Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2020-07-07 Thread Adam D. Barratt
Control: tags -1 -pending +confirmed On Mon, 2020-05-04 at 22:02 +0200, Xavier wrote: > Le 04/05/2020 à 18:53, Mattia Rizzolo a écrit : > > Hi, > > > > let me reply before adsb has a chance ;) > > > > On Mon, May 04, 2020 at 02:24:20PM +0200, Xavier wrote: > > > Finally I found a way to fix CVE

Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2020-05-04 Thread Xavier
Le 04/05/2020 à 18:53, Mattia Rizzolo a écrit : > Hi, > > let me reply before adsb has a chance ;) > > On Mon, May 04, 2020 at 02:24:20PM +0200, Xavier wrote: >> Finally I found a way to fix CVE and keep autopkgtest OK >> (node-markdown-it-html5-embed). Here is a debdiff for a future point

Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2020-05-04 Thread Mattia Rizzolo
Hi, let me reply before adsb has a chance ;) On Mon, May 04, 2020 at 02:24:20PM +0200, Xavier wrote: > Finally I found a way to fix CVE and keep autopkgtest OK > (node-markdown-it-html5-embed). Here is a debdiff for a future point release This is good, however, > diff --git a/debian/changelog

Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2020-05-04 Thread Xavier
Le 04/05/2020 à 11:54, Adam D. Barratt a écrit : > On Mon, 2020-05-04 at 11:36 +0200, Xavier wrote: >> Le 02/05/2020 à 11:58, Adam D. Barratt a écrit : >>> On Sat, 2020-04-25 at 21:30 +0200, Paul Gevers wrote: Hi Xavier, On Sat, 8 Feb 2020 08:23:25 +0100 Xavier wrote: > Le

Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2020-05-04 Thread Xavier
Le 04/05/2020 à 11:54, Adam D. Barratt a écrit : > On Mon, 2020-05-04 at 11:36 +0200, Xavier wrote: >> Le 02/05/2020 à 11:58, Adam D. Barratt a écrit : >>> On Sat, 2020-04-25 at 21:30 +0200, Paul Gevers wrote: Hi Xavier, On Sat, 8 Feb 2020 08:23:25 +0100 Xavier wrote: > Le

Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2020-05-04 Thread Adam D. Barratt
On Mon, 2020-05-04 at 11:36 +0200, Xavier wrote: > Le 02/05/2020 à 11:58, Adam D. Barratt a écrit : > > On Sat, 2020-04-25 at 21:30 +0200, Paul Gevers wrote: > > > Hi Xavier, > > > > > > On Sat, 8 Feb 2020 08:23:25 +0100 Xavier wrote: > > > > Le 07/02/2020 à 20:16, Adam D. Barratt a écrit : > >

Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2020-05-04 Thread Xavier
Le 02/05/2020 à 11:58, Adam D. Barratt a écrit : > On Sat, 2020-04-25 at 21:30 +0200, Paul Gevers wrote: >> Hi Xavier, >> >> On Sat, 8 Feb 2020 08:23:25 +0100 Xavier wrote: >>> Le 07/02/2020 à 20:16, Adam D. Barratt a écrit : On Sat, 2020-01-25 at 20:40 +, Adam D. Barratt wrote:

Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2020-05-02 Thread Adam D. Barratt
On Sat, 2020-04-25 at 21:30 +0200, Paul Gevers wrote: > Hi Xavier, > > On Sat, 8 Feb 2020 08:23:25 +0100 Xavier wrote: > > Le 07/02/2020 à 20:16, Adam D. Barratt a écrit : > > > On Sat, 2020-01-25 at 20:40 +, Adam D. Barratt wrote: > > > This apparently causes regressions in the autopkgtests

Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2020-04-25 Thread Paul Gevers
Hi Xavier, On Sat, 8 Feb 2020 08:23:25 +0100 Xavier wrote: > Le 07/02/2020 à 20:16, Adam D. Barratt a écrit : > > On Sat, 2020-01-25 at 20:40 +, Adam D. Barratt wrote: > > This apparently causes regressions in the autopkgtests of node- > > markdown-it-html5-embed, which you also most

Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2020-02-07 Thread Xavier
Le 07/02/2020 à 20:16, Adam D. Barratt a écrit : > On Sat, 2020-01-25 at 20:40 +, Adam D. Barratt wrote: >> Control: tags -1 + confirmed >> >> On Mon, 2019-12-30 at 07:51 +0100, Xavier Guimard wrote: >>> node-handlebars is vulnearable to prototype pollution (CVE-2019- >>> 19919). >>> >> >>

Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2020-02-07 Thread Adam D. Barratt
On Sat, 2020-01-25 at 20:40 +, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Mon, 2019-12-30 at 07:51 +0100, Xavier Guimard wrote: > > node-handlebars is vulnearable to prototype pollution (CVE-2019- > > 19919). > > > > Please go ahead. This apparently causes regressions in

Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2020-01-25 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2019-12-30 at 07:51 +0100, Xavier Guimard wrote: > node-handlebars is vulnearable to prototype pollution (CVE-2019- > 19919). > Please go ahead. Regards, Adam

Bug#947758: buster-pu: package node-handlebars/3:4.1.0-1+deb10u1

2019-12-29 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Hi, node-handlebars is vulnearable to prototype pollution (CVE-2019-19919). This patch is exactly the one of upstream. Cheers, Xavier diff --git a/debian/changelog