Bug#954236: Proposed Buster Fix (pyhon3-bleach: New secuirty issue: mutation XSS (again))

2020-03-20 Thread Salvatore Bonaccorso
Hi Scott, On Fri, Mar 20, 2020 at 01:57:25PM -0400, Scott Kitterman wrote: > On Thursday, March 19, 2020 6:24:22 PM EDT Salvatore Bonaccorso wrote: > > Hi Scott, > > > > On Thu, Mar 19, 2020 at 12:20:25AM -0400, Scott Kitterman wrote: > > > Upstream's 3.1.2 release had just the security fix in it

Bug#954236: Proposed Buster Fix (pyhon3-bleach: New secuirty issue: mutation XSS (again))

2020-03-20 Thread Scott Kitterman
On Thursday, March 19, 2020 6:24:22 PM EDT Salvatore Bonaccorso wrote: > Hi Scott, > > On Thu, Mar 19, 2020 at 12:20:25AM -0400, Scott Kitterman wrote: > > Upstream's 3.1.2 release had just the security fix in it. I propose > > updating buster with it (I put 3.1.3 in unstable, but it had non-secu

Bug#954236: Proposed Buster Fix (pyhon3-bleach: New secuirty issue: mutation XSS (again))

2020-03-19 Thread Salvatore Bonaccorso
Hi Scott, On Thu, Mar 19, 2020 at 12:20:25AM -0400, Scott Kitterman wrote: > Upstream's 3.1.2 release had just the security fix in it. I propose updating > buster with it (I put 3.1.3 in unstable, but it had non-security fixes in it. > > I'm not 100% sure about if we need to modify the import p

Bug#954236: Proposed Buster Fix (pyhon3-bleach: New secuirty issue: mutation XSS (again))

2020-03-18 Thread Scott Kitterman
Upstream's 3.1.2 release had just the security fix in it. I propose updating buster with it (I put 3.1.3 in unstable, but it had non-security fixes in it. I'm not 100% sure about if we need to modify the import path for the new test since we don't use the vendored html5lib, but other than that