Re: Match ecosystems with limited support in debian-security-support

2021-04-16 Thread Moritz Mühlenhoff
Am Fri, Apr 16, 2021 at 11:05:35AM +0200 schrieb Sylvain Beucler: > Hi Security Team, > > I'm proposing a couple changes in debian-security-support and I'd welcome > your review :) > > 1) Match ecosystems > https://bugs.debian.org/986333 > https://salsa.debian.org/debian/debian-security-support/-

Re: Match ecosystems with limited support in debian-security-support

2021-04-16 Thread Holger Levsen
Hi Sylvain, btw, you mailed the uploaders: but not the maintainer: email address... On Fri, Apr 16, 2021 at 11:05:35AM +0200, Sylvain Beucler wrote: > I'm proposing a couple changes in debian-security-support and I'd welcome > your review :) [...] > If you agree with these changes I can merge the

Match ecosystems with limited support in debian-security-support

2021-04-16 Thread Sylvain Beucler
Hi Security Team, I'm proposing a couple changes in debian-security-support and I'd welcome your review :) 1) Match ecosystems https://bugs.debian.org/986333 https://salsa.debian.org/debian/debian-security-support/-/merge_requests/10 Sometimes, entire ecosystems are affected by Debian support

Re: Marking CVE-2021-23369/{node,libjs}-handlebars are no-dsa for all suites

2021-04-16 Thread Utkarsh Gupta
Hi again, On Fri, Apr 16, 2021 at 1:31 PM Utkarsh Gupta wrote: > After discussing a bit with Yadd (CC'ed here), it seems that > CVE-2021-23369 affecting node-handlebars for buster and > libjs-handlebars for stretch and jessie is a bit too intrusive and > difficult to fix for all the mentioned sui

Marking CVE-2021-23369/{node,libjs}-handlebars are no-dsa for all suites

2021-04-16 Thread Utkarsh Gupta
Hello, After discussing a bit with Yadd (CC'ed here), it seems that CVE-2021-23369 affecting node-handlebars for buster and libjs-handlebars for stretch and jessie is a bit too intrusive and difficult to fix for all the mentioned suites and therefore I am marking them as no-dsa (Too intrusive to f