[Pkg-javascript-devel] Bug#924462: marked as done (node-opencv: please make the build reproducible)

2019-03-26 Thread Debian Bug Tracking System
Your message dated Wed, 27 Mar 2019 06:36:09 + with message-id and subject line Bug#924462: fixed in node-opencv 6.0.0+git20180416.cfc96ba0-3 has caused the Debian Bug report #924462, regarding node-opencv: please make the build reproducible to be marked as done. This means that you claim tha

[Pkg-javascript-devel] Bug#925571: marked as done (node-opencv: CVE-2019-10061)

2019-03-26 Thread Debian Bug Tracking System
Your message dated Wed, 27 Mar 2019 06:36:09 + with message-id and subject line Bug#925571: fixed in node-opencv 6.0.0+git20180416.cfc96ba0-3 has caused the Debian Bug report #925571, regarding node-opencv: CVE-2019-10061 to be marked as done. This means that you claim that the problem has be

[Pkg-javascript-devel] node-opencv_6.0.0+git20180416.cfc96ba0-3_sourceonly.changes ACCEPTED into unstable

2019-03-26 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Wed, 27 Mar 2019 04:27:41 +0530 Source: node-opencv Architecture: source Version: 6.0.0+git20180416.cfc96ba0-3 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers Changed-By: Utkarsh Gupta

[Pkg-javascript-devel] Processing of node-opencv_6.0.0+git20180416.cfc96ba0-3_sourceonly.changes

2019-03-26 Thread Debian FTP Masters
node-opencv_6.0.0+git20180416.cfc96ba0-3_sourceonly.changes uploaded successfully to localhost along with the files: node-opencv_6.0.0+git20180416.cfc96ba0-3.dsc node-opencv_6.0.0+git20180416.cfc96ba0-3.debian.tar.xz Greetings, Your Debian queue daemon (running on host usper.debian.o

[Pkg-javascript-devel] node-opencv_6.0.0+git20180416.cfc96ba0-3_sourceonly.changes REJECTED

2019-03-26 Thread Debian FTP Masters
node-opencv_6.0.0+git20180416.cfc96ba0-3.dsc: Invalid size hash for node-opencv_6.0.0+git20180416.cfc96ba0.orig.tar.gz: According to the control file the size hash should be 6230500, but node-opencv_6.0.0+git20180416.cfc96ba0.orig.tar.gz has 6232937. If you did not include node-opencv_6.0.0+git

[Pkg-javascript-devel] node-make-dir_2.1.0-1_sourceonly.changes ACCEPTED into experimental

2019-03-26 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Wed, 27 Mar 2019 05:13:19 +0530 Source: node-make-dir Architecture: source Version: 2.1.0-1 Distribution: experimental Urgency: medium Maintainer: Debian Javascript Maintainers Changed-By: Utkarsh Gupta Changes: nod

[Pkg-javascript-devel] Processing of node-opencv_6.0.0+git20180416.cfc96ba0-3_sourceonly.changes

2019-03-26 Thread Debian FTP Masters
node-opencv_6.0.0+git20180416.cfc96ba0-3_sourceonly.changes uploaded successfully to localhost along with the files: node-opencv_6.0.0+git20180416.cfc96ba0-3.dsc node-opencv_6.0.0+git20180416.cfc96ba0-3.debian.tar.xz Greetings, Your Debian queue daemon (running on host usper.debian.o

[Pkg-javascript-devel] Processing of node-make-dir_2.1.0-1_sourceonly.changes

2019-03-26 Thread Debian FTP Masters
node-make-dir_2.1.0-1_sourceonly.changes uploaded successfully to localhost along with the files: node-make-dir_2.1.0-1.dsc node-make-dir_2.1.0.orig.tar.gz node-make-dir_2.1.0-1.debian.tar.xz Greetings, Your Debian queue daemon (running on host usper.debian.org) -- Pkg-javascript-

[Pkg-javascript-devel] Processed: Bug #925571 in node-opencv marked as pending

2019-03-26 Thread Debian Bug Tracking System
Processing control commands: > tag -1 pending Bug #925571 [src:node-opencv] node-opencv: CVE-2019-10061 Added tag(s) pending. -- 925571: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=925571 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- Pkg-javascript-devel maili

[Pkg-javascript-devel] RFS: node-opencv

2019-03-26 Thread Utkarsh Gupta
Hey, The recent update fixes the CVE-2019-10061 and thus the bug #925571. The package was tested on sbuild and was successfully built and was lintian clean. The changes can be found at: https://salsa.debian.org/js-team/node-opencv Requesting you to please review and upload the same :) Best, Ut

[Pkg-javascript-devel] Bug#925571: node-opencv: CVE-2019-10061

2019-03-26 Thread Salvatore Bonaccorso
Source: node-opencv Version: 6.0.0+git20180416.cfc96ba0-2 Severity: important Tags: security upstream Hi, The following vulnerability was published for node-opencv. CVE-2019-10061[0]: | utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) | prior to 6.1.0 is vulnerable to Comman

[Pkg-javascript-devel] Bug#925517: Bug#925517: Non-NSA/Microsoft upstream repo, new version

2019-03-26 Thread Jeffrey Cliff
> many packages come from GitHub And I intend on filing a bug report on every single one of those packages, as they come up. This is a huge problem, but one that can be solved since it is free software we are talking about. On Tue, 26 Mar 2019 at 15:28, Xavier wrote: > Le 26/03/2019 à 20:17,

[Pkg-javascript-devel] Bug#925517: Bug#925517: Non-NSA/Microsoft upstream repo, new version

