Re: roundcube: CVE-2021-46144: XSS vulnerability via HTML messages with malicious CSS content

2022-01-12 Thread Sylvain Beucler
Hi Guilhem, On 12/01/2022 16:07, Guilhem Moulin wrote: On Wed, 12 Jan 2022 at 15:48:51 +0100, Sylvain Beucler wrote: On 12/01/2022 14:15, Guilhem Moulin wrote: Thanks for the update. Go ahead and upload to stretch-security, and I'll publish the DLA accordingly :) Uploaded to security-m

Debian LTS and ELTS - January 2022

2022-02-01 Thread Sylvain Beucler
://lists.debian.org/debian-lts-announce/2022/01/msg5.html -- Sylvain Beucler Debian LTS Team

Re: EOL guacamole-client in Stretch

2022-02-02 Thread Sylvain Beucler
Hi, On 31/01/2022 22:29, Markus Koschany wrote: I believe we should mark guacamole-client as end-of-life in Stretch but I would like to hear your opinion too. Guacamole in Stretch is a five year old web application with four open CVE. Upstream recommends to upgrade to the latest 1.4.0 release an

Debian LTS and ELTS - February 2022

2022-03-01 Thread Sylvain Beucler
-- Sylvain Beucler Debian LTS Team

Re: libspring-java support

2022-04-01 Thread Sylvain Beucler
Hi, On 01/04/2022 11:50, Emilio Pozuelo Monfort wrote: On 03/12/2021 23:50, Markus Koschany wrote: Am Freitag, dem 03.12.2021 um 14:28 +0100 schrieb Sylvain Beucler: This year I worked on libspring-java twice for LTS&ELTS. In both case upstream provided limited information for the CVEs,

Debian LTS and ELTS - March 2022

2022-04-01 Thread Sylvain Beucler
documentation: proofread / fix typo https://wiki.debian.org/LTS/Development - ELTS documentation: newly-supported-packages: improve procedure -- Sylvain Beucler Debian LTS Team

Re: libspring-java support

2022-04-02 Thread Sylvain Beucler
Hi Holger, On 02/04/2022 14:30, Holger Levsen wrote: On Fri, Apr 01, 2022 at 12:06:40PM +0200, Sylvain Beucler wrote: Holger, can you clarify if you want the LTS team to handle debian-security-support backports to stretch, or if you intend to do it yourself? thanks for asking, I'd be

Tracking buster/stable updates suited for LTS

2022-04-20 Thread Sylvain Beucler
-triage.py' output. Front-desk may need to use 'no-dsa' sparingly in the future, in favor of its 'postponed' and 'ignored' sub-states [4], so as to better help the tool. What do you think? Cheers! Sylvain Beucler Debian LTS Team [1] https://security-tracker.debian.org/

Re: Tracking buster/stable updates suited for LTS

2022-04-20 Thread Sylvain Beucler
Now with the patch. On Wed, Apr 20, 2022 at 05:08:20PM +0200, Sylvain Beucler wrote: > During my last front-desk week I noticed that we tend to miss or delay > some buster security updates, in particular those that come in point > releases, and a few batches of minor postponed fixes.

Re: Tracking buster/stable updates suited for LTS

2022-04-20 Thread Sylvain Beucler
s for your work! Could you please create a merge request, so we can discuss this nice improvement there? Regards Am Mi., 20. Apr. 2022 um 17:33 Uhr schrieb Sylvain Beucler mailto:b...@beuc.net>>: Now with the patch. On Wed, Apr 20, 2022 at 05:08:20PM +0200, Sylvain Be

Re: Tracking buster/stable updates suited for LTS

2022-04-21 Thread Sylvain Beucler
wrote: I have just tested the patch and it really produces much more packages to be triaged and they are really reasonable! I would propose to merge it into the master branch and start to use it. Thanks for that! Am Mi., 20. Apr. 2022 um 20:54 Uhr schrieb Sylvain Beucler mailto:b...@beuc.net

Debian LTS and ELTS - April 2022

2022-05-02 Thread Sylvain Beucler
https://lists.debian.org/debian-lts/2022/04/msg3.html - triage: precise how to use the 'oldstable' report https://wiki.debian.org/LTS/Development?action=diff&rev2=289&rev1=288 - Internal discussions - Unsupported packages in jessie and stretch ELTS - Documenting speci

Support for ckeditor3 in Debian

2022-05-06 Thread Sylvain Beucler
or'? Or mark it as end-of-life? Cheers! Sylvain Beucler Debian LTS Team

