Re: sqlalchemy security fix available for testing

2019-03-15 Thread Mike Gabriel

Hi Sylvain,

On  Fr 15 Mär 2019 15:35:07 CET, Mike Gabriel wrote:


HI Sylvain,

On  Di 12 Mär 2019 15:17:01 CET, Sylvain Beucler wrote:


Hi,

I made a fix for sqlalchemy available for testing (CVE-2019-7164/7548):
https://people.debian.org/~beuc/lts/sqlalchemy/

Upstream author Mike Bayer warns that this might break applications,
hence if you are depend on sqlalchemy you are encouraged to test:
https://gerrit.sqlalchemy.org/#/c/sqlalchemy/sqlalchemy/+/1165/

I'll update it if upstream makes more fine-tuning.
I plan to push it next week unless users/testers report breakage.

Cheers!
Sylvain


ok. Thanks for the feedback. Please ping us when the upload has  
arrived in jessie-security, so that one of the paid contributors can  
handle the DLAnnouncement.


Thanks!
Mike


Ouch! I just realized that you are on the team of paid LTS devs. So,  
ignore my previous mail.


light+love
Mike
--

DAS-NETZWERKTEAM
c\o Technik- und Ökologiezentrum Eckernförde
Mike Gabriel, Marienthaler str. 17, 24340 Eckernförde
mobile: +49 (1520) 1976 148
landline: +49 (4354) 8390 139

GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22  0782 9AF4 6B30 2577 1B31
mail: mike.gabr...@das-netzwerkteam.de, http://das-netzwerkteam.de



pgpaH8oUm_FWh.pgp
Description: Digitale PGP-Signatur


Re: sqlalchemy security fix available for testing

2019-03-15 Thread Mike Gabriel

HI Sylvain,

On  Di 12 Mär 2019 15:17:01 CET, Sylvain Beucler wrote:


Hi,

I made a fix for sqlalchemy available for testing (CVE-2019-7164/7548):
https://people.debian.org/~beuc/lts/sqlalchemy/

Upstream author Mike Bayer warns that this might break applications,
hence if you are depend on sqlalchemy you are encouraged to test:
https://gerrit.sqlalchemy.org/#/c/sqlalchemy/sqlalchemy/+/1165/

I'll update it if upstream makes more fine-tuning.
I plan to push it next week unless users/testers report breakage.

Cheers!
Sylvain


ok. Thanks for the feedback. Please ping us when the upload has  
arrived in jessie-security, so that one of the paid contributors can  
handle the DLAnnouncement.


Thanks!
Mike
--

DAS-NETZWERKTEAM
c\o Technik- und Ökologiezentrum Eckernförde
Mike Gabriel, Marienthaler str. 17, 24340 Eckernförde
mobile: +49 (1520) 1976 148
landline: +49 (4354) 8390 139

GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22  0782 9AF4 6B30 2577 1B31
mail: mike.gabr...@das-netzwerkteam.de, http://das-netzwerkteam.de



pgpWPWLZIHpuu.pgp
Description: Digitale PGP-Signatur


sqlalchemy security fix available for testing

2019-03-12 Thread Sylvain Beucler
Hi,

I made a fix for sqlalchemy available for testing (CVE-2019-7164/7548):
https://people.debian.org/~beuc/lts/sqlalchemy/

Upstream author Mike Bayer warns that this might break applications,
hence if you are depend on sqlalchemy you are encouraged to test:
https://gerrit.sqlalchemy.org/#/c/sqlalchemy/sqlalchemy/+/1165/

I'll update it if upstream makes more fine-tuning.
I plan to push it next week unless users/testers report breakage.

Cheers!
Sylvain