Bug#856879: [src:imagemagick] out-of-bounds read

2017-03-05 Thread Bastien ROUCARIÈS
Package: src:imagemagick Version: 8:6.6.0.4-3 Severity: serious Tags: security X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org control: found -1 8:6.7.7.10-5 control: found -1 8:6.8.9.9-5 forwarded: https://github.com/ImageMagick/ImageMagick/issues/375 See also https://github.com/ImageMa

Bug#856878: [src:imagemagick] Assertion failure in TGA coder

2017-03-05 Thread Bastien ROUCARIÈS
Package: src:imagemagick Version: 8:6.6.0.4-3 Severity: serious Tags: security X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org control: found -1 8:6.7.7.10-5 control: found -1 8:6.8.9.9-5 forwarded: https://github.com/ImageMagick/ImageMagick/pull/359. Fixed in 65f75a32a93ae4044c528a987a6

Bug#856880: [src:imagemagick] Fixed memory leak when creating nested exceptions in Magick++

2017-03-05 Thread Bastien ROUCARIÈS
Package: src:imagemagick Version: 8:6.6.0.4-3 Severity: serious Tags: security X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org control: found -1 8:6.7.7.10-5 control: found -1 8:6.8.9.9-5 forwarded: https://www.imagemagick.org/discourse-server/viewtopic.php?f=23&p=142634 Fixed in 3358f0

Bug#856881: [src:imagemagick] Avoid null pointer dereference in xcf coder

2017-03-05 Thread Bastien ROUCARIÈS
Package: src:imagemagick Version: 8:6.6.0.4-3 Severity: serious Tags: security X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org control: found -1 8:6.7.7.10-5 control: found -1 8:6.8.9.9-5 Fixed in d31fec57e9dfb0516deead2053a856e3c71e9751 From Андрей Черный signature.asc Description: Th

Bug#856882: [src:imagemagick] Added missing null check in psd coder

2017-03-05 Thread Bastien ROUCARIÈS
Package: src:imagemagick Version: 8:6.6.0.4-3 Severity: serious Tags: security X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org control: found -1 8:6.7.7.10-5 control: found -1 8:6.8.9.9-5 Fixed in 7f2dc7a1afc067d0c89f12c82bcdec0445fb1b94 signature.asc Description: This is a digitally

Bug#856883: [src:imagemagick] Fixed fd leak for webp coder

2017-03-05 Thread Bastien ROUCARIÈS
Package: src:imagemagick Version: 8:6.6.0.4-3 Severity: serious Tags: security X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org control: found -1 8:6.7.7.10-5 control: found -1 8:6.8.9.9-5 Does not affect debian due to webp not compiled by default. So not important Fixed in 126c7c98ea788

Bug#918628: node-stream-splicer FTBFS with nodejs 10.15.0

2019-01-13 Thread Bastien Roucariès
Package: node-stream-splicer Version: 2.0.0 Followup-For: Bug #918628 control: forwarded -1 https://github.com/browserify/stream-splicer/issues/11 control: tags -1 + upstream -- System Information: Debian Release: buster/sid APT prefers testing APT policy: (900, 'testing') Architecture: amd

Bug#795716: [libtest-perl-critic-perl] lintian FTBFS with new version

2015-08-16 Thread Bastien ROUCARIÈS
Package: libtest-perl-critic-perl Version: 1.03-1 Severity: serious control: affects -1 lintian Sid version FTBFS whereas testing work fine see https://jenkins.debian.net/job/lintian-tests_sid/ Bastien signature.asc Description: This is a digitally signed message part.

Bug#851307: [vtable-dumper] New upstream version fixing securities bug

2017-01-13 Thread Bastien ROUCARIÈS
Package: vtable-dumper Severity: serious Tags: patch security X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org Hi, vtable dumper could be run from network process in order to test remote binaries. Newer version fix some security bug like off-by-ones, segfault and memory leak Thanks s

Bug#851376: [imagemagick] memory corruption heap overflow

2017-01-14 Thread Bastien ROUCARIÈS
Package: imagemagick Version: 8:6.7.7.10-5 Severity: serious Tags: patch security fixed-upstream X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org forwarded: https://github.com/ImageMagick/ImageMagick/issues/348 Memory corruption via a PSB file another one. Please open a CVE or merge wit

Bug#851374: [imagemagick] memory corruption heap overflow

2017-01-14 Thread Bastien ROUCARIÈS
Package: imagemagick Version: 8:6.7.7.10-5 Severity: serious Tags: patch security fixed-upstream X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org forwarded: https://github.com/ImageMagick/ImageMagick/issues/347 Specially crafted PSB file create a memory corruption. Please open a CVE s

Bug#851377: [imagemagick] out of bound in psd file handling

2017-01-14 Thread Bastien ROUCARIÈS
Package: imagemagick Version: 8:6.7.7.10-5 Severity: serious Tags: patch security fixed-upstream X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org forwarded: https://github.com/ImageMagick/ImageMagick/issues/350 Memory corruption via a PSB file another one. Please open a CVE or merge wit

