[Python-modules-team] Bug#977487: pyvows: please make the build reproducible

2020-12-15 Thread Chris Lamb
reproducibly. This is because it did not generate the manpage correctly — it contained a traceback with the error (which included the absolute build path). Patch attached that sets PYTHONPATH correctly. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb

[Python-modules-team] Bug#885326: flask-peewee: please make the build reproducible

2020-12-12 Thread Chris Lamb
Chris Lamb wrote: > [..] Gentle ping on this? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-team@alioth-lists.debian.net ht

[Python-modules-team] Bug#885326: flask-peewee: please make the build reproducible

2020-09-13 Thread Chris Lamb
Chris Lamb wrote: > Would you consider applying this patch and uploading? Friendly ping on this? Seems like there hasn't been any update on this bug in 991 days now (!). Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co

[Python-modules-team] Bug#838713: python-xlib: please make the build reproducible

2020-09-12 Thread Chris Lamb
Chris Lamb wrote: > [..] Gentle ping on this? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-team@alioth-lists.debian.net ht

[Python-modules-team] Bug#944782: python-sybil: please make the build reproducible

2020-09-04 Thread Chris Lamb
Chris Lamb wrote: > Would you consider applying this patch and uploading? Friendly ping on this? Seems like there hasn't been any update on this bug in 287 days now (!). Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co

[Python-modules-team] Bug#943674: flask: please make the build reproducible

2020-09-01 Thread Chris Lamb
Chris Lamb wrote: > Would you consider applying this patch and uploading? Friendly ping on this? Seems like there hasn't been any update on this bug in 305 days now (!). Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co

[Python-modules-team] Bug#969367: python-django: CVE-2020-24583 CVE-2020-24584

2020-09-01 Thread Chris Lamb
ttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24584 [2] https://www.djangoproject.com/weblog/2020/sep/01/security-releases/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- ___ Py

[Python-modules-team] Bug#965362: numpydoc: please make the build reproducible

2020-07-20 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk ` a/debian/rules 2020-07-20 11:14:23.254979286 +0100 --- b/debian/rules 2020-07-20 11:20:45.409510366 +0100 @@ -12,3 +12,8 @@ %: dh $@ --with python3 --buildsystem=pybuild + +override_dh_auto_install

[Python-modules-team] Bug#962323: python-django: CVE-2020-13254 CVE-2020-13596

2020-06-18 Thread Chris Lamb
Hi Sébastien, > They look fine, please upload to security-master. Done. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-t

[Python-modules-team] Bug#962323: python-django: CVE-2020-13254 CVE-2020-13596

2020-06-15 Thread Chris Lamb
Chris Lamb wrote: > The full debdiffs are attached. Can you especially check the > versioning scheme and distribution fields for me? I often get this > wrong and end up confusing myself. Really appreciated. They are now attached. Regards, -- ,''`. : :' : C

[Python-modules-team] Bug#962323: python-django: CVE-2020-13254 CVE-2020-13596

2020-06-14 Thread Chris Lamb
Chris Lamb wrote: > I will wait a few days to see what upstream says. I will also have to > re-release for jessie LTS, alas. Okay, this is now fixed in the following versions (without and with the regression fix): DistributionUpload with regressionUpload with regression

[Python-modules-team] Bug#962323: python-django: CVE-2020-13254 CVE-2020-13596

2020-06-09 Thread Chris Lamb
three. However, I just independently discovered a regression in the latest change for CVE-2020-13254: https://code.djangoproject.com/ticket/31654#comment:14 I will wait a few days to see what upstream says. I will also have to re-release for jessie LTS, alas. Regards, -- ,''`. : :'

[Python-modules-team] Bug#962323: python-django: CVE-2020-13254 CVE-2020-13596

2020-06-06 Thread Chris Lamb
Hi, > python-django: CVE-2020-13254 CVE-2020-13596 Security team, would you like an update for stretch and/or buster to address these issues? It's fixed in sid, experimental as well as jessie LTS. Bullseye is just pending migration time AFAICT. Regards, -- ,''`. : :' : Ch

