[Desktop-packages] [Bug 1706471] Re: please demote exiv2 to universe

2018-05-22 Thread Bug Watch Updater
** Changed in: gexiv2
   Status: Confirmed => Expired

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to exiv2 in Ubuntu.
https://bugs.launchpad.net/bugs/1706471

Title:
  please demote exiv2 to universe

Status in gexiv2:
  Expired
Status in exiv2 package in Ubuntu:
  Triaged

Bug description:
  Hello,

  Please consider demoting exiv2 to universe.

  http://dev.exiv2.org/issues/1248

  The upstream author appears overwhelmed with the task of hardening
  exiv2 for use against untrusted inputs and thus far (~nine months) no
  users have provided the project with patches against known issues.

  $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/gexiv2/+bug/1706471/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp


[Desktop-packages] [Bug 1706471] Re: please demote exiv2 to universe

2017-11-03 Thread Adam Conrad
Unsubscribing ~ubuntu-archive, this is up to the desktop team to choose
to remove from their seeds and, if they do, our magic reports will tell
us to demote, we don't need a bug for that.

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to exiv2 in Ubuntu.
https://bugs.launchpad.net/bugs/1706471

Title:
  please demote exiv2 to universe

Status in gexiv2:
  Confirmed
Status in exiv2 package in Ubuntu:
  Triaged

Bug description:
  Hello,

  Please consider demoting exiv2 to universe.

  http://dev.exiv2.org/issues/1248

  The upstream author appears overwhelmed with the task of hardening
  exiv2 for use against untrusted inputs and thus far (~nine months) no
  users have provided the project with patches against known issues.

  $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/gexiv2/+bug/1706471/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp


[Desktop-packages] [Bug 1706471] Re: please demote exiv2 to universe

2017-07-28 Thread Bug Watch Updater
** Changed in: gexiv2
   Status: Unknown => Confirmed

** Changed in: gexiv2
   Importance: Unknown => Medium

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to exiv2 in Ubuntu.
https://bugs.launchpad.net/bugs/1706471

Title:
  please demote exiv2 to universe

Status in gexiv2:
  Confirmed
Status in exiv2 package in Ubuntu:
  Triaged

Bug description:
  Hello,

  Please consider demoting exiv2 to universe.

  http://dev.exiv2.org/issues/1248

  The upstream author appears overwhelmed with the task of hardening
  exiv2 for use against untrusted inputs and thus far (~nine months) no
  users have provided the project with patches against known issues.

  $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/gexiv2/+bug/1706471/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp


[Desktop-packages] [Bug 1706471] Re: please demote exiv2 to universe

2017-07-28 Thread Jeremy Bicha
Thank you!

** Project changed: exiv2 => gexiv2

** Changed in: exiv2 (Ubuntu)
   Status: Incomplete => Triaged

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to exiv2 in Ubuntu.
https://bugs.launchpad.net/bugs/1706471

Title:
  please demote exiv2 to universe

Status in gexiv2:
  Unknown
Status in exiv2 package in Ubuntu:
  Triaged

Bug description:
  Hello,

  Please consider demoting exiv2 to universe.

  http://dev.exiv2.org/issues/1248

  The upstream author appears overwhelmed with the task of hardening
  exiv2 for use against untrusted inputs and thus far (~nine months) no
  users have provided the project with patches against known issues.

  $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/gexiv2/+bug/1706471/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp


[Desktop-packages] [Bug 1706471] Re: please demote exiv2 to universe

2017-07-28 Thread Seth Arnold
Good idea Jeremy; https://bugzilla.gnome.org/show_bug.cgi?id=785547
(heh, launchpad called it 'exiv2' when I linked them together. Oh well.)

Thanks

** Bug watch added: GNOME Bug Tracker #785547
   https://bugzilla.gnome.org/show_bug.cgi?id=785547

** Also affects: exiv2 via
   https://bugzilla.gnome.org/show_bug.cgi?id=785547
   Importance: Unknown
   Status: Unknown

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to exiv2 in Ubuntu.
https://bugs.launchpad.net/bugs/1706471

Title:
  please demote exiv2 to universe

Status in Exiv2:
  Unknown
Status in exiv2 package in Ubuntu:
  Incomplete

Bug description:
  Hello,

  Please consider demoting exiv2 to universe.

  http://dev.exiv2.org/issues/1248

  The upstream author appears overwhelmed with the task of hardening
  exiv2 for use against untrusted inputs and thus far (~nine months) no
  users have provided the project with patches against known issues.

