Bug#787316: marked as done (CVE-2015-1833)

2015-06-21 Thread Debian Bug Tracking System
Your message dated Mon, 22 Jun 2015 06:05:34 + with message-id and subject line Bug#787316: fixed in jackrabbit 2.10.1-1 has caused the Debian Bug report #787316, regarding CVE-2015-1833 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the c

Bug#654049: marked as done (Updating the libcommons-cli-java Uploaders list)

2015-06-21 Thread Debian Bug Tracking System
Your message dated Mon, 22 Jun 2015 06:05:40 + with message-id and subject line Bug#654049: fixed in libcommons-cli-java 1.3.1-1 has caused the Debian Bug report #654049, regarding Updating the libcommons-cli-java Uploaders list to be marked as done. This means that you claim that the problem

libcommons-cli-java_1.3.1-1_amd64.changes ACCEPTED into experimental

2015-06-21 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 22 Jun 2015 05:40:07 + Source: libcommons-cli-java Binary: libcommons-cli-java Architecture: source all Version: 1.3.1-1 Distribution: experimental Urgency: medium Maintainer: Debian Java Maintainers Changed-

jackrabbit_2.10.1-1_amd64.changes ACCEPTED into unstable

2015-06-21 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Sun, 21 Jun 2015 18:35:47 +0200 Source: jackrabbit Binary: libjackrabbit-java Architecture: source all Version: 2.10.1-1 Distribution: unstable Urgency: high Maintainer: Debian Java Maintainers Changed-By: Markus Kosc

Processing of jackrabbit_2.10.1-1_amd64.changes

2015-06-21 Thread Debian FTP Masters
jackrabbit_2.10.1-1_amd64.changes uploaded successfully to localhost along with the files: jackrabbit_2.10.1-1.dsc jackrabbit_2.10.1.orig.tar.xz jackrabbit_2.10.1-1.debian.tar.xz libjackrabbit-java_2.10.1-1_all.deb Greetings, Your Debian queue daemon (running on host franck.debian

Processing of libcommons-cli-java_1.3.1-1_amd64.changes

2015-06-21 Thread Debian FTP Masters
libcommons-cli-java_1.3.1-1_amd64.changes uploaded successfully to localhost along with the files: libcommons-cli-java_1.3.1-1.dsc libcommons-cli-java_1.3.1.orig.tar.gz libcommons-cli-java_1.3.1-1.debian.tar.xz libcommons-cli-java_1.3.1-1_all.deb Greetings, Your Debian queue daemo

Bug#789518: wagon2: FTBFS in sid

2015-06-21 Thread Markus Koschany
Source: wagon2 Version: 2.7-1 Severity: serious Tags: stretch sid Hi, while I was working on jackrabbit, I discovered that its reverse-dependency wagon2 can no longer be built from source. However this is not related to jackrabbit. Full build log is here: https://reproducible.debian.net/rb-pkg/

libparanamer-java 2.7+repack-1 MIGRATED to testing

2015-06-21 Thread Debian testing watch
FYI: The status of the libparanamer-java source package in Debian's testing distribution has changed. Previous version: (not in testing) Current version: 2.7+repack-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple time

libpicocontainer-java 2.15-1 MIGRATED to testing

2015-06-21 Thread Debian testing watch
FYI: The status of the libpicocontainer-java source package in Debian's testing distribution has changed. Previous version: (not in testing) Current version: 2.15-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times

robocode 1.9.2.4-2 MIGRATED to testing

2015-06-21 Thread Debian testing watch
FYI: The status of the robocode source package in Debian's testing distribution has changed. Previous version: 1.6.2+dfsg2-1 Current version: 1.9.2.4-2 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you wil

surefire 2.17-2 MIGRATED to testing

2015-06-21 Thread Debian testing watch
FYI: The status of the surefire source package in Debian's testing distribution has changed. Previous version: 2.17-1 Current version: 2.17-2 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive

Bug#789514: jaffl: Please remove this package from the archive

2015-06-21 Thread Miguel Landaeta
Package: src:jaffl Version: 0.5.9-8 Severity: serious This is mostly a reminder, remove this package since it has been superseded by jnr-ffi. -- System Information: Debian Release: 8.1 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable') Architecture: amd64 (x86_64)

Bug#789513: mustache-java: Please replace dependencies on jaffl with jnr-ffi

2015-06-21 Thread Miguel Landaeta
Package: src:mustache-java Version: 0.8.17-3 Severity: important As title says. -- System Information: Debian Release: 8.1 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 4.0.0-1-amd64 (SMP w/2 CPU cores) Locale: LANG