[Python-modules-team] Bug#962323: python-django: CVE-2020-13254 CVE-2020-13596

2020-06-06 Thread Chris Lamb
rity-tracker.debian.org/tracker/CVE-2020-13254 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13254 [1] https://security-tracker.debian.org/tracker/CVE-2020-13596 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13596 Regards, -- ,''`. : :' : Chris Lamb `. `'`

[Python-modules-team] Bug#961242: python-django-crispy-forms: Not compatible with Django 3.x

2020-05-21 Thread Chris Lamb
Error 2 dpkg-buildpackage: error: debian/rules build subprocess returned exit status 2 […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

[Python-modules-team] Bug#961239: python-django-registration: Not compatible with Django 3.x

2020-05-21 Thread Chris Lamb
-debian-experimental.python3-mini-buildd/mini-buildd-1.1.31' make: *** [debian/rules:4: build] Error 2 dpkg-buildpackage: error: debian/rules build subprocess returned exit status 2 […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'`

[Python-modules-team] Bug#961177: django-simple-captcha: Not compatible with Django 3.x

2020-05-20 Thread Chris Lamb
1]: Leaving directory '/home/lamby/temp/cdt.20200516235112.uZ6Wnbr4DL.ags.lamby-debian-experimental.freedombox/plinth-20.8' make: *** [debian/rules:7: binary] Error 2 dpkg-buildpackage: error: debian/rules binary subprocess returned exit status 2 […] The full build log is attached.

[Python-modules-team] Bug#961175: django-haystack: Not compatible with Django 3.x

2020-05-20 Thread Chris Lamb
[debian/rules:12: override_dh_auto_test] Error 25 make[1]: Leaving directory '/home/lamby/temp/cdt.20200517000807.BbMTSL1dzK.ags.lamby-debian-experimental.python3-django-celery-haystack/celery-haystack-0.10' make: *** [debian/rules:9: build] Error 2 dpkg-buildpackage: error: debian/rules build subprocess returne

[Python-modules-team] Bug#961171: djangorestframework: FTBFS with Django 3.x

2020-05-20 Thread Chris Lamb
log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- djangorestframework.3.10.2-1.unstable.amd64.log.txt.gz Description: Binary data ___ Python-modules-team mailing list Py

[Python-modules-team] Bug#961170: python-django-tagging: FTBFS with Django 3.x

2020-05-20 Thread Chris Lamb
/rules:6: build] Error 2 dpkg-buildpackage: error: debian/rules build subprocess returned exit status 2 […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- python-django-tagging.1:0.4.5-3.unstabl

[Python-modules-team] Bug#961167: python-django-imagekit: FTBFS with Django 3.x

2020-05-20 Thread Chris Lamb
ailed with: exit code=2: python3.8 setup.py test dh_auto_test: error: pybuild --test -i python{version} -p 3.8 returned exit code 13 make: *** [debian/rules:9: binary] Error 25 dpkg-buildpackage: error: debian/rules binary subprocess returned exit status 2 […] The full build log is atta

[Python-modules-team] Bug#961166: python-django-extensions: FTBFS with Django 3.x

2020-05-20 Thread Chris Lamb
override_dh_auto_test] Error 25 make[1]: Leaving directory '/home/lamby/temp/cdt.20200517001318.QUh0NKOOtV.ags.lamby-debian-experimental.python3-django-extensions/python-django-extensions-2.2.1' make: *** [debian/rules:6: build] Error 2 dpkg-buildpackage: error: debian/rules build subproces

[Python-modules-team] Bug#961168: python-django-mptt: FTBFS with Django 3.x

2020-05-20 Thread Chris Lamb
subprocess returned exit status 2 […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- python-django-mptt.0.10.0-1.unstable.amd64.log.txt.gz

[Python-modules-team] Bug#961169: python-django-navtag: FTBFS with Django 3.x

2020-05-20 Thread Chris Lamb
17002556.DquEm9jhp8.ags.lamby-debian-experimental.python3-django-navtag/python-django-navtag-2.1.3' make: *** [debian/rules:9: build] Error 2 dpkg-buildpackage: error: debian/rules build subprocess returned exit status 2 […] The full build log is attached. Regards, -- ,''`.

