Re: [SECURITY] [DLA 4018-1] ruby2.7 security update

2025-01-27 Thread Daniel Leidert
Hi, On Mon, 2025-01-27 at 20:06 +, Bastien Roucariès wrote: > Le lundi 27 janvier 2025, 15:04:49 UTC Sylvain Beucler a écrit : > > Hi, > > > > Do we plan/want to fix these REXML vulnerabilities accordingly in > > ruby3.1 (6 postponed) and ruby3.3 (1 unfixed) ? > > I will try JFTR: The ruby

Re: [SECURITY] [DLA 4018-1] ruby2.7 security update

2025-01-27 Thread Bastien Roucariès
Le lundi 27 janvier 2025, 15:04:49 UTC Sylvain Beucler a écrit : > Hi, > > Do we plan/want to fix these REXML vulnerabilities accordingly in > ruby3.1 (6 postponed) and ruby3.3 (1 unfixed) ? I will try > > This sounds like a candidate for a (O)SPU task: > https://salsa.debian.org/lts-team/lts-u

Re: About the possibility of a Front Desk wiki

2025-01-27 Thread Sylvain Beucler
Hi, (I wasn't present during this month's meeting and Roberto asked me to check this thread as I recently (re)wrote some FD docs.) Before checking how to implement this wiki, I'd suggest we define what additional information we want to track in a wiki (I couldn't find the information in the

Tooling bug fix help - bin/package-operations

2025-01-27 Thread Roberto C . Sánchez
I'm not sure if everyone is subscribed to the issues in the lts-team/lts-extra-tasks project, so I'd like to highlight a bug I encountered earlier today in bin/package-operations: https://salsa.debian.org/lts-team/lts-extra-tasks/-/issues/75 I don't think this is a big task/bug fix, so if anyone

Re: [SECURITY] [DLA 4018-1] ruby2.7 security update

2025-01-27 Thread Sylvain Beucler
Hi, Do we plan/want to fix these REXML vulnerabilities accordingly in ruby3.1 (6 postponed) and ruby3.3 (1 unfixed) ? This sounds like a candidate for a (O)SPU task: https://salsa.debian.org/lts-team/lts-updates-tasks/-/issues Cheers! Sylvain On 18/01/2025 09:06, ro...@debian.org wrote: ---