Bug#1033993: unbound 1.13.1-1+deb11u1 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1033993 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: unbound Version:

Bug#1033506: libreoffice 7.0.4-4+deb11u6 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1033506 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: libreoffice Version:

Bug#1032921: node-webpack 4.43.0-6+deb11u1 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1032921 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: node-webpack Version:

Bug#1031948: libgit2 1.1.0+dfsg.1-4+deb11u1 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1031948 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: libgit2 Version:

Bug#1031410: postgis 3.1.1+dfsg-1+deb11u1 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1031410 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: postgis Version:

Bug#1025703: libexplain 1.4.D001-11+deb11u1 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1025703 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: libexplain Version:

Bug#1032134: node-cookiejar 2.1.2-1+deb11u1 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1032134 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: node-cookiejar Version:

Bug#1030598: lemonldap-ng 2.0.11+ds-4+deb11u4 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1030598 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: lemonldap-ng Version:

Bug#1033578: joblib 0.17.0-4+deb11u1 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1033578 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: joblib Version:

Bug#1031926: gtk+3.0 3.24.24-4+deb11u3 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1031926 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: gtk+3.0 Version:

Bug#1033160: flatpak 1.10.8-0+deb11u1 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1033160 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: flatpak Version:

Bug#1031630: containerd 1.4.13~ds1-1~deb11u4 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1031630 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: containerd Version:

Bug#1031109: crun 0.17+dfsg-1+deb11u1 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1031109 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: crun Version:

Bug#1027258: golang-github-containers-psgo 1.5.2-1+deb11u1 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1027258 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package:

Bug#1027257: golang-github-containers-storage 1.24.8+dfsg1-1+deb11u1 flagged for acceptance

2023-04-07 Thread Adam D Barratt
package release.debian.org tags 1027257 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package:

Bug#1034039: bullseye-pu: package libpod/3.0.1+dfsg1-3+deb11u1

2023-04-07 Thread Adam D. Barratt
On Thu, 2023-04-06 at 19:46 -0400, Reinhard Tartler wrote: > This code change picks up code changes in golang-github-containers- > psgo > and golang-github-containers-storage to fix CVE-2022-1227. This is > reported > as 1020907. This addresses a priviledge escalation issue when using > 'podman

Bug#1031042: mariadb-10.5 10.5.19-0+deb11u1 flagged for acceptance

2023-04-07 Thread Adam D. Barratt
On Sun, 2023-03-26 at 07:35 +0200, Paul Gevers wrote: > Hi Otto, > > On 26-03-2023 06:48, Otto Kekäläinen wrote: > > Based on > > https://packages.debian.org/search?keywords=mariadb-server=names=all=all > > this 10.5.19-0+deb11u1 is still pending and a stable update of > > Debian > > 11

Bug#1025654: bullseye-pu: package x4d-icons/1.2-2+deb11u1

2023-04-07 Thread Adam D. Barratt
Control: tags -1 -moreinfo +confirmed On Sun, 2023-04-02 at 01:14 +0200, Santiago Vila wrote: > El 1/4/23 a las 21:58, Adam D. Barratt escribió: > > Have you confirmed via a binary debdiff that there are no changes > > to > > the resulting packages? > > The package c

Bug#1033770: bullseye-pu: package apache2/2.4.56-1~deb11u2

2023-04-07 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2023-04-02 at 07:08 +0400, Yadd wrote: > Control: tags -1 - confirmed > > On 4/1/23 22:47, Moritz Mühlenhoff wrote: > > Am Sat, Apr 01, 2023 at 08:32:55AM +0400 schrieb Yadd: [...] > > > apache2 silently reenable apache2-doc.conf despite having been > > >

Bug#1032237: bullseye-pu: zfs-linux/2.0.3-9+deb11u1

2023-04-07 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2023-04-02 at 10:53 +0800, Aron Xu wrote: > Control: tags -1 - moreinfo > > On Sun, Apr 2, 2023 at 3:10 AM Adam D. Barratt < > a...@adam-barratt.org.uk> wrote: > > Control: tags -1 + moreinfo > > > > On Thu, 2023-03-02 at