[Python-modules-team] Bug#961165: libthumbor: FTBFS with Django 3.x

2020-05-20 Thread Chris Lamb
package: error: debian/rules build subprocess returned exit status 2 […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- libthumbor.1.3.3-2.unstable.amd64.log.txt.gz Description: Binary data _

[Python-modules-team] Bug#961164: django-oauth-toolkit: FTBFS with Django 3.x

2020-05-20 Thread Chris Lamb
y. Must be one of: admin_list admin_modify admin_urls cache i18n l10n log static tz […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- django-oauth-toolkit.1.3.2-1.unstable.amd64.log.txt.

[Python-modules-team] Bug#961163: django-modeltranslation: FTBFS with Django 3.x

2020-05-20 Thread Chris Lamb
n-0.13.3' make: *** [debian/rules:6: build] Error 2 dpkg-buildpackage: error: debian/rules build subprocess returned exit status 2 […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

[Python-modules-team] Bug#961162: django-fsm: FTBFS with Django 3.x

2020-05-20 Thread Chris Lamb
ke: *** [debian/rules:10: build] Error 2 dpkg-buildpackage: error: debian/rules build subprocess returned exit status 2 […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- django-fsm.2.

[Python-modules-team] Bug#961160: django-model-utils: FTBFS with Django 3.x

2020-05-20 Thread Chris Lamb
rules:7: build] Error 2 dpkg-buildpackage: error: debian/rules build subprocess returned exit status 2 […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- django-model-utils.3.1.1-2.unstable.amd64.log.txt.gz D

[Python-modules-team] Bug#941072: kivy: please make the build reproducible

2020-05-19 Thread Chris Lamb
Hi Scott, > Looks like the attached patch is empty. Trying again... Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- --- a/debian/patches/reproducible-build.patch 1970-01-01 01:00:00.0 +0100 --- b/debian/patc

[Python-modules-team] Bug#961078: python-django-jsonfield: FTBFS with Django 3.x

2020-05-19 Thread Chris Lamb
test] Error 25 make[1]: Leaving directory '/home/lamby/temp/cdt.20200517002210.n7i3i8p1o1.ags.lamby-debian-experimental.python3-django-jsonfield/python-django-jsonfield-1.1.0' make: *** [debian/rules:6: build] Error 2 dpkg-buildpackage: error: debian/rules build subprocess returned exit sta

[Python-modules-team] Bug#961079: python-django-contact-form: FTBFS with Django 3.x

2020-05-19 Thread Chris Lamb
rt text_type ModuleNotFoundError: No module named 'django.utils.six' […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- python-django-contact-form.1.4.2-3.unstable.amd64.l

[Python-modules-team] Bug#961072: django-pipeline: FTBFS with Django 3.x

2020-05-19 Thread Chris Lamb
25: override_dh_auto_test] Error 1 […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- django-pipeline.1.6.14-3.unstable.amd64.log.txt.gz Description: Binary data _

[Python-modules-team] Bug#961069: python-django-csp: FTBFS with Django 3.x

2020-05-19 Thread Chris Lamb
ards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- python-django-csp.3.5-2.unstable.amd64.log.txt.gz Description: Binary data ___ Python-modules-team mailing list Python-modules-team@al

[Python-modules-team] Bug#961068: django-cors-headers: FTBFS with Django 3.x

2020-05-19 Thread Chris Lamb
rs-headers-2.2.0' make: *** [debian/rules:5: build] Error 2 dpkg-buildpackage: error: debian/rules build subprocess returned exit status 2 […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- dja

[Python-modules-team] Bug#961066: django-simple-captcha: FTBFS with Django 3.x

2020-05-19 Thread Chris Lamb
ncoding import python_2_unicode_compatible ImportError: cannot import name 'python_2_unicode_compatible' from 'django.utils.encoding' (/usr/lib/python3/dist-packages/django/utils/encoding.py) […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debi

[Python-modules-team] Bug#961067: django-cas-server: FTBFS with Django 3.x

2020-05-19 Thread Chris Lamb
ode_compatible ImportError: cannot import name 'python_2_unicode_compatible' from 'django.utils.encoding' (/usr/lib/python3/dist-packages/django/utils/encoding.py) […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debi

