[Git][security-tracker-team/security-tracker][master] data/dla-needed.txt: claim frr

2025-01-14 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 7e8d6e92 by Arturo Borrero Gonzalez at 2025-01-14T12:19:42+01:00 data/dla-needed.txt: claim frr I will work on this package next. Signed-off-by: Arturo Borrero Gonzalez <art...@debian.

[Cloud] Re: LLM services

2025-01-10 Thread Arturo Borrero Gonzalez
On 1/10/25 05:21, Huji Lee wrote: Hi all, Are there any LLMs available on Cloud services, or are there any plans for them? I think there are many possible use cases. Even free, lightweight LLMs (like LLaMa) could be helpful, e.g. in bots that review edits, categorize pages, etc. Hi Huji,

[jira] [Updated] (HTTPCLIENT-2354) ResponseCachingPolicy::isExplicitlyCacheable does not account for "must-revalidate"

2025-01-10 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2354?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal updated HTTPCLIENT-2354: -- Fix Version/s: 5.4.2 > ResponseCachingPolicy::isExplicitlyCacheable does

[jira] [Resolved] (HTTPCLIENT-2354) ResponseCachingPolicy::isExplicitlyCacheable does not account for "must-revalidate"

2025-01-09 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2354?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal resolved HTTPCLIENT-2354. --- Resolution: Fixed > ResponseCachingPolicy::isExplicitlyCacheable does

Re: [VOTE] Release HttpCore 5.3.2 based on RC1

2025-01-06 Thread Arturo Bernal
+1 Release the packages as HttpCore 5.3.2. Thank you Arturo On Mon, Jan 6, 2025 at 6:55 PM Oleg Kalnichevski wrote: > Please vote on releasing these packages as HttpCore 5.3.2. > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are bin

[jira] [Updated] (HTTPCLIENT-2353) Incorrect IDN-hostname validation from TLS-certificates

2025-01-06 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2353?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal updated HTTPCLIENT-2353: -- Fix Version/s: 5.5-alpha1 > Incorrect IDN-hostname validation from

[jira] [Resolved] (HTTPCLIENT-2353) Incorrect IDN-hostname validation from TLS-certificates

2025-01-06 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2353?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal resolved HTTPCLIENT-2353. --- Resolution: Fixed > Incorrect IDN-hostname validation from TLS-certifica

Re: Inconsistent default values for RequestConfig.protocolUpgradeEnabled

2025-01-05 Thread Arturo Bernal
properly declared. Jetty’s stricter enforcement reflects a security-conscious approach, which is understandable, but it goes beyond the minimum requirements outlined by the RFC IMO Arturo On Mon, Jan 6, 2025 at 3:47 AM jan luehe wrote: > Hi Oleg, > this is the response we have received fr

Re: HttpCore 5.3.2 release notes

2025-01-05 Thread Arturo Bernal
LGTM Arturo On Sun, Jan 5, 2025 at 9:15 AM Oleg Kalnichevski wrote: > Folks > > Please review the release notes for HttpCcore 5.3.2 and amend them as > you deem necessary > > https://github.com/apache/httpcomponents-core/blob/5.3.x/RELEASE_

Re: Inconsistent default values for RequestConfig.protocolUpgradeEnabled

2025-01-03 Thread Arturo Bernal
CDI constructor simply serves an internal purpose, so any discrepancy in defaults there is generally not considered a bug. Kind regards Arturo On Fri, Jan 3, 2025 at 10:11 PM jan luehe wrote: > The reason I'm asking is because when we upgraded > org.apache.httpcomponents.client5 f

Re: is there a maximum request size supported by the httpclient library?

2025-01-03 Thread Arturo Bernal
Hi Patricia, There’s no hard-coded request-size limit in Apache HttpClient itself . A 413 Request Entity Too Large error usually originates on the server or proxy side when it decides that the incoming request (header + body) exceeds its configured maximum size. Arturo On Fri, Jan 3, 2025 at 7

Re: [DRAFT] 2025/01 Board report

2025-01-03 Thread Arturo Bernal
Hi Juan Pablo, LGTM Thank you. Arturo On Thu, Jan 2, 2025 at 4:13 PM Juan Pablo Santos Rodríguez < juanpablo.san...@gmail.com> wrote: > Hi, > > as usual, please see below for the draft for upcoming Board meeting. > Any edits, comments, etc. as always are more than welcome

Debian LTS and ELTS report: December 2024

2025-01-01 Thread Arturo Borrero Gonzalez
Hello, This is my December 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! ELTS: I spent all of my time this month working on activemq for Jessie. Some highlights: * CVE-2020-13920 -- patch backport co

