Re: How to avoid maintainers to feel pushed?

2017-06-08 Thread Markus Koschany
Am 08.06.2017 um 23:14 schrieb Ola Lundqvist: > Hi LTS team > > Today I got a reply from the tor maintainer that he felt pushed. He > wanted me to hold back more than a few minutes before pinging him. > I'm guessing this because the security team informed him shortly before. > I do not know that f

Re: Wheezy update of samba?

2017-06-08 Thread Ola Lundqvist
Hi Ok, thank you. We will handle it then. Wheezy do not have any point releases (anymore). // Ola On 8 June 2017 at 22:02, Mathieu Parent wrote: > Hello, > > 2017-06-06 22:25 GMT+02:00 Ola Lundqvist : > > Dear maintainer(s), > > > > The Debian LTS team would like to fix the security issues whi

Re: How to avoid maintainers to feel pushed?

2017-06-08 Thread Ola Lundqvist
Hi again It turned out that the reason was that the maintainer had filed the Debian bug and informed the security team about it. - Do this mean that we should add instructions that we should formulate the email differently in case it is clear that the maintainer already know about the problem (lik

How to avoid maintainers to feel pushed?

2017-06-08 Thread Ola Lundqvist
Hi LTS team Today I got a reply from the tor maintainer that he felt pushed. He wanted me to hold back more than a few minutes before pinging him. I'm guessing this because the security team informed him shortly before. I do not know that for sure yet as I just sent that email. My question to you

Re: Wheezy update of tor?

2017-06-08 Thread Ola Lundqvist
Hi Peter Sorry if you think I'm pushy. This was not my intention. I'm guessing that the "a few minutes" referred to the fact that you had got information from the security team, right? The security team is not the same team as the long term security team. I do not see the emails from the securit

Re: Wheezy update of tor?

2017-06-08 Thread Peter Palfrader
On Thu, 08 Jun 2017, Ola Lundqvist wrote: > The Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of tor: > https://security-tracker.debian.org/tracker/CVE-2017-0376 This feels really pushy. Please give a maintainer at least some time (more th

Re: Wheezy update of samba?

2017-06-08 Thread Mathieu Parent
Hello, 2017-06-06 22:25 GMT+02:00 Ola Lundqvist : > Dear maintainer(s), > > The Debian LTS team would like to fix the security issues which are > currently open in the Wheezy version of samba: > https://security-tracker.debian.org/tracker/source-package/samba > Specifically bug #864291. > > Would

Wheezy update of irssi?

2017-06-08 Thread Ola Lundqvist
Dear maintainer, The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of irssi: https://security-tracker.debian.org/tracker/CVE-2017-9468 https://security-tracker.debian.org/tracker/CVE-2017-9469 (these two CVEs refer to the same patch) Would yo

Wheezy update of mercurial?

2017-06-08 Thread Ola Lundqvist
Dear maintainers, The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of mercurial: https://security-tracker.debian.org/tracker/CVE-2017-9462 Would you like to take care of this yourself? Thanks to Wagner Bruna there are already patch proposal

Wheezy update of tor?

2017-06-08 Thread Ola Lundqvist
Dear maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of tor: https://security-tracker.debian.org/tracker/CVE-2017-0376 Would you like to take care of this yourself? If yes, please follow the workflow we have defined here: ht

Re: Wheezy update of tomcat6 and tomcat7?

2017-06-08 Thread Emilio Pozuelo Monfort
On 07/06/17 23:27, Ola Lundqvist wrote: > Hi > > Great! Should I mark this CVE as no-dsa or something else? Not no-dsa, but end-of-life (for wheezy). Cheers, Emilio