Bug#1008285: Should zorp be removed?

2022-04-25 Thread Moritz Mühlenhoff
severity 1008285 normal reassign 1008285 ftp.debian.org retitle 1008285 RM: -- RoM; Depends on Python 2 thanks Am Fri, Mar 25, 2022 at 11:30:26PM +0100 schrieb Moritz Muehlenhoff: > Source: zorp > Version: 7.0.1~alpha2-3 > Severity: serious > > Your package came up as a candidate for removal

Bug#1008272: Should postnews be removed?

2022-04-25 Thread Moritz Mühlenhoff
severity 1008272 normal reassign 1008272 ftp.debian.org retitle 1008272 RM: -- RoM; depends on Python 2, unmaintained thanks Am Fri, Mar 25, 2022 at 08:57:50PM +0100 schrieb Moritz Muehlenhoff: > Source: postnews > Version: 0.7-1 > Severity: serious > > Your package came up as a candidate for

Bug#1008274: Should sandsifter be removed?

2022-04-25 Thread Moritz Mühlenhoff
severity 1008274 normal reassign 1008274 ftp.debian.org retitle 1008274 RM: -- RoM; depends on Python 2, unmaintained thanks Am Fri, Mar 25, 2022 at 08:59:21PM +0100 schrieb Moritz Muehlenhoff: > Source: sandsifter > Version: 1.04-1 > Severity: serious > > Your package came up as a candidate

Bug#1008271: Should arriero be removed?

2022-04-25 Thread Moritz Mühlenhoff
severity 1008271 normal reassign 1008271 ftp.debian.org retitle 1008271 RM: arriero -- RoQA; depends on Python 2, unmaintained thanks Am Fri, Mar 25, 2022 at 08:57:10PM +0100 schrieb Moritz Muehlenhoff: > Source: arriero > Version: 0.6-1 > Severity: serious > > Your package came up as a

Bug#1009273: Should python-keepkey be removed?

2022-04-11 Thread Moritz Mühlenhoff
Am Mon, Apr 11, 2022 at 10:50:05AM +0200 schrieb Richard Ulrich: > Hi Moritz, > > If it all worked and was in sync with electrum, that would be great. > > But I stopped updating it back then because in the end most of the time > I still had to install electrum and those plugins manually. > >

Bug#1008700: [Pkg-electronics-devel] Bug#1008700: Should geda-gaf be removed?

2022-04-10 Thread Moritz Mühlenhoff
Am Wed, Mar 30, 2022 at 04:43:12PM -0600 schrieb Bdale Garbee: > Moritz Muehlenhoff writes: > > > Source: geda-gaf > > Version: 1:1.8.2-11 > > Severity: serious > > > > Your package came up as a candidate for removal from Debian: > > For the record, I've previously indicated that I consider

Bug#936777: k3d: Python2 removal in sid/bullseye

2022-04-10 Thread Moritz Mühlenhoff
Hi Manuel, > > Given upstream's reply at https://github.com/K-3D/k3d/issues/38 this > > seems unlikely to get ported, let's remove k3d? > > Basically I'd like to extend its life in Debian and keep users using > this package rather than having to build the version themselves, as > long as it

Bug#1003113: python-django: CVE-2021-45115, CVE-2021-45116 & CVE-2021-45452

2022-01-11 Thread Moritz Mühlenhoff
Am Thu, Jan 06, 2022 at 12:44:03PM - schrieb Chris Lamb: > Hi Security Team, > > I was just looking at these CVEs for ELTS and LTS, but before I make > a move there, I was just wondering if you were planning on (or would > like) a DSA. Hi Chris, these both seem rather harmless to me, I'd say

Bug#1003125: e2guardian: CVE-2021-44273

2022-01-04 Thread Moritz Mühlenhoff
Source: e2guardian X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for e2guardian. CVE-2021-44273[0]: | e2guardian v5.4.x = v5.4.3r is affected by missing SSL certificate | validation in the SSL MITM engine. In standalone mode

Bug#995212: chromium: Update to version 94.0.4606.61 (security-fixes)

2021-12-05 Thread Moritz Mühlenhoff
Am Sun, Dec 05, 2021 at 10:53:56AM +0100 schrieb Paul Gevers: > Hi Andres, > > On 05-12-2021 03:36, Andres Salomon wrote: > > So what's happening with chromium in both sid and stable? I saw on > > d-release that it was removed from testing (#998676 and #998732), with a > > discussion about ending

Bug#937945: python-neuroshare: Python2 removal in sid/bullseye

2021-11-01 Thread Moritz Mühlenhoff
Am Sun, Feb 09, 2020 at 01:18:27PM +0100 schrieb Andreas Tille: > Hi, > > I've taken over this package into Debian Med team to > >https://salsa.debian.org/med-team/python-neuroshare > > It needs some remaining work to port for Python3 which I > can not do right now. Any help is welcome.

