Re: Revisiting some old DLAs

2024-12-31 Thread Roberto C. Sánchez
On Thu, Dec 12, 2024 at 03:51:06AM +0200, Adrian Bunk wrote: > On Wed, Dec 11, 2024 at 07:19:50PM -0500, Roberto C. Sánchez wrote: > >... > > We can look at our various tasks as follows: > > > > - creation of a DLA (requires preparing the update, uploading the > > package, and making the announc

Re: Revisiting some old DLAs

2024-12-31 Thread Roberto C . Sánchez
On Thu, Dec 12, 2024 at 03:51:06AM +0200, Adrian Bunk wrote: > On Wed, Dec 11, 2024 at 07:19:50PM -0500, Roberto C. Sánchez wrote: > >... > > We can look at our various tasks as follows: > > > > - creation of a DLA (requires preparing the update, uploading the > > package, and making the announc

Re: Revisiting some old DLAs

2024-12-12 Thread Sean Whitton
Hello, On Thu 12 Dec 2024 at 03:51am +02, Adrian Bunk wrote: > On Wed, Dec 11, 2024 at 07:19:50PM -0500, Roberto C. Sánchez wrote: >>... >> We can look at our various tasks as follows: >> >> - creation of a DLA (requires preparing the update, uploading the >> package, and making the announcemen

Re: Revisiting some old DLAs

2024-12-11 Thread Adrian Bunk
On Wed, Dec 11, 2024 at 07:19:50PM -0500, Roberto C. Sánchez wrote: >... > We can look at our various tasks as follows: > > - creation of a DLA (requires preparing the update, uploading the > package, and making the announcement) >... > - additional work in support of stable (-sec or -pu) >...

Re: Revisiting some old DLAs

2024-12-11 Thread Roberto C . Sánchez
On Thu, Dec 12, 2024 at 12:59:46AM +0200, Adrian Bunk wrote: > On Wed, Dec 11, 2024 at 02:35:00PM -0500, Roberto C. Sánchez wrote: > > > > > Only they aren't necessarily incomplete DLAs. > >... > > I thought submitting DLA fixes also to (old)stable was part of our job. > Yes, it is part of our j

Re: Revisiting some old DLAs

2024-12-11 Thread Adrian Bunk
On Wed, Dec 11, 2024 at 02:35:00PM -0500, Roberto C. Sánchez wrote: > On Tue, Dec 10, 2024 at 01:45:49AM +0200, Adrian Bunk wrote: > > On Mon, Dec 09, 2024 at 07:22:30PM -0300, Santiago Ruano Rincón wrote: > > > > > > To be discussed. The issue with dla-needed (in its current form) and > > > bookw

Re: Revisiting some old DLAs

2024-12-11 Thread Roberto C . Sánchez
On Tue, Dec 10, 2024 at 01:45:49AM +0200, Adrian Bunk wrote: > On Mon, Dec 09, 2024 at 07:22:30PM -0300, Santiago Ruano Rincón wrote: > > > > To be discussed. The issue with dla-needed (in its current form) and > > bookworm point updates is that dla-needed is aimed at the LTS release. > > Current

Re: Revisiting some old DLAs

2024-12-09 Thread Adrian Bunk
On Mon, Dec 09, 2024 at 07:22:30PM -0300, Santiago Ruano Rincón wrote: >... > El 08/12/24 a las 07:30, Adrian Bunk escribió: > > On Fri, Dec 06, 2024 at 10:10:19PM -0500, Roberto C. Sánchez wrote: >... > > > I have done my best to carefully document for each package the CVE(s) > > > which are invol

Re: Revisiting some old DLAs

2024-12-09 Thread Santiago Ruano Rincón
Hi, El 08/12/24 a las 07:30, Adrian Bunk escribió: > On Fri, Dec 06, 2024 at 10:10:19PM -0500, Roberto C. Sánchez wrote: > > Hello everyone, > > Hi Roberto, > > > The Security Team has supplied a list of packages/CVEs which were fixed > > by DLA (some in bullseye and some in buster) but which re

Re: Revisiting some old DLAs

2024-12-09 Thread Sylvain Beucler
Hi, On 07/12/2024 04:10, Roberto C. Sánchez wrote: The Security Team has supplied a list of packages/CVEs which were fixed by DLA (some in bullseye and some in buster) but which remain unfixed in bookworm (and which are tagged no-dsa, indicating that the Security Team has no immediate plans to a

Re: Revisiting some old DLAs

2024-12-07 Thread Adrian Bunk
On Fri, Dec 06, 2024 at 10:10:19PM -0500, Roberto C. Sánchez wrote: > Hello everyone, Hi Roberto, > The Security Team has supplied a list of packages/CVEs which were fixed > by DLA (some in bullseye and some in buster) but which remain unfixed in > bookworm (and which are tagged no-dsa, indicatin

Re: Revisiting some old DLAs

2024-12-07 Thread Holger Levsen
On Fri, Dec 06, 2024 at 10:10:19PM -0500, Roberto C. Sánchez wrote: > The Security Team has supplied a list of packages/CVEs which were fixed > by DLA (some in bullseye and some in buster) but which remain unfixed in > bookworm (and which are tagged no-dsa, indicating that the Security Team > has n

Revisiting some old DLAs

2024-12-06 Thread Roberto C . Sánchez
Hello everyone, The Security Team has supplied a list of packages/CVEs which were fixed by DLA (some in bullseye and some in buster) but which remain unfixed in bookworm (and which are tagged no-dsa, indicating that the Security Team has no immediate plans to address them). Based on this informat