Re: golang-github-dgrijalva-jwt-go / CVE-2020-26160

2020-12-01 Thread Salvatore Bonaccorso
Hi Brian, On Wed, Dec 02, 2020 at 09:01:21AM +1100, Brian May wrote: > Salvatore Bonaccorso writes: > > > Hi Brian, > > > > On Tue, Dec 01, 2020 at 09:01:37AM +1100, Brian May wrote: > >> I note this package - golang-github-dgrijalva-jwt-go - has been marked > >> as vulnerable to CVE-2020-26160

Re: golang-github-dgrijalva-jwt-go / CVE-2020-26160

2020-12-01 Thread Brian May
Salvatore Bonaccorso writes: > Hi Brian, > > On Tue, Dec 01, 2020 at 09:01:37AM +1100, Brian May wrote: >> I note this package - golang-github-dgrijalva-jwt-go - has been marked >> as vulnerable to CVE-2020-26160 in both Debian stretch and buster. >> >> https://security-tracker.debian.org/tracke

(E)LTS report for November 2020

2020-12-01 Thread Holger Levsen
hi, in November 2020 I spent 8h managing (E)LTS contributors: - dispatching work hours for LTS and ELTS - preparing, runninng und post-processing the monthly team meeting on IRC - preparing the monthly Freexian blog post published on raphaelhertzog.com - mail and irc communication, incl. - semi

Re: Bug#976219: zsh uninstallable due to partial oldstable security update

2020-12-01 Thread Markus Koschany
Hello, zsh 5.3.1-4+deb9u4 was sucessfully uploaded to stretch-security thirteen hours ago but it still remains in status "uploaded" for all supported architectures except arch all. Who can "install" the packages into the archive or is another upload necessary? Regards, Markus signature.asc

Debian LTS and ELTS - November 2020

2020-12-01 Thread Sylvain Beucler
Here is my public monthly report. Thanks to our sponsors for making this possible, and to Freexian for handling the offering. https://www.freexian.com/services/debian-lts.html#sponsors LTS - Fix LTS RSS feed https://lists.debian.org/debian-lts/2020/11/msg1.html - sympa - DLA 2441-1