Bug#937194: opencaster: Python2 removal in sid/bullseye

2021-11-01 Thread Moritz Mühlenhoff
Am Fri, Jan 29, 2021 at 09:56:46PM + schrieb Thorsten Alteholz: > Hi Moritz, > > On Fri, 29 Jan 2021, Moritz Mühlenhoff wrote: > > opencaster seems dead upstream, should it be removed or are > > you planning to port it to Python 3 yourself? > > I don't plan to

Bug#937209: openopt: Python2 removal in sid/bullseye

2021-10-06 Thread Moritz Mühlenhoff
Am Fri, Aug 30, 2019 at 07:29:33AM + schrieb Matthias Klose: > Package: src:openopt > Version: 0.38+svn1589-1.1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2

Bug#994790: hcxtools: CVE-2021-32286

2021-09-20 Thread Moritz Mühlenhoff
Source: hcxtools X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for hcxtools. CVE-2021-32286[0]: | An issue was discovered in hcxtools through 6.1.6. A global-buffer- | overflow exists in the function pcapngoptionwalk located

Bug#992973: plib: CVE-2021-38714

2021-09-14 Thread Moritz Mühlenhoff
Am Wed, Aug 25, 2021 at 09:23:37PM +0200 schrieb Salvatore Bonaccorso: > Source: plib > Version: 1.8.5-8 > Severity: grave > Tags: security upstream > Justification: user security hole > Forwarded: https://sourceforge.net/p/plib/bugs/55/ > X-Debbugs-Cc: car...@debian.org, Debian Security Team >

Bug#937269: peframe: Python2 removal in sid/bullseye

2021-08-31 Thread Moritz Mühlenhoff
Am Sun, Sep 13, 2020 at 05:44:44PM +0200 schrieb Sascha Steinbiss: > Hi Moritz, > > >> Just an update: Python 3 compatibility is indeed introduced in the latest > >> upstream version, however, that version also adds some new dependencies > >> that would need to be packaged and pass NEW. For

Bug#992046: rust-anymap: CVE-2021-38187

2021-08-09 Thread Moritz Mühlenhoff
Source: rust-anymap X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for rust-anymap. CVE-2021-38187[0]: | An issue was discovered in the anymap crate through 0.12.1 for Rust. | It violates soundness via conversion of a *u8 to a

Bug#991971: [pkg-lynx-maint] Bug#991971: [CVE-2021-38165] lynx: bug in SSL certificate validation -> leaks password in clear text via SNI (under some circumstances)

2021-08-08 Thread Moritz Mühlenhoff
Am Sun, Aug 08, 2021 at 01:54:56AM +0200 schrieb Axel Beckert: > Hi Andreas, > > Andreas Metzler wrote: > > > > tags 991971 fixed-upstream > > > Bug #991971 [lynx] lynx: SSL certificate validation fails with URLs > > > containing user name or user name and password, i.e. > > >

Bug#991593: fixed in otrs2 6.0.32-6

2021-08-05 Thread Moritz Mühlenhoff
Am Thu, Aug 05, 2021 at 09:19:14AM + schrieb Debian FTP Masters: > Source: otrs2 > Source-Version: 6.0.32-6 > Done: Patrick Matthäi > > We believe that the bug you reported is fixed in the latest version of > otrs2, which is due to be installed in the Debian FTP archive. > > A summary of

Bug#991593: otrs2: CVE-2021-36092 CVE-2021-36091 CVE-2021-21443 CVE-2021-21440

2021-07-28 Thread Moritz Mühlenhoff
Source: otrs2 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for otrs2. Couldn't find any Znuny references yet. CVE-2021-36092[0]: | It's possible to create an email which contains specially crafted link | and it can be

Bug#991496: libsndfile: CVE-2021-3246

2021-07-25 Thread Moritz Mühlenhoff
Source: libsndfile X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for libsndfile. CVE-2021-3246[0]: | A heap buffer overflow vulnerability in msadpcm_decode_block of | libsndfile 1.0.30 allows attackers to execute arbitrary

Bug#991307: aspell: CVE-2019-25051

2021-07-20 Thread Moritz Mühlenhoff
Source: aspell X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for aspell. CVE-2019-25051[0]: | objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in | acommon::ObjStack::dup_top (called from acommon::StringMap::add

Bug#991046: tomcat9: CVE-2021-33037 CVE-2021-30640 CVE-2021-30639

2021-07-13 Thread Moritz Mühlenhoff
Source: tomcat9 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for tomcat9. Commit references below, although it's worth considering to simply update to 9.0.47, given that stable-security upgraded to new Tomcat point

Bug#990815: ruby2.7: CVE-2021-31799 CVE-2021-31810 CVE-2021-32066

2021-07-08 Thread Moritz Mühlenhoff
Source: ruby2.7 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for ruby2.7. CVE-2021-31799[0]: A command injection vulnerability in RDoc https://www.ruby-lang.org/en/news/2021/05/02/os-command-injection-in-rdoc/

Bug#990792: redmine: CVE-2021-31863 CVE-2021-31864 CVE-2021-31865 CVE-2021-31866

2021-07-07 Thread Moritz Mühlenhoff
Source: redmine X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for redmine. CVE-2021-31863[0]: | Insufficient input validation in the Git repository integration of | Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x