Bug#1027257: bullseye-pu: package golang-github-containers-storage/1.24.8+dfsg1-2~deb11u1

2023-04-07 Thread Adam D. Barratt
On Sat, 2023-04-01 at 19:04 -0400, Reinhard Tartler wrote: > > On 4/1/23 3:51 PM, Adam D. Barratt wrote: > > Control: tags -1 + moreinfo > > > > Apologies for the delay in getting back to you on this. > > > > On Wed, 2022-12-28 at 22:26 -0500, Reinhard Tart

Bug#1026845: bullseye-pu: package systemd/247.3-7+deb11u2

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed d-i On Thu, 2022-12-22 at 12:13 +, Luca Boccassi wrote: > We'd like to upload several bug fixes, including security fixes, for > systemd to bullseye. > The fixes come from the upstream stable branches which are covered by > CI and confirmed by reporters. >

Bug#1025703: bullseye-pu: package libexplain/1.4.D001-11+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2022-12-07 at 19:37 +0100, Santiago Vila wrote: > I'd like to make this QA upload to fix FTBFS bug #997222 in > bullseye, > plus allow compilation with kernels slightly newer than the one in > bullseye (for example bullseye-backports). > > The two patches

Bug#1025654: bullseye-pu: package x4d-icons/1.2-2+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Tue, 2022-12-06 at 23:47 +0100, Santiago Vila wrote: > I'd like to fix FTBFS bug #991067 in stable using the attached > debdiff > (not uploaded yet). > Apologies for the delay in getting back to you on this. > The way the FTBFS is fixed is the same I used in

Bug#1027257: bullseye-pu: package golang-github-containers-storage/1.24.8+dfsg1-2~deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + moreinfo Apologies for the delay in getting back to you on this. On Wed, 2022-12-28 at 22:26 -0500, Reinhard Tartler wrote: > In order to fix CVE-2022-1227, an update to golang-github-containers- > psgo > is needed, more specifically, >

Bug#1027258: bullseye-pu: package golang-github-containers-psgo/1.5.2-2~deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Wed, 2022-12-28 at 22:40 -0500, Reinhard Tartler wrote: > Backport for CVE-2022-1227, taken from > https://github.com/containers/psgo/pull/92 > > This prevents an exploit when running 'podman top' > Apologies for the delay in getting back to you regarding this.

Bug#1029142: bullseye-pu: package geeqie/1:1.6-9+deb11u2 (pre-approval)

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Wed, 2023-01-18 at 15:13 +0100, Andreas Rönnquist wrote: > The clutter library is buggy, to the extent that geeqie might crash > if > not ran without it. This fix simply removes the libchamplain > dependency > (which in it's turn depends on clutter). This makes it

Bug#1033653: bullseye-pu: package lemonldap-ng/2.0.11+ds-4+deb11u

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2023-03-29 at 16:26 +0400, Yadd wrote: > lemonldap-ng is vulnarable to a second factor bypass when used with > an > "AuthBasic handler" (generally used for non-browser apps). > [...] > I didn't pushed yet the already accepted patch for deb11u3 > (#1030598). >

Bug#1031097: bullseye-pu: package conmon/2.0.25+ds1-1.1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2023-02-11 at 19:03 +0100, Reinhard Tartler wrote: > conmon 2.0.25 contains a bug where the container will hang when there > is lots of terminal output. You can easily reproduce like so: > > podman run -it --rm debian:latest > find / > Please go ahead;

Bug#1031410: bullseye-pu: package postgis/3.1.1+dfsg-1+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2023-02-16 at 19:38 +0100, Bas Couwenberg wrote: > As reported in #1031392, postgis 3.1.1 has an important issue with > polar > stereographic projections which was resolved in 3.1.2. > > [ Impact ] > Unusable coordinates from transformations. > Please go