Bug#851380: [imagemagick] memory leak in caption and label handling

2017-01-14 Thread Bastien ROUCARIÈS
Package: imagemagick Version: 8:6.7.7.10-5 Severity: serious Tags: patch security fixed-upstream X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org forwarded: https://github.com/ImageMagick/ImageMagick/commit/aeff00de228bc5a158c2a975ab47845d8a1db456 Fixed here https://github.com/ImageMag

Bug#851381: [imagemagick] Crash - PushQuantumPixel - Heap-Buffer-Overflow (TIFF)

2017-01-14 Thread Bastien ROUCARIÈS
Package: imagemagick Version: 8:6.7.7.10-5 Severity: serious Tags: patch security fixed-upstream X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org forwarded: https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=31161 Fixed here https://github.com/ImageMagick/ImageMagick/comm

Bug#851382: [imagemagick] memory leak in MPC file handling

2017-01-14 Thread Bastien ROUCARIÈS
Package: imagemagick Version: 8:6.7.7.10-5 Severity: serious Tags: patch security fixed-upstream X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org forwarded: https://github.com/ImageMagick/ImageMagick/commit/4493d9ca1124564da17f9b628ef9d0f1a6be9738 Fixed here https://github.com/ImageMag

Bug#851383: [imagemagick] double free in profile

2017-01-14 Thread Bastien ROUCARIÈS
Package: imagemagick Version: 8:6.7.7.10-5 Severity: serious Tags: patch security fixed-upstream X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org forwarded:https://github.com/ImageMagick/ImageMagick/issues/354 Fixed https://github.com/ImageMagick/ImageMagick/commit/6235f1f7a9f7b0f83b197

Bug#851483: [imagemagick] wpg file off by one

2017-01-15 Thread Bastien ROUCARIÈS
Package: src:imagemagick Version: 8:6.7.7.10-5 Severity: serious Tags: patch security fixed-upstream X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org Fix a off by one error Fixed https://github.com/ImageMagick/ImageMagick/commit/d23beebe7b1179fb75db1e85fbca3100e49593d9 signature.asc

Bug#851485: [imagemagick] ipl file missing malloc check

2017-01-15 Thread Bastien ROUCARIÈS
Package: src:imagemagick Version: 8:6.7.7.10-5 Severity: serious Tags: patch security fixed-upstream X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org Fixed https://github.com/ImageMagick/ImageMagick/commit/97566cf2806c0a5a86e884c96831a0c3b1ec6c20 signature.asc Description: This is a d

Bug#851374: found in stable and unstable

2017-01-15 Thread Bastien ROUCARIÈS
control: found -1 8:6.8.9.9-5+deb8u6 control: found -1 8:6.8.9.9-5 control: found -1 8:6.9.6.6+dfsg-1 control: found -1 8:6.9.6.6+dfsg-2 signature.asc Description: This is a digitally signed message part.

Bug#1038902: docker.io: FTBFS skip btrfs

2023-06-22 Thread Bastien Roucariès
Source: docker.io Severity: serious Tags: ftbfs control: tags -1 + patch Justification: FTBFS Dear Maintainer, I had applied the following patch for compiling under btrfs for buster. Could you refresh and apply for other version BastienFrom: =?utf-8?q?Bastien_Roucari=C3=A8s?= Date: Thu, 22 Jun

Bug#1039083: crun: Embed yajl

2023-06-25 Thread Bastien Roucariès
Source: crun Severity: serious Justification: embed code copy devref Dear Maintainer, Your package include an embed code copy of yajl Could you please: - deembed - the repack (+ds source if needed) in order to be sure it will be not compiled in by accident in newer release Thanks Bastien -- S

Bug#1039085: burp: embed yajl

2023-06-25 Thread Bastien Roucariès
Source: burp Severity: serious Justification: devref Dear Maintainer, Your package embed a code copy of yajl. Could you: - build against yajl debian package - repack your package removing the emded code copy in order to avoid accidental compilation in future. Thanks rouca -- System Informatio

Bug#1039086: collada2gltf: Embed yajl

2023-06-25 Thread Bastien Roucariès
Source: collada2gltf Severity: serious Justification: devref Dear Maintainer, Your package embed a copy a yajl Could you: - build against yajl package - remove by repacking the code copy in order to avoid in the future accidental code compilation against the embed code copy Thanks Bastien --

Bug#1039087: epic-base: embed yajl

2023-06-25 Thread Bastien Roucariès
Source: epic-base Severity: serious Justification: devref Dear Maintainer, Your package embed a copy of yajl. Could you: - compile against the packaged yajl package - remove by repacking the embded code copy in order to avoid accidental compilation of the embed code copy Thanks Rouca -- Syst

Bug#1039088: whitedb: embed yajl

2023-06-25 Thread Bastien Roucariès
Source: whitedb Version: embed yajl Severity: serious Justification: devref Dear Maintainer, Your package embed a copy of yajl. Could you: - compile against debian yajl package - remove by repacking the yajl code copy in order to accidentally compile the embed code copy Thanks Rouca -- System