[jira] [Commented] (HTTPCLIENT-2352) Race condition causing java.lang.ArithmeticException: Update causes flow control window to exceed 2147483647

2024-12-20 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2352?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17907495#comment-17907495 ] Arturo Bernal commented on HTTPCLIENT-2352: --- Hi [~markslater] ç,

[GROW] Re: [WGADOPTION] draft-ramseyer-grow-peering-api - ends 11/29/2024 (Nov 29, 2024)

2024-12-06 Thread Arturo Servin
Mohamed I remember that at least as authors we discussed some models that were proposed in some discussions on the WG. At least the ones that we reviewed, we found that the interconnection model was more about transport and physical links and didn't fit well with public link peering links. I trie

[MARMAM] New Publication: Hemoplasma in melon-headed whale (Peponocephala electra, Gray, 1846), Veracruz, Mexico

2024-12-02 Thread Serrano Solis Arturo
My co-authors and I are happy to announce the publication of a recent paper the Comparative Immunology, Microbiology and Infectious Diseases: Gerardo.G. Ballados-González, et al. 2025. Hemoplasma in melon-headed whale (Peponocephala electra, Gray, 1846), Veracruz, Mexico. Comparative Immunology,

Debian LTS & ELTS report -- November 2024

2024-11-30 Thread Arturo Borrero Gonzalez
Hello, This is my November 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! ELTS: I spent most of my time this month working on ELTS releases (Jessie, Stretch, Buster), with the activemq package. Some

about CVE-2022-41678 in activemq 5.6.0

2024-11-24 Thread Arturo Borrero Gonzalez
Hi there, As part of the debian (E)LTS initiative, I'm working on trying to fix CVE-2022-41678 on the activemq packages in Debian. In particular, I'm interested in Debian Jessie and activemq 5.6.0. The patch [0] to correct the jolokia config doesn't apply to the source code we have in Debian

about CVE-2022-41678 in activemq 5.6.0

2024-11-24 Thread Arturo Borrero Gonzalez
Hi there, As part of the debian (E)LTS initiative, I'm working on trying to fix CVE-2022-41678 on the activemq packages in Debian. In particular, I'm interested in Debian Jessie and activemq 5.6.0. The patch [0] to correct the jolokia config doesn't apply to the source code we have in Debian

patch for CVE-2023-46604 on activemq 5.6.0

2024-11-24 Thread Arturo Borrero Gonzalez
Hi there, I'm looking for a fix for CVE-2023-46604 in activemq 5.6.0. The patch that is published [0] does not apply to 5.6.0, and I would like you to either: * provide a patch that applies to the source tree in activemq 5.6.0 * confirm if the bug does not apply to activemq 5.6.0 regards. [0

[jira] [Resolved] (HTTPCLIENT-2350) Option to prevent hostname resolution to InetAddress

2024-11-16 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2350?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal resolved HTTPCLIENT-2350. --- Resolution: Fixed In master. > Option to prevent hostname resolution

Debian LTS & ELTS report -- October 2024

2024-10-31 Thread Arturo Borrero Gonzalez
Hello, This is my October 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! LTS: I spent most of the time working on the nss package for Debian Bullseye, plus some work to sync security changes with Debian

Re: CVE-2024-6602 & CVE-2024-6609 nss for debian/buster

2024-10-31 Thread Arturo Borrero Gonzalez
On 10/29/24 18:19, Arturo Borrero Gonzalez wrote: Hi Chris, the work has been done already.  Packages with the patches will be uploaded soon. Offering more information here. There are uploads scheduled for all ELTS releases: * buster * stretch * jessie The git repository contains all

Re: CVE-2024-6602 & CVE-2024-6609 nss for debian/buster

2024-10-29 Thread Arturo Borrero Gonzalez
Hi Chris, the work has been done already. Packages with the patches will be uploaded soon. regards. -- Forwarded message - From: Chris Frey Date: Tue, Oct 29, 2024, 08:36 Subject: CVE-2024-6602 & CVE-2024-6609 nss for debian/buster To: Just in case anyone else is in the same

[SECURITY] [DLA 3937-1] nss security update

2024-10-28 Thread Arturo Borrero Gonzalez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 - - Debian LTS Advisory DLA-3937-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Arturo Borrero Gonzalez October 27, 2024

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3937-1 for nss

2024-10-27 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 8256d066 by Arturo Borrero Gonzalez at 2024-10-27T20:49:31+01:00 Reserve DLA-3937-1 for nss - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

