Re: Drop support for libqb?

2019-11-12 Thread Roberto C . Sánchez
On Tue, Nov 12, 2019 at 06:53:19PM +0100, Markus Koschany wrote: > Hi, > > Am 12.11.19 um 18:11 schrieb Roberto C. Sánchez: > [...] > > With that in mind, does this seem like a package for which we should > > declare the end of support? > > That sounds reasonable to me. > Is it as simple as upda

Re: Drop support for libqb?

2019-11-12 Thread Markus Koschany
Hi, Am 12.11.19 um 18:11 schrieb Roberto C. Sánchez: [...] > With that in mind, does this seem like a package for which we should > declare the end of support? That sounds reasonable to me. Cheers, Markus signature.asc Description: OpenPGP digital signature

Drop support for libqb?

2019-11-12 Thread Roberto C . Sánchez
Hello all, In recent days I made an attempt at backporting fixes made upstream in libqb to address CVE-2019-12779. I requested a review from upstream in the related GitHub issue [0]. The essence of the discussion is that some important parts of the upstream changes do not apply to the libqb in J

Re: Security issues in standards (ruby-openid / CVE-2019-11027)

2019-11-12 Thread Utkarsh Gupta
Hi Sylvain, hi all, On Thu, 7 Nov, 2019, 3:19 PM Sylvain Beucler, wrote: > Hi, > > On 06/11/2019 21:14, Utkarsh Gupta wrote: > > On 06/11/19 11:47 am, Brian May wrote: > >> Utkarsh Gupta writes: > >> > >>> I am not quite sure about what should we do here because the update > (DLA > >>> 1956-1)

Re: Security issues in standards (ruby-openid / CVE-2019-11027)

2019-11-12 Thread Raphael Hertzog
Hi, (Sylvain, please cc me if you want me to read something in any timely fashion) On Thu, 07 Nov 2019, Sylvain Beucler wrote: > Raphael, given that this package is low popcon and the vulnerability is > fuzzy, do you know if the sponsor for this package would be willing to > test fixes? The spon

Re: (E)LTS report for October

2019-11-12 Thread Sylvain Beucler
Hi, On 10/11/2019 21:41, Brian May wrote: > Holger Levsen writes: > >> then, just for the record, this was discussed with Raphael and me. Please >> don't do more hours than assigned without coordination. See "What should >> I do if I work more than the hours allocated?" in debian-lts.git for >> m