Bug#1031109: bullseye-pu: package crun/0.17+dfsg-1+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2023-02-12 at 00:06 +0200, Faidon Liambotis wrote: > A no-dsa security vulnerability, CVE-2022-27650: > https://security-tracker.debian.org/tracker/CVE-2022-27650 > > [ Impact ] > Copying from the CVE: > > "A flaw was found in crun where containers were

Bug#1031630: bullseye-pu: package containerd/1.4.13~ds1-1~deb11u4

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2023-02-19 at 22:56 +0800, Shengjing Zhu wrote: > Backport patches for 2 CVE: > > * CVE-2023-25153: OCI image importer memory exhaustion > * CVE-2023-25173: Supplementary groups are not set up properly > Please go ahead; sorry for the delay. Regards, Adam

Bug#1031926: bullseye-pu: package gtk+3.0/3.24.24-4+deb11u3

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2023-02-25 at 12:05 +, Simon McVittie wrote: > User request via #1020937: make it possible to run GTK 3 apps in > native > Wayland on some proprietary GLES-only graphics drivers (Raspberry Pi > video core, iMX/Vivante). > Please go ahead, sorry for the

Bug#1031788: bullseye-pu: package publicsuffix/20230209.2326-0+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2023-02-22 at 13:48 -0500, Daniel Kahn Gillmor wrote: > Please consider an update to publicsuffix in debian bullseye. > > This package reflects the state of the network, and keeping it > current > is useful for all the packages that depend on it. > Please

Bug#1031948: bullseye-pu: package libgit2/1.1.0+dfsg.1-4+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2023-02-25 at 21:16 +0100, Tobias Frost wrote: > After fixing CVE-2023-22742 for LTS and ELTS, I'd like to see > this CVE also fixed in stable, for consistency. > > The CVE is an inproper ssh certificate validation vulnerabilty, > which allows

Bug#1032134: bullseye-pu: package node-cookiejar/2.1.2-1+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2023-02-28 at 18:00 +0400, Yadd wrote: > node-cookiejar is vulnerable to ReDoS (CVE-2022-25901). > Please go ahead. Regards, Adam

Bug#1032237: bullseye-pu: zfs-linux/2.0.3-9+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Thu, 2023-03-02 at 15:33 +0800, Aron Xu wrote: > I would like to apply a few patches to address some stability issues > in the > zfs-linux package in bullseye. All the patches are cherry-picked from > upstream > > 2.0.x and 2.1.x stable branches. > +This change

Bug#1032299: bullseye-pu: package node-css-what/4.0.0-3

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2023-03-03 at 08:57 +, Bastien Roucariès wrote: > CVE-2022-21222/CVE-2021-33587 The package css-what before 2.1.3 are > vulnerable > to Regular Expression Denial of Service (ReDoS) due to the usage of > insecure > regular expression in the re_attr variable

Bug#1033160: bullseye-pu: package flatpak/1.10.8-0+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2023-03-18 at 16:20 +, Simon McVittie wrote: > CVE-2023-28101: A malicious Flatpak app could prevent the flatpak(1) > CLI > from displaying its permissions as intended, by having crafted > permissions > or other metadata containing terminal escape

Bug#1032921: bullseye-pu: package node-webpack/4.43.0-6+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2023-03-14 at 08:01 +0400, Yadd wrote: > node-webpack is vulnerable to cross-realm object access > (#1032904, CVE-2023-28154) > Please go ahead. Regards, Adam

Bug#1033759: bullseye-pu: duktape/2.5.0-2+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2023-03-31 at 22:28 +, Thorsten Alteholz wrote: > The attached debdiff for duktape fixes CVE-2021-46322 in Bullseye. > Please go ahead. Regards, Adam

Bug#1033578: bullseye-pu: package joblib/0.17.0-4+deb11u1

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2023-03-27 at 19:42 +0200, Helmut Grohne wrote: > Fix no-dsa security vulnerability CVE-2022-21797. > > [ Impact ] > > The n_jobs parameter of the parallel_backend, which used to be a > string > containing a Python expression, becomes restricted to fairly