Re: CVE-2024-7531/nss for debian/bullseye LTS

2024-10-27 Thread Arturo Borrero Gonzalez
s the data from https://hg.mozilla.org/projects/nss/rev/525c5044cc9e53f5015c697b04b1405df91003ac, I would feel more comfortable if upstream confirmed that the commit ^ above fixes the vulnerability. Arturo, could you please ask upstream to confirm that reference is correct? Hi, they have conf

[Git][security-tracker-team/security-tracker][master] CVE-2024-7531/nss: does not affect bullseye

2024-10-27 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 52c90c3f by Arturo Borrero Gonzalez at 2024-10-27T20:01:18+01:00 CVE-2024-7531/nss: does not affect bullseye See also: https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c

Re: [dev-tech-crypto] about CVE-2024-7531 for nss 3.61 in Debian Bullseye

2024-10-27 Thread Arturo Borrero Gonzalez
El miércoles, 23 de octubre de 2024 a las 21:52:57 UTC+2, John Schanck escribió: Hi Arturo, NSS 3.61 is not affected. The bug was introduced in 3.72. Hi John, thanks for this information, it is really valuable for us. Additionally, I would like to double check if this patch [0] is the

Re: [VOTE] Release HttpClient 5.4.1 based on RC1

2024-10-25 Thread Arturo Bernal
+1 Release the packages as HttpClient 5.4.1 Arturo On Fri, Oct 25, 2024 at 9:50 AM Oleg Kalnichevski wrote: > Please vote on releasing these packages as HttpClient 5.4.1. > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are binding.

Re: CVE-2024-7531/nss for debian/bullseye LTS

2024-10-24 Thread Arturo Borrero Gonzalez
Hi, On 10/23/24 23:48, Santiago Ruano Rincón wrote: I added the reference to the commit that introduced the vulnerability after you committed it to the elts security tracker. I have no recollection of this. In any case, upstream confirmed [0] the vulnerability was introduced in nss 3.72. So

Re: CVE-2024-7531/nss for debian/bullseye LTS

2024-10-23 Thread Arturo Borrero Gonzalez
Hi, sorry for the late follow up. On 10/16/24 00:38, Santiago Ruano Rincón wrote: Again, you can also ask upstream. They are in a better position to tell you if the vulnerability is present in 3.61 or not. For the record, I have just now sent an email to upstream: https://groups.google.com/

[dev-tech-crypto] about CVE-2024-7531 for nss 3.61 in Debian Bullseye

2024-10-23 Thread Arturo Borrero Gonzalez
Hi there, I'm interesting in having a patch for CVE-2024-7531 available for the nss version we have in Debian Bullseye (nss 3.61). We have some information [0] about the code that introduced the vulnerability [1] and the patch that fixes it [2], but the patch does not apply cleanly to the code

[Cloud] Re: Fwd: [Cloud VPS alert][wikispeech] Puppet failure on producer.wikispeech.eqiad1.wikimedia.cloud (172.16.0.200)

2024-10-22 Thread Arturo Borrero Gonzalez
On 10/22/24 12:13, Dreamy Jazz wrote: I also got this error today for my instance. Hi there, I can confirm there was a problem today with puppetservers because a Java upgrade. See here for details: https://phabricator.wikimedia.org/T377803 I think the problem should be solved now. regard

Re: [VOTE] Release HttpCore 5.3.1 based on RC1

2024-10-19 Thread Arturo Bernal
+1 Release the packages as HttpCore 5.3.1. Arturo On Sat, Oct 19, 2024 at 12:33 PM Oleg Kalnichevski wrote: > Please vote on releasing these packages as HttpCore 5.3.1. > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are binding. The vo

Re: CVE-2024-7531/nss for debian/bullseye LTS

2024-10-15 Thread Arturo Borrero Gonzalez
On 10/15/24 16:58, Santiago Ruano Rincón wrote: Moreover, I do see the code introduced by that change as part of 2:3.61-1+deb11u3, that relate to HACL* AVX2 support for different crypto algorithms. Could you please give more details about why do you say bullseye doesn't contain the affected code

Re: Host header in HTTP/2 requests / RFC 7540 interpretation

2024-10-12 Thread Arturo Bernal
+1. Being strict. No need to flood the logs Arturo On Sat, Oct 12, 2024 at 3:14 PM Oleg Kalnichevski wrote: > On Sat, 2024-10-12 at 07:43 -0400, Gary Gregory wrote: > > I think the remaining decisions are: > > > > - whether we should log a warning (but not throw an exc

