Re: security upload imposing load on other parts of Debian

2020-03-01 Thread Chris Lamb
en I have not been as precise as I would have liked on the distinction between and , incorrectly thinking them to be essentially synonymous. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: [SECURITY] [DLA 2115-1] proftpd-dfsg security update

2020-03-02 Thread Chris Lamb
st wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2020-03-09 Thread Chris Lamb
Hi Holger et al., > ERROR: .data or .wml file missing for DLA 2115-2 (reserved by Chris Lamb) __^__ How does we announce a regression (ie. -2, -3) via the website? The namespacing used here (captured in the filenames such as 2020/ dla-2115.wml

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2020-03-09 Thread Chris Lamb
.* Ah, I had looked for exactly this but somehow these files escaped me. I have submitted a MR now: https://salsa.debian.org/webmaster-team/webwml/-/merge_requests/385 Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Bug#953950: python-twisted: twisted version 14.0.2-3+deb8u1 in jessie (security) is broken

2020-03-19 Thread Chris Lamb
Hi all, > Please, can you […] revert this patch and re-publish the working (but > security flawed) 14.0.2-3 twisted version ? I will take charge of fixing this in jessie with the utmost urgency. Thank you for raising this issue. Regards, -- ,''`. : :&#x

Re: Bug#953950: python-twisted: twisted version 14.0.2-3+deb8u1 in jessie (security) is broken

2020-03-19 Thread Chris Lamb
Chris Lamb wrote: > I will take charge of fixing this in jessie with the utmost urgency. I have just uploaded 14.0.2-3+deb8u2 and DLA-2145-2 will be announced after sending this email. Thank you again for raising this issue. Best wishes, -- ,''`. : :'

Re: CVE-2020-10938/graphicsmagick and additional upstream change

2020-03-30 Thread Chris Lamb
maximum of clarity to our users with the minimum of soul-searching & ontological debate regarding what ought to be included or not by the security team(s). :) Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

CVE-2020-1957 in shiro (#955018)

2020-04-07 Thread Chris Lamb
g and I just sent a followup the bug (as message #17) to that effect but perhaps someone reading this list will know the right switch to flip. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Jessie update of ceph?

2020-04-08 Thread Chris Lamb
r test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of ceph updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of the LTS team m

Re: CVE-2020-1957 in shiro (#955018)

2020-04-11 Thread Chris Lamb
this in the meantime? Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: dla-needed.txt: Add note on CVE-2020-1769 in otrs2.

2020-04-28 Thread Chris Lamb
-- https://bugzilla.mozilla.org/show_bug.cgi?id=1353035#c2 Regardless and unrelated to the merits of this argument, I am now more and more inclined to believe this is a no-dsa issue. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: keystone support in Jessie

2020-05-07 Thread Chris Lamb
me know and I will go ahead with that. I have removed keystone from dla-needed.txt in 18c3371ddc. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: nginx / CVE-2020-11724

2020-05-07 Thread Chris Lamb
nvasive". Fixed in bcc6ceb1c0... Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: keystone support in Jessie

2020-05-08 Thread Chris Lamb
ity-support/-/merge_requests/3 Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Refreshing mysql-connector-java

2020-05-08 Thread Chris Lamb
oblems by refreshing this package without knowing much about it. (Do we have an idea of how big the debdiff would be for this initial upload? Have we had issues in the past? Is there another metric we can use?) Best wishes, -- ,''`. : :' : Chris Lamb `. `'`

Re: Apache's mod_remoteip: IP address spoofing via X-Forwarded-For when mod_rewrite rule is triggered

2020-05-09 Thread Chris Lamb
of severity then by that very fact it won't be worth fixing in Jessie LTS. (Getting a CVE is somewhat easier than you think and my the first CVE I was assigned was actually a nice little badge of honour.) Regards, -- ,''`. : :' : Chris Lamb `. `&#

Re: Triage of CVE-2020-9489/tika

2020-05-09 Thread Chris Lamb
dsa here, did you consider upgrading the entire package to a newer version? (Is it even compatible? Is this critical enough of a package? etc.) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Jessie update of freerdp?

