Bug#996024: buster-pu: package ruby-httpclient/2.8.3-3+deb10u1

2021-12-05 Thread Antonio Terceiro
On Sat, Dec 04, 2021 at 05:31:52PM +, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Sun, 2021-10-10 at 09:58 -0300, Antonio Terceiro wrote: > > ruby-httpclient uses a vendored copy of a CA certificate bundle, and > > that is a ticking time bomb. This update fixes that by

Bug#996024: buster-pu: package ruby-httpclient/2.8.3-3+deb10u1

2021-12-04 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2021-10-10 at 09:58 -0300, Antonio Terceiro wrote: > ruby-httpclient uses a vendored copy of a CA certificate bundle, and > that is a ticking time bomb. This update fixes that by removing that > vendored copy and making it use the system CA certificate bundle

Processed: Re: Bug#996024: buster-pu: package ruby-httpclient/2.8.3-3+deb10u1

2021-12-04 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #996024 [release.debian.org] buster-pu: package ruby-httpclient/2.8.3-3+deb10u1 Added tag(s) confirmed. -- 996024: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=996024 Debian Bug Tracking System Contact ow...@bugs.debian.org with

Bug#996024: buster-pu: package ruby-httpclient/2.8.3-3+deb10u1

2021-10-10 Thread Antonio Terceiro
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu [ Reason ] ruby-httpclient uses a vendored copy of a CA certificate bundle, and that is a ticking time bomb. This update fixes that by removing that vendored copy and making it use