  $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/exiv2/+bug/1706471/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp


[Desktop-packages] [Bug 1706471] Re: please demote exiv2 to universe

2017-07-28 Thread Jeremy Bicha
Thank you for taking the time to report this bug and helping to make
Ubuntu better. The issue you are reporting is an upstream one and it
would be nice if somebody having it could send the bug to the developers
of the software by following the instructions at
https://wiki.ubuntu.com/Bugs/Upstream/GNOME. If you have done so, please
tell us the number of the upstream bug (or the link), so we can add a
bugwatch that will inform us about its status. Thanks in advance.

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to exiv2 in Ubuntu.
https://bugs.launchpad.net/bugs/1706471

Title:
  please demote exiv2 to universe

Status in exiv2 package in Ubuntu:
  Incomplete

Bug description:
  Hello,

  Please consider demoting exiv2 to universe.

  http://dev.exiv2.org/issues/1248

  The upstream author appears overwhelmed with the task of hardening
  exiv2 for use against untrusted inputs and thus far (~nine months) no
  users have provided the project with patches against known issues.

  $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp


[Desktop-packages] [Bug 1706471] Re: please demote exiv2 to universe

2017-07-28 Thread Jeremy Bicha
Yes, but could you file a bug or whatever upstream?

Also, you should probably talk to the Desktop team about your concerns
before asking the Archive Admins to demote a Desktop package.

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to exiv2 in Ubuntu.
https://bugs.launchpad.net/bugs/1706471

Title:
  please demote exiv2 to universe

Status in exiv2 package in Ubuntu:
  Incomplete

Bug description:
  Hello,

  Please consider demoting exiv2 to universe.

  http://dev.exiv2.org/issues/1248

  The upstream author appears overwhelmed with the task of hardening
  exiv2 for use against untrusted inputs and thus far (~nine months) no
  users have provided the project with patches against known issues.

  $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp


[Desktop-packages] [Bug 1706471] Re: please demote exiv2 to universe

2017-07-28 Thread Seth Arnold
I'm not saying it's not useful. The point is that the library that we're
using for Exif metadata is unsuited for use on a modern desktop operating
system or server connected to the Internet.

The maintainer doesn't want to put in the work to take it from a fun
hobby to a production-grade tool. I can understand that, and I'm even
sympathetic that it was used more widely than it should have been. That's
not his fault.

But we have millions of users who expect us to protect them against
drive-by downloads that own their desktops and server administrators
who expect to use the tools we provide to build safe services for their
users in turn.

Ideally shotwell would be able to degrade service gracefully until someone
cares enough to write a safe Exif library. Less ideal would be to demote
shotwell until this is addressed.

Thanks

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to exiv2 in Ubuntu.
https://bugs.launchpad.net/bugs/1706471

Title:
  please demote exiv2 to universe

Status in exiv2 package in Ubuntu:
  Incomplete

Bug description:
  Hello,

  Please consider demoting exiv2 to universe.

  http://dev.exiv2.org/issues/1248

  The upstream author appears overwhelmed with the task of hardening
  exiv2 for use against untrusted inputs and thus far (~nine months) no
  users have provided the project with patches against known issues.

  $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp


[Desktop-packages] [Bug 1706471] Re: please demote exiv2 to universe

2017-07-28 Thread Jeremy Bicha
shotwell doesn't build without libgexiv2-dev.

I assume you're aware that showing Exif information is very useful for a
photo app. Are there any other libraries you suggest instead of exiv2?

Please discuss your concerns with the shotwell and gexiv2 maintainer - I
believe they are the same person. :)

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to exiv2 in Ubuntu.
https://bugs.launchpad.net/bugs/1706471

Title:
  please demote exiv2 to universe

Status in exiv2 package in Ubuntu:
  Incomplete

Bug description:
  Hello,

  Please consider demoting exiv2 to universe.

  http://dev.exiv2.org/issues/1248

  The upstream author appears overwhelmed with the task of hardening
  exiv2 for use against untrusted inputs and thus far (~nine months) no
  users have provided the project with patches against known issues.

  $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp


[Desktop-packages] [Bug 1706471] Re: please demote exiv2 to universe

2017-07-28 Thread Seth Arnold
I certainly hope that shotwell's dependency can be disabled at build
time.

Thanks

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to exiv2 in Ubuntu.
https://bugs.launchpad.net/bugs/1706471

Title:
  please demote exiv2 to universe

Status in exiv2 package in Ubuntu:
  Incomplete

Bug description:
  Hello,

  Please consider demoting exiv2 to universe.

  http://dev.exiv2.org/issues/1248

  The upstream author appears overwhelmed with the task of hardening
  exiv2 for use against untrusted inputs and thus far (~nine months) no
  users have provided the project with patches against known issues.