2020-05-10 Thread Chris Lamb
nd/or test the updated package before it gets released. You can also opt-out from receiving future similar emails in your answer and then the LTS Team will take care of freerdp updates for the LTS releases. Thank you very much. Chris Lamb, on behalf of the Debian LTS team. PS: A member of th

Re: What to do about DLA-2176-1

2020-05-10 Thread Chris Lamb
is can be ameliorated by, for example, appending a supplementary message that explicitly mentions and explains the delay in the mail. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: How to handle back-to-back firefox-esr uploads

2020-06-08 Thread Chris Lamb
too. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: jquery / CVE-2020-7656

2020-06-08 Thread Chris Lamb
Brian, > Do we only need to filter out javascript if a selector is provided for > some reason? Yes. Javascript development is fun. (As I added in the notes, I do not know how we are meant to cleanly fix this issue in jessie's version of jQuery.) Regards, -- ,''`.

Re: jquery / CVE-2020-7656

2020-06-09 Thread Chris Lamb
) so I would not be able to look at this before you would. In any case, I only know enough Javascript to know to avoid it anyway. Sorry I cannot be of more direct help here, but you have my moral support. Regards, -- ,''`. : :' : Chris Lamb `. `'`

Re: jquery / CVE-2020-7656

2020-06-10 Thread Chris Lamb
make my language clearer. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Draft: Debian 8 Long Term Support reaching end-of-life

2020-07-03 Thread Chris Lamb
these architectures are new to this support cycle? (i.e. "diff") Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Draft: Debian 8 Long Term Support reaching end-of-life

2020-07-03 Thread Chris Lamb
addition we are > pleased to announce, for the first time support will be extended to > include the arm64 architecture. Perfect. :) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: DLA template and user signatures

2020-07-07 Thread Chris Lamb
potentially- important security release? (Oh, almost entirely unrelated but I don't want to start a new thread for this: but don't forget to upload any LTS/ELTS entries in your ~/.dput.cf or similar.) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: [Git][security-tracker-team/security-tracker][master] Triage CVE-2020-12675, CVE-2020-12691, CVE-2020-12690 and CVE-2020-12689 for stretch LTS.

2020-07-07 Thread Chris Lamb
ou as it is a kind of 'meta' process question, feel free to poke it on. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: DLA template and user signatures

2020-07-07 Thread Chris Lamb
o if it gets resolved off-list or this is really minor, I'm totally fine with that. 👍 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

fwupd_0.7.4-2+deb9u1 (was: "Re: Debian 9 (Stretch) LTS: archive side should be done")

2020-07-09 Thread Chris Lamb
n my 0.7.4-2+deb9u1. I therefore conclude that this is fine *this* time. Please let me know if this is incorrect and, if so, what I can do to remedy it. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: drafted bits about the LTS survey

2020-07-11 Thread Chris Lamb
obably > want to do another survey in 2020... > - neither I'm unsure whether to include an email address for private > feedback and if so which. press@? me? utkarsh? buxy? (No strong feelings.) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: jruby support

2020-07-11 Thread Chris Lamb
Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: kernel updates

2020-07-28 Thread Chris Lamb
egards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: [Git][security-tracker-team/security-tracker][master] 2 commits: data/dla-needed.txt: Triage python-django for stretch LTS.

2020-09-01 Thread Chris Lamb
27; maintainer of Django. Will adjust the situation when I return to this, either later today or early tomorrow. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: [Git][security-tracker-team/security-tracker][master] 2 commits: data/dla-needed.txt: Triage python-django for stretch LTS.

2020-09-02 Thread Chris Lamb
Chris Lamb wrote: > > > Don't the new Django vulnerabilities only apply when running with Python > > 3.7 or > > newer? > > Replying quickly — possibly, have not looked into the (E)LTS angle yet. > > I was just ensuring that there was no duplicated effort

Re: golang-1.7 / CVE-2019-9514 / CVE-2019-9512

2020-09-09 Thread Chris Lamb
(Minor issue) Good spot. I'm not quite sure why either — I might first guess that it was something to do with the ordering of the entries, but not at all certain. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: IRC meeting this Thursday 24th - Agenda

2020-09-21 Thread Chris Lamb
ong), but a confirmation would be really appreciated. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Incomplete fix for CVE-2019-20218/sqlite3

2020-12-08 Thread Chris Lamb
: Fix integer overflow in sqlite3_str_vappendf. 27 28 -- Roberto C. Sanchez Tue, 04 Aug 2020 19:07:43 -0400 Roberto, can you follow-up on this? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: How to backport test binaries?

