Bug#1016986: Should pd-py be removed?

2022-08-10 Thread Moritz Muehlenhoff
Source: pd-py Version: 0.2.2+git20170625.1.88fc77a-2 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2, which is finally being removed in Bookworm - Last upload in 2018 If you disagree and want to continue to maintain this package, please

Bug#1016983: Should k3d be removed?

2022-08-10 Thread Moritz Muehlenhoff
Source: k3d Version: 0.8.0.6-8 Severity: serious Your package came up as a candidate for removal from Debian: - Python 2 will finally be removed in Bookworm and there's no upstream porting activity - Last upload four years ago - Multiple other FTBFS issue If you disagree and want to continue to

Bug#1016139: For Review: Bug#1016139: (net-snmp: CVE-2022-24810 CVE-2022-24809 CVE-2022-24808 CVE-2022-24807 CVE-2022-24806 CVE-2022-24805)

2022-08-10 Thread Moritz Muehlenhoff
On Wed, Aug 10, 2022 at 05:05:12PM +1000, Craig Small wrote: > > Do you have capacity to prepare updates for bullseye? > > > Yes, see attached debdiff for review. It's just those two patches. Looks good, thanks! Please upload to security-master. Cheers, Moritz

Bug#1016845: warn users about insecure webkit* packages

2022-08-08 Thread Moritz Muehlenhoff
On Mon, Aug 08, 2022 at 11:07:16AM +, Holger Levsen wrote: > so, for bookworm, we should add > > - qtwebkit-opensource-src > - qtwebengine-opensource-src > > to security-support-limited ("only for trusted content") and that's it? I think so, yes. Cheers, Moritz

Bug#1016667: Should this package be removed?

2022-08-04 Thread Moritz Muehlenhoff
Source: caldav-tester Version: 7.0+20190225-4 Severity: serious Your package came up as a candidate for removal from Debian: The plan is to remove Python 2 in Bookworm and there's no porting activity towards Python 3. If you disagree and want to continue to maintain this package, please just

Bug#1016666: RM: iotjs -- RoQA; unmaintained, open security issues, depends on Python 2

2022-08-04 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal See #1011124 Cheers, Moritz

Bug#1016665: RM: gspiceui -- RoQA; Blocks removal of geda-gaf, unmaintained

2022-08-04 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove gspiceui. It blocks the removal of geda-gaf (#1008700) and #967915 hasn't seen maintainer action since two years. Cheers, Moritz

Bug#1016664: RM: easyspice -- RoQA; depends on geda-gaf which is being removed

2022-08-04 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove easyspice. It blocks the removal of geda-gaf (#1008700) and #967916 hasn't seen a reply in two years. Cheers, Moritz

Bug#1014764: closed by Hilko Bengen (Re: Bug#1014764: guestfs-tools: CVE-2022-2211)g

2022-07-28 Thread Moritz Muehlenhoff
reopen 1014764 thanks On Thu, Jul 28, 2022 at 07:51:03AM +, Debian Bug Tracking System wrote: > This is an automatic notification regarding your Bug report > which was filed against the src:guestfs-tools package: > > #1014764: guestfs-tools: CVE-2022-2211 > > It has been closed by Hilko

Bug#1015981: Should grokmirror be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: grokmirror Version: 1.0.0-1.1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Last maintainer upload in 2016 If you disagree and want to continue to maintain this package, please just close this bug (and fix the open issues).

Bug#1015980: Should pd-aubio be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: pd-aubio Version: 0.4-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Last upload in 2014 If you disagree and want to continue to maintain this package, please just close this bug (and fix the open issues). If you agree with

Bug#1015979: Should python-unshare be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: python-unshare Version: 0.2-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Last upload in 2016 If you disagree and want to continue to maintain this package, please just close this bug (and fix the open issues). If you

Bug#1015978: Should falcon be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: falcon Version: 1.8.8-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Dropped from testing in 2018 - Last upload in 2017 If you disagree and want to continue to maintain this package, please just close this bug (and fix the

Bug#1015977: Should vland be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: vland Version: 0.8-1 Severity: serious Your package came up as a candidate for removal from Debian, it's one of the few remaining packages still depending on Python 2 and there're no visible upstream activity to port it to vland? If you disagree and want to continue to maintain this

