Processed: Re: Bug#953763: buster-pu: package node-minimist/1.2.0-1+deb10u1

2020-04-25 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #953763 [release.debian.org] buster-pu: package node-minimist/1.2.0-1+deb10u1 Added tag(s) confirmed. -- 953763: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=953763 Debian Bug Tracking System Contact ow...@bugs.debian.org with

Bug#953763: buster-pu: package node-minimist/1.2.0-1+deb10u1

2020-04-25 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2020-03-13 at 07:23 +0100, Xavier Guimard wrote: > node-minimist is vulnerable to prototype pollution. I fixed this > using > whole 1.2.0-to-1.2.5 diff (very little) since only prototype related > issues have been fixed. > Please go ahead. Regards, Adam

Bug#953763: buster-pu: package node-minimist/1.2.0-1+deb10u1

2020-03-13 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Hi, node-minimist is vulnerable to prototype pollution. I fixed this using whole 1.2.0-to-1.2.5 diff (very little) since only prototype related issues have been fixed. Cheers,