[Pkg-javascript-devel] Bug#898315: node-mixin-deep: CVE-2018-3719: Prototype pollution via merging functions

2018-05-10 Thread Salvatore Bonaccorso
Source: node-mixin-deep Version: 1.1.3-1 Severity: important Tags: security upstream Forwarded: https://nodesecurity.io/advisories/578 Hi, The following vulnerability was published for node-mixin-deep. CVE-2018-3719[0]: Prototype pollution via merging functions If you fix the vulnerability

Re: [Pkg-javascript-devel] Problems to recreate minimized JS in r-cran-jsonld

2018-05-10 Thread Pirate Praveen
On Wed, May 9, 2018 at 3:05 PM, Andreas Tille wrote: Hi, I was stumbling upon an issue with some minimized JS in the package r-cran-jsonld (ITPed in #898224). I tried to recreate jsonld.min.js and have written a script[1] which calls webpack in a clone of the Github

Re: [Pkg-javascript-devel] Problems to recreate minimized JS in r-cran-jsonld

2018-05-10 Thread Pirate Praveen
On Thu, May 10, 2018 at 2:31 PM, Andreas Tille wrote: > jsonld.js does not work. The file size of this uncompressed file is way > smaller than the minimazion result and doese not work together with the > R code. Thus I really need to undergo the process to create

[Pkg-javascript-devel] Processed: Reopen

2018-05-10 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reopen 887586 ro...@debian.org Bug #887586 {Done: Bastien Roucariès } [mocha] mocha 4.0.1-3 causes build hangs in various build-rdeps 'reopen' may be inappropriate when a bug has been closed with a version; all fixed versions

[Pkg-javascript-devel] node-cookie-parser_1.4.3-1_source.changes ACCEPTED into unstable

2018-05-10 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Thu, 10 May 2018 14:45:21 +0200 Source: node-cookie-parser Binary: node-cookie-parser Architecture: source Version: 1.4.3-1 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers

Re: [Pkg-javascript-devel] nodejs >= 6 for gitlab in stretch-backports

2018-05-10 Thread Pirate Praveen
On Thu, May 10, 2018 at 1:22 PM, Jérémy Lal wrote: Yes the server is setup by the tests. Anyway if local interface was not setup, you would have seen more test failures, so that was a bad suggestion. A better idea: this test might be depending on some libc-ares2 recent

Re: [Pkg-javascript-devel] nodejs >= 6 for gitlab in stretch-backports

2018-05-10 Thread Pirate Praveen
On Thu, May 3, 2018 at 3:19 PM, Jérémy Lal wrote: 2018-05-03 11:32 GMT+02:00 Pirate Praveen : On ബു, മേയ് 2, 2018 at 9:04 വൈകു, Jérémy Lal wrote: Correction: nodejs 8.11 supports both openssl 1.0.1 or openssl >= 1.1.0g.

Re: [Pkg-javascript-devel] nodejs >= 6 for gitlab in stretch-backports

2018-05-10 Thread Jérémy Lal
2018-05-10 9:15 GMT+02:00 Pirate Praveen : > > > On Thu, May 3, 2018 at 3:19 PM, Jérémy Lal wrote: > > > > 2018-05-03 11:32 GMT+02:00 Pirate Praveen : > >> >> >> On ബു, മേയ് 2, 2018 at 9:04 വൈകു, Jérémy Lal

Re: [Pkg-javascript-devel] Packages ready to review

2018-05-10 Thread Paolo Greppi
Il 09/05/2018 10:30, Paolo Greppi ha scritto: > ... > Of course before we make it part of our workflow, the manual bits have to be > streamlined. > > There are some python scripts that you can use to sync the BTS bugs to gitlab > issues: >

[Pkg-javascript-devel] Processing of node-body-parser_1.18.2-1_source.changes

2018-05-10 Thread Debian FTP Masters
node-body-parser_1.18.2-1_source.changes uploaded successfully to localhost along with the files: node-body-parser_1.18.2-1.dsc node-body-parser_1.18.2.orig.tar.gz node-body-parser_1.18.2-1.debian.tar.xz node-body-parser_1.18.2-1_source.buildinfo Greetings, Your Debian queue

[Pkg-javascript-devel] libuv1_1.18.0-3~bpo9+1_amd64.changes is NEW

2018-05-10 Thread Debian FTP Masters
binary:libuv1 is NEW. binary:libuv1-dev is NEW. binary:libuv1-dev is NEW. binary:libuv1 is NEW. source:libuv1 is NEW. Your package has been put into the NEW queue, which requires manual action from the ftpteam to process. The upload was otherwise valid (it had a good OpenPGP signature and file