Bug#1015976: Should vmm be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: vmm Version: 0.6.2-2 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Last upload in 2017, removed from testing since 2019 If you disagree and want to continue to maintain this package, please just close this bug (and fix the

Bug#1015975: Should python-neuroshare be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: python-neuroshare Version: 0.9.2-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Last upload in 2014 - Dead upstream (last commits from 2016) If you disagree and want to continue to maintain this package, please just close

Bug#1015974: Should gnat-gps be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: gnat-gps Version: 19.2-3 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Removed from testing since 2019 If you disagree and want to continue to maintain this package, please just close this bug (and fix the open issues). If

Bug#1015973: Should xdeb be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: xdeb Version: 0.6.7 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - No upload since five years If you disagree and want to continue to maintain this package, please just close this bug (and fix the open issues). If you agree

Bug#1014533: php8.1: CVE-2022-31625 CVE-2022-31626

2022-07-07 Thread Moritz Muehlenhoff
Hi Ondřej, On Thu, Jul 07, 2022 at 05:57:24PM +0200, Ondřej Surý wrote: > Hi, > > thanks for the poke. > > Would it be also ok to do the php7.4 via bullseye-security or do you > want me specifically to do the stable-updates? The two issues are not the most severe, but we can do a DSA. I'll

Bug#1013343: dbus-broker: CVE-2022-31212

2022-06-23 Thread Moritz Muehlenhoff
On Thu, Jun 23, 2022 at 07:24:50AM +0200, Salvatore Bonaccorso wrote: > > Gut feeling, to me this looks something which can be fixed in the > upcoming point release but would not need a DSA. Will leave the final > decision on it though to Moritz. Agreed, I don't think we need a DSA here, this is

Bug#1013278: RM: nvtv -- RoQA; Dead upstream, RC buggy, unmaintained

2022-06-20 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove nvtv. The last maintainer upload happened a decade ago, it's dead upstream and RC-buggy. Cheers, Moritz

Bug#1013274: RM: w3-recs -- RoQA; Obsolete

2022-06-20 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove w3-recs. It contains an 11 year old summary of World Wide Web Consortium (W3C) recommendations, which are obsolete by now. And the package is orphaned since six years. Cheers, Moritz

Bug#1013266: RM: golang-github-blevesearch-bleve -- RoQA; Obsolete, orphaned, outdated

2022-06-20 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove golang-github-blevesearch-bleve. The version in the archive is five years old and there are no reverse deps (it was added for Gitea, which is no longer shipped). Cheers, Moritz

Bug#1012513: apache2: CVE-2022-31813 CVE-2022-26377 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30522 CVE-2022-30556

2022-06-08 Thread Moritz Muehlenhoff
On Wed, Jun 08, 2022 at 07:51:28PM +0200, Yadd wrote: > Hi, > > those CVEs are tagged low/moderate by upstream, why did you tag this bug as > grave ? Anything moderate or above should get fixed by the next Debian release IOW RC severity. Cheers, Moritz

Bug#1012332: RM: pluxml -- RoQA; unmaintained, open security issues

2022-06-04 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove pluxml. The last upload was in 2018 and there's plenty of open/unfixed security vulnerabilities. Cheers, Moritz

Bug#1012138: CVE-2021-40426

2022-05-30 Thread Moritz Muehlenhoff
Source: sox Version: 14.4.2+git20190427-3 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team https://talosintelligence.com/vulnerability_reports/TALOS-2021-1434 The report states that upstream was notified, but we need to figure out whether this was addressed by upstream already

Bug#1011954: CVE-2022-1586 CVE-2022-1587

2022-05-27 Thread Moritz Muehlenhoff
Source: pcre2 Version: 10.36-2 Severity: important Tags: security X-Debbugs-Cc: Debian Security Team CVE-2022-1587 https://github.com/PCRE2Project/pcre2/commit/03654e751e7f0700693526b67dfcadda6b42c9d0 CVE-2022-1586

Bug#1010671: libsdl2-ttf-dev: CVE-2022-27470 - Arbitrary memory overwrite loading glyphs and rendering text

