Bug#740955: no subject

2014-07-23 Thread Potter, Tim (Cloud Services)
This is bugging me as well, and I've figured out the root cause. The maven2 package runs update-alternatives with a priority of 200, and maven (3) with a priority of 150. If you install maven2 and maven at the same time, you will always get maven2. Since maven2 is a dependency for

Bug#759736: elasticsearch: CVE-2014-3120

2014-09-01 Thread Potter, Tim (Cloud Services)
On 30/08/14 5:37 AM, Salvatore Bonaccorso car...@debian.org wrote: Source: elasticsearch Severity: grave Tags: security upstream fixed-upstream Hi Hilko, I see elasticsearch entered unstable now. Some time ago the following vulnerability was published for elasticsearch. CVE-2014-3120[0]: | The

Bug#759736: elasticsearch: CVE-2014-3120

2014-09-01 Thread Potter, Tim (Cloud Services)
On 2/09/14 2:19 AM, tony mancill tmanc...@debian.org wrote: CVE-2014-3120[0]: | The default configuration in Elasticsearch before 1.2 enables dynamic | scripting, which allows remote attackers to execute arbitrary MVEL | expressions and Java code via the source parameter to _search. NOTE: |

Bug#773131: jruby: Update it to 1.7.17 or more recent release

2014-12-16 Thread Potter, Tim (Cloud Services)
On 16/12/14 3:48 PM, tony mancill tmanc...@debian.org wrote: On 12/14/2014 12:39 PM, Miguel Landaeta wrote: Package: src:jruby Version: 1.5.6-9 Severity: wishlist I need a recent jruby version so I'll give a try to update this package. It's going to take time as anything related with

Bug#773131:

2015-01-23 Thread Potter, Tim (Cloud Services)
On 24 Jan 2015, at 1:57 am, Miguel Landaeta nomad...@debian.org wrote: On Fri, Jan 23, 2015 at 06:21:34AM +, Potter, Tim (Cloud Services) wrote: Just a quick update for the dependencies I’m working on. [...] * jnr-enxio, jnr-unixsocket, packaged and pushed to pkg-java While

Bug#773131: jruby: Update it to 1.7.17 or more recent release

2015-01-19 Thread Potter, Tim (Cloud Services)
On 19/12/14 12:11 PM, Miguel Landaeta nomad...@debian.org wrote: Thanks for info, Tony and Tim! When I begin to work on those dependencies I'll ping you again to let you know to coordinate and avoid work duplication. Hi Miguel. I've just been going over the status of jruby1.7 and the work

Bug#773131:

2015-01-22 Thread Potter, Tim (Cloud Services)
Just a quick update for the dependencies I’m working on. * jffi, packaged version 1.2.7 and pushed to the pkg-java repo as jffi-1.2.7. Waiting for some direction on whether to merge over the old version, which I expect will be the way to go This is a dependency for the remaining jnr-*

Bug#776081:

2015-01-26 Thread Potter, Tim (Cloud Services)
The current version of the libconstantine-java package is in the (old?) pkg-java subversion repository. Let’s move it to git, and update to 0.8.6. However the package has been renamed to jnr-constants in 2011-2012. View the git commit log to see the gradual deprecation of the name

Bug#779112: closed by Tim Potter t...@hp.com (Bug#779112: fixed in jnr-constants 0.8.6-3)

2015-03-05 Thread Potter, Tim (Cloud Services)
On 6/03/15 6:37 AM, Andreas Beckmann a...@debian.org wrote: On 2015-03-05 04:21, Debian Bug Tracking System wrote: * Change dependency on libconstantine-java to Conflicts, from Breaks. (Closes: #779112). No. Breaks should have been sufficient, but you are still missing a Replaces.

Bug#663342: /usr/lib/ruby/vendor_ruby now in $LOAD_PATH

2015-05-27 Thread Potter, Tim (Cloud Services)
It looks like this has been fixed, at least in sid: root@56264f4d8fa9:/Source/pkg-java/jruby# cat /etc/issue Debian GNU/Linux 8 \n \l root@56264f4d8fa9:/Source/pkg-java/jruby# ruby -v ruby 2.1.5p273 (2014-11-13) [x86_64-linux-gnu] root@56264f4d8fa9:/Source/pkg-java/jruby# irb irb(main):001:0