[Pkg-javascript-devel] Bug#894932: marked as done (Quoting fixed in autopkgtest 5.2)

2018-05-10 Thread Debian Bug Tracking System
Your message dated Thu, 10 May 2018 17:19:57 + with message-id

[Pkg-javascript-devel] nodejs_10.0.0~dfsg1-4_source.changes ACCEPTED into experimental

2018-05-10 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Thu, 10 May 2018 20:49:20 +0200 Source: nodejs Binary: nodejs-dev libnode64-dev nodejs libnode64 nodejs-doc Architecture: source Version: 10.0.0~dfsg1-4 Distribution: experimental Urgency: medium Maintainer: Debian

Re: [Pkg-javascript-devel] New version of node-tape breaks autopkgtests of node-sha.js in testing

2018-05-10 Thread Paul Gevers
Hmm, a retry was already triggered. It was already picked up in the last run. You can ignore this e-mail. Paul On 10-05-18 20:14, Paul Gevers wrote: > Dear maintainers, > > [This e-mail is automatically sent. V2 (20180508)] > > As recently announced [1] Debian is now running autopkgtests in

[Pkg-javascript-devel] New version of node-tape breaks autopkgtests of node-sha.js in testing

2018-05-10 Thread Paul Gevers
Dear maintainers, [This e-mail is automatically sent. V2 (20180508)] As recently announced [1] Debian is now running autopkgtests in testing to check if the migration of a new source package causes regressions. It does this with the binary packages of the new version of the source package from

Re: [Pkg-javascript-devel] Problems to recreate minimized JS in r-cran-jsonld

2018-05-10 Thread David I. Lehn
On Wed, May 9, 2018 at 5:35 AM, Andreas Tille wrote: > I was stumbling upon an issue with some minimized JS in the package > r-cran-jsonld (ITPed in #898224). I tried to recreate jsonld.min.js and > have written a script[1] which calls webpack in a clone of the Github >

[Pkg-javascript-devel] RFC: vue.js

2018-05-10 Thread Paolo Greppi
Hi all, no it's not a typo: it's really a RFC (request for comment). I have packaged the vue.js library: https://salsa.debian.org/js-team/vue.js but rather than ask for sponsorship from a DD [1] this time I am asking for comments from ALL members of the js-team, be you a guest or a member, a DM

[Pkg-javascript-devel] Processing of nodejs_10.0.0~dfsg1-4_source.changes

2018-05-10 Thread Debian FTP Masters
nodejs_10.0.0~dfsg1-4_source.changes uploaded successfully to localhost along with the files: nodejs_10.0.0~dfsg1-4.dsc nodejs_10.0.0~dfsg1-4.debian.tar.xz nodejs_10.0.0~dfsg1-4_source.buildinfo Greetings, Your Debian queue daemon (running on host usper.debian.org) --

[Pkg-javascript-devel] Bug#887586: Fixed

2018-05-10 Thread Bastien ROUCARIES
control: affects -1 - src:node-connect On Thu, May 10, 2018 at 9:57 PM, Bastien ROUCARIES wrote: > control: affects -1 - src:node-cookie-parser -- Pkg-javascript-devel mailing list Pkg-javascript-devel@alioth-lists.debian.net

Re: [Pkg-javascript-devel] Problems to recreate minimized JS in r-cran-jsonld

2018-05-10 Thread Andreas Tille
Hi David, On Thu, May 10, 2018 at 02:42:29PM -0400, David I. Lehn wrote: > On Wed, May 9, 2018 at 5:35 AM, Andreas Tille wrote: > > I was stumbling upon an issue with some minimized JS in the package > > r-cran-jsonld (ITPed in #898224). I tried to recreate jsonld.min.js

[Pkg-javascript-devel] Bug#887586: Fixed

2018-05-10 Thread Bastien ROUCARIES
control: affects -1 - src:node-connect-timeout On Thu, May 10, 2018 at 11:34 PM, Bastien ROUCARIES wrote: > control: affects -1 - src:node-connect > > On Thu, May 10, 2018 at 9:57 PM, Bastien ROUCARIES > wrote: >> control: affects -1 -

