Debian LTS and ELTS - June 2024

2024-07-01 Thread Sylvain Beucler
) - Jitsi Meeting https://lists.debian.org/debian-lts/2024/06/msg00012.html -- Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - May 2024

2024-06-01 Thread Sylvain Beucler
: optimize lengthy post-commit checks - Report issue with pyxian source access - IRC meeting https://meetbot.debian.net/debian-lts/2024/debian-lts.2024-05-23-14.00.html -- Sylvain Beucler Debian LTS Team

Re: Fixing glib2.0 CVE-2024-34397 in buster

2024-05-11 Thread Sylvain Beucler
:) Cheers! Sylvain Beucler Debian LTS Team On 10/05/2024 17:02, Simon McVittie wrote: Please cc either me or the glib2.0 package's address on any replies that are relevant outside the LTS team: I am not subscribed to -lts. Normally I don't attempt to support any packages in the LTS distributions

Debian LTS and ELTS - April 2024

2024-05-02 Thread Sylvain Beucler
- Help with handling package / understand triage: https://lists.debian.org/debian-lts/2024/04/msg00014.html https://lists.debian.org/debian-lts/2024/04/msg00015.html - Jitsi meeting Also took notes: https://lists.debian.org/debian-lts/2024/04/msg00113.html -- Sylvain Beucler Debian LTS

Re: How to handle freeimage package

2024-04-08 Thread Sylvain Beucler
Hi, I think this requires a bit of coordination: - the package is basically dead upstream, there hasn't been a fix in the official repos, neither Debian or other distros attempted to fix them - we do have a sponsor for LTS and ELTS/stretch, so we're paid to take care of this package - secteam

Re: Remove runc from dla-needed

2024-04-08 Thread Sylvain Beucler
Hi, Please read the dla-needed.txt entry. It says we should sync *bullseye*. Cheers! Sylvain On 07/04/2024 23:47, Ola Lundqvist wrote: Hi fellow LTS contributors I was about to assign runc to myself but realized that it should not be in dla-needed. There is just one CVE to be fixed and that

Debian LTS and ELTS - March 2024

2024-04-02 Thread Sylvain Beucler
com - Update upcoming ELA documentation rdeps status updated ~every hour Fix missing dcut suite (internal) - IRC meeting -- Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3765-1] cacti security update

2024-03-18 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3765-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler March 18, 2024

Re: Expanding the scope (slightly) of dla-needed.txt

2024-03-18 Thread Sylvain Beucler
Hi, On 17/03/2024 06:54, Sean Whitton wrote: On Thu 14 Mar 2024 at 04:47pm -04, Roberto C. Sánchez wrote: - it is important update the notes on packages in dla-needed.txt to indicate what work has been done and what remains I think that we should be also reviewing old notes and deleting

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-03-16 Thread Sylvain Beucler
a/freexian/services/deblts/lts/git' is not a git working directory => fix this first in your ~/.config/freexian.ini :) Cheers! Sylvain Beucler Debian LTS Team

Re: Expanding the scope (slightly) of dla-needed.txt

2024-03-16 Thread Sylvain Beucler
Hi, On 14/03/2024 21:47, Roberto C. Sánchez wrote: - FD should be confirming that package removals from dla-needed.txt are valid (i.e., that the package does not require any work towards an upload to (old)stable) Phrased that way, I don't really like the idea of FD checking on his

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-03-15 Thread Sylvain Beucler
Hi, I add here a reminder to use './find-work' (as documented, including at the top of dla-needed.txt) to look for work _sorted by priority_. I triaged a few low, non-sponsored, harmonize-with-point-updates packages this week, and I'm a bit surprised that some were claimed and even uploaded

Re: Removal of sendmail from dla-needed?

