Bug#973531: ITP: sakia -- client for the duniter crypto-currency project

2020-11-01 Thread Jonas Smedegaard
Package: wnpp Severity: wishlist Owner: Jonas Smedegaard X-Debbugs-Cc: debian-devel@lists.debian.org -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: sakia Version : 0.53.1 Upstream Author : inso * URL : https://git.duniter.org/clients/python/sakia * L

Re: Reminder: MiniDebConfOnline, Games Edition

2020-11-01 Thread Hoai-Nam.NGUYEN
Unsubscribe please On Mon., Oct. 19, 2020, 4:28 p.m. Nattie Mayer-Hutchings wrote: > Would you like to speak at the upcoming MiniDebconfOnline, Games Edition? > Here's your chance! The conference takes place on the 21st and 22nd of > November, and we will be accepting submissions for talks unt

CITL Releasing 7000 defects/vulnerabilities

2020-11-01 Thread Ole Streicher
Hi all, I just stumbled upon the following web page: https://cyber-itl.org/2020/10/28/citl-7000-defects.html They claim to have found ~7000 defects in Ubuntu packages (a number of those are maintained by me). Does anyone have more information about this? Or did I miss a discussion here about th

Re: CITL Releasing 7000 defects/vulnerabilities

2020-11-01 Thread Alexis Murzeau
Hi, Le 01/11/2020 à 14:14, Ole Streicher a écrit : > Hi all, > > I just stumbled upon the following web page: > > https://cyber-itl.org/2020/10/28/citl-7000-defects.html > > They claim to have found ~7000 defects in Ubuntu packages (a number of > those are maintained by me). > > Does anyone ha

Re: CITL Releasing 7000 defects/vulnerabilities

2020-11-01 Thread Utkarsh Gupta
[CCing team@security.d.o] On Sun, Nov 1, 2020 at 7:09 PM Ole Streicher wrote: > I just stumbled upon the following web page: > https://cyber-itl.org/2020/10/28/citl-7000-defects.html > They claim to have found ~7000 defects in Ubuntu packages (a number of > those are maintained by me). On a *ver

Re: CITL Releasing 7000 defects/vulnerabilities

2020-11-01 Thread Xavier
Hi, Ubuntu is based on testing and does not import our fixes after its release (except a few list), then it's normal to find a lot of vulnerabilities. See https://lemonldap-ng.org/documentation for exemple Le 1 novembre 2020 14:59:32 GMT+01:00, Utkarsh Gupta a écrit : >[CCing team@security.d

Re: CITL Releasing 7000 defects/vulnerabilities

2020-11-01 Thread Matthias Klumpp
Am So., 1. Nov. 2020 um 15:22 Uhr schrieb Xavier : > > Hi, > > Ubuntu is based on testing and does not import our fixes after its release > (except a few list), then it's normal to find a lot of vulnerabilities. See > https://lemonldap-ng.org/documentation for exemple > > > Le 1 novembre 2020 14:

Re: CITL Releasing 7000 defects/vulnerabilities

2020-11-01 Thread Daniel Leidert
Am Sonntag, den 01.11.2020, 14:14 +0100 schrieb Ole Streicher: > I just stumbled upon the following web page: > > https://cyber-itl.org/2020/10/28/citl-7000-defects.html The list misses the package version. IMHO this is rather vital information. They also used Ubuntu 18.04 which is more then two

Bug#973535: ITP: php-league-mime-type-detection -- generic mime-type detection interface for PHP

2020-11-01 Thread Robin Gustafsson
Package: wnpp Severity: wishlist Owner: Robin Gustafsson Control: block 951666 by -1 * Package name: php-league-mime-type-detection Version : 1.5.1 Upstream Author : Frank de Jonge * URL : https://github.com/thephpleague/mime-type-detection * License : MIT/Exp

Re: CITL Releasing 7000 defects/vulnerabilities

2020-11-01 Thread Colin Watson
On Sun, Nov 01, 2020 at 03:13:24PM +0100, Xavier wrote: > Ubuntu is based on testing and does not import our fixes after its > release (except a few list), then it's normal to find a lot of > vulnerabilities. It's not really relevant to this CITL list; but just on a point of information, Ubuntu im

Re: CITL Releasing 7000 defects/vulnerabilities

2020-11-01 Thread Xavier
Le 01/11/2020 à 21:34, Colin Watson a écrit : > On Sun, Nov 01, 2020 at 03:13:24PM +0100, Xavier wrote: >> Ubuntu is based on testing and does not import our fixes after its >> release (except a few list), then it's normal to find a lot of >> vulnerabilities. > > It's not really relevant to this C

Bug#973568: ITP: libpj-java -- API and middleware for parallel programming in Java

2020-11-01 Thread Pierre Gruet
Package: wnpp Severity: wishlist Owner: Debian-med project X-Debbugs-Cc: debian-devel@lists.debian.org, debian-...@lists.debian.org * Package name: libpj-java Version : 20150107 Upstream Author : Alan Kaminsky * URL : https://www.cs.rit.edu/~ark/pj.shtml * License

Re: CITL Releasing 7000 defects/vulnerabilities

2020-11-01 Thread Russ Allbery
Utkarsh Gupta writes: > That said, it'd be a bit weird if they don't report these issues and ask > for a CVE assignment against these. Anyway, the security team might > know more about this. It appears to be the output of automated fuzz testing, which based on past experience means that a large

Re: CITL Releasing 7000 defects/vulnerabilities

2020-11-01 Thread Calum McConnell
On Sun, 2020-11-01 at 14:56 -0800, Russ Allbery wrote: > Utkarsh Gupta writes: > > > That said, it'd be a bit weird if they don't report these issues and ask > > for a CVE assignment against these. Anyway, the security team might > > know more about this. > > It appears to be the output of auto

Re: Hosting the original youtube-dl sources on salsa?

2020-11-01 Thread Wouter Verhelst
On Fri, Oct 30, 2020 at 09:16:21AM +0100, Philip Hands wrote: > Rogério Brito writes: > > > Dear people, > > > > As many of you may know, the RIAA issued a resquest for GitHub to take down > > the youtube-dl repository. > > IANAL so I may be confused, but AIUI that takedown is based on the > not