[Pkg-javascript-devel] Processed: Re: Bug#887586: Fixed

2018-05-10 Thread Debian Bug Tracking System
Processing control commands: > affects -1 - src:node-connect-timeout Bug #887586 [mocha] mocha 4.0.1-3 causes build hangs in various build-rdeps Removed indication that 887586 affects src:node-connect-timeout -- 887586: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=887586 Debian Bug

[Pkg-javascript-devel] Processing of node-connect-timeout_1.9.0-1_source.changes

2018-05-10 Thread Debian FTP Masters
node-connect-timeout_1.9.0-1_source.changes uploaded successfully to localhost along with the files: node-connect-timeout_1.9.0-1.dsc node-connect-timeout_1.9.0.orig.tar.gz node-connect-timeout_1.9.0-1.debian.tar.xz node-connect-timeout_1.9.0-1_source.buildinfo Greetings, Your

[Pkg-javascript-devel] Processing of node-chokidar_1.7.0-2_source.changes

2018-05-10 Thread Debian FTP Masters
node-chokidar_1.7.0-2_source.changes uploaded successfully to localhost along with the files: node-chokidar_1.7.0-2.dsc node-chokidar_1.7.0-2.debian.tar.xz node-chokidar_1.7.0-2_source.buildinfo Greetings, Your Debian queue daemon (running on host usper.debian.org) --

[Pkg-javascript-devel] Bug#887586: marked as done (mocha 4.0.1-3 causes build hangs in various build-rdeps)

2018-05-10 Thread Debian Bug Tracking System
Your message dated Fri, 11 May 2018 00:16:23 +0200 with message-id

[Pkg-javascript-devel] node-chokidar_1.7.0-2_source.changes ACCEPTED into unstable

2018-05-10 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Fri, 11 May 2018 00:01:44 +0200 Source: node-chokidar Binary: node-chokidar Architecture: source Version: 1.7.0-2 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers

[Pkg-javascript-devel] nodejs_10.1.0~dfsg-1_source.changes ACCEPTED into experimental

2018-05-10 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Thu, 10 May 2018 22:56:08 +0200 Source: nodejs Binary: nodejs-dev libnode64-dev nodejs libnode64 nodejs-doc Architecture: source Version: 10.1.0~dfsg-1 Distribution: experimental Urgency: medium Maintainer: Debian

[Pkg-javascript-devel] node-connect_3.6.7-1_source.changes ACCEPTED into unstable

2018-05-10 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Thu, 10 May 2018 23:28:55 +0200 Source: node-connect Binary: node-connect Architecture: source Version: 3.6.7-1 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers

[Pkg-javascript-devel] node-connect-timeout_1.9.0-1_source.changes ACCEPTED into unstable

2018-05-10 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Thu, 10 May 2018 23:42:47 +0200 Source: node-connect-timeout Binary: node-connect-timeout Architecture: source Version: 1.9.0-1 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers

[Pkg-javascript-devel] Bug#882965: marked as done (node-connect-timeout: should depend on node-ms)

2018-05-10 Thread Debian Bug Tracking System
Your message dated Thu, 10 May 2018 22:25:24 + with message-id and subject line Bug#882965: fixed in node-connect-timeout 1.9.0-1 has caused the Debian Bug report #882965, regarding node-connect-timeout: should depend on node-ms to be marked as done. This

[Pkg-javascript-devel] Processing of node-brorand_1.1.0-2_source.changes

2018-05-10 Thread Debian FTP Masters
node-brorand_1.1.0-2_source.changes uploaded successfully to localhost along with the files: node-brorand_1.1.0-2.dsc node-brorand_1.1.0-2.debian.tar.xz node-brorand_1.1.0-2_source.buildinfo Greetings, Your Debian queue daemon (running on host usper.debian.org) --

[Pkg-javascript-devel] Processed: Re: Fixed

2018-05-10 Thread Debian Bug Tracking System
Processing control commands: > affects -1 - src:node-vhost Bug #887586 [mocha] mocha 4.0.1-3 causes build hangs in various build-rdeps Removed indication that 887586 affects src:node-vhost -- 887586: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=887586 Debian Bug Tracking System Contact

[Pkg-javascript-devel] Bug#887586: Fixed

2018-05-10 Thread Bastien ROUCARIES
control: affects -1 - src:node-vhost -- Pkg-javascript-devel mailing list Pkg-javascript-devel@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