Bug#1039119: darktable: use packaged lua

2023-06-25 Thread Bastien Roucariès
Source: darktable Version: Use packaged lua Severity: serious Justification: embded code copy Dear Maintainer, It appear that your package embded and compile lua Could you: - use the packaged lua lib - repack in order to avoid accidental reintroduction of compiling lua rouca -- System Informa

Bug#1039438: enigma: Embded and use lua copy (outdated)

2023-06-25 Thread Bastien Roucariès
Source: enigma Severity: serious Tags: security Justification: embded X-Debbugs-Cc: Debian Security Team Dear Maintainer, You ship a outdated and embed lua: - could you use the system library - repack in order to avoid compiling accidentally the embded version Bastien -- System Information: D

Bug#1031859: false positive of embedded expat library leads to ftp-master rejection

2023-02-25 Thread Bastien Roucariès
control: tags -1 +moreinfo Le vendredi 24 février 2023, 11:28:18 UTC Matthias Klose a écrit : > Package: lintian > Version: 2.116.3 > Severity: serious > Tags: sid bookworm > > seen with the binary packages from > https://people.debian.org/~doko/tmp/ > > $ lintian -F python3.12_3.12.0~a5-1_amd64.

Bug#1031952: gettext: Missing source for an installed windows binary

2023-02-25 Thread Bastien Roucariès
Package: gettext Version: 0.21-11 Severity: serious Tags: ftbfs upstream Justification: DFSG #2 User: lintian-ma...@debian.org Usertags: source-is-missing X-Debbugs-Cc: ftpmas...@debian.org Hi, your package includes some files that seem to lack sources in preferred forms of modification: gettext-

Bug#1031859: false positive of embedded expat library leads to ftp-master rejection

2023-02-26 Thread Bastien Roucariès
control: tags -1 + moreinfo Le dimanche 26 février 2023, 13:17:54 UTC Matthias Klose a écrit : Hi, > control: tags -1 -moreinfo > > On 25.02.23 15:14, Bastien Roucariès wrote: > > control: tags -1 +moreinfo > > Le vendredi 24 février 2023, 11:28:18 UTC Matthias Klose a

Bug#1032188: node-css-what: CVE-2022-21222/CVE-2021-33587

2023-03-01 Thread Bastien Roucariès
Package: node-css-what Version: 4.0.0-3 Severity: serious Tags: security Justification: security X-Debbugs-Cc: Debian Security Team Dear Maintainer, Find the minimal ReDoS fix for 4.0.0, checked with recheck Bastien>From eeb1fafd26a9f09114b6f8282a9569f99d52d716 Mon Sep 17 00:00:00 2001 From: =?

Bug#1032188: debdiff

2023-03-01 Thread Bastien Roucariès
+re_attr variable. +The exploitation of this vulnerability could be triggered +via the parse function. +Fix CVE-2022-21222, CVE-2021-33587 (Closes: #989264, #1032188) + + -- Bastien Roucariès Wed, 01 Mar 2023 13:47:23 + + node-css-what (4.0.0-3) unstable; urgency=medium * Team

Bug#1032188: Old stable debdiff

2023-03-01 Thread Bastien Roucariès
expression in the +re_attr variable. +The exploitation of this vulnerability could be triggered +via the parse function. +Fix CVE-2022-21222, CVE-2021-33587 (Closes: #989264, #1032188) + + -- Bastien Roucariès Wed, 01 Mar 2023 15:33:15 + + node-css-what (2.1.0-1) unstable

Bug#1032188: old old stable debdiff

2023-03-01 Thread Bastien Roucariès
triggered +via the parse function. +Fix CVE-2022-21222, CVE-2021-33587 (Closes: #989264, #1032188) + + -- Bastien Roucariès Wed, 01 Mar 2023 15:33:15 + + node-css-what (2.1.0-1) unstable; urgency=medium * new upstream version diff -Nru node-css-what-2.1.0/debian/patches/0001-Partial

Bug#1033223: chromium: #ozone-platform-hint should be set to auto

2023-03-20 Thread Bastien Roucariès
Package: chromium Version: 111.0.5563.64-1 Severity: serious Tags: patch Justification: unusable under wayland kde Dear Maintainer, Under wayland chromium tab are unresponsible to mouse. #ozone-platform-hint set to auto instead of default help here to detect wayland. Could you set this option ?

Bug#1040141: FTBFS: FAIL: TestCheckoutGit

2023-07-02 Thread Bastien Roucariès
Source: docker.io Version: 18.09.1+dfsg1-7.1+deb10u3 Severity: serious Justification: FTBFS X-Debbugs-Cc: debian-...@lists.debian.org Dear Maintainer, The current security version FTBFS for me with -- FAIL: TestCheckoutGit (0.52s) gitutils_test.go:188: assertion failed: error is not nil: exit

Bug#974430: plasma-workspace-wayland: Undefined symbols: Need rebuild ?

