Bug#981474: node-rollup-plugin-terser: test randomly fails due to timeout problems

2021-01-31 Thread Xavier Guimard
Package: node-rollup-plugin-terser Version: 7.0.2-4 Severity: serious Tags: ftbfs Justification: Policy 2.1 https://ci.debian.net/packages/n/node-rollup-plugin-terser/testing/amd64/ shows that node-rollup-plugin-terser test randomly fails

Bug#981279: lintian: False positive: pkg-js-autopkgtest-file-does-not-exist packages/*/test

2021-01-28 Thread Xavier Guimard
Package: lintian Version: 2.104.0 Severity: normal X-Debbugs-Cc: pkg-javascript-de...@lists.alioth.debian.org Hi, lintian looks enable to understand `packages/*/test` expression when trying to verify that files declared in debian/tests/pkg-js/files exist.

Bug#981222: update-alternatives: please provide a way to change a master alternative into a slave one

2021-01-27 Thread Xavier Guimard
Package: dpkg Version: 1.20.7.1 Severity: normal Hi, I made an error using master alternatives to install some manpages, but I can't change this because update-alternatives refuse to replace a master alternative into a slave one during upgrade. Could you provide a way to do this in

Bug#980805: RM: node-express-generator -- ROM; RC buggy and useless

2021-01-22 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, node-express-generator isn't compatible with current node-commander and node-mkdirp. It has no reverse dependencies, so I thinks it should be removed from Debian.

Bug#980259: buster-pu: package cyrus-imapd/3.0.8-6+deb10u5

2021-01-16 Thread Xavier Guimard
) [ Changes ] Regex fix Cheers, Xavier diff --git a/debian/changelog b/debian/changelog index c96adf9c..240d1f4d 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,9 @@ +cyrus-imapd (3.0.8-6+deb10u5) buster; urgency=medium + + * Fix cron script (Closes: #980240) + + -- Xavier Guimard Sat

Bug#980032: RM: node-request/2.88.1-5

2021-01-13 Thread Xavier Guimard
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm X-Debbugs-Cc: pkg-javascript-de...@lists.alioth.debian.org Hi, node-request is deprecated (#956423) and won't be part of Bullseye. I'd like to see it removed from testing after node-jsdom

Bug#980012: FTBFS: TypeError: Cannot read property 'register' of undefined

2021-01-12 Thread Xavier Guimard
Package: coffeescript Version: 1.12.8~dfsg-4 Severity: serious coffeescript build seems broken. Logs: dpkg-source -b . dpkg-source: info: using source format '3.0 (quilt)' dpkg-source: info: building coffeescript using existing ./coffeescript_1.12.8~dfsg.orig.tar.gz dpkg-source: info: using

Bug#979874: node-cross-spawn-async: Keep out of testing

2021-01-12 Thread Xavier Guimard
Package: node-cross-spawn-async Version: 2.2.5-4 Severity: serious As node-cross-spawn, node-cross-spawn-async shoul d be kept out of Bullseye

Bug#979587: ITP: ts-jest -- Node.js preprocessor with source maps support to help use TypeScript with Jest

2021-01-08 Thread Xavier Guimard
Package: wnpp Severity: wishlist Owner: Xavier Guimard X-Debbugs-Cc: debian-de...@lists.debian.org, pkg-javascript-de...@lists.alioth.debian.org * Package name: ts-jest Version : 26.4.4 Upstream Author : Kulshekhar Kabra <https://github.com/kulshekhar> * URL :

Bug#979553: node-vinyl-fs: Please ship typescript definitions

2021-01-08 Thread Xavier Guimard
Package: node-vinyl-fs Version: 3.0.3-5 Severity: normal Please embed typescript definitions

Bug#979475: node-gyp-build: Keep out of testing

2021-01-06 Thread Xavier Guimard
Package: node-gyp-build Severity: serious Justification: Policy 2.1 node-gyp-rebuild replaces `node-gyp rebuild` using pre-compiled binaries. This is useless in Debian. I did an error when packaging it, this package should be removed from Debian archive, shouldn't it?

Bug#979457: RM: node-babel-preset-env -- ROM; Useless and replaced by node-babel7

2021-01-06 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: pkg-javascript-de...@lists.alioth.debian.org Hi, all reverse dependencies to node-babel-preset-env have been updated to use node-babel7 (or virtual "node-babel-preset-env ≥ 7"), so this package can now be safely removed from Debian archive.