[Pkg-javascript-devel] Processing of nodejs_10.1.0~dfsg-1_source.changes

2018-05-10 Thread Debian FTP Masters
nodejs_10.1.0~dfsg-1_source.changes uploaded successfully to localhost along with the files: nodejs_10.1.0~dfsg-1.dsc nodejs_10.1.0~dfsg.orig.tar.gz nodejs_10.1.0~dfsg-1.debian.tar.xz nodejs_10.1.0~dfsg-1_source.buildinfo Greetings, Your Debian queue daemon (running on host

[Pkg-javascript-devel] node-brorand_1.1.0-2_source.changes ACCEPTED into unstable

2018-05-10 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Thu, 10 May 2018 22:53:57 +0200 Source: node-brorand Binary: node-brorand Architecture: source Version: 1.1.0-2 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers

[Pkg-javascript-devel] node-errorhandler_1.5.0-1_source.changes ACCEPTED into unstable

2018-05-10 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Thu, 10 May 2018 22:04:50 +0200 Source: node-errorhandler Binary: node-errorhandler Architecture: source Version: 1.5.0-1 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers

[Pkg-javascript-devel] node-inline-source-map 0.6.1-5 MIGRATED to testing

2018-05-10 Thread Debian testing watch
FYI: The status of the node-inline-source-map source package in Debian's testing distribution has changed. Previous version: 0.6.1-4 Current version: 0.6.1-5 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day

[Pkg-javascript-devel] node-browser-pack 6.1.0+ds-2 MIGRATED to testing

2018-05-10 Thread Debian testing watch
FYI: The status of the node-browser-pack source package in Debian's testing distribution has changed. Previous version: 6.0.4+ds-1 Current version: 6.1.0+ds-2 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day

[Pkg-javascript-devel] node-create-hmac 1.1.7-1 MIGRATED to testing

2018-05-10 Thread Debian testing watch
FYI: The status of the node-create-hmac source package in Debian's testing distribution has changed. Previous version: 1.1.6-1 Current version: 1.1.7-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you

[Pkg-javascript-devel] node-js-yaml 3.11.0+dfsg-1 MIGRATED to testing

2018-05-10 Thread Debian testing watch
FYI: The status of the node-js-yaml source package in Debian's testing distribution has changed. Previous version: 3.10.0+dfsg-1 Current version: 3.11.0+dfsg-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a

Re: [Pkg-javascript-devel] Problems to recreate minimized JS in r-cran-jsonld

2018-05-10 Thread Paolo Greppi
Il 10/05/2018 23:45, Andreas Tille ha scritto: >>> [1] >>> https://salsa.debian.org/r-pkg-team/r-cran-jsonld/blob/master/debian/JS/get-jsonld.min >>> >> >> Hi, I'm an upstream developer for jsonld.js and the one to blame for >> the webpack config. ;-) > > Thanks a lot for stepping in here. > >>

[Pkg-javascript-devel] Bug#894928: marked as done (Quoting fixed in autopkgtest 5.2)

2018-05-10 Thread Debian Bug Tracking System
Your message dated Thu, 10 May 2018 21:43:58 +0200 with message-id

[Pkg-javascript-devel] Bug#887586: Fixed

2018-05-10 Thread Bastien ROUCARIES
control: affects -1 - src:node-cookie-parser -- Pkg-javascript-devel mailing list Pkg-javascript-devel@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

[Pkg-javascript-devel] Processed: workarround

2018-05-10 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + patch Bug #887586 [mocha] mocha 4.0.1-3 causes build hangs in various build-rdeps Added tag(s) patch. -- 887586: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=887586 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems --

[Pkg-javascript-devel] Bug#887586: workarround

2018-05-10 Thread Bastien ROUCARIES
control: tags -1 + patch problematic package should be updated or use mocha --exit -- Pkg-javascript-devel mailing list Pkg-javascript-devel@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Re: [Pkg-javascript-devel] New version of node-tape breaks autopkgtests of node-sha.js in testing

2018-05-10 Thread Bastien ROUCARIES
If you have an idea why it fail. Locally I run it 10 000 and I could not reproduce Bastien On Thu, May 10, 2018 at 8:23 PM, Paul Gevers wrote: > Hmm, a retry was already triggered. It was already picked up in the last > run. You can ignore this e-mail. > > Paul > > On

[Pkg-javascript-devel] Processed: Fixed

2018-05-10 Thread Debian Bug Tracking System
Processing control commands: > affects -1 - src:node-cookie-parser Bug #887586 [mocha] mocha 4.0.1-3 causes build hangs in various build-rdeps Removed indication that 887586 affects src:node-cookie-parser -- 887586: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=887586 Debian Bug Tracking