Re: Security support for chromium in jessie

2017-11-04 Thread Michael Gilbert
On Tue, Aug 15, 2017 at 1:09 PM, Emilio Pozuelo Monfort wrote: > I think we should do this for as long as it's reasonably possible, given > firefox > updates will get harder and harder (they will require newer versions of rustc, > which may need to be bootstrapped) so having another supported brow

Security support for chromium in jessie

2017-07-30 Thread Michael Gilbert
Hi all, I do not have enough free time to be able to keep up with security updates to chromium in jessie (oldstable) any more. It is technically feasible to keep it working in a jessie environment, but each update has been more and more work. I expect that to continue. Anyway, if anyone would l

Re: Bug#808081: squeeze update of bind9?

2015-12-16 Thread Michael Gilbert
On Wed, Dec 16, 2015 at 3:22 PM, Raphael Hertzog wrote: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of bind9: > https://security-tracker.debian.org/tracker/CVE-2015-8000 As mentioned before, please go a

Re: squeeze update of bind9?

2015-09-03 Thread Michael Gilbert
On Thu, Sep 3, 2015 at 3:21 PM, Santiago Ruano Rincón wrote: > If you don't want to take care of this update, it's not a problem, we > will do our best with your package. Just let us know whether you would > like to review and/or test the updated package before it gets released. Please go ahead wi

Re: squeeze update of bind9?

2015-07-11 Thread Michael Gilbert
On Sat, Jul 11, 2015 at 7:22 AM, Santiago Ruano Rincón wrote: > Hello dear maintainer(s), > > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of bind9: > https://security-tracker.debian.org/tracker/CVE-2015-4620 >From my perspective, plea

Re: squeeze-lts and the security tracker

2014-08-08 Thread Michael Gilbert
On Fri, Aug 8, 2014 at 11:16 AM, Holger Levsen wrote: > But then, this target (copied from update-backports(-*) is never called, just > like update-backports. doc/security-team.d.o/security_tracker only mentions > the update-stable target... > > So there must be something missing here. You'll want

Re: squeeze-lts and the security tracker

2014-08-06 Thread Michael Gilbert
>> where's the repo for that code? > > svn://anonscm.debian.org/svn/secure-testing > (as listed on the bottom of the security-tracker pages) In particular the Makefile, which fetches and parses the package archive data. Best wishes, Mike -- To UNSUBSCRIBE, email to debian-lts-requ...@lists.deb

Re: LTS-ID : LTS6A-2014-015

2014-07-13 Thread Michael Gilbert
On Sun, Jul 13, 2014 at 6:07 PM, Holger Levsen wrote: > Hi, > > On Sonntag, 13. Juli 2014, Thorsten Alteholz wrote: >> Hmm, according to your announce this upload fixes CVE-2014-4699 which has >> DSA-2972-1. >> Or DSA-2949-1 for CVE-2014-3145. > > so let's roll a dice? IMO there is no problem / muc

Re: LTS-ID : LTS6A-2014-015

2014-07-12 Thread Michael Gilbert
On Sat, Jul 12, 2014 at 3:27 PM, Holger Levsen wrote: > Hi, > > I've refrained from adding "LTS6A-2014-015" to the subject of the linux-2.6 > announcement, as well as from including it in the body. But I think we should > have some ID there, and I propose to use "Long Term Support for Debian 6 > A

Re: Draft announce of Debian 6 LTS, please review quickly

2014-06-14 Thread Michael Gilbert
On Sat, Jun 14, 2014 at 9:05 PM, Michael Gilbert wrote: > Why not put up a wiki page that can get continuously updated, and > actually show which companies have in fact contributed? Better yet, why not state "This LTS update brought to you by company X, company Y, and company

Re: Draft announce of Debian 6 LTS, please review quickly

2014-06-14 Thread Michael Gilbert
On Sat, Jun 14, 2014 at 3:01 AM, Raphael Hertzog wrote: > On Sat, 14 Jun 2014, Matt Palmer wrote: >> Why list the companies, but not the volunteers? > > Because: > - it would become unmanageable and hard to read > - listing companies is a way to make them accountable of their promise > (i.e. "tha

Re: Missing openssl build for i386

2014-06-06 Thread Michael Gilbert
On Thu, Jun 5, 2014 at 8:46 PM, Carlos Alberto Lopez Perez wrote: > For the future... is there any site where one can manually download the > packages waiting on the queue? I know about incoming.debian.org, but > this openssl:i386=0.9.8o-4squeeze15 don't seems to be there You can download and buil