Bug#990791: ruby-addressable: CVE-2021-32740

2021-07-07 Thread Moritz Mühlenhoff
Source: ruby-addressable X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for ruby-addressable. CVE-2021-32740[0]: | Addressable is an alternative implementation to the URI implementation | that is part of Ruby's standard

Bug#990566: dovecot: CVE-2021-33515 CVE-2021-29157 CVE-2020-28200

2021-07-02 Thread Moritz Mühlenhoff
Source: dovecot X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for dovecot. CVE-2021-33515[0]: | The submission service in Dovecot before 2.3.15 allows STARTTLS | command injection in lib-smtp. Sensitive information can be

Bug#990561: libuv1: CVE-2021-22918

2021-07-02 Thread Moritz Mühlenhoff
Source: libuv1 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, the latest nodejs security release included an issue in libuv: https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/ The patch hasn't landed in libuv.git, but here's the patch as applied by

Bug#990540: mruby: CVE-2020-36401

2021-07-01 Thread Moritz Mühlenhoff
Source: mruby X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for mruby. CVE-2020-36401[0]: | mruby 2.1.2 has a double free in mrb_default_allocf (called from | mrb_free and obj_free).

Bug#990528: ndpi: CVE-2021-36082

2021-07-01 Thread Moritz Mühlenhoff
Source: ndpi X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for ndpi. CVE-2021-36082[0]: | ntop nDPI 3.4 has a stack-based buffer overflow in | processClientServerHello.

Bug#990527: kimageformats: CVE-2021-36083

2021-07-01 Thread Moritz Mühlenhoff
Source: kimageformats X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for kimageformats. CVE-2021-36083[0]: | KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer | overflow in XCFImageFormat::loadTileRLE.

Bug#990525: libgrokj2k: CVE-2021-36089

2021-07-01 Thread Moritz Mühlenhoff
Source: libgrokj2k X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for libgrokj2k. CVE-2021-36089[0]: | Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in | grk::FileFormatDecompress::apply_palette_clr (called from |

Bug#987504: imagemagick: attempt to perform an operation not allowed by the security policy `EPS'

2021-06-03 Thread Moritz Mühlenhoff
Am Wed, May 19, 2021 at 08:49:01PM +0200 schrieb Paul Gevers: > Hi, > > First off, thanks Adrian for raising the concern. In general, at this > stage we don't like packages breaking other packages. This should have been fixed in unstable for a long time, I pinged the maintainer multiple times

Bug#988729: [Pkg-rust-maintainers] Bug#988729: CVE-2021-21299

2021-05-24 Thread Moritz Mühlenhoff
Am Wed, May 19, 2021 at 07:39:55PM +0200 schrieb Fabian Grünbichler: > On May 18, 2021 8:42 pm, Moritz Muehlenhoff wrote: > > Source: rust-hyper > > Severity: grave > > Tags: security > > X-Debbugs-Cc: Debian Security Team > > > > CVE-2021-21299: > >

Bug#986803: [Pkg-rust-maintainers] Bug#986803: CVE-2021-28875 CVE-2021-28876 CVE-2021-28877 CVE-2021-28878 CVE-2021-28879 CVE-2020-36317 CVE-2020-36318

2021-05-18 Thread Moritz Mühlenhoff
Sorry for the late reply, got backlogged in my inbox. Am Mon, Apr 12, 2021 at 11:18:16AM +0100 schrieb Ximin Luo: > It looks like these CVEs affect all versions up to 1.52 (which is not yet > released). > > Do you have links to patches fixing these bugs that can be backported to > 1.48? We've

Bug#987353: CVE-2020-8903 CVE-2020-8907 CVE-2020-8933

2021-05-10 Thread Moritz Mühlenhoff
Am Thu, Apr 22, 2021 at 09:53:24AM -0700 schrieb Zach Marano: > Hi, since this package was brought into Debian in ~2018, there have been > several transformations in the GCE guest software stack and thus the > current landscape is very different. Google doesn't actually maintain the > official

Bug#987149: xscreensaver: allows starting external programs with cap_net_raw

2021-05-06 Thread Moritz Mühlenhoff
Am Mon, Apr 19, 2021 at 11:42:54AM +0200 schrieb Moritz Muehlenhoff: > On Sun, Apr 18, 2021 at 07:21:31PM +0200, Tormod Volden wrote: > > Yes, I think dropping the set_cap is the easy way out of here. sonar > > will still be visually pleasing, just not so interesting. > > Let's do that for

Bug#986815: CVE-2021-21375

2021-04-12 Thread Moritz Mühlenhoff
retitle 986815 CVE-2021-21375 CVE-2020-15260 thanks Am Mon, Apr 12, 2021 at 01:21:04PM +0200 schrieb Moritz Muehlenhoff: > Source: ring > Severity: grave > Tags: security > X-Debbugs-Cc: Debian Security Team > > ring bundles pjproject, so it's probably also affected by CVE-2021-21375? > >

