Hi Xavier,

On Mon, Oct 05, 2026 at 03:28:28PM +0200, Xavier wrote:
> Le 05/10/2026 à 11:27, Salvatore Bonaccorso a écrit :
> > Hi Xavier,
> > 
> > On Sat, Oct 03, 2026 at 07:47:47AM +0200, Xavier wrote:
> > > Le 02/10/2026 à 16:51, Salvatore Bonaccorso a écrit :
> > > > Source: node-shell-quote
> > > > Version: 1.10.0-1
> > > > X-Debbugs-CC: [email protected]
> > > > Severity: grave
> > > > Tags: security upstream
> > > > 
> > > > Hi,
> > > > 
> > > > The following vulnerability was published for node-shell-quote.
> > > > 
> > > > CVE-2026-102422[0]:
> > > 
> > > Hi,
> > > 
> > > here is the debdiff. If you don't consider it as urgent, of course I can
> > > push it to release.debian.org.
> > 
> > We have node-shell-quote ineed in dsa-needed list, and issue
> > warranting a DSA. But while at it, can you as well include the fix for
> > the no-dsa marked one, CVE-2026-13311? Or is there a reason we should
> > rather ignore it?
> > 
> > Regards,
> > Salvatore
> 
> Hi,
> 
> done. I also fixed the debdiff, base was not good

Indeed, that was wrong base as we already have 1.7.4+~1.7.1-1+deb13u1.

> diff --git a/debian/changelog b/debian/changelog
> index 05e6b17..273622b 100644
> --- a/debian/changelog
> +++ b/debian/changelog
> @@ -1,3 +1,12 @@
> +node-shell-quote (1.7.4+~1.7.1-1+deb13u2) trixie; urgency=medium

Target distribution should be trixie-security instead. With that
fixed, please upload to security-master.

Regards,
Salvatore

-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to