[Python-modules-team] Bug#961065: sorl-thumbnail: FTBFS with Django 3.x

2020-05-19 Thread Chris Lamb
mpatible' from 'django.utils.encoding' (/usr/lib/python3/dist-packages/django/utils/encoding.py) […] The full build log is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- sorl-thumbnail.12.5.0-2.unstable.amd64.log.txt.gz Descriptio

[Python-modules-team] Bug#960890: python-django: New upstream 3.x release

2020-05-18 Thread Chris Lamb
long-term goal. However, it would be nice to be able for people to elect to install 3.x from experimental, as well as to get started on the various small updates on the many leaf packages. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debia

[Python-modules-team] Bug#960890: python-django: New upstream 3.x release

2020-05-17 Thread Chris Lamb
plinth Michal Čihař django-taggit Stephan Sürken mini-buildd § Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-mo

[Python-modules-team] Bug#958848: [Pkg-privacy-maintainers] Bug#958848: pytest (build-)depends on pypy-funcsigs which the maintainer would like to get rid of.

2020-04-25 Thread Chris Lamb
" in the dh_auto_test line is right. "{interpreter}" there is replaced with pypy). This also assumes that running PyPy at runtime will have identical behaviour as Python 3.x. Enjoy... Regards, -- ,''`. : :' : Chris Lamb `. `'`

[Python-modules-team] Bug#953950: python-twisted: twisted version 14.0.2-3+deb8u1 in jessie (security) is broken

2020-03-19 Thread Chris Lamb
Chris Lamb wrote: > I will take charge of fixing this in jessie with the utmost urgency. I have just uploaded 14.0.2-3+deb8u2 and DLA-2145-2 will be announced after sending this email. Thank you again for raising this issue. Best wishes, -- ,''`. : :' : Chris L

[Python-modules-team] Bug#953950: python-twisted: twisted version 14.0.2-3+deb8u1 in jessie (security) is broken

2020-03-19 Thread Chris Lamb
Hi all, > Please, can you […] revert this patch and re-publish the working (but > security flawed) 14.0.2-3 twisted version ? I will take charge of fixing this in jessie with the utmost urgency. Thank you for raising this issue. Regards, -- ,''`. : :' : Chri

[Python-modules-team] Bug#952555: azure-uamqp-python: please make the build reproducible

2020-03-11 Thread Chris Lamb
it would be a shame that individual maintainers need to add/test the introduction of +fixfilepath everywhere.) Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- ___ Python-modules-team mai

[Python-modules-team] Bug#950138: pikepdf: please make the build reproducible

2020-01-29 Thread Chris Lamb
forwarded 950138 https://github.com/pikepdf/pikepdf/pull/76 thanks I've forwarded this upstream here: https://github.com/pikepdf/pikepdf/pull/76 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

[Python-modules-team] Bug#950138: pikepdf: please make the build reproducible

2020-01-29 Thread Chris Lamb
that was determined by their layout on the filesystem which is, at least in UNIX systems, non-deterministic. Patch attached that addresses both these issues. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

[Python-modules-team] Bug#948279: python-gmusicapi: please make the build reproducible

2020-01-06 Thread Chris Lamb
not be built reproducibly. This is because the documentation embedded the build user's home directory (via the XDG config directory). Patch attached. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

Re: [Python-modules-team] Bug#943509: python-django: FTBFS due to failed tests: failures=7, skipped=891, expected failures=4

2019-12-31 Thread Chris Lamb
his exception was already fixed in #947549… > Happy New Year! … you too. :) Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-

Re: [Python-modules-team] Bug#943509: python-django: FTBFS due to failed tests: failures=7, skipped=891, expected failures=4

2019-12-29 Thread Chris Lamb
e or fix in sqlite3 is not forthcoming within a few days. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-team@alioth-lists.debian.net https://alio

[Python-modules-team] Bug#946937: python-django: CVE-2019-19844: Potential account hijack via password reset form

2019-12-18 Thread Chris Lamb
blog/2019/dec/18/security-releases/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-team@alioth-lists.debian.net https://al