Bug#983446: redis: CVE-2021-21309

2021-02-24 Thread Moritz Mühlenhoff
Am Wed, Feb 24, 2021 at 11:17:55AM + schrieb Chris Lamb: > Chris Lamb wrote: > > > Package: redis > > Version: 3:3.2.6-3+deb9u3 > [..] > > CVE-2021-21309: > > https://groups.google.com/g/redis-db/c/fV7cI3GSgoQ/m/ocwV-MlzAgAJ > > Security team, would you like an upload to stretch-security or

Bug#937194: opencaster: Python2 removal in sid/bullseye

2021-01-29 Thread Moritz Mühlenhoff
Am Fri, Aug 30, 2019 at 07:29:17AM + schrieb Matthias Klose: > Package: src:opencaster > Version: 3.2.2+dfsg-1.1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2

Bug#718272: Processed: reopening 718272

2021-01-27 Thread Moritz Mühlenhoff
reopen 718272 thx Reopening. The reasons are listed in the bug log and were given by the upstream developers. If you want to provide it to bullseye stable users, get it into fasttrack.debian.net. Cheers, Moritz

Bug#937102: mysql-workbench: Python2 removal in sid/bullseye

2021-01-22 Thread Moritz Mühlenhoff
Am Sun, Oct 04, 2020 at 07:45:01PM +1100 schrieb Dmitry Smirnov: > On Saturday, 12 September 2020 5:09:47 AM AEDT Moritz Mühlenhoff wrote: > > Fair enough, let's give upstream some more time, then. > > Upstream told me that they are working on transition to Python3 and tha

Bug#937184: offlineimap: Python2 removal in sid/bullseye

2021-01-16 Thread Moritz Mühlenhoff
Am Sat, Jan 16, 2021 at 11:12:21AM + schrieb Sudip Mukherjee: > Hi All, > > On Mon, Nov 09, 2020 at 08:14:38PM +0100, Moritz Mühlenhoff wrote: > > On Sun, Aug 02, 2020 at 06:24:44PM +0300, Ilias Tsitsimpis wrote: > > > Control: severity -1 serious > > > >

Bug#961302: Processed: bug 961302 is forwarded to https://gitlab.com/sane-project/backends/-/issues/279

2021-01-09 Thread Moritz Mühlenhoff
Am Mon, Jun 01, 2020 at 09:33:48PM +0200 schrieb Salvatore Bonaccorso: > Hi Jörg, > > On Mon, Jun 01, 2020 at 09:27:14PM +0200, Jörg Frings-Fürst wrote: > > Hi Salvatore, > > > > I get always "You need to sign in or sign up before continuing." > > heh okay, not from here which seem strange as I

Bug#937234: pam-python/libpam-mklocaluser/debian-edu-config python3 migration.

2020-11-10 Thread Moritz Mühlenhoff
On Sat, Sep 19, 2020 at 06:00:05PM +0100, peter green wrote: > The debian python maintainers are trying to phase out python 2. > > python 2 has been granted a stay of execution as some important software > requires it to build. In Bullseye Python 2 will only be supported for build deps (using

Bug#937184: offlineimap: Python2 removal in sid/bullseye

2020-11-09 Thread Moritz Mühlenhoff
On Sun, Aug 02, 2020 at 06:24:44PM +0300, Ilias Tsitsimpis wrote: > Control: severity -1 serious > > On Sun, Jul 26, 2020 at 01:21PM, Moritz Mühlenhoff wrote: > > Nine months later there's no progress, let's remove? > > Agreed. > > Raising the severity to ser

Bug#936241: broctl: Python2 removal in sid/bullseye

2020-11-03 Thread Moritz Mühlenhoff
On Mon, Oct 14, 2019 at 07:23:54PM -0400, Scott Kitterman wrote: > It looks like broctl is replaced by zeekctl upstream: > > https://github.com/zeek/zeekctl > > It does support python3, so it'd be great to see this updated to the newer > version. zeekctl is in experimental for a few months,

Bug#956285: Problems identified in debian/copyright

2020-10-31 Thread Moritz Mühlenhoff
On Thu, Oct 29, 2020 at 03:14:44PM +0100, Petter Reinholdtsen wrote: > [Moritz Mühlenhoff] > > JFTR, this is fixed in 1.2.9 > > Great. Now if the maintainer or someone else could just upload it to > unstable, my vlc-plugin-bittorrent package would have a fighting chanc

Bug#943060: ifupdown-multi: Python2 removal in sid/bullseye

2020-10-28 Thread Moritz Mühlenhoff
On Wed, Oct 28, 2020 at 02:38:14PM -0400, Robert Edmonds wrote: > Moritz Mühlenhoff wrote: > > On Wed, Oct 23, 2019 at 02:33:26AM +, mo...@debian.org wrote: > > > Source: ifupdown-multi > > > Version: 0.1.1 > > > Severity: normal > > &

