Support of lua-cgi

2020-02-24 Thread Ola Lundqvist
Hi fellow LTS members Today (as part of front desk work) I triaged lua-cgi and I thought that the session id vulnerabilities were rather basic and severe. So I thought that if it is a really used software it would have been found much earlier. Especially since the vulnerability have been there for

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2020-02-24 Thread Chris Lamb
Hi all, > And, thanks to Emilio's patch showing the authors here, we got significantly > less DLAs missing on www.debian.org: [..] > ERROR: .data or .wml file missing for DLA 1985-1 (reserved by Chris Lamb) Thanks for your dilegence. Another one with a local commit but I neglected to ensure an MR

Re: zsh_5.0.7-5+deb8u1_amd64.changes REJECTED

2020-02-24 Thread Roberto C . Sánchez
On Mon, Feb 24, 2020 at 04:57:19PM +0100, Salvatore Bonaccorso wrote: > Hi, > > On Mon, Feb 24, 2020 at 10:18:45AM -0500, Roberto C. Sánchez wrote: > > Hi FTP team folks & LTS folks, > > > > The below rejection error message is confusing. > > > > On Mon, Feb 24, 2020 at 02:30:20PM +, Debian

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2020-02-24 Thread Ben Hutchings
On Mon, 2020-02-24 at 14:17 +, Holger Levsen wrote: > hi, > > today I unclaimed > > for LTS: > - python-pysaml2 (Abhijith PA) > > and none for eLTS. > > > And, thanks to Emilio's patch showing the authors here, we got significantly > less DLAs missing on www.debian.org: > > ERROR: .data o

Re: zsh_5.0.7-5+deb8u1_amd64.changes REJECTED

2020-02-24 Thread Holger Levsen
On Mon, Feb 24, 2020 at 05:04:18PM +0100, Salvatore Bonaccorso wrote: > But this is not the problem here. The problem here is the Built-Using > on libcap2. In such cases ftp-masters need (for now) manually sync the > missing libcap2, then src:zsh can be processed again. ah. humpf. sorry for the no

Re: zsh_5.0.7-5+deb8u1_amd64.changes REJECTED

2020-02-24 Thread Salvatore Bonaccorso
Hi Holger, On Mon, Feb 24, 2020 at 04:00:50PM +, Holger Levsen wrote: > On Mon, Feb 24, 2020 at 04:57:19PM +0100, Salvatore Bonaccorso wrote: > > > Is this a transient condition? Should I just upload again? Or is there > > > some other issue which I have missed? > > The source package is mis

Re: zsh_5.0.7-5+deb8u1_amd64.changes REJECTED

2020-02-24 Thread Holger Levsen
On Mon, Feb 24, 2020 at 04:57:19PM +0100, Salvatore Bonaccorso wrote: > > Is this a transient condition? Should I just upload again? Or is there > > some other issue which I have missed? > The source package is missing on the archive on security. So > ftp-master need to copy it over in this case

Re: zsh_5.0.7-5+deb8u1_amd64.changes REJECTED

2020-02-24 Thread Salvatore Bonaccorso
Hi, On Mon, Feb 24, 2020 at 10:18:45AM -0500, Roberto C. Sánchez wrote: > Hi FTP team folks & LTS folks, > > The below rejection error message is confusing. > > On Mon, Feb 24, 2020 at 02:30:20PM +, Debian FTP Masters wrote: > > > > zsh-static_5.0.7-5+deb8u1_amd64.deb: Built-Using refers to

Re: zsh_5.0.7-5+deb8u1_amd64.changes REJECTED

2020-02-24 Thread Roberto C . Sánchez
Hi FTP team folks & LTS folks, The below rejection error message is confusing. On Mon, Feb 24, 2020 at 02:30:20PM +, Debian FTP Masters wrote: > > zsh-static_5.0.7-5+deb8u1_amd64.deb: Built-Using refers to non-existing > source package libcap2 (= 1:2.24-8) > > The package appears to be pr

(semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2020-02-24 Thread Holger Levsen
hi, today I unclaimed for LTS: - python-pysaml2 (Abhijith PA) and none for eLTS. And, thanks to Emilio's patch showing the authors here, we got significantly less DLAs missing on www.debian.org: ERROR: .data or .wml file missing for DLA 2114-1 (reserved by Ben Hutchings) ERROR: .data or .wml

Re: Xen update request and status

2020-02-24 Thread Bastian Blank
Hi Robert On Sat, Feb 22, 2020 at 09:14:10AM -0500, Roberto C. Sánchez wrote: > Is it then Credativ's intent to continue maintenance of Xen 4.4? If so, > could you provide some information on when we might expect the next > update? If not, I would like to request that you begin the process of >