Re: Ruby 1.9.1 Squeeze package for test

2015-06-29 Thread Guido Günther
On Sun, Jun 28, 2015 at 02:12:48PM +0200, Santiago Ruano Rincón wrote: [..snip..] > > Apart from that I noticed this behaviour change due to the fix for > > CVE-2013-0269 (based on [1]): > > > > Squeeze version: > > # cat < > > > require 'json' > > p JSON.p

Re: squeeze update of shibboleth-sp2?

2015-06-29 Thread Raphael Hertzog
Hi, On Mon, 13 Apr 2015, Ferenc Wagner wrote: > Anyway, I pushed the backported fix to the squeeze branch of > http://anonscm.debian.org/cgit/pkg-shibboleth/shibboleth-sp2.git. You > can find the corresponding source package at http://apt.niif.hu/lts/ > (debdiff below). Unfortunately, I couldn't

Re: [PATCH] lts-cve-triage: allow to skip packages already in dla-needed.txt

2015-06-29 Thread Raphael Hertzog
Hi, On Fri, 26 Jun 2015, Guido Günther wrote: > With lots of packages in dla-needed.txt it's easier to focus on CVEs of > packages that are not being worked on at all. Looks fine to me. > for pkg in tracker.iterate_packages(): > +if args.skip_dla_needed and pkg in tracker.dla_needed.keys():

Re: Accepted unattended-upgrades 0.62.2+squeeze1 (source all) into squeeze-lts

2015-06-29 Thread Raphael Hertzog
Hi Michael, On Mon, 29 Jun 2015, Michael Vogt wrote: > unattended-upgrades (0.62.2+squeeze1) squeeze-lts; urgency=high > . >* fix missing package authentication check for apt > configurations that force-{confold,confnew} (CVE-2015-1330) Will you release a DLA for this upload? cf https