Bug#938150: python-ruamel.ordereddict: Python2 removal in sid/bullseye

2020-10-28 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:46:25AM +, Matthias Klose wrote: > Package: src:python-ruamel.ordereddict > Version: 0.4.14-1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove >

Bug#956285: Problems identified in debian/copyright

2020-10-28 Thread Moritz Mühlenhoff
On Mon, Jul 06, 2020 at 10:14:48PM +0200, Petter Reinholdtsen wrote: > [Michael Lustfield] > > I noticed that this package appears to have some issues with > > debian/copyright. > > Hi. Any hope to have a fix for this in time for the next stable release? JFTR, this is fixed in 1.2.9 Cheers,

Bug#943060: ifupdown-multi: Python2 removal in sid/bullseye

2020-10-28 Thread Moritz Mühlenhoff
On Wed, Oct 23, 2019 at 02:33:26AM +, mo...@debian.org wrote: > Source: ifupdown-multi > Version: 0.1.1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2 from the

Bug#937488: pynast: Python2 removal in sid/bullseye

2020-10-26 Thread Moritz Mühlenhoff
On Fri, Oct 23, 2020 at 08:08:58AM +0200, Andreas Tille wrote: > On Wed, Oct 21, 2020 at 11:09:57PM +0200, Moritz Mühlenhoff wrote: > > > > Given that there's been no upstream reaction for almost a year, let's > > remove? > > Agreed, Andreas. Ack, I've just f

Bug#937488: pynast: Python2 removal in sid/bullseye

2020-10-21 Thread Moritz Mühlenhoff
On Wed, Jan 08, 2020 at 03:03:57PM +0100, Andreas Tille wrote: > Control: tags -1 upstream > Control: forwarded -1 https://github.com/biocore/pynast/issues/20 > > I managed to create a patch using 2to3 but pynast depends python-cogent > vesion <= 1.9 which is Python2. The python3-cogent3 package

Bug#936604: FYI: Python 3 migration of distributuion

2020-10-21 Thread Moritz Mühlenhoff
On Tue, Nov 19, 2019 at 10:43:49PM +0900, Osamu Aoki wrote: > On Sun, Nov 17, 2019 at 02:28:44PM +0900, Osamu Aoki wrote: > > Hi, > > > > On Wed, Nov 13, 2019 at 11:11:43AM -0600, Charles Cazabon wrote: > > > Osamu Aoki wrote: > > > > > > > > Currently, getmail is a candidate for removal from the

Bug#936146: archivemail - Python 3 porting

2020-10-21 Thread Moritz Mühlenhoff
On Tue, Aug 04, 2020 at 11:12:51AM +0100, Jonathan Dowland wrote: > On Mon, Jul 27, 2020 at 12:37:36AM -0400, Sandro Tosi wrote: > > do you have any plan on completing this port? I'm not a user of > > archivemail but it looks like it should be removed, not salvaged: > > > > * no new upstream

Bug#971367: [debian-mysql] Bug#971367: Bug#971367: Bug#971367: mariadb-10.5 should not embed wolfssl

2020-10-02 Thread Moritz Mühlenhoff
On Wed, Sep 30, 2020 at 08:09:10PM +0300, Otto Kekäläinen wrote: > Control: forwarded -1 https://jira.mariadb.org/browse/MDEV-21835 > > Note that the upstream MariaDB uses OpenSSL both for building the > server and the client. In Debian OpenSSL is forbidden in the current > state (or so has e.g.

Bug#971367: mariadb-10.5 should not embed wolfssl

2020-09-29 Thread Moritz Mühlenhoff
On Tue, Sep 29, 2020 at 02:57:48PM +0200, Helmut Grohne wrote: > Source: mariadb-10.5 > Version: 1:10.5.5-1 > Tags: security > Severity: serious > Justification: unsupportable by the Debian security team > > Hi Otto, > > I've hinted that the situation about an embedded ssl library might be >

Bug#937255: pbgenomicconsensus: Python2 removal in sid/bullseye

2020-09-15 Thread Moritz Mühlenhoff
On Tue, Sep 15, 2020 at 10:56:22AM +0200, Andreas Tille wrote: > Hi Moritz, > > On Mon, Aug 31, 2020 at 08:59:37PM +0200, Moritz Mühlenhoff wrote: > > On Fri, Aug 30, 2019 at 07:30:23AM +, Matthias Klose wrote: > > > Package: src:pbgenomicconsensus > > >

Bug#964399: Should ganglia be removed?