2022-05-09 Thread Moritz Muehlenhoff
On Mon, May 09, 2022 at 12:59:42PM +0100, Simon McVittie wrote: > If I'm understanding the issue correctly, it's only a problem if a user > of SDL_ttf is using an untrusted TTF font file, which is a relatively > unusual thing to do: normally games either rely on system fonts, or bundle > a font in

Bug#1010626: RM: dpatch -- RoQA; obsolete

2022-05-05 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove dpatch. It has been obsoleted by source format 3.0/quilt Please force the removal, there are still 10 remaining build deps, but they are all dropped from testing, have RC bugs and are generally unmaintained (no maintainer uploads since at

Bug#1010264: CVE-2022-28391

2022-04-28 Thread Moritz Muehlenhoff
On Wed, Apr 27, 2022 at 11:29:00PM -0400, Theodore Ts'o wrote: > Neither seems to be security related. Are you sure this was correctly > filed against e2fsprogs? Apologies, I reported multiple incoming new issues from the CVE feed and I must have mis-pasted the wrong Emacs buffer into the

Bug#1010265: CVE-2022-28805

2022-04-27 Thread Moritz Muehlenhoff
Package: lua5.4 Version: 5.4.4-1 Severity: important Tags: security X-Debbugs-Cc: Debian Security Team This was assigned CVE-2022-28805: https://github.com/lua/lua/commit/1f3c6f4534c6411313361697d98d1145a1f030fa http://lua-users.org/lists/lua-l/2022-02/msg1.html

Bug#1010264: CVE-2022-28391

2022-04-27 Thread Moritz Muehlenhoff
Package: e2fsprogs Version: 1.46.5-2 Severity: important This issue was found by Alpine: https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661 Details and the patches they used are in the report above, but the patches are not yet merged upstream, might be worth to wait until that's fixed

Bug#1010263: CVE-2022-1304

2022-04-27 Thread Moritz Muehlenhoff
Package: e2fsprogs Version: 1.46.5-2 Severity: important Tags: security X-Debbugs-Cc: Debian Security Team This was assigned CVE-2022-1304, originally reported to Red Hat: https://bugzilla.redhat.com/show_bug.cgi?id=2069726 https://bugzilla.redhat.com/show_bug.cgi?id=2068113 Patch (not yet

Bug#1009932: RM: gjots2 -- RoQA; Depends on Python 2, unmaintained

2022-04-20 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove gjots2. It still depends on Python 2 and is thus removed from testing since 2019, the last maintainer upload dates back to 2018. Cheers, Moritz

Bug#1009929: RM: lxmms2 -- RoQA; Depends on xmms2, which is going away

2022-04-20 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove lxmms2. It's a wrapper around xmms2, which itself is dead upstream ad incompatible with ffmpeg 5 and will be removed from bookworm (and eventually the archive). Cheers, Moritz

Bug#1009930: Drop Suggests on xmms2

2022-04-20 Thread Moritz Muehlenhoff
Source: playerctl Version: 2.4.1-1 Severity: normal Hi, please remove the Suggests: on xmms2. It will not be part of bookworm (#1005902) and eventually removed from the archive. Cheers, Moritz

Bug#1009335: RM: python-keepkey -- RoQA; Depends on Python 2

2022-04-11 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: ri...@paraeasy.ch Please remove python-keepkey. The version currently in the archive is very old and still depends on Python 2. Removal acked by the maintainer in #1009273 Cheers, Moritz

Bug#1009282: Should live-wrapper be removed?

2022-04-10 Thread Moritz Muehlenhoff
Source: live-wrapper Version: 0.10 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Depends on vmdebootstrap which was removed - It's not included in Bullseye, but we did release live images so

Bug#1009281: Should cinfony be removed?

2022-04-10 Thread Moritz Muehlenhoff
Source: cinfony Version: 1.2-4 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Dead upstream - No reverse dependencies If you disagree and want to continue to maintain this package, please just

Bug#1009280: Should python-passfd be removed?

2022-04-10 Thread Moritz Muehlenhoff
Source: python-passfd Version: 0.2-3 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2020 - No reverse dependencies - Last upload in 2016 If you disagree and want to continue to maintain this package,

Bug#1009276: Should fsl be removed?

