(semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2021-06-07 Thread Holger Levsen
moining, today two packages were unclaimed for LTS: -ceph (Emilio) -thunderbird (Emilio) and two for ELTS: -ceph (Emilio) -openjdk-7 (Emilio) Nobody claimed 4 packages or more. Two DLAs have been reserved and haven't been published yet: - DLA 2678-1 (06 Jun 2021) (ruby-nokogiri) - DLA 2676-1 (0

Re: libxstream-java blacklist EOL?

2021-06-07 Thread Emilio Pozuelo Monfort
On 02/06/2021 14:24, Markus Koschany wrote: Hi Emilio, Am Mittwoch, den 02.06.2021, 12:26 +0200 schrieb Emilio Pozuelo Monfort: I think it is time we declare the block list unsupported, asking users to switch to the allow list. Thoughts? I believe it is sensible to switch to the whitelist

Re: [SECURITY] [DLA 2677-1] libwebp security update

2021-06-07 Thread Marc SCHAEFER
On Sun, Jun 06, 2021 at 08:38:17PM +0200, Anton Gladky wrote: > Multiple security issues have been discovered in libwebp I always liked the idea of putting what a package really is used for / does in the security advisories. Something like: Lossy compression of digital photographic images suppo