Re: Regarding the new "Debian User Repository"

2021-07-05 Thread Brian Thompson
On Mon, Jul 05, 2021 at 12:44:15AM -0500, Hunter Wittenborn wrote: >> By the way, how many users do you currently have? > >At the time of checking there's 46 registered users. > >There's also a counter on the DUR website (bottom-right corner) that displays >the amount of users. Thanks, I haven't

RE: Debian Installer Bullseye RC 1 release

2021-04-23 Thread Brian Thompson
Looks to be fixed now. -Brian  Best regards, Brian Thompson From: Andrew M.A. CaterSent: Friday, April 23, 2021 3:46 AMTo: debian-devel-annou...@lists.debian.orgCc: debian-b...@lists.debian.orgSubject: Re: Debian Installer Bullseye RC 1 release Unfortunately, the website links to media still only

RE: Thanks and Decision making working group (was Re: General Resolution: Statement regarding Richard Stallman's readmission to the FSF board result)

2021-04-18 Thread Brian Thompson
very day.  The last thing people want to do is contribute to a project in their free time that does the same thing. -Brian Thompson  Best regards, Brian Thompson From: Donald NorwoodSent: Sunday, April 18, 2021 5:54 PMTo: Adrian Bunk; debian-devel@lists.debian.orgSubject: Re: Thanks and Decision mak

Re: Debian choice of upstream tarballs for packaging

2021-08-25 Thread Brian Thompson
On 0825, Simon Richter wrote: >Hi, > >On 8/25/21 1:21 AM, Sean Whitton wrote: > >> From my point of view, signing git tags is no less well established a >>best practice than signing tarballs -- in fact, to me, it seems *more* >>well established. > >That is ecosystem dependent. > >FWIW, I'd love to

Re: Bits from the Release Team: say hello to our studious bookworm

2021-08-14 Thread Brian Thompson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Sun, 2021-08-15 at 00:02 +0100, Jonathan Wiltshire wrote: > Hi, > > On 14th August 2021 we released Debian 11 "bullseye". > > There are too many people who should be thanked for their work on > getting > us to this point to list them all

Re: Debian package manager privilege escalation attack

2021-08-12 Thread Brian Thompson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2021-08-12 at 07:38 +0200, Niels Thykier wrote: > Timothy M Butterworth: > > All, > > > > I just ran across this article > > https://blog.ikuamike.io/posts/2021/package_managers_privesc/ I > > tested > > the attacks on Debian 11 and they

Re: Debian package manager privilege escalation attack

2021-08-12 Thread Brian Thompson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2021-08-12 at 10:44 +0500, Andrey Rahmatullin wrote: > On Wed, Aug 11, 2021 at 10:55:44PM -0500, Brian Thompson wrote: > > Thank you for bringing this to everyone's attention. This are very > > real > > vu

Re: Debian package manager privilege escalation attack

2021-08-12 Thread Brian Thompson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2021-08-12 at 11:19 +0500, Andrey Rahmatullin wrote: > On Thu, Aug 12, 2021 at 01:12:37AM -0500, Brian Thompson wrote: > > Would you agree that there is an issue with sudo access that is > > enabled > > by default on m

Re: Debian package manager privilege escalation attack

2021-08-11 Thread Brian Thompson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Wed, 2021-08-11 at 23:30 -0400, Timothy M Butterworth wrote: > All, > > I just ran across this article > https://blog.ikuamike.io/posts/2021/package_managers_privesc/ I tested > the attacks on Debian 11 and they work successfully giving me a

Re: merged /usr considered harmful (was Re: Bits from the Technical Committee)

2021-07-20 Thread Brian Thompson
On Tue, 2021-07-20 at 21:13 -0400, Polyna-Maude Racicot-Summerside wrote: > Ended up with a 3 month useless discussion regarding if this would > give > a bad impression, that we need to use node for doing development. > Later on I was working on a plugin that treated huge amount of data. > So > I

Re: Reducing allowed Vcs for packaging?

2023-02-26 Thread Brian Thompson
On Sun, 2023-02-26 at 14:24 +0100, Bastian Germann wrote: > Hi! > > During the last weeks I had a look at the Vcs situation in Debian. Currently, > there are eight possible systems allowed and one might specify several of them > for > one package. No package makes use of several Vcs references

Re: Consensus on closing old bugs

2023-02-06 Thread Brian Thompson
On Mon, 2023-02-06 at 11:51 +0100, Santiago Vila wrote: > Let the maintainers handle their bugs. > Old bugs should not be closed just because they are "old". > > For example, I have an open bug which is 26 years old: > > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=5898 > > and I don't see

Consensus on closing old bugs

2023-02-06 Thread Brian Thompson
I understand that the usual way to close out bug reports is having the original author do it themselves. What's the policy on closing bug reports that haven't had activity in over 6 months? Specifically I am talking about the following: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1007922

Re: Bug#1030780: Maintainers wanted for softether-vpn

2023-02-10 Thread Brian Thompson
On Wed, 2023-02-08 at 05:52 -0600, Brian Thompson wrote: > On Tue, 2023-02-07 at 14:23 +0100, Andrej Shadura wrote: > > Package: wnpp > > Severity: normal > > X-Debbugs-Cc: debian-devel@lists.debian.org > > > > Hi all, > > > > I packaged Soft

Re: Bug#1030780: Maintainers wanted for softether-vpn

2023-02-08 Thread Brian Thompson
On Tue, 2023-02-07 at 14:23 +0100, Andrej Shadura wrote: > Package: wnpp > Severity: normal > X-Debbugs-Cc: debian-devel@lists.debian.org > > Hi all, > > I packaged SoftEther VPN back in 2020 when people in Belarus protested > against decades of > dictatorship, and they needed a safe way to