2022-04-10 Thread Moritz Muehlenhoff
Source: fsl Version: 5.0.8-6 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since two years - Also FTBFSes with GCC 10 - Last upload in 2019 If you disagree and want to continue to maintain this package,

Bug#1009273: Should python-keepkey be removed?

2022-04-10 Thread Moritz Muehlenhoff
Source: python-keepkey Version: 0.7.3-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Last upload back in 2016 If you disagree and want to continue to maintain this package, please just close

Bug#1009269: Should sphinx-patchqueue be removed?

2022-04-10 Thread Moritz Muehlenhoff
Source: sphinx-patchqueue Version: 0.5.0-2 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - No remaining reverse dependencies - Last upload in 2015 If you disagree and want to continue to

Bug#1008920: Versions table not rebuilt after latest Buster 10.2 point release

2022-04-04 Thread Moritz Muehlenhoff
Package: tracker.debian.org Severity: normal The last point release for buster updated various packages. The packages updated as part of the release are showing up under "news", but the respective versions are not updated in the "versions" table on the left. And likewise for "versioned links".

Bug#1008792: Should vmtk be removed?

2022-04-01 Thread Moritz Muehlenhoff
Source: vmtk Version: 1.3+dfsg-2.3 Severity: serious Your package came up as a candidate for removal from Debian: - Depends on Python 2 and thus removed from testing since 2019 (current upstream 1.4 is fixed, though) - Last maintainer upload in 2016 If you disagree and want to continue to

Bug#1008791: Should googlefontdirectory-tools be removed?

2022-04-01 Thread Moritz Muehlenhoff
Source: googlefontdirectory-tools Version: 20120309.1-1.1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Last maintainer upload in 2015 If you disagree and want to continue to maintain this

Bug#1008704: Sould astk be removed?

2022-03-30 Thread Moritz Muehlenhoff
Source: astk Version: 1.13.1-2.1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Last maintainer upload in 2014 If you disagree and want to continue to maintain this package, please just close

Bug#1008703: Should sortsmill-tools be removed?

2022-03-30 Thread Moritz Muehlenhoff
Source: sortsmill-tools Version: 0.4-2 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python and thus removed from testing since 2019 - Last upload in 2013 If you disagree and want to continue to maintain this package, please just close this

Bug#1008702: Should ketchup be removed?

2022-03-30 Thread Moritz Muehlenhoff
Source: ketchup Version: 1.0.1+git20111228+e1c62066-2 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Last upload in 2017 - Seems dead upstream (last commit from eight years ago) - Per #946203

Bug#1008701: Should broctl be removed?

2022-03-30 Thread Moritz Muehlenhoff
Source: broctl Version: 1.4-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still uses Python 2.7 and thus removed from testing since 2019 - Last upload in 2015 If you disagree and want to continue to maintain this package, please just close this bug (and fix

Bug#1008700: Should geda-gaf be removed?

2022-03-30 Thread Moritz Muehlenhoff
Source: geda-gaf Version: 1:1.8.2-11 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Also uses outdated Guile - Last upload in 2018 If you disagree and want to continue to maintain this

Bug#1008500: Should undertaker be removed?

2022-03-27 Thread Moritz Muehlenhoff
Source: undertaker Version: 1.6.1-4.2 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Last maintainer upload in 2016 If you disagree and want to continue to maintain this package, please just

Bug#1008499: Should neard be removed?

2022-03-27 Thread Moritz Muehlenhoff
Source: neard Version: 0.16-0.1 Severity: serious Your package came up as a candidate for removal from Debian: - Last maintainer upload in 2013 - Depends on Python 2 and thus removed from testing since 2019 If you disagree and want to continue to maintain this package, please just close this

Bug#1008498: Should hgsubversion be removed?

2022-03-27 Thread Moritz Muehlenhoff
Source: hgsubversion Version: 1.9.3+git20190419+6a6ce-5 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and removed from testing since 2020 - Dead upstream (no commits after 2019) If you disagree and want to continue to maintain this

Bug#1008286: Should nglister be removed?

2022-03-25 Thread Moritz Muehlenhoff
Source: nglister Version: 1.0.2 Severity: serious Your package came up as a candidate for removal from Debian: - Last upload in 2016 - Removed from testing since 2019 - Multiple RC bugs If you disagree and want to continue to maintain this package, please just close this bug (and

Bug#1008285: Should zorp be removed?