Bug#1033506: bullseye-pu: package libreoffice/1:7.0.4-4+deb11u6

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2023-03-26 at 14:23 +0200, Rene Engelhard wrote: > This fixes "CVE-2022-38745. Empty entry in Java class path risks > arbitrary code execution" just disclosed by Apache OpenOffice. > Please go ahead. Regards, Adam

Bug#1033770: bullseye-pu: package apache2/2.4.56-1~deb11u2

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2023-04-01 at 08:32 +0400, Yadd wrote: > apache2 silently reenable apache2-doc.conf despite having been > disabled > (#1018718) > > [ Impact ] > This behavior overwrites local changes on upgrade, which is a > release-critical bug as it’s a Policy violation >

Bug#1033766: bullseye-pu: package cyrus-imapd/3.6.1-4

2023-04-01 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Sat, 2023-04-01 at 07:32 +0400, Yadd wrote: > debian/copyright was incomplete > The debdiff and package version both appear to be for unstable, not bullseye. In general, an update purely to licensing information isn't sufficient to justify a rebuild and update

Bug#1033669: libdatetime-timezone-perl 2.47-1+2023c flagged for acceptance

2023-04-01 Thread Adam D Barratt
package release.debian.org tags 1033669 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: libdatetime-timezone-perl

Bug#1033157: debian-archive-keyring 2021.1.1+deb11u1 flagged for acceptance

2023-04-01 Thread Adam D Barratt
package release.debian.org tags 1033157 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: debian-archive-keyring

Bug#1033079: intel-microcode 3.20230214.1~deb11u1 flagged for acceptance

2023-03-25 Thread Adam D Barratt
package release.debian.org tags 1033079 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: intel-microcode Version:

Bug#1030113: openvswitch 2.15.0+ds1-2+deb11u3 flagged for acceptance

2023-03-25 Thread Adam D Barratt
package release.debian.org tags 1030113 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: openvswitch Version:

Bug#1033412: libdatetime-timezone-perl 2.47-1+2023b flagged for acceptance

2023-03-25 Thread Adam D Barratt
package release.debian.org tags 1033412 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: libdatetime-timezone-perl

Bug#1029123: bullseye-pu: package apache2/2.4.55-1~deb11u1

2023-03-18 Thread Adam D. Barratt
On Wed, 2023-01-18 at 11:25 +0400, Yadd wrote: > Apache2 has 3 new security issues: > * CVE-2006-20001: mod_dav out of bounds read, or write of zero byte. >A carefully crafted If: request header can cause a memory read, or > write >of a single zero byte, in a pool (heap) memory location

Upcoming stable point release (11.7)

2023-03-18 Thread Adam D. Barratt
Hi, The next point release for "bullseye" (11.7) is scheduled for Saturday, April 29th. Processing of new uploads into bullseye-proposed-updates will be frozen during the preceding weekend. Regards, Adam

Bug#1033079: bullseye-pu: package intel-microcode/3.20230214.1~deb11u1

2023-03-18 Thread Adam D. Barratt
On Sat, 2023-03-18 at 08:54 +0100, Tobias Frost wrote: > On Fri, Mar 17, 2023 at 09:15:36PM +0100, Salvatore Bonaccorso wrote: > > Yes this is correct, you do not need to mention it. I just wanted > > to > > make double sure it's as well on the radar (and have not checked if > > you have uploaded

Re: 11.7 planning

2023-03-15 Thread Adam D. Barratt
On Wed, 2023-03-15 at 20:33 +, Jonathan Wiltshire wrote: > We're overdue for 11.7 and need it done with a keyring update > included > before bookworm can be released. The wheels are turning on the > keyring so > how do dates in April look for everybody? Saturdays are 1st (probably > too >

Re: Processed: reassign 1031259 release.debian.org

2023-03-11 Thread Adam D. Barratt
Control: reassign -1 ddcutil On Sat, 2023-03-11 at 09:42 +, Debian Bug Tracking System wrote: > Processing commands for cont...@bugs.debian.org: > > > reassign 1031259 release.debian.org > Bug #1031259 [ddcutil] ddcutil requires module i2c-dev > Bug reassigned from package 'ddcutil' to

