Bug#921952: [Pkg-sass-devel] Bug#921952: Don't include in buster without proper commitment to update in stable

2019-05-21 Thread Aljoscha Lautenbach
Hi, On Mon, 20 May 2019 at 23:11, Moritz Mühlenhoff wrote: > What's considered needed is that someone should actually look through > https://security-tracker.debian.org/tracker/source-package/libsass and > triage/fix. > > The only visible action done in five weeks was to lower the severity, so >

Bug#921952: [Pkg-sass-devel] Bug#921952: Don't include in buster without proper commitment to update in stable

2019-04-09 Thread Aljoscha Lautenbach
Hi, during the BSP in Gothenburg last weekend I discussed with Jonas how I could help to put libsass back on track regarding its security status. We agreed that the best move is to start with triaging the existing Debian bugs and by identifying the CVE status in upstream's issue tracker. [0]