2021-02-03 Thread Chris Lamb
Hi Utkarsh, > On several occasions, I've seen that fixing commits of CVEs have some > sort of binaries (either an image or some compressed file or whatever) > added as a test to ensure that the fix is indeed working as expected. > > And whilst trying to backport, the patches don't seem to like git

Re: Update of OpenVSwitch in Stretch

2021-02-15 Thread Chris Lamb
anges. Can you vouch for upstream making sensible/reasonable decisions between these minor releases? That would be necessary for a hypothetical 2.6.11 too. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: CVE-2020-36193 php-pear vs drupal7

2021-02-25 Thread Chris Lamb
of triage. After all, the code copy of Tar.php (in "system.tar.inc") is very slightly hidden. I would go ahead and add drupal7 as well -- a very quick glance suggests that it is, indeed, vulnerable. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: DLA 2550-1: CVE-2020-27844: Patch present in source but not applied?

2021-03-16 Thread Chris Lamb
> Thanks for the analysis! And thanks for removing it from data/dla-needed.txt - I thought I should add it so the issue could not somehow get lost. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Adding python-django to dla-needed.txt

2021-04-06 Thread Chris Lamb
Hi Emilio, Glancing at lts-frontdesk.2021.txt, it seems like you are on LTS duty this week. Would you object if I added and claimed python-django to address CVE-2021-28658? I am the maintainer in unstable. (The same goes for ela-needed.txt too.) Regards, -- ,''`. : :

Re: Adding python-django to dla-needed.txt

2021-04-08 Thread Chris Lamb
e? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Adding python-django to dla-needed.txt

2021-04-09 Thread Chris Lamb
ar oversight nd does not realise they are on FD this week.) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Adding python-django to dla-needed.txt

2021-04-14 Thread Chris Lamb
h ongoing and new contributors) for little, if any, benefit. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: libgetdata

2021-05-10 Thread Chris Lamb
the package to you. I couldn't easily find the patch for CVE-2021-20204 to confirm that the version in LTS is vulnerable, but from your message I will assume that you have access. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: CVE-2021-32642 in radsecproxy

2021-05-27 Thread Chris Lamb
nce, I would be happy to upload it. Just to 100% check though: you are not in a position to upload it, create and publish a DLA, update the website, etc.? (Just avoiding duplicate work.) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: CVE-2021-32642 in radsecproxy

2021-05-27 Thread Chris Lamb
upload if FD believes the vulnerability does warrant an update, mind you. (Thanks either way, of course.) Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2021-06-14 Thread Chris Lamb
ty | source, all $ Am I missing something? Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2021-06-14 Thread Chris Lamb
ended up on the website. I've merged the commit from my fork of the webwml.git repository and it should appear on the website in due course. Thanks for the pointers. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: packages in *-lts newer than in subsequent releases

2021-08-02 Thread Chris Lamb
Andreas Beckmann wrote: > libpam-tacplus https://bugs.debian.org/962830 > pyxdg https://bugs.debian.org/930099 Will resolve these two. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: packages in *-lts newer than in subsequent releases

2021-08-03 Thread Chris Lamb
, your mail had not landed on the list by the time I replied to Andreas. Luckily, I had not started on libpam-tacplus.) Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: packages in *-lts newer than in subsequent releases

2021-08-05 Thread Chris Lamb
elease. * Add IBPB support for family 17h AMD processors (CVE-2017-5715) (since version 3.20180515.1). Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: packages in *-lts newer than in subsequent releases

2021-08-05 Thread Chris Lamb
gs like these, I'll take this one as well. Ah, I saw "jessie" and quickly added it so it didn't get lost in the archive. Can you move the entry to the correct file? Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Bug#993129: redis-tools 3:3.2.6-3+deb9u6 has broken dependencies

2021-08-27 Thread Chris Lamb
Utkarsh Gupta wrote: > Could you take a look at this bug report (#993129), please? Already fixed, just in the upload/archive pipeline... (was successfully ACCEPTED 30+ mins ago, for example.) Regards, -- ,''`. : :' : Chris Lamb `. `'` la

Re: (semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2021-09-06 Thread Chris Lamb
egards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Lintian changes for LTS development?