Re: Support for ckeditor3 in Debian

2022-05-10 Thread Sylvain Beucler
Hello Salvatore, On 08/05/2022 21:17, Salvatore Bonaccorso wrote: On Fri, May 06, 2022 at 09:23:27PM +0200, Sylvain Beucler wrote: Hello Security Team, I'm currently checking 'ckeditor' (v4), an HTML editor for web applications, currently v4), for vulnerabilities to fix

Re: Question and proposed change for lts-cve-triage.py

2022-05-17 Thread Sylvain Beucler
the change tomorrow. This section is where we are late compared to stable/oldstable, where CVEs are already fixed and published in Debian, but not in Debian LTS, sometimes months after. This sounds more urgent to me than checking untriaged CVEs, hence why it's output before. So I'd keep the ordering as-is. Cheers! Sylvain Beucler Debian LTS Team

Re: Question and proposed change for lts-cve-triage.py

2022-05-17 Thread Sylvain Beucler
Hi, On 17/05/2022 15:37, Anton Gladky wrote: As far as I understand all of those packages can be added into the dla-needed without pre-review? Why not just put all of them together. Some can be added to dla-needed.txt, some need finer triage (e.g. no-dsa -> ignored); and some may be false pos

Re: Support for ckeditor3 in Debian

2022-05-21 Thread Sylvain Beucler
Hi all, On 12/05/2022 08:35, Mike Gabriel wrote: On Tue, May 10, 2022 at 12:31:46PM +0200, Sylvain Beucler wrote: On 08/05/2022 21:17, Salvatore Bonaccorso wrote: Now, php-horde-editor is the only rdepends of ckeditor3. IMHO we need to do a re-evaluation of the current CVEs for ckeditor to

Re: Support for ckeditor3 in Debian

2022-05-21 Thread Sylvain Beucler
Hi Mike, On 21/05/2022 10:45, Mike Gabriel wrote: as I have a company interest in Horde and thus in ckeditor3, I'd be happy to co-fund work hours on ckeditor3. Esp. because ckeditor3 in unstable needs the same love as in LTS. And we are currently working on upgrading the company mailserver.

CVE-2022-1552/postgresql-9.6 for stretch

2022-05-23 Thread Sylvain Beucler
upstream since 2021-11 https://www.postgresql.org/support/versioning/ so if this changes anything in your plans please let me know. Cheers! Sylvain Beucler Debian LTS Team

Re: CVE-2022-1552/postgresql-9.6 for stretch

2022-05-23 Thread Sylvain Beucler
Hello Christoph, On 23/05/2022 10:04, Christoph Berg wrote: Re: Sylvain Beucler According to the LTS files, you plan to take care of postgresql-9.6 security updates for stretch. I had told the security team that I do *not* intend to updated 9.6 in stretch. I guess that got noted incorrectly

Re: How to interpret packages-to-support

2022-05-23 Thread Sylvain Beucler
Hi, In LTS triage, 'packages-to-support' is only relevant for non-free packages. Some sponsors requested updates for nvidia-graphics-drivers, so even if it is in (unsupported) non-free, LTS supports it. However no sponsors requested updates for (separate) nvidia-graphics-drivers-legacy-340xx

Re: Tracking buster/stable updates suitable for LTS

2022-05-24 Thread Sylvain Beucler
Regards Anton Am Di., 17. Mai 2022 um 14:43 Uhr schrieb Sylvain Beucler mailto:b...@beuc.net>>: > > Hi, > > On 17/05/2022 08:44, Ola Lundqvist wrote: > > When doing triaging this week as part of the front desk assignment I

Re: What is going on with debian-security-support in stretch?

2022-05-25 Thread Sylvain Beucler
Hi, For the record: https://salsa.debian.org/security-tracker-team/security-tracker/-/blob/03a7d97fa8090d6f48808b08265b970606cb1569/data/dla-needed.txt#L50 Cheers! Sylvain Beucler Debian LTS Team On 20/05/2022 22:00, Roberto C. Sánchez wrote: I've not looked at the debian-security-su

Re: Support for ckeditor3 in Debian

2022-05-25 Thread Sylvain Beucler
Hi, On 21/05/2022 12:06, Sylvain Beucler wrote: On 21/05/2022 10:45, Mike Gabriel wrote: as I have a company interest in Horde and thus in ckeditor3, I'd be happy to co-fund work hours on ckeditor3. Esp. because ckeditor3 in unstable needs the same love as in LTS. And we are currently wo

