Hello Lester! Leave you more comments:
- d/patches/0011-fix-vulnerable-username.patch: AFAIU your are not the author of that patch https://github.com/mitmproxy/mitmproxy/commit/71c9234057922bc29b9734ec408d712113d294d2, you should mention the Origin and the correct Author. Also Bug-Debian key, it would be great add it. - Same commento for d/patches/0010-remove-return-in-finally.patch - Seems that mitmproxy/contrib/tornado/__init__.py is LGPL-2.1+. - Could you improve d/upstream/metadata file please? Let me know when you have new version to review. On 2026-08-31 13:00, Lester Guerzon wrote: > Hi Emmanuel, > > Thanks for the review. > > > - Please review the license of mitmproxy/contrib/click/__init__.py, > > I was able to track the source of the file [1]. Added to d/copyright. > > > mitmproxy/contrib/tornado/__init__.py and, > > Upstream forgot to update the copyright placeholder in their license file so > I used the copyright string from their website (although this one did not > have a copyright year). Hope this is okay. > > > mitmproxy/contrib/urwid/raw_display.py > > Added to d/copyright. > > > - There're some open bugs, do you plan fix them? > > This release would fix #1146166 and #1094593. I took a look at #1119682 and > was able to fix that as well. > > I also added a fix to a warning (ex. when running mitmweb): > 0010-remove-return-in-finally.patch. > > There is one more bug #1134620 for CVE-2026-40606. Technically, 8.1.1 is not > vulnerable to this specific CVE [2] since the commit in question has been > introduced in 10.1.2. But the same code is still vulnerable to the same > unsanitized username. I took the same approach as the fix for CVE-2026-40606 > [3], adapted it, and applied a patch 0011-fix-vulnerable-username.patch. > > > - I guess you can update Standards-Version. > > - All b-depends are still needed? (I didn't check it) > > Updated standards version and compat (=14). Cleaned up some in build-deps and > deps. > > > Let me know when you have a new version to review. > > I pushed my changes to the repo. > > Thanks! > > > [1] https://github.com/pallets/click/blob/main/src/click/termui.py > [2] > https://salsa.debian.org/security-tracker-team/security-tracker/-/merge_requests/324?pow_referer=https%3A%2F%2Fsalsa.debian.org%2Flester > [3] > https://github.com/mitmproxy/mitmproxy/commit/71c9234057922bc29b9734ec408d712113d294d2 > > -- > Regards, > Lester > > [email protected] > OpenPGP: 107B6026A82D044C97D7D8B92100C145E0F3655E > > -- cheers, Emmanuel Arias ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ [email protected] ⢿⡄⠘⠷⠚⠋⠀ OpenPGP: 13796755BBC72BB8ABE2AEB5 FA9DEC5DE11C63F1 ⠈⠳⣄
signature.asc
Description: PGP signature

