[Pkg-javascript-devel] Bug#715325: npm: leaves lots of stuff in /tmp

2013-07-10 Thread Jérémy Lal
The security issue is fixed there : https://github.com/isaacs/npm/commit/f4d31693 this will eventually come to npm debian package. Jérémy. ___ Pkg-javascript-devel mailing list Pkg-javascript-devel@lists.alioth.debian.org

[Pkg-javascript-devel] Bug#715325: Bug#715325: npm: leaves lots of stuff in /tmp

2013-07-10 Thread Daniel Kahn Gillmor
On 07/10/2013 12:11 PM, Jérémy Lal wrote: The security issue is fixed there : https://github.com/isaacs/npm/commit/f4d31693 this will eventually come to npm debian package. Thanks for the followup on this, jérémy! I confess i'm kind of amazed that node doesn't have any primitive like

[Pkg-javascript-devel] Bug#715325: [oss-security] npm uses predictable temporary filenames when unpacking tarballs

2013-07-10 Thread Daniel Kahn Gillmor
On 07/10/2013 04:02 PM, Daniel Kahn Gillmor wrote: hi oss-sec folks-- i recently learned that npm, the node.js language-specific package manager, created predictable temporary directory names in a world-writable filesystem (/tmp) by default when unpacking archives. It looks like this

[Pkg-javascript-devel] Bug#715325: Bug#715325: npm: leaves lots of stuff in /tmp

2013-07-10 Thread Jérémy Lal
On 10/07/2013 18:59, Daniel Kahn Gillmor wrote: I notice that your message was sent privately to me, ../.. feel free to post copies of it to the BTS. My mistake. On 07/10/2013 12:31 PM, Jérémy Lal wrote: On 10/07/2013 18:17, Daniel Kahn Gillmor wrote: I confess i'm kind of amazed that

[Pkg-javascript-devel] Processed: javascript-common needs an update for apche2.4 transition

2013-07-10 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: user debian-apa...@lists.debian.org Setting user to debian-apa...@lists.debian.org (was jmv_...@nirgal.com). usertag 710475 +apache24webapptransition There were no usertags set. Usertags are now: apache24webapptransition. block 661958 by 710475