2020-11-11 Thread Bastien Roucariès
Package: plasma-workspace-wayland Version: 4:5.17.5-4 Severity: grave Justification: renders package unusable Dear Maintainer, This package crash. Log contains the following error, that point to a missing deps or a missing rebuild: /usr/lib/x86_64-linux-gnu/libkwin.so.5: undefined symbol: _ZN12Sc

Bug#863480: [node-static-module] Uninitialized Memory Exposure

2017-05-27 Thread Bastien ROUCARIÈS
Package: node-static-module Version: 1.3.1-1 Severity: grave Tags: patch security fixed-upstream X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org forwarded: https://snyk.io/vuln/npm:concat-stream:20160901 concat-stream is writable stream that concatenates strings or binary data and calls

Bug#863481: [node-concat-stream] Uninitialized Memory Exposure

2017-05-27 Thread Bastien ROUCARIÈS
Package: node-concat-stream Version: 1.5.1-1 Severity: grave Tags: patch security fixed-upstream fixed-in-experimental X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org forwarded: https://snyk.io/vuln/npm:concat-stream:20160901 Overview concat-stream is writable stream that concatenates s

Bug#858725: [src:gitlab] FTBFS for /vendor/assets/javascripts/fuzzaldrin-plus.js and incomplete copyright

2017-03-25 Thread Bastien ROUCARIÈS
Package: src:gitlab Version: 8.13.11+dfsg-8 Severity: serious /vendor/assets/javascripts/fuzzaldrin-plus.js is a concatenation of few files. Moreover copyright file lack some part of copyright of this file. I suppose moreover that some concatenation has lost some part of license and author

Bug#859865: [node-test] Package does not package test directory => FTBFS other package

2017-04-08 Thread Bastien ROUCARIÈS
Package: node-test Version: 0.6.0-2 Severity: serious owner: ! will do signature.asc Description: This is a digitally signed message part.

Bug#860438: [node-jsonstream] Install binary with wrong name

2017-04-16 Thread Bastien ROUCARIÈS
Package: node-jsonstream Version: 1.0.3-2 Severity: serious Upstream binary is JSONStream not jsonstream. Will fix Bastien signature.asc Description: This is a digitally signed message part.

Bug#860483: [node-minimalistic-assert] Could be replaced by node-assert

2017-04-17 Thread Bastien ROUCARIÈS
Package: node-minimalistic-assert Severity: serious This is only two function of node-assert.. This module is compatible with node-assert. so nuke it before it go to release signature.asc Description: This is a digitally signed message part.

Bug#849829: [arc-gui-clients] Some sources are not included in your package

2016-12-31 Thread Bastien ROUCARIÈS
Package: arc-gui-clients Version: 0.4.6-3 user: lintian-ma...@debian.org usertags: source-is-missing severity: serious X-Debbugs-CC: ftpmas...@debian.org Hi, your package includes some files that seem to lack sources in preferred forms of modification: * docs/users_guide/build/html/_static

Bug#849830: [src:digikam] Some sources are not included in your package

2016-12-31 Thread Bastien ROUCARIÈS
Package: src:digikam Version: 4:5.3.0-1 user: lintian-ma...@debian.org usertags: source-is-missing severity: serious X-Debbugs-CC: ftpmas...@debian.org Hi, your package includes some files that seem to lack sources in preferred forms of modification (even if removed during clean target). I have c

Bug#872480: [node-acorn] Need depends on nodejs > 6

2017-08-17 Thread Bastien ROUCARIÈS
Package: node-acorn Version: 5.0.3-1 Severity: grave This version use a lot of depends of nodejs > 6 YOu could drop the second patch serie and use an hard depends acorn fail on testing Bastien signature.asc Description: This is a digitally signed message part.

Bug#840428: Forwarded

2016-10-24 Thread Bastien ROUCARIÈS
control: forwarded -1 https://github.com/ImageMagick/PythonMagick/issues/5 signature.asc Description: This is a digitally signed message part.

Bug#842303: [web2py] License problem and source missing

2016-10-27 Thread Bastien ROUCARIÈS
Package: web2py Version: 2.12.3-1 Severity: serious usertags: source-is-missing severity: serious X-Debbugs-CC: ftpmas...@debian.org Hi, your package includes some files that seem to lack sources in preferred forms of modification (analytic seems to be google analytic under non free license):

Bug#991982: nano does not work with TERM unsetted

2021-08-07 Thread Bastien Roucariès
Package: nano Version: 5.4-2 Severity: grave Tags: upstream buster-ignore bullseye-ignore Justification: Policy 11.4 Control: affects -1 sensible-utils Dear Maintainer, Feel free to downgrade to important, but this bug affects sensible utils in case of disaster recovery so mark as grave (nano is

Bug#991982: nano does not work with TERM unset

2021-08-08 Thread Bastien Roucariès
Le dimanche 8 août 2021, 10:04:30 UTC Benno Schulenberg a écrit : > > $env -i nano > > command fail because TERM is unset > > I can work around an unset TERM. But what if TERM=="" or TERM=="nonsense"? > Checking whether TERM is a valid terminal name goes too far, in my opinion. > > Also, is the

