Who's using Debian

2024-03-21 Thread Salvatore Bonaccorso
Hi We would like to add an entry for https://www.debian.org/users/ for our organization, with the following information: Organization: Swiss Federal Institute of Technology Zurich, Department of Information Technology and Electrical Engineering (D-ITET), ETH Zurich, Switzerland Organization

Re: new redirects for www.d.o/security and www.d.o/lts/security

2024-01-05 Thread Salvatore Bonaccorso
Hi Thomas, On Fri, Jan 05, 2024 at 12:06:58AM +0100, Thomas Lange wrote: > Hi all, > > we now redirect all DSA/DLA URLs under security and lts/security with > or without having the year in the path and with or without a version > to their announcement mail: > Examples: > /security/dsa-5576 >

Re: upcoming changes of the web pages /security and /lts/security

2023-12-26 Thread Salvatore Bonaccorso
Hi Thomas, On Mon, Dec 25, 2023 at 09:14:51PM +0100, Thomas Lange wrote: > Hi all, > > as announced on Dec 7th, I have now removed the old index.wml files > and renamed new.wml to index.wml in the webwml repository under > security/ and lts/security/. > >

Re: https://security-team.debian.org/ needs an update

2023-09-14 Thread Salvatore Bonaccorso
Hi, On Tue, Sep 12, 2023 at 12:04:18PM -0400, Boyuan Yang wrote: > Hi, > > This website is managed by Debian Security Team. Forwarding your mail there. > > Meanwhile, you are welcome to contribute to this website at >

Re: sources.list 4 bullseye-security

2021-07-04 Thread Salvatore Bonaccorso
Hi Paul, On Sun, Jul 04, 2021 at 05:27:56AM +, Paul Wise wrote: > On Sat, Jul 3, 2021 at 9:31 PM Salvatore Bonaccorso wrote: > > > I have pushed > > https://salsa.debian.org/webmaster-team/webwml/-/commit/4ca2253325130f7e96bf2644d31cf5a95fdf7bcc > > Note th

Re: sources.list 4 bullseye-security

2021-07-03 Thread Salvatore Bonaccorso
Hi, On Sun, Jun 27, 2021 at 04:52:26PM -0400, Boyuan Yang wrote: > Hi, > > (This email originally appears on > https://lists.debian.org/debian-www/2021/05/msg00017.html ) > > 在 2021-05-15星期六的 12:47 +0200,Harald Dunkel写道: > > Hi folks, > > > > Obviously > > > >

Bug#985427: Wrong DLA number for spice CVEs

2021-03-18 Thread Salvatore Bonaccorso
For the record, the security-tracker ships the authoritative assignment, they are: [31 Aug 2018] DLA-1488-1 mariadb-10.0 - security update {CVE-2018-3058 CVE-2018-3063 CVE-2018-3064 CVE-2018-3066} [jessie] - mariadb-10.0 10.0.36-0+deb8u1 [31 Aug 2018] DLA-1486-1 spice - security

Bug#859122: about 500 DLAs missing from the website

2019-02-11 Thread Salvatore Bonaccorso
tation in the security tracker so the new URL paths are used from > now on is also needed. I have the attached patch commited in a local branch, but want first to confirm is this the final intended URL to reach the DLAs? Regards, Salvatore >From ceda9e3d1fc38f505462bce8c0aa4cdd2b165d87 M

Re: about 500 DLAs missing from the website

2019-02-03 Thread Salvatore Bonaccorso
Hi Antoinie, [adding team@s.d.o to CC] Thanks for working on this. On Fri, Feb 01, 2019 at 01:44:10PM -0500, Antoine Beaupré wrote: > On 2018-12-19 18:05:36, Antoine Beaupré wrote: > > The DLAs are visible here: > > > > https://www-staging.debian.org/security/2018/dla-1580 > > > > One thing

Bug#910467: www.debian.org: security/2018/dsa-4309.wml points twice to CVE-2018-16151

2018-10-06 Thread Salvatore Bonaccorso
Hi, On Sat, Oct 06, 2018 at 08:11:48PM +0200, Rafa wrote: > Package: www.debian.org > Severity: minor > > Dear Maintainers, > > Page security/2018/dsa-4309.wml points twice to CVE-2018-16151. It probably > should point to CVE-2018-16151 and to CVE-2018-16152, instead. Yes that is right, I have

Re: Stretch 9.2 announcement: dead link for ruby-rack-cors DSA

2017-10-11 Thread Salvatore Bonaccorso
Hi Adam, On Wed, Oct 11, 2017 at 09:15:08PM +0100, Adam D. Barratt wrote: > On Wed, 2017-10-11 at 22:08 +0200, Holger Wansing wrote: > > at https://www.debian.org/News/2017/20171007 the DSA link for ruby- > > rack-cors > > is dead: > > > > https://www.debian.org/security/2017/dsa-3931 > > > >

https://www.debian.org/distrib/archive: Link to Debian Archives should be plain HTTP transport protocol

2017-07-21 Thread Salvatore Bonaccorso
Hi [In case needed, please CC me on replies, not subscribed to the list] The link to the Debian Archives on https://www.debian.org/distrib/archive should not be available via https. Details can be found at https://lists.debian.org/debian-user/2017/03/msg00306.html . archive.debian.org is not

Re: typo: DSA-3688-1 nss update

2016-10-08 Thread Salvatore Bonaccorso
Hi It's actually not a typo, but we might have better used a wording like 2:3.23-1 or earlier versions. In fact it is that the jessie-security upload fixes the mentioned issues in the 2:3.26-1+debu8u1. But for unstable fixes were included in versions 2:3.19.1-1, 2:3.20.1-1, 2:3.21-1 or 2:3.23-1.

Bug#509139: link for package browser on http://www.debian.org/devel/todo/

2008-12-18 Thread Salvatore Bonaccorso
Package: www.debian.org Severity: minor Hi On http://www.debian.org/devel/todo/ in the section regarding the The Debian package browser, two links are not working (at least at the point of writing this report). First the links still have to be tagged