[Python-modules-team] Bug#937645: python-cjson: Python2 removal in sid/bullseye

2020-06-30 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:37:25AM +, Matthias Klose wrote: > Package: src:python-cjson > Version: 1.2.1-1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2 from th

[Python-modules-team] Bug#938756: Bug#937769: getting python-linecache2/python-traceback2 fixes into testing (FAO traceback2, funcsigs nipype and numba maintainers).

2020-04-30 Thread Moritz Mühlenhoff
On Mon, Apr 20, 2020 at 09:57:30AM +0200, Thomas Goirand wrote: > On 4/20/20 4:36 AM, peter green wrote: > > Funcsigs is a backport of the PEP 362 function signature features from > Python 3.3's inspect module. Python 2 has never been removed from this > package. Though instead, we shall remove th

[Python-modules-team] Bug#938800: fixed in voluptuous 0.11.7-1

2020-03-30 Thread Moritz Mühlenhoff
On Sat, Sep 21, 2019 at 07:49:48PM +, Thomas Goirand wrote: > Source: voluptuous > Source-Version: 0.11.7-1 > > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Format: 1.8 > Date: Sat, 21 Sep 2019 21:15:26 +0200 > Source: voluptuous > Architecture: source > Version: 0.11.7-1 > Distri

[Python-modules-team] Bug#938736: txwinrm: Python2 removal in sid/bullseye

2020-03-09 Thread Moritz Mühlenhoff
On Mon, Mar 09, 2020 at 09:02:29PM +, Christopher Hoskin wrote: > Dear Moritz, > > Yes - that seems sensible. There's no sign of an upstream Python 3 version. Thanks, I've just filed a removal bug. Cheers, Moritz ___ Python-modules-team ma

[Python-modules-team] Bug#938736: txwinrm: Python2 removal in sid/bullseye

2020-03-09 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:57:05AM +, Matthias Klose wrote: > Package: src:txwinrm > Version: 1.3.3-1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2 from the dis

[Python-modules-team] Bug#953013: Bug#953013: pyyaml: CVE-2020-1747: arbitrary command execution through python/object/new when FullLoader is used

2020-03-03 Thread Moritz Mühlenhoff
On Tue, Mar 03, 2020 at 12:15:09PM -0500, Scott Kitterman wrote: > On Tuesday, March 3, 2020 11:41:26 AM EST Salvatore Bonaccorso wrote: > > OK. If anyone has a reproducer for this, it'd be very helpful to sort it out. > > I think this is like the recent CVE for python-bleach where the affected

[Python-modules-team] Bug#937609: patch

2019-11-28 Thread Moritz Mühlenhoff
tags 937609 patch thanks There are no rev deps left for the Python 2 package, patch attached. Cheers, Moritz diff -Naur python-biplist-1.0.3.orig/debian/control python-biplist-1.0.3/debian/control --- python-biplist-1.0.3.orig/debian/control 2018-02-22 11:16:31.0 +0100 +++ python-

[Python-modules-team] Bug#875190: [shiboken] Future Qt4 removal from Buster

2019-09-30 Thread Moritz Mühlenhoff
On Sat, Sep 09, 2017 at 11:09:45PM +0200, Lisandro Damián Nicanor Pérez Meyer wrote: > Source: shiboken > Version: 1.2.2-5 > Severity: wishlist > User: debian-qt-...@lists.debian.org > Usertags: qt4-removal > > > Hi! As you might know we the Qt/KDE team are preparing to remove Qt4 > as [announce

[Python-modules-team] Bug#875144: [qscintilla2] Future Qt4 removal from Buster

2019-09-08 Thread Moritz Mühlenhoff
Hi, On Sat, Sep 09, 2017 at 11:07:32PM +0200, Lisandro Damián Nicanor Pérez Meyer wrote: > Source: qscintilla2 > Version: 2.9.3+dfsg-4 > Severity: wishlist > User: debian-qt-...@lists.debian.org > Usertags: qt4-removal > > > Hi! As you might know we the Qt/KDE team are preparing to remove Qt4 >

[Python-modules-team] Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-09-02 Thread Moritz Mühlenhoff
On Mon, Sep 02, 2019 at 10:36:58PM +0200, Salvatore Bonaccorso wrote: > Hi Chris, > > On Mon, Sep 02, 2019 at 02:07:55PM +0100, Chris Lamb wrote: > > Chris Lamb wrote: > > > > > > > +python-django (1:1.11.23-1~deb10u1) buster-security; urgency=high > > > > > > > > Thanks, these both look good; p

[Python-modules-team] Bug#932960: python-django doesn't fix a CVE and drops Python 2 support at the same time

2019-07-25 Thread Moritz Mühlenhoff
On Thu, Jul 25, 2019 at 08:45:48PM +0200, Paul Gevers wrote: > Control: tags -1 moreinfo > > Hi Chris, > > On 25-07-2019 18:51, Chris Lamb wrote: > >> PS: I failed to spot bugs against (some of) those packages communication > >> the removal, I think that would be nice for those maintainers. > >

[Python-modules-team] Bug#931316: python-django: CVE-2019-12308: Incorrect HTTP detection with reverse-proxy connecting via HTTPS

2019-07-02 Thread Moritz Mühlenhoff
On Mon, Jul 01, 2019 at 05:57:51PM -0300, Chris Lamb wrote: > [Adding t...@security.debian.org, to CC] > > Hi Salvatore, > > > Control: found -1 2:2.2.1-1 > > Control: found -1 1:1.10.7-2+deb9u4 > > Control: found -1 1:1.10.7-1 > > I've uploaded fixes to experimental, unstable and to jessie LTS.

[Python-modules-team] Bug#922027: python-django: Django security release

2019-02-14 Thread Moritz Mühlenhoff
On Mon, Feb 11, 2019 at 03:07:36PM +0100, Chris Lamb wrote: > [Adding t...@security.debian.org to CC] > > Chris Lamb wrote: > > > retitle 922027 CVE-2019-6975: Memory exhaustion in > > django.utils.numberformat.format() > > severity 922027 grave > > found 922027 1:1.10.7-2+deb9u3 > > tags 922027