External check

2014-09-15 Thread Raphael Geissert
CVE-2014-6300: RESERVED -- The output might be a bit terse, but the above ids are known elsewhere, check the references in the tracker. The second part indicates the status of that id in the tracker at the moment the script was run. -- To UNSUBSCRIBE, email to

Re: Switching the tracker to git

2014-09-15 Thread Thijs Kinkhorst
On Mon, September 15, 2014 07:33, Henri Salo wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Sun, Sep 14, 2014 at 07:06:46PM -0400, micah wrote: My guess is that the only reason that subversion is still used is inertia and that people would be happier with git. However, I'm curious

Bug#611163: re: nice css: let there be patches...

2014-09-15 Thread u
Hi, See attached or branch html5+external_css from ssh://git.debian.org/git/collab-maint/secure-testing.git These patches turn the html into html5 and introduce a modern, slick css style inspired from tracker.d.o - enjoy! :) Feedback welcome! Let me just mention that Holger and me

Re: Switching the tracker to git

2014-09-15 Thread Salvatore Bonaccorso
Hi I forgot about two more points: One is the sectracker user is subscribed to the commits mailinglists, and the commit messages trigger updates of the tracker. The other thing, the svn checkout is also used for http://security-team.debian.org, but this should be a simple case. I will add all

Re: Switching the tracker to git

2014-09-15 Thread Holger Levsen
Hi, On Montag, 15. September 2014, Thijs Kinkhorst wrote: What would be the actual benefits of moving to Git and I'm not talking git log, git show, git stash and git branch and cherry-pick...!! Working with a decentralized and fast(!) version control system locally is so much more fun +

Re: RFC: Invert ordering of issues in source package view: newest should be up

2014-09-15 Thread Holger Levsen
Hi Salvatore, On Samstag, 13. September 2014, Salvatore Bonaccorso wrote: This changes the ordering in the 'Security announcements section, ordering it by release date of the DSA/DLA, right? So for example file will show with your patch: DSA / DLA Description DLA-50-1 file - security

Bug#610220: Show URLs in TODO/NOTE as hyperlinks in the web view

2014-09-15 Thread Salvatore Bonaccorso
Hi Holger, On Mon, Sep 15, 2014 at 02:32:54PM +0200, Holger Levsen wrote: On Samstag, 13. September 2014, Salvatore Bonaccorso wrote: I had a look at this patch. It can only address isolated URLs in the notes this way. We usually use this in other ways, one example is that was Florian

Bug#610220: Show URLs in TODO/NOTE as hyperlinks in the web view

2014-09-15 Thread Holger Levsen
Hi, On Montag, 15. September 2014, Salvatore Bonaccorso wrote: Hmm, would something wrapping around of the following work? sounds like a good start... Considering there might be more than one matching group in each line, so the example holds only for a simplest case again :( are there

Bug#610220: Show URLs in TODO/NOTE as hyperlinks in the web view

2014-09-15 Thread Holger Levsen
control: tags -1 + pending Hi, see attached. This version also deals with several URLs in one note :) It also works for all three recent examples of Salvatore. cheers, Holger From 7b4ea6cc46ffc1a507d94c2a13ef3c27e3123031 Mon Sep 17 00:00:00 2001 From: Holger Levsen

Processed: Re: Bug#610220: Show URLs in TODO/NOTE as hyperlinks in the web view

2014-09-15 Thread Debian Bug Tracking System
Processing control commands: tags -1 + pending Bug #610220 [security-tracker] Show URLs in TODO/NOTE as hyperlinks in the web view Added tag(s) pending. -- 610220: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610220 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#611163: nice css: let there be patches...

2014-09-15 Thread Thijs Kinkhorst
On Mon, September 15, 2014 01:36, Holger Levsen wrote: Hi, See attached or branch html5+external_css from ssh://git.debian.org/git/collab-maint/secure-testing.git These patches turn the html into html5 and introduce a modern, slick css style inspired from tracker.d.o - enjoy! :)

Bug#610220: Show URLs in TODO/NOTE as hyperlinks in the web view

2014-09-15 Thread Salvatore Bonaccorso
Hi Holger, On Mon, Sep 15, 2014 at 03:30:05PM +0200, Holger Levsen wrote: Hi, On Montag, 15. September 2014, Salvatore Bonaccorso wrote: Hmm, would something wrapping around of the following work? sounds like a good start... Considering there might be more than one matching group in

Bug#610220: Show URLs in TODO/NOTE as hyperlinks in the web view

2014-09-15 Thread Salvatore Bonaccorso
Hi Holger, On Mon, Sep 15, 2014 at 06:05:29PM +0200, Salvatore Bonaccorso wrote: Hi Holger, On Mon, Sep 15, 2014 at 03:30:05PM +0200, Holger Levsen wrote: Hi, On Montag, 15. September 2014, Salvatore Bonaccorso wrote: Hmm, would something wrapping around of the following work?