Bug#1031635: snakeyaml 1.28-1+deb11u2 flagged for acceptance

2023-03-10 Thread Adam D Barratt
package release.debian.org tags 1031635 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: snakeyaml Version:

Bug#1030851: symfony 4.4.19+dfsg-2+deb11u3 flagged for acceptance

2023-03-10 Thread Adam D Barratt
package release.debian.org tags 1030851 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: symfony Version:

Bug#1031042: mariadb-10.5 10.5.19-0+deb11u1 flagged for acceptance

2023-03-10 Thread Adam D Barratt
package release.debian.org tags 1031042 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: mariadb-10.5 Version:

Re: EC SRM key for bookworm?

2023-03-10 Thread Adam D. Barratt
On Sat, 2023-03-04 at 16:03 +0200, Adrian Bunk wrote: > On Sat, Mar 04, 2023 at 01:33:13PM +0000, Adam D. Barratt wrote: > > SRM is considering using an ed25519 GPG key for bookworm. Does > > anyone > > see any issues with that? > > ... > > We know tha

Re: bookworm release date?

2023-03-09 Thread Adam D. Barratt
Hi, Sorry for the delayed reply, apparently I'm further behind than I realised. :-( On Fri, 2023-02-17 at 21:56 +0100, Paul Gevers wrote: [...] > What do people think of the idea > to start picking a release date already? > [...] > Adam, I think we'd also want to do a point release before that

EC SRM key for bookworm?

2023-03-04 Thread Adam D. Barratt
[Please CC me on replies and keep discussion on d-release regardless of how you received the mail] Hi, SRM is considering using an ed25519 GPG key for bookworm. Does anyone see any issues with that? We've tested merging signatures from a (different) ed25519 key and an RSA key using dak's

Bug#1030709: libvirt 7.0.0-3+deb11u2 flagged for acceptance

2023-03-01 Thread Adam D Barratt
package release.debian.org tags 1030709 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: libvirt Version:

Bug#1028313: isc-dhcp 4.4.1-2.3+deb11u2 flagged for acceptance

2023-02-23 Thread Adam D Barratt
package release.debian.org tags 1028313 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: isc-dhcp Version:

Bug#1031635: snakeyaml 1.28-1+deb11u1 flagged for acceptance

2023-02-23 Thread Adam D Barratt
package release.debian.org tags 1031635 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: snakeyaml Version:

Bug#1030888: ncurses 6.2+20201114-2+deb11u1 flagged for acceptance

2023-02-23 Thread Adam D Barratt
package release.debian.org tags 1030888 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: ncurses Version:

Bug#1031783: command-not-found 20.10.1-1+deb11u1 flagged for acceptance

2023-02-23 Thread Adam D Barratt
package release.debian.org tags 1031783 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: command-not-found Version:

Bug#1030851: symfony 4.4.19+dfsg-2+deb11u2 flagged for acceptance

2023-02-23 Thread Adam D Barratt
package release.debian.org tags 1030851 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: symfony Version:

Bug#1029121: lxc 4.0.6-2+deb11u2 flagged for acceptance

2023-02-23 Thread Adam D Barratt
package release.debian.org tags 1029121 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: lxc Version:

Bug#1030987: vagrant 2.2.14+dfsg-2 flagged for acceptance

2023-02-23 Thread Adam D Barratt
package release.debian.org tags 1030987 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: vagrant Version:

Bug#1028395: exiv2 0.27.3-3+deb11u2 flagged for acceptance

2023-02-23 Thread Adam D Barratt
package release.debian.org tags 1028395 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: exiv2 Version:

Bug#1027264: traceroute 2.1.0-2+deb11u1 flagged for acceptance

2023-02-23 Thread Adam D Barratt
package release.debian.org tags 1027264 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: traceroute Version:

Bug#1031042: Acknowledgement (bullseye-pu: package mariadb-10.5 10.5.19-0+deb11u1)

