DSA candidates

2018-11-05 Thread Security Tracker
ansible/stable -- cairo/stable -- chromium-browser/stable -- gettext/stable -- golang-golang-x-net-dev/stable -- icu/stable -- libapache-mod-jk/stable -- libapache2-mod-perl2/stable -- liblivemedia/stable -- libsdl2-image/stable -- mini-httpd/stable -- mkvtoolnix/stable -- mupdf/stable --

Re: DLA link is broken

2018-11-05 Thread Salvatore Bonaccorso
Hi, On Tue, Nov 06, 2018 at 04:11:02AM +0900, Hideki Yamane wrote: > Hi, > > DLA link is broken. > e.g. https://security-tracker.debian.org/tracker/DLA-1445-1 page > "Source Debian LTS" points to > https://www.debian.org/security/2018/dla-1445 > but there's no such page. Cf. #762255

Re: Gaps in security coverage?

2018-11-05 Thread Paul Wise
On Mon, 2018-11-05 at 20:52 -0600, John Goerzen wrote: > That is good advice, thanks. I've been a DD for a long while, but it's > been awhile (years) since I've been involved in the security process and > wasn't quite sure what the flow was anymore. It is still mostly the same but the security

Re: Gaps in security coverage?

2018-11-05 Thread John Goerzen
On Tue, Nov 06 2018, Paul Wise wrote: > On Mon, Nov 5, 2018 at 10:29 PM John Goerzen wrote: > >> Hi folks, > > FTR, in case you were trying to contact the Debian Security Team > directly I suggest using secur...@debian.org or > t...@security.debian.org instead, debian-security is more of a

Re: Gaps in security coverage?

2018-11-05 Thread Paul Wise
On Mon, Nov 5, 2018 at 10:29 PM John Goerzen wrote: > Hi folks, FTR, in case you were trying to contact the Debian Security Team directly I suggest using secur...@debian.org or t...@security.debian.org instead, debian-security is more of a general security discussion list than a Debian Security

Gaps in security coverage?

2018-11-05 Thread John Goerzen
Hi folks, So I recently started running debsecan on one of my boxes. It's a fairly barebones server install, uses unattended-upgrades and is fully up-to-date. I expected a clean bill of health, but didn't get that. I got pages and pages and pages of output. Some of it (especially kernel