[Python-modules-team] Bug#946011: python-django: CVE-2019-19118

2019-12-03 Thread Chris Lamb
g too. I was being overly- cautious in assuming that it was vulnerable without doing any checking first, thus leading to this noise (for which I apologise). I have updated data/dla-needed.txt and data/CVE/list to match. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@

[Python-modules-team] Bug#946011: python-django: CVE-2019-19118

2019-12-02 Thread Chris Lamb
Chris Lamb wrote: > Package: python-django > Version: 1.7.11-1+deb8u7 […] > CVE-2019-19118[0]: > | Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model > | editing. A Django model admin displaying inline related models, where > | the user has view-only permi

[Python-modules-team] Bug#946011: python-django: CVE-2019-19118

2019-12-02 Thread Chris Lamb
9118 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-team@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/list

[Python-modules-team] Bug#944782: python-sybil: please make the build reproducible

2019-11-15 Thread Chris Lamb
forwarded 944782 https://github.com/cjw296/sybil/pull/18 thanks I've forwarded this upstream here: https://github.com/cjw296/sybil/pull/18 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

[Python-modules-team] Bug#944782: python-sybil: please make the build reproducible

2019-11-15 Thread Chris Lamb
reproducible +Author: Chris Lamb +Last-Update: 2019-11-15 + +--- python-sybil-1.2.0.orig/docs/conf.py python-sybil-1.2.0/docs/conf.py +@@ -1,5 +1,5 @@ + # -*- coding: utf-8 -*- +-import os, pkg_resources, datetime, sys ++import os, pkg_resources, datetime, sys, time + + on_rtd = os.environ.get

[Python-modules-team] Bug#943320: python3-pluggy: missing dependency on python3-importlib-metadata

2019-10-23 Thread Chris Lamb
b_metadata' This appears to be a regression from 0.12.0-1 (which has this dependency). Discovered when trying to release diffoscope on behalf on the Reproducible Builds[0] effort hence the X-Debbugs-CC, but likely affects other packages. [0] https://reproducible-builds.org

[Python-modules-team] Bug#942342: traitlets: please make the output reproducible

2019-10-14 Thread Chris Lamb
Chris Lamb wrote: > Patch attached. Let's try that again: --- a/traitlets/traitlets.py +++ b/traitlets/traitlets.py @@ -2366,6 +2366,10 @@ class Set(List): """ super(Set, self).__init__(trait, default_value, minlen, maxlen, **kwargs)

[Python-modules-team] Bug#942342: traitlets: please make the output reproducible

2019-10-14 Thread Chris Lamb
forwarded 942342 https://github.com/ipython/traitlets/pull/535 thanks I've forwarded this upstream here: https://github.com/ipython/traitlets/pull/535 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

[Python-modules-team] Bug#942342: traitlets: please make the output reproducible

2019-10-14 Thread Chris Lamb
/ amd64/nbconvert.html on 20191014) This is due to it not iterating over a Set traitlet type in a deterministic ordering when generating the "Default:" human-readable string. Patch attached. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' :

[Python-modules-team] Bug#941072: kivy: please make the build reproducible

2019-09-24 Thread Chris Lamb
reproducibly. This is because it generated a version.py file that contains the current build date. A patch is attached that uses SOURCE_DATE_EPOCH [1]. [0] https://reproducible-builds.org/ [1] https://reproducible-builds.org/specs/source-date-epoch/ Regards, -- ,''`. : :' : Chris Lamb

[Python-modules-team] Bug#932960: python-django doesn't fix a CVE and drops Python 2 support at the same time

2019-09-17 Thread Chris Lamb
Hi Paul, > How is progress here? I failed to spot recent activity, but I may have > missed it. I'm not sure you've missed anything, at least from me -- I've not found it possible to prioritise time on this, alas. Regards, -- ,''`. : :' : Chris Lamb `. `'`

[Python-modules-team] Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-09-02 Thread Chris Lamb
Chris Lamb wrote: > > > +python-django (1:1.11.23-1~deb10u1) buster-security; urgency=high > > > > Thanks, these both look good; please upload to security-master. > > Both uploaded to security-master. There is now a 1.11.24 (ie. 1:1.11.24-1~deb10u1) upstream: htt

[Python-modules-team] Bug#937704: Bug#937704: python-django: Python2 removal in sid/bullseye