Debian LTS and ELTS - May 2022

2022-06-01 Thread Sylvain Beucler
ts/2022/05/msg00035.html https://lists.debian.org/debian-lts/2022/05/msg00038.html - Clarify report label and document expected front-desk action - Internal discussions - Recommend keeping documentation in the wiki and ad-hoc READMEs - Recommend leaving git-based workflow optional - Help

Re: buster & ntpd leapsecond file ('/usr/share/zoneinfo/leap-seconds.list'): will expire in less than 19 days

2022-06-09 Thread Sylvain Beucler
Hello Marc, The exact switch dates aren't set yet. I'd recommend opening a bug against buster's ntpd, and add debian-lts@lists.debian.org in Cc. Cheers! Sylvain Beucler Debian LTS Team On 09/06/2022 11:04, Marc SCHAEFER wrote: buster is not yet handled by LTS, but it wil

ckeditor4 security update

2022-06-17 Thread Sylvain Beucler
Does that sound doable and safe enough, or do you think there's too much of a risk of breakage? Cheers! Sylvain Beucler Debian LTS Team

Debian LTS - June 2022

2022-07-01 Thread Sylvain Beucler
ation - Running tests: document direct run with newer/stretch syntax, some logging tips https://wiki.debian.org/LTS/TestSuites/autopkgtest?action=diff&rev2=3&rev1=2 -- Sylvain Beucler Debian LTS Team

Re: What do do with bullseye minor issues?

2022-07-25 Thread Sylvain Beucler
Hi, On 14/07/2022 23:49, Ola Lundqvist wrote: During my front desk work I have now got down to the CVEs for buster that are "postponed". The triage script suggests me to "ignore" or "fix". You mean this particular section: "Issues postponed for , but already fixed in via DSA or point releases

Debian LTS and ELTS - July 2022

2022-08-01 Thread Sylvain Beucler
the CVEs: contribute opinion https://salsa.debian.org/lts-team/lts-extra-tasks/-/issues/38 - LTS documentation: fix a couple migration issues - IRC meeting -- Sylvain Beucler Debian LTS Team

EOL candidates for security-support-ended.deb10

2022-08-03 Thread Sylvain Beucler
Hi, I think the following stretch EOL entries also apply to buster, because the rationale still applies to the buster versions: - ckeditor3 https://lists.debian.org/debian-lts/2022/05/msg00060.html - gpac https://lists.debian.org/debian-lts/2022/04/msg8.html - libspring-java https://lists.d

Re: EOL candidates for security-support-ended.deb10 (OpenStack support)

2022-08-08 Thread Sylvain Beucler
Hi, On Wed, Aug 03, 2022 at 11:54:28AM +0200, Sylvain Beucler wrote: > OpenStack: we tend not to support openstack beyond upstream's support My statement was influenced by the OpenStack 2020 EOL in jessie: https://salsa.debian.org/debian/debian-security-support/-/merge_requests/3 &quo

Re: EOL candidates for security-support-ended.deb10 (libspring-java support)

2022-08-08 Thread Sylvain Beucler
Hello Moritz, On 05/08/2022 11:59, Moritz Mühlenhoff wrote: Am Wed, Aug 03, 2022 at 11:54:28AM +0200 schrieb Sylvain Beucler: I think the following stretch EOL entries also apply to buster, because the rationale still applies to the buster versions: - libspring-java https://lists.debian.org

Re: gst-plugins-good1.0/1.14.4-1+deb10u2 for DLA

2022-08-09 Thread Sylvain Beucler
Hi, Thanks for the heads-up. I'll make the announcement. Cheers! Sylvain Beucler Debian LTS Team On 09/08/2022 14:07, Salvatore Bonaccorso wrote: Hi LTS team members! The maintainer for gst-plugins-good1.0 uploaded for buster-security an update to address current CVEs. I have thus adde

Re: EOL candidates for security-support-ended.deb10 (recap)

2022-08-09 Thread Sylvain Beucler
mozilla - nodejs-mozilla - reel - tomcat6 https://salsa.debian.org/debian/debian-security-support/-/blob/master/security-support-ended.deb9 https://salsa.debian.org/debian/debian-security-support/-/blob/master/security-support-ended.deb10 Cheers! Sylvain Beucler Debian LTS Team

Re: EOL candidates for security-support-ended.deb10 (recap)

2022-08-10 Thread Sylvain Beucler
Hi, On 10/08/2022 11:47, Emilio Pozuelo Monfort wrote: On 09/08/2022 19:04, Sylvain Beucler wrote: Here's a little recap for security-support-ended.deb9 -> deb10 evaluation, following our discussion, also including dropped entries for completeness/transparency: Supported again i

