Re: golang-go.crypto / CVE-2019-11841

2020-10-11 Thread Brian May
Emilio Pozuelo Monfort writes: > I would look for an automated way to do this. E.g. by downloading and > inspecting > the binaries to see if they have the affected code. Hmmm. Good idea in theory, but not sure how to do this in practise. I tried building two copies of acmetool, and comparing,

Re: golang-go.crypto / CVE-2019-11841

2020-10-11 Thread Adrian Bunk
On Fri, Oct 09, 2020 at 12:17:26PM +0200, Emilio Pozuelo Monfort wrote: > On 09/10/2020 00:23, Brian May wrote: > > We probably need someway of keeping track of what packages have already > > been looked at and their status with respect to this rebuild. Not really > > convinced data/dla-needed.txt