2019-08-30 Thread Chris Lamb
Hi Scott, > It's stilll there as cruft: […] > Once those binaries are gone we'll pick it up with the arch all decrufting. Ah, thanks for explaining. It seems a little bit of waste of Doku's energy to file unactionable bug reports. :) Regards, -- ,''`. : :' : Chri

[Python-modules-team] Bug#937704: python-django: Python2 removal in sid/bullseye

2019-08-30 Thread Chris Lamb
quot;buster". * Update debian/gbp.conf to refer to debian/sid after merge. -- Chris Lamb Sun, 07 Jul 2019 11:59:04 -0300 [..] python-django (1:2.0~alpha1-2) experimental; urgency=medium New upstream alpha release of Django 2.0. <https://docs.djangoproject.com/

[Python-modules-team] Bug#935394: python3-django breaks python3-mysqldb (<<1.3.13), but only python3-mysqldb 1.3.10 is available

2019-08-22 Thread Chris Lamb
exposing by doing that, knowing MySQL... Therefore I think the best solution would be to upload a new version of python3-mysqldb. I'm taking the liberty of reassigning (with a "reverse" affects for visibility) here in lieu of asking you to file a separate bug. Regards, -- ,''`.

[Python-modules-team] Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-10 Thread Chris Lamb
curity-master. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-team@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/python-modules-team

[Python-modules-team] Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-09 Thread Chris Lamb
although it's not a "re"-build of anything; 1.11.23 won't be in any other suite… :p) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- ___ Python-modules-team mailing list Python

[Python-modules-team] Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
on we should use? > > 1:1.11.23-1~deb10u1? > > Looks good! Updated debdiff attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-diff --git a/Django.egg-info/PKG-INFO b/Django.egg-info/PKG-INFO index 75a27527c..f6cdde7db

[Python-modules-team] Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
PoV Lintian should probably just waive that check > unless the target distro for the upload is "unstable". I took a different approach (to mirror similar existing logic) here: https://salsa.debian.org/lintian/lintian/commit/bcded0a16c1094ae55afdd65caca7f598e3be7fc Regards, -

[Python-modules-team] Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
given that > we agreed to follow 1.11.x in buster, shouldn't we rather use that one? D'oh, that makes more sense. Okay, I can prepare a debdiff for that -- however, can you just confirm the version we should use? 1:1.11.23-1~deb10u1? Regards, -- ,''`. : :' : Chris Lamb `. `'

[Python-modules-team] Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
about existing releases? How does it > know that 1:1.11.22-1 is missing? debian/changelog. Lintian, as a strict rule, does not query external sources. (I should probably clarify; missing *sequential* releases.) Regards, -- ,''`. : :' : Chris Lamb `. `'`

[Python-modules-team] Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
new debian/buster branch. -- Chris Lamb Wed, 03 Jul 2019 15:18:13 -0300 … and that I've tentatively versioned the updated version to address these new CVEs as 1:1.11.22-1+deb10u1 (ie. with a plus, not a tilde). I mention it specifically as I'm not 100% confident this is correct and Lintian somew

[Python-modules-team] Bug#934120: python-bleach: please make the build reproducible

2019-08-07 Thread Chris Lamb
forwarded 934120 https://github.com/mozilla/bleach/pull/465 thanks I've forwarded this upstream here: https://github.com/mozilla/bleach/pull/465 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

[Python-modules-team] Bug#934120: python-bleach: please make the build reproducible

2019-08-07 Thread Chris Lamb
Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/patches/0003-reproducible_build.patch 1970-01-01 01:00:00.0 +0100 --- b/debian/patches/0003-reproducible_build.patch 2019-08-07 09:24:23.478886645 +0100 @@ -0,0 +1,15 @@ +D

[Python-modules-team] Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-06 Thread Chris Lamb
[Adding t...@security.debian.org to CC] Chris Lamb wrote: > The following vulnerabilities were published for python-django. > > CVE-2019-14232[0]: > CVE-2019-14233[1]: > CVE-2019-14234[2]: > CVE-2019-14235[3]: I have just fixed this in sid and will fix this in jessie LTS