2021-09-27 Thread Chris Lamb
is on the basis that if I automatically ignore some of them, I might be inadvertently 'training' myself to ignore other, more serious, ones. However, I'm sure there is more low-hanging fruit that might prevent potential regressions. Thoughts welcome. Regards, -- ,''

Re: Lintian changes for LTS development?

2021-09-28 Thread Chris Lamb
ut between before and after applying a fix for relevant CVE(s)? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Semi-automatic unclaim of packages with more than 2 weeks being inactive

2021-10-26 Thread Chris Lamb
Jeremiah C. Foster wrote: > DLA 2791-1 (23 Oct 2021) (mailman) This has now been published; thanks for spotting. :) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: privoxy stretch package 3.0.26-3+deb9u3 prepared

2021-12-10 Thread Chris Lamb
bsequent update. The second CVE (CVE-2021-44543) looks like it might, in some configurations, be remotely exploitable. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: DLA needed for NBD 1:3.15.2-3

2022-03-09 Thread Chris Lamb
tive, especially when doing security releases.) Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: DLA needed for NBD 1:3.15.2-3

2022-03-10 Thread Chris Lamb
[[[ Just a quick administrative follow-up to this thread: to avoid any potential duplicated effort, I've gone ahead and claimed the nbd entry in dla-needed.txt. ]]] Chris Lamb wrote: >> I've prepared an update and pushed it to my repository at >> https://salsa.debian

Re: DLA needed for NBD 1:3.15.2-3

2022-03-10 Thread Chris Lamb
Hi Wouter, > Sure, that makes sense. Thanks for checking, but go right ahead and run > autogen.sh :-) Sure thing. So I've just gone ahead and released/uploaded this as DLA-2944-1 — thanks for helping to prepare this update. :) Best wishes, -- ,''`. :

Re: [SECURITY] [DLA 3077-1] ruby-tzinfo security update

2022-08-19 Thread Chris Lamb
7-1 within the security-tracker Git working tree. What am I missing? // Chris >> - >> Debian LTS Advisory DLA-3077-1debian-lts@lists.debian.org >> https://www.debian.org/lts/security/

Re: [SECURITY] [DLA 3077-1] ruby-tzinfo security update

2022-08-22 Thread Chris Lamb
t? I was programmatically generating the text myself, yes. I've updated my script accordingly though; thanks for pointing out the rather subtle s/"Stretch"/stretch/ change. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: [SECURITY] [DLA 3107-1] sqlite3 security update

2022-09-13 Thread Chris Lamb
I mistook the "2" suffix of "+deb10u2" to assume that the orig tarball was already in the archive and, as such, so I did not append dpkg-genchanges' -sa flag. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: [SECURITY] [DLA 3107-1] sqlite3 security update

2022-09-14 Thread Chris Lamb
Chris Lamb wrote: >> Did you forget to upload this? I don't see any sqlite3 update in >> buster-security (or maybe it was rejected or something). > > I didn't forget. Rather, it was REJECTED late last night and I re- > uploaded first thing this morning.

Re: [SECURITY] [DLA 3107-1] sqlite3 security update

2022-09-14 Thread Chris Lamb
block announcements until the package appears in the archive as you suggest; previously I was merely waiting an arbitrary amount of time. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Accepted knot-resolver 3.2.1-3+deb10u1 (source amd64 all) into oldstable

2022-10-07 Thread Chris Lamb
e uploads from the LTS tree, as well as fixed it on the Debian website. Thanks for pointing it out. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Updating the LTS/ELTS instructions on freexian.com

2022-10-10 Thread Chris Lamb
uot;a)" simply needs updating to the latest version (freexian-archive-keyring_2022.06.08_all.deb), but I'm not sure what to do with "b)", as well as how to update these instructions in the first place. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Updating the LTS/ELTS instructions on freexian.com

2022-10-10 Thread Chris Lamb
s will help. Thanks. -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-+++ type = "docs" title = "How to use Extended LTS" date = 2018-05-30T12:13:12+02:00 weight = 100 draft = false bref = "To ben

Re: clickhouse - Please review

2022-11-02 Thread Chris Lamb
true" instead of not running any of it. If you are using the autopkgtest facility, this can be achieved by marking the test as "flaky". (Replying for the edification of the list at large; pretty sure Anton shares this view & knowledge.) Best wishes, -- ,''