2022-03-25 Thread Moritz Muehlenhoff
Source: zorp Version: 7.0.1~alpha2-3 Severity: serious Your package came up as a candidate for removal from Debian: - Last upload in 2019, removed from testing since 2017 - Still depends on Python 2.7 and thus RC-buggy If you disagree and want to continue to maintain this package, please just

Bug#1008273: Should python-nemu be removed?

2022-03-25 Thread Moritz Muehlenhoff
Source: python-nemu Version: 0.3.1-1 Severity: serious Your package came up as a candidate for removal from Debian: - Last upload in 2016 and dropped from testing in 2019 - Still uses Python 2.7 and not fixed upstream either If you disagree and want to continue to maintain this package, please

Bug#1008274: Should sandsifter be removed?

2022-03-25 Thread Moritz Muehlenhoff
Source: sandsifter Version: 1.04-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still uses Python 2.7 and thus RC buggy - Last upload in 2019 and not in testing since 2019 If you disagree and want to continue to maintain this package, please just close this

Bug#1008272: Should postnews be removed?

2022-03-25 Thread Moritz Muehlenhoff
Source: postnews Version: 0.7-1 Severity: serious Your package came up as a candidate for removal from Debian: - Removed from testing for ~ two years, no followup to RC bugs - Also no changes upstream since 2017 If you disagree and want to continue to maintain this package, please just close

Bug#1008271: Should arriero be removed?

2022-03-25 Thread Moritz Muehlenhoff
Source: arriero Version: 0.6-1 Severity: serious Your package came up as a candidate for removal from Debian: - Last upload in 2017 - Still uses Python 2.7 and thus RC buggy - Missed the last two stable releases and removed from testing since 2018 If you disagree and want to continue to

Bug#1008265: CVE-2018-25032: zlib memory corruption on deflate

2022-03-25 Thread Moritz Muehlenhoff
Source: zlib Version: 1:1.2.11.dfsg-2 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team This was assigned CVE-2018-25032: https://www.openwall.com/lists/oss-security/2022/03/24/1 https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531 Cheers,

Bug#1008264: Multiple security issues

2022-03-25 Thread Moritz Muehlenhoff
Source: pluxml Version: 5.6-1 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team CVE-2022-25020: https://github.com/MoritzHuppert/CVE-2022-25020/blob/main/CVE-2022-25020.pdf CVE-2022-25018: https://github.com/MoritzHuppert/CVE-2022-25018/blob/main/CVE-2022-25018.pdf

Bug#1008071: RM: xcal -- RoQA; unmaintained, RC-buggy

2022-03-21 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove xcal. It's dead upstream, unmaintained (last upload in 2008) and there's three RC bugs. Cheers, Moritz

Bug#1008070: RM: bopm -- RoQA; unmaintained, RC-buggy, alternatives exist

2022-03-21 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove bopm. It's unmaintained (last upload a decade ago), RC buggy, dead upstream and a maintained fork (hopm) is in the archive. Cheers, Moritz

Bug#1007931: buster-pu: package qemu/1:3.1+dfsg-8+deb10u9

2022-03-18 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: m...@tls.msk.ru Various low severity qemu issues, but since quite a few of those have piled up, it makes sense to move to an update. Debdiff below. Cheers,

Bug#1007920: buster-pu: package flac/1.3.3-2+deb11u1

2022-03-18 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: fab...@debian.org Fixes a minor security issue, debdiff below (and was just uploaded). Tested with a few sample files. Cheers, Moritz diff -Nru

Bug#1005981: Please migrate away from dpatch

2022-02-19 Thread Moritz Muehlenhoff
On Fri, Feb 18, 2022 at 02:41:57PM -0800, Bill Poser wrote: > I am the developer of redet. I don't understand this bug report. redet does > not use anything called dpatch so far as I know. Is this something added in > the Debianization of redet downstream from me? Yes, exactly. It's a legacy

Bug#1005988: Don't release with bookworm

2022-02-18 Thread Moritz Muehlenhoff
Source: dpatch Version: 2.0.41 Severity: serious dpatch has been obsoleted by source format 3.0 (quilt), there's only 19 reverse dependencies in the archive (5 of them in testing), for which bugs have been filed. Cheers, Moritz