Bug#979174: node-express-generator: Incompatible with current node-commander and node-mkdirp

2021-01-03 Thread Xavier Guimard
Package: node-express-generator Version: 4.0.0-2 Severity: grave Tags: sid, ftbfs Justification: renders package unusable node-express-generator isn't compatible with current node-commander, neither node-mkdirp. As it has no reverse dependency, I suggest to remove it from Debian

Bug#978418: RM: node-cross-spawn-async -- ROM; Useless and FTBFS

2020-12-27 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, like node-cross-spawn (already removed), node-cross-spawn-async is useless in Debian ad should be removed. It has no reverse dependencies. Cheers, Xavier

Bug#978051: node-consolidate depends on babel-core 6

2020-12-25 Thread Xavier Guimard
Package: node-consolidate Version: 0.15.1+repack-1 Severity: serious Enabling test proves that node-consolidate depends on node-babel-core 6: ``` function requireReact(module, filename) { var babel = requires.babel || (requires.babel = require('babel-core')); var compiled =

Bug#977963: node-terser: Please fix test to be compatible with node-commander ≥ 6

2020-12-23 Thread Xavier Guimard
Package: node-terser Version: 4.1.2-7 Severity: important Tags: patch With commander 6, uglifyjs.terser displays: Usage: uglifyjs [options]... instead of: Usage: uglifyjs.terser [options]... The simple attached patch fixes test check with a more tolerant regex. Please apply this patch if

Bug#977886: RM: node-samsam -- ROM; Obsolete, replaced by node-sinonjs-samsam

2020-12-22 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: pkg-javascript-de...@lists.alioth.debian.org Hi, node-samsam is deprecated. It is now @sinonjs/samsam (node-sinonjs-samsam) which is part of node-sinon. node-samsam has no reverse dependencies, it should be removed from Debian archive.

Bug#977864: libjs-bootstrap4: Missing maintscript blocks upgrade

2020-12-21 Thread Xavier Guimard
Package: libjs-bootstrap4 Version: 4.5.2+dfsg1-3 Severity: serious Version 4.5.2+dfsg1-2 transform /usr/share/javascript/bootstrap4 from symlink to dir without any maintscript. This break updates.

Bug#977735: buster-pu: package node-ini/1.3.5-1+deb10u1

2020-12-19 Thread Xavier Guimard
@@ -1,3 +1,11 @@ +node-ini (1.3.5-1+deb10u1) buster; urgency=medium + + * Team upload + * Do not allow invalid hazardous string as section name +(Closes: #977718, CVE-2020-7788) + + -- Xavier Guimard Sat, 19 Dec 2020 20:48:36 +0100 + node-ini (1.3.5-1) unstable; urgency=medium * Team Upload

Bug#977712: RM: node-jsv -- ROM; Unmaintained and orphaned

2020-12-19 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: pkg-javascript-de...@lists.alioth.debian.org node-jsv isn't maintained upstream for 8 years, useless and unmaintained in Debian. It has no reverse dependencies and could be safely removed.

Bug#977710: libjs-milligram is not maintained by JS Team

2020-12-19 Thread Xavier Guimard
Package: libjs-milligram Severity: serious Tags: security libjs-milligram is marked as maintained by JS Team, howeber uploader is not member of this team and repository isn't under /js-team/ tree.

Bug#977677: FTBFS: dependency to node-babel-runtime >=7 isn't understood by deb tools

2020-12-18 Thread Xavier Guimard
Package: node-regenerator-transform Version: 0.14.5-2 Severity: serious Tags: ftbfs Since 0.14.5-2, dependency to node-babel7 was replaced by a dependency to node-babel-runtime (>= 7) which is provided by: * node-babel-runtime (src node-babel 6) * virtual node-babel-runtime provided by

Bug#977472: ITP: node-gyp-build -- Node.js build tool and bindings loader that supports prebuilds

2020-12-15 Thread Xavier Guimard
Package: wnpp Severity: wishlist Owner: Xavier Guimard X-Debbugs-Cc: debian-de...@lists.debian.org, pkg-javascript-de...@lists.alioth.debian.org * Package name: node-gyp-build Version : 4.2.3 Upstream Author : Mathias Buus * URL : https://github.com/prebuild/node

Bug#977269: node-rollup-plugin-terser seems incompatible with current node-terser

2020-12-13 Thread Xavier Guimard
Package: node-rollup-plugin-terser Version: 7.0.2-2 Severity: grave Justification: renders package unusable When trying current rollup-plugin-terser (7.0.2) with current node-terser (4.1.2), package is unuseable: $ rollup -c index.js → dist/pako.js, dist/pako.min.js... [!] (plugin terser)

Bug#976955: FTBFS: semver not found

2020-12-09 Thread Xavier Guimard
Package: ts-node Version: 9.0.0-1 Severity: serious Tags: ftbfs Here is the relevant part of build log: make[1]: Entering directory '/<>' tsc src/index.spec.ts(4,25): error TS2307: Cannot find module 'semver' or its corresponding type declarations. make[1]: *** [debian/rules:7:

Bug#976839: node-istanbul: @types/istanbul-lib-instrument depends on deprecated babel-types

2020-12-08 Thread Xavier Guimard
Package: node-istanbul Version: 0.4.5+ds+~cs53.14.45-1 Severity: important babel-types should be replaced by @babel/types

Bug#976713: RM: node-formatio -- ROM; Useless and unmaintained upstream

2020-12-07 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: pkg-javascript-de...@lists.alioth.debian.org Hi, node-formatio isn't maintained upstream [1]: it has been replaced by @sinonjs/formatio which is included in node-sinon. No package depend on it, so I think it should be removed from Debian

Bug#976392: buster-pu: package node-y18n/3.2.1-2+deb10u1

2020-12-04 Thread Xavier Guimard
+ + * Team upload. + * Fix prototype pollution (Closes: #976390, CVE-2020-7774) + + -- Xavier Guimard Fri, 04 Dec 2020 15:41:08 +0100 + node-y18n (3.2.1-2) unstable; urgency=medium * Enable tests diff --git a/debian/patches/CVE-2020-7774.patch b/debian/patches/CVE-2020-7774.patch new file

Bug#976262: RM: node-htmlparser -- ROM; Useless and deprecated

2020-12-02 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, node-htmlparser has been deprecated in favor of node-htmlparser2. It is no more maintained upstream and here and has no reverse dependencies. Cheers, Xavier

Bug#976197: RM: node-databank -- ROM; Unmaintained and useless

2020-12-01 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, node-databank is unmaintained in Debian for a while and useless: no reverse dependency, popcon ~0,... I think it should be removed from Debian. Cheers, Xavier

Bug#976186: node-backbone: Please provides typescript definition

2020-11-30 Thread Xavier Guimard
Package: node-backbone Version: 1.3.3~dfsg-5 Severity: important node-typescript-types is deprecated, please embed @types/backbone in node-backbone.

Bug#975952: RM: node-libnpx -- ROM; No more used, npx is provided by npm

2020-11-27 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, npx is provided by npm, this old library is: * no more used in Debian * orphaned upstream (npm integrated it directly) I thinks it should be removed from Debian. Cheers, Xavier

Bug#975942: RM: node-cross-spawn -- ROM; unneeded for Debian, does risky path mangling

2020-11-26 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, following #958403, node-cross-spawn does risky path mangling and should be rremoved from Debian. Cheers, Xavier

Bug#975877: libjs-sizzle: Please embed typescript definitions

2020-11-25 Thread Xavier Guimard
Package: libjs-sizzle Version: 1.10.18-1 Severity: important Tags: patch ftbfs Hi, following #974218 discussion, node-typescript-types no more embeds @types/sizzle, please embed it in libjs-sizzle. A proposal package is ready in https://salsa.debian/org/js-team/sizzle, it fixes this and the 2

Bug#975508: ITP: node-yaml -- Nodejs parser and stringifier for YAML standard

2020-11-22 Thread Xavier Guimard
Package: wnpp Severity: wishlist Owner: Xavier Guimard X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: node-yaml Version : 1.10.0 Upstream Author : Eemeli Aro * URL : https://github.com/eemeli/yaml * License : ISC Programming Lang: JavaScript

Bug#975405: wabt: Please build wabt.js

2020-11-21 Thread Xavier Guimard
Package: wabt Version: 1.0.20-1 Severity: important X-Debbugs-Cc: pkg-javascript-de...@lists.alioth.debian.org Hi, wabt.js upstream repository is a minified file built from wabt. This package is a reverse dependency of many packages in Debian (via webpack, webassembly, jest,...). Without it,

Bug#975009: node-schema-utils breacking change

2020-11-17 Thread Xavier Guimard
Package: node-schema-utils Version: 2.6.6-1 Severity: serious node-schema-utils API changed: `require("schema-utils")` becomes `require("schema-utils").validate`

Bug#974906: RM: node-minimalistic-assert -- ROM; Useless and too small package

2020-11-16 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi ftpmasters, node-minimalistic-assert is a very small package, unused in Debian and never migrates to testing (#860483: too small package). I think this package should be removed from Debian. Cheers, Xavier

Bug#974670: lintian-brush: "Re-export upstream signing key without extra signatures" is not optimal

2020-11-13 Thread Xavier Guimard
Package: lintian-brush Version: 0.86 Severity: normal Hi, when launching lintian-brush in apache2 source directories, it says that upstream signing key were optimized but I still have: public-upstream-key-not-minimal upstream/signing-key.asc has 2 extra signature(s) for keyid

Bug#974587: node-uuid: Bad "exports" field?