CVE-2024-7531/nss for debian/bullseye LTS

2024-10-12 Thread Arturo Borrero Gonzalez
Hi there, this email is to propose we mark the nss package in debian bullseye as not affected by CVE-2024-7531 [0]. The upstream patch is clearly identified [1], but debian/bullseye [2] just doesn't contain the affected code. We did a similar thing for debian/{jessie,stretch,buster} already

Re: Host header in HTTP/2 requests / RFC 7540 interpretation

2024-10-12 Thread Arturo Bernal
. Arturo On Sat, Oct 12, 2024 at 12:47 PM Oleg Kalnichevski wrote: > Folks > > Presently HttpCore HTTP/2 protocol handler treats HTTP/2 request > messages with a `Host` header as malformed. > > However I just recently discovered that Apache HTTPD happily sends us > push pr

write combining using virtio

2024-10-11 Thread Arturo Vivas
27;t state the same for Alibaba and virtio. I would be thankful for any help in this regard. Regards, Arturo

[jira] [Closed] (HTTPCLIENT-2322) Javadoc lists each class twice

2024-10-06 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2322?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal closed HTTPCLIENT-2322. - Resolution: Fixed Since the duplicate class listings no longer appear, and the

[jira] [Commented] (HTTPCLIENT-2322) Javadoc lists each class twice

2024-10-06 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2322?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17887229#comment-17887229 ] Arturo Bernal commented on HTTPCLIENT-2322: --- [~michael-o] I believ

[jira] [Updated] (HTTPCLIENT-2343) Regression in setting USER_TOKEN context attribute in PoolingHttpClientConnectionManager

2024-10-03 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2343?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal updated HTTPCLIENT-2343: -- Fix Version/s: (was: 5.4.1) Affects Version/s: (was: 5.4

[jira] [Comment Edited] (HTTPCLIENT-2343) Regression in setting USER_TOKEN context attribute in PoolingHttpClientConnectionManager

2024-10-03 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2343?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17886779#comment-17886779 ] Arturo Bernal edited comment on HTTPCLIENT-2343 at 10/3/24 8:0

[jira] [Closed] (HTTPCLIENT-2343) Regression in setting USER_TOKEN context attribute in PoolingHttpClientConnectionManager

2024-10-03 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2343?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal closed HTTPCLIENT-2343. - Resolution: Won't Fix After thorough review and testing, it is clear tha

[jira] [Resolved] (HTTPCLIENT-2233) Metrics missing

2024-10-03 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2233?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal resolved HTTPCLIENT-2233. --- Resolution: Fixed In master > Metrics miss

[jira] [Updated] (HTTPCLIENT-2233) Metrics missing

2024-10-03 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2233?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal updated HTTPCLIENT-2233: -- Fix Version/s: 5.4-alpha1 > Metrics miss

[Cloud] Re: Request for my Cloud VPS project review

2024-09-30 Thread Arturo Borrero Gonzalez
On 9/30/24 02:57, Sulav K Shetri wrote: I had requested an new Cloud VPS project 6 days back and waiting for review or approval but it has been 6 days since my request but till now no one has reviewed it so I wanted to know when will be reviewed and this is the link of my request Request creati

Debian LTS & ELTS report -- September 2024

2024-09-29 Thread Arturo Borrero Gonzalez
Hello, This is my September 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! LTS: I worked on the nss package for Debian Bullseye, with the following highlights: * briefly evaluated CVE-2023-5388, but t

[jira] [Resolved] (HTTPCLIENT-2159) Invalid handling of charset content type parameter

2024-09-29 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2159?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal resolved HTTPCLIENT-2159. --- Fix Version/s: 5.4-alpha1 Resolution: Fixed In master > Inva

[jira] [Resolved] (HTTPCORE-769) Force close on connection when 408 is returned

2024-09-29 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCORE-769?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal resolved HTTPCORE-769. Fix Version/s: 5.4-alpha1 (was: Stuck) Resolution: Fixed

Re: [VOTE][LAZY] Release HttpComponents Parent 14 based on RC1

2024-09-29 Thread Arturo Bernal
+1 Arturo On Thu, Sep 26, 2024 at 9:37 AM Oleg Kalnichevski wrote: > Please lazy vote on releasing HttpComponents Parent 14 based on RC1. > > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are binding. The vote passes if at least one