2023-02-23 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2023-02-17 at 08:00 -0800, Otto Kekäläinen wrote: > Can I proceed to upload MariaDB 10.5.19 to proposed stable updates? A week's a little early for a personal poke... FWIW the original request never made it to debian-release, most likely due to the size of

Bug#1028992: bullseye-pu: package node-json5/2.1.3-2+deb11u1

2023-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2023-01-16 at 07:38 +0400, Yadd wrote: > node-json5 is vulnerable to prototype pollution (CVE-2022-46175) > Please go ahead. Regards, Adam

Bug#1021176: bullseye-pu: package openvswitch/2.15.0+ds1-2+deb11u1

2023-02-19 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Mon, 2022-10-03 at 13:17 +0200, Thomas Goirand wrote: > It appears that the command ovs-dpctl-top was wrongly patched > in the Bullseye version of OVS. Removing the wrong hunks fixes it. > > [ Reason ] > The bug is due to me, who patched all to make OVS working

Bug#1029121: bullseye-pu: package lxc/4.0.6-2+deb11u2

2023-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2023-01-18 at 03:36 +, Mathias Gibbens wrote: > The version of lxc in bullseye is affected by the low-severity > CVE-2022-47952 which was fixed in the recent release of lxc 5.0.2 > (uploaded to unstable yesterday). As the fix was trivial to apply to > the

Bug#1027264: bullseye pu: traceroute/2.1.0-2+deb11u1

2023-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2022-12-29 at 08:57 +0100, László Böszörményi wrote: > Quite recently a new traceroute version was released. Most > importantly > it fixes an excessive CPU consumption on one core (it's not > multi-threaded). It's easy to trigger it, but not considered a >

Bug#1028313: bullseye-pu: package isc-dhcp/4.4.1-2.3+deb11u2

2023-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed d-i On Mon, 2023-01-09 at 14:04 +0100, Bastian Blank wrote: > Under not completely understood conditions, dhclient completely > removes > IPv6 addresses from use and is unable to restore them. This problem > was > fixed in the separate script upstream maintains some

Bug#1028472: bullseye-pu: package publicsuffix/20221208.1942-0+deb11u1

2023-02-19 Thread Adam D. Barratt
On Wed, 2023-01-11 at 11:07 -0500, Daniel Kahn Gillmor wrote: > Please consider an update to publicsuffix in debian bullseye. > > This package reflects the state of the network, and keeping it > current > is useful for all the packages that depend on it. > > The debdiff from the previous version

Bug#1028395: bullseye-pu: package exiv2/0.27.3-3+deb11u2

2023-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2023-01-10 at 13:31 +0100, Helmut Grohne wrote: > I've been working on an exiv2 security update. A significant number > of > vulnerabilities have piled up and they're all tagged no-dsa. I > propose > fixing them via the stable update procedure. > Please go

Bug#1030987: bullseye-pu: package vagrant/2.2.14+dfsg-2

2023-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2023-02-10 at 09:58 +0100, Antonio Terceiro wrote: > Since VirtualBox is not in stable, people will install it either from > upstream, and from Fasttrack (https://fasttrack.debian.net/). When a > new > version of VirtualBox comes out, vagrant needs change to

Bug#1030888: bullseye-pu: package ncurses/6.2+20201114-2+deb11u1

2023-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2023-02-08 at 20:30 +0100, Sven Joachim wrote: > I would like to fix two crash bugs in tic(1) & friends for Bullseye. > There have been various similar issues in the previous years which we > usually fixed in point releases. > > [ Reason ] > 1. Bug

Bug#1030851: bullseye-pu: package symfony/4.4.19+dfsg-2+deb11u2

2023-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2023-02-08 at 13:53 +0100, David Prévot wrote: > Two CVEs have been assigned to Symfony, the version currently in > unstable and bookworm ships the fixes, the attached debdiff is a > proposal for Bullseye. > >