2020-11-12 Thread Xavier Guimard
Package: node-uuid Version: 8.2.0-1 Severity: important Hi, node-uuid breaks dependent package with error like: Package subpath './v1' is not defined by "exports" in /usr/share/nodejs/uuid/package.json (same error with any of v{1,2,3,4}.js) Cheers, Xavier

Bug#974218: node-requirejs: Please embed typescript definitions

2020-11-11 Thread Xavier Guimard
Package: node-requirejs Version: 2.3.6-2 Severity: important X-Debbugs-Cc: pkg-javascript-de...@lists.alioth.debian.org Hi, to avoid version conflicts, JS team decided to remove typescript definitions (node-typescript-types) and embed them directly in the relevant packages. node-requirejs isn't

Bug#974191: RM: node-crypto-cacerts -- ROM; Useless and unmaintained

2020-11-10 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, node-crypto-cacerts is: * very small (should be embedded) * unmaintained upstream (only one commit 5 years ago) * useless in Debian So I think it should be removed from Debian. Cheers, Xavier

Bug#974190: RM: node-capture-stream -- ROM; Useless and unmaintained

2020-11-10 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, node-capture-stream is: * very small (should be embedded) * unmaintained upstream (no commit for 5 years) * useless in Debian So I think it should be removed from Debian. Cheers, Xavier

Bug#974189: RM: node-array-series -- ROM; Useless and unmaintained

2020-11-10 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, node-array-series is: * very small (should be embedded) * unmaintained upstream (no commit for 7 years * useless in Debian So I think it should be removed from Debian. Cheers, Xavier

Bug#974188: RM: node-array-parallel -- ROM; Useless and orphaned

2020-11-10 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, node-array-parallel is: * very small (should be embedded) * unmaintained upstream (no changes for 6 years) * useless in Debian So I think it should be removed from Debian. Cheers, Xavier

Bug#974187: RM: node-absolute-path -- ROM; Useless and unmaintained upstream

2020-11-10 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, node-absolute-path is: * very small (should be embedded) * unmaintained upstream (only one commit 7 years ago) * useless in Debian So I think it should be removed from Debian. Cheers, Xavier

Bug#974064: node-client-sessions: Remove dependency to (deprecated) node-request

2020-11-09 Thread Xavier Guimard
Package: node-client-sessions Version: 0.8.0-2 Severity: serious Tags: ftbfs upstream Hi, node-request won't be part of bullseye, please patch node-client-sessions to replace node-request by another library (node-got, node-fetch, node-axios,...).

Bug#973975: ITP: node-prompts -- Nodejs lightweight, beautiful and user-friendly interactive prompts

2020-11-08 Thread Xavier Guimard
Package: wnpp Severity: wishlist Owner: Xavier Guimard X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: node-prompts Version : 2.4.0 Upstream Author : Terkel Gjervig Nielsen * URL : https://github.com/terkelg/prompts * License : Expat Programming

Bug#973954: ITP: node-sane -- Nodejs fast, small, and reliable file system watcher

2020-11-08 Thread Xavier Guimard
Package: wnpp Severity: wishlist Owner: Xavier Guimard X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: node-sane Version : 4.1.0 Upstream Author : Amjad Masad * URL : https://github.com/amasad/sane * License : Expat Programming Lang: JavaScript

Bug#973946: ITP: node-emittery -- Nodejs simple and modern async event emitter

2020-11-08 Thread Xavier Guimard
Package: wnpp Severity: wishlist Owner: Xavier Guimard X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: node-emittery Version : 0.7.2 Upstream Author : Sindre Sorhus * URL : https://github.com/sindresorhus/emittery * License : Expat Programming

Bug#973913: RM: eyes.js -- ROM; Orphaned upstream

2020-11-07 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: pkg-javascript-de...@alioth-lists.debian.net Hi, eyes.js is no longer maintained upstream. I patched its reverse dependency (vows) to remove this link. No eyes.js can be safely removed from Debian. This removal has been discussed in RC-bug

Bug#973814: uscan: add "compat" target to download a compatible component

2020-11-05 Thread Xavier Guimard
Package: devscripts Version: 2.20.4 Severity: wishlist Control: user -1 devscri...@packages.debian.org Control: usertags -1 uscan uscan offers some target for components: ignore, same,... "same" is strict and matches only the exact same version, while "ignore" doesn't check anything. It could be

Bug#973702: licensecheck should read "license" field from package.json files

2020-11-03 Thread Xavier Guimard
Package: licensecheck Version: 3.0.47-1 Severity: minor Hi, when launching licensecheck in a nodejs module, I'd like to see licensecheck reveals which license is used in package.json Cheers, Xavier

