[Pkg-javascript-devel] pkg-js-tools_0.9.16~bpo10+1_sourceonly.changes ACCEPTED into buster-backports

2019-10-03 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Fri, 04 Oct 2019 06:50:13 +0200 Source: pkg-js-tools Architecture: source Version: 0.9.16~bpo10+1 Distribution: buster-backports Urgency: medium Maintainer: Debian Javascript Maintainers Changed-By: Xavier Guimard

[Pkg-javascript-devel] Processing of pkg-js-tools_0.9.16~bpo10+1_sourceonly.changes

2019-10-03 Thread Debian FTP Masters
pkg-js-tools_0.9.16~bpo10+1_sourceonly.changes uploaded successfully to localhost along with the files: pkg-js-tools_0.9.16~bpo10+1.dsc pkg-js-tools_0.9.16~bpo10+1.tar.xz Greetings, Your Debian queue daemon (running on host usper.debian.org) -- Pkg-javascript-devel mailing list

[Pkg-javascript-devel] pkg-js-tools 0.9.16 MIGRATED to testing

2019-10-03 Thread Debian testing watch
FYI: The status of the pkg-js-tools source package in Debian's testing distribution has changed. Previous version: 0.9.14 Current version: 0.9.16 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will

[Pkg-javascript-devel] node-rollup-plugin-node-resolve 3.4.0-2 MIGRATED to testing

2019-10-03 Thread Debian testing watch
FYI: The status of the node-rollup-plugin-node-resolve source package in Debian's testing distribution has changed. Previous version: 3.4.0-1 Current version: 3.4.0-2 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple

[Pkg-javascript-devel] node-rollup-plugin-replace 2.2.0-3 MIGRATED to testing

2019-10-03 Thread Debian testing watch
FYI: The status of the node-rollup-plugin-replace source package in Debian's testing distribution has changed. Previous version: 2.2.0-2 Current version: 2.2.0-3 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a

[Pkg-javascript-devel] node-rollup-plugin-json 4.0.0-3 MIGRATED to testing

2019-10-03 Thread Debian testing watch
FYI: The status of the node-rollup-plugin-json source package in Debian's testing distribution has changed. Previous version: 4.0.0-2 Current version: 4.0.0-3 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day

[Pkg-javascript-devel] Bug#941700: Update babel to version 7

2019-10-03 Thread Evgeny Kapun
Source: node-babel Version: 6.26.0+dfsg-3 Severity: important Babel 7 was released more than a year ago, so perhaps it's time to package the new version. -- Pkg-javascript-devel mailing list Pkg-javascript-devel@alioth-lists.debian.net

[Pkg-javascript-devel] [bts-link] source package node-browserify-lite

2019-10-03 Thread debian-bts-link
# # bts-link upstream status pull for source package node-browserify-lite # see http://lists.debian.org/debian-devel-announce/2006/05/msg1.html # https://bts-link-team.pages.debian.net/bts-link/ # user debian-bts-l...@lists.debian.org # remote status report for #941309

[Pkg-javascript-devel] [bts-link] source package node-typescript

2019-10-03 Thread debian-bts-link
# # bts-link upstream status pull for source package node-typescript # see http://lists.debian.org/debian-devel-announce/2006/05/msg1.html # https://bts-link-team.pages.debian.net/bts-link/ # user debian-bts-l...@lists.debian.org # remote status report for #930268

[Pkg-javascript-devel] Bug#941683: buster-pu: package node-yarnpkg/1.13.0-1+deb10u1

2019-10-03 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Hi, node-yarnpkg is vulnerable: it exports auth data in http requests (#941354, CVE-2019-5448). This patch imports upstream fix. Cheers, Xavier diff --git a/debian/changelog

[Pkg-javascript-devel] Bug#941354: node-yarnpkg: CVE-2019-5448

2019-10-03 Thread Salvatore Bonaccorso
Hi Xavier, On Thu, Oct 03, 2019 at 06:27:40PM +0200, Xavier wrote: > Hi, > > I don't know if you want to DSA this bug. Anyway here is the patch. I think we can have this schedule via next point releases as well. Regards, Salvatore -- Pkg-javascript-devel mailing list

[Pkg-javascript-devel] node-yarnpkg_1.19.0-1~exp1_source.changes REJECTED

2019-10-03 Thread Debian FTP Masters
ACL dm: NEW uploads are not allowed node-yarnpkg_1.19.0.orig-decode-uri-component.tar.gz is only available in NEW. node-yarnpkg_1.19.0.orig-decode-uri-component.tar.gz is only available in NEW. === Please feel free to respond to this email if you don't understand why your files were rejected,

[Pkg-javascript-devel] Processing of node-yarnpkg_1.19.0-1~exp1_source.changes

2019-10-03 Thread Debian FTP Masters
node-yarnpkg_1.19.0-1~exp1_source.changes uploaded successfully to localhost along with the files: node-yarnpkg_1.19.0-1~exp1.dsc node-yarnpkg_1.19.0.orig-babel-plugin-transform-inline-imports-commonjs.tar.gz node-yarnpkg_1.19.0.orig-decode-uri-component.tar.gz

[Pkg-javascript-devel] Bug#941354: node-yarnpkg: CVE-2019-5448

2019-10-03 Thread Xavier
Hi, I don't know if you want to DSA this bug. Anyway here is the patch. Cheers, Xavier https://bugs.debian.org/941354 https://security-tracker.debian.org/tracker/CVE-2019-5448 diff --git a/debian/changelog b/debian/changelog index 01fe7d70d..464a7c745 100644 --- a/debian/changelog +++

Re: [Pkg-javascript-devel] strange behavior of gbp import-orig --uscan --pristine-tar

2019-10-03 Thread Xavier
More simple : salsa co node-yarnpkg; uscan; ... Le 3 octobre 2019 12:56:50 GMT+02:00, Paolo Greppi a écrit : >On 03/10/19 10:19, Xavier wrote: >> Never use gbp --uscan, totally buggy. Préfet uscan, then gbp >import-orig ../xx.orig.tard.gz > >Thanks for the quick reply. It is indeed a

Re: [Pkg-javascript-devel] strange behavior of gbp import-orig --uscan --pristine-tar

2019-10-03 Thread Paolo Greppi
On 03/10/19 10:19, Xavier wrote: > Never use gbp --uscan, totally buggy. Préfet uscan, then gbp import-orig > ../xx.orig.tard.gz Thanks for the quick reply. It is indeed a git-buildpackage bug: https://bugs.debian.org/934200 For future reference, this worked: cd `mktemp -d` git clone

Re: [Pkg-javascript-devel] strange behavior of gbp import-orig --uscan --pristine-tar

2019-10-03 Thread Xavier
Never use gbp --uscan, totally buggy. Préfet uscan, then gbp import-orig ../xx.orig.tard.gz Le 3 octobre 2019 09:57:17 GMT+02:00, Paolo Greppi a écrit : >I do this: > >cd `mktemp -d` >git clone https://salsa.debian.org/js-team/node-yarnpkg >cd node-yarnpkg >git checkout -b upstream

[Pkg-javascript-devel] strange behavior of gbp import-orig --uscan --pristine-tar

2019-10-03 Thread Paolo Greppi
I do this: cd `mktemp -d` git clone https://salsa.debian.org/js-team/node-yarnpkg cd node-yarnpkg git checkout -b upstream origin/upstream git checkout upstream git pull git checkout master gbp import-orig --uscan --pristine-tar at the end of the process, the master branch is screwed: grep name