Bug#991982: nano does not work with TERM unset

2021-08-09 Thread Bastien Roucariès
Le dimanche 8 août 2021, 14:57:42 UTC Bastien Roucariès a écrit : > Le dimanche 8 août 2021, 10:04:30 UTC Benno Schulenberg a écrit : > > > $env -i nano > > > command fail because TERM is unset > > > > I can work around an unset TERM. But what if TERM=="&

Bug#991982: nano does not work with TERM unset

2021-08-09 Thread Bastien Roucariès
Le dimanche 8 août 2021, 10:04:30 UTC Benno Schulenberg a écrit : > > $env -i nano > > command fail because TERM is unset > > I can work around an unset TERM. But what if TERM=="" or TERM=="nonsense"? > Checking whether TERM is a valid terminal name goes too far, in my opinion. > > Also, is the

Bug#991982: nano does not work with TERM unset

2021-08-10 Thread Bastien Roucariès
Le mardi 10 août 2021, 08:05:00 UTC Benno Schulenberg a écrit : > Op 09-08-2021 om 15:08 schreef Bastien Roucariès: > > nano work with TERM=dumb (but is strange but it work), > > For me, 'TERM=dumb nano somefile' does not work, not on a console, not > on an xterm, not

Bug#992150: Please allow symlink in system extension

2021-08-13 Thread Bastien Roucariès
Package: firefox Version: 57.0.0 Severity: serious Tags: upstream Justification: Policy 4.13 Forwarded: https://bugzilla.mozilla.org/show_bug.cgi?id=1420286 X-Debbugs-Cc: pkg-javascript-de...@lists.alioth.debian.org Control: tags -1 + security Hi, By default firefox does not allow symlink in syst

Bug#992150: Please allow symlink in system extension

2021-08-16 Thread Bastien Roucariès
Followup-For: Bug #992150 Control: clone -1 src:firefox-esr

Bug#993301: prototypejs: FTBFS

2021-08-30 Thread Bastien Roucariès
Source: prototypejs Severity: serious Justification: 4 Dear Maintainer, The source is https://github.com/prototypejs/prototype/tree/master and need rake for building... So FTBFS Bastien

Bug#993659: firefox-esr: FTBFS and embeded copy of code

2021-09-04 Thread Bastien Roucariès
Source: src:firefox-esr Version: FTBFS and embdeded copy Severity: serious Tags: upstream ftbfs Control: clone -1 -2 Control: affects -2 src:firefox Dear Maintainer, I could not found the source of the following files https://sources.debian.org/src/firefox- esr/78.13.0esr-1/devtools/client/debugg

Bug#994451: golang-github-containers-common: secomp.json does not include newer syscall used by stable kernel/glibc on arm

2021-09-16 Thread Bastien Roucariès
Package: golang-github-containers-common Version: 0.33.4+ds1-1 Severity: critical Tags: upstream Forwarded: https://github.com/containers/common/commit/42d1db16bfc0dbaee5781d230dc2bcbaa0849c6e Control: fixed -1 0.42.1+ds1-1 Dear Maintainer, golang-github-containers-common in stable does not incl

Bug#994603: node-stringprep: FTBFS or build empty lib

2021-09-18 Thread Bastien Roucariès
Source: node-stringprep Severity: grave Tags: upstream Justification: renders package unusable Dear Maintainer, Trying to convert this package to arch:foreign due to an upstream error when we removed icu-config this package does not compile source, thus ship an empty lib.. I tried to get the sou

Bug#994612: nodjes: Please fix nodejs debci regression

2021-09-18 Thread Bastien Roucariès
Package: nodjes Version: 12.22.5~dfsg-3 Severity: serious Dear Maintainer, Debci fail with against 12.22.5~dfsg-2 with: duration_ms: 0.293 severity: fail exitcode: 1 stack: |- assert.js:101 throw new AssertionError(obj); ^ AssertionError [ERR_ASSERTION]: Expected valu

Bug#994703: nodejs: please documents deps or avoid it

2021-09-19 Thread Bastien Roucariès
Package: nodejs Version: 12.22.5~dfsg-2 Severity: serious Dear Maintainer, README.source should document the deps directory. It will be better to remove some libs from deps. Why libz is needed for node ? Could we push this plugin stuff to libz and so on. Acorn embdeded should be fixed by recent

Bug#994720: nodejs: Please depends of sse2-support

2021-09-19 Thread Bastien Roucariès
Source: nodejs Severity: serious Tags: patch Justification: base arch Forwarded: https://chromium.googlesource.com/v8/v8.git/+/e825c4318eb2065ffdf9044aa6a5278635c36427 Dear Maintainer, libv8 need sse2 on i386 since 2017... I asked upstream better communication with us, but we must depends on ss

