Re: Certbot security update (Bug #969126)

2020-12-07 Thread Utkarsh Gupta
Hi Harlan, On Sun, Dec 6, 2020 at 5:37 AM Harlan Lieberman-Berg wrote: > Took a look at this and tried to duplicate it by updating my stretch > sbuild to use the security repo in case that did anything. No joy. > The only difference between our environments now is eatmydata -- which > could expl

(semi-)automatic unclaim of packages with more than 2 weeks of inactivity (and missing DLAs on www.do)

2020-12-07 Thread Holger Levsen
hi, today one package was unclaimed for LTS: - snapd (Brian May) and none for ELTS. Thorsten Alteholz probably claimed too many, 4, packages: minidlna openjpeg2 slirp x11vnc Finally there are two DLAs which have been reserved but not yet been published: - DLA 2483-1 (05 Dec 2020) (linux-4.19)

Re: golang-1.7 / CVE-2019-9514 / CVE-2019-9512

2020-12-07 Thread Brian May
Brian May writes: > I have a patch to fix this. As attached. I believe that there are exactly two additional packages that would need to be rebuilt in stretch (i.e. that include the http2 server code): - dnss - gobgpd Not 100% sure if these support creating a http2 server, but might be worth r