Bug#761945: fixing links for DLAs in the security tracker

2017-03-28 Thread Salvatore Bonaccorso
Hi,

On Wed, Mar 29, 2017 at 06:28:49AM +0200, Salvatore Bonaccorso wrote:
> Hi,
> 
> On Tue, Mar 28, 2017 at 10:16:52PM +, Holger Levsen wrote:
> > On Tue, Mar 28, 2017 at 10:35:34PM +0200, Moritz Muehlenhoff wrote:
> > > Well, you don't have a web site comparable to 
> > > https://www.debian.org/security/2017/dsa-3796, so where should
> > > it possibly link to?
> >  
> > I guess it's time to create this "web site" then :)
> 
> See as well https://bugs.debian.org/761945 (and respective clones for
> debian-).

The security-tracker side of this has been implemented now, Paul Wise
did the corresponding work. But around 400 DLA's are not yet imported
so many links will sow a page not found.

A working example:
https://security-tracker.debian.org/tracker/DLA-55-1 or
https://security-tracker.debian.org/tracker/DLA-400-1

Regards,
Salvatore

p.s.: generally: for changes to the security-tracker, please do not use
  debian-lts but rather the security-tracker list (or even
  better/depending on case via bugreports).



Bug#761945: marked as done (security-tracker: link to DLA details from Source field)

2017-03-28 Thread Debian Bug Tracking System
Your message dated Wed, 29 Mar 2017 13:26:44 +0800
with message-id <1490765204.25136.1.ca...@debian.org>
and subject line Re: security-tracker: link to DLA details from Source field
has caused the Debian Bug report #761945,
regarding security-tracker: link to DLA details from Source field
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
761945: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=761945
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: security-tracker
Severity: wishlist

DLAs include a "Source" field that simply says "Debian LTS Team". It
would be nice if, like DSAs, the "Source" field linked to a source of
further information, like the mailing list archive or the Debian website
or to the security tracker SVN/git repository.

https://security-tracker.debian.org/tracker/DLA-55-1
https://security-tracker.debian.org/tracker/DSA-3020-1

-- 
bye,
pabs

https://wiki.debian.org/PaulWise



signature.asc
Description: This is a digitally signed message part
--- End Message ---
--- Begin Message ---
Version: r50156

On Wed, 17 Sep 2014 15:02:27 +0800 Paul Wise wrote:

> DLAs include a "Source" field that simply says "Debian LTS Team". It
> would be nice if, like DSAs, the "Source" field linked to a source of
> further information, like the mailing list archive or the Debian website
> or to the security tracker SVN/git repository.

This has been fixed in SVN r50156:

https://anonscm.debian.org/viewvc/secure-testing?view=revision=50156

-- 
bye,
pabs

https://wiki.debian.org/PaulWise


signature.asc
Description: This is a digitally signed message part
--- End Message ---


DSA candidates

2017-03-28 Thread Raphael Geissert
android-platform-system-core/stable
--
ansible/stable
--
apng2gif/stable
--
apparmor/stable
--
bitlbee/stable
--
cakephp/stable
--
calibre/stable
--
dhcpcd5/stable
--
eject/stable
--
freetype/stable
--
gradle/stable
--
jasper/stable
--
jhead/stable
--
kde4libs/stable
--
libapache2-mod-auth-mellon/stable
--
libapache2-mod-auth-openidc/stable
--
libav/stable
--
libgit2/stable
--
libphp-phpmailer/stable
--
libpodofo/stable
--
libtorrent-rasterbar/stable
--
libvpx/stable
--
libxslt/stable
--
lshell/stable
--
mcollective/stable
--
mp3splt/stable
--
mysql-5.5/stable
--
mysql-connector-python/stable
--
nova/stable
--
ntopng/stable
--
ntp/stable
--
openjpeg2/stable
--
percona-xtrabackup/stable
--
php5/stable
--
polarssl/stable
--
potrace/stable
--
profanity/stable
--
putty/stable
--
python-pysaml2/stable
--
sleekxmpp/stable
--
slurm-llnl/stable
--
tcpdf/stable
--
tiff/stable
--
wavpack/stable
--
web2py/stable
--
xrdp/stable
--
zendframework/stable
--
zziplib/stable
--
--
The above is a list of DSA candidates based on the tracker's information.
One should evaluate the candidates and either add them to dsa-needed.txt
or consider tagging them no-dsa.