LTS report for November 2020 - Abhijith PA

2020-12-06 Thread Abhijith PA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 November was my 33rd month as a Debian LTS paid contributor. I had a total of 12 hours. I've spent all of them for the following, * 1 week of LTS front desk * lxml: Fixed CVE-2018-19787 CVE-2020-27783, tested and uploaded[1] * spice-vdagent:

Re: golang-1.7 / CVE-2019-9514 / CVE-2019-9512

2020-12-06 Thread Utkarsh Gupta
Hi Brian, On Mon, Dec 7, 2020 at 3:34 AM Brian May wrote: > What is Debian LTS policy concerning Debian salsa git repos? Should I > push these changes to the git repo in new a debian/stretch branch? Ask > the maintainer for permission? Or what? I don't want to accidentally > tread on any toes her

Re: golang-1.7 / CVE-2019-9514 / CVE-2019-9512

2020-12-06 Thread Brian May
I have a patch to fix this. As attached. I had to apply this patch manually be hand, but I didn't notice any issues. I also noticed that tests failed when I built this in a Docker container without IPv6 support. So I added a tiny change to disable this IPv6 test if IPv6 is not supported on host (