  $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp


[Desktop-packages] [Bug 1706471] Re: please demote exiv2 to universe

2017-07-28 Thread Jeremy Bicha
shotwell depends on libgexiv2-2 which depends on libexiv2-14

So, um how would you fix that?

** Changed in: exiv2 (Ubuntu)
   Status: New => Incomplete

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to exiv2 in Ubuntu.
https://bugs.launchpad.net/bugs/1706471

Title:
  please demote exiv2 to universe

Status in exiv2 package in Ubuntu:
  Incomplete

Bug description:
  Hello,

  Please consider demoting exiv2 to universe.

  http://dev.exiv2.org/issues/1248

  The upstream author appears overwhelmed with the task of hardening
  exiv2 for use against untrusted inputs and thus far (~nine months) no
  users have provided the project with patches against known issues.

  $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp


[Desktop-packages] [Bug 1706471] Re: please demote exiv2 to universe

2017-07-25 Thread Seth Arnold
** Description changed:

  Hello,
  
  Please consider demoting exiv2 to universe.
  
  http://dev.exiv2.org/issues/1248
  
  The upstream author appears overwhelmed with the task of hardening exiv2
  for use against untrusted inputs and thus far (~nine months) no users
  have provided the project with patches against known issues.
  
- $ reverse-depends src:exiv2
- Reverse-Recommends
- ==
- * geeqie(for exiv2)
- 
+ $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
- * cameraplugin-aal [amd64 arm64 armhf i386]  (for libexiv2-14)
- * darktable [amd64 arm64]   (for libexiv2-14)
- * decopy(for exiv2)
- * digikam-private-libs  (for libexiv2-14)
- * ffdiaporama   (for libexiv2-14)
- * forensics-extra   (for exiv2)
- * gallery-app   (for libexiv2-14)
- * geeqie(for libexiv2-14)
- * gimp-lensfun  (for libexiv2-14)
- * gimp-ufraw(for libexiv2-14)
- * gnome-color-manager   (for libexiv2-14)
- * gnome-commander   (for libexiv2-14)
- * gpscorrelate  (for libexiv2-14)
- * gpscorrelate-gui  (for libexiv2-14)
- * gthumb(for libexiv2-14)
- * gwenview  (for libexiv2-14)
- * hugin (for libexiv2-14)
- * hugin-tools   (for libexiv2-14)
- * kde-runtime   (for libexiv2-14)
- * kio-extras(for libexiv2-14)
- * kphotoalbum   (for libexiv2-14)
- * krename   (for libexiv2-14)
- * krita [amd64 i386 ppc64el s390x]  (for libexiv2-14)
- * libextractor3 (for libexiv2-14)
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)
- * libkexiv2-11v5(for libexiv2-14)
- * libkf5filemetadata-bin(for libexiv2-14)
- * libkf5kexiv2-15.0.0   (for libexiv2-14)
- * libkfilemetadata4 (for libexiv2-14)
- * libmyth-0.28-0(for libexiv2-14)
- * libnomacsloader3  (for libexiv2-14)
- * libstreamanalyzer0v5  (for libexiv2-14)
- * luminance-hdr (for libexiv2-14)
- * merkaartor(for libexiv2-14)
- * pdf2djvu  (for libexiv2-14)
- * phototonic(for libexiv2-14)
- * pinot (for libexiv2-14)
- * python-pyexiv2(for libexiv2-14)
- * qtdeclarative5-ubuntu-ui-extras0.2  (for libexiv2-14)
- * rapid-photo-downloader(for exiv2)
- * ufraw (for libexiv2-14)
- * ufraw-batch   (for libexiv2-14)
- * viewnior  (for libexiv2-14)
  
  Thanks

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to exiv2 in Ubuntu.
https://bugs.launchpad.net/bugs/1706471

Title:
  please demote exiv2 to universe

Status in exiv2 package in Ubuntu:
  New

Bug description:
  Hello,

  Please consider demoting exiv2 to universe.

  http://dev.exiv2.org/issues/1248

  The upstream author appears overwhelmed with the task of hardening
  exiv2 for use against untrusted inputs and thus far (~nine months) no
  users have provided the project with patches against known issues.

  $ reverse-depends -c main -r artful src:exiv2
  Reverse-Depends
  ===
  * libgexiv2-2   (for libexiv2-14)
  * libgexiv2-dev (for libexiv2-dev)

  Thanks

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1706471/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp