Version: 18.13.0+dfsg1-1 > > Severity: important > > Tags: security upstream > > X-Debbugs-Cc:

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-06-30 Thread Jérémy Lal
Hi, Le ven. 30 juin 2023 à 19:21, Salvatore Bonaccorso a écrit : > Source: nodejs > Version: 18.13.0+dfsg1-1 > Severity: important > Tags: security upstream > X-Debbugs-Cc: car...@debian.org, Debian Security Team < > t...@security.debian.org> > > Hi, > > The following vulnerabilities were