Bug#1005987: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: mgetty Version: 1.2.1-1.1 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005985: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: scim-skk Version: 0.5.2-7.2 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005986: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: dvbsnoop Version: 1.4.50-5 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005984: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: scim-canna Version: 1.0.0-4.3 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005983: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: myspell Version: 1:3.0+pre3.1-24.2 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005982: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: elscreen Version: 1.4.6-5.3 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005980: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: syrep Version: 0.9-4.3 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005981: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: redet Version: 8.26-1.4 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005979: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: efax Version: 1:0.9a-20 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005978: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: vdk2 Version: 2.4.0-5.5 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1004963: CVE-2020-21598 CVE-2020-21600 CVE-2020-21602

2022-02-04 Thread Moritz Muehlenhoff
Source: libde265 Version: 1.0.8-1 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team CVE-2020-21602: https://github.com/strukturag/libde265/issues/242 CVE-2020-21600: https://github.com/strukturag/libde265/issues/243 CVE-2020-21598:

Bug#1004933: RM: gif2apng -- RoQA; dead upstream, open security issues

2022-02-03 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove gif2apng, it's dead upstream and has open security issues Cheers, Moritz

Bug#1004293: warn users that src:webkit2gtk and src:khtml are insecure?

2022-01-24 Thread Moritz Muehlenhoff
On Tue, Jan 25, 2022 at 12:20:46AM +1100, Trent W. Buck wrote: > Package: debian-security-support > Version: 1:11+2021.03.19 > Severity: normal > File: /usr/share/debian-security-support/security-support-limited > > As at Debian 11, > > * webkitgtk is in src:webkit2gtk, not src:webkit. > *

Bug#1003662: Update homepage header

2022-01-13 Thread Moritz Muehlenhoff
Source: libsixel Version: 1.8.6-2 Severity: normal It seems that since 1.10.3-1 the Debian package moved from https://github.com/saitoha/libsixel to https://github.com/libsixel/libsixel , right? If so please update the Homepage: entry in debian/control so the new site properly shows up in

Bug#1003410: RM: flexbackup -- RoQA; unmaintained, dead upstream, RC-buggy

2022-01-09 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove flexbackup. It's dead upstream (last release from 2003), unmaintained (last maintainer upload in 2008, orphaned without an adopter since 2012) and currently RC-buggy. Plenty of alternatives exist. Cheers, Moritz

Bug#1003409: RM: xxgdb -- RoQA; dead upstream, unmaintained, alternatives exist

2022-01-09 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove xxgdb. It's dead upstream, unmaintained (last upload in 2010 and orphaned without an adopter since 2019) and alternatives like ddd exist. Cheers, Moritz

Bug#1003149: Still declares some Py2 build deps

2022-01-04 Thread Moritz Muehlenhoff
Source: topydo Version: 0.14-5 Severity: important topydo uses Python 3, but there are still two Python 2 build deps: python-all and python-setuptools. Cheers, Moritz

Bug#995212: chromium: Update to version 94.0.4606.61 (security-fixes)

2022-01-02 Thread Moritz Muehlenhoff
On Sat, Jan 01, 2022 at 01:23:09PM -0500, Andres Salomon wrote: > How should I handle this? NMU to sid, let people try it out, and then > deal with buster/bullseye? Yeah, let's proceed with unstable first in any case. > Upload everything all at once? I'm also > going to try building for buster,

Bug#995212: chromium: Update to version 94.0.4606.61 (security-fixes)

2022-01-02 Thread Moritz Muehlenhoff
On Sun, Jan 02, 2022 at 06:53:51PM +0100, Mattia Rizzolo wrote: > Correlated, do you know how long do they plan on keeping using python2? > That's plainly unsuitable, it really is not going to last much longer in > debian. Current state of the Python 3 upstream migration can be found here:

Bug#995212: chromium: Update to version 94.0.4606.61 (security-fixes)

2021-12-13 Thread Moritz Muehlenhoff
On Sun, Dec 12, 2021 at 08:11:00PM -0500, Andres Salomon wrote: > On 12/5/21 6:41 AM, Moritz Mühlenhoff wrote: > > Am Sun, Dec 05, 2021 at 10:53:56AM +0100 schrieb Paul Gevers: > > Exactly that. > > > > I'd suggest anyone who's interested in seeing Chromium supported to first > > update it in