Bug#973696: ITP: node-source-map-resolve -- Node module to resolve source map and/or sources for a generated file

2020-11-03 Thread Xavier Guimard
Package: wnpp Severity: wishlist Owner: Xavier Guimard X-Debbugs-Cc: debian-de...@lists.debian.org, pkg-javascript-de...@lists.alioth.debian.org * Package name: node-source-map-resolve Version : 0.6.0 Upstream Author : Simon Lydell * URL : https://github.com/lydell

Bug#973470: ftp.debian.org: dak rejects unstable uploads

2020-10-31 Thread Xavier Guimard
Package: ftp.debian.org Severity: grave Justification: renders package unusable User: ftp.debian@packages.debian.org Usertags: dak Today dak rejected 4 of my uploads with: Processing raised an exception: a bytes-like object is required, not 'str'. Traceback (most recent call last):

Bug#973429: autopkgtest: Update Architecture field to permit to set "flaky" to a specified arch

2020-10-30 Thread Xavier Guimard
Package: autopkgtest Version: 5.15 Severity: wishlist Hi, thanks for the new "Architecture" field. I'd like to propose an improvment. node-millstone test randomly fails on i386 arch (it's a arch=all package). For now, I disabled i386 autopkgtest, but I'd like to have a autopkgtest feature that

Bug#973342: buster-pu: package libdbi-perl/1.642-1+deb10u2

2020-10-29 Thread Xavier Guimard
@@ -1,3 +1,11 @@ +libdbi-perl (1.642-1+deb10u2) buster; urgency=medium + + [ Salvatore Bonaccorso ] + * t/51dbm_file.t: add test from RT#99508 + * lib/DBD/File.pm: fix CVE-2014-10401 (Closes: #972180) + + -- Xavier Guimard Thu, 29 Oct 2020 07:35:08 +0100 + libdbi-perl (1.642-1+deb10u1) buster

Bug#972932: node-eslint-scope: Please embed @types/eslint-scope

2020-10-26 Thread Xavier Guimard
Package: node-eslint-scope Version: 5.0.0-2 Severity: important Hi, @types/eslint-scope is required at least to upgrade webpak. Please embed it. Cheers, Xavier

Bug#972931: eslint: Please embed @types/eslint

2020-10-26 Thread Xavier Guimard
Package: eslint Version: 5.16.0~dfsg-7 Severity: important Hi, @types/eslint is required at least to update webpack. Please embed it. Cheers, Xavier

Bug#972903: buster-pu: package node-pathval/1.1.0-3+deb10u1

2020-10-25 Thread Xavier Guimard
-7751) + + -- Xavier Guimard Mon, 26 Oct 2020 04:44:16 +0100 + node-pathval (1.1.0-3) unstable; urgency=medium * Point d/watch to /releases instead of /tags. diff --git a/debian/patches/CVE-2020-7751.diff b/debian/patches/CVE-2020-7751.diff new file mode 100644 index 000..7d1ed9a

Bug#972694: buster-pu: package node-object-path/0.11.4-2+deb10u1

2020-10-22 Thread Xavier Guimard
pollution in set() (Closes: CVE-2020-15256) + + -- Xavier Guimard Thu, 22 Oct 2020 18:38:10 +0200 + node-object-path (0.11.4-2) unstable; urgency=medium * Update Vcs fields for migration to https://salsa.debian.org/ diff --git a/debian/patches/CVE-2020-15256.diff b/debian/patches/CVE-2020

Bug#972614: lintian: False positive: package-does-not-install-examples debian/examples

2020-10-21 Thread Xavier Guimard
Package: lintian Version: 2.98.0 Severity: normal Hi all, last lintian shows a strange false positive info: package-does-not-install-examples debian/examples Cheers, Xavier

Bug#972575: npm2deb should search node modules in virtual packages

2020-10-20 Thread Xavier Guimard
Package: npm2deb Version: 0.3.0-5 Severity: important npm2deb currently uses salsa repository to know if a package already exists or not. This is a bad way because: * some node packages are not under pkg-js umbrella (node-almond,...) * lintian warns when a package does not declare its modules

Bug#972570: node-lightgallery is built using minified files

2020-10-20 Thread Xavier Guimard
Package: node-lightgallery Version: 1.6.11+dfsg-1 Severity: serious Justification: 4 Hi, debian/source/lintian-overrides overwrites some real problems: the "concat" part of Gulpfile uses modules/* files which are all obfuscated using minification (downloaded from distinct sources). A possible

Bug#972414: node-pruddy-error: Please enable test

2020-10-18 Thread Xavier Guimard
Package: node-pruddy-error Version: 2.0.2-1 Severity: important Tags: patch Hi, test is not enabled in this package, while it is easy to enable it: * `echo mocha >debian/tests/pkg-js/test` * install "assume" and "fn.name" in debian/tests/test_modules and update debian/copyright * update