Re: EOL candidates for security-support-ended.deb10 (recap)

2022-08-12 Thread Sylvain Beucler
uture, and the discussion seems to have reached consensus, so I think it's good for upload :) Cheers! Sylvain Beucler Debian LTS Team

Re: Accepted webkit2gtk 2.36.7-1~deb10u1 (source) into oldstable

2022-08-30 Thread Sylvain Beucler
Hi all, On 30/08/2022 07:38, Carsten Schoenert wrote: Hello Anton, Am 29.08.22 um 22:28 schrieb Anton Gladky: Hi Carsten, thanks for update! As the buster is now in LTS hands, would you want us to release a DLA? sure, I've somehow forgotten that Buster is now LTS handled. In the past Emili

Debian LTS - August 2022

2022-09-01 Thread Sylvain Beucler
information - New weekly information report: internal discussion on how to present and handle outstanding package updates - Monthly meeting (using Jitsi) -- Sylvain Beucler Debian LTS Team

Re: Updating OpenStack compute (aka src:nova) in Buster

2022-09-12 Thread Sylvain Beucler
Hi Thomas, To answer the second part of your e-mail: > How to proceed? Can I simply upload the normal way? IS there a 3rd > party peer reviewing accepting / rejecting uploads for LTS? While LTS is mostly handled by members of the LTS Team, any DD can contribute directly; we have a few maintainers

Re: node-thenify

2022-09-12 Thread Sylvain Beucler
Hi, If sponsored packages are already handled, and we have time to fix this package, and I think we can fix it. I think we need to evaluate a package's usage only when fixing is problematic (time constraints, backport issues, uncooperative upstream...). Package usage would then be used among

Re: Bug#961654: buster-pu: package bzip2/1.0.6-9.2~deb10u1

2022-09-13 Thread Sylvain Beucler
Hi, IIUC this is about fixing 2 non-security bugs, that were introduced prior to buster's initial release. I personally don't think this fits the LTS project scope. Maybe other LTS members will have a different opinion. Cheers! Sylvain Beucler Debian LTS Team On 13/09/2022 15:27

Re: Accepted pcs 0.10.1-2+deb10u1 (source) into oldstable

2022-09-14 Thread Sylvain Beucler
ther work to do, are you waiting for us to check/review something? Cheers! Sylvain Beucler Debian LTS Team On 12/09/2022 00:50, Debian FTP Masters wrote: Format: 1.8 Date: Sun, 04 Sep 2022 21:55:16 +0200 Source: pcs Architecture: source Version: 0.10.1-2+deb10u1 Distribution: buster-security Urge

Re: Accepted pcs 0.10.1-2+deb10u1 (source) into oldstable

2022-09-14 Thread Sylvain Beucler
Hello, On 14/09/2022 22:43, Valentin Vidic wrote: On Wed, Sep 14, 2022 at 06:46:47PM +0200, Sylvain Beucler wrote: Thank you for claiming 'pcs' in dla-needed.txt and uploading a fixed version. LTS uploads follow a procedure which notably involves reserving a DLA in the security t

Re: What do do with bullseye minor issues?

2022-09-29 Thread Sylvain Beucler
Hi, On 29/09/2022 09:09, Emilio Pozuelo Monfort wrote: On 28/09/2022 23:54, Ola Lundqvist wrote: Took me a month to get down here in the email backlog. I think your reasoning makes sense. I have added the following to the LTS/Development page. "If a CVE has been fixed in Debian Stable it shoul

Debian LTS and ELTS - September 2022

2022-10-01 Thread Sylvain Beucler
vate) bin/package-operations front-desk tooling - IRC meeting http://meetbot.debian.net/debian-lts/2022/debian-lts.2022-09-22-13.58.html -- Sylvain Beucler Debian LTS Team

Re: Cannot read newsgroups with new Thunderbird

2022-10-12 Thread Sylvain Beucler
d suggest you look at the official Thunderbird contact points. Cheers! Sylvain Beucler Debian LTS Team On 05/10/2022 15:17, Miroslav Skoric wrote: After a recent Thunderbird upgrade in Buster (from version 91-something to 101-something, or like), it stopped handling newsgroups properly (where the so

Re: Call for testing: glibc update for buster

2022-10-12 Thread Sylvain Beucler
Hi, I'll give it some testing on my buster system. A couple things I noticed right now: - dist in debian/changelog should be 'buster-security' (not 'buster') - debdiff|diffstat shows spurious '.pc' work files from quilt (plus a change in a patches/README which maybe adds more noise than it he

