Bug#907667: lintian: should html escape output if --color=html is used

2018-09-01 Thread Chris Lamb
Hi Niels, > Though, reminder - if you introduce a new dependency, you will have to > get DSA to install it on lindsay.d.o before you can upgrade lintian there. (Oh, I forgot to mention; it's already installed on lindsay) Regards, -- ,''`. : :' : Chris Lamb `. `'`

Bug#907667: lintian: should html escape output if --color=html is used

2018-09-01 Thread Niels Thykier
Chris Lamb: > Hi Niels, > >> Any reason for introducing the CGI dependency over simply applying the >> same escape rules for the $information variable? > > Only because well-used libraries are preferred, particularly for data > sanitisation (!) operations. > > Is the extra dependency

Bug#907667: lintian: should html escape output if --color=html is used

2018-09-01 Thread Chris Lamb
Hi Niels, > Any reason for introducing the CGI dependency over simply applying the > same escape rules for the $information variable? Only because well-used libraries are preferred, particularly for data sanitisation (!) operations. Is the extra dependency problematic? We use some far-more

Bug#907667: lintian: should html escape output if --color=html is used

2018-09-01 Thread Niels Thykier
Chris Lamb: > tags 907667 + pending > thanks > > Fixed in Git, pending upload: > > > https://salsa.debian.org/lintian/lintian/commit/897c485d61387adc5689f287c7e0404e604136e7 > > debian/changelog | 5 + > debian/control| 2 ++

Bug#907667: lintian: should html escape output if --color=html is used

2018-09-01 Thread Chris Lamb
tags 907667 + pending thanks Fixed in Git, pending upload: https://salsa.debian.org/lintian/lintian/commit/897c485d61387adc5689f287c7e0404e604136e7 debian/changelog | 5 + debian/control| 2 ++ lib/Lintian/Output.pm

Bug#907667: lintian: should html escape output if --color=html is used

2018-08-31 Thread Chris Lamb
Dear James, > some privacy-breach-generic tags contained tags in their information which get emitted into the above pages. > Browsers then proceed to load these stylesheets from foreign websites. The irony that this is designed to /prevent/ loading from these websites in the first place is

Bug#907667: lintian: should html escape output if --color=html is used

2018-08-30 Thread James Cowgill
Package: lintian Version: 2.5.99 Severity: important X-Debbugs-CC: ftpmas...@ftp-master.debian.org X-Debbugs-CC: debian-ad...@lists.debian.org Hi, Lintian does not html escape tag information when --color=html is used. I noticed this after browsing a few packages in the NEW queue which have