Hi Xavier,

On Sat, Oct 03, 2026 at 07:47:47AM +0200, Xavier wrote:
> Le 02/10/2026 à 16:51, Salvatore Bonaccorso a écrit :
> > Source: node-shell-quote
> > Version: 1.10.0-1
> > X-Debbugs-CC: [email protected]
> > Severity: grave
> > Tags: security upstream
> > 
> > Hi,
> > 
> > The following vulnerability was published for node-shell-quote.
> > 
> > CVE-2026-102422[0]:
> 
> Hi,
> 
> here is the debdiff. If you don't consider it as urgent, of course I can
> push it to release.debian.org.

We have node-shell-quote ineed in dsa-needed list, and issue
warranting a DSA. But while at it, can you as well include the fix for
the no-dsa marked one, CVE-2026-13311? Or is there a reason we should
rather ignore it?

Regards,
Salvatore

-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to