Bug#971833: node-babel7 should depends on node-regenerator-runtime

2020-10-08 Thread Xavier Guimard
Package: node-babel7 Version: 7.11.6+~cs65.71.39-1 Severity: normal This is required by @babel/runtime/regenerator/index.js

Bug#971785: libconfig-model-dpkg-perl: cme should accept "needs-internet" autopkgtest restriction

2020-10-07 Thread Xavier Guimard
Package: libconfig-model-dpkg-perl Version: 2.139 Severity: normal All is in the subject ;-) Cheers, Xavier

Bug#971784: libconfig-model-dpkg-perl: cme should not warn on "unknown dh-sequence-nodejs package"

2020-10-07 Thread Xavier Guimard
Package: libconfig-model-dpkg-perl Version: 2.139 Severity: minor Hi, Since all dh-sequence-* build dependencies are virtual packages, cme should ignore related warnings. Cheers, Xavier

Bug#971656: lintian: dh_addons should accept dh-sequence-nodejs as a replacement for pkg-js-tools

2020-10-04 Thread Xavier Guimard
Package: lintian Version: 2.97.0 Severity: normal X-Debbugs-Cc: pkg-javascript-de...@lists.alioth.debian.org When building nodejs packages, using dh-sequence-nodejs, lintian reports: E: node-rollup-plugin-typescript source: missing-build-dependency-for-dh-addon nodejs => pkg-js-tools This is

Bug#971519: node-locate-character: Rebuild from sources

2020-10-01 Thread Xavier Guimard
Package: node-locate-character Version: 2.0.5-1 Severity: serious Justification: source-is-missing 2.0.5 is packaged from npm registry temporarily to be able to build rollup 2. Upstream didn't push 2.0.5 source in git repo (last github release/HEAD is 2.0.1), then 2.0.5 was packaged from npm

Bug#970651: rollup: Unable to build with current tsc

2020-09-20 Thread Xavier Guimard
Package: rollup Version: 1.12.0-2 Severity: serious Tags: ftbfs Justification: Policy 7.7.7 node-rollup 1.12.0 can't be build with current typescript (4.0.2). It requires tsc 3.4.5 (tested with success). Output: $ tsc --esModuleInterop src/ModuleLoader.ts:59:3 - error TS2322: Type '(id: string)

Bug#970506: ITP: node-deepmerge -- Node.js module to merge properties of two objects deeply

2020-09-17 Thread Xavier Guimard
Package: wnpp Severity: wishlist Owner: Xavier Guimard X-Debbugs-Cc: debian-de...@lists.debian.org, pkg-javascript-de...@lists.alioth.debian.org * Package name: node-deepmerge Version : 4.2.2 Upstream Author : Josh Duff * URL : https://github.com/TehShrike/deepmerge

Bug#970307: buster-pu: package node-mysql/2.16.0-1+deb10u1

2020-09-14 Thread Xavier Guimard
+ * Team upload + * Add localInfile option to control LOAD DATA LOCAL INFILE +(Closes: #934712, CVE-2019-14939) + + -- Xavier Guimard Mon, 14 Sep 2020 15:57:57 +0200 + node-mysql (2.16.0-1) unstable; urgency=medium * Team upload diff --git a/debian/patches/CVE-2019-14939.patch b/debi

Bug#970096: buster-pu: package libdbi-perl/1.642-1+deb10u1

2020-09-11 Thread Xavier Guimard
when Perl stack is reallocated +(Closes: CVE-2020-14392) + + -- Xavier Guimard Thu, 10 Sep 2020 10:04:13 +0200 + libdbi-perl (1.642-1) unstable; urgency=medium [ Xavier Guimard ] diff --git a/debian/patches/CVE-2020-14392.patch b/debian/patches/CVE-2020-14392.patch new file mode 100644

Bug#969719: lintian: Unable to override team/pkg-perl/testsuite/no-team-tests

2020-09-07 Thread Xavier Guimard
Package: lintian Version: 2.93.0 Severity: normal Hi, I'm unable to override team/pkg-perl/testsuite/no-team-tests. When adding source: team/pkg-perl/testsuite/no-team-tests autopkgtest lintian report a `bad override` and when adding package source: team/pkg-perl/testsuite/no-team-tests

Bug#969706: buster-pu: package grunt/1.0.1-8+deb10u1

2020-09-06 Thread Xavier Guimard
: #969668, CVE-2020-7729) + + -- Xavier Guimard Sun, 06 Sep 2020 23:41:10 +0200 + grunt (1.0.1-8) unstable; urgency=medium [ Harish K ] diff --git a/debian/patches/CVE-2020-7729.patch b/debian/patches/CVE-2020-7729.patch new file mode 100644 index 000..64bed12 --- /dev/null +++ b/debian