2024-03-13 Thread Sylvain Beucler
Hi, For reference, re-added through https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9a2a182dc53f0632ecd32108c91c071bdad76289 Cheers! Sylvain Beucler Debian LTS Team On 10/03/2024 23:18, Ola Lundqvist wrote: Hi all Since I'm not 100% sure about this one I'm sending

Re: Question about tinymce dsa/no-dsa decisions

2024-03-13 Thread Sylvain Beucler
Hi Ola, On 12/03/2024 20:52, Ola Lundqvist wrote: I have claimed the package myself now. I think the conclusion will be that all are minor issues and the package do not need an update. But we will see when I have gone through all the CVEs. tinymce is only available up to buster, so we don't

Debian LTS and ELTS - February 2024

2024-03-01 Thread Sylvain Beucler
with freexian administrative tooling and help test - Documentation - (internal) improves notes on reproducing ELTS autopkgtest setup locally - TestSuites: improves python3 notes https://lts-team.pages.debian.net/wiki/TestSuites/python3.html - Jitsi meeting -- Sylvain Beucler Debian LTS

Debian LTS and ELTS - January 2024

2024-02-01 Thread Sylvain Beucler
freerdp tests https://lts-team.pages.debian.net/wiki/TestSuites/freerdp.html - Ping lts-coordinator about issues with Front-Desk reminder template -- Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - December 2023

2024-01-02 Thread Sylvain Beucler
an.net/wiki/TestSuites/xfreerdp.html - Jitsi team meeting -- Sylvain Beucler Debian LTS Team

Re: upcoming changes of the web pages /security and /lts/security

2023-12-26 Thread Sylvain Beucler
ery nice! & thanks for clarifying too! https://lts-team.pages.debian.net/wiki/Development.html updated :) Cheers! Sylvain Beucler Debian LTS Team

Re: Make stable-security build logs public after embargo

2023-12-12 Thread Sylvain Beucler
sounds doable, solves the most immediate use case (i.e. LTS devs comparing previous logs on new FTBFS), so I think we can privilege this option. What do you think? [1] https://wiki.debian.org/DebianEvents/gb/2023/MiniDebConfCambridge/Zini Cheers! Sylvain Beucler Debian LTS Team On 12/12/2023 00

Debian LTS and ELTS - November 2023

2023-12-01 Thread Sylvain Beucler
d/docs/how-to-use-extended-lts/ - IRC team meeting http://meetbot.debian.net/debian-lts/2023/debian-lts.2023-11-30-13.57.html -- Sylvain Beucler Debian LTS Team

Re: tinymce git repository

2023-11-30 Thread Sylvain Beucler
Hi Sean, At a point LTS pre-created *empty* Git repositories under /lts-team/packages for packages added to dla-needed.txt, but since then we've been trying to leave that to the contributor, so he can e.g. appropriately fork the repository and better keep the history. Consequently empty Git

Debian LTS and ELTS - October 2023

2023-11-02 Thread Sylvain Beucler
ntributors on IRC - Jitsi team meeting -- Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - September 2023

2023-10-02 Thread Sylvain Beucler
ollowing weekly report) - Team discussions (private GitLab issues) - Experimental GitLab issue-based workflow: Clean-up and unify my LTS/ELTS check-list - Help clarify linux-5.10 status in current tooling - Monthly report guidelines comment - IRC team meeting -- Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3566-1] ruby-rails-html-sanitizer security update

2023-09-13 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3566-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler September 13, 2023

[SECURITY] [DLA 3565-1] ruby-loofah security update

2023-09-13 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3565-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler September 13, 2023

Re: Call for tests/review: glib2.0/buster

2023-09-01 Thread Sylvain Beucler
update? I considered it but I was mostly out of time, I can do some testing next week. IIUC there was also progress on the older releases since. Cheers! Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - August 2023

2023-09-01 Thread Sylvain Beucler
ttps://salsa.debian.org/lts-team/lts-updates-tasks/-/issues/36#note_423686 - LTS Documentation - information-for-lts-contributors (internal): clarifications - Tooling - queue report ('find-work'): link tracker package status page - Help newcomers on IRC - Jitsi team meeting -- Sylvain Beu