Bug#1030709: bullseye-pu: package libvirt/7.0.0-3+deb11u2

2023-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2023-02-06 at 18:08 +0100, Guido Günther wrote: > This update fixes the test failures on arm64 that were > detected by the 7.0.0-3+deb11u1 build. > Thanks; please go ahead. Regards, Adam

Bug#1030598: bullseye-pu: package lemonldap-ng/2.0.11+ds-4+deb11u3

2023-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2023-02-05 at 18:08 +0400, Yadd wrote: > lemonldap-ng is vulnerable to URL validation bypass > (https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2832). > Please go ahead. Regards, Adam

Bug#1031527: mono 6.8.0.105+dfsg-3.3~deb11u1 flagged for acceptance

2023-02-18 Thread Adam D Barratt
package release.debian.org tags 1031527 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: mono Version:

Bug#1031536: clamav 0.103.8+dfsg-0+deb11u1 flagged for acceptance

2023-02-18 Thread Adam D Barratt
package release.debian.org tags 1031536 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: clamav Version:

Bug#1026447: libapache2-mod-auth-openidc 2.4.9.4-0+deb11u2 flagged for acceptance

2023-02-18 Thread Adam D Barratt
package release.debian.org tags 1026447 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: libapache2-mod-auth-openidc

Bug#1029320: w3m 0.5.3+git20210102-6+deb11u1 flagged for acceptance

2023-02-12 Thread Adam D Barratt
package release.debian.org tags 1029320 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: w3m Version:

Bug#1030732: debian-ports-archive-keyring 2023.02.01~deb11u1 flagged for acceptance

2023-02-12 Thread Adam D Barratt
package release.debian.org tags 1030732 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package:

Bug#1029994: phyx 1.01+ds-2+deb11u1 flagged for acceptance

2023-02-12 Thread Adam D Barratt
package release.debian.org tags 1029994 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: phyx Version:

Bug#1029823: ruby-cfpropertylist 2.2.8-1.1+deb11u1 flagged for acceptance

2023-02-12 Thread Adam D Barratt
package release.debian.org tags 1029823 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: ruby-cfpropertylist

Bug#1029680: grep 3.6-1+deb11u1 flagged for acceptance

2023-02-12 Thread Adam D Barratt
package release.debian.org tags 1029680 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: grep Version: 3.6-1+deb11u1

Bug#1029651: libxpm 3.5.12-1.1~deb11u1 flagged for acceptance

2023-02-12 Thread Adam D Barratt
package release.debian.org tags 1029651 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: libxpm Version:

Bug#1029728: passenger 5.0.30-1.2+deb11u1 flagged for acceptance

2023-02-12 Thread Adam D Barratt
package release.debian.org tags 1029728 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: passenger Version:

Bug#1029385: postfix 3.5.18-0+deb11u1 flagged for acceptance

2023-02-12 Thread Adam D Barratt
package release.debian.org tags 1029385 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: postfix Version:

Bug#1029217: libapreq2 2.13-7+deb11u1 flagged for acceptance

2023-02-12 Thread Adam D Barratt
package release.debian.org tags 1029217 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: libapreq2 Version:

Bug#1029619: ghostscript 9.53.3~dfsg-7+deb11u3 flagged for acceptance

2023-02-12 Thread Adam D Barratt
package release.debian.org tags 1029619 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: ghostscript Version:

Bug#1029147: needrestart 3.5-4+deb11u3 flagged for acceptance

2023-02-12 Thread Adam D Barratt
package release.debian.org tags 1029147 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: needrestart Version:

Bug#1028386: avahi 0.8-5+deb11u2 flagged for acceptance

2023-02-12 Thread Adam D Barratt
package release.debian.org tags 1028386 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: avahi Version:

Bug#1029147: bullseye-pu: package needrestart/3.5-4+deb11u3

2023-02-04 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2023-01-18 at 16:27 +0100, Patrick Matthäi wrote: > needrestart on stable reports a uninitialized perl warning on some > amd64 > systems when using option "-b" > Please go ahead. Regards, Adam

<    4   5   6   7   8   9   10   11   12   13   >