Bug#887060: testing migration happened despite FTBFS on arch:all buildd

2020-12-19 Thread Paul Gevers
Hi all, On Thu, 15 Nov 2018 20:49:43 +0100 Paul Gevers wrote: > I think I have found the cause for this issue. Apparently some arch:all > binary packages are not listed in both the binary-/Packages.* and > binary-all/Packages.* file groups, but ONLY in the binary-all/Packages.* > files (at least

Bug#977735: buster-pu: package node-ini/1.3.5-1+deb10u1

2020-12-19 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu [ Reason ] node-ini is vulnearable to CVE-2020-7788: if an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on t

Bug#977720: transition: http-parser

2020-12-19 Thread Christoph Biedl
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition Hello, the http-parser library should see an update from 2.9.2 (unstable) and 2.9.3 (experimental) to 2.9.4. Now I am unsure whether this requires a transition - at least the 2.9.3 uploa