Re: bullseye / libgdbm6:amd64 is a catastrophgy

2023-08-25 Thread Sylvain Beucler
the maintainer (e.g. with comprehensive testing). In conclusion, I believe there's a higher chance of fixing the bug right now in bullseye/oldstable, rather later in bullseye/LTS. Cheers! Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3541-1] w3m security update

2023-08-24 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3541-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler August 24, 2023

Re: Accepted thunderbird 1:102.14.0-1~deb10u1 (source) into oldoldstable

2023-08-07 Thread Sylvain Beucler
Hello Carsten, Thanks for updating Thunderbird for buster :) Do you want the LTS Team to take care of the DLA registration and announcement, or do you plan to do that yourself? (I assume this matches https://www.debian.org/security/2023/dsa-5469) Cheers! Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - July 2023

2023-08-01 Thread Sylvain Beucler
kage updates - Help newcomers on IRC -- Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3502-1] python-git security update

2023-07-25 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3502-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler July 25, 2023

Re: nsis CVE-2023-37378

2023-07-08 Thread Sylvain Beucler
Hi, On 08/07/2023 10:04, Sean Whitton wrote: On Sat 08 Jul 2023 at 09:14am +02, Salvatore Bonaccorso wrote: Just noticed the suffix for the version for the buster-security / LTS upload was +deb9u1, was this intentional? This should have been +deb10u1. It wasn't. Thank you for pointing out

Re: nsis CVE-2023-37378

2023-07-07 Thread Sylvain Beucler
/lts-team/packages/runc/-/blob/debian/buster/debian/patches/CVE-2022-29162.patch Cheers! Sylvain Beucler Debian LTS Team On 06/07/2023 20:42, Sean Whitton wrote: Hello, I've prepared an upload to buster-security [1] to fix CVE-2023-37378. I've tested it using an example script from [2

Debian LTS and ELTS - June 2023

2023-07-01 Thread Sylvain Beucler
non-security LTS upload from non-team contributor https://bugs.debian.org/1039489 - Continue internal discussions on packages claimfiles format/workflow - Jitsi team meeting -- Sylvain Beucler Debian LTS Team

Re: #1036797 bullseye-pu: package mariadb-10.5 10.5.20-0+deb11u1

2023-06-22 Thread Sylvain Beucler
Hello Otto, On 22/06/2023 19:41, Otto Kekäläinen wrote: I filed on May 26th this but never got any reply from stable managers: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=103679 It is affected by only one minor CVE-2022-47015. The same CVE was already fixed in DLA-3444-1 with MariaDB

Re: Request for suggestions/opinion about triaging decision for renderdoc

2023-06-20 Thread Sylvain Beucler
Hi, On 17/06/2023 22:14, Roberto C. Sánchez wrote: My opinion is that the package should be added to dla-needed.txt with a note linking to this thread on the mailing list. [snip] There should also be a note there to consider backporting a new upstream release once the security team decides

[SECURITY] [DLA 3454-1] ffmpeg security update

2023-06-13 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3454-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler June 13, 2023

[SECURITY] [DLA 3449-1] openssl security update

2023-06-08 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3449-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler June 08, 2023

Make stable-security build logs public after embargo

2023-06-01 Thread Sylvain Beucler
some time on the implementation, as part of my work on LTS. Do you think this can be achieved, and how? Cheers! Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - May 2023

2023-06-01 Thread Sylvain Beucler
said maintainer - Internal discussions on Git workflow, and packages claimfiles format/workflow - IRC Meeting http://meetbot.debian.net/debian-lts/2023/debian-lts.2023-05-25-13.58.html -- Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3434-1] sysstat security update

2023-05-27 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3434-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler May 27, 2023

[SECURITY] [DLA 3432-1] python2.7 security update

2023-05-24 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3432-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler May 24, 2023