Bug#789512: jnr-netdb: Please replace dependencies on jaffl with jnr-ffi

2015-06-21 Thread Miguel Landaeta
Package: src:jnr-netdb Version: 1.1.4-1 Severity: important As title says. -- System Information: Debian Release: 8.1 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 4.0.0-1-amd64 (SMP w/2 CPU cores) Locale: LANG=en_U

libjnr-posix-java REMOVED from testing

2015-06-21 Thread Debian testing watch
FYI: The status of the libjnr-posix-java source package in Debian's testing distribution has changed. Previous version: 1.1.8-3 Current version: (not in testing) Hint: (no removal hint found) The script that generates this mail tries to extract removal reasons from comments in the britney

Bug#789511: gradle: Please replace dependencies on jaffl with jnr-ffi

2015-06-21 Thread Miguel Landaeta
Package: src:gradle Version: 1.5-2 Severity: important As title says. -- System Information: Debian Release: 8.1 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 4.0.0-1-amd64 (SMP w/2 CPU cores) Locale: LANG=en_US.UTF

Bug#789510: eclipse-pydev: Please replace dependencies on jaffl with jnr-ffi

2015-06-21 Thread Miguel Landaeta
Package: src:eclipse-pydev Version: 3.9.2-2 Severity: important As title says. -- System Information: Debian Release: 8.1 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 4.0.0-1-amd64 (SMP w/2 CPU cores) Locale: LANG=

jnr-posix 3.0.10-2 MIGRATED to testing

2015-06-21 Thread Debian testing watch
FYI: The status of the jnr-posix source package in Debian's testing distribution has changed. Previous version: (not in testing) Current version: 3.0.10-2 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you

jsch 0.1.53-1 MIGRATED to testing

2015-06-21 Thread Debian testing watch
FYI: The status of the jsch source package in Debian's testing distribution has changed. Previous version: 0.1.52-1 Current version: 0.1.53-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive

Bug#789509: libjnr-posix-java: Please remove this package from the archive

2015-06-21 Thread Miguel Landaeta
Package: src:libjnr-posix-java Version: 1.1.8-3 Severity: serious This is mostly a reminder, remove this package since it has been superseded by jnr-posix. -- System Information: Debian Release: 8.1 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable') Architecture:

jblas 1.2.3-6 MIGRATED to testing

2015-06-21 Thread Debian testing watch
FYI: The status of the jblas source package in Debian's testing distribution has changed. Previous version: 1.2.3-5 Current version: 1.2.3-6 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive l

jsch-agent-proxy 0.0.8-1 MIGRATED to testing

2015-06-21 Thread Debian testing watch
FYI: The status of the jsch-agent-proxy source package in Debian's testing distribution has changed. Previous version: 0.0.7-1 Current version: 0.0.8-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you wil

Bug#789485: jruby: Don't bundle all jruby dependencies inside jruby-core jar file

2015-06-21 Thread Miguel Landaeta
On Sun, Jun 21, 2015 at 04:38:24PM +0200, Emmanuel Bourg wrote: > Hi Emmanuel, > It looks like the embedded dependencies are also relocated under the > org.jruby namespace. Removing them could lead to incompatibilities with > applications importing them. That's right, I don't intend to diverge

Bug#789485: jruby: Don't bundle all jruby dependencies inside jruby-core jar file

2015-06-21 Thread Emmanuel Bourg
Le 21/06/2015 15:31, Miguel Landaeta a écrit : > This is a bad practice that can lead to bugs due to outdated > dependencies or security bugs when dependencies are patched > but jruby is not rebuild. > > This also should reduce jruby binary package size. It looks like the embedded dependencies a

Bug#789485: jruby: Don't bundle all jruby dependencies inside jruby-core jar file

2015-06-21 Thread Miguel Landaeta
Package: jruby Severity: normal This is a bad practice that can lead to bugs due to outdated dependencies or security bugs when dependencies are patched but jruby is not rebuild. This also should reduce jruby binary package size. -- System Information: Debian Release: 8.1 APT prefers stable-u

Bug#788471: elasticsearch: CVE-2015-4165: unspecified arbitrary files modification vulnerability

2015-06-21 Thread Hilko Bengen
* Salvatore Bonaccorso: > Did you had a chance to get more details on it? ,[ http://seclists.org/bugtraq/2015/Jun/53 ] | Elasticsearch versions 1.0.0 - 1.5.2 are vulnerable to an engineered | attack on other applications on the system. The snapshot API may be used | indirectly to place snapsh