[dev-tech-crypto] about CVE-2024-6609 for nss 3.61 in Debian Bullseye

2024-09-25 Thread Arturo Borrero Gonzalez
Hi there, I'm interested in having a patch for CVE-2024-6609 available for the nss version we have in Debian Bullseye (nss 3.61). We have a note [0] that mentions this: === 8< === To address CVE in older versions of src:nss what is needed is to add the error handling code (confirmed by upstrea

[Git][security-tracker-team/security-tracker][master] LTS: claim nss in dla-needed.txt

2024-09-25 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 5d6adf76 by Arturo Borrero Gonzalez at 2024-09-25T21:16:28+02:00 LTS: claim nss in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes

[jira] [Commented] (HTTPCLIENT-2344) HTTP/1.1 TLS Upgrade (RFC-2817) should not be default

2024-09-24 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2344?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17884346#comment-17884346 ] Arturo Bernal commented on HTTPCLIENT-2344: --- I still don’t see any i

[jira] [Commented] (HTTPCLIENT-2344) HTTP/1.1 TLS Upgrade (RFC-2817) should not be default

2024-09-24 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2344?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17884323#comment-17884323 ] Arturo Bernal commented on HTTPCLIENT-2344: --- IMO We should stri

[Git][security-tracker-team/security-tracker][master] CVE-2024-6609: bullseye: mark as fixed in nss > 3.61

2024-09-23 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 551af19f by Arturo Borrero Gonzalez at 2024-09-23T22:13:20+02:00 CVE-2024-6609: bullseye: mark as fixed in nss > 3.61 The upstream source code for nss starting with 3.61 contains the

[Git][security-tracker-team/security-tracker][master] CVE-2023-6135: mark as ignored for debian bullseye

2024-09-23 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 88b4b247 by Arturo Borrero Gonzalez at 2024-09-23T21:49:22+02:00 CVE-2023-6135: mark as ignored for debian bullseye Upstream says it is too invasive to fix. See also: https

[dev-tech-crypto] Re: running nss tests/all.sh for Debian package

2024-09-23 Thread Arturo Borrero Gonzalez
El viernes, 13 de septiembre de 2024 a las 19:13:37 UTC+2, Arturo Borrero Gonzalez escribió: Hi there, I'm working on improving CI integration for the nss debian package. [...] If I'm reading the script correctly, it mostly expects to be executed in the context of a freshly-built

[jira] [Commented] (HTTPCLIENT-2159) Invalid handling of charset content type parameter

2024-09-22 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2159?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17883624#comment-17883624 ] Arturo Bernal commented on HTTPCLIENT-2159: --- Hi [~michael-o]  [~res

Re: [VOTE][LAZY] Release HttpComponents CheckStyle 3 based on RC1

2024-09-22 Thread Arturo Bernal
+1 Arturo On Fri, Sep 20, 2024 at 3:46 PM Oleg Kalnichevski wrote: > Please lazy vote on releasing HttpComponents CheckStyle 3 based on RC1. > > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are binding. The vote passes if at least o

[jira] [Commented] (HTTPCLIENT-2343) Regression in setting USER_TOKEN context attribute in PoolingHttpClientConnectionManager

2024-09-21 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2343?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17883475#comment-17883475 ] Arturo Bernal commented on HTTPCLIENT-2343: --- HI [~bratkartoffel] 

[jira] [Commented] (HTTPCLIENT-2342) Regression: Content-Type header not returned anymore

2024-09-20 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2342?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17883231#comment-17883231 ] Arturo Bernal commented on HTTPCLIENT-2342: --- Hi [~ctabin]  I ran a

[jira] [Commented] (HTTPCLIENT-1843) Create module httpclient5-compress to use Apache Commons Compress

2024-09-19 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-1843?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17883111#comment-17883111 ] Arturo Bernal commented on HTTPCLIENT-1843: --- Hi [~ggregory] 

Re: [VOTE] Release HttpClient 5.4 based on RC1

2024-09-16 Thread Arturo Bernal
+1 Release the packages as HttpClient 5.4. Arturo On Mon, Sep 16, 2024 at 5:40 PM Oleg Kalnichevski wrote: > Please vote on releasing these packages as HttpClient 5.4. > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are binding. The vo

[dev-tech-crypto] running nss tests/all.sh for Debian package

2024-09-13 Thread Arturo Borrero Gonzalez
Hi there, I'm working on improving CI integration for the nss debian package. The nss testsuite (which can be run via tests/all.sh) contains a lot of test cases, and I would like to run this script from the debian CI infrastructure. Because the nss package in Debian can receive backported patc

[Git][security-tracker-team/security-tracker][master] LTS: claim nss in dla-needed.txt