Re: Bug 1035537 - split -n k/N gives incorrect data on blocks after the first

2023-05-19 Thread Sylvain Beucler
Hi, On 19/05/2023 21:14, Chris Frey wrote: On Fri, May 19, 2023 at 08:45:23PM +0200, Sylvain Beucler wrote: On 05/05/2023 05:14, Chris Frey wrote: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1035537 At first glance, it looks like this could lead to data corruption, and hence

Re: Bug 1035537 - split -n k/N gives incorrect data on blocks after the first

2023-05-19 Thread Sylvain Beucler
the coreutil's package maintainers input on the subject first (right now the BTS entry has no replies) :) Cheers! Sylvain Beucler Debian LTS Team

Re: LTS: add libpcap to dla-needed.txt

2023-05-19 Thread Sylvain Beucler
For the record, typo was fixed: libpcap -> libcap2. Cheers! Sylvain On 17/05/2023 12:01, Abhijith PA wrote: Hello Anton, From 5b2bcfaa20e12d0c90eb3999fba8b6e942e201ab Mon Sep 17 00:00:00 2001 From: Anton Gladky Date: Tue, 16 May 2023 22:39:34 +0200 Subject: [PATCH] LTS:

Re: nvidia-graphics-drivers in DLA needed?

2023-05-11 Thread Sylvain Beucler
Hi, On 11/05/2023 17:22, Tobias Frost wrote: nvidia-graphics-drivers-legacy-390xx is now uploaded, (tested with some old GTX770…) A procedural question: For the remaining CVE's (and those of nvidia-graphics-drivers), do I mark them "end-of-life" (e.g by saying in CVE/list: [buster] -

Debian LTS and ELTS - April 2023

2023-05-02 Thread Sylvain Beucler
-- Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3395-2] golang-1.11 regression update

2023-04-20 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3395-2debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler April 20, 2023

[SECURITY] [DLA 3395-1] golang-1.11 security update

2023-04-19 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3395-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler April 19, 2023

Re: (E)LTS improved salsa pipeline support

2023-04-19 Thread Sylvain Beucler
Hi, On 17/04/2023 21:36, Sylvain Beucler wrote: On 20/03/2023 09:40, Emilio Pozuelo Monfort wrote: On 17/03/2023 19:39, Raphael Hertzog wrote: On Thu, 16 Mar 2023, Emilio Pozuelo Monfort wrote: The result is an improved pipeline with better support for both LTS and ELTS. [1] Great work

Re: (E)LTS improved salsa pipeline support

2023-04-17 Thread Sylvain Beucler
Hi, On 20/03/2023 09:40, Emilio Pozuelo Monfort wrote: On 17/03/2023 19:39, Raphael Hertzog wrote: On Thu, 16 Mar 2023, Emilio Pozuelo Monfort wrote: The result is an improved pipeline with better support for both LTS and ELTS. [1] Great work Emilio! It would be nice to have all this

Re: Triage status for a few old packages

2023-04-15 Thread Sylvain Beucler
y apply really to the > old code-base. In such a case, add > > - sqlite > > and triage it further for buster. So we can do the same as with python2.7, expect this time the LTS Team members are the only ones adding the '- sqlite ' entries for new sqlite3 CVEs. I can proceed to add such entries for the past CVEs and prepare LTS procedures to ensure this is done, until the end of buster-lts next year. Are you OK with this? Cheers! Sylvain Beucler Debian LTS Team

Re: Triage status for a few old packages

2023-04-06 Thread Sylvain Beucler
' CLI: for accessing v2 databases, and migrate v2 databases to v3 (AFAICS). So I'm more inclined to keep it supported for the duration of buster-lts (package was removed in later dists). What do you think? Cheers! Sylvain Beucler Debian LTS Team On 01/04/2023 21:31, Salvatore Bonaccorso wrote

Debian LTS and ELTS - February 2023

2023-04-01 Thread Sylvain Beucler
IRC - User help: seabios buggy in Buster https://lists.debian.org/debian-lts/2023/03/msg00046.html - Monthly meeting (via IRC) http://meetbot.debian.net/debian-lts/2023/debian-lts.2023-03-23-13.58.html -- Sylvain Beucler Debian LTS Team