2020-09-15 Thread Moritz Mühlenhoff
On Mon, Sep 14, 2020 at 12:17:00AM +0200, Marcos Fouces wrote: > Hi Moritz! > > Yes, i uploaded it to salsa.d.o and i am waiting for Frontdesk aproval > to become DD (that should happens in a few days) in order to upload it > myself instead of asking for sponsorship. > > Its new home is here:

Bug#937288: piggyphoto: Python2 removal in sid/bullseye

2020-09-11 Thread Moritz Mühlenhoff
On Fri, Sep 11, 2020 at 09:51:24PM +0200, Aigars Mahinovs wrote: > Agreed. It was packaged as a reverse dependency for other software, > but other problems eventually prevented the packaging of that. Ack, I've just filed an RM bug. Cheers, Moritz

Bug#937288: piggyphoto: Python2 removal in sid/bullseye

2020-09-11 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:30:59AM +, Matthias Klose wrote: > Package: src:piggyphoto > Version: 0.1dev-git20141014 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove >

Bug#937102: mysql-workbench: Python2 removal in sid/bullseye

2020-09-11 Thread Moritz Mühlenhoff
On Tue, Sep 01, 2020 at 07:11:46PM +1000, Dmitry Smirnov wrote: > On Tuesday, 1 September 2020 4:57:56 AM AEST Moritz Mühlenhoff wrote: > > There's radio silence on https://bugs.mysql.com/bug.php?id=98839, > > They are not very transparent and their public bug tracker is somewhat

Bug#964399: Should ganglia be removed?

2020-09-11 Thread Moritz Mühlenhoff
On Sun, Jul 26, 2020 at 01:31:08PM +0200, Moritz Mühlenhoff wrote: > Hi Marcos, > > I overlooked this in my inbox.. > > On Tue, Jul 07, 2020 at 11:15:58PM +0200, Marcos Fouces wrote: > > Hello Moritz > > > > I did some work time ago on ganglia [1] but i neve

Bug#937269: peframe: Python2 removal in sid/bullseye

2020-09-11 Thread Moritz Mühlenhoff
On Thu, Dec 26, 2019 at 03:57:53PM +0100, Sascha Steinbiss wrote: > Just an update: Python 3 compatibility is indeed introduced in the latest > upstream version, however, that version also adds some new dependencies that > would need to be packaged and pass NEW. For example,

Bug#937187: olefile: Python2 removal in sid/bullseye

2020-09-11 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:29:10AM +, Matthias Klose wrote: > Package: src:olefile > Version: 0.46-1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2 from the

Bug#937184: offlineimap: Python2 removal in sid/bullseye

2020-09-11 Thread Moritz Mühlenhoff
On Sun, Aug 02, 2020 at 06:24:44PM +0300, Ilias Tsitsimpis wrote: > Control: severity -1 serious > > On Sun, Jul 26, 2020 at 01:21PM, Moritz Mühlenhoff wrote: > > Nine months later there's no progress, let's remove? > > Agreed. > > Raising the severity to ser

Bug#936941: found 936941 in 2.9.10+dfsg-2

2020-09-04 Thread Moritz Mühlenhoff
On Wed, Jun 24, 2020 at 03:18:18PM +0200, Mattia Rizzolo wrote: > On Tue, Jun 23, 2020 at 10:58:17PM +0200, Moritz Mühlenhoff wrote: > > With the removal of gnome-doc-utils the only remaining rdep of > > python-libxml2 > > is gone (apart from src:chirp, but it's already unin

Bug#937255: pbgenomicconsensus: Python2 removal in sid/bullseye

2020-08-31 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:30:23AM +, Matthias Klose wrote: > Package: src:pbgenomicconsensus > Version: 2.3.2-5 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2

Bug#937102: mysql-workbench: Python2 removal in sid/bullseye

2020-08-31 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:27:37AM +, Matthias Klose wrote: > Package: src:mysql-workbench > Version: 8.0.17+dfsg-1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove >

Bug#937940: python-nemu: Python2 removal in sid/bullseye

2020-08-31 Thread Moritz Mühlenhoff
On Fri, Mar 27, 2020 at 11:57:00PM +0100, Moritz Mühlenhoff wrote: > On Fri, Aug 30, 2019 at 07:42:40AM +, Matthias Klose wrote: > > Package: src:python-nemu > > Version: 0.3.1-1 > > Severity: normal > > Tags: sid bullseye > > User: debian-pyt...@lists.de

Bug#968833: [Pkg-nagios-devel] Bug#968833: CVE-2020-24368

2020-08-23 Thread Moritz Mühlenhoff
On Sat, Aug 22, 2020 at 04:37:16PM +0200, Sebastiaan Couwenberg wrote: > On 8/22/20 4:26 PM, Moritz Muehlenhoff wrote: > > On Sat, Aug 22, 2020 at 07:58:34AM +0200, Sebastiaan Couwenberg wrote: > >> Hi Moritz, > >> > >> This is fixed in icingaweb2 (2.8.2-1) which was just uploaded to unstable. >

Bug#936309: closure-linter: Python2 removal in sid/bullseye

2020-08-05 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:13:28AM +, Matthias Klose wrote: > Package: src:closure-linter > Version: 2.3.19-1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2

Bug#936873: libhdate: diff for NMU version 1.6.02-2.1

2020-08-05 Thread Moritz Mühlenhoff
The debdiff for my NMU for libhdate (versioned as 1.6.02-2.1) Cheers, Moritz diff -Nru libhdate-1.6.02/debian/changelog libhdate-1.6.02/debian/changelog --- libhdate-1.6.02/debian/changelog 2018-07-30 05:49:11.0 +0200 +++ libhdate-1.6.02/debian/changelog 2020-08-02