2019-03-26 Thread Xavier
Le 26/03/2019 à 20:17, Jeffrey Cliff a écrit : > As maintainer, that's up to you, but I do not accept any project hosted > in the NSA/Microsoft walled garden as the legitimate upstream of > anything and I will continue to host 'progress', in particular, > somewhere, until a 2.0.0+ version is availa

[Pkg-javascript-devel] Bug#925517: marked as done (Non-NSA/Microsoft upstream repo, new version)

2019-03-26 Thread Debian Bug Tracking System
Your message dated Tue, 26 Mar 2019 20:29:33 +0100 with message-id <77c23e3a-f9bf-d08a-2a9d-809c9bff6...@debian.org> and subject line Closing has caused the Debian Bug report #925517, regarding Non-NSA/Microsoft upstream repo, new version to be marked as done. This means that you claim that the pr

[Pkg-javascript-devel] Bug#925517: Bug#925517: Non-NSA/Microsoft upstream repo, new version

2019-03-26 Thread Jeffrey Cliff
As maintainer, that's up to you, but I do not accept any project hosted in the NSA/Microsoft walled garden as the legitimate upstream of anything and I will continue to host 'progress', in particular, somewhere, until a 2.0.0+ version is available in some other upstream place. On Tue, 26 Mar 2019

[Pkg-javascript-devel] Bug#925517: Bug#925517: Non-NSA/Microsoft upstream repo, new version

2019-03-26 Thread Xavier
Le 26/03/2019 à 19:04, Jeffrey Cliff a écrit : > 2.0.0 was the version when Microsoft captured Github.  That's the newest > one I have, but thankfully that's as new as is needed by the version of > eslint in RFP. > > I prefer to do my contributions anonymously.  I am not the author. > >> Followin

[Pkg-javascript-devel] Bug#925517: Bug#925517: Non-NSA/Microsoft upstream repo, new version

2019-03-26 Thread Xavier
Le 26/03/2019 à 17:53, Jeffrey Cliff a écrit : > I don't use NSA/Microsoft github so I'll assume you mean to update the > readme in the repo I control, which I have added a note to.  Is there > anything in specific you are interested in my adding? > > On Tue, 26 Mar 2019 at 07:17, Xavier

Re: [Pkg-javascript-devel] Giuseppe Pereira Interesting to join js-team

2019-03-26 Thread Xavier
Le 21/03/2019 à 01:28, Giuseppe M. Pereira a écrit : > Dear js-team, > > My name is Giuseppe Pereira and I'm NodeJS Software Architect in Brazil. > I'm contacting you to apply for join on js-team and collaborate to > Debian community. > > > How may I proceed? Hello, join us on https://salsa.de

[Pkg-javascript-devel] Bug#925517: Bug#925517: Non-NSA/Microsoft upstream repo, new version

2019-03-26 Thread Jeffrey Cliff
I don't use NSA/Microsoft github so I'll assume you mean to update the readme in the repo I control, which I have added a note to. Is there anything in specific you are interested in my adding? On Tue, 26 Mar 2019 at 07:17, Xavier wrote: > Le 26/03/2019 à 08:07, Jeffrey Cliff a écrit : > > Pack

Re: [Pkg-javascript-devel] Giuseppe Pereira Interesting to join js-team

2019-03-26 Thread Pirate Praveen
On Thu, Mar 21, 2019 at 5:58 AM, "Giuseppe M. Pereira" wrote: Dear js-team, My name is Giuseppe Pereira and I'm NodeJS Software Architect in Brazil. I'm contacting you to apply for join on js-team and collaborate to Debian community. How may I proceed? Hi Guiseppe, Welcome to js-tea

[Pkg-javascript-devel] yarnpkg vs. yarn

2019-03-26 Thread Jack Bates
Thank you for getting Yarn into Debian! Being able to install Yarn with APT is great, but I spent a while hunting for an explanation why the command is called "yarnpkg" instead of "yarn", like the upstream command (my scripts all expect to call "yarn"). Would you consider adding a link to [1] t

[Pkg-javascript-devel] Giuseppe Pereira Interesting to join js-team

2019-03-26 Thread Giuseppe M. Pereira
Dear js-team, My name is Giuseppe Pereira and I'm NodeJS Software Architect in Brazil. I'm contacting you to apply for join on js-team and collaborate to Debian community. How may I proceed? Thank You, Giuseppe Pereira. -- Pkg-javascript-devel mailing list Pkg-javascript-devel@alioth-lists.d

[Pkg-javascript-devel] Bug#925517: Bug#925517: Non-NSA/Microsoft upstream repo, new version

2019-03-26 Thread Xavier
Le 26/03/2019 à 08:07, Jeffrey Cliff a écrit : > Package: node-progress > Version: 1.1.8-1 > Severity: normal > > As NSA/Microsoft has taken over Github, it is long since time to move to > a non-Microsoft source for projects like node-progress.  I have made a > non-microsoft repo at salsa > at htt

[Pkg-javascript-devel] Processed: eslint depends on node-progress 2.0.0

2019-03-26 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > block 743404 by 925517 Bug #743404 [wnpp] RFP: eslint -- tool for static analysis of ECMAScript (JavaScript™) code 743404 was blocked by: 774565 901186 910824 780357 922941 743404 was blocking: 842420 901183 908765 910381 910614 910828 920871 923

[Pkg-javascript-devel] Bug#925517: Non-NSA/Microsoft upstream repo, new version

2019-03-26 Thread Jeffrey Cliff
Package: node-progress Version: 1.1.8-1 Severity: normal As NSA/Microsoft has taken over Github, it is long since time to move to a non-Microsoft source for projects like node-progress. I have made a non-microsoft repo at salsa at https://salsa.debian.org/themusicgod1-guest/progress/ for use as a