Hi Xavier, On Mon, Oct 05, 2026 at 03:28:28PM +0200, Xavier wrote: > Le 05/10/2026 à 11:27, Salvatore Bonaccorso a écrit : > > Hi Xavier, > > > > On Sat, Oct 03, 2026 at 07:47:47AM +0200, Xavier wrote: > > > Le 02/10/2026 à 16:51, Salvatore Bonaccorso a écrit : > > > > Source: node-shell-quote > > > > Version: 1.10.0-1 > > > > X-Debbugs-CC: [email protected] > > > > Severity: grave > > > > Tags: security upstream > > > > > > > > Hi, > > > > > > > > The following vulnerability was published for node-shell-quote. > > > > > > > > CVE-2026-102422[0]: > > > > > > Hi, > > > > > > here is the debdiff. If you don't consider it as urgent, of course I can > > > push it to release.debian.org. > > > > We have node-shell-quote ineed in dsa-needed list, and issue > > warranting a DSA. But while at it, can you as well include the fix for > > the no-dsa marked one, CVE-2026-13311? Or is there a reason we should > > rather ignore it? > > > > Regards, > > Salvatore > > Hi, > > done. I also fixed the debdiff, base was not good
Indeed, that was wrong base as we already have 1.7.4+~1.7.1-1+deb13u1. > diff --git a/debian/changelog b/debian/changelog > index 05e6b17..273622b 100644 > --- a/debian/changelog > +++ b/debian/changelog > @@ -1,3 +1,12 @@ > +node-shell-quote (1.7.4+~1.7.1-1+deb13u2) trixie; urgency=medium Target distribution should be trixie-security instead. With that fixed, please upload to security-master. Regards, Salvatore -- Pkg-javascript-devel mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel
