Bug#925602: unblock: ruby-globalid/0.4.2-1

2019-03-27 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal Hey, Please unblock package ruby-globalid. Recently, there was a bug (#925178) reported against the package with severity: important. The package was in testing and the bug was reported

Bug#925607: unblock: ruby-chromedriver-helper/2.1.0-7

2019-03-27 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal Hey, Please unblock package ruby-chromedriver-helper. There was a bug (#924125) reported against the package with severity: serious. The bug was reported on 9th March and was resolved in

Bug#925604: unblock: ruby-doorkeeper-openid-connect/1.5.5-1

2019-03-27 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal Hey, Please unblock package ruby-doorkeeper-openid-connect. There was a CVE bug (#924747) reported against the package with severity: grave. It was reported on 16th March and was resolved

Bug#925609: unblock: rails/2:5.2.2.1+dfsg-1

2019-03-27 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal Hey, Please unblock package rails. There were 2 bugs (#924520 and #924521) reported against the package with severity: grave and severity: important, respectively. Both the bugs were

Bug#925605: unblock: ruby-carrierwave/1.3.1-2

2019-03-27 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal Hey, Please unblock package ruby-carrierwave. There was a bug (#924830) reported against the package with severity: serious. The bug was reported on 17th March and was resolved in the

Bug#925604: unblock: ruby-doorkeeper-openid-connect/1.5.5-1

2019-04-03 Thread Utkarsh Gupta
Hey, On Sat, Mar 30, 2019 at 9:41 PM Ivo De Decker wrote: > Control: tags -1 moreinfo > > Hi, > > On Wed, Mar 27, 2019 at 07:11:57PM +0530, Utkarsh Gupta wrote: > > Please unblock package ruby-doorkeeper-openid-connect. > > > > There was a CVE bug (#924

Bug#925602: unblock: ruby-globalid/0.4.2-1

2019-03-28 Thread Utkarsh Gupta
Hey, On Thu, Mar 28, 2019 at 2:16 AM Paul Gevers wrote: > Control: tags -1 moreinfo > > Hi Utkarsh, > > On 27-03-2019 14:30, Utkarsh Gupta wrote: > > Please unblock package ruby-globalid. > > > > Recently, there was a bug (#925178) reported against the pac

Bug#926639: unblock: ruby-hangouts-chat/0.0.5-2

2019-04-08 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal Hey, Please unblock package ruby-hangouts-chat. This was affected by #926247, which was an RC bug. However, in the latest upload, this has been fixed and is good to go. The bug was

Bug#922310: unblock: ruby-jquery-ui-rails/6.0.1+dfsg-3

2019-02-14 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal Hey, Please unblock package ruby-jquery-ui-rails I am writing this on behalf of the Ruby team, requesting you to unblock ruby-jquery-ui-rails[1] by the soft freeze. The autopkgtest

Bug#922316: unblock: ruby-leaflet-rails/1.3.1+dfsg-1

2019-02-14 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal Hey, Please unblock package ruby-leaflet-rails I am writing this on behalf of the Ruby team, requesting you to unblock ruby-leaflet-rails[1] by the soft freeze. The autopkgtest regression

Bug#928868: unblock: ruby-globalid/0.4.2+REALLY.0.3.6-1

2019-05-12 Thread Utkarsh Gupta
Hey, On Mon 13 May, 2019, 12:42 AM Paul Gevers, wrote: > Hi Utkarsh, > > On 12-05-2019 11:44, Utkarsh Gupta wrote: > > Hence, requesting you to: > > unblock ruby-globalid/0.4.2+REALLY.0.3.6-1 > > It would have been easier if you would have left the old patches in &

Bug#928868: unblock: ruby-globalid/0.4.2+REALLY.0.3.6-1

2019-05-12 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal Hey, Please unblock package ruby-globalid. The latest upload fixes the FTBFS and thus the bug #925178. It has no test failures now and builds fine with rails, too. Hence, requesting you

Re: Proposal: Repository for fast-paced package backports

2019-05-19 Thread Utkarsh Gupta
Hi Dominik, On 26/12/18 2:16 am, Dominik George wrote: > Heisann, alle sammen, > > as announced in the recent thread about maintaining, I hereby propose a > repository that allows making “backports” of packages available to users > of the stable distribution, if those packages cannot be

Bug#929331: unblock: ruby-devise/4.5.0-3

2019-05-21 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal Hey, Please unblock package ruby-devise. The latest upload contains a CVE-2019-5421 (and #926348) fix. Thus requesting you to: unblock ruby-devise/4.5.0-3 Best, Utkarsh --- -- System

Bug#953123: stretch-pu: package rake/10.5.0-2+deb9u1

2020-03-04 Thread Utkarsh Gupta
/changelog2016-03-01 23:45:05.0 +0530 +++ rake-10.5.0/debian/changelog2020-02-29 20:57:18.0 +0530 @@ -1,3 +1,10 @@ +rake (10.5.0-2+deb9u1) stretch; urgency=high + + * Team upload + * Add patch to use File.open explicitly. (Fixes: CVE-2020-8130) + + -- Utkarsh Gupta S

Bug#953124: buster-pu: package rake/12.3.1-3+deb10u1

2020-03-04 Thread Utkarsh Gupta
:40:36.0 +0530 @@ -1,3 +1,10 @@ +rake (12.3.1-3+deb10u1) buster; urgency=high + + * Team upload + * Add patch to use File.open explicitly. (Fixes: CVE-2020-8130) + + -- Utkarsh Gupta Sat, 29 Feb 2020 20:40:36 +0530 + rake (12.3.1-3) unstable; urgency=medium * Revert the drop of the r

Bug#951131: RM: berkshelf-api/2.2.0-1

2020-02-11 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: rm Severity: normal Hi, This package hasn't been in testing since 1242 days and also fails to build against Ruby 2.7. And also has an RC bug since a long time. Each of its reverse dependencies are being filed for

Bug#951132: RM: ruby-berkshelf-api-client/2.0.2-1

2020-02-11 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: rm Severity: normal Hi, This package hasn't been in testing since 1402 days and also fails to build against Ruby 2.7. And also has an RC bug since a long time. Each of its reverse dependencies are being filed for

Bug#951130: RM: reel/0.6.1-4

2020-02-11 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: rm Severity: normal Hi, This package hasn't been in testing since 1124 days and also fails to build against Ruby 2.7. And also has an RC bug since a long time. Each of its reverse dependencies are being filed for

Bug#951129: RM: ruby-websocket-parser/1.0.0-1

2020-02-11 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: rm Severity: normal Hi, This package hasn't been in testing since 1578 days and was last uploaded on 13th October, 2015. This fails to build against Ruby 2.7. And also has an RC bug since a long time. Each of its

Bug#951129: RM: ruby-websocket-parser/1.0.0-1

2020-02-11 Thread Utkarsh Gupta
reassign 951129 ftp.debian.org User pkg-ruby-extras-maintain...@lists.alioth.debian.org Usertags: ruby2.7-transition thanks On Tue, Feb 11, 2020 at 9:39 AM Adam D. Barratt wrote: > This sounds like you want the package removing from unstable? > Ah, yes. Reassigned to ftp.d.o. Shall fix the

Bug#951133: RM: berkshelf/4.3.5-2

2020-02-11 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: rm Severity: normal Hi, This package hasn't been in testing since 1057 days and also fails to build against Ruby 2.7. And also has an RC bug since a long time. Each of its reverse dependencies are being filed for

Bug#951130: RM: reel/0.6.1-4

2020-02-11 Thread Utkarsh Gupta
reassign 951130 ftp.debian.org user pkg-ruby-extras-maintain...@lists.alioth.debian.org usertags 951130 + ruby2.7-transition thanks On Tue, Feb 11, 2020 at 9:39 AM Adam D. Barratt wrote: > This sounds like you want the package removing from unstable? > Ah, yes. Fixed. Thanks! Best, Utkarsh

Bug#944228: stretch-pu: package phpmyadmin/4:4.6.6-4+deb9u1

2020-03-28 Thread Utkarsh Gupta
Hi Adam. On Tue, 28 Jan 2020 08:35:54 + "Adam D. Barratt" wrote: > Control: tags -1 + confirmed > Thanks. Please go ahead. For some reason, this upload never happened. However, now, the maintainer, William (CCed here) has prepared these CVE fixes + some new CVEs on top of this, too. All of

Bug#944228:

2020-03-29 Thread Utkarsh Gupta
Hi all, On Sat, Mar 28, 2020 at 6:56 PM William Desportes wrote: > Done Thank you! :) > Done, thank you for the suggestion Thank you! :) > I uploaded the file to > https://mentors.debian.net/debian/pool/main/p/phpmyadmin/phpmyadmin_4.6.6-4+deb9u1.dsc Thank you, this has been uploaded from

Bug#954664: stretch-pu: package rails/2:4.2.7.1-1+deb9u2

2020-03-22 Thread Utkarsh Gupta
s (2:4.2.7.1-1+deb9u2) stretch; urgency=high + + * Team upload. + * Add patch to fix possible XSS vector in JS escape helper. +(Fixes: CVE-2020-5267) (Closes: #954304) + + -- Utkarsh Gupta Sun, 22 Mar 2020 18:05:32 +0530 + rails (2:4.2.7.1-1+deb9u1) stretch; urgency=medium * CVE-2018-164

Bug#954714: buster-pu: package rails/2:5.2.2.1+dfsg-1+deb10u1

2020-03-22 Thread Utkarsh Gupta
1,3 +1,11 @@ +rails (2:5.2.2.1+dfsg-1+deb10u1) buster; urgency=high + + * Team upload. + * Add patch to fix possible XSS vector in JS escape helper. +(Fixes: CVE-2020-5267) (Closes: #954304) + + -- Utkarsh Gupta Sun, 22 Mar 2020 18:47:31 +0530 + rails (2:5.2.2.1+dfsg-1) unstable; urgency=medi

Bug#972161: buster-pu: package ruby2.5/2.5.5-3+deb10u3

2020-10-13 Thread Utkarsh Gupta
EBrick. (Fixes: CVE-2020-25613) + + -- Utkarsh Gupta Tue, 13 Oct 2020 18:32:32 +0530 + ruby2.5 (2.5.5-3+deb10u2) buster-security; urgency=high * Non-maintainer upload by the Security Team. diff -Nru ruby2.5-2.5.5/debian/patches/CVE-2020-25613.patch ruby2.5-2.5.5/debian/patches/CVE-2020-25613.patch --- ru

Bug#962255: buster-pu: package ruby-json/2.1.0+dfsg-2+deb10u1

2020-06-05 Thread Utkarsh Gupta
02-25 23:03:06.0 +0530 +++ ruby-json-2.1.0+dfsg/debian/changelog2020-06-05 12:13:54.0 +0530 @@ -1,3 +1,10 @@ +ruby-json (2.1.0+dfsg-2+deb10u1) buster; urgency=high + + * Add patch to fix unsafe object creation vulnerability. +(Fixes: CVE-2020-10663) + + -- Utkarsh Gupta F

Bug#962256: stretch-pu: package ruby-json/2.0.1+dfsg-3+deb9u1

2020-06-05 Thread Utkarsh Gupta
12-06 05:03:24.0 +0530 +++ ruby-json-2.0.1+dfsg/debian/changelog2020-06-05 12:33:14.0 +0530 @@ -1,3 +1,10 @@ +ruby-json (2.0.1+dfsg-3+deb9u1) stretch; urgency=high + + * Add patch to fix unsafe object creation vulnerability. +(Fixes: CVE-2020-10663 + + -- Utkarsh Gupta F

Bug#962264: stretch-pu: package ruby2.3/2.3.3-1+deb9u8

2020-06-05 Thread Utkarsh Gupta
00 +0530 +++ ruby2.3-2.3.3/debian/changelog2020-06-05 14:25:50.0 +0530 @@ -1,3 +1,11 @@ +ruby2.3 (2.3.3-1+deb9u8) stretch; urgency=high + + * Non-maintainer upload. + * Add patch to fix unsafe object creation vulnerability. +(Fixes: CVE-2020-10663) + + -- Utkarsh Gupta F

Bug#971571: transition: libgit2

2020-12-07 Thread Utkarsh Gupta
Hi Peter, On Sun, Dec 6, 2020 at 11:06 AM peter green wrote: > In addition to the packages mentioned here, it seems there is another > package involved: golang-gopkg-libgit2-git2go.v28 . It only builds > arch-all packages and does not directly depend on the library, but it > FTBFS and it's

Bug#971571: transition: libgit2

2020-12-04 Thread Utkarsh Gupta
Hi Sebastian, On Fri, Dec 4, 2020 at 10:54 PM Sebastian Ramacher wrote: > Please go ahead with the upload to unstable. Great, thanks, I did an upload just now! :) - u

Bug#971571: transition: libgit2

2020-12-04 Thread Utkarsh Gupta
Hi, On Sat, Dec 5, 2020 at 1:41 AM Sebastian Ramacher wrote: > Scheduled the binNMUs except for horizon-eda (involved in python3.9-defaults). Great, thank you! I've, meanwhile, uploaded python-pygit2 and libgit-raw-perl! Will hopefully get on to ruby-rugged, as well! \o/ - u

Bug#971571: transition: libgit2

2020-12-08 Thread Utkarsh Gupta
Hi Sebastian, On Tue, Dec 8, 2020 at 3:30 PM Sebastian Ramacher wrote: > v30 was accepted. Please perform a source-only upload for the arch: all > packages. That should be done now! \o/ > > The only reverse-{,build-}dependency is gitaly, it seems. So I'm CCing > > Praveen so he gets a heads

Bug#971571: transition: libgit2

2020-12-09 Thread Utkarsh Gupta
Hello, On Wed, Dec 9, 2020 at 2:23 AM Sebastian Ramacher wrote: > > So I conclude that it's probably fine to upload libgit2 1.1.0 to unstable > > now? > Okay, then let's do this now. Please go ahead. Awesome, uploaded! I'll take a look at python-pygit2 today as well. So leaves us with

Bug#971571: transition: libgit2

2020-12-09 Thread Utkarsh Gupta
Hey, On Wed, Dec 9, 2020 at 3:13 PM Utkarsh Gupta wrote: > I'll take a look at python-pygit2 today as well. So leaves us with > ruby-rugged. I'll come to that in next few days if no one beats me to > it. FWIW, I've uploaded both, thereby completing all the blockers. Hopefully this t

Re: Re: source-only uploads for future point releases (Re: Bug

2021-01-30 Thread Utkarsh Gupta
Henrique de Moraes Holschuh wrote: > But just in case, what about Jessie ELTS non-free ? A source-only upload should work and the builders would pick it from there. However, uploading to jessie now is not straightforward. There's a different repository altogether, so only those who have their

Bug#989703: unblock: eterm/0.9.6-6.1

2021-06-10 Thread Utkarsh Gupta
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Hey, src:eterm has been affected by CVE-2021-33477 which is fixed in sid & stretch. -pu update for buster has also been filed. Since this is just a CVE fix, I'd request you to unblock

Bug#989702: buster-pu: package eterm/0.9.6-5+deb10u1

2021-06-10 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Tags: buster Severity: normal Hello, src:eterm has been affected by CVE-2021-33477 which is fixed in sid & stretch. Since the version in stretch & buster is the same, I'd like to get this update into -pu in the next release

Bug#989037: unblock: rails/2:6.0.3.7+dfsg-1

2021-05-24 Thread Utkarsh Gupta
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: debian-r...@lists.debian.org Hello, Rails was recently affected by 3 CVEs (CVE-2021-2290{2,4} and CVE-2021-22885). I'm attaching a filtered diff for your review; the diff is

Bug#989036: unblock: ruby-marcel/1.0.1+dfsg-2

2021-05-24 Thread Utkarsh Gupta
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: debian-r...@lists.debian.org Hello, We had to bump ruby-marcel to a newer version because the mimemagic dependency - which relies on GPL-licensed mime type data from

Bug#989037: Bug#988214: fixed in rails 2:6.0.3.7+dfsg-1

2021-06-04 Thread Utkarsh Gupta
Hi Paul, On Fri, Jun 4, 2021 at 1:38 AM Paul Gevers wrote: > > You haven't answered my question: "does rails still work with the old > > version of ruby-marcel and can the version bump be reverted" > > Ping. Without a proper answer, I can't decide. Thanks, I'm yet to figure that out and

Bug#989037: Bug#988214: fixed in rails 2:6.0.3.7+dfsg-1

2021-07-11 Thread Utkarsh Gupta
Hi Paul, [CC'ed team@s.d.o] On Sat, Jul 10, 2021 at 1:34 AM Paul Gevers wrote: > Unblocked the latest version in unstable. Awesome, thank you so much! Just as a heads up, I'll be also filing unblock requests for ruby2.7 (already uploaded) and libjdom1-java & libjdom2-java (yet to upload). All

Bug#987489: buster-pu: package jackson-databind/2.9.8-3+deb10u3

2021-04-24 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org X-Debbugs-Cc: t...@security.debian.org, a...@debian.org Usertags: pu bsp-2021-04-AT-Salzburg Tags: buster Severity: normal Hello, src:jackson-databind has been affected by 18 CVEs which are fixed in unstable and bullseye

Bug#987471:

2021-04-24 Thread Utkarsh Gupta
user debian-release@lists.debian.org usertags -1 + bsp-2021-04-AT-Salzburg thank you

Bug#987501: unblock ruby-librarian/0.6.4-3

2021-04-24 Thread Utkarsh Gupta
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock bsp-2021-04-AT-Salzburg Hello, This upload fixes #987113 and is actually a one-liner change: ``` - project_path = Pathname.new(__FILE__).expand_path +

Bug#987494: buster-pu: package fluidsynth/1.1.11-1+deb10u1

2021-04-24 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org X-Debbugs-Cc: t...@security.debian.org, a...@debian.org Usertags: pu bsp-2021-04-AT-Salzburg Tags: buster Severity: normal Hello, src:fluidsynth has been affected by CVE-2021-28421 which is fixed in sid and unblocked for

Bug#987531: buster-pu: package opendmarc/1.3.2-6+deb10u2

2021-04-25 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Usertags: pu User: debian-release@lists.debian.org Usertags: bsp-2021-04-at-salzburg X-Debbugs-Cc: t...@security.debian.org Tags: buster Severity: normal Hello, src:opendmarc has been affected by CVE-2020-12460, which is

Bug#981271: buster-pu: package python-bottle/0.12.15-2+deb10u1

2021-01-28 Thread Utkarsh Gupta
;` anymore. (Fixes: CVE-2020-28473) + + -- Utkarsh Gupta Thu, 28 Jan 2021 20:22:22 +0530 + python-bottle (0.12.15-2) unstable; urgency=medium * Update tox dependency (Closes: #924836) diff -Nru python-bottle-0.12.15/debian/patches/CVE-2020-28473.patch python-bottle-0.12.15/debian/patches/CVE-

Bug#986146: unblock: rabbitmq-server/3.8.9-2

2021-03-30 Thread Utkarsh Gupta
Hello, Awesome, thanks for this upload, Thomas. I can confirm that this is a pure bug-fix release only and indeed fixes the problems raised, thereby making this package even better for bullseye. A huge +1 for unblocking. - u

Bug#986742: unblock: ruby2.7/2.7.3-1

2021-04-17 Thread Utkarsh Gupta
Hi Sebastian, On Sat, Apr 17, 2021 at 3:08 PM Sebastian Ramacher wrote: > Thanks, please go ahead and remove the moreinfo tag once the version is > available in unstable. Uploaded to unstable, thanks. And removed the tag as well. - u

Bug#983113: buster-pu: package ruby-mechanize/2.7.6-1+deb10u1

2021-02-19 Thread Utkarsh Gupta
/changelog2019-01-04 16:57:45.0 +0530 +++ ruby-mechanize-2.7.6/debian/changelog2021-02-19 22:47:27.0 +0530 @@ -1,3 +1,10 @@ +ruby-mechanize (2.7.6-1+deb10u1) buster; urgency=medium + + * Team upload for buster-pu. + * Add patch to prevent OS command injection. (Fixes: CVE-20

Re: Update of debian-archive-keyring in stretch?

2021-08-25 Thread Utkarsh Gupta
Hi Raphael, On Wed, Aug 25, 2021 at 11:27 PM Raphael Hertzog wrote: > it would be nice if we could get an update of debian-archive-keyring > in stretch to add the bullseye key just like it has been done in buster a > while ago: [...] > > The missing key creates problems for example with

Re: Update of debian-archive-keyring in stretch?

2021-09-14 Thread Utkarsh Gupta
Hello all, On Thu, Aug 26, 2021 at 12:33 AM Utkarsh Gupta wrote: > > The missing key creates problems for example with simple-cdd: > > https://bugs.debian.org/992966 > > Okay, I'll be happy to do the update. Though I wonder if it'd rather > be helpful in just doing a rebuild

Bug#991842: unblock: libjdom1-java/1.1.3-2.1

2021-08-03 Thread Utkarsh Gupta
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Hey, src:libjdom1-java has been affected by CVE-2021-33813 which is fixed in sid & stretch. -pu update for buster is also being filed. Since this is just a CVE fix, I'd request you to

Bug#991844: unblock: libpam-tacplus/1.3.8-2.1

2021-08-03 Thread Utkarsh Gupta
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Hey, src:libpam-tacplus has been affected by CVE-2020-13881 which is fixed in sid & stretch. -pu update for buster is also being filed. This update also helps in fixing the versioning

Bug#991843: unblock: libjdom2-java/2.0.6-1.1

2021-08-03 Thread Utkarsh Gupta
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Hey, src:libjdom2-java has been affected by CVE-2021-33813 which is fixed in sid & stretch. -pu update for buster is also being filed. Since this is just a CVE fix, I'd request you to

Bug#991844: unblock: libpam-tacplus/1.3.8-2.1

2021-08-03 Thread Utkarsh Gupta
Hi Paul, On Tue, Aug 3, 2021 at 9:46 PM Paul Gevers wrote: > On 03-08-2021 10:46, Utkarsh Gupta wrote: > > src:libpam-tacplus > > ... is not in testing. > > closing this bug as there's nothing to do (no, we're not going to let it > in now). Ugh, my bad for n

Bug#991886: buster-pu: package libpam-tacplus/1.3.8-2+deb10u1

2021-08-04 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Tags: buster Severity: normal Hello, src:libpam-tacplus has been affected by CVE-2020-13881 which is fixed in sid & stretch. Thus this -pu update for buster. This update also helps in fixing the versioning problem because

Bug#991843: unblock: libjdom2-java/2.0.6-1.1

2021-08-03 Thread Utkarsh Gupta
Hi Sebastian, On Tue, Aug 3, 2021 at 10:35 PM Sebastian Ramacher wrote: > Unstable and bullseye contain the same version of libjdom2-java. Are you > sure that the upload reached unstable? There was a bit of a fiasco and processing delay from dak (see my mail at -devel for more information) but

Re: Update of debian-archive-keyring in stretch?

2021-10-10 Thread Utkarsh Gupta
Hi Jonathan, On Tue, Oct 5, 2021 at 1:26 PM Jonathan Wiltshire wrote: > You will need (but may not want) the commit removing jessie's keys as well. > Basically all intermediate commits which touch keyrings - a removal is > really a move from the main keyring to the archive keyring, so it will >

Re: Update of debian-archive-keyring in stretch?

2021-10-02 Thread Utkarsh Gupta
Hi Jonathan, On Wed, Aug 25, 2021 at 11:27 PM Raphael Hertzog wrote: > it would be nice if we could get an update of debian-archive-keyring > in stretch to add the bullseye key just like it has been done in buster a > while ago: >

Re: Update of debian-archive-keyring in stretch?

2021-10-02 Thread Utkarsh Gupta
On Sat, Oct 2, 2021 at 9:35 PM Utkarsh Gupta wrote: > With these 3 commits, I tried to build the package and it failed > with the following error: > 8<---8<---8<---8<---8<---8<---8<---8<---8<---8<---8<---8<---8< > gpg --no-options --no-def

Re: Update of debian-archive-keyring in stretch?

2022-03-11 Thread Utkarsh Gupta
Hi Jonathan, On Mon, Oct 11, 2021 at 6:24 AM Utkarsh Gupta wrote: > On Tue, Oct 5, 2021 at 1:26 PM Jonathan Wiltshire wrote: > > You will need (but may not want) the commit removing jessie's keys as well. > > Basically all intermediate commits which touch keyrings - a remova

Bug#1028468: bullseye-pu: package tomcat9/9.0.43-2~deb11u5

2023-01-11 Thread Utkarsh Gupta
Package: release.debian.org User: release.debian@packages.debian.org Tags: bullseye Severity: normal Hello, src:tomcat9 has been affected by debbug #1020948 which was fixed in sid and thus would want to backport the fix to bullseye in the next point release. It was noticed that the

Bug#1024055: Upload MariaDB 1:10.3.37-0+deb10u1 ?

2022-12-05 Thread Utkarsh Gupta
Hi Otto, On Mon, Dec 5, 2022 at 5:33 AM Otto Kekäläinen wrote: > I didn't get a reply to this, so asking again. I could take care of the upload but if you'd like to do that, please feel free to do so and I can take care of the paperwork. One quick thing I spotted in the target in d/ch is