Re: Using Salsa-CI as pre-upload QA for Bullseye and Buster uploads: Lintian and Piuparts

2022-11-14 Thread Chris Lamb
alsa.debian.org/salsa-ci-team/pipeline#changing-the-debian-release … variable? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Using Salsa-CI as pre-upload QA for Bullseye and Buster uploads: Lintian and Piuparts

2023-01-02 Thread Chris Lamb
A packages before upload to _any_ Debian release? When I was maintaining Lintian, that was my intention. But it was never perfect in that regard. Hope this helps. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Accepted python-cryptography 2.6.1-3+deb10u4 (source amd64 all) into oldstable

2023-02-26 Thread Chris Lamb
Does this still needs a follow-up DLA to DLA 3331-1? Yes, indeed. This has been announced as DLA 3331-2. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

LTS upload of ruby-loofah

2023-03-13 Thread Chris Lamb
Hi Daniel, After being unclaimed through inactivity, I took over the claim for ruby-loofah in data/dla-needed.txt. However, I've just noticed that you have already authored and prepared some patches in the Git repo, which clearly took some time and effort. If you had not committed anything, I wou

Re: LTS upload of ruby-loofah

2023-03-14 Thread Chris Lamb
today and > tomorrow and finish this. Ah, great. I see that you've taken it the claim back and have requested feedback in a separate thread — thanks for the quick reply. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: [Git][security-tracker-team/security-tracker][master] Reserve DLA-3389-1 for lldpd

2023-04-12 Thread Chris Lamb
ommand, re-entering all the information again which might get a bit annoying. Maybe this would be good logic to introduce if we scripted the rebase at the very top of gen-DLA, but that is not entirely unproblematic either. Thoughts welcome. Regards, -- ,''`. : :&#

Re: Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload

2023-06-07 Thread Chris Lamb
t. Although you mentioned you were going to wait a bit more, I'm just 100%-checking you aren't waiting on anything from me to upload that? Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload

2023-06-07 Thread Chris Lamb
No, please go ahead and do both: my availability is spotty for the next 18 hours. :) (on mobile) Utkarsh Gupta wrote: > Hi Chris, > > On Wed, Jun 7, 2023 at 9:01 PM Chris Lamb wrote: >> I see your 2.5.5-3+deb10u6 update on the debian/buster branch which >> fixes the b

Re: opendmarc 1.3.2-6+deb10u3 postinst hangs

2023-08-30 Thread Chris Lamb
arts) did not surface this issue. Could it be different debconf frontends? If so, we should of course broaden our testing surface. Regards, -- o ⬋ ⬊ Chris Lamb o o reproducible-builds.org 💠 ⬊ ⬋ o

Re: Python review request, CVE-2022-22817 & CVE-2023-50447 in pillow

2024-03-01 Thread Chris Lamb
… which also has a lot of details that expose just enough info about Python's evaluation model to be interesting. Curiously , it also demonstrates how to use compile(…) in pretty much the same way that the patch for CVE-2022-22817 performs its check. Regards, -- ,''`.

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-04-10 Thread Chris Lamb
0 updates (see > https://lists.debian.org/debian-lts-announce/2024/03/threads.html for > example). Mmm, I highly suspect some counting mishap here. A quick, dirty (and likely inexact) grep across my last 12 LTS reports indicates I alone have addressed over 40. Regards, -- ,

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-04-11 Thread Chris Lamb
ive. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: [SECURITY] [DLA 3856-1] python-html-sanitizer security update

2024-08-26 Thread Chris Lamb
debian-lts-announce list. :( Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: bullseye-security upload queue open (was: [SECURITY] [DLA 3856-1] python-html-sanitizer security update)

2024-08-31 Thread Chris Lamb
. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org 🍥 chris-lamb.co.uk `-

Re: bullseye-security upload queue open (was: [SECURITY] [DLA 3856-1] python-html-sanitizer security update)

2024-09-02 Thread Chris Lamb
Chris Lamb wrote: > Hi Santiago et al., > >> Chris, are you able to upload python-html-sanitizer (or libtommath)? It >> would help to verify that everything is OK. > > Sure thing. I'll upload libtommath 1.1.0-3+deb10u1 presently as it > contains both arch:all and

<    1   2   3   4   5