2024-09-04 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: c0316a58 by Arturo Borrero Gonzalez at 2024-09-04T17:44:53+02:00 LTS: claim nss in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes

Debian LTS & ELTS report -- August 2024

2024-08-28 Thread Arturo Borrero Gonzalez
Hello, This is my August 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! LTS: I did not engage in any LTS activities this month. ELTS: I spent my available time this month working on two packages:

Bug#1079219: RFP: LightPad -- A plugin for XFCE DE that shows a grid menu applications like GNOME

2024-08-21 Thread Arturo Ingenito
Package: wnpp Severity: wishlist Owner: Arturo Ingenito * Package name : lightpad Version : 0.0.8 Upstream Author : DEB Libre * URL : https://github.com/libredeb * License : GPL Description : A plugin for XFCE DE that shows a grid menu like GNOME The Lightpad plugin for XFCE is a lightweight

Bug#1079219: RFP: LightPad -- A plugin for XFCE DE that shows a grid menu applications like GNOME

2024-08-21 Thread Arturo Ingenito
Package: wnpp Severity: wishlist Owner: Arturo Ingenito * Package name : lightpad Version : 0.0.8 Upstream Author : DEB Libre * URL : https://github.com/libredeb * License : GPL Description : A plugin for XFCE DE that shows a grid menu like GNOME The Lightpad plugin for XFCE is a lightweight

Debian LTS & ELTS -- June 2024

2024-08-01 Thread Arturo Borrero Gonzalez
Hello, Here is my July 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! This month, again, I would like to thank Santiago for the assistance, review and support. LTS: I did not engage in any LTS activi

Bug#1076389: ITS: rpmlint

2024-07-15 Thread Arturo Borrero Gonzalez
Please go ahead, no need for delay. I have no time (or interest) in this package anymore. You may drop me from the maintainer list as well.

[Cloud-announce] Toolforge operation scheduled for 2024-07-16 @ 09:00 UTC

2024-07-12 Thread Arturo Borrero Gonzalez
Hi there, The Toolforge Kubernetes system has been scheduled to be upgraded to version 1.25 [0] next Tuesday 2024-07-17 @ 09:00 UTC. The operation window will last 2 hours, and during this time, some Toolforge components will briefly and intermittently become unavailable. Examples of things

[Cloud] Toolforge operation scheduled for 2024-07-16 @ 09:00 UTC

2024-07-12 Thread Arturo Borrero Gonzalez
Hi there, The Toolforge Kubernetes system has been scheduled to be upgraded to version 1.25 [0] next Tuesday 2024-07-17 @ 09:00 UTC. The operation window will last 2 hours, and during this time, some Toolforge components will briefly and intermittently become unavailable. Examples of things

Re: Leer puerto desde RPGLE de una bascula

2024-07-10 Thread Jorge Arturo Perez
rights in the terms established in the > current regulations by contacting us. Likewise, you can request us to send > additional information about our data protection policy, tel 961 920 029, > e-mail: proteccionda...@silomar.es > > Únete a Recursos AS400, nuestra Comunidad ( http://bit.ly/db68dd ) > Forum.Help400 � Publicaciones Help400, S.L. > -- *Jorge Arturo Pèrez Osorio.* . Únete a Recursos AS400, nuestra Comunidad ( http://bit.ly/db68dd ) Forum.Help400 � Publicaciones Help400, S.L.

[GROW]Re: Working Group Call for Adoption for draft-ramseyer-grow-peering-api (start 07/Jun/2024 end 21/Jun/2024)

2024-07-02 Thread Arturo Servin
upport and something is missing, we are open to it. Regards as On Fri, 28 Jun 2024 at 19:06, Matthias Wichtlhuber < matthias.wichtlhu...@de-cix.net> wrote: > Hi Arturo, > > > One assumption that we have is that the Peering Database (in this case > PeeringDB but it could be any)

Debian LTS & ELTS -- June 2024

2024-06-30 Thread Arturo Borrero Gonzalez
Hello, Here is my June 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! Turns out, this was my first month working on the LTS/ELTS projects, and I would like to thank Santiago for the assistance, review, suppo

Debian LTS & ELTS -- June 2024

2024-06-30 Thread Arturo Borrero Gonzalez
Hello, Here is my June 2024 monthly report for the Freexian LTS/ELTS [1] initiative. Many thanks to Freexian and sponsors [2] for providing this opportunity! Turns out, this was my first month working on the LTS/ELTS projects, and I would like to thank Santiago for the assistance, review, suppo