Bug#742855: Sort releases correctly in tabular view. (Closes: #742855)

2014-09-15 Thread Salvatore Bonaccorso
Hi Holger, On Mon, Sep 15, 2014 at 01:47:57AM +0200, Holger Levsen wrote: Hi Salvatore, On Samstag, 13. September 2014, Salvatore Bonaccorso wrote: I tested the patch in my local instance. yeah, it's clearly the wrong patch, I attached, sorry. libspring-java as by now, might change

Re: Switching the tracker to git

2014-09-15 Thread Florian Weimer
My guess is that the only reason that subversion is still used is inertia and that people would be happier with git. However, I'm curious to know if anyone thinks otherwise? For releasing security advisories, we need the centralized repository to gurantuee uniqness of DSA numbers. I'm also

Bug#610220: Show URLs in TODO/NOTE as hyperlinks in the web view

2014-09-15 Thread Holger Levsen
Hi Salvatore, On Montag, 15. September 2014, Salvatore Bonaccorso wrote: https://security-tracker.debian.org/tracker/CVE-2011-2825 hmpf, that works for 1 out 3, the other 2 are detected as one :/ We only have a handfull of those, so: If you find a solution to catch also these then good.

Re: RFC: Invert ordering of issues in source package view: newest should be up

2014-09-15 Thread Salvatore Bonaccorso
Hi, On Mon, Sep 15, 2014 at 02:24:34PM +0200, Holger Levsen wrote: Hi Salvatore, On Samstag, 13. September 2014, Salvatore Bonaccorso wrote: This changes the ordering in the 'Security announcements section, ordering it by release date of the DSA/DLA, right? So for example file will show

Bug#610220: Show URLs in TODO/NOTE as hyperlinks in the web view

2014-09-15 Thread Salvatore Bonaccorso
Hi, On Mon, Sep 15, 2014 at 07:59:53PM +0200, Holger Levsen wrote: Hi Salvatore, On Montag, 15. September 2014, Salvatore Bonaccorso wrote: https://security-tracker.debian.org/tracker/CVE-2011-2825 hmpf, that works for 1 out 3, the other 2 are detected as one :/ We only have a

Bug#611163: marked as done (make generated HTML CSS-friendlier)

2014-09-15 Thread Debian Bug Tracking System
Your message dated Mon, 15 Sep 2014 21:31:57 +0200 with message-id 201409152132.42383.hol...@layer-acht.org and subject line Re: Bug#611163: nice css: let there be patches... has caused the Debian Bug report #611163, regarding make generated HTML CSS-friendlier to be marked as done. This means

Bug#642987: Display end-of-live information in the web view. (Closes: #642987)

2014-09-15 Thread Holger Levsen
Hi, updated patch attached. cheers, Holger commit da14dc2780b7f3e3a1bde8cbd526eb271497fde2 Author: Holger Levsen hol...@layer-acht.org Date: Sat Sep 13 02:02:42 2014 +0200 Display end-of-life information in the web view. (Closes: #642987) diff --git a/bin/tracker_service.py

Bug#664866: #664866 security-tracker: stable-backports not present in CVE and package pages

2014-09-15 Thread Holger Levsen
control: tags -1 + pending signature.asc Description: This is a digitally signed message part.

Processed: #664866 security-tracker: stable-backports not present in CVE and package pages

2014-09-15 Thread Debian Bug Tracking System
Processing control commands: tags -1 + pending Bug #664866 [security-tracker] security-tracker: stable-backports not present in CVE and package pages. please add Added tag(s) pending. -- 664866: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=664866 Debian Bug Tracking System Contact

Bug#761730: tracker.d.o: please provide links to https://security-tracker.debian.org/tracker/source-package/$PKG

2014-09-15 Thread Holger Levsen
package: tracker.debian.org severity: wishlist x-debbugs-cc: debian-security-tracker@lists.debian.org Hi, the information gathered in the security-tracker should be displayed in the package tracker.d.o. There is an interface for it, see https://security-tracker.debian.org/tracker/data/pts/1

Bug#664866: patch for: Include squeeze- and wheezy-backports in issue and package views. (Closes: #664866)

2014-09-15 Thread Holger Levsen
Hi, we really need to refactor the codebase eventually ;-) I've thought about treating backports as subrelease, but I've came to the conclusion that would be wrong. See attached. cheers, Holger From aaee1f290a7d96f8dcdff412fd9207b0a5a77bc2 Mon Sep 17 00:00:00 2001 From: Holger

Bug#742382: Display oldstable/stable security and olstable-lts repositories in tabular view. (Closes: #742382)

2014-09-15 Thread Salvatore Bonaccorso
Hi, On Mon, Sep 15, 2014 at 11:40:59PM +0200, Holger Levsen wrote: Hi, On Samstag, 13. September 2014, Salvatore Bonaccorso wrote: I have your patch running on my testinstance and looks good so far! (But having done only some basic tests). I'd like to push this one next, as this really