Hello Lester!

Leave you more comments:

- d/patches/0011-fix-vulnerable-username.patch: AFAIU your are not the
  author of that patch
  
https://github.com/mitmproxy/mitmproxy/commit/71c9234057922bc29b9734ec408d712113d294d2,
  you should mention the Origin and the correct Author. Also
  Bug-Debian key, it would be great add it.
- Same commento for d/patches/0010-remove-return-in-finally.patch
- Seems that mitmproxy/contrib/tornado/__init__.py is LGPL-2.1+.
- Could you improve d/upstream/metadata file please?

Let me know when you have new version to review.

On 2026-08-31 13:00, Lester Guerzon wrote:
> Hi Emmanuel,
> 
> Thanks for the review.
> 
> > - Please review the license of mitmproxy/contrib/click/__init__.py,
> 
> I was able to track the source of the file [1]. Added to d/copyright.
> 
> >    mitmproxy/contrib/tornado/__init__.py and,
> 
> Upstream forgot to update the copyright placeholder in their license file so 
> I used the copyright string from their website (although this one did not 
> have a copyright year). Hope this is okay.
> 
> >    mitmproxy/contrib/urwid/raw_display.py
> 
> Added to d/copyright.
> 
> > - There're some open bugs, do you plan fix them?
> 
> This release would fix #1146166 and #1094593. I took a look at #1119682 and 
> was able to fix that as well.
> 
> I also added a fix to a warning (ex. when running mitmweb): 
> 0010-remove-return-in-finally.patch.
> 
> There is one more bug #1134620 for CVE-2026-40606. Technically, 8.1.1 is not 
> vulnerable to this specific CVE [2] since the commit in question has been 
> introduced in 10.1.2. But the same code is still vulnerable to the same 
> unsanitized username. I took the same approach as the fix for CVE-2026-40606 
> [3], adapted it, and applied a patch 0011-fix-vulnerable-username.patch.
> 
> > - I guess you can update Standards-Version.
> > - All b-depends are still needed? (I didn't check it)
> 
> Updated standards version and compat (=14). Cleaned up some in build-deps and 
> deps.
> 
> > Let me know when you have a new version to review.
> 
> I pushed my changes to the repo.
> 
> Thanks!
> 
> 
> [1] https://github.com/pallets/click/blob/main/src/click/termui.py
> [2] 
> https://salsa.debian.org/security-tracker-team/security-tracker/-/merge_requests/324?pow_referer=https%3A%2F%2Fsalsa.debian.org%2Flester
> [3] 
> https://github.com/mitmproxy/mitmproxy/commit/71c9234057922bc29b9734ec408d712113d294d2
> 
> -- 
> Regards,
> Lester
> 
> [email protected]
> OpenPGP: 107B6026A82D044C97D7D8B92100C145E0F3655E
> 
> 




-- 
cheers,
        Emmanuel Arias

 ⢀⣴⠾⠻⢶⣦⠀
 ⣾⠁⢠⠒⠀⣿⡁  [email protected]
 ⢿⡄⠘⠷⠚⠋⠀  OpenPGP: 13796755BBC72BB8ABE2AEB5 FA9DEC5DE11C63F1
 ⠈⠳⣄

Attachment: signature.asc
Description: PGP signature

Reply via email to