[SECURITY] [DLA 3846-1] libmojolicious-perl security update

2024-06-30 Thread Arturo Borrero Gonzalez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3846-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Arturo Borrero Gonzalez June 28, 2024

[Git][security-tracker-team/security-tracker][master] data/CVE/list: ignore nss CVE-2023-6135 in buster

2024-06-28 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: dd290270 by Arturo Borrero Gonzalez at 2024-06-28T23:28:37+02:00 data/CVE/list: ignore nss CVE-2023-6135 in buster Not fixing nss CVE-2023-6135 in Debian Buster. Signed-off-by: Arturo

Re: Bad signature for jspwiki-wikipages-de-2.12.2.zip

2024-06-28 Thread Arturo Bernal
Cheking Arturo On Fri, Jun 28, 2024 at 6:47 PM Florian Preinstorfer < lists-jspw...@nblock.org> wrote: > Hi, > Am 2024-06-26 19:09, schrieb Arturo Bernal: > >I apologize for the confusion and any inconvenience caused by the > >invalid signatures. If you encounter any fu

[GROW]Re: Working Group Call for Adoption for draft-ramseyer-grow-peering-api (start 07/Jun/2024 end 21/Jun/2024)

2024-06-28 Thread Arturo Servin
Matthias One assumption that we have is that the Peering Database (in this case PeeringDB but it could be any) is the canonical source of most of the information that you need to set up a peering session. In the case of RS, all that information is already there and there is no need to add it agai

Re: [VOTE] Release HttpCore 5.2.5 based on RC1

2024-06-27 Thread Arturo Bernal
+1 Release the packages as HttpCore 5.2.5. Arturo On Thu, Jun 27, 2024 at 10:25 AM Oleg Kalnichevski wrote: > Please vote on releasing these packages as HttpCore 5.2.5. > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are binding. The vo

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3846-1 for libmojolicious-perl

2024-06-27 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 7c515ba9 by Arturo Borrero Gonzalez at 2024-06-27T22:59:02+02:00 Reserve DLA-3846-1 for libmojolicious-perl - - - - - 2 changed files: - data/DLA/list - data/dla-needed.txt Changes

Re: [dev-tech-crypto] about CVE-2023-6125 in nss 3.42.1 in Debian Buster

2024-06-27 Thread Arturo Borrero Gonzalez
On 6/27/24 21:12, John Schanck wrote: Hi Arturo, we don't plan on backporting any of the patches for CVE-2023-6135 to the NSS 3.90 branch at this time. The patches you linked to are, unfortunately, not sufficient to fix the issue. Short of copying the entire lib/freebl/ecl directory fro

[jira] [Created] (JSPWIKI-1194) CI/CD Pipeline Optimization for Apache JSPWiki with JDK-17 Integration

2024-06-26 Thread Arturo Bernal (Jira)
Arturo Bernal created JSPWIKI-1194: -- Summary: CI/CD Pipeline Optimization for Apache JSPWiki with JDK-17 Integration Key: JSPWIKI-1194 URL: https://issues.apache.org/jira/browse/JSPWIKI-1194 Project

[jira] [Updated] (JSPWIKI-1194) CI/CD Pipeline Optimization for Apache JSPWiki with JDK-17 Integration

2024-06-26 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/JSPWIKI-1194?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal updated JSPWIKI-1194: --- Assignee: Arturo Bernal > CI/CD Pipeline Optimization for Apache JSPWiki with JDK

Re: Bad signature for jspwiki-wikipages-de-2.12.2.zip

2024-06-26 Thread Arturo Bernal
reach out. Best regards, Arturo On Tue, Jun 25, 2024 at 11:38 AM Arturo Bernal wrote: > Hi All, > > I'm okay with not doing a new release and instead replacing the files that > have signature issues. > > > Arturo > > > On Mon, Jun 24, 2024 at

[Cloud-announce] Toolforge: introducing new security policy engine 2024-06-26 @ 08:30 UTZ

2024-06-25 Thread Arturo Borrero Gonzalez
Hi there, tomorrow 2024-06-26 @ 08:30Z we will start enforcing new Kubernetes security rules in Toolforge [0]. We have taken measures to eliminate any user impact, but this being a potentially sensitive change, I wanted to send a heads up email. In a nut-shell, pod-related kubernetes resour

