Bug#888547: CVE-2017-1000190

2019-04-22 Thread Ivo De Decker
Hi, On Sun, Apr 14, 2019 at 11:57:26PM +0200, Emmanuel Bourg wrote: > Le 14/04/2019 à 23:27, Markus Koschany a écrit : > > > Simple-xml is only required to build carrotsearch-randomizedtesting. It > > is not a test-dependency though. > > > Apparently the removal makes no difference for

Bug#888547: CVE-2017-1000190

2019-04-14 Thread Emmanuel Bourg
Le 14/04/2019 à 23:27, Markus Koschany a écrit : > Simple-xml is only required to build carrotsearch-randomizedtesting. It > is not a test-dependency though. > Apparently the removal makes no difference for lucene4.10. Indeed, because carrotsearch-randomizedtesting is just a test dependency of

Bug#888547: CVE-2017-1000190

2019-04-14 Thread Markus Koschany
Hi, Am 13.04.19 um 11:31 schrieb Ivo De Decker: [...] > It is possible to remove the test-dependency (probably by disabling the > tests)? That way simple-xml could be removed from buster. Even if we don't do > this for buster, it might be good to do this for bullseye anyway, if the > package

Bug#888547: CVE-2017-1000190

2019-04-13 Thread Ivo De Decker
Hi, On Fri, Aug 24, 2018 at 01:18:09AM +0200, Emmanuel Bourg wrote: > On 23/08/2018 17:11, Markus Koschany wrote: > > > My concern is that we have an upstream project that does not even > > consider such a trivial fix. Then we have another example of a > > fire-and-forget one time upload

Bug#888547: CVE-2017-1000190

2018-08-23 Thread Emmanuel Bourg
On 23/08/2018 17:11, Markus Koschany wrote: > My concern is that we have an upstream project that does not even > consider such a trivial fix. Then we have another example of a > fire-and-forget one time upload (simple-xml) and now the package is > carried "by the team".

Bug#888547: CVE-2017-1000190

2018-08-23 Thread Markus Koschany
Am 23.08.2018 um 15:55 schrieb Emmanuel Bourg: > On 23/08/2018 13:14, Markus Koschany wrote: >> Apparently upstream doesn't consider this "to be their problem". Since >> simple-xml has no reverse-dependencies and the current uploader is MIA, >> I think we should consider requesting the removal of

Bug#888547: CVE-2017-1000190

2018-08-23 Thread Emmanuel Bourg
On 23/08/2018 13:14, Markus Koschany wrote: > Apparently upstream doesn't consider this "to be their problem". Since > simple-xml has no reverse-dependencies and the current uploader is MIA, > I think we should consider requesting the removal of simple-xml. simple-xml is a dependency of

Bug#888547: CVE-2017-1000190

2018-08-23 Thread Markus Koschany
Apparently upstream doesn't consider this "to be their problem". Since simple-xml has no reverse-dependencies and the current uploader is MIA, I think we should consider requesting the removal of simple-xml. Markus signature.asc Description: OpenPGP digital signature __ This is the maintainer