Re: seabios buggy in Buster

2023-03-30 Thread Sylvain Beucler
upgrading to bullseye? Cheers! Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3369-1] runc security update

2023-03-27 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3369-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler March 27, 2023

Triage status for a few old packages

2023-03-20 Thread Sylvain Beucler
te somehow?) If they are not triaged and you do not wish to perform such triage, would you mind if we do, and do you have recommendations so as to respect each other's workflows? Cheers! Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3355-1] xapian-core bugfix update

2023-03-18 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3355-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Olly Betts March 18, 2023

[SECURITY] [DLA 3362-1] qemu security update

2023-03-14 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3362-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler March 14, 2023

Debian LTS and ELTS - February 2023

2023-03-01 Thread Sylvain Beucler
curity-tracker ELTS fork - Newcomers help - Report misplaced commit - Answer questions on IRC (processes, packages priority) - Help identify/source LTS start date for debian-timeline - Monthly meeting (using Jitsi) -- Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3346-1] python-werkzeug security update

2023-02-27 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3346-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler February 27, 2023

[SECURITY] [DLA 3322-1] golang-github-opencontainers-selinux security update

2023-02-18 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3322-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler February 18, 2023

Re: Three Apache2 vulnerabilities

2023-02-02 Thread Sylvain Beucler
/bugreport.cgi?bug=1029123 ("no-dsa" can be misleading) Cheers! Sylvain Beucler Debian LTS Team On 02/02/2023 08:39, Marc SCHAEFER wrote: Hello, CERT-FR considers three new Apache2 vulnerabilities to be of concern [1]. These are: CVE-2022-37436 [2] CVE-2022-36760 [3] CVE-2006-20001 [4] The

Debian LTS and ELTS - January 2023

2023-02-01 Thread Sylvain Beucler
team - Monthly meeting (via IRC) http://meetbot.debian.net/debian-lts/2023/debian-lts.2023-01-26-14.00.html -- Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3282-1] git security update

2023-01-26 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3282-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler January 26, 2023

[SECURITY] [DLA 3278-1] tiff security update

2023-01-20 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3278-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler January 20, 2023

Re: nvidia-graphics-drivers in DLA needed?

2023-01-03 Thread Sylvain Beucler
wish to involve myself with non-free packages. Maybe you can coordinate with Markus and/or open a ticket to make sure this clarification happen? Cheers! Sylvain Beucler Debian LTS Team On 28/12/2022 23:45, Ola Lundqvist wrote: Hi fellow LTS developers As you can see below I had a question

Debian LTS - December 2022

2023-01-02 Thread Sylvain Beucler
- LTS documentation - Fix multiple links and markup issues - Monthly meeting (using Jitsi) -- Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3239-2] git regression update

2022-12-14 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3239-2debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler December 14, 2022

[SECURITY] [DLA 3239-1] git security update

2022-12-13 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3239-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler December 13, 2022

Re: https://bugs.debian.org/1024932 ceph-base: ceph to root privilege escalation via ceph-crash.service CVE-2022-3650

2022-12-03 Thread Sylvain Beucler
Hi Thomas, ceph was added about 1 month ago in the tasks list; I referenced your note there: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a9487a265227c3d4181511570bdf61889ce4c8e2 Cheers! Sylvain Beucler Debian LTS Team On 30/11/2022 14:46, Thomas Goirand wrote

Debian LTS and ELTS - November 2022

2022-12-01 Thread Sylvain Beucler
://lists.debian.org/debian-security/2022/11/msg2.html - New contributor help (via IRC) - Monthly meeting (via IRC) http://meetbot.debian.net/debian-lts/2022/debian-lts.2022-11-24-13.59.html -- Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3202-1] libarchive security update

2022-11-22 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3202-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler November 22, 2022