Bug#1000906: RM: bareos -- RoQA; Really RC-buggy, unmaintained

2021-11-30 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove bareos. It has nine open RC bugs, the last maintainer upload was in Feb 2019 and there was no objection to my removal proposal at #995837 for two months. Cheers, Moritz

Bug#1000904: RM: pycalendar -- RoQA; Depends on Python 2, dead upstream, unmaintained

2021-11-30 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove pycalendar. It depends on Python 2, is dead upstream (upstream issue for Py3 support is open since 2017 without action), there are no reverse dependencies (just a Recommends: by caldav-tester, but it's dropped from testing since a year for

Bug#1000902: RM: python-mode -- RoQA; orphaned, RC-buggy

2021-11-30 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove python-mode. It's RC-buggy (missed Bullseye, dropped from testing for > 15 months) and orphaned without an adopter since Sep 2020. Cheers, Moritz

Bug#1000479: buster-pu: package jtreg/5.1-b01-2~deb10u1

2021-11-23 Thread Moritz Muehlenhoff
@@ +jtreg (5.1-b01-2~deb10u1) buster; urgency=medium + + * Rebuild for buster, needed for latest OpenJDK 11.x release +- Switch to debhelper 12 + + -- Moritz Muehlenhoff Fri, 19 Nov 2021 16:26:05 + + jtreg (5.1-b01-2) unstable; urgency=medium * Team upload. diff -Nru jtreg-5.1-b01/debian

Bug#1000480: buster-pu: package jtharness/6.0-b15-1~deb10u1

2021-11-23 Thread Moritz Muehlenhoff
@@ +jtharness (6.0-b15-1~deb10u1) buster; urgency=medium + + * Rebuild for buster, needed for latest OpenJDK 11.x release +- Switch to debhelper 12 + + -- Moritz Muehlenhoff Fri, 19 Nov 2021 16:17:12 + + jtharness (6.0-b15-1) unstable; urgency=medium * Team upload. diff -Nru

Bug#998659: RM: residualvm -- ROM; Obsolete, merged into src:scummvm

2021-11-05 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: only...@debian.org Please remove residualvm. It got merged into ScummVM 2.5.0, which is now in unstable: https://www.scummvm.org/news/20211009/ Removal also acked by Dmitry (CCed) Cheers, Moritz

Bug#998277: RM: opencaster -- RoQA; Depends on Python 2, dead upstream

2021-11-01 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove opencaster. It depends on Python 2 and is dead upstream. Removal was acked by Thorsten in #937194. Cheers, Moritz

Bug#998276: RM: libvirt-sandbox -- RoQA; Depends on Python 2, dead upstream

2021-11-01 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: a...@sigxcpu.org Please remove libvirt-sandbox. It depends on Python 2 and is dead upstream. Removal was acked by Guido. Cheers, Moritz

Bug#996650: RM: citadel -- RoQA; Orphaned, RC buggy

2021-10-16 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove citadel. It's orphaned for over two years without an adopter and removed from testing since years since the current package is broken (939377). In addition there's open security issues. Cheers, Moritz

Bug#995845: RM: openopt -- RoQA; Depends on Python 2

2021-10-06 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: deb...@onerussian.com Please remove openopt. It depends on Python 2 and is dead upstream. Acked by the maintainer (CCed) in #937209. Cheers, Moritz

Bug#995838: Should condor be removed?

2021-10-06 Thread Moritz Muehlenhoff
Source: condor Severity: serious condor came up as a candidate for removal from Debian: - Last upload was in 2018 - Three RC bugs, including various toolchain issues (GCC, Python 2) - Open security issues If you disagree and want to continue to maintain this package, please just close this bug

Bug#995837: Should bareos be removed?

2021-10-06 Thread Moritz Muehlenhoff
Package: bareos Severity: serious Your package came up as a candidate for removal from Debian: Bareos hasn't seen an upload since 2019, missed Bullseye and has a total of 8 RC bugs at this point. If you disagree and want to continue to maintain this package, please just close this bug (and fix

<    1   2   3   4   5   6   7   8   9   10   >