Re: lowering severity of bugs not tracked by release team

2014-12-21 Thread Michael Gilbert
On Sun, Dec 21, 2014 at 9:11 AM, Bálint Réczey wrote: >> The problem still remains that the backlog of libv8 security issues >> never get fixed (except for a new upstream every now and then), so >> treating this one as RC but not the others is rather inconsistent: >> https://security-tracker.debian

Re: lowering severity of bugs not tracked by release team

2014-12-21 Thread Bálint Réczey
Hi Mike, First, I had to cancel the upload because of too strict reverse dependencies. Dear fellow JavaScript maintainers please figure out a less strict dependency graph because every otherwise fully compatible libv8 update would break several packages. 2014-12-21 2:13 GMT+01:00 Michael Gilbert

Re: lowering severity of bugs not tracked by release team

2014-12-20 Thread Michael Gilbert
On Sat, Dec 20, 2014 at 7:52 PM, Bálint Réczey wrote: > The proper severity of this bug is grave as set by Moritz IMO. I'm > restoring it wearing my maintainer hat. It's not really constructive arguing over severity, so that's fine. You've saved yourself from needing to write an unblock request.

Re: lowering severity of bugs not tracked by release team

2014-12-20 Thread Bálint Réczey
Control: severity -1 grave Hi Mike, 2014-12-20 20:57 GMT+01:00 Michael Gilbert : > On Sat, Dec 20, 2014 at 6:15 AM, Adam D. Barratt wrote: >> On Sat, 2014-12-20 at 11:48 +0100, Jonas Smedegaard wrote: >>> [sent again, cc correct list address this time] >>> >>> Quoting Michael Gilbert (2014-12-20

Re: lowering severity of bugs not tracked by release team

2014-12-20 Thread Michael Gilbert
On Sat, Dec 20, 2014 at 6:15 AM, Adam D. Barratt wrote: > On Sat, 2014-12-20 at 11:48 +0100, Jonas Smedegaard wrote: >> [sent again, cc correct list address this time] >> >> Quoting Michael Gilbert (2014-12-20 11:06:47) >> > On Sat, Dec 20, 2014 at 4:59 AM, Balint Reczey wrote: >> >> On Fri, 19 Dec

Re: lowering severity of bugs not tracked by release team

2014-12-20 Thread Adam D. Barratt
On Sat, 2014-12-20 at 11:48 +0100, Jonas Smedegaard wrote: > [sent again, cc correct list address this time] > > Quoting Michael Gilbert (2014-12-20 11:06:47) > > On Sat, Dec 20, 2014 at 4:59 AM, Balint Reczey wrote: > >> On Fri, 19 Dec 2014 21:11:10 -0500 Michael Gilbert wrote: > >>> control: sev

Re: lowering severity of bugs not tracked by release team

2014-12-20 Thread Jonas Smedegaard
[sent again, cc correct list address this time] Quoting Michael Gilbert (2014-12-20 11:06:47) > On Sat, Dec 20, 2014 at 4:59 AM, Balint Reczey wrote: >> On Fri, 19 Dec 2014 21:11:10 -0500 Michael Gilbert wrote: >>> control: severity -1 important >>> >>> There is no security support for libv8 in je