Bug#967032: fixed in nodejs 12.18.3~dfsg-1

2020-08-05 Thread Moritz Mühlenhoff
On Tue, Aug 04, 2020 at 10:33:37PM +, Debian FTP Masters wrote: >* New upstream version 12.18.3~dfsg >* B-D python3, python3-distutils > patch configure to use python3 (Closes: #967032) debian/tests/control still refers to "python": | Depends: @, ca-certificates, cdbs, python,

Bug#937490: pynifti: Python2 removal in sid/bullseye

2020-08-03 Thread Moritz Mühlenhoff
On Mon, Aug 03, 2020 at 07:39:12AM +0200, Michael Hanke wrote: > Hi, > > On Sun, Aug 2, 2020, 23:47 Moritz Mühlenhoff wrote: > > > On Fri, Jul 10, 2020 at 01:08:44PM +0200, Andreas Tille wrote: > > > On Mon, Jun 29, 2020 at 08:37:58PM +0200, Moritz Mühlenhoff wrote: &

Bug#937490: pynifti: Python2 removal in sid/bullseye

2020-08-02 Thread Moritz Mühlenhoff
On Fri, Jul 10, 2020 at 01:08:44PM +0200, Andreas Tille wrote: > On Mon, Jun 29, 2020 at 08:37:58PM +0200, Moritz Mühlenhoff wrote: > > On Fri, Aug 30, 2019 at 07:34:39AM +, Matthias Klose wrote: > > > > The upstream homepage states > > > > | PyNIfTI is no

Bug#516394: removal of djbdns ?

2020-08-02 Thread Moritz Mühlenhoff
Hi Peter, On Mon, Jul 27, 2020 at 05:20:23PM +0300, Peter Pentchev wrote: > Now... related to that. I am not sure whether Moritz Muehlenhoff, when > reopening this bug, was aware of the fact that Dmitry Bogatov included > two patches from Jeff King that address the cache poisoning attack - > and

Bug#964399: Should ganglia be removed?

2020-07-26 Thread Moritz Mühlenhoff
Hi Marcos, I overlooked this in my inbox.. On Tue, Jul 07, 2020 at 11:15:58PM +0200, Marcos Fouces wrote: > Hello Moritz > > I did some work time ago on ganglia [1] but i never get this work > published due to unactive/unresponsive uploaders. > > I also done some work on ganglia-web and

Bug#936288: cfv: Python2 removal in sid/bullseye

2020-07-26 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:13:06AM +, Matthias Klose wrote: > Package: src:cfv > Version: 1.18.3-2.1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal Hi Stefan, given your comment at

Bug#937378: purity-ng: Python2 removal in sid/bullseye

2020-07-06 Thread Moritz Mühlenhoff
On Sun, Jun 07, 2020 at 01:03:15AM +0200, Moritz Mühlenhoff wrote: > On Fri, Aug 30, 2019 at 07:32:38AM +, Matthias Klose wrote: > > Package: src:purity-ng > > Version: 0.2.0-2.1 > > Severity: normal > > Tags: sid bullseye > > User: debian-pyt...@lists.de

Bug#937645: python-cjson: Python2 removal in sid/bullseye

2020-06-30 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:37:25AM +, Matthias Klose wrote: > Package: src:python-cjson > Version: 1.2.1-1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2 from

Bug#937490: pynifti: Python2 removal in sid/bullseye

2020-06-30 Thread Moritz Mühlenhoff
On Mon, Jun 29, 2020 at 08:41:26PM +0200, Michael Hanke wrote: > Hi, > > yes, that sounds like to best course of action to me. Ack, I've filed an RM bug. Cheers, Moritz

Bug#937959: python-ntlm: Python2 removal in sid/bullseye

2020-06-29 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:43:00AM +, Matthias Klose wrote: > Package: src:python-ntlm > Version: 1.1.0-1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2 from

Bug#937490: pynifti: Python2 removal in sid/bullseye

2020-06-29 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:34:39AM +, Matthias Klose wrote: > Package: src:pynifti > Version: 0.20100607.1-4.1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2

Bug#943015: marked as pending in fonts-ebgaramond

2020-06-18 Thread Moritz Mühlenhoff
On Thu, Nov 14, 2019 at 02:09:28PM +, Hideki Yamane wrote: > Control: tag -1 pending > > Hello, > > Bug #943015 in fonts-ebgaramond reported by you has been fixed in the > Git repository and is awaiting an upload. You can see the commit > message below and you can check the diff of the fix

Bug#937485: pymvpa2: Python2 removal in sid/bullseye

2020-06-15 Thread Moritz Mühlenhoff
On Sat, Jun 13, 2020 at 01:24:23PM -0400, Yaroslav Halchenko wrote: > As the upstream and Debian maintainer for it, I am ok with it. It could be > easily made to build for python 3 but tests would show that it is not > entirely kosher. I better reupload it when it i an sure it is functioning >

Bug#936465: Remove python-ecryptfs?