Bug#994974: node-define-property: Please deembed and fix vulnereability

2021-09-24 Thread Bastien Roucariès
Package: node-define-property Severity: serious Tags: security upstream fixed-upstream Justification: security bug Forwarded: https://github.com/jonschlinkert/define-property/pull/6 X-Debbugs-Cc: Debian Security Team Dear Maintainer, According to https://www.npmjs.com/advisories/1490 node-define

Bug#995722: loash: Vendoring should be removed

2021-10-04 Thread Bastien Roucariès
Source: src:node-lodash Version: 4.17.21+dfsg+~cs8.31.173-1 Severity: serious Justification: do not compile from source Dear Maintainer, The vendor directory should be emptied The debug version is compiled without source (lintian warn) and moreover the rest of file are already packaged grep -R

Bug#978051: Need it

2021-10-06 Thread Bastien Roucariès
Hi; I need it for gulp-wrap that is needed for a chai extension signature.asc Description: This is a digitally signed message part.

Bug#917294: [libjs-mocha] Does not build like upstream

2018-12-25 Thread Bastien Roucariès
Package: libjs-mocha Version: 4.1.0+ds2-2 Severity: grave control: block 887583 by -1 The libjs-mocha is unusable as is due to be build as udd not as a classical module. Will fix ASAP signature.asc Description: This is a digitally signed message part.

Bug#917328: [src:node-mocha] Sourceless chai

2018-12-26 Thread Bastien Roucariès
Package: src:node-mocha Version: 4.1.0+ds3-1 Severity: serious chai.js is from libjs-chai and is sourceless signature.asc Description: This is a digitally signed message part.

Bug#913604: [firefox-esr] Lack of login storage API on recent firefox

2018-11-12 Thread Bastien Roucariès
Package: firefox-esr Version: 60.3.0esr-1 Severity: serious Tags: security X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org forwarded: https://bugzilla.mozilla.org/show_bug.cgi?id=1344788 control: tag -1 + upstream Firefox quantum break login storage api, means that my saved login on my

Bug#1023239: dracut: [regression] missing grep

2022-10-31 Thread Bastien Roucariès
Package: dracut Version: 056-3 Severity: critical Tags: patch upstream Justification: breaks the whole system Forwarded: https://github.com/dracutdevs/dracut/commit/79f9d9e1c29a9c8fc046ab20765e5bde2aaa3428 Dear Maintainer, grep is missing failling with lvm main partition. Could you apply patch

Bug#1017083: bibledit: Some sources are not included in your package

2022-08-13 Thread Bastien Roucariès
Source: bibledit Version: 5.0.983-1 Severity: serious Tags: upstream ftbfs security Justification: DFSG #2 X-Debbugs-Cc: Debian Security Team , debian...@lists.debian.org Dear Maintainer, Your package includes some files that seem to lack sources in preferred forms of modification: # Several m

Bug#1017213: Need gcc11

2022-08-15 Thread Bastien Roucariès
control: tags -1 + confirmed Need gcc11 ... Bastien /build/cross-toolchain-base-59.1/glibc-2.34/configure: line 2671: x86_64-linux- gnu-gcc-11: command not found configure:2673: $? = 127 configure: failed program was: | /* confdefs.h */ | #define PACKAGE_NAME "GNU C Library" | #define PACKAGE_TAR

Bug#1017213: cross-toolchain-base: Patch for gcc11 support

2022-08-15 Thread Bastien Roucariès
Source: cross-toolchain-base Version: 59 Followup-For: Bug #1017213 Control: tags -1 + patch Dear Maintainer, Could you apply https://salsa.debian.org/toolchain-team/cross-toolchain- base/-/merge_requests/7 Thanks Rouca -- System Information: Debian Release: bookworm/sid APT prefers testin

Bug#1017513: isa-support: mktemp on /usr/lib and base64 encoded binary in preinst are evil

2022-08-17 Thread Bastien Roucariès
Source: isa-support Version: 7 Severity: grave Tags: patch Justification: causes non-serious data loss Dear Maintainer, mktemp could fail and base64 is preinst is not nice -- System Information: Debian Release: bookworm/sid APT prefers testing APT policy: (900, 'testing') Architecture: amd6

Bug#1020747: AM_PATH_PYTHON

2022-09-30 Thread Bastien Roucariès
control: reassign -1 automake control: affects -1 autoconf-archive Hi, The macro AM_PATH_PYTHON dos not support 3 level python version... The bug lie in automake not autoconf-archive Could be workarround by a little sed script in order remove micro version on graph tool side Bastien

Bug#899266: [node-backbone] FTBFS documentation

2018-05-21 Thread Bastien ROUCARIÈS
Package: src:backbone Severity: serious docs/*.html are build with docco not packaged for debian So FTBFS could you please rip it ? BTW you could also remove: docs/*.css docs/public A and you could also remove normalize.c If packaged docco will add it for you. BTW I could not find copyrig

Bug#900596: [chromium-browser] unicode non free license

2018-06-01 Thread Bastien ROUCARIÈS
Package: chromium-browser Severity: serious version: 67.0.3396.62-1 The following file are non free: third_party/breakpad/breakpad/src/common/convert_UTF.c third_party/swiftshader/third_party/llvm-subzero/lib/Support/ ConvertUTF.cpp Found by lintian, checked manually The following