Re: Call for testing: glibc update for buster

2022-10-17 Thread Sylvain Beucler
Hi, On 17/10/2022 10:00, Helmut Grohne wrote: On Wed, Oct 12, 2022 at 03:45:11PM +0200, Sylvain Beucler wrote: I'll give it some testing on my buster system. Thank you. I take the absense of a further reponse as "nothing broke". Right, although I was kinda waiting for your

Debian LTS and ELTS - October 2022

2022-11-02 Thread Sylvain Beucler
bian.org/debian-lts/2022/10/msg00022.html https://lists.debian.org/debian-lts/2022/10/msg00031.html - Answer LTS Thunderbird user question https://lists.debian.org/debian-lts/2022/10/msg00021.html - Monthly meeting (video/Jitsi) -- Sylvain Beucler Debian LTS Team

Pre-creating Git repos in salsa.d.o/lts-team/packages/ - or not?

2022-11-07 Thread Sylvain Beucler
Hi, I see that a few repositories in salsa.d.o/lts-team/packages/ were created for packages that haven't been claimed yet. https://salsa.debian.org/lts-team/packages?sort=created_desc (I'm not sure who/what did it exactly, there's activity from "Bot-LTS-package", which may be the 'package-ope

Re: Pre-creating Git repos in salsa.d.o/lts-team/packages/ - or not?

2022-11-08 Thread Sylvain Beucler
Hi, On 07/11/2022 19:08, Anton Gladky wrote: as you know one of our goals is to keep the git-history of all {E,L}TS uploads. Some semi-automatic repo creation scripts are in a test phase to ease this process. I have created some repos and imported the last available security versions of packages

Re: Using Salsa-CI as pre-upload QA for Bullseye and Buster uploads: Lintian and Piuparts

2022-11-14 Thread Sylvain Beucler
inconvenient to push to Salsa. I'd be interested in knowing how other LTS contributors handle those issues :) Cheers! Sylvain Beucler Debian LTS Team

Re: Using Salsa-CI as pre-upload QA for Bullseye and Buster uploads: Lintian and Piuparts

2022-11-21 Thread Sylvain Beucler
e new 'apt-get satisfy' command, for reasons I can't debug because of a redacted "collapsed multi-line command" even in the raw log; maybe it could written in a buster-compatible way, or otherwise just dropped for buster because it's confusing. My $0.02 :) Cheers!

Debian LTS and ELTS - November 2022

2022-12-01 Thread Sylvain Beucler
acker triage https://lists.debian.org/debian-security/2022/11/msg2.html - New contributor help (via IRC) - Monthly meeting (via IRC) http://meetbot.debian.net/debian-lts/2022/debian-lts.2022-11-24-13.59.html -- Sylvain Beucler Debian LTS Team

Re: https://bugs.debian.org/1024932 ceph-base: ceph to root privilege escalation via ceph-crash.service CVE-2022-3650

2022-12-03 Thread Sylvain Beucler
Hi Thomas, ceph was added about 1 month ago in the tasks list; I referenced your note there: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a9487a265227c3d4181511570bdf61889ce4c8e2 Cheers! Sylvain Beucler Debian LTS Team On 30/11/2022 14:46, Thomas Goirand wrote

Debian LTS - December 2022

2023-01-02 Thread Sylvain Beucler
- LTS documentation - Fix multiple links and markup issues - Monthly meeting (using Jitsi) -- Sylvain Beucler Debian LTS Team

Re: nvidia-graphics-drivers in DLA needed?

2023-01-03 Thread Sylvain Beucler
hould be more formally decided and documented. I personally don't particularly wish to involve myself with non-free packages. Maybe you can coordinate with Markus and/or open a ticket to make sure this clarification happen? Cheers! Sylvain Beucler Debian LTS Team On 28/12/2022 23:45, Ola

Debian LTS and ELTS - January 2023

2023-02-01 Thread Sylvain Beucler
discussion on helping security team - Monthly meeting (via IRC) http://meetbot.debian.net/debian-lts/2023/debian-lts.2023-01-26-14.00.html -- Sylvain Beucler Debian LTS Team

Re: Three Apache2 vulnerabilities

2023-02-02 Thread Sylvain Beucler
/bugreport.cgi?bug=1029123 ("no-dsa" can be misleading) Cheers! Sylvain Beucler Debian LTS Team On 02/02/2023 08:39, Marc SCHAEFER wrote: Hello, CERT-FR considers three new Apache2 vulnerabilities to be of concern [1]. These are: CVE-2022-37436 [2] CVE-2022-36760 [3] CVE-2006-20001 [4] The

