Hi Sean,

On Fri, Jul 07, 2023 at 01:07:57PM +0100, Sean Whitton wrote:
> Hello,
> 
> On Fri 07 Jul 2023 at 12:23pm +02, Sylvain Beucler wrote:
> 
> > Hello Sean,
> >
> > I had a quick test with my:
> > http://git.savannah.gnu.org/cgit/freedink.git/tree/nsis
> > which is kinda old but does call WriteUninstaller.
> > The installer and uninstaller appear to work correctly in a W10 VM.
> >
> > About the source changes, I'd recommend to use the CVE ID as part of the 
> > patch
> > file name (otherwise it can be tedious to determine which fixed what,
> > especially later on if there's (upstream) confusion over CVEs or regression
> > fixes to consider).
> > In addition I like to add a couple fields to note the source of the patch 
> > and
> > some who/when info, e.g.:
> > https://salsa.debian.org/lts-team/packages/runc/-/blob/debian/buster/debian/patches/CVE-2022-29162.patch
> 
> Thank you very much for this review.
> I've applied those changes and I'll upload shortly.

Just noticed the suffix for the version for the buster-security / LTS
upload was +deb9u1, was this intentional? This should have been
+deb10u1.

Regards,
Salvatore

Reply via email to