Bug#900598: [desmume] Include non free file

2018-06-01 Thread Bastien ROUCARIÈS
Package: desmume Severity: serious The following file source files include material under a non-free license from Unicode Inc. Therefore, it is not possible to ship this in main or contrib. src/utils/ConvertUTF.c This license does not grant any permission to modify the files (thus failing DFSG

Bug#900599: [fceux] include non free file

2018-06-01 Thread Bastien ROUCARIÈS
Package: src:fceux Severity: serious version: 2.2.2+dfsg0-1 The following file source files include material under a non-free license from Unicode Inc. Therefore, it is not possible to ship this in main or contrib. src/utils/ConvertUTF.c This license does not grant any permission to modify the

Bug#900600: [firefox,firefox-esr] Non free license: unicode

2018-06-01 Thread Bastien ROUCARIÈS
Package: firefox,firefox-esr Version: 52.8 Severity: serious The following file source files include material under a non-free license from Unicode Inc. Therefore, it is not possible to ship this in main or contrib. toolkit/crashreporter/google-breakpad/src/common/convert_UTF.* This license doe

Bug#900601: [src:libantlr3c] Non free file : unicode

2018-06-01 Thread Bastien ROUCARIÈS
Package: src:libantlr3c Version: 3.2-3 Severity: serious The following file source files include material under a non-free license from Unicode Inc. Therefore, it is not possible to ship this in main or contrib. src/antlr3convertutf.* This license does not grant any permission to modify the fil

Bug#900603: [src:kino] Lena non free image

2018-06-01 Thread Bastien ROUCARIÈS
Package: src:kino Version: 1.3.4-2.4 Severity: serious Please repack and remove ffmpeg/tests/lena.pnm Best will be to remove ffmpeg The given source file is cropped from playboy centerfold. This image is a picture of Lena Söderberg, shot by photographer Dwight Hooker, cropped from the centerf

Bug#900852: [icingaweb2] FTBFS: font fontello-ifont

2018-06-05 Thread Bastien ROUCARIÈS
Package: icingaweb2 Severity: serious I could not found the source for public/font/* I plan to upload this fonts soon, but you must repack Bastien signature.asc Description: This is a digitally signed message part.

Bug#900854: [bulk-media-downloader] FTBFS: missing source

2018-06-05 Thread Bastien ROUCARIÈS
Package: bulk-media-downloader Severity: serious Hi, The file data/window/fontello.woff from fontello upstream does not build from source. I plan to upload this fonts ASAP Bastien signature.asc Description: This is a digitally signed message part.

Bug#900853: [request-tracker4] FTBFS: missing fonts in ckeditor

2018-06-05 Thread Bastien ROUCARIÈS
Package: request-tracker4 Severity: serious Hi, third-party-source/devel/third-party/ckeditor-4.5.3/samples/toolbarconfigurator/font/fontello* Does not build from source Time to use ckeditor package ? Will upload this font ASAP Thanks Bastien signature.asc Description: This is a digital

Bug#900855: [qtquickcontrols2-opensource-src] FTBFS font fontenello

2018-06-05 Thread Bastien ROUCARIÈS
Package: qtquickcontrols2-opensource-src Severity: serious Hi, examples/quickcontrols2/swipetoremove/fonts/fontello.ttf fail to build from source In your case I suppose they are no need to wait that I upload the package. A repack will be quicker Bastien signature.asc Description: This is

Bug#895315: xul-ext-greasemonkey: Could not use script with recent firefox need to upgrade to 4.x

2018-04-09 Thread Bastien Roucariès
Package: xul-ext-greasemonkey Version: 3.8-1 Severity: grave Justification: renders package unusable Hi, The current greasemonkey is incompatible with newer firefox. Could you please upgrade -- System Information: Debian Release: buster/sid APT prefers testing APT policy: (900, 'testing')

Bug#892695: [node-acorn] Create failure in other package

2018-03-11 Thread Bastien ROUCARIÈS
Package: node-acorn Version: 5.5.3+ds1-1 Severity: serious According to debci it create failure on at least: node-astw node-browser-unpack node-falafel node-lexical-scope signature.asc Description: This is a digitally signed message part.