Debian LTS and ELTS - February 2023

2023-03-01 Thread Sylvain Beucler
th security-tracker ELTS fork - Newcomers help - Report misplaced commit - Answer questions on IRC (processes, packages priority) - Help identify/source LTS start date for debian-timeline - Monthly meeting (using Jitsi) -- Sylvain Beucler Debian LTS Team

Triage status for a few old packages

2023-03-20 Thread Sylvain Beucler
ey obsolete somehow?) If they are not triaged and you do not wish to perform such triage, would you mind if we do, and do you have recommendations so as to respect each other's workflows? Cheers! Sylvain Beucler Debian LTS Team

Re: seabios buggy in Buster

2023-03-30 Thread Sylvain Beucler
e consider upgrading to bullseye? Cheers! Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - February 2023

2023-04-01 Thread Sylvain Beucler
et/wiki/TestSuites/qemu.html - Newcomers help on IRC - User help: seabios buggy in Buster https://lists.debian.org/debian-lts/2023/03/msg00046.html - Monthly meeting (via IRC) http://meetbot.debian.net/debian-lts/2023/debian-lts.2023-03-23-13.58.html -- Sylvain Beucler Debian LTS Team

Re: Triage status for a few old packages

2023-04-06 Thread Sylvain Beucler
of the 'sqlite' CLI: for accessing v2 databases, and migrate v2 databases to v3 (AFAICS). So I'm more inclined to keep it supported for the duration of buster-lts (package was removed in later dists). What do you think? Cheers! Sylvain Beucler Debian LTS Team On 01/04/2023 21:

Re: Triage status for a few old packages

2023-04-15 Thread Sylvain Beucler
ite affecting CVEs if they apply really to the > old code-base. In such a case, add > > - sqlite > > and triage it further for buster. So we can do the same as with python2.7, expect this time the LTS Team members are the only ones adding the '- sqlite ' entries for new sqlite3 CVEs. I can proceed to add such entries for the past CVEs and prepare LTS procedures to ensure this is done, until the end of buster-lts next year. Are you OK with this? Cheers! Sylvain Beucler Debian LTS Team

Re: (E)LTS improved salsa pipeline support

2023-04-17 Thread Sylvain Beucler
Hi, On 20/03/2023 09:40, Emilio Pozuelo Monfort wrote: On 17/03/2023 19:39, Raphael Hertzog wrote: On Thu, 16 Mar 2023, Emilio Pozuelo Monfort wrote: The result is an improved pipeline with better support for both LTS and ELTS. [1] Great work Emilio! It would be nice to have all this proper

Re: (E)LTS improved salsa pipeline support

2023-04-19 Thread Sylvain Beucler
Hi, On 17/04/2023 21:36, Sylvain Beucler wrote: On 20/03/2023 09:40, Emilio Pozuelo Monfort wrote: On 17/03/2023 19:39, Raphael Hertzog wrote: On Thu, 16 Mar 2023, Emilio Pozuelo Monfort wrote: The result is an improved pipeline with better support for both LTS and ELTS. [1] Great work

Debian LTS and ELTS - April 2023

2023-05-02 Thread Sylvain Beucler
items https://lts-team.pages.debian.net/wiki/Meetings.html -- Sylvain Beucler Debian LTS Team

Re: nvidia-graphics-drivers in DLA needed?

2023-05-11 Thread Sylvain Beucler
Hi, On 11/05/2023 17:22, Tobias Frost wrote: nvidia-graphics-drivers-legacy-390xx is now uploaded, (tested with some old GTX770…) A procedural question: For the remaining CVE's (and those of nvidia-graphics-drivers), do I mark them "end-of-life" (e.g by saying in CVE/list: [buster] - n

Re: LTS: add libpcap to dla-needed.txt

2023-05-19 Thread Sylvain Beucler
For the record, typo was fixed: libpcap -> libcap2. Cheers! Sylvain On 17/05/2023 12:01, Abhijith PA wrote: Hello Anton, From 5b2bcfaa20e12d0c90eb3999fba8b6e942e201ab Mon Sep 17 00:00:00 2001 From: Anton Gladky Date: Tue, 16 May 2023 22:39:34 +0200 Subject: [PATCH] LTS: add

Re: Bug 1035537 - split -n k/N gives incorrect data on blocks after the first

2023-05-19 Thread Sylvain Beucler
would rather get the coreutil's package maintainers input on the subject first (right now the BTS entry has no replies) :) Cheers! Sylvain Beucler Debian LTS Team