[Python-modules-team] Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-06 Thread Chris Lamb
=CVE-2019-14235 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-team@alioth-lists.debian.net https://alioth-lists.debian.net/cgi

[Python-modules-team] Bug#932960: python-django doesn't fix a CVE and drops Python 2 support at the same time

2019-08-02 Thread Chris Lamb
python-semantic-version … still Build-Depend or Build-Depend-Indep on python-django. (Zigo, did you neglect python-oauth2client and python-semantic-version in your mass uploads recently?) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb

[Python-modules-team] Bug#932960: python-django doesn't fix a CVE and drops Python 2 support at the same time

2019-07-26 Thread Chris Lamb
of regular reverse-dependencies but I fear I would be missing the test ones. Or: if someone could furnish me with such a list I will happily file the bugs in question. Thanks again for your patience and understanding here, Paul. Best wishes, -- ,''`. : :' : Chris Lamb `. `'

[Python-modules-team] Bug#932960: python-django doesn't fix a CVE and drops Python 2 support at the same time

2019-07-25 Thread Chris Lamb
oing forward regarding this CVE, at least? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-team@alioth-lists.debian.net ht

[Python-modules-team] Bug#932960: python-django doesn't fix a CVE and drops Python 2 support at the same time

2019-07-25 Thread Chris Lamb
looked into the specifics...) > Your package is trying to fix a CVE Can you elaborate? I'm a little distracted by DebConf stuff but I can't seem to grok what you mean here specifically. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-l

[Python-modules-team] Bug#929927: Bug#931316: python-django: CVE-2019-12308: Incorrect HTTP detection with reverse-proxy connecting via HTTPS

2019-07-02 Thread Chris Lamb
t builds for me (with all tests passing) in a stretch chroot. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-diff --git a/debian/changelog b/debian/changelog index fa89c8b21..5bb1d6625 100644 --- a/debian/changelog +++ b/debian/ch

[Python-modules-team] Bug#931316: python-django: CVE-2019-12308: Incorrect HTTP detection with reverse-proxy connecting via HTTPS

2019-07-01 Thread Chris Lamb
e? Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-team@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman

[Python-modules-team] Bug#929927: python-django: CVE-2019-12308: AdminURLFieldWidget XSS

2019-06-04 Thread Chris Lamb
embargo? I might have some bandwidth the next day or so if not, but let me know. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modul

[Python-modules-team] Bug#897489: python-whoosh: FTBFS: dh_auto_test: pybuild --test --test-pytest -i python{version} -p 3.6 returned exit code 13

2019-04-07 Thread Chris Lamb
archive"). Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-team@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/python-modules-team

[Python-modules-team] Bug#897489: python-whoosh: FTBFS: dh_auto_test: pybuild --test --test-pytest -i python{version} -p 3.6 returned exit code 13

2019-04-05 Thread Chris Lamb
25969 > > Am I missing something? No, I just have a terrible memory and/or didn't read what you wrote more carefully before replying. Fixing this bug and reuploading now... :) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.o

[Python-modules-team] Bug#897489: python-whoosh: FTBFS: dh_auto_test: pybuild --test --test-pytest -i python{version} -p 3.6 returned exit code 13

2019-04-05 Thread Chris Lamb
ackage, though; any objection from the rest of the DPMT? Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-team@alioth-lists.debian

[Python-modules-team] Bug#924784: python-django: FTBFS on i386: OverflowError: timestamp out of range for platform time_t

2019-03-18 Thread Chris Lamb
forwarded 924784 https://code.djangoproject.com/ticket/30264#ticket thanks I've forwarded this upstream here: https://code.djangoproject.com/ticket/30264#ticket Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

[Python-modules-team] Bug#922027: python-django: Django security release

2019-02-14 Thread Chris Lamb
Hi Moritz, > > Security team, may I upload this to stretch-security? Diff attached. > > This doesn't warrant a DSA, let's postpone this until more severe comes up. Noted. Can you update data/CVE/list? Regards, -- ,''`. : :' : Chris Lamb `. `'` la..

