Re: [Reportbug-maint] Bug#878088: reportbug: please inform security and lts teams about security update regressions

2017-12-29 Thread Markus Koschany
Hello Sandro, Am 29.12.2017 um 02:27 schrieb Sandro Tosi: > Hello everyone, > let me first apologize for the long time with no input from the > reportbug maints. Yes, we were eagerly interested in your comments for this feature but had to move forward. > i had a look a the patch and.. i'm not re

Re: Bug#878088: reportbug: please inform security and lts teams about security update regressions

2017-12-29 Thread Salvatore Bonaccorso
Hi Sandro, On Thu, Dec 28, 2017 at 08:30:34PM -0500, Sandro Tosi wrote: > >> +if is_security_update and support != 'none': > >> +if support == 'lts': > >> +email_address = ['debian-lts@lists.debian.org'] > >> +else: > >> +email_addres

Re: Bug#878088: reportbug: please inform security and lts teams about security update regressions

2017-12-28 Thread Sandro Tosi
>> +if is_security_update and support != 'none': >> +if support == 'lts': >> +email_address = ['debian-lts@lists.debian.org'] >> +else: >> +email_address = ['t...@security.debian.org'] >> +listcc.extend(email_address) >> +

Re: [Reportbug-maint] Bug#878088: reportbug: please inform security and lts teams about security update regressions

2017-12-28 Thread Sandro Tosi
Hello everyone, let me first apologize for the long time with no input from the reportbug maints. i had a look a the patch and.. i'm not really happy :( it looks like the version format is the same for both security updates and stable updates: this means for every bug report (on a stable release a

Re: reportbug: please inform security and lts teams about security update regressions

2017-12-22 Thread Markus Koschany
Am 21.12.2017 um 22:42 schrieb Salvatore Bonaccorso: [...] > Don't worry anymore. It was as well not about all the timeline, I'm > aware when you did the initial ping, but rather on the "we think it > needs a change on security tracker and want this information exposed > ... I want to do the wheezy

Re: reportbug: please inform security and lts teams about security update regressions

2017-12-21 Thread Salvatore Bonaccorso
Hi Markus, On Wed, Dec 13, 2017 at 01:34:05PM +0100, Markus Koschany wrote: > Hi Salvatore, > > Am 12.12.2017 um 07:19 schrieb Salvatore Bonaccorso: > [...] > > I have made the above change now live/commited. The file is still thus > > extensible and for futher (and future use). Thanks for your w

Re: reportbug: please inform security and lts teams about security update regressions

2017-12-13 Thread Markus Koschany
Hi Salvatore, Am 12.12.2017 um 07:19 schrieb Salvatore Bonaccorso: [...] > I have made the above change now live/commited. The file is still thus > extensible and for futher (and future use). Thanks for your work on > that! (as a personal note on my side, would have prefered to get less > pressure

Re: reportbug: please inform security and lts teams about security update regressions

2017-12-11 Thread Salvatore Bonaccorso
Hi Markus, On Sun, Dec 10, 2017 at 03:58:30PM +0100, Markus Koschany wrote: > Am 10.12.2017 um 13:35 schrieb Salvatore Bonaccorso: > [...] > >>> and beeing accessible under > >>> https://security-tracker.debian.org/tracker/distributions.json > >> > >> That makes as lot of sense! (I used YAML in t

Re: reportbug: please inform security and lts teams about security update regressions

2017-12-10 Thread Guido Günther
Hi, On Sun, Dec 10, 2017 at 01:35:43PM +0100, Salvatore Bonaccorso wrote: > Hi Guido, > > On Sun, Dec 10, 2017 at 12:59:05PM +0100, Guido Günther wrote: > > Hi, > > On Sun, Dec 10, 2017 at 12:51:38PM +0100, Salvatore Bonaccorso wrote: > > > Hi > > > > > > On Sun, Dec 10, 2017 at 10:00:55AM +0100,

Re: reportbug: please inform security and lts teams about security update regressions

2017-12-10 Thread Markus Koschany
Am 10.12.2017 um 13:35 schrieb Salvatore Bonaccorso: [...] >>> and beeing accessible under >>> https://security-tracker.debian.org/tracker/distributions.json >> >> That makes as lot of sense! (I used YAML in the example for readability, >> output of the tracker should be JSON). The main reason why

Re: reportbug: please inform security and lts teams about security update regressions

2017-12-10 Thread Salvatore Bonaccorso
Hi Guido, On Sun, Dec 10, 2017 at 12:59:05PM +0100, Guido Günther wrote: > Hi, > On Sun, Dec 10, 2017 at 12:51:38PM +0100, Salvatore Bonaccorso wrote: > > Hi > > > > On Sun, Dec 10, 2017 at 10:00:55AM +0100, Salvatore Bonaccorso wrote: > > > Hi > > > > > > Cc'ing explicitly Guido and Raphael, wh

Re: reportbug: please inform security and lts teams about security update regressions

2017-12-10 Thread Guido Günther
Hi, On Sun, Dec 10, 2017 at 12:51:38PM +0100, Salvatore Bonaccorso wrote: > Hi > > On Sun, Dec 10, 2017 at 10:00:55AM +0100, Salvatore Bonaccorso wrote: > > Hi > > > > Cc'ing explicitly Guido and Raphael, who commented before. > > > > On Sat, Dec 09, 2017 at 03:25:14PM +0100, Markus Koschany wro

Re: reportbug: please inform security and lts teams about security update regressions

2017-12-10 Thread Salvatore Bonaccorso
Hi On Sun, Dec 10, 2017 at 10:00:55AM +0100, Salvatore Bonaccorso wrote: > Hi > > Cc'ing explicitly Guido and Raphael, who commented before. > > On Sat, Dec 09, 2017 at 03:25:14PM +0100, Markus Koschany wrote: > > Hi, > > > > I have updated my patch for reportbug. Now emails are sent only to on

Re: reportbug: please inform security and lts teams about security update regressions

2017-12-10 Thread Salvatore Bonaccorso
Hi Cc'ing explicitly Guido and Raphael, who commented before. On Sat, Dec 09, 2017 at 03:25:14PM +0100, Markus Koschany wrote: > Hi, > > I have updated my patch for reportbug. Now emails are sent only to one > of the team mailing lists based on the release number in the version > string. There i

Re: reportbug: please inform security and lts teams about security update regressions

2017-12-09 Thread Markus Koschany
Hi, I have updated my patch for reportbug. Now emails are sent only to one of the team mailing lists based on the release number in the version string. There is apparently no simple way to determine the relationship between release number, code name, suite and whether this is a LTS release. So we

reportbug: please inform security and lts teams about security update regressions

2017-11-28 Thread Markus Koschany
Hello, I still haven't got a response for Debian bug #878088 and I wonder if we should implement this feature in Wheezy (and Jessie/Stretch if the security team agrees) now. Are there any objections, hints, recommendations? Regards, Markus signature.asc Description: OpenPGP digital signature

Bug#878088: reportbug: please inform security and lts teams about security update regressions

2017-10-09 Thread Markus Koschany
Package: reportbug Version: 7.1.7 Severity: wishlist Tags: patch Hi, the Debian LTS Team and the Debian Security Team would like to propose a new feature for reportbug. We discussed this at DebConf 17 during the LTS BoF and shortly on debian-lts [1] that it would make sense to inform both teams