Re: Using Salsa-CI as pre-upload QA for Bullseye and Buster uploads: Lintian and Piuparts

2022-11-21 Thread Sylvain Beucler
'apt-get satisfy' command, for reasons I can't debug because of a redacted "collapsed multi-line command" even in the raw log; maybe it could written in a buster-compatible way, or otherwise just dropped for buster because it's confusing. My $0.02 :) Cheers! Sylvain Beucler Debia

[SECURITY] [DLA 3198-1] php-phpseclib security update

2022-11-17 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3198-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler November 17, 2022

[SECURITY] [DLA 3197-1] phpseclib security update

2022-11-17 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3197-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler November 17, 2022

Re: Using Salsa-CI as pre-upload QA for Bullseye and Buster uploads: Lintian and Piuparts

2022-11-14 Thread Sylvain Beucler
it inconvenient to push to Salsa. I'd be interested in knowing how other LTS contributors handle those issues :) Cheers! Sylvain Beucler Debian LTS Team

Re: Pre-creating Git repos in salsa.d.o/lts-team/packages/ - or not?

2022-11-08 Thread Sylvain Beucler
Hi, On 07/11/2022 19:08, Anton Gladky wrote: as you know one of our goals is to keep the git-history of all {E,L}TS uploads. Some semi-automatic repo creation scripts are in a test phase to ease this process. I have created some repos and imported the last available security versions of

Pre-creating Git repos in salsa.d.o/lts-team/packages/ - or not?

2022-11-07 Thread Sylvain Beucler
Hi, I see that a few repositories in salsa.d.o/lts-team/packages/ were created for packages that haven't been claimed yet. https://salsa.debian.org/lts-team/packages?sort=created_desc (I'm not sure who/what did it exactly, there's activity from "Bot-LTS-package", which may be the

[SECURITY] [DLA 3178-1] ffmpeg security update

2022-11-04 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3178-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler November 04, 2022

Debian LTS and ELTS - October 2022

2022-11-02 Thread Sylvain Beucler
2022/10/msg00022.html https://lists.debian.org/debian-lts/2022/10/msg00031.html - Answer LTS Thunderbird user question https://lists.debian.org/debian-lts/2022/10/msg00021.html - Monthly meeting (video/Jitsi) -- Sylvain Beucler Debian LTS Team

[SECURITY] [DLA 3157-1] bluez security update

2022-10-24 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3157-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler October 24, 2022

Re: Call for testing: glibc update for buster

2022-10-17 Thread Sylvain Beucler
Hi, On 17/10/2022 10:00, Helmut Grohne wrote: On Wed, Oct 12, 2022 at 03:45:11PM +0200, Sylvain Beucler wrote: I'll give it some testing on my buster system. Thank you. I take the absense of a further reponse as "nothing broke". Right, although I was kinda waiting for your inpu

[SECURITY] [DLA 3150-1] rexical security update

2022-10-12 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3150-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler October 12, 2022

[SECURITY] [DLA 3149-1] ruby-nokogiri security update

2022-10-12 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3149-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler October 12, 2022

Re: Call for testing: glibc update for buster

2022-10-12 Thread Sylvain Beucler
Hi, I'll give it some testing on my buster system. A couple things I noticed right now: - dist in debian/changelog should be 'buster-security' (not 'buster') - debdiff|diffstat shows spurious '.pc' work files from quilt (plus a change in a patches/README which maybe adds more noise than it

Re: Cannot read newsgroups with new Thunderbird

2022-10-12 Thread Sylvain Beucler
at the official Thunderbird contact points. Cheers! Sylvain Beucler Debian LTS Team On 05/10/2022 15:17, Miroslav Skoric wrote: After a recent Thunderbird upgrade in Buster (from version 91-something to 101-something, or like), it stopped handling newsgroups properly (where the source is News Server (NNTP

[SECURITY] [DLA 3137-1] nodejs security update

2022-10-05 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3137-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler October 05, 2022

Debian LTS and ELTS - September 2022

2022-10-01 Thread Sylvain Beucler
ons front-desk tooling - IRC meeting http://meetbot.debian.net/debian-lts/2022/debian-lts.2022-09-22-13.58.html -- Sylvain Beucler Debian LTS Team

Re: What do do with bullseye minor issues?