Re: Bug 1035537 - split -n k/N gives incorrect data on blocks after the first

2023-05-19 Thread Sylvain Beucler
Hi, On 19/05/2023 21:14, Chris Frey wrote: On Fri, May 19, 2023 at 08:45:23PM +0200, Sylvain Beucler wrote: On 05/05/2023 05:14, Chris Frey wrote: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1035537 At first glance, it looks like this could lead to data corruption, and hence

Debian LTS and ELTS - May 2023

2023-06-01 Thread Sylvain Beucler
reminder from said maintainer - Internal discussions on Git workflow, and packages claimfiles format/workflow - IRC Meeting http://meetbot.debian.net/debian-lts/2023/debian-lts.2023-05-25-13.58.html -- Sylvain Beucler Debian LTS Team

Make stable-security build logs public after embargo

2023-06-01 Thread Sylvain Beucler
k hook?) I also volunteer to spend some time on the implementation, as part of my work on LTS. Do you think this can be achieved, and how? Cheers! Sylvain Beucler Debian LTS Team

Re: Request for suggestions/opinion about triaging decision for renderdoc

2023-06-20 Thread Sylvain Beucler
Hi, On 17/06/2023 22:14, Roberto C. Sánchez wrote: My opinion is that the package should be added to dla-needed.txt with a note linking to this thread on the mailing list. [snip] There should also be a note there to consider backporting a new upstream release once the security team decides wha

Re: #1036797 bullseye-pu: package mariadb-10.5 10.5.20-0+deb11u1

2023-06-22 Thread Sylvain Beucler
Hello Otto, On 22/06/2023 19:41, Otto Kekäläinen wrote: I filed on May 26th this but never got any reply from stable managers: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=103679 It is affected by only one minor CVE-2022-47015. The same CVE was already fixed in DLA-3444-1 with MariaDB 10.3

Debian LTS and ELTS - June 2023

2023-07-01 Thread Sylvain Beucler
bian.net/wiki/Development.html - Guide non-security LTS upload from non-team contributor https://bugs.debian.org/1039489 - Continue internal discussions on packages claimfiles format/workflow - Jitsi team meeting -- Sylvain Beucler Debian LTS Team

Re: nsis CVE-2023-37378

2023-07-07 Thread Sylvain Beucler
debian.org/lts-team/packages/runc/-/blob/debian/buster/debian/patches/CVE-2022-29162.patch Cheers! Sylvain Beucler Debian LTS Team On 06/07/2023 20:42, Sean Whitton wrote: Hello, I've prepared an upload to buster-security [1] to fix CVE-2023-37378. I've tested it using an example scr

Re: nsis CVE-2023-37378

2023-07-08 Thread Sylvain Beucler
Hi, On 08/07/2023 10:04, Sean Whitton wrote: On Sat 08 Jul 2023 at 09:14am +02, Salvatore Bonaccorso wrote: Just noticed the suffix for the version for the buster-security / LTS upload was +deb9u1, was this intentional? This should have been +deb10u1. It wasn't. Thank you for pointing out t

Debian LTS and ELTS - July 2023

2023-08-01 Thread Sylvain Beucler
sed workflow for package updates - Help newcomers on IRC -- Sylvain Beucler Debian LTS Team

Re: Accepted thunderbird 1:102.14.0-1~deb10u1 (source) into oldoldstable

2023-08-07 Thread Sylvain Beucler
Hello Carsten, Thanks for updating Thunderbird for buster :) Do you want the LTS Team to take care of the DLA registration and announcement, or do you plan to do that yourself? (I assume this matches https://www.debian.org/security/2023/dsa-5469) Cheers! Sylvain Beucler Debian LTS Team On

Re: bullseye / libgdbm6:amd64 is a catastrophgy

2023-08-25 Thread Sylvain Beucler
tinue the discussion with the maintainer (e.g. with comprehensive testing). In conclusion, I believe there's a higher chance of fixing the bug right now in bullseye/oldstable, rather later in bullseye/LTS. Cheers! Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - August 2023

2023-09-01 Thread Sylvain Beucler
- Jitsi team meeting -- Sylvain Beucler Debian LTS Team

Re: Call for tests/review: glib2.0/buster

2023-09-01 Thread Sylvain Beucler
;s glib2.0 update? I considered it but I was mostly out of time, I can do some testing next week. IIUC there was also progress on the older releases since. Cheers! Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - September 2023

2023-10-02 Thread Sylvain Beucler
red (following weekly report) - Team discussions (private GitLab issues) - Experimental GitLab issue-based workflow: Clean-up and unify my LTS/ELTS check-list - Help clarify linux-5.10 status in current tooling - Monthly report guidelines comment - IRC team meeting -- Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - October 2023