2020-06-15 Thread Moritz Mühlenhoff
On Thu, May 14, 2020 at 04:56:01PM -0400, Scott Talbert wrote: > Does it make sense to just remove the python-ecrpyptfs bindings? They don't > seem to have any reverse dependencies and popcon is very low. Patch attached. Cheers, Moritz diff -Naur ecryptfs-utils-111.orig/debian/control

Bug#807648: your mail

2020-06-13 Thread Moritz Mühlenhoff
On Mon, Sep 03, 2018 at 11:25:07PM -0400, Tiago Bortoletto Vaz wrote: > Hi, sorry for the long delay. > > I'm doing a (late) cleanup in my packages and will update Zyne to the new > upstream version, which now runs with python3 and python-wxgtk4.0. I'll have > to package a new dependency as well:

Bug#937485: pymvpa2: Python2 removal in sid/bullseye

2020-06-13 Thread Moritz Mühlenhoff
On Mon, Feb 03, 2020 at 08:36:43AM +1100, Stuart Prescott wrote: > Dear maintainers, > > In the last update on pymvpa2, it sounded like upstream would soon have > sorted > Python 3 compatibility and the FTBFS bugs for the package would soon be > fixed. > However, there has been no upstream

Bug#937437: pyfeed: Python2 removal in sid/bullseye

2020-06-13 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:33:42AM +, Matthias Klose wrote: > Package: src:pyfeed > Version: 0.7.4-2 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2 from the

Bug#936239: fixed in brian 2.2.2.1-1

2020-06-13 Thread Moritz Mühlenhoff
On Sat, Oct 12, 2019 at 10:00:17PM +, Andreas Tille wrote: > Source: brian > Source-Version: 2.2.2.1-1 > > We believe that the bug you reported is fixed in the latest version of > brian, which is due to be installed in the Debian FTP archive. > > A summary of the changes between this version

Bug#938314: qpid-python: Python2 removal in sid/bullseye

2020-06-09 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:49:29AM +, Matthias Klose wrote: > Package: src:qpid-python > Version: 1.37.0+dfsg-1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2

Bug#942622: Would the Games Team adopt Lightyears (pygame based, Python 3 port available)?

2020-06-08 Thread Moritz Mühlenhoff
On Thu, Feb 20, 2020 at 11:44:28AM -0500, Olek Wojnar wrote: > Hi Steve, > > On Thu, Feb 13, 2020, 14:42 Steve Cotton wrote: > > > Hi all in the Games Team, > > > > One of the Debian games affected by the python3 transition is 2 > > Lightyears > > Into Space, source package name

Bug#937483: pymtbl: Python2 removal in sid/bullseye

2020-06-08 Thread Moritz Mühlenhoff
On Mon, Jun 08, 2020 at 01:42:29PM -0400, Robert Edmonds wrote: > Moritz Mühlenhoff wrote: > > On Fri, Aug 30, 2019 at 07:34:31AM +, Matthias Klose wrote: > > > Package: src:pymtbl > > > Version: 0.4.0-1 > > > Severity: normal > > > Tags: sid bullse

Bug#937483: pymtbl: Python2 removal in sid/bullseye

2020-06-08 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:34:31AM +, Matthias Klose wrote: > Package: src:pymtbl > Version: 0.4.0-1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2 from the

Bug#938192: your mail

2020-06-08 Thread Moritz Mühlenhoff
On Sat, Dec 28, 2019 at 03:38:24PM +0100, Joel Rosdahl wrote: > I think that it's time to remove python-sqlite from Debian: it's a > module for the obsolete SQLite 2 API and there's (understandably) no > upstream activity. Makes sense, I've just filed an RM bug. Cheers, Moritz

Bug#937378: purity-ng: Python2 removal in sid/bullseye

2020-06-06 Thread Moritz Mühlenhoff
On Fri, Aug 30, 2019 at 07:32:38AM +, Matthias Klose wrote: > Package: src:purity-ng > Version: 0.2.0-2.1 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2 from

Bug#937749: python-fcgi: Python2 removal in sid/bullseye

2020-06-06 Thread Moritz Mühlenhoff
On Fri, Apr 24, 2020 at 11:12:26PM +0200, Moritz Mühlenhoff wrote: > On Fri, Aug 30, 2019 at 07:39:14AM +, Matthias Klose wrote: > > Package: src:python-fcgi > > Version: 19980130-1 > > Severity: normal > > Tags: sid bullseye > > User: debian-pyt...@lists.de

Bug#938587: sugar-etoys-activity: Python2 removal in sid/bullseye

2020-06-06 Thread Moritz Mühlenhoff
On Sat, Jun 06, 2020 at 05:03:08PM +0200, Jonas Smedegaard wrote: > Hi Moritz, > > Quoting Moritz Mühlenhoff (2020-06-06 16:34:38) > > sugar-etoys-activity seems dead upstream the last commit is from 2012, > > shall we remove it? > > What a coincidence that you should

<    1   2   3   4   5   6   7   8   9   10   >