Bug#969369: buster-pu: package node-elliptic/6.4.1_dfsg-1+deb10u1

2020-09-01 Thread Xavier Guimard
..3bc7a59 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,9 @@ +node-elliptic (6.4.1~dfsg-1+deb10u1) buster; urgency=medium + + * Prevent malleability and overflows (Closes: CVE-2020-13822) + + -- Xavier Guimard Tue, 01 Sep 2020 13:24:44 +0200 + node-elliptic (6.4.1~dfsg-1) unstable

Bug#969366: buster-pu: package node-url-parse/1.2.0-2+deb10u1

2020-09-01 Thread Xavier Guimard
d missing test dependency: mocha + * Fix insufficient validation and sanitization of user input +(Closes: CVE-2020-8124) + + -- Xavier Guimard Tue, 01 Sep 2020 12:55:09 +0200 + node-url-parse (1.2.0-2) unstable; urgency=medium * Team upload diff --git a/debian/control b/debian/control

Bug#969348: buster-pu: package node-bl/1.1.2-1+deb10u1

2020-08-31 Thread Xavier Guimard
+1,10 @@ +node-bl (1.1.2-1+deb10u1) buster; urgency=medium + + * Team upload + * Add patch to fix over-read vulnerability (Closes: #969309, CVE-2020-8244) + + -- Xavier Guimard Mon, 31 Aug 2020 10:35:09 +0200 + node-bl (1.1.2-1) unstable; urgency=low * Team upload. diff --git a/debian

Bug#969318: ITP: liburi-normalize-perl -- Perl module to normalize URIs according to RFC 3986

2020-08-31 Thread Xavier Guimard
Package: wnpp Severity: wishlist Owner: Xavier Guimard X-Debbugs-Cc: debian-de...@lists.debian.org, debian-p...@lists.debian.org * Package name: liburi-normalize-perl Version : 0.002 Upstream Author : Andrew Sterling Hanenkamp * URL : https://metacpan.org/pod/URI

Bug#969163: buster-pu: package npm/5.8.0+ds6-4+deb10u2

2020-08-28 Thread Xavier Guimard
+ * Team upload + * Don't show password in logs (Closes: CVE-2020-15095) + + -- Xavier Guimard Fri, 28 Aug 2020 13:36:33 +0200 + npm (5.8.0+ds6-4+deb10u1) buster; urgency=medium * Add patches to fix arbitrary path access diff --git a/debian/patches/CVE-2020-15095.diff b/debian/patches/CVE-

Bug#969081: gyp should not stay under pkg-js umbrella

2020-08-27 Thread Xavier Guimard
Package: gyp Version: 0.1+20200513gitcaa6002-1 Severity: normal Hi, gyp is currently maintain under pkg-js umbrella. This package is a cross platform tool written in Python and stored in salsa.d.o/debian/ area. Then I don't understand the link with pkg-js team. Cheers, Xavier

Bug#962586: autodep8: debian/tests/autopkgtest-pkg-${type}.conf is not read

2020-06-10 Thread Xavier Guimard
Package: autodep8 Version: 0.23 Severity: important Hi, when trying to use new debian/tests/autopkgtest-pkg-${type}.conf, it seems to be unread. Example with pkg-js-tools (after removing current debian/tests/control and adding Testsuite): $ cat debian/tests/autopkgtest-pkg-perl.conf

Bug#962168: loggerhead: Depends on yui3 which is going to be removed

2020-06-04 Thread Xavier Guimard
Source: loggerhead Severity: serious Hi, as explained one year ago ([1] without any response), yui3 is going to be removed (#962167). Please remove dependency to this library (libjs-yui3-min). As yui3 never entered in testing due to DFSG problems, I chose to set severity to serious here.

Bug#962167: RM: yui3 -- ROM; unmaintained

2020-06-04 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, yui3 was uploaded in 2012 and never maintained since except one NMU by security team. I wrote a mail 1 year ago o the bazaar team which has the only one reverse dep (loggerhead), without any response [4]. yui3 has DFSG problem and should not stay as

Bug#961840: RM: node-diffie-hellman -- ROM; unmaintained upstream

2020-05-30 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, node-diffie-hellman never entered in testing due to security issue [1]. Upstream did not fix it for 3 years. node-diffie-hellman was introduced to be able to package node-browserify, but this package no more needs it. Then I think node-diffie-hellman

Bug#961646: node-deep-for-each breaks node-grunt-webpack

2020-05-26 Thread Xavier Guimard
Package: node-deep-for-each Version: 3.0.0-1 Severity: serious Control: affects -1 node-grunt-webpack Version 3.0.0 breaks node-grunt-webpack. Probably due to this change: > This library is no longer built with Babel, you must compile it > yourself within your app Revert to a version 2.x may

Bug#961487: node-code: Remove this package and replace it by node-hapi-code

2020-05-25 Thread Xavier Guimard
Package: node-code Version: 6.0.0-3 Severity: important Hi, node-code is useless and has a name that could be ambiguous. Upstream name is now @hapi/code. I think we should remove this package. If a package needs @hapi/code, we could package it later.