2023-11-02 Thread Sylvain Beucler
ibutors on IRC - Jitsi team meeting -- Sylvain Beucler Debian LTS Team

Re: tinymce git repository

2023-11-30 Thread Sylvain Beucler
Hi Sean, At a point LTS pre-created *empty* Git repositories under /lts-team/packages for packages added to dla-needed.txt, but since then we've been trying to leave that to the contributor, so he can e.g. appropriately fork the repository and better keep the history. Consequently empty Git

Debian LTS and ELTS - November 2023

2023-12-01 Thread Sylvain Beucler
ded/docs/how-to-use-extended-lts/ - IRC team meeting http://meetbot.debian.net/debian-lts/2023/debian-lts.2023-11-30-13.57.html -- Sylvain Beucler Debian LTS Team

Re: Make stable-security build logs public after embargo

2023-12-12 Thread Sylvain Beucler
sounds doable, solves the most immediate use case (i.e. LTS devs comparing previous logs on new FTBFS), so I think we can privilege this option. What do you think? [1] https://wiki.debian.org/DebianEvents/gb/2023/MiniDebConfCambridge/Zini Cheers! Sylvain Beucler Debian LTS Team On 12/12/2023 00

Re: upcoming changes of the web pages /security and /lts/security

2023-12-26 Thread Sylvain Beucler
l. ah, very nice! & thanks for clarifying too! https://lts-team.pages.debian.net/wiki/Development.html updated :) Cheers! Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - December 2023

2024-01-02 Thread Sylvain Beucler
an.net/wiki/TestSuites/xfreerdp.html - Jitsi team meeting -- Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - January 2024

2024-02-01 Thread Sylvain Beucler
freerdp tests https://lts-team.pages.debian.net/wiki/TestSuites/freerdp.html - Ping lts-coordinator about issues with Front-Desk reminder template -- Sylvain Beucler Debian LTS Team

Debian LTS and ELTS - February 2024

2024-03-01 Thread Sylvain Beucler
freexian administrative tooling and help test - Documentation - (internal) improves notes on reproducing ELTS autopkgtest setup locally - TestSuites: improves python3 notes https://lts-team.pages.debian.net/wiki/TestSuites/python3.html - Jitsi meeting -- Sylvain Beucler Debian LTS

Re: Question about tinymce dsa/no-dsa decisions

2024-03-13 Thread Sylvain Beucler
Hi Ola, On 12/03/2024 20:52, Ola Lundqvist wrote: I have claimed the package myself now. I think the conclusion will be that all are minor issues and the package do not need an update. But we will see when I have gone through all the CVEs. tinymce is only available up to buster, so we don't h

Re: Removal of sendmail from dla-needed?

2024-03-13 Thread Sylvain Beucler
Hi, For reference, re-added through https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9a2a182dc53f0632ecd32108c91c071bdad76289 Cheers! Sylvain Beucler Debian LTS Team On 10/03/2024 23:18, Ola Lundqvist wrote: Hi all Since I'm not 100% sure about this one I'

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-03-15 Thread Sylvain Beucler
Hi, I add here a reminder to use './find-work' (as documented, including at the top of dla-needed.txt) to look for work _sorted by priority_. I triaged a few low, non-sponsored, harmonize-with-point-updates packages this week, and I'm a bit surprised that some were claimed and even uploaded

Re: Expanding the scope (slightly) of dla-needed.txt

2024-03-16 Thread Sylvain Beucler
Hi, On 14/03/2024 21:47, Roberto C. Sánchez wrote: - FD should be confirming that package removals from dla-needed.txt are valid (i.e., that the package does not require any work towards an upload to (old)stable) Phrased that way, I don't really like the idea of FD checking on his peers

Re: Guidance for CVE triage and listing packages in dla-needed.txt

2024-03-16 Thread Sylvain Beucler
me/ola/freexian/services/deblts/lts/git' is not a git working directory => fix this first in your ~/.config/freexian.ini :) Cheers! Sylvain Beucler Debian LTS Team

Re: Expanding the scope (slightly) of dla-needed.txt

2024-03-18 Thread Sylvain Beucler
Hi, On 17/03/2024 06:54, Sean Whitton wrote: On Thu 14 Mar 2024 at 04:47pm -04, Roberto C. Sánchez wrote: - it is important update the notes on packages in dla-needed.txt to indicate what work has been done and what remains I think that we should be also reviewing old notes and deleting t

<    1   2   3   4   >