Re: RFS: ruby-loofah 2.2.1-1 (CVE-2018-8048)

2018-03-22 Thread Georg Faerber
On 18-03-22 01:33:20, Chris Hofstaedtler wrote: > * Georg Faerber [180322 01:29]: > > On 18-03-22 01:04:23, Cédric Boutillier wrote: > > > Can you also take care of applying the patch to the version currently > > > in stable and contact the security team for a proposed update

Re: ruby-loofah 2.0.3-2 (stretch) update (CVE-2018-8048)

2018-03-22 Thread Moritz Muehlenhoff
On Thu, Mar 22, 2018 at 05:21:15PM +0100, Georg Faerber wrote: > Dear security team, > > I would like to fix CVE-2018-8048, which is currently present in > ruby-loofah 2.0.3-2 in stretch. Do you prefer an "straight" upload done > by you, or should this be instead an upload via stretch-pu? > > In

Re: RFS ruby-aws-sdk (1.67.0-2) && 2 questions

2018-03-22 Thread Antonio Terceiro
On Mon, Mar 19, 2018 at 03:05:11AM +0100, Tomasz Nitecki wrote: > Hey, > > ruby-aws-sdk started to fail during CI run [1] due to ruby-json version > requirement. This issue was (hot)fixed in Ubuntu version [2][3] so I've > ported their patch to us. Additionally, I've refreshed the package >