[Python-modules-team] Bug#897489: python-whoosh: FTBFS: dh_auto_test: pybuild --test --test-pytest -i python{version} -p 3.6 returned exit code 13

2019-02-13 Thread Chris Lamb
Chris Lamb wrote: > Locally I cannot reproduce. Ah, I can now; it's a non-determinism issue in the NFA.minimize routine itself dfa.__dict__ = {'initial': 1, 'transitions': {1: {'a': 3, 'b': 2}, 3: {'a': 1}, 2: {'b': 1}}, 'defaults': {}, 'final_states': {1}, 'outlabels': {}} g

[Python-modules-team] Bug#897489: python-whoosh: FTBFS: dh_auto_test: pybuild --test --test-pytest -i python{version} -p 3.6 returned exit code 13

2019-02-13 Thread Chris Lamb
ackages/_pytest/_code/code.py", line 415, in __init__ self._excinfo = tup File "whoosh/collectors.py", line 1075, in _was_signaled raise TimeLimit TimeLimit Locally I cannot reproduce. Note that I just uploaded 2.7.4+git6-g9134ad92-2 to fix a number of smaller is

[Python-modules-team] Bug#922027: python-django: Django security release

2019-02-13 Thread Chris Lamb
Chris Lamb wrote: > [Adding t...@security.debian.org to CC] > > > retitle 922027 CVE-2019-6975: Memory exhaustion in > > django.utils.numberformat.format() > > severity 922027 grave > > found 922027 1:1.10.7-2+deb9u3 > > tags 922027 + security > &g

[Python-modules-team] Bug#922027: python-django: Django security release

2019-02-11 Thread Chris Lamb
[Adding t...@security.debian.org to CC] Chris Lamb wrote: > retitle 922027 CVE-2019-6975: Memory exhaustion in > django.utils.numberformat.format() > severity 922027 grave > found 922027 1:1.10.7-2+deb9u3 > tags 922027 + security > thanks Security team, may I upload this t

[Python-modules-team] Bug#922027: python-django: Django security release

2019-02-11 Thread Chris Lamb
#comment:4 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `- ___ Python-modules-team mailing list Python-modules-team@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman

[Python-modules-team] Bug#921513: sphinx: please make the build reproducible

2019-02-06 Thread Chris Lamb
forwarded 921513 https://github.com/sphinx-doc/sphinx/pull/6028 thanks I've forwarded this upstream here: https://github.com/sphinx-doc/sphinx/pull/6028 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk

[Python-modules-team] Bug#921513: sphinx: please make the build reproducible

2019-02-06 Thread Chris Lamb
` variable ends up in the final constructed filename; I assume there is a good reason for including the `options` dictionary in the first place, otherwise we could simply omit it. [0] https://reproducible-builds.org (Patch attached.) Regards, -- ,''`. : :' : Chris Lamb

Re: [Python-modules-team] Comments regarding python-css-parser_1.0.4-1_amd64.changes

2019-02-05 Thread Chris Lamb
Nicholas, > Alternatively, would you like to me ask upstream to document their > copyright holders? That sounds far better than trying to guess at-length at their intentions and will result in a better longer-term outcome. Regards, -- ,''`. : :' : Chri

[Python-modules-team] Bug#920030: ships headers in /usr/include/python3.7/

2019-01-21 Thread Chris Lamb
Hi, > your package ships the header file(s): FYI this will be explicitly detected and reported on in lintian 2.5.123 in the package-contains-python-header-in-incorrect- directory tag. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co

[Python-modules-team] Bug#918671: python-shade: Incomplete debian/copyright?

2019-01-08 Thread Chris Lamb
so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- ___ Python-modules-team mailing list Python

[Python-modules-team] Bug#918230: python-django: CVE-2019-3498: Content spoofing possibility in the default 404 page

2019-01-06 Thread Chris Lamb
load.debian.org for security-master. > Thank you for your work on this update, No problem. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- ___ Python-modules-team mailing l

[Python-modules-team] Bug#918230: python-django: CVE-2019-3498: Content spoofing possibility in the default 404 page

2019-01-06 Thread Chris Lamb
included all of these nonsense changes. Updated patch attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diff --git a/debian/changelog b/debian/changelog index b1c56f7c5..fa89c8b21 100644 --- a/debian/changelog +++ b/debian/chang

  1   2   >