Re: Security fix for jquery-jplayer 2.1.0-1

2013-04-29 Thread Bernhard R. Link
* Adam D. Barratt [130428 21:24]: > >From the page in question: > > > Rule #1. In all cases, when preparing an upload, please do not make > changes to the package that are not related to fixing the bugs in > question. As a non-exhaustive list, this implies not: > > Changing source format > Chan

Re: Security fix for jquery-jplayer 2.1.0-1

2013-04-28 Thread Adam D. Barratt
On Sun, 2013-04-28 at 20:38 +0200, Bernhard R. Link wrote: > * Niels Thykier [130427 09:18]: > > On 2013-04-27 09:12, Vincent Bernat wrote: > > > Not in the release team either but I disagree that switching to 3.0 > > > (quilt) is an unacceptable change. [...] > > While you are welcome to disagree

Re: Security fix for jquery-jplayer 2.1.0-1

2013-04-28 Thread Bernhard R. Link
* Niels Thykier [130427 09:18]: > On 2013-04-27 09:12, Vincent Bernat wrote: > > Not in the release team either but I disagree that switching to 3.0 > > (quilt) is an unacceptable change. This is far more simple than adding a > > patch system in debian/rules and better practice than putting those

Re: Security fix for jquery-jplayer 2.1.0-1

2013-04-27 Thread Adam D. Barratt
On Sat, 2013-04-27 at 12:41 +0200, Pau Garcia i Quiles wrote: > On Sat, Apr 27, 2013 at 10:31 AM, Adam D. Barratt > wrote: > One middle ground that's been used in some other packages is > to > apply the patch directly but also add a copy of the patch to > the sourc

Re: Security fix for jquery-jplayer 2.1.0-1

2013-04-27 Thread Pau Garcia i Quiles
On Sat, Apr 27, 2013 at 10:31 AM, Adam D. Barratt wrote: > On Sat, 2013-04-27 at 09:12 +0200, Vincent Bernat wrote: > > ❦ 27 avril 2013 09:01 CEST, "Thijs Kinkhorst" : > > > > >> Wheezy contains my package jquery-jplayer 2.1.0-1, which is affected > by a > > >> few security issues which have bee

Re: Security fix for jquery-jplayer 2.1.0-1

2013-04-27 Thread Adam D. Barratt
On Sat, 2013-04-27 at 09:12 +0200, Vincent Bernat wrote: > ❦ 27 avril 2013 09:01 CEST, "Thijs Kinkhorst" : > > >> Wheezy contains my package jquery-jplayer 2.1.0-1, which is affected by a > >> few security issues which have been recently fixed upstream. One of the > >> issues is CVE-2013-1942. T

Re: Security fix for jquery-jplayer 2.1.0-1

2013-04-27 Thread Vincent Bernat
❦ 27 avril 2013 09:18 CEST, Niels Thykier  : >> Not in the release team either but I disagree that switching to 3.0 >> (quilt) is an unacceptable change. This is far more simple than adding a >> patch system in debian/rules and better practice than putting those >> changes in diff.gz. >> > > Hi,

Re: Security fix for jquery-jplayer 2.1.0-1

2013-04-27 Thread Niels Thykier
On 2013-04-27 09:12, Vincent Bernat wrote: > ❦ 27 avril 2013 09:01 CEST, "Thijs Kinkhorst" : > >> [...] > > Not in the release team either but I disagree that switching to 3.0 > (quilt) is an unacceptable change. This is far more simple than adding a > patch system in debian/rules and better pr

Re: Security fix for jquery-jplayer 2.1.0-1

2013-04-27 Thread Vincent Bernat
❦ 27 avril 2013 09:01 CEST, "Thijs Kinkhorst"  : >> Wheezy contains my package jquery-jplayer 2.1.0-1, which is affected by a >> few security issues which have been recently fixed upstream. One of the >> issues is CVE-2013-1942. Two other issues, although important, did not get >> a CVE number. >

Re: Security fix for jquery-jplayer 2.1.0-1

2013-04-27 Thread Thijs Kinkhorst
Hi Pau, On Sat, April 27, 2013 01:31, Pau Garcia i Quiles wrote: > Wheezy contains my package jquery-jplayer 2.1.0-1, which is affected by a > few security issues which have been recently fixed upstream. One of the > issues is CVE-2013-1942. Two other issues, although important, did not get > a CV

Security fix for jquery-jplayer 2.1.0-1

2013-04-26 Thread Pau Garcia i Quiles
Hello, Wheezy contains my package jquery-jplayer 2.1.0-1, which is affected by a few security issues which have been recently fixed upstream. One of the issues is CVE-2013-1942. Two other issues, although important, did not get a CVE number. I have backported the patches and created jquery-jplaye