(semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2020-09-14 Thread Holger Levsen
hi, today five packages were unclaimed for LTS: - freerdp (Mike Gabriel) - gnome-shell (Mike Gabriel) - php-horde-trean (Mike Gabriel) - ruby-json-jwt (Utkarsh Gupta) - ruby-kaminari (Utkarsh Gupta) - ruby-rack-cors (Utkarsh Gupta) and two for ELTS: - samba (Mike Gabriel) - squid3 (Markus Kosch

Re: Backports needed for Firefox/Thunderbird ESR 78 in Buster/Stretch

2020-09-14 Thread Christoph Martin
Hi. Any progress here? Or any way to help? Am 01.09.20 um 19:17 schrieb Moritz Muehlenhoff: >> It may be more future-proof, in case we need it for a future >> rustc for the next ESR bump. > > My gut feeling is the next ESR thing will need LLVM 11 or so, but happy to > be proven wrong :-) So mayb

Re: golang-go.crypto / CVE-2019-11841

2020-09-14 Thread Ola Lundqvist
Hi So the header is not signed. Good to know. I think we can ignore the spoofing issue. Yes it is possible to spoof it but on the other hand you can just omit it even if it is checked. I think this is a minor issue. If at all an issue. But as always I may have missed some important point. The i