Re: [dev-tech-crypto] about CVE-2023-6125 in nss 3.42.1 in Debian Buster

2024-06-25 Thread Arturo Borrero Gonzalez
On 6/24/24 18:25, Dana Keeler wrote: To save others from potential confusion, the CVE in question is CVE-2023-6135, not 6125. Correct, there was a typo on my side. -- You received this message because you are subscribed to the Google Groups "dev-tech-crypto@mozilla.org" group. To unsubscrib

Re: Bad signature for jspwiki-wikipages-de-2.12.2.zip

2024-06-25 Thread Arturo Bernal
Hi All, I'm okay with not doing a new release and instead replacing the files that have signature issues. Arturo On Mon, Jun 24, 2024 at 9:57 PM Juan Pablo Santos Rodríguez < juanpablo.san...@gmail.com> wrote: > Hi! > > my bad: gpg --keyserver hkps://pgp.mit.edu/ --re

Re: Bad signature for jspwiki-wikipages-de-2.12.2.zip

2024-06-24 Thread Arturo Bernal
Hi, The key is available (gpg --list-keys --fingerprint 2D51AAC6), but I don't think that will solve the issue. It seems that I might have generated the signature incorrectly. I checked and, yes, there are binaries that were signed correctly. Verification worked for jspwiki-portable-2.12.2-woas

Re: Bad signature for jspwiki-wikipages-de-2.12.2.zip

2024-06-24 Thread Arturo Bernal
resses all potential issues. what do you think? Best regards, Arturo On Sat, Jun 22, 2024 at 6:05 PM Arturo Bernal wrote: > Hi, > > Let me check. > > Cheers > > > Arturo > > > On Sat, Jun 22, 2024 at 6:03 PM Florian Preinstorfer < > lists-jspw...@nblock.o

Re: [VOTE] Release HttpClient 5.4-beta1 based on RC1

2024-06-24 Thread Arturo Bernal
+1 Release the packages as HttpClient 5.4-beta1. Arturo On Sun, Jun 23, 2024 at 11:09 AM Oleg Kalnichevski wrote: > Please vote on releasing these packages as HttpClient 5.4-beta1. > The vote is open for the at least 72 hours, and only votes from > HttpComponents PMC members are bin

[dev-tech-crypto] about CVE-2023-6125 in nss 3.42.1 in Debian Buster

2024-06-23 Thread Arturo Borrero Gonzalez
Hi there, I am exploring how to fix CVE-2023-6125 in the nss package (version 3.42.1) in Debian Buster. There is a note from a Debian college saying that we should wait until you have backported the fix to the 3.90 series, but scanning your releases did not immediately showed to me where (if

Re: Bad signature for jspwiki-wikipages-de-2.12.2.zip

2024-06-22 Thread Arturo Bernal
Hi, Let me check. Cheers Arturo On Sat, Jun 22, 2024 at 6:03 PM Florian Preinstorfer < lists-jspw...@nblock.org> wrote: > Hi, > it seems the GPG signature for jspwiki-wikipages-de-2.12.2.zip is > invalid: > >wget -q > https://archive.apache.org/dist/jspwiki/

[Git][security-tracker-team/security-tracker][master] data/dla-needed: claim libmojolicious-perl

2024-06-22 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: 7cf13c7e by Arturo Borrero Gonzalez at 2024-06-22T14:49:55+02:00 data/dla-needed: claim libmojolicious-perl Claim this package, I'll work on it. Signed-off-by: Arturo Borrero Gonzalez

[Git][security-tracker-team/security-tracker][master] data/dla-needed: add note about CVE-2023-6125 for nss

2024-06-22 Thread @arturo
Arturo Borrero González pushed to branch master at Debian Security Tracker / security-tracker Commits: e5209be0 by Arturo Borrero Gonzalez at 2024-06-22T14:08:07+02:00 data/dla-needed: add note about CVE-2023-6125 for nss Add new note. Signed-off-by: Arturo Borrero Gonzalez <

[jira] [Resolved] (HTTPCLIENT-2331) Single cookie header should be sent for multiple cookies

2024-06-19 Thread Arturo Bernal (Jira)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-2331?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Arturo Bernal resolved HTTPCLIENT-2331. --- Resolution: Fixed Solved https://github.com/apache/httpcomponents-client/pull

[ANNOUNCE] Apache JSPWiki 2.12.2 released

2024-06-19 Thread Arturo Bernal
: https://jspwiki-wiki.apache.org/Wiki.jsp?page=NewIn2.12 We welcome your help and feedback. For more information on how to report problems, and to get involved visit the project website at http://jspwiki.apache.org/ The Apache JSPWiki Team Arturo

  1   2   3   4   5   6   7   8   9   10   >