2022-09-29 Thread Sylvain Beucler
Hi, On 29/09/2022 09:09, Emilio Pozuelo Monfort wrote: On 28/09/2022 23:54, Ola Lundqvist wrote: Took me a month to get down here in the email backlog. I think your reasoning makes sense. I have added the following to the LTS/Development page. "If a CVE has been fixed in Debian Stable it

Re: Accepted pcs 0.10.1-2+deb10u1 (source) into oldstable

2022-09-14 Thread Sylvain Beucler
Hello, On 14/09/2022 22:43, Valentin Vidic wrote: On Wed, Sep 14, 2022 at 06:46:47PM +0200, Sylvain Beucler wrote: Thank you for claiming 'pcs' in dla-needed.txt and uploading a fixed version. LTS uploads follow a procedure which notably involves reserving a DLA in the security tracker

Re: Accepted pcs 0.10.1-2+deb10u1 (source) into oldstable

2022-09-14 Thread Sylvain Beucler
, are you waiting for us to check/review something? Cheers! Sylvain Beucler Debian LTS Team On 12/09/2022 00:50, Debian FTP Masters wrote: Format: 1.8 Date: Sun, 04 Sep 2022 21:55:16 +0200 Source: pcs Architecture: source Version: 0.10.1-2+deb10u1 Distribution: buster-security Urgency: high Maintainer

Re: Bug#961654: buster-pu: package bzip2/1.0.6-9.2~deb10u1

2022-09-13 Thread Sylvain Beucler
Hi, IIUC this is about fixing 2 non-security bugs, that were introduced prior to buster's initial release. I personally don't think this fits the LTS project scope. Maybe other LTS members will have a different opinion. Cheers! Sylvain Beucler Debian LTS Team On 13/09/2022 15:27, Santiago

Re: node-thenify

2022-09-12 Thread Sylvain Beucler
Hi, If sponsored packages are already handled, and we have time to fix this package, and I think we can fix it. I think we need to evaluate a package's usage only when fixing is problematic (time constraints, backport issues, uncooperative upstream...). Package usage would then be used

Re: Updating OpenStack compute (aka src:nova) in Buster

2022-09-12 Thread Sylvain Beucler
Hi Thomas, To answer the second part of your e-mail: > How to proceed? Can I simply upload the normal way? IS there a 3rd > party peer reviewing accepting / rejecting uploads for LTS? While LTS is mostly handled by members of the LTS Team, any DD can contribute directly; we have a few

Debian LTS - August 2022

2022-09-01 Thread Sylvain Beucler
information - New weekly information report: internal discussion on how to present and handle outstanding package updates - Monthly meeting (using Jitsi) -- Sylvain Beucler Debian LTS Team

Re: Accepted webkit2gtk 2.36.7-1~deb10u1 (source) into oldstable

2022-08-30 Thread Sylvain Beucler
Hi all, On 30/08/2022 07:38, Carsten Schoenert wrote: Hello Anton, Am 29.08.22 um 22:28 schrieb Anton Gladky: Hi Carsten, thanks for update! As the buster is now in LTS hands, would you want us to release a DLA? sure, I've somehow forgotten that Buster is now LTS handled. In the past

[SECURITY] [DLA 3082-1] exim4 security update

2022-08-27 Thread Sylvain Beucler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3082-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler August 27, 2022

Re: EOL candidates for security-support-ended.deb10 (recap)

2022-08-12 Thread Sylvain Beucler
ate future, and the discussion seems to have reached consensus, so I think it's good for upload :) Cheers! Sylvain Beucler Debian LTS Team

  1   2   3   4   5   >