Bug#941683: buster-pu: package node-yarnpkg/1.13.0-1+deb10u1

2019-11-08 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2019-10-03 at 20:57 +0200, Xavier Guimard wrote: > node-yarnpkg is vulnerable: it exports auth data in http requests > (#941354, CVE-2019-5448). This patch imports upstream fix. Please go ahead; thanks. Regards, Adam

Processed: Re: Bug#941683: buster-pu: package node-yarnpkg/1.13.0-1+deb10u1

2019-11-08 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #941683 [release.debian.org] buster-pu: package node-yarnpkg/1.13.0-1+deb10u1 Added tag(s) confirmed. -- 941683: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=941683 Debian Bug Tracking System Contact ow...@bugs.debian.org with

Bug#941683: buster-pu: package node-yarnpkg/1.13.0-1+deb10u1

2019-10-03 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Hi, node-yarnpkg is vulnerable: it exports auth data in http requests (#941354, CVE-2019-5448). This patch imports upstream fix. Cheers, Xavier diff --git a/debian/changelog