Re: [RFC] Proposal: Migrate LTS/TODO wiki page to GitLab issues

2020-05-25 Thread Roberto C . Sánchez
On Tue, May 26, 2020 at 07:10:57AM +1000, Brian May wrote: > Roberto C. Sánchez writes: > > > Rationale: The nature of a wiki makes it suboptimal for managing > > discrete work units. As developers, we are all familiar with > > interacting with the Debian BTS and other similar systems (e.g., Jir

Re: [RFC] Proposal: Migrate LTS/TODO wiki page to GitLab issues

2020-05-25 Thread Brian May
Roberto C. Sánchez writes: > Rationale: The nature of a wiki makes it suboptimal for managing > discrete work units. As developers, we are all familiar with > interacting with the Debian BTS and other similar systems (e.g., Jira, > GitHub issues, etc.). While the Debian BTS would be a natural f

[RFC] Proposal: Migrate LTS/TODO wiki page to GitLab issues

2020-05-25 Thread Roberto C . Sánchez
Hello fello LTS folks, I have been discussing with Raphael some things which we can do to improve the state of the LTS/TODO page in the Debian wiki. This arose from part of the discussion during the April LTS Contributors IRC meeting. After some back-and-forth discussion I would like to make the

Re: Taking care of Keystone in Stretch and Jessie

2020-05-25 Thread Moritz Mühlenhoff
On Fri, May 15, 2020 at 03:49:10PM +0200, Thomas Goirand wrote: > On 5/15/20 3:12 PM, Sylvain Beucler wrote: > > Hi Thomas, > > > > On 14/05/2020 19:08, Thomas Goirand wrote: > >> I released an update of Keystone for a quite serious problem related to > >> ec2 credentials where a user can become a

RFT: salt 2014.1.13+ds-3+deb8u1

2020-05-25 Thread Abhijith PA
Hello. I've backported CVE-2020-11651, CVE-2020-11652 mostly from https://github.com/rossengeorgiev/salt-security-backports/ and uploaded to people.debian.org https://people.debian.org/~abhijith/upload/salt_2014.1.13+ds-3+deb8u1.dsc Please review the patch and let me know if you find any regress

Re: Refreshing mysql-connector-java

2020-05-25 Thread Moritz Mühlenhoff
On Mon, May 25, 2020 at 10:22:50AM +0200, Sylvain Beucler wrote: > Hi Security Team, > > What is your view on updating mysql-connector-java 5.1.42->5.1.49 for > Stretch? We can update to 5.1.49, yes. We've had to update it to new 5.1.x releases in the past and I don't remember any issues. The fac

Re: [Pkg-phototools-devel] Jessie update of libexif?

2020-05-25 Thread Mike Gabriel
Hi Hugh, On Mo 25 Mai 2020 14:15:43 CEST, Hugh McMaster wrote: Hi Mike, On Mon, 25 May 2020 at 14:21, Hugh McMaster wrote: On Mon, 25 May 2020 at 00:55, Adam D. Barratt wrote: Personally, it probably makes more sense for the new stretch version to be +deb9u3, built on top of the already u

Re: [Pkg-phototools-devel] Jessie update of libexif?

2020-05-25 Thread Hugh McMaster
Hi Mike, On Mon, 25 May 2020 at 14:21, Hugh McMaster wrote: > > On Mon, 25 May 2020 at 00:55, Adam D. Barratt wrote: >> >> Personally, it probably makes more sense for the new stretch version to >> be +deb9u3, built on top of the already uploaded package (and similar >> for buster) with a second r

Re: TODO List

2020-05-25 Thread Raphael Hertzog
Hi, On Wed, 20 May 2020, Holger Levsen wrote: > > Is the "Find upstream developers who are willing to work on LTS support" > > still relevant? It lists packages such as Xen, which I thought were > > already dealt with. > > yes and yes, xen is being taken care of atm. I've updated the TODO page.

Re: Refreshing mysql-connector-java

2020-05-25 Thread Sylvain Beucler
Hi Security Team, What is your view on updating mysql-connector-java 5.1.42->5.1.49 for Stretch? Would you need a complete debdiff specifically for Stretch to make a decision, or do you already have feedback on this proposal? Cheers! Sylvain On 11/05/2020 13:51, Sylvain Beucler wrote: > On 08/0

Re: security upload imposing load on other parts of Debian

2020-05-25 Thread Sylvain Beucler
Hi Salvatore, On 24/05/2020 16:48, Salvatore Bonaccorso wrote: > On Wed, May 20, 2020 at 12:34:13PM +, Holger Levsen wrote: > Yes sure (fixing my obvious english grammar issues and typos). We have > a very "high level" view on this in [1], but it might make sense to > add some verb

(semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2020-05-25 Thread Holger Levsen
hi, today I unclaimed for LTS: - apache2 (Utkarsh Gupta) - mumble (Abhijith PA) and none for ELTS. Four DLA have been reserved but not yet been published on www.debian.org: - DLA 2220-1 (reserved by Thorsten Alteholz) - DLA 2219-1 (reserved by Thorsten Alteholz) - DLA 2218-1 (reserved by Thor