Bug#960808: node-babel7: upgrade to 7.9.6

2020-05-16 Thread Xavier Guimard
Package: node-babel7 Version: 7.4.5+~cs6.2.2-2 Severity: important Control: affects -1 twitter-boostrap4 Please upgrade to last published version (7.9.6). This is required at least to upgrade twitter-bootstrap to 4.5.0

Bug#960684: RM: node-babel-plugin-transform-builtin-extend -- ROM; Useless with node-babel7

2020-05-15 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, node-babel-plugin-transform-builtin-extend is deprecated with node-babel7. It should be removed from Debian archive

Bug#960658: src:cyrus-imapd: test fails on all big endian arch

2020-05-15 Thread Xavier Guimard
Package: src:cyrus-imapd Version: 3.2.0-3 Severity: serious Control: forwarded -1 https://github.com/cyrusimap/cyrus-imapd/issues/3040 Test fails on all big endian arch

Bug#960657: libdpkg-perl: dpkg-buildpackage should accept pkg.$sourcepackage.$anything DEB_BUILD_OPTIONS flags

2020-05-15 Thread Xavier Guimard
Package: libdpkg-perl Version: 1.19.7 Severity: normal Hi, while trying to use pkg.$sourcepackage.$anything in DEB_BUILD_OPTIONS, dkg-buildpackage reports: dpkg-buildpackage: warning: invalid flag in DEB_BUILD_OPTIONS: pkg.node-yarnpkg.test However it seems that

Bug#960575: buster-pu: package node-dot-prop/4.1.1-1+deb10u2

2020-05-14 Thread Xavier Guimard
f7509b9..9b6d599 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,9 @@ +node-dot-prop (4.1.1-1+deb10u2) buster; urgency=medium + + * Fix regression introduced in CVE-2020-8116 fix (Closes: #960283) + + -- Xavier Guimard Thu, 14 May 2020 09:42:34 +0200 + node-dot-prop (4.1.1-1

Bug#960488: eslint: autopkgtest failure: missing test dependency to node-babel7

2020-05-13 Thread Xavier Guimard
Package: eslint Version: 5.16.0~dfsg-5 Severity: serious Justification: unknwon Hi, node-babel7 seems required by autopkgtest test: not ok 344 - /tmp/autopkgtest-lxc.9p09fhxf/downtmp/build.w0w/src/lib/formatters/codeframe.js --- message: '"@babel/code-frame" is not found.' severity:

Bug#960483: RM: node-babel-plugin-precompile-charcodes -- ROM; Useless with node-babel7

2020-05-13 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi all, node-babel-plugin-precompile-charcodes is deprecated with node-babel7 and depends on node-babel 6 which is going to be removed. It should be removed from Debian archive.

Bug#960484: RM: node-babel-preset-es2015-loose -- ROM; Useless with node-babel7

2020-05-13 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi all, node-babel-preset-es2015-loose is deprecated with node-babel7 and depends on node-babel 6 which is going to be removed. It should be removed from Debian archive.

Bug#960482: rainloop: Build with node-babel7

2020-05-13 Thread Xavier Guimard
Package: rainloop Version: 1.12.1-2 Severity: important Hi, rainloop build-depends on node-babel* 6 which are going to be removed. Please fix this.

Bug#960440: RM: node-babel-plugin-transform-async-to-bluebird -- ROM; Useless with node-babel7

2020-05-12 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, node-babel-plugin-transform-async-to-bluebird is deprecated by node-babel7. It should be removed from Debian. Cheers, Xavier

Bug#960432: RM: node-babel-preset-flow-vue -- ROM; Useless with node-babel7

2020-05-12 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, node-babel-preset-flow-vue is deprecated with node-babel7 and not used. It should be removed. Cheers, Xavier

Bug#960433: RM: node-babel-preset-airbnb -- ROM; Useless with node-babel7

2020-05-12 Thread Xavier Guimard
Package: ftp.debian.org Severity: normal Hi, Useless with node-babel7 is deprecated with node-babel7 and not used. It should be removed. Cheers, Xavier

  1   2   3   4   5   >