Bug#872580: [node-evp-bytestokey] FTBFS with node v6

2017-08-18 Thread Bastien ROUCARIÈS
Package: node-evp-bytestokey Version: 1.0.0-3 Severity: serious forwarded: https://github.com/crypto-browserify/EVP_BytesToKey/issues/8 nodejs test.js TAP version 13 # password: password ok 1 should be equal # password: ふっかつ あきる すぶり はやい つける まゆげ たんさん みんぞく ねほりはほり せまい たいまつばな ひはん not ok 2 should be e

Bug#873029: [unicode-data] Copyriht/Lack of get-orig-source where is the source

2017-08-23 Thread Bastien ROUCARIÈS
Package: unicode-data Version: 10.0.0-1 Severity: serious Without copyright information with exact location of souce, it is hard to get source It is at least a violation of 12.5. Copyright information I could help with this package if needed signature.asc Description: This is a digitally s

Bug#889045: [node-source-map] Need not available nodejs > 8

2018-02-01 Thread Bastien ROUCARIÈS
Package: node-source-map Version: 0.7.0+dfsg-1 Severity: serious Need nodejs > 8 that is not available under debian Give me on reverse dep: ReferenceError: WebAssembly is not defined at readWasm.then.buffer (/usr/lib/nodejs/source-map/lib/wasm.js:26:14) { name: 'TAP', type: 'ReferenceError',

Bug#889048: [node-source-map] FTBFS: lib/mappings.wasm

2018-02-01 Thread Bastien ROUCARIÈS
Package: node-source-map Version: 0.7.0+dfsg-1 Severity: serious Please give me pointer how to compile this file Bastien signature.asc Description: This is a digitally signed message part.

Bug#898779: src:cargo-doc: [RC] embedded code copy of node-normalize.css

2018-05-15 Thread Bastien Roucariès
Package: src:cargo-doc Version: 0.25.0-2 Severity: serious Justification: Policy 4.13 The files: cargo-doc: /usr/share/doc/cargo-doc/doc/normalize.css cargo-doc: /usr/share/doc/cargo-doc/doc/stylesheets/normalize.css Are embedded copy of node-normalize.css. Please use the package (maybe using su

Bug#898780: coffeescript-doc: [RC] embedded code copy of node-normalize.css

2018-05-15 Thread Bastien ROUCARIÈS
Package: src:coffeescript-doc Version: 1.12.7~dfsg-3 Severity: serious Justification: Policy 4.13 The files: coffeescript-doc: /usr/share/doc/coffeescript/html/annotated-source/public/ stylesheets/normalize.css Are embedded copy of node-normalize.css. Please use the package (maybe using suggest)

Bug#898782: glances: [RC] embedded copy of normalize.css

2018-05-15 Thread Bastien ROUCARIÈS
Package: src:glances Version: 2.11.1-3 Severity: serious Justification: Policy 4.13 The files: glances: /usr/lib/python3/dist-packages/glances/outputs/static/css/normalize.css Please use the package (maybe using suggest) instead to use local copy Thanks Bastien signature.asc Description: Thi

Bug#898785: granafa: [RC] embedded copy of normalize.css

2018-05-15 Thread Bastien ROUCARIÈS
Package: src:granafa Version: 2.6.0+dfsg-3 Severity: serious Justification: Policy 4.13 This package include embedded copy of normalize.css The files: grafana-data: /usr/share/grafana/missing-sources/normalize.css grafana-data: /usr/share/grafana/missing-sources/normalize.css.url (possibly includ

Bug#898786: icingaweb2: [RC] embedded copy of normalize.css

2018-05-15 Thread Bastien ROUCARIÈS
Package: src:icingaweb2 Version: 2.5.3-1 Severity: serious Justification: Policy 4.13 This package include embedded copy of normalize.css icingaweb2: /usr/share/icingaweb2/public/css/vendor/normalize.css Please use the package (maybe using suggest) instead to use local copy Thanks Bastien sig

Bug#898787: ldap-account-manager: [RC] embedded copy of normalize.css

2018-05-15 Thread Bastien ROUCARIÈS
Package: src:ldap-account-manager Version: 6.3-1 Severity: serious Justification: Policy 4.13 This package include embedded copy of normalize.css /usr/share/ldap-account-manager/style/responsive/105_normalize.css Please use the package instead to use local copy Thanks Bastien signature.asc De

Bug#898788: libreoffice-help-common: [RC] embedded copy of normalize.css

2018-05-15 Thread Bastien ROUCARIÈS
Package: libreoffice-help-common Version: 1:6.1.0~beta1~git20180507-1 Severity: serious Justification: Policy 4.13 This package include embedded copy of normalize.css /usr/share/libreoffice/help/normalize.css Please use the package instead to use local copy Thanks Bastien signature.asc Descri

Bug#898789: recon-ng: [RC] embedded copy of normalize.css

2018-05-15 Thread Bastien ROUCARIÈS
Package: recon-ng Version: 4.9.3-1 Severity: serious Justification: Policy 4.13 This package include embedded copy of normalize.css /usr/share/recon-ng/recon/core/web/static/normalize.css Please use the package libjs-normalize.css instead to use local copy Thanks Bastien signature.asc Descri

Bug#898790: r-cran-shiny: [RC] embedded copy of normalize.css

2018-05-15 Thread Bastien ROUCARIÈS
Package: r-cran-shiny Version: 1.0.5+dfsg-4 Severity: serious Justification: Policy 4.13 This package include embedded copy of normalize.css /usr/share/libreoffice/help/normalize.css Please use the package libjs-normalize.css